File name:

KMSAuto++ Portable v1.5.5 Final.rar

Full analysis: https://app.any.run/tasks/50069991-b4b7-418a-bf88-b8057fb9b14e
Verdict: Malicious activity
Analysis date: February 07, 2024, 08:59:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

463F3F13A9978AAA467F6D325ED5EAC9

SHA1:

D95D1889B08E0121A36650C4D12A99DBBA3603B5

SHA256:

2A0BB36706ED995380E83EBBBA1C5A7CEBE6E1686C8A1EC7ACE8442FBD8E9AAE

SSDEEP:

98304:L8Vugmr5T2dZ7d12yX99n3X+XWHUbvg8UG2mBjjqRhVy321alvKfz1GqU+GxLHoE:LQSvtssA17HR2mh/ShMBi0RKMcfQCG+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 268)
      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
  • SUSPICIOUS

    • Start notepad (likely ransomware note)

      • WinRAR.exe (PID: 268)
    • Process drops legitimate windows executable

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
    • Starts a Microsoft application from unusual location

      • signtool.exe (PID: 3012)
    • Reads security settings of Internet Explorer

      • signtool.exe (PID: 3012)
    • Checks Windows Trust Settings

      • signtool.exe (PID: 3012)
    • Reads settings of System Certificates

      • signtool.exe (PID: 3012)
    • Reads the Internet Settings

      • signtool.exe (PID: 3012)
    • Executable content was dropped or overwritten

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
    • Starts CMD.EXE for commands execution

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
    • Drops 7-zip archiver for unpacking

      • OInstallLite.exe (PID: 3580)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3548)
    • The executable file from the user directory is run by the CMD process

      • files.dat (PID: 2612)
    • Adds/modifies Windows certificates

      • signtool.exe (PID: 3012)
    • The process drops C-runtime libraries

      • files.dat (PID: 2612)
  • INFO

    • Reads product name

      • KMSAuto++.exe (PID: 1428)
    • Checks supported languages

      • KMSAuto++.exe (PID: 1428)
      • signtool.exe (PID: 3012)
      • files.dat (PID: 2612)
      • OInstallLite.exe (PID: 3580)
      • wmpnscfg.exe (PID: 3884)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 268)
    • Reads the computer name

      • signtool.exe (PID: 3012)
      • OInstallLite.exe (PID: 3580)
      • wmpnscfg.exe (PID: 3884)
    • Reads Environment values

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
    • Reads the machine GUID from the registry

      • signtool.exe (PID: 3012)
    • Create files in a temporary directory

      • KMSAuto++.exe (PID: 1428)
      • signtool.exe (PID: 3012)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3884)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe notepad.exe no specs kmsauto++.exe no specs kmsauto++.exe cmd.exe no specs signtool.exe oinstalllite.exe cmd.exe no specs cmd.exe no specs files.dat wmpnscfg.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\KMSAuto++ Portable v1.5.5 Final.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1172"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\kmsauto++.exe
c:\windows\system32\ntdll.dll
1428"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\kmsauto++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1588"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa268.40018\KMSAuto++.iniC:\Windows\System32\notepad.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2508"C:\Windows\System32\cmd.exe" /c copy C:\Windows\system32\Tasks\KMSAuto "C:\Users\admin\AppData\Local\Temp\KMSAuto.tmp" /YC:\Windows\System32\cmd.exeKMSAuto++.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2612files.dat -y -pkmsautoC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\files.dat
cmd.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7z Console SFX
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\files\files.dat
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3012"C:\Users\admin\AppData\Local\Temp\signtool.exe" verify /v /ph /sha1 648384a4dee53d4c1c87e10d67cc99307ccc9c98 "C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe"C:\Users\admin\AppData\Local\Temp\signtool.exe
KMSAuto++.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Authenticode(R) - signing and verifying tool
Exit code:
1
Version:
4.00 (rs1_release_sec.170105-1850)
Modules
Images
c:\users\admin\appdata\local\temp\signtool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\user32.dll
3356"C:\Windows\System32\cmd.exe" /D /c copy C:\Windows\system32\Tasks\OInstall "C:\Windows\Temp\OInstall.tmp" /YC:\Windows\System32\cmd.exeOInstallLite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3548"C:\Windows\System32\cmd.exe" /D /c files.dat -y -pkmsautoC:\Windows\System32\cmd.exeOInstallLite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3580"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\OInstallLite.exe" /x=100 /y=100C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\OInstallLite.exe
KMSAuto++.exe
User:
admin
Integrity Level:
HIGH
Description:
Office 2013-2016 C2R Install Lite
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\oinstalllite.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
5 541
Read events
5 494
Write events
47
Delete events
0

Modification events

(PID) Process:(268) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
9
Suspicious files
4
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3012signtool.exeC:\Users\admin\AppData\Local\Temp\TarAF02.tmpbinary
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
3012signtool.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:472A2BF14D1AC725A7DB9C66ECE0C700
SHA256:9ABB7D2CEFD14FC8A1A0F2A7DAF6E5C9823B2B0B517565B98022A6CD9E27CDA0
3012signtool.exeC:\Users\admin\AppData\Local\Temp\CabAF01.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa268.40018\KMSAuto++.initext
MD5:F9EA4571821D978CA8A13384E49BAD1A
SHA256:FD1015A97100A23AF9BDF682604187CFFE974042F45EEAF65EBD56F258992076
2612files.datC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\x64\cleanospp.exeexecutable
MD5:162AB955CB2F002A73C1530AA796477F
SHA256:5CE462E5F34065FC878362BA58617FAB28C22D631B9D836DDDCF43FB1AD4DE6E
2612files.datC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\x86\cleanospp.exeexecutable
MD5:5FD363D52D04AC200CD24F3BCC903200
SHA256:3FDEFE2AD092A9A7FE0EDF0AC4DC2DE7E5B9CE6A0804F6511C06564194966CF9
1428KMSAuto++.exeC:\Users\admin\AppData\Local\Temp\signtool.exeexecutable
MD5:05624E6D27EAEF0DB0673AE627BD6027
SHA256:962A92821F54A1E706AA989973130FDC1072C7BD8B9E6D11EA1050B46EB9D313
2612files.datC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\x64\msvcr100.dllexecutable
MD5:DF3CA8D16BDED6A54977B30E66864D33
SHA256:1D1A1AE540BA132F998D60D3622F0297B6E86AE399332C3B47462D7C0F560A36
2612files.datC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\x86\msvcr100.dllexecutable
MD5:BF38660A9125935658CFA3E53FDC7D65
SHA256:60C06E0FA4449314DA3A0A87C1A9D9577DF99226F943637E06F61188E5862EFA
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exeexecutable
MD5:69FBF6849D935432BAC8B04BDB00FD68
SHA256:D5DC790F6F220CF7E42C6C1C9F5BC6E4443CB52D07BCDEF24A6BF457153C1D86
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3012
signtool.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c450e6b2e12ab1c2
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3012
signtool.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted

Threats

No threats detected
No debug info