File name:

KMSAuto++ Portable v1.5.5 Final.rar

Full analysis: https://app.any.run/tasks/50069991-b4b7-418a-bf88-b8057fb9b14e
Verdict: Malicious activity
Analysis date: February 07, 2024, 08:59:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

463F3F13A9978AAA467F6D325ED5EAC9

SHA1:

D95D1889B08E0121A36650C4D12A99DBBA3603B5

SHA256:

2A0BB36706ED995380E83EBBBA1C5A7CEBE6E1686C8A1EC7ACE8442FBD8E9AAE

SSDEEP:

98304:L8Vugmr5T2dZ7d12yX99n3X+XWHUbvg8UG2mBjjqRhVy321alvKfz1GqU+GxLHoE:LQSvtssA17HR2mh/ShMBi0RKMcfQCG+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 268)
      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
  • SUSPICIOUS

    • Start notepad (likely ransomware note)

      • WinRAR.exe (PID: 268)
    • Starts CMD.EXE for commands execution

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
    • Executable content was dropped or overwritten

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
    • Process drops legitimate windows executable

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
    • Reads security settings of Internet Explorer

      • signtool.exe (PID: 3012)
    • Starts a Microsoft application from unusual location

      • signtool.exe (PID: 3012)
    • Reads settings of System Certificates

      • signtool.exe (PID: 3012)
    • Checks Windows Trust Settings

      • signtool.exe (PID: 3012)
    • Reads the Internet Settings

      • signtool.exe (PID: 3012)
    • Drops 7-zip archiver for unpacking

      • OInstallLite.exe (PID: 3580)
    • The executable file from the user directory is run by the CMD process

      • files.dat (PID: 2612)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3548)
    • Adds/modifies Windows certificates

      • signtool.exe (PID: 3012)
    • The process drops C-runtime libraries

      • files.dat (PID: 2612)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 268)
    • Reads Environment values

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
    • Reads product name

      • KMSAuto++.exe (PID: 1428)
    • Checks supported languages

      • KMSAuto++.exe (PID: 1428)
      • signtool.exe (PID: 3012)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
      • wmpnscfg.exe (PID: 3884)
    • Create files in a temporary directory

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
      • signtool.exe (PID: 3012)
    • Reads the computer name

      • signtool.exe (PID: 3012)
      • OInstallLite.exe (PID: 3580)
      • wmpnscfg.exe (PID: 3884)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3884)
    • Reads the machine GUID from the registry

      • signtool.exe (PID: 3012)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe notepad.exe no specs kmsauto++.exe no specs kmsauto++.exe cmd.exe no specs signtool.exe oinstalllite.exe cmd.exe no specs cmd.exe no specs files.dat wmpnscfg.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\KMSAuto++ Portable v1.5.5 Final.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1172"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\kmsauto++.exe
c:\windows\system32\ntdll.dll
1428"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\kmsauto++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1588"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa268.40018\KMSAuto++.iniC:\Windows\System32\notepad.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2508"C:\Windows\System32\cmd.exe" /c copy C:\Windows\system32\Tasks\KMSAuto "C:\Users\admin\AppData\Local\Temp\KMSAuto.tmp" /YC:\Windows\System32\cmd.exeKMSAuto++.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2612files.dat -y -pkmsautoC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\files.dat
cmd.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7z Console SFX
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\files\files.dat
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3012"C:\Users\admin\AppData\Local\Temp\signtool.exe" verify /v /ph /sha1 648384a4dee53d4c1c87e10d67cc99307ccc9c98 "C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe"C:\Users\admin\AppData\Local\Temp\signtool.exe
KMSAuto++.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Authenticode(R) - signing and verifying tool
Exit code:
1
Version:
4.00 (rs1_release_sec.170105-1850)
Modules
Images
c:\users\admin\appdata\local\temp\signtool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\user32.dll
3356"C:\Windows\System32\cmd.exe" /D /c copy C:\Windows\system32\Tasks\OInstall "C:\Windows\Temp\OInstall.tmp" /YC:\Windows\System32\cmd.exeOInstallLite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3548"C:\Windows\System32\cmd.exe" /D /c files.dat -y -pkmsautoC:\Windows\System32\cmd.exeOInstallLite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3580"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\OInstallLite.exe" /x=100 /y=100C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\OInstallLite.exe
KMSAuto++.exe
User:
admin
Integrity Level:
HIGH
Description:
Office 2013-2016 C2R Install Lite
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\oinstalllite.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
5 541
Read events
5 494
Write events
47
Delete events
0

Modification events

(PID) Process:(268) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
9
Suspicious files
4
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa268.40018\KMSAuto++.initext
MD5:F9EA4571821D978CA8A13384E49BAD1A
SHA256:FD1015A97100A23AF9BDF682604187CFFE974042F45EEAF65EBD56F258992076
1428KMSAuto++.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\Configure.xmltext
MD5:30011456806B22FDB46EA8E7D51CC3AE
SHA256:5C3545990D871C693994B1AA234BF63BF32D122DAE40D6A5F3179D3D8929F1B6
3012signtool.exeC:\Users\admin\AppData\Local\Temp\TarAF02.tmpbinary
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
3012signtool.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:472A2BF14D1AC725A7DB9C66ECE0C700
SHA256:9ABB7D2CEFD14FC8A1A0F2A7DAF6E5C9823B2B0B517565B98022A6CD9E27CDA0
3580OInstallLite.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\files.datexecutable
MD5:55D21B2C272A5D6B9F54FA9ED82BF9EB
SHA256:7A1C82E264258470D14CA345EA1A9B6FC34FA19B393A92077A01BE5F1AD08F47
2612files.datC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\x64\msvcr100.dllexecutable
MD5:DF3CA8D16BDED6A54977B30E66864D33
SHA256:1D1A1AE540BA132F998D60D3622F0297B6E86AE399332C3B47462D7C0F560A36
2612files.datC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\x64\cleanospp.exeexecutable
MD5:162AB955CB2F002A73C1530AA796477F
SHA256:5CE462E5F34065FC878362BA58617FAB28C22D631B9D836DDDCF43FB1AD4DE6E
3012signtool.exeC:\Users\admin\AppData\Local\Temp\CabAF01.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2612files.datC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\x86\msvcr100.dllexecutable
MD5:BF38660A9125935658CFA3E53FDC7D65
SHA256:60C06E0FA4449314DA3A0A87C1A9D9577DF99226F943637E06F61188E5862EFA
3580OInstallLite.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\Configure.xmltext
MD5:BD8FAE29B9C4AA8049C737A24EA872B2
SHA256:050A2E973202BD20563490352C8D5E7A790B8ECDE53B921A04030FAF5022A082
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3012
signtool.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c450e6b2e12ab1c2
GB
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3012
signtool.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted

Threats

No threats detected
No debug info