File name:

Desktop.rar

Full analysis: https://app.any.run/tasks/7b9b6c68-bc29-4798-8d60-c066c7a94652
Verdict: Malicious activity
Analysis date: April 25, 2025, 15:47:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

96F4BFCF1BE5306E9DA0BCE41F08168F

SHA1:

491E6AC76A9944445A8ED1F157DB7012151B2BF7

SHA256:

10DF1121B3E392937F690CD0DD37575BDC398B57023809E876068517B09FBBDE

SSDEEP:

98304:o9HTVQT3CJk+YF+4W2OpL4/6qAuZ8DlUuPrrGW/jdwwGGne49Le8TjadnZtWi+IP:lF9M7UxBJ6E9v5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7324)
  • SUSPICIOUS

    • Reads the BIOS version

      • NEW PRIME LOADER.exe (PID: 8144)
      • aa.exe (PID: 6272)
      • aa.exe (PID: 7788)
    • Starts CMD.EXE for commands execution

      • NEW PRIME LOADER.exe (PID: 8144)
      • aa.exe (PID: 6272)
      • aa.exe (PID: 7788)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7324)
    • Process checks whether UAC notifications are on

      • NEW PRIME LOADER.exe (PID: 8144)
      • aa.exe (PID: 6272)
      • aa.exe (PID: 7788)
    • Manual execution by a user

      • KA-LicenseKey_x86_x64_v1.1.exe (PID: 7948)
      • KA-LicenseKey_x86_x64_v1.1.exe (PID: 7900)
      • NEW PRIME LOADER.exe (PID: 8144)
      • NEW PRIME LOADER.exe (PID: 8092)
      • KA-LicenseKey_x86_x64_v1.1.exe (PID: 7764)
      • aa.exe (PID: 1188)
      • aa.exe (PID: 6272)
      • KA-LicenseKey_x86_x64_v1.1.exe (PID: 780)
      • aa.exe (PID: 7788)
      • aa.exe (PID: 7800)
    • Checks supported languages

      • NEW PRIME LOADER.exe (PID: 8144)
      • KA-LicenseKey_x86_x64_v1.1.exe (PID: 7948)
      • KA-LicenseKey_x86_x64_v1.1.exe (PID: 7764)
      • aa.exe (PID: 6272)
      • aa.exe (PID: 7788)
    • Reads the computer name

      • KA-LicenseKey_x86_x64_v1.1.exe (PID: 7948)
      • NEW PRIME LOADER.exe (PID: 8144)
      • aa.exe (PID: 6272)
      • KA-LicenseKey_x86_x64_v1.1.exe (PID: 7764)
      • aa.exe (PID: 7788)
    • Gets the hash of the file via CERTUTIL.EXE

      • certutil.exe (PID: 3156)
      • certutil.exe (PID: 5204)
      • certutil.exe (PID: 6028)
    • Creates files in the program directory

      • aa.exe (PID: 6272)
      • NEW PRIME LOADER.exe (PID: 8144)
    • Reads the software policy settings

      • slui.exe (PID: 7472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 2477267
UncompressedSize: 5561856
OperatingSystem: Win32
ArchivedFileName: KA-LicenseKey_x86_x64_v1.1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
163
Monitored processes
32
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe ka-licensekey_x86_x64_v1.1.exe no specs ka-licensekey_x86_x64_v1.1.exe conhost.exe no specs new prime loader.exe no specs new prime loader.exe conhost.exe no specs cmd.exe no specs certutil.exe no specs find.exe no specs find.exe no specs svchost.exe aa.exe no specs aa.exe conhost.exe no specs cmd.exe no specs certutil.exe no specs find.exe no specs find.exe no specs ka-licensekey_x86_x64_v1.1.exe no specs ka-licensekey_x86_x64_v1.1.exe conhost.exe no specs slui.exe no specs aa.exe no specs aa.exe conhost.exe no specs cmd.exe no specs certutil.exe no specs find.exe no specs find.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
780"C:\Users\admin\Desktop\KA-LicenseKey_x86_x64_v1.1.exe" C:\Users\admin\Desktop\KA-LicenseKey_x86_x64_v1.1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\ka-licensekey_x86_x64_v1.1.exe
c:\windows\system32\ntdll.dll
1188"C:\Users\admin\Desktop\aa.exe" C:\Users\admin\Desktop\aa.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\aa.exe
c:\windows\system32\ntdll.dll
1676find /i /v "certutil"C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2692C:\WINDOWS\system32\cmd.exe /c certutil -hashfile "C:\Users\admin\Desktop\aa.exe" MD5 | find /i /v "md5" | find /i /v "certutil"C:\Windows\System32\cmd.exeaa.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
3156certutil -hashfile "C:\Users\admin\Desktop\NEW PRIME LOADER.exe" MD5 C:\Windows\System32\certutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CertUtil.exe
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\certutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4920find /i /v "certutil"C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
5124find /i /v "md5" C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
5204certutil -hashfile "C:\Users\admin\Desktop\aa.exe" MD5 C:\Windows\System32\certutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CertUtil.exe
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\certutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5364C:\WINDOWS\system32\cmd.exe /c certutil -hashfile "C:\Users\admin\Desktop\NEW PRIME LOADER.exe" MD5 | find /i /v "md5" | find /i /v "certutil"C:\Windows\System32\cmd.exeNEW PRIME LOADER.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
Total events
3 978
Read events
3 957
Write events
21
Delete events
0

Modification events

(PID) Process:(7324) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7324) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7324) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7324) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Desktop.rar
(PID) Process:(7324) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7324) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7324) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7324) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7324) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(7324) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\General\Toolbar\Layout
Operation:writeName:Band76_2
Value:
4C000000730100000400000000000000F0F0F00000000000000000000000000000000000000000008C0205000000000000000000180000006400000000000000000000000000000003000000
Executable files
2
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
7324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7324.39858\NEW PRIME LOADER.exeexecutable
MD5:D216A54871C5438AB84B78DF33B34A2D
SHA256:3365C66FD413719E9DE49C5026968B6B3EC506A6B153BE365EF9BBFA20FEB790
6272aa.exeC:\ProgramData\KeyAuth\Debug\aa\04-25-2025.txttext
MD5:28F9C0703452F493B5B1935B7F8A8811
SHA256:E146077D4C9970DBF30041154E90D9576422FC27EC33B77A0AD49D2C71FCFFDE
7324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7324.39858\KA-LicenseKey_x86_x64_v1.1.exeexecutable
MD5:EFAB4965DA18F638BA67ECE790FDED62
SHA256:93679AF51F96EDFA02CABEA6801ABA4484A90449745E2AA78AFBD3E13FC1E070
8144NEW PRIME LOADER.exeC:\ProgramData\KeyAuth\Debug\NEW PRIME LOADER\04-25-2025.txttext
MD5:17BBC589CC1928112535D3C138140C5E
SHA256:EFFADE0CDEAC1A28374894EDEC850F4BB98ADBE2CF570E53D2B8BCC4D209D00C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
22
DNS requests
16
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4448
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
756
lsass.exe
GET
200
23.192.153.142:80
http://x1.c.lencr.org/
unknown
whitelisted
4448
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
8144
NEW PRIME LOADER.exe
104.26.1.5:443
keyauth.win
CLOUDFLARENET
US
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
keyauth.win
  • 104.26.1.5
  • 104.26.0.5
  • 172.67.72.57
malicious
x1.c.lencr.org
  • 23.192.153.142
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Potentially Bad Traffic
ET INFO KeyAuth Open-source Authentication System Domain in DNS Lookup (keyauth .win)
8144
NEW PRIME LOADER.exe
Potentially Bad Traffic
ET INFO KeyAuth Open-source Authentication System Domain (keyauth .win) in TLS SNI
6272
aa.exe
Potentially Bad Traffic
ET INFO KeyAuth Open-source Authentication System Domain (keyauth .win) in TLS SNI
7788
aa.exe
Potentially Bad Traffic
ET INFO KeyAuth Open-source Authentication System Domain (keyauth .win) in TLS SNI
No debug info