File name:

Setup_File_KMS_Pico.exe

Full analysis: https://app.any.run/tasks/5ac7d914-6c6e-408a-995c-2692a249e97e
Verdict: Malicious activity
Analysis date: October 20, 2025, 14:06:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

93FC69C5E6A8BAA0798A9B70F5CE30BE

SHA1:

673F9E6C4F46429CDC4A16FAA400772235404304

SHA256:

6CB6B00E5101C7244688B8A20F56C186DA8BE8019E9130E8EE63D67BAB0E9FA2

SSDEEP:

98304:2FrKddSaEVSXYEi+RvlbDIquD+T8uhY1ld3fFHrpWtSly05//t/GSCTb413sKjS6:21aYydce9CF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Setup_File_KMS_Pico.exe (PID: 7860)
      • KMSpico.exe (PID: 2192)
      • KMSpico.exe (PID: 2460)
    • GENERIC has been found (auto)

      • KMSpico.exe (PID: 7240)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 3036)
    • Starts CMD.EXE for self-deleting

      • KMSpico.exe (PID: 7240)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Setup_File_KMS_Pico.exe (PID: 7860)
      • KMSpico.tmp (PID: 8044)
      • KMSpico.exe (PID: 7240)
    • There is functionality for taking screenshot (YARA)

      • Setup_File_KMS_Pico.exe (PID: 7860)
    • Executable content was dropped or overwritten

      • KMSpico.exe (PID: 7240)
      • KMSpico.exe (PID: 2460)
      • KMSpico.tmp (PID: 2332)
      • KMSpico.exe (PID: 2192)
    • Reads the date of Windows installation

      • KMSpico.exe (PID: 7240)
    • Starts CMD.EXE for commands execution

      • KMSpico.exe (PID: 7240)
    • Searches for installed software

      • KMSpico.exe (PID: 7240)
    • Reads the Windows owner or organization settings

      • KMSpico.tmp (PID: 2332)
    • The process executes via Task Scheduler

      • Todumev.exe (PID: 8100)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 8132)
    • Process drops legitimate windows executable

      • KMSpico.tmp (PID: 2332)
  • INFO

    • Checks supported languages

      • Setup_File_KMS_Pico.exe (PID: 7860)
      • KMSpico.exe (PID: 2192)
      • KMSpico.exe (PID: 2460)
      • KMSpico.tmp (PID: 2332)
      • KMSpico.tmp (PID: 8044)
      • Todumev.exe (PID: 8100)
      • KMSpico.exe (PID: 7240)
    • Reads the computer name

      • Setup_File_KMS_Pico.exe (PID: 7860)
      • KMSpico.exe (PID: 7240)
      • KMSpico.tmp (PID: 8044)
      • KMSpico.tmp (PID: 2332)
    • The sample compiled with english language support

      • Setup_File_KMS_Pico.exe (PID: 7860)
      • KMSpico.exe (PID: 7240)
      • KMSpico.tmp (PID: 2332)
    • Create files in a temporary directory

      • Setup_File_KMS_Pico.exe (PID: 7860)
      • KMSpico.exe (PID: 2192)
      • KMSpico.exe (PID: 7240)
      • KMSpico.exe (PID: 2460)
      • KMSpico.tmp (PID: 2332)
    • Reads Windows Product ID

      • KMSpico.exe (PID: 7240)
    • Creates files or folders in the user directory

      • KMSpico.exe (PID: 7240)
    • Process checks computer location settings

      • Setup_File_KMS_Pico.exe (PID: 7860)
      • KMSpico.tmp (PID: 8044)
      • KMSpico.exe (PID: 7240)
    • Reads CPU info

