File name:

atikmdag-patcher-1.4.14.zip

Full analysis: https://app.any.run/tasks/e9901223-8ece-470f-9a5b-d67bd8f6ac77
Verdict: Malicious activity
Analysis date: October 30, 2023, 03:41:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
autoit
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

2720DE174BDB937CE659A4685F8292C4

SHA1:

5F2C3E68FE8F893DB6B58A02B0EF84D084C227AA

SHA256:

292E8C418A53C4A2B809CC452FDCF30963C908D37E28B7E4A8DCC7681306211C

SSDEEP:

98304:xIiyTkZ1U6MgrYemel+AFxqYzY0h1D97qDHC6wNQJQ72cs61KjjvtkQ1ayv3ewQF:7DHh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • atikmdag-patcher.exe (PID: 316)
      • atikmdag-patcher.exe (PID: 3204)
      • atikmdag-patcher.exe (PID: 1228)
      • BitZum.exe (PID: 128)
      • LayoutMinutes.exe (PID: 3520)
      • atikmdag-patcher.exe (PID: 3456)
      • Full.pif (PID: 3380)
      • Beats.pif (PID: 1912)
    • Creates a writable file the system directory

      • atikmdag-patcher.exe (PID: 1228)
    • Drops the executable file immediately after the start

      • atikmdag-patcher.exe (PID: 1228)
      • BitZum.exe (PID: 128)
      • LayoutMinutes.exe (PID: 3520)
      • cmd.exe (PID: 2900)
      • cmd.exe (PID: 3436)
      • Beats.pif (PID: 1912)
    • Create files in the Startup directory

      • cmd.exe (PID: 3248)
  • SUSPICIOUS

    • Application launched itself

      • atikmdag-patcher.exe (PID: 3204)
      • atikmdag-patcher.exe (PID: 316)
      • cmd.exe (PID: 3856)
      • cmd.exe (PID: 604)
      • cmd.exe (PID: 1140)
      • cmd.exe (PID: 3540)
    • Reads the Windows owner or organization settings

      • atikmdag-patcher.exe (PID: 316)
      • atikmdag-patcher.exe (PID: 1228)
    • Reads the Internet Settings

      • atikmdag-patcher.exe (PID: 316)
    • Starts CMD.EXE for commands execution

      • LayoutMinutes.exe (PID: 3520)
      • BitZum.exe (PID: 128)
      • cmd.exe (PID: 604)
      • cmd.exe (PID: 3856)
      • cmd.exe (PID: 3540)
      • cmd.exe (PID: 1140)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 1140)
      • cmd.exe (PID: 3540)
    • Get information on the list of running processes

      • cmd.exe (PID: 1140)
      • cmd.exe (PID: 3540)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 1140)
      • cmd.exe (PID: 3540)
    • Drops the AutoIt3 executable file

      • cmd.exe (PID: 2900)
      • cmd.exe (PID: 3436)
      • Beats.pif (PID: 1912)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3540)
      • cmd.exe (PID: 1140)
  • INFO

    • Reads the computer name

      • atikmdag-patcher.exe (PID: 3204)
      • atikmdag-patcher.exe (PID: 316)
      • atikmdag-patcher.exe (PID: 1228)
      • Full.pif (PID: 3380)
      • Beats.pif (PID: 1912)
    • Checks supported languages

      • atikmdag-patcher.exe (PID: 3204)
      • atikmdag-patcher.exe (PID: 316)
      • atikmdag-patcher.exe (PID: 1228)
      • BitZum.exe (PID: 128)
      • atikmdag-patcher.exe (PID: 3456)
      • LayoutMinutes.exe (PID: 3520)
      • Full.pif (PID: 3380)
      • Beats.pif (PID: 1912)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 556)
    • Creates files in the program directory

      • atikmdag-patcher.exe (PID: 1228)
    • Create files in a temporary directory

      • BitZum.exe (PID: 128)
      • LayoutMinutes.exe (PID: 3520)
    • Reads mouse settings

      • Full.pif (PID: 3380)
      • Beats.pif (PID: 1912)
    • The executable file from the user directory is run by the CMD process

      • Beats.pif (PID: 1912)
      • Full.pif (PID: 3380)
    • Creates files or folders in the user directory

