File name:

HEU_KMS_Activator_v63.2.0.exe

Full analysis: https://app.any.run/tasks/63eeeec8-6071-4a4b-898b-ea14eb104f97
Verdict: Malicious activity
Analysis date: August 21, 2025, 02:45:50
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
kms
tool
qrcode
upx
autoit
anti-evasion
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

8F331BCBF428291F36EA59467A4E080B

SHA1:

5DB1793734E2A7577614BCE7E07067AA9CD08F65

SHA256:

85D199B41482B4D0C341F817ADE60EDF789CCEDDC2845F4B1938C597D5F54300

SSDEEP:

98304:i8Cgzkib1obp+hPWl1LoJFKZ5oJQFRHQcBnbPQqMFoSc+pbCxc8VQTQGkhmsCGal:SLt0QD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Opens a text file (SCRIPT)

      • cscript.exe (PID: 6808)
      • cscript.exe (PID: 5436)
      • cscript.exe (PID: 4944)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 4580)
      • cmd.exe (PID: 6288)
    • Changes image file execution options

      • kms_x64.exe (PID: 2528)
    • Starts NET.EXE for service management

      • cmd.exe (PID: 3768)
      • net.exe (PID: 4580)
      • net.exe (PID: 3640)
      • cmd.exe (PID: 6756)
      • net.exe (PID: 6240)
      • net.exe (PID: 2384)
      • cmd.exe (PID: 5236)
      • net.exe (PID: 6320)
      • net.exe (PID: 2880)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
    • There is functionality for taking screenshot (YARA)

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • kms_x64.exe (PID: 2528)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
    • Starts CMD.EXE for commands execution

      • kms_x64.exe (PID: 2528)
      • kms_x64.exe (PID: 3960)
    • Application launched itself

      • ClipUp.exe (PID: 3460)
      • ClipUp.exe (PID: 4748)
    • Uses WMI to retrieve WMI-managed resources (SCRIPT)

      • cscript.exe (PID: 5712)
      • cscript.exe (PID: 6452)
      • cscript.exe (PID: 6808)
      • cscript.exe (PID: 5436)
      • cscript.exe (PID: 1232)
      • cscript.exe (PID: 6212)
      • cscript.exe (PID: 4936)
      • cscript.exe (PID: 4944)
      • cscript.exe (PID: 7104)
      • cscript.exe (PID: 4448)
      • cscript.exe (PID: 2076)
      • cscript.exe (PID: 3688)
      • cscript.exe (PID: 5776)
    • Queries Computer System Information (Win32_ComputerSystem) (SCRIPT)

      • cscript.exe (PID: 5712)
      • cscript.exe (PID: 2076)
    • Executes WMI query (SCRIPT)

      • cscript.exe (PID: 5712)
      • cscript.exe (PID: 6452)
      • cscript.exe (PID: 6808)
      • cscript.exe (PID: 5436)
      • cscript.exe (PID: 1232)
      • cscript.exe (PID: 4936)
      • cscript.exe (PID: 6212)
      • cscript.exe (PID: 4944)
      • cscript.exe (PID: 4448)
      • cscript.exe (PID: 7104)
      • cscript.exe (PID: 2076)
      • cscript.exe (PID: 3688)
      • cscript.exe (PID: 5776)
    • Possibly malicious use of IEX has been detected

      • cmd.exe (PID: 7064)
    • Probably obfuscated PowerShell command line is found

      • cmd.exe (PID: 7064)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 7064)
      • cmd.exe (PID: 4196)
    • The process executes VB scripts

      • cmd.exe (PID: 5772)
      • cmd.exe (PID: 4024)
      • cmd.exe (PID: 5724)
      • cmd.exe (PID: 6912)
    • Gets full path of the running script (SCRIPT)

      • cscript.exe (PID: 6808)
      • cscript.exe (PID: 5436)
      • cscript.exe (PID: 4944)
      • cscript.exe (PID: 5776)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • cscript.exe (PID: 6808)
      • cscript.exe (PID: 5436)
      • cscript.exe (PID: 4944)
      • cscript.exe (PID: 5776)
    • Checks whether a specific file exists (SCRIPT)

      • cscript.exe (PID: 6808)
      • cscript.exe (PID: 5436)
      • cscript.exe (PID: 4944)
      • cscript.exe (PID: 5776)
    • Reads data from a binary Stream object (SCRIPT)

      • cscript.exe (PID: 6808)
      • cscript.exe (PID: 5436)
      • cscript.exe (PID: 4944)
    • The executable file from the user directory is run by the CMD process

      • TSforge.exe (PID: 6176)
      • TSforge.exe (PID: 7008)
      • TSforge.exe (PID: 3960)
      • TSforge.exe (PID: 4948)
      • TSforge.exe (PID: 1040)
      • TSforge.exe (PID: 6240)
      • TSforge.exe (PID: 6948)
      • kms-server.exe (PID: 6104)
    • Reads security settings of Internet Explorer

      • kms_x64.exe (PID: 2528)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 2188)
      • cmd.exe (PID: 504)
      • cmd.exe (PID: 4456)
      • cmd.exe (PID: 2220)
      • cmd.exe (PID: 5468)
    • Lists all scheduled tasks

      • schtasks.exe (PID: 4476)
    • Modifies existing scheduled task

      • schtasks.exe (PID: 5300)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 7140)
    • Starts application with an unusual extension

      • cmd.exe (PID: 5600)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 5600)
    • Lists all scheduled tasks in specific format

      • schtasks.exe (PID: 2188)
    • The process creates files with name similar to system file names

      • Dism.exe (PID: 2220)
      • Dism.exe (PID: 6856)
      • Dism.exe (PID: 6768)
    • Starts a Microsoft application from unusual location

      • DismHost.exe (PID: 6360)
      • DismHost.exe (PID: 4684)
      • DismHost.exe (PID: 1636)
    • Executing commands from a ".bat" file

      • kms_x64.exe (PID: 2528)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 6360)
  • INFO

    • KMS mutex has been found

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
    • The sample compiled with chinese language support

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • 7Z.EXE (PID: 5140)
      • kms_x64.exe (PID: 2528)
      • 7Z.EXE (PID: 6428)
    • Reads mouse settings

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • kms_x64.exe (PID: 2528)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
      • kms_x64.exe (PID: 3960)
    • Reads the computer name

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • 7Z.EXE (PID: 5140)
      • kms_x64.exe (PID: 2528)
      • 7Z.EXE (PID: 2404)
      • TSforge.exe (PID: 6176)
      • TSforge.exe (PID: 7008)
      • TSforge.exe (PID: 3960)
      • TSforge.exe (PID: 6240)
      • TSforge.exe (PID: 4948)
      • TSforge.exe (PID: 1040)
      • identity_helper.exe (PID: 1576)
      • TSforge.exe (PID: 6948)
      • identity_helper.exe (PID: 504)
      • identity_helper.exe (PID: 2140)
      • kms-server.exe (PID: 6104)
      • kms-server.exe (PID: 3148)
      • DismHost.exe (PID: 1636)
      • DismHost.exe (PID: 6360)
      • DismHost.exe (PID: 4684)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
      • 7Z.EXE (PID: 6428)
      • kms_x64.exe (PID: 3960)
    • Checks supported languages

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • 7Z.EXE (PID: 5140)
      • kms_x64.exe (PID: 2528)
      • 7Z.EXE (PID: 2404)
      • TSforge.exe (PID: 6176)
      • TSforge.exe (PID: 7008)
      • TSforge.exe (PID: 3960)
      • TSforge.exe (PID: 6240)
      • TSforge.exe (PID: 4948)
      • TSforge.exe (PID: 1040)
      • identity_helper.exe (PID: 1576)
      • TSforge.exe (PID: 6948)
      • identity_helper.exe (PID: 504)
      • identity_helper.exe (PID: 2140)
      • chcp.com (PID: 1324)
      • kms-server.exe (PID: 6104)
      • kms-server.exe (PID: 3148)
      • DismHost.exe (PID: 1636)
      • DismHost.exe (PID: 6360)
      • DismHost.exe (PID: 4684)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
      • 7Z.EXE (PID: 6428)
      • kms_x64.exe (PID: 3960)
    • Create files in a temporary directory

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • 7Z.EXE (PID: 5140)
      • kms_x64.exe (PID: 2528)
      • ClipUp.exe (PID: 828)
      • 7Z.EXE (PID: 2404)
      • Dism.exe (PID: 2220)
      • Dism.exe (PID: 6856)
      • Dism.exe (PID: 6768)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
      • 7Z.EXE (PID: 6428)
      • kms_x64.exe (PID: 3960)
      • ClipUp.exe (PID: 1096)
    • The sample compiled with english language support

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • Dism.exe (PID: 2220)
      • Dism.exe (PID: 6768)
      • Dism.exe (PID: 6856)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
    • Reads Environment values

      • kms_x64.exe (PID: 2528)
      • TSforge.exe (PID: 6176)
      • TSforge.exe (PID: 3960)
      • TSforge.exe (PID: 1040)
      • identity_helper.exe (PID: 1576)
      • identity_helper.exe (PID: 504)
      • identity_helper.exe (PID: 2140)
      • DismHost.exe (PID: 1636)
      • DismHost.exe (PID: 6360)
      • DismHost.exe (PID: 4684)
      • kms_x64.exe (PID: 3960)
    • UPX packer has been detected

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
    • Reads product name

      • kms_x64.exe (PID: 2528)
      • kms_x64.exe (PID: 3960)
    • The process uses AutoIt

      • HEU_KMS_Activator_v63.2.0.exe (PID: 4888)
      • kms_x64.exe (PID: 2528)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
    • Reads security settings of Internet Explorer

      • cscript.exe (PID: 5712)
      • cscript.exe (PID: 6452)
      • cscript.exe (PID: 6808)
      • cscript.exe (PID: 5436)
      • cscript.exe (PID: 4936)
      • cscript.exe (PID: 6212)
      • cscript.exe (PID: 1232)
      • cscript.exe (PID: 4944)
      • cscript.exe (PID: 7104)
      • cscript.exe (PID: 4448)
      • cscript.exe (PID: 3688)
      • cscript.exe (PID: 2076)
      • Taskmgr.exe (PID: 7008)
      • cscript.exe (PID: 5776)
    • Creates files in the program directory

      • kms_x64.exe (PID: 2528)
      • ClipUp.exe (PID: 828)
      • ClipUp.exe (PID: 1096)
      • kms_x64.exe (PID: 3960)
    • Reads the machine GUID from the registry

      • TSforge.exe (PID: 6176)
      • TSforge.exe (PID: 7008)
      • TSforge.exe (PID: 3960)
      • TSforge.exe (PID: 6240)
      • TSforge.exe (PID: 4948)
      • TSforge.exe (PID: 1040)
      • TSforge.exe (PID: 6948)
      • kms-server.exe (PID: 3148)
      • kms_x64.exe (PID: 3960)
    • Disables trace logs

      • TSforge.exe (PID: 6176)
      • TSforge.exe (PID: 3960)
      • TSforge.exe (PID: 1040)
    • Checks proxy server information

      • TSforge.exe (PID: 6176)
      • TSforge.exe (PID: 3960)
      • TSforge.exe (PID: 1040)
    • Reads the software policy settings

      • TSforge.exe (PID: 6176)
      • TSforge.exe (PID: 3960)
      • TSforge.exe (PID: 1040)
    • Manual execution by a user

      • msedge.exe (PID: 7044)
      • msedge.exe (PID: 7084)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 5132)
      • HEU_KMS_Activator_v63.2.0.exe (PID: 6244)
      • Taskmgr.exe (PID: 3652)
      • Taskmgr.exe (PID: 7008)
    • Reads Microsoft Office registry keys

      • kms_x64.exe (PID: 2528)
    • Application launched itself

      • msedge.exe (PID: 7044)
      • msedge.exe (PID: 1216)
      • msedge.exe (PID: 6200)
    • Changes the display of characters in the console

      • cmd.exe (PID: 5600)
    • Process checks computer location settings

      • kms_x64.exe (PID: 3960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (43.5)
.exe | Win32 EXE Yoda's Crypter (42.7)
.exe | Win32 Executable (generic) (7.2)
.exe | Generic Win/DOS Executable (3.2)
.exe | DOS Executable Generic (3.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:08:17 14:49:58+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 380928
InitializedDataSize: 4112384
UninitializedDataSize: 4665344
EntryPoint: 0x4d0d00
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 63.2.0.0
ProductVersionNumber: 63.2.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
FileVersion: 63.2.0.0
Comments: KMS/数字权利/KMS38/OEM激活
FileDescription: HEU KMS Activator™
ProductVersion: 63.2.0.0
LegalCopyright: 知彼而知己
Productname: HEU KMS Activator
CompanyName: 知彼而知己
OriginalFileName: HEU_KMS_Activator_v63.2.0
InternalName: HEU_KMS_Activator_v63.2.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
400
Monitored processes
230
Malicious processes
18
Suspicious processes
12

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
188"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2396,i,1534092698662435886,18333397761972534554,262144 --variations-seed-version --mojo-platform-channel-handle=2340 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
320"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2196,i,9038401685476498952,9576981917042080514,262144 --variations-seed-version --mojo-platform-channel-handle=2540 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
320\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
424"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4244,i,1534092698662435886,18333397761972534554,262144 --variations-seed-version --mojo-platform-channel-handle=3976 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
436"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=5100,i,9038401685476498952,9576981917042080514,262144 --variations-seed-version --mojo-platform-channel-handle=5092 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
440\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
504"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5224,i,9038401685476498952,9576981917042080514,262144 --variations-seed-version --mojo-platform-channel-handle=1484 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
504C:\WINDOWS\system32\cmd.exe /c icacls C:\WINDOWS\System32\SppExtComObjHook.dll /findsid *S-1-5-32-545C:\Windows\System32\cmd.exekms_x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
512schtasks /create /tn "HEU KMS Renewal" /ru "SYSTEM" /xml C:\Users\admin\AppData\Local\Temp\_temp_heu168yyds\xml\HEU_KMS_Renewal.xmlC:\Windows\System32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
44 931
Read events
44 818
Write events
92
Delete events
21

Modification events

(PID) Process:(2528) kms_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\55c92734-d682-4d71-983e-d6ec3f16059f\2de67392-b7a7-462a-b1ca-108dd189f588
Operation:writeName:KeyManagementServiceName
Value:
127.0.0.2
(PID) Process:(2528) kms_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\55c92734-d682-4d71-983e-d6ec3f16059f\2de67392-b7a7-462a-b1ca-108dd189f588
Operation:writeName:KeyManagementServicePort
Value:
1688
(PID) Process:(2528) kms_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\55c92734-d682-4d71-983e-d6ec3f16059f\2de67392-b7a7-462a-b1ca-108dd189f588
Operation:delete keyName:(default)
Value:
(PID) Process:(6176) TSforge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TSforge_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6176) TSforge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TSforge_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6176) TSforge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TSforge_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6176) TSforge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TSforge_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6176) TSforge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TSforge_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6176) TSforge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TSforge_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6176) TSforge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TSforge_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
Executable files
180
Suspicious files
256
Text files
324
Unknown types
0

Dropped files

PID
Process
Filename
Type
4888HEU_KMS_Activator_v63.2.0.exeC:\Users\admin\AppData\Local\Temp\splashlogo.jpgimage
MD5:03361B7B3BAB104DFF232D8AB607319F
SHA256:81FF582D54D96E22AC5E54B0BC914560B2D0E85EB775DCF500EEBA1BFD9F72F8
51407Z.EXEC:\Users\admin\AppData\Local\Temp\_temp_heu168yyds\OtherOfficeOSPP\SLERROR.XMLtext
MD5:36F7DADFE84E62DA00292D0569C3F523
SHA256:B3378A3178F3E52094DB20E8A828011CD8882017919522A544BAEF3057BD11D3
4888HEU_KMS_Activator_v63.2.0.exeC:\Users\admin\AppData\Local\Temp\_temp_heu168yyds\7Z.EXEexecutable
MD5:43141E85E7C36E31B52B22AB94D5E574
SHA256:EA308C76A2F927B160A143D94072B0DCE232E04B751F0C6432A94E05164E716D
4888HEU_KMS_Activator_v63.2.0.exeC:\Users\admin\AppData\Local\Temp\autD9B2.tmpcompressed
MD5:B807F536B1847B554FEC9DDB671BDCDF
SHA256:C50F29B1FD4F454A7A3137517072B35A1FB84B3B54EF12DB43BCED6C826FA045
4888HEU_KMS_Activator_v63.2.0.exeC:\Users\admin\AppData\Local\Temp\ScriptTemp.initext
MD5:5DB27831FED315E9E72B47C6693B084B
SHA256:9A536B4E5AEF1C73E2CB491EF89F3340197DBFA7D3A5387AB5FACA4480C16543
4888HEU_KMS_Activator_v63.2.0.exeC:\Users\admin\AppData\Local\Temp\autD934.tmpbinary
MD5:3A349B600BB8FED89C6BF260E2E227FC
SHA256:9EFCD38D69C487EA1D4A9BA88F82F44993C2747B88871CF279CFF5C5891E8C51
4888HEU_KMS_Activator_v63.2.0.exeC:\Users\admin\AppData\Local\Temp\~DF1C2BCFD590B4DA9B.TMPbinary
MD5:114AD8A12DB4E5675301BA32F4B8716A
SHA256:993BC5EC322986B935ED5065518C1B75DFA4718CBD3E08BF25DDD752ACFE3952
4888HEU_KMS_Activator_v63.2.0.exeC:\Users\admin\AppData\Local\Temp\_temp_heu168yyds\files.7zcompressed
MD5:19141175C6CA86126B1532AA4486382D
SHA256:9A16451C3CD87C9176AA3B68B776B4E9725D55E053D6A913B5BC51348F9F56CF
4888HEU_KMS_Activator_v63.2.0.exeC:\Users\admin\AppData\Local\Temp\_temp_heu168yyds\KMSmini.7zcompressed
MD5:B807F536B1847B554FEC9DDB671BDCDF
SHA256:C50F29B1FD4F454A7A3137517072B35A1FB84B3B54EF12DB43BCED6C826FA045
4888HEU_KMS_Activator_v63.2.0.exeC:\Users\admin\AppData\Local\Temp\autDA8F.tmpbinary
MD5:E25E09DF3DB990F98A165990B2F48B02
SHA256:52F64C84948068514240283D6C7FA1204E81CA0549CF0159FCACC556A950CD94
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
93
DNS requests
116
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
4520
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
2628
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
1632
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:-27op2guV6L2Qa5RRWDDcR4sCGjC2khnUwq62DsOQO8&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
98 b
whitelisted
2940
svchost.exe
GET
200
72.246.169.163:80
http://x1.c.lencr.org/
DE
binary
734 b
whitelisted
4036
svchost.exe
HEAD
200
23