      • KMSpico.exe (PID: 7240)
    • Checks proxy server information

      • KMSpico.exe (PID: 7240)
    • Reads mouse settings

      • Todumev.exe (PID: 8100)
    • Reads the machine GUID from the registry

      • KMSpico.exe (PID: 7240)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:12:01 18:00:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 201216
InitializedDataSize: 337408
UninitializedDataSize: -
EntryPoint: 0x1ec40
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.1.55.0
ProductVersionNumber: 2.1.55.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: AVG Technologies CZ, s.r.o.
Edition: 15
FileDescription: AVG Installer
FileVersion: 2.1.55.0
InternalName: microstub
LegalCopyright: Copyright (C) 2021 AVG Technologies CZ, s.r.o.
OriginalFileName: microstub.exe
ProductName: AVG
ProductVersion: 2.1.55.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
158
Monitored processes
17
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2192C:\Users\admin\AppData\Roaming\ServiceTod\KMSpico.exeC:\Users\admin\AppData\Roaming\ServiceTod\KMSpico.exe
cmd.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
KMSpico Setup
Version:
10.2.0
Modules
Images
c:\users\admin\appdata\roaming\servicetod\kmspico.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2276C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2332"C:\Users\admin\AppData\Local\Temp\is-4VD85.tmp\KMSpico.tmp" /SL5="$100330,2952592,69120,C:\Users\admin\AppData\Roaming\ServiceTod\KMSpico.exe" /SPAWNWND=$E01E8 /NOTIFYWND=$60338 C:\Users\admin\AppData\Local\Temp\is-4VD85.tmp\KMSpico.tmp
KMSpico.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-4vd85.tmp\kmspico.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2460"C:\Users\admin\AppData\Roaming\ServiceTod\KMSpico.exe" /SPAWNWND=$E01E8 /NOTIFYWND=$60338 C:\Users\admin\AppData\Roaming\ServiceTod\KMSpico.exe
KMSpico.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
KMSpico Setup
Version:
10.2.0
Modules
Images
c:\users\admin\appdata\roaming\servicetod\kmspico.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3036 /C schtasks /create /tn \Service\Diagnostic /tr """"C:\Users\admin\AppData\Roaming\ServiceTod\Todumev.exe""" """C:\Users\admin\AppData\Roaming\ServiceTod\Todumev.dat"""" /st 00:01 /du 9800:19 /sc once /ri 1 /fC:\Windows\SysWOW64\cmd.exeKMSpico.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5424\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5884C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7188\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7240"C:\Users\admin\AppData\Local\Temp\RarSFX0\KMSpico.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\KMSpico.exe
Setup_File_KMS_Pico.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\kmspico.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7284\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
2 097
Read events
2 097
Write events
0
Delete events
0

Modification events

No data
Executable files
6
Suspicious files
19
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7860Setup_File_KMS_Pico.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\KMSpico.exe
MD5:
SHA256:
2192KMSpico.exeC:\Users\admin\AppData\Local\Temp\is-NDECI.tmp\KMSpico.tmpexecutable
MD5:1778C1F66FF205875A6435A33229AB3C
SHA256:95C06ACAC4FE4598840E5556F9613D43AA1039C52DAC64536F59E45A70F79DA6
7240KMSpico.exeC:\Users\admin\AppData\Local\Temp\2917.tmpbinary
MD5:A45465CDCDC6CB30C8906F3DA4EC114C
SHA256:4412319EF944EBCCA9581CBACB1D4E1DC614C348D1DFC5D2FAAAAD863D300209
7240KMSpico.exeC:\Users\admin\AppData\Local\Temp\2958.tmpbinary
MD5:B0F370A1FF124FB09504B693FB9408CC
SHA256:4110FDF2F66EDB3F9C66599693B1F23AE55AABF96E8C15B51E92A90BA2C5185F
2460KMSpico.exeC:\Users\admin\AppData\Local\Temp\is-4VD85.tmp\KMSpico.tmpexecutable
MD5:1778C1F66FF205875A6435A33229AB3C
SHA256:95C06ACAC4FE4598840E5556F9613D43AA1039C52DAC64536F59E45A70F79DA6
7240KMSpico.exeC:\Users\admin\AppData\Roaming\ServiceTod\KMSpico.exeexecutable
MD5:A02164371A50C5FF9FA2870EF6E8CFA3
SHA256:64C731ADBE1B96CB5765203B1E215093DCF268D020B299445884A4AE62ED2D3A
7240KMSpico.exeC:\Users\admin\AppData\Roaming\ServiceTod\Todumev.dattext
MD5:B76FD3FF64CD02382CC76CF8F3ED605D
SHA256:5896A46EA4C12AC04A44376143299CE24864A720E6A4923978FAEE2478E0C105
7240KMSpico.exeC:\Users\admin\AppData\Roaming\ServiceTod\Todumev.exeexecutable
MD5:C56B5F0201A3B3DE53E561FE76912BFD
SHA256:237D1BCA6E056DF5BB16A1216A434634109478F882D3B1D58344C801D184F95D
7240KMSpico.exeC:\Users\admin\AppData\Local\Temp\278F.tmpbinary
MD5:96505B66DD5F732A78EC146D32A6E424
SHA256:17780E7564F979024524AC9C3CEEFE7570E01EB37D07828B0BC4554BEACFADDC
7240KMSpico.exeC:\Users\admin\AppData\Local\Temp\28F7.tmpbinary
MD5:3EB66F8F3F058E157563F42DBF644355
SHA256:AD0A6073D226341F699F465BDD35F01E88F0E9D4BCCEC816D6DF06D34F848350
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
38
DNS requests
21
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
5308
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
whitelisted
7524
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1808
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6336
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5596
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.97.177:443
www.bing.com
Akamai International B.V.
AT
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
7500
backgroundTaskHost.exe
2.23.97.177:443
www.bing.com
Akamai International B.V.
AT
whitelisted
3440
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7524
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7524
backgroundTaskHost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.129
  • 20.190.159.128
  • 20.190.159.23
  • 40.126.31.129
  • 40.126.31.2
  • 20.190.159.73
  • 40.126.31.0
whitelisted
google.com
  • 142.250.185.142
whitelisted
www.bing.com
  • 2.23.97.177
  • 2.23.97.184
  • 2.23.97.192
  • 2.23.97.178
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 162.159.142.9
  • 172.66.2.5
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
arc.msn.com
  • 20.223.35.26
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 135.233.95.144
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2276
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
No debug info