File name:

KMSAuto Net 2016 1.4.9 Portable + 1.5.1.zip

Full analysis: https://app.any.run/tasks/92d0e78e-e761-4663-8a8f-b5900ee2483c
Verdict: Malicious activity
Analysis date: January 16, 2024, 17:54:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

146C2759347E0D52625CCB4076E97EBB

SHA1:

37A5E26C83CDD143C9265AB454196A4AFC6FF79E

SHA256:

322E6E04DB88AADBA5EF0C92CA471F2A11046C1884DDE3D3FA05C35F3418EF36

SSDEEP:

196608:dhAfd4e3KegPHGl9sDgXWEtydP0QLFjReeoSuANd+BOJMuMmeu2iOQhNO+Qu7Yy5:dhe2lnmoEXWEw+8FFeeKduuu2hztu7YM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • bin.dat (PID: 2904)
      • AESDecoder.exe (PID: 2496)
      • bin_x86.dat (PID: 2836)
      • KMSAuto Net.exe (PID: 2296)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • KMSAuto Net.exe (PID: 2296)
      • cmd.exe (PID: 3000)
    • Reads Internet Explorer settings

      • KMSAuto Net.exe (PID: 2296)
    • Executable content was dropped or overwritten

      • KMSAuto Net.exe (PID: 2296)
      • bin.dat (PID: 2904)
      • bin_x86.dat (PID: 2836)
      • AESDecoder.exe (PID: 2496)
    • Drops 7-zip archiver for unpacking

      • KMSAuto Net.exe (PID: 2296)
    • Starts application with an unusual extension

      • cmd.exe (PID: 2672)
      • cmd.exe (PID: 3064)
    • Drops a system driver (possible attempt to evade defenses)

      • bin_x86.dat (PID: 2836)
    • Process drops legitimate windows executable

      • bin_x86.dat (PID: 2836)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • KMSAuto Net.exe (PID: 2296)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • KMSAuto Net.exe (PID: 2296)
    • Starts SC.EXE for service management

      • KMSAuto Net.exe (PID: 2296)
    • Creates or modifies Windows services

      • KMSAuto Net.exe (PID: 2296)
    • Executes as Windows Service

      • KMSSS.exe (PID: 604)
    • Application launched itself

      • cmd.exe (PID: 3000)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2184)
    • Manual execution by a user

      • KMSAuto Net 1.5.1.exe (PID: 1236)
      • KMSAuto Net 1.5.1.exe (PID: 2020)
      • KMSAuto Net.exe (PID: 1816)
      • KMSAuto Net.exe (PID: 2296)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2184)
    • Checks supported languages

      • KMSAuto Net 1.5.1.exe (PID: 1236)
      • KMSAuto Net.exe (PID: 2296)
      • bin.dat (PID: 2904)
      • AESDecoder.exe (PID: 2496)
      • bin_x86.dat (PID: 2836)
      • KMSSS.exe (PID: 604)
    • Reads the computer name

      • KMSAuto Net 1.5.1.exe (PID: 1236)
      • KMSAuto Net.exe (PID: 2296)
      • KMSSS.exe (PID: 604)
    • Reads the machine GUID from the registry

      • KMSAuto Net 1.5.1.exe (PID: 1236)
      • KMSAuto Net.exe (PID: 2296)
      • KMSSS.exe (PID: 604)
    • Creates files or folders in the user directory

