| File name: | KMSpico.zip |
| Full analysis: | https://app.any.run/tasks/cdfce9b2-9553-465c-83bd-a8a6ef7838cd |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | August 06, 2019, 08:18:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 07EFA4B79227B94E0AC1973FA06AF428 |
| SHA1: | B84CCBAF1F4F241050AC65D3B462C87392F2E770 |
| SHA256: | 4EB64A35E00552CC9CC94F5742157F3CC7F70B775D6DE8A5FB8CA1ECCFF46F54 |
| SSDEEP: | 98304:m88nbcnEGPqbWEd2BjuXrbkfxKpLPglyqXvvCgqksuorz:SbcHPA+juPk5qgvvZqk2rz |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2018:12:28 00:08:16 |
| ZipCRC: | 0x4cec0751 |
| ZipCompressedSize: | 14 |
| ZipUncompressedSize: | 12 |
| ZipFileName: | PASSWORD.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 692 | "C:\Users\admin\AppData\Roaming\KMSpico-setup.exe" /SPAWNWND=$D0096 /NOTIFYWND=$C01DE | C:\Users\admin\AppData\Roaming\KMSpico-setup.exe | KMSpico-setup.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: KMSpico Setup Exit code: 0 Version: 10.2.0 Modules
| |||||||||||||||
| 804 | "C:\Windows\system32\cmd.exe" /C ""C:\Program Files\KMSpico\scripts\Install_Task.cmd"" | C:\Windows\system32\cmd.exe | — | KMSpico-setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 916 | sc create "Service KMSELDI" binPath= "C:\Program Files\KMSpico\Service_KMS.exe" type= own error= normal start= auto DisplayName= "Service KMSELDI" | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1672 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\KMSpico.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 1896 | "C:\Program Files\KMSpico\KMSELDI.exe" /silent /backup | C:\Program Files\KMSpico\KMSELDI.exe | KMSpico-setup.tmp | ||||||||||||
User: admin Company: @ByELDI Integrity Level: HIGH Description: KMS GUI ELDI Exit code: 4294967295 Version: 37.1.0.0 Modules
| |||||||||||||||
| 1952 | "C:\Users\admin\AppData\Roaming\KMSpico-setup.exe" | C:\Users\admin\AppData\Roaming\KMSpico-setup.exe | Setup.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: KMSpico Setup Exit code: 0 Version: 10.2.0 Modules
| |||||||||||||||
| 2056 | "C:\Users\admin\AppData\Roaming\terra.exe" | C:\Users\admin\AppData\Roaming\terra.exe | Setup.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2256 | "C:\Users\admin\AppData\Local\Temp\is-0R6H2.tmp\KMSpico-setup.tmp" /SL5="$C01DE,2952592,69120,C:\Users\admin\AppData\Roaming\KMSpico-setup.exe" | C:\Users\admin\AppData\Local\Temp\is-0R6H2.tmp\KMSpico-setup.tmp | — | KMSpico-setup.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2352 | "C:\Users\admin\AppData\Local\Temp\is-OR8N9.tmp\KMSpico-setup.tmp" /SL5="$11016A,2952592,69120,C:\Users\admin\AppData\Roaming\KMSpico-setup.exe" /SPAWNWND=$D0096 /NOTIFYWND=$C01DE | C:\Users\admin\AppData\Local\Temp\is-OR8N9.tmp\KMSpico-setup.tmp | KMSpico-setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2548 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1672.1688\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1672.1688\Setup.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (1672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1672) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\KMSpico.zip | |||
| (PID) Process: | (1672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2056 | terra.exe | C:\ProgramData\2X21369Q58H55UYNRNOVX7RIB\files\outlook.txt | — | |
MD5:— | SHA256:— | |||
| 2056 | terra.exe | C:\ProgramData\2X21369Q58H55UYNRNOVX7RIB\files\information.txt | — | |
MD5:— | SHA256:— | |||
| 2352 | KMSpico-setup.tmp | C:\Program Files\KMSpico\is-P5DK4.tmp | — | |
MD5:— | SHA256:— | |||
| 2352 | KMSpico-setup.tmp | C:\Program Files\KMSpico\is-2ARSQ.tmp | — | |
MD5:— | SHA256:— | |||
| 2352 | KMSpico-setup.tmp | C:\Program Files\KMSpico\is-N5EHG.tmp | — | |
MD5:— | SHA256:— | |||
| 2352 | KMSpico-setup.tmp | C:\Program Files\KMSpico\is-AOC77.tmp | — | |
MD5:— | SHA256:— | |||
| 2352 | KMSpico-setup.tmp | C:\Windows\system32\is-OJAR2.tmp | — | |
MD5:— | SHA256:— | |||
| 2352 | KMSpico-setup.tmp | C:\Program Files\KMSpico\is-UMV2H.tmp | — | |
MD5:— | SHA256:— | |||
| 2352 | KMSpico-setup.tmp | C:\Program Files\KMSpico\is-55JT1.tmp | — | |
MD5:— | SHA256:— | |||
| 2352 | KMSpico-setup.tmp | C:\Program Files\KMSpico\is-5QIBP.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2056 | terra.exe | POST | 200 | 185.194.141.58:80 | http://ip-api.com/line/ | DE | text | 144 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1896 | KMSELDI.exe | 37.120.184.82:123 | 0.pool.ntp.org | netcup GmbH | DE | suspicious |
2876 | AutoPico.exe | 146.0.32.144:123 | 0.pool.ntp.org | myLoc managed IT AG | DE | suspicious |
2056 | terra.exe | 185.194.141.58:80 | ip-api.com | netcup GmbH | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
rapidbtcinvest.com |
| malicious |
ip-api.com |
| malicious |
0.pool.ntp.org |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2056 | terra.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup ip-api.com |
2056 | terra.exe | A Network Trojan was detected | SUSPICIOUS [PTsecurity] Possible Generic.Trojan Boundary |
2056 | terra.exe | A Network Trojan was detected | MALWARE [PTsecurity] Arkei/Vidar Stealer |