| File name: | KMSAuto++ Portable v1.5.5 Final.rar |
| Full analysis: | https://app.any.run/tasks/50069991-b4b7-418a-bf88-b8057fb9b14e |
| Verdict: | Malicious activity |
| Analysis date: | February 07, 2024, 08:59:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 463F3F13A9978AAA467F6D325ED5EAC9 |
| SHA1: | D95D1889B08E0121A36650C4D12A99DBBA3603B5 |
| SHA256: | 2A0BB36706ED995380E83EBBBA1C5A7CEBE6E1686C8A1EC7ACE8442FBD8E9AAE |
| SSDEEP: | 98304:L8Vugmr5T2dZ7d12yX99n3X+XWHUbvg8UG2mBjjqRhVy321alvKfz1GqU+GxLHoE:LQSvtssA17HR2mh/ShMBi0RKMcfQCG+ |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 268 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\KMSAuto++ Portable v1.5.5 Final.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1172 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1428 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1588 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa268.40018\KMSAuto++.ini | C:\Windows\System32\notepad.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2508 | "C:\Windows\System32\cmd.exe" /c copy C:\Windows\system32\Tasks\KMSAuto "C:\Users\admin\AppData\Local\Temp\KMSAuto.tmp" /Y | C:\Windows\System32\cmd.exe | — | KMSAuto++.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2612 | files.dat -y -pkmsauto | C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\files.dat | cmd.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7z Console SFX Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
| 3012 | "C:\Users\admin\AppData\Local\Temp\signtool.exe" verify /v /ph /sha1 648384a4dee53d4c1c87e10d67cc99307ccc9c98 "C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe" | C:\Users\admin\AppData\Local\Temp\signtool.exe | KMSAuto++.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Authenticode(R) - signing and verifying tool Exit code: 1 Version: 4.00 (rs1_release_sec.170105-1850) Modules
| |||||||||||||||
| 3356 | "C:\Windows\System32\cmd.exe" /D /c copy C:\Windows\system32\Tasks\OInstall "C:\Windows\Temp\OInstall.tmp" /Y | C:\Windows\System32\cmd.exe | — | OInstallLite.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3548 | "C:\Windows\System32\cmd.exe" /D /c files.dat -y -pkmsauto | C:\Windows\System32\cmd.exe | — | OInstallLite.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3580 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\OInstallLite.exe" /x=100 /y=100 | C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\OInstallLite.exe | KMSAuto++.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Office 2013-2016 C2R Install Lite Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3012 | signtool.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.exe | executable | |
MD5:69FBF6849D935432BAC8B04BDB00FD68 | SHA256:D5DC790F6F220CF7E42C6C1C9F5BC6E4443CB52D07BCDEF24A6BF457153C1D86 | |||
| 268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\KMSAuto++.ini | text | |
MD5:F9EA4571821D978CA8A13384E49BAD1A | SHA256:FD1015A97100A23AF9BDF682604187CFFE974042F45EEAF65EBD56F258992076 | |||
| 3012 | signtool.exe | C:\Users\admin\AppData\Local\Temp\CabAF01.tmp | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa268.40018\KMSAuto++.ini | text | |
MD5:F9EA4571821D978CA8A13384E49BAD1A | SHA256:FD1015A97100A23AF9BDF682604187CFFE974042F45EEAF65EBD56F258992076 | |||
| 3012 | signtool.exe | C:\Users\admin\AppData\Local\Temp\TarAF02.tmp | binary | |
MD5:9C0C641C06238516F27941AA1166D427 | SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F | |||
| 3580 | OInstallLite.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\files.dat | executable | |
MD5:55D21B2C272A5D6B9F54FA9ED82BF9EB | SHA256:7A1C82E264258470D14CA345EA1A9B6FC34FA19B393A92077A01BE5F1AD08F47 | |||
| 1428 | KMSAuto++.exe | C:\Users\admin\AppData\Local\Temp\signtool.exe | executable | |
MD5:05624E6D27EAEF0DB0673AE627BD6027 | SHA256:962A92821F54A1E706AA989973130FDC1072C7BD8B9E6D11EA1050B46EB9D313 | |||
| 2612 | files.dat | C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\x86\msvcr100.dll | executable | |
MD5:BF38660A9125935658CFA3E53FDC7D65 | SHA256:60C06E0FA4449314DA3A0A87C1A9D9577DF99226F943637E06F61188E5862EFA | |||
| 2612 | files.dat | C:\Users\admin\AppData\Local\Temp\Rar$EXa268.41267\KMSAuto++ Portable v1.5.5 Final\files\Uninstall.xml | text | |
MD5:364F86F97324EA82FE0D142CD01CF6DD | SHA256:09D5B42140BAB13165BA97FBD0E77792304C3C93555BE02C3DCE21A7A69C66DD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3012 | signtool.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c450e6b2e12ab1c2 | unknown | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3012 | signtool.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
ctldl.windowsupdate.com |
| whitelisted |