File name:

atikmdag-patcher-1.4.14.zip

Full analysis: https://app.any.run/tasks/e9901223-8ece-470f-9a5b-d67bd8f6ac77
Verdict: Malicious activity
Analysis date: October 30, 2023, 03:41:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
autoit
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

2720DE174BDB937CE659A4685F8292C4

SHA1:

5F2C3E68FE8F893DB6B58A02B0EF84D084C227AA

SHA256:

292E8C418A53C4A2B809CC452FDCF30963C908D37E28B7E4A8DCC7681306211C

SSDEEP:

98304:xIiyTkZ1U6MgrYemel+AFxqYzY0h1D97qDHC6wNQJQ72cs61KjjvtkQ1ayv3ewQF:7DHh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • atikmdag-patcher.exe (PID: 3204)
      • BitZum.exe (PID: 128)
      • atikmdag-patcher.exe (PID: 316)
      • atikmdag-patcher.exe (PID: 1228)
      • atikmdag-patcher.exe (PID: 3456)
      • LayoutMinutes.exe (PID: 3520)
      • Beats.pif (PID: 1912)
      • Full.pif (PID: 3380)
    • Creates a writable file the system directory

      • atikmdag-patcher.exe (PID: 1228)
    • Drops the executable file immediately after the start

      • atikmdag-patcher.exe (PID: 1228)
      • BitZum.exe (PID: 128)
      • LayoutMinutes.exe (PID: 3520)
      • cmd.exe (PID: 2900)
      • Beats.pif (PID: 1912)
      • cmd.exe (PID: 3436)
    • Create files in the Startup directory

      • cmd.exe (PID: 3248)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • atikmdag-patcher.exe (PID: 316)
      • atikmdag-patcher.exe (PID: 1228)
    • Application launched itself

      • atikmdag-patcher.exe (PID: 3204)
      • atikmdag-patcher.exe (PID: 316)
      • cmd.exe (PID: 604)
      • cmd.exe (PID: 3856)
      • cmd.exe (PID: 1140)
      • cmd.exe (PID: 3540)
    • Reads the Internet Settings

      • atikmdag-patcher.exe (PID: 316)
    • Starts CMD.EXE for commands execution

      • BitZum.exe (PID: 128)
      • LayoutMinutes.exe (PID: 3520)
      • cmd.exe (PID: 604)
      • cmd.exe (PID: 3856)
      • cmd.exe (PID: 3540)
      • cmd.exe (PID: 1140)
    • Get information on the list of running processes

      • cmd.exe (PID: 1140)
      • cmd.exe (PID: 3540)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 1140)
      • cmd.exe (PID: 3540)
    • Drops the AutoIt3 executable file

      • cmd.exe (PID: 2900)
      • Beats.pif (PID: 1912)
      • cmd.exe (PID: 3436)
    • Starts application with an unusual extension

      • cmd.exe (PID: 1140)
      • cmd.exe (PID: 3540)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 1140)
      • cmd.exe (PID: 3540)
  • INFO

    • Checks supported languages

      • atikmdag-patcher.exe (PID: 3204)
      • atikmdag-patcher.exe (PID: 1228)
      • BitZum.exe (PID: 128)
      • atikmdag-patcher.exe (PID: 3456)
      • LayoutMinutes.exe (PID: 3520)
      • Full.pif (PID: 3380)
      • Beats.pif (PID: 1912)
      • atikmdag-patcher.exe (PID: 316)
    • Reads the computer name

      • atikmdag-patcher.exe (PID: 3204)
      • atikmdag-patcher.exe (PID: 1228)
      • atikmdag-patcher.exe (PID: 316)
      • Full.pif (PID: 3380)
      • Beats.pif (PID: 1912)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 556)
    • Creates files in the program directory

      • atikmdag-patcher.exe (PID: 1228)
    • Create files in a temporary directory

      • LayoutMinutes.exe (PID: 3520)
      • BitZum.exe (PID: 128)
    • The executable file from the user directory is run by the CMD process

      • Full.pif (PID: 3380)
      • Beats.pif (PID: 1912)
    • Reads mouse settings

      • Full.pif (PID: 3380)
      • Beats.pif (PID: 1912)
    • Manual execution by a user

