File name:

SirHurt V5.rar

Full analysis: https://app.any.run/tasks/9860e388-9ec4-4f60-952d-b22fe5570f5a
Verdict: Malicious activity
Analysis date: December 04, 2024, 16:16:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
themida
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

E64309D0F24F701FE368D1EF95A40707

SHA1:

00DA24516B3A2011260AE1E5EFA569E8848DD557

SHA256:

911D322FF6AFEEC165EB573CA55DC75DA8D61E5999F3539D18F925971CEDDC4E

SSDEEP:

98304:+FR4OmKoWeElRDZx3JwehFRH5AfDjlnNnvAMKGd34VGIq2H4xMN5u+kbUAWVNhPX:7WPcoMwbRRHG3VGzYXXL6JIz33k/9fd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6276)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SirHurt V5.exe (PID: 1412)
      • bootstrapper.exe (PID: 6560)
      • SirHurt V5.exe (PID: 1488)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6276)
    • Manual execution by a user

      • SirHurt V5.exe (PID: 7124)
      • SirHurt V5.exe (PID: 1412)
      • O54tTiUSob.exe (PID: 2452)
      • bootstrapper.exe (PID: 6560)
      • O54tTiUSob.exe (PID: 6524)
      • O54tTiUSob.exe (PID: 3988)
      • bootstrapper.exe (PID: 4704)
      • O54tTiUSob.exe (PID: 6668)
      • TitNCNxWwn.exe (PID: 7148)
      • TitNCNxWwn.exe (PID: 2144)
    • Themida protector has been detected

      • SirHurt V5.exe (PID: 1412)
      • TitNCNxWwn.exe (PID: 2144)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 1189788
UncompressedSize: 3722240
OperatingSystem: Win32
ArchivedFileName: sirhurt.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
18
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs sirhurt v5.exe no specs sirhurt v5.exe conhost.exe no specs o54ttiusob.exe no specs o54ttiusob.exe conhost.exe no specs bootstrapper.exe no specs bootstrapper.exe o54ttiusob.exe no specs o54ttiusob.exe conhost.exe no specs sirhurt v5.exe conhost.exe no specs titncnxwwn.exe no specs titncnxwwn.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1344\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeTitNCNxWwn.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1412"C:\Users\admin\Desktop\New folder\SirHurt V5.exe" C:\Users\admin\Desktop\New folder\SirHurt V5.exe
explorer.exe
User:
admin
Company:
HP Inc.
Integrity Level:
HIGH
Description:
SirHurt V5
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\new folder\sirhurt v5.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mscoree.dll
1488"C:\Users\admin\Desktop\New folder\SirHurt V5.exe" C:\Users\admin\Desktop\New folder\SirHurt V5.exe
bootstrapper.exe
User:
admin
Company:
HP Inc.
Integrity Level:
HIGH
Description:
SirHurt V5
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\new folder\sirhurt v5.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mscoree.dll
2144"C:\Users\admin\Desktop\New folder\TitNCNxWwn.exe" C:\Users\admin\Desktop\New folder\TitNCNxWwn.exe
explorer.exe
User:
admin
Company:
HP Inc.
Integrity Level:
HIGH
Description:
SirHurt V5
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\new folder\titncnxwwn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mscoree.dll
2452"C:\Users\admin\Desktop\New folder\O54tTiUSob.exe" C:\Users\admin\Desktop\New folder\O54tTiUSob.exe
explorer.exe
User:
admin
Company:
HP Inc.
Integrity Level:
HIGH
Description:
SirHurt V5
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\new folder\o54ttiusob.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mscoree.dll
3988"C:\Users\admin\Desktop\New folder\O54tTiUSob.exe" C:\Users\admin\Desktop\New folder\O54tTiUSob.exeexplorer.exe
User:
admin
Company:
HP Inc.
Integrity Level:
MEDIUM
Description:
SirHurt V5
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\new folder\o54ttiusob.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4244\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeO54tTiUSob.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4704"C:\Users\admin\Desktop\New folder\bootstrapper.exe" C:\Users\admin\Desktop\New folder\bootstrapper.exeexplorer.exe
User:
admin
Company:
HP Inc.
Integrity Level:
MEDIUM
Description:
SirHurt V2 GUI Bootstrapper
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\new folder\bootstrapper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5076\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSirHurt V5.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5200\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSirHurt V5.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
6 822
Read events
6 737
Write events
85
Delete events
0