      • KMSAuto Net.exe (PID: 2296)
    • Reads Environment values

      • KMSAuto Net.exe (PID: 2296)
    • Reads product name

      • KMSAuto Net.exe (PID: 2296)
    • Creates files in the program directory

      • cmd.exe (PID: 2688)
      • KMSAuto Net.exe (PID: 2296)
      • bin.dat (PID: 2904)
      • AESDecoder.exe (PID: 2496)
      • bin_x86.dat (PID: 2836)
      • KMSSS.exe (PID: 604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2017:10:11 22:05:14
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: KMSAuto Net 2016 1.4.9 Portable + 1.5.1/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
84
Monitored processes
27
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe kmsauto net 1.5.1.exe no specs kmsauto net 1.5.1.exe kmsauto net.exe no specs kmsauto net.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs bin.dat cmd.exe no specs cmd.exe no specs aesdecoder.exe cmd.exe no specs cmd.exe no specs bin_x86.dat cmd.exe no specs cmd.exe no specs cmd.exe no specs netstat.exe no specs find.exe no specs netsh.exe no specs netsh.exe no specs sc.exe no specs sc.exe no specs kmsss.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
604"C:\ProgramData\KMSAuto\bin\KMSSS.exe" -Port 1688 -PWin RandomKMSPID -PO14 RandomKMSPID -PO15 RandomKMSPID -PO16 RandomKMSPID -AI 43200 -RI 43200 -Log -IPC:\ProgramData\KMSAuto\bin\KMSSS.exeservices.exe
User:
SYSTEM
Company:
MSFree Inc.
Integrity Level:
SYSTEM
Description:
KMS emulator by Ratiborus, thanks to Hotbird64.
Exit code:
0
Version:
2.0.3.0
Modules
Images
c:\programdata\kmsauto\bin\kmsss.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1236"C:\Users\admin\Desktop\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\KMSAuto Net 1.5.1.exe" C:\Users\admin\Desktop\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\KMSAuto Net 1.5.1.exe
explorer.exe
User:
admin
Company:
MSFree Inc.
Integrity Level:
HIGH
Description:
KMSAuto Net
Exit code:
0
Version:
1.5.1
Modules
Images
c:\users\admin\desktop\kmsauto net 2016 1.4.9 portable + 1.5.1\kmsauto net 1.5.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1816"C:\Users\admin\Desktop\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\KMSAuto Net.exe" C:\Users\admin\Desktop\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\KMSAuto Net.exeexplorer.exe
User:
admin
Company:
MSFree Inc.
Integrity Level:
MEDIUM
Description:
KMSAuto Net
Exit code:
3221226540
Version:
1.4.9
Modules
Images
c:\users\admin\desktop\kmsauto net 2016 1.4.9 portable + 1.5.1\kmsauto net.exe
c:\windows\system32\ntdll.dll
2020"C:\Users\admin\Desktop\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\KMSAuto Net 1.5.1.exe" C:\Users\admin\Desktop\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\KMSAuto Net 1.5.1.exeexplorer.exe
User:
admin
Company:
MSFree Inc.
Integrity Level:
MEDIUM
Description:
KMSAuto Net
Exit code:
3221226540
Version:
1.5.1
Modules
Images
c:\users\admin\desktop\kmsauto net 2016 1.4.9 portable + 1.5.1\kmsauto net 1.5.1.exe
c:\windows\system32\ntdll.dll
2096cmd /c md "C:\Users\admin\AppData\Local\MSfree Inc"C:\Windows\System32\cmd.exeKMSAuto Net.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2184"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\KMSAuto Net 2016 1.4.9 Portable + 1.5.1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2296"C:\Users\admin\Desktop\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\KMSAuto Net.exe" C:\Users\admin\Desktop\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\KMSAuto Net.exe
explorer.exe
User:
admin
Company:
MSFree Inc.
Integrity Level:
HIGH
Description:
KMSAuto Net
Exit code:
0
Version:
1.4.9
Modules
Images
c:\users\admin\desktop\kmsauto net 2016 1.4.9 portable + 1.5.1\kmsauto net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2376C:\Windows\System32\cmd.exe /D /c del /F /Q "AESDecoder.exe"C:\Windows\System32\cmd.exeKMSAuto Net.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2424cmd /c echo test>>"C:\Users\admin\Desktop\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\test.test"C:\Windows\System32\cmd.exeKMSAuto Net.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2476C:\Windows\System32\cmd.exe /D /c del /F /Q "bin.dat"C:\Windows\System32\cmd.exeKMSAuto Net.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
2 757
Read events
2 644
Write events
113
Delete events
0

Modification events

(PID) Process:(2184) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
18
Suspicious files
10
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.17003\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\readme\readme_en.txttext
MD5:2A710AB80A87F13F5AED664D04E5C6A6
SHA256:F9F41A1ADF235066F7B1C477CAE36A7AE9C344E7DEF7059A9148E74669809924
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.17003\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\readme\readme_es.txttext
MD5:A99B01CEFE99E1DBCE3285F625320A43
SHA256:8B422282263EFC65C9F688F78632D8F931AC27E58FAFCBA49A7A9F1DCE012D1D
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.17003\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\KMSAuto Net.exeexecutable
MD5:2FB86BE791B4BB4389E55DF0FEC04EB7
SHA256:B8AEC57F7E9C193FCD9796CF22997605624B8B5F9BF5F0C6190E1090D426EE31
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.17003\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\readme\readme_fr.txttext
MD5:474FB9BCC634EA9BC1F2B77382A0D03B
SHA256:D0B8BBE89016B3E05FF1C376C9A3CCE7CA2E4070BFFC11BFD9A91808B6DC060C
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.17003\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\readme\readme_kms.txttext
MD5:352709B6AED3902D4399F6615A7A7E70
SHA256:D3BEF0FEF19603B33B86E1CA431A25CB8A6DF047058E073BBF8BB931533217AA
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.17003\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\readme\readme_vi.txttext
MD5:A97E744273BB537DE38CDCBD6650DD93
SHA256:C7C77FDBE3FB105DCED5F1B77B37748BE411361E39204C28C9D878C5467FB86D
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.17003\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\readme\readme_ua.txttext
MD5:D2DBDCDD45DB12313A758F70F3214CFB
SHA256:4E6E727F2608ABB0BDCE88395952F32088C94CBBFD46AC3FE332705CA02F484A
2296KMSAuto Net.exeC:\ProgramData\KMSAuto\bin.datexecutable
MD5:2A96E417738225FA806A6EF275443BC8
SHA256:839D31305D8FA842C832E8EC0F61D6BC575734449EB774B7C8DD79669594E25B
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.17003\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\readme\readme_bg.txttext
MD5:D6761E218D57B85236345F74EA44A684
SHA256:E03107D2DEC7EB59033B4D0CACF9DD320C3BE1D9389295F87F069E667F138201
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2184.17003\KMSAuto Net 2016 1.4.9 Portable + 1.5.1\readme\readme_cn.txttext
MD5:67FA7B665E63269A86043ABA1C462EFA
SHA256:752D7FF42C648AFAC4D40A418512DB6E49896FA24BB1949442DDF50FF64B01AA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info