File name:

KMSAuto++ Portable v1.5.5 Final.rar

Full analysis: https://app.any.run/tasks/50069991-b4b7-418a-bf88-b8057fb9b14e
Verdict: Malicious activity
Analysis date: February 07, 2024, 08:59:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

463F3F13A9978AAA467F6D325ED5EAC9

SHA1:

D95D1889B08E0121A36650C4D12A99DBBA3603B5

SHA256:

2A0BB36706ED995380E83EBBBA1C5A7CEBE6E1686C8A1EC7ACE8442FBD8E9AAE

SSDEEP:

98304:L8Vugmr5T2dZ7d12yX99n3X+XWHUbvg8UG2mBjjqRhVy321alvKfz1GqU+GxLHoE:LQSvtssA17HR2mh/ShMBi0RKMcfQCG+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 268)
      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
  • SUSPICIOUS

    • Start notepad (likely ransomware note)

      • WinRAR.exe (PID: 268)
    • Starts CMD.EXE for commands execution

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
    • Checks Windows Trust Settings

      • signtool.exe (PID: 3012)
    • Process drops legitimate windows executable

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
    • Starts a Microsoft application from unusual location

      • signtool.exe (PID: 3012)
    • Executable content was dropped or overwritten

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
    • Reads security settings of Internet Explorer

      • signtool.exe (PID: 3012)
    • Reads settings of System Certificates

      • signtool.exe (PID: 3012)
    • Reads the Internet Settings

      • signtool.exe (PID: 3012)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3548)
    • Drops 7-zip archiver for unpacking

      • OInstallLite.exe (PID: 3580)
    • Adds/modifies Windows certificates

      • signtool.exe (PID: 3012)
    • The executable file from the user directory is run by the CMD process

      • files.dat (PID: 2612)
    • The process drops C-runtime libraries

      • files.dat (PID: 2612)
  • INFO

    • Reads Environment values

      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
    • Checks supported languages

      • KMSAuto++.exe (PID: 1428)
      • signtool.exe (PID: 3012)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
      • wmpnscfg.exe (PID: 3884)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 268)
    • Reads product name

      • KMSAuto++.exe (PID: 1428)
    • Create files in a temporary directory

      • signtool.exe (PID: 3012)
      • KMSAuto++.exe (PID: 1428)
      • OInstallLite.exe (PID: 3580)
      • files.dat (PID: 2612)
    • Reads the machine GUID from the registry

      • signtool.exe (PID: 3012)
    • Reads the computer name

      • signtool.exe (PID: 3012)
      • OInstallLite.exe (PID: 3580)
      • wmpnscfg.exe (PID: 3884)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3884)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe notepad.exe no specs kmsauto++.exe no specs kmsauto++.exe cmd.exe no specs signtool.exe oinstalllite.exe cmd.exe no specs cmd.exe no specs files.dat wmpnscfg.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\KMSAuto++ Portable v1.5.5 Final.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1172"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\kmsauto++.exe
c:\windows\system32\ntdll.dll
1428"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\kmsauto++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1588"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa268.40018\KMSAuto++.iniC:\Windows\System32\notepad.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2508"C:\Windows\System32\cmd.exe" /c copy C:\Windows\system32\Tasks\KMSAuto "C:\Users\admin\AppData\Local\Temp\KMSAuto.tmp" /YC:\Windows\System32\cmd.exeKMSAuto++.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2612files.dat -y -pkmsautoC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\files.dat
cmd.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7z Console SFX
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\files\files.dat
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3012"C:\Users\admin\AppData\Local\Temp\signtool.exe" verify /v /ph /sha1 648384a4dee53d4c1c87e10d67cc99307ccc9c98 "C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe"C:\Users\admin\AppData\Local\Temp\signtool.exe
KMSAuto++.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Authenticode(R) - signing and verifying tool
Exit code:
1
Version:
4.00 (rs1_release_sec.170105-1850)
Modules
Images
c:\users\admin\appdata\local\temp\signtool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\user32.dll
3356"C:\Windows\System32\cmd.exe" /D /c copy C:\Windows\system32\Tasks\OInstall "C:\Windows\Temp\OInstall.tmp" /YC:\Windows\System32\cmd.exeOInstallLite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3548"C:\Windows\System32\cmd.exe" /D /c files.dat -y -pkmsautoC:\Windows\System32\cmd.exeOInstallLite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3580"C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\OInstallLite.exe" /x=100 /y=100C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\OInstallLite.exe
KMSAuto++.exe
User:
admin
Integrity Level:
HIGH
Description:
Office 2013-2016 C2R Install Lite
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa268.41267\kmsauto++ portable v1.5.5 final\oinstalllite.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
5 541
Read events
5 494
Write events
47
Delete events
0

Modification events

(PID) Process:(268) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
9
Suspicious files
4
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3012signtool.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exeexecutable
MD5:69FBF6849D935432BAC8B04BDB00FD68
SHA256:D5DC790F6F220CF7E42C6C1C9F5BC6E4443CB52D07BCDEF24A6BF457153C1D86
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.initext
MD5:F9EA4571821D978CA8A13384E49BAD1A
SHA256:FD1015A97100A23AF9BDF682604187CFFE974042F45EEAF65EBD56F258992076
3012signtool.exeC:\Users\admin\AppData\Local\Temp\CabAF01.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa268.40018\KMSAuto++.initext
MD5:F9EA4571821D978CA8A13384E49BAD1A
SHA256:FD1015A97100A23AF9BDF682604187CFFE974042F45EEAF65EBD56F258992076
3012signtool.exeC:\Users\admin\AppData\Local\Temp\TarAF02.tmpbinary
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
3580OInstallLite.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\files.datexecutable
MD5:55D21B2C272A5D6B9F54FA9ED82BF9EB
SHA256:7A1C82E264258470D14CA345EA1A9B6FC34FA19B393A92077A01BE5F1AD08F47
1428KMSAuto++.exeC:\Users\admin\AppData\Local\Temp\signtool.exeexecutable
MD5:05624E6D27EAEF0DB0673AE627BD6027
SHA256:962A92821F54A1E706AA989973130FDC1072C7BD8B9E6D11EA1050B46EB9D313
2612files.datC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\x86\msvcr100.dllexecutable
MD5:BF38660A9125935658CFA3E53FDC7D65
SHA256:60C06E0FA4449314DA3A0A87C1A9D9577DF99226F943637E06F61188E5862EFA
2612files.datC:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\Uninstall.xmltext
MD5:364F86F97324EA82FE0D142CD01CF6DD
SHA256:09D5B42140BAB13165BA97FBD0E77792304C3C93555BE02C3DCE21A7A69C66DD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3012
signtool.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c450e6b2e12ab1c2
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3012
signtool.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted

Threats

No threats detected
No debug info