Modification events

(PID) Process:(6276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\SirHurt V5.rar
(PID) Process:(6276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF4401000071000000040500005A020000
(PID) Process:(6276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
10
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
6276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6276.32126\SirHurt V5.exeexecutable
MD5:AAE096AEE8465E91D7086BC5274DE3D8
SHA256:1AF8D3B4EB8A8847328CDB346A2E9EDA944519AF786E112791C2EB50D5643726
6276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6276.32126\sirhurt.exeexecutable
MD5:07D1EB26E14817EB6F1278992AF36997
SHA256:5D75E1979655DEB2F691C61591D77420AD27453769FDE72CF2BA1E3262DB5C95
6276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6276.32126\READ ME Instructions.txttext
MD5:2EF35C616D9F5321743CA43527446110
SHA256:87449E2239611893C3217BFD47EE21DFB4B18BCDEF819297167ADC3ED7A16535
6276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6276.32126\VMProtectSDK64.dllexecutable
MD5:8952450F3D98016016682A6B0B716518
SHA256:A56239B26392A8EC49A47D27B0632B65A3F98A2735BF60DCE66139A71FF804FC
6560bootstrapper.exeC:\Users\admin\Desktop\New folder\sirhurt.dllexecutable
MD5:B4638AB8A6BF1D0638C6ECB308B16AEE
SHA256:2544FA22E270C6B9D2213855A47A31BE1F09CA6C0BC51C94B42E31169BBF879B
1412SirHurt V5.exeC:\Users\admin\AppData\Local\Temp\ScintillaNET\3.6.3\x86\SciLexer.dllexecutable
MD5:2FF7ACFA80647EE46CC3C0E446327108
SHA256:08F0CBBC5162F236C37166772BE2C9B8FFD465D32DF17EA9D45626C4ED2C911D
6560bootstrapper.exeC:\Users\admin\Desktop\New folder\SirHurt.newexecutable
MD5:B4638AB8A6BF1D0638C6ECB308B16AEE
SHA256:2544FA22E270C6B9D2213855A47A31BE1F09CA6C0BC51C94B42E31169BBF879B
1412SirHurt V5.exeC:\Users\admin\Desktop\New folder\O54tTiUSob.exeexecutable
MD5:AAE096AEE8465E91D7086BC5274DE3D8
SHA256:1AF8D3B4EB8A8847328CDB346A2E9EDA944519AF786E112791C2EB50D5643726
1488SirHurt V5.exeC:\Users\admin\Desktop\New folder\TitNCNxWwn.exeexecutable
MD5:AAE096AEE8465E91D7086BC5274DE3D8
SHA256:1AF8D3B4EB8A8847328CDB346A2E9EDA944519AF786E112791C2EB50D5643726
2144TitNCNxWwn.exeC:\Users\admin\AppData\Roaming\sirhurt\sirhui\sirhurt.dattext
MD5:CFC61A1E9F7CF7993D9F38FC97367E7F
SHA256:350CEA9FA146D43AF66A2448392FB28B8495CB9B888706CBE14B465DA83FB017
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
38
DNS requests
21
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6940
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6940
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5040
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
104.126.37.137:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1076
svchost.exe
23.32.186.57:443
go.microsoft.com
AKAMAI-AS
BR
whitelisted
6068
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5040
backgroundTaskHost.exe
20.103.156.88:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 104.126.37.137
  • 104.126.37.178
  • 104.126.37.185
  • 104.126.37.129
  • 104.126.37.144
  • 104.126.37.147
  • 104.126.37.139
  • 104.126.37.123
  • 104.126.37.179
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.73
  • 40.126.31.71
  • 20.190.159.4
  • 20.190.159.2
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.71
  • 20.190.159.68
whitelisted
go.microsoft.com
  • 23.32.186.57
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Image Sharing Service (imgur.com)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Image Sharing Service (imgur.com)
No debug info