      • Beats.pif (PID: 1912)
    • Manual execution by a user

      • cmd.exe (PID: 3248)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:10:26 12:16:10
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: atikmdag-patcher-1.4.14/
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
28
Malicious processes
12
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start winrar.exe no specs atikmdag-patcher.exe no specs atikmdag-patcher.exe atikmdag-patcher.exe no specs bitzum.exe no specs layoutminutes.exe no specs atikmdag-patcher.exe no specs ftp.exe no specs ftp.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs beats.pif no specs full.pif no specs ping.exe no specs ping.exe no specs cmd.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Windows\system32\BitZum.exe"C:\Windows\System32\BitZum.exeatikmdag-patcher.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\system32\bitzum.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
316"C:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exe" /SPAWNWND=$100198 /NOTIFYWND=$100198 C:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exe
atikmdag-patcher.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mpr.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
372findstr /I "avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe"C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imm32.dll
460cmd /c mkdir 2190C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
556"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\atikmdag-patcher-1.4.14.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
604cmd /k cmd < Right & exitC:\Windows\System32\cmd.exeBitZum.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\cmd.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
1140cmd C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1228"C:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exe" /VERYSILENTC:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exeatikmdag-patcher.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1244cmd /c copy /b Cb + Hindu 2190\i C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1740ping -n 5 localhostC:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
Total events
3 881
Read events
3 844
Write events
25
Delete events
12

Modification events

(PID) Process:(556) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
12
Suspicious files
11
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\atikmdag-patcher-0.binbinary
MD5:8C5C3337FE439858CCF5D196DD890685
SHA256:D7A9246B43EBBA4855DCBD880283501244C335E9D1A2965CE7C12B8FE7052970
1228atikmdag-patcher.exeC:\Windows\System32\BitZum.exeexecutable
MD5:4B957C551B1FE17BD807761C78AE9C19
SHA256:9ECBF1256434C864ADC3F887D09A96FE65BDC6551821F925126D07D4BB839B2B
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa556.29761\atikmdag-patcher-1.4.14\Info.txttext
MD5:C47CD60656EA1ECA9DEC05897685D132
SHA256:66BF818AC5653849AB7BC3BE797958857A8A685160942B5318BAFB0A2F5A4C2E
1228atikmdag-patcher.exeC:\Windows\system32\is-MLNGG.tmpexecutable
MD5:4B957C551B1FE17BD807761C78AE9C19
SHA256:9ECBF1256434C864ADC3F887D09A96FE65BDC6551821F925126D07D4BB839B2B
1228atikmdag-patcher.exeC:\Windows\system32\is-5SPRK.tmpexecutable
MD5:0E51FEC89B9F51488F287ED76DBCC490
SHA256:B349B9E4D35A973F5E600555AA79F59FA7B6567C355184ED5E04C8E2EC477399
1228atikmdag-patcher.exeC:\Windows\System32\LayoutMinutes.exeexecutable
MD5:0E51FEC89B9F51488F287ED76DBCC490
SHA256:B349B9E4D35A973F5E600555AA79F59FA7B6567C355184ED5E04C8E2EC477399
128BitZum.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\Pleasedbinary
MD5:4497118A49285E6E8C131ED8E6F734E0
SHA256:7F26CCB7B343EB43D52B014DFC915D9D27BB0382CDD3B61CAB483CDDA7A8CB15
3520LayoutMinutes.exeC:\Users\admin\AppData\Local\Temp\IXP001.TMP\Porschebinary
MD5:B6AFDE484B855C070B0911A02213897F
SHA256:F3E8626BC5BA9E62FBAB87ADCDC76F7BAFB646A23D026E5BCB79C2E80E211896
128BitZum.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\Herexecutable
MD5:F7C70E65578719CB549E75787F23D287
SHA256:171D8C2446254FB10280F86D36D036374260F1ABC87C097F8329455E4DF05070
128BitZum.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\Responsibletext
MD5:3CA9F37D958908EDFC4DD6AB19E934D0
SHA256:A203755F0F308A24E42AE152048237D8B1F310003FCD95B63B11FA18417A7380
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2656
svchost.exe
239.255.255.250:1900
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
KgANSDbkeolvszV.KgANSDbkeolvszV
unknown
YYKTPnvnYcq.YYKTPnvnYcq
unknown

Threats

No threats detected
No debug info