      • cmd.exe (PID: 3248)
    • Creates files or folders in the user directory

      • Beats.pif (PID: 1912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:10:26 12:16:10
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: atikmdag-patcher-1.4.14/
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
28
Malicious processes
12
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start winrar.exe no specs atikmdag-patcher.exe no specs atikmdag-patcher.exe atikmdag-patcher.exe no specs bitzum.exe no specs layoutminutes.exe no specs atikmdag-patcher.exe no specs ftp.exe no specs ftp.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs beats.pif no specs full.pif no specs ping.exe no specs ping.exe no specs cmd.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Windows\system32\BitZum.exe"C:\Windows\System32\BitZum.exeatikmdag-patcher.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\system32\bitzum.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
316"C:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exe" /SPAWNWND=$100198 /NOTIFYWND=$100198 C:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exe
atikmdag-patcher.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mpr.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
372findstr /I "avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe"C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imm32.dll
460cmd /c mkdir 2190C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
556"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\atikmdag-patcher-1.4.14.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
604cmd /k cmd < Right & exitC:\Windows\System32\cmd.exeBitZum.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\cmd.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
1140cmd C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1228"C:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exe" /VERYSILENTC:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exeatikmdag-patcher.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1244cmd /c copy /b Cb + Hindu 2190\i C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1740ping -n 5 localhostC:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
Total events
3 881
Read events
3 844
Write events
25
Delete events
12

Modification events

(PID) Process:(556) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
12
Suspicious files
11
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exeexecutable
MD5:8B544F989469413C4D90FE113B847DEB
SHA256:A87AF4000CD6DF6603E04B39A70ADF968A88FE976F9DDE845FF96756D7220F94
128BitZum.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\Repliesbinary
MD5:9239FDBE6CA70F51E2D295BC378EFA7A
SHA256:30DBED07087FA3E83F78545F02EEC9051AC3A4E23A613A268A3137874F76D18C
1228atikmdag-patcher.exeC:\Windows\system32\is-MLNGG.tmpexecutable
MD5:4B957C551B1FE17BD807761C78AE9C19
SHA256:9ECBF1256434C864ADC3F887D09A96FE65BDC6551821F925126D07D4BB839B2B
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher-0.binbinary
MD5:8C5C3337FE439858CCF5D196DD890685
SHA256:D7A9246B43EBBA4855DCBD880283501244C335E9D1A2965CE7C12B8FE7052970
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\Info.txttext
MD5:C47CD60656EA1ECA9DEC05897685D132
SHA256:66BF818AC5653849AB7BC3BE797958857A8A685160942B5318BAFB0A2F5A4C2E
1228atikmdag-patcher.exeC:\Windows\System32\LayoutMinutes.exeexecutable
MD5:0E51FEC89B9F51488F287ED76DBCC490
SHA256:B349B9E4D35A973F5E600555AA79F59FA7B6567C355184ED5E04C8E2EC477399
1228atikmdag-patcher.exeC:\Program Files\My Program\is-6I30H.tmpexecutable
MD5:CE53DCF26C43EB08E70E220BB69419F6
SHA256:575DF9C65E0251572372226E6323068E2C17ADBBCBA91BB5ADC22F2F653DB7BA
1228atikmdag-patcher.exeC:\Windows\system32\is-5SPRK.tmpexecutable
MD5:0E51FEC89B9F51488F287ED76DBCC490
SHA256:B349B9E4D35A973F5E600555AA79F59FA7B6567C355184ED5E04C8E2EC477399
1228atikmdag-patcher.exeC:\Windows\System32\BitZum.exeexecutable
MD5:4B957C551B1FE17BD807761C78AE9C19
SHA256:9ECBF1256434C864ADC3F887D09A96FE65BDC6551821F925126D07D4BB839B2B
1228atikmdag-patcher.exeC:\Program Files\My Program\atikmdag-patcher.exeexecutable
MD5:CE53DCF26C43EB08E70E220BB69419F6
SHA256:575DF9C65E0251572372226E6323068E2C17ADBBCBA91BB5ADC22F2F653DB7BA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2656
svchost.exe
239.255.255.250:1900
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
KgANSDbkeolvszV.KgANSDbkeolvszV
unknown
YYKTPnvnYcq.YYKTPnvnYcq
unknown

Threats

No threats detected
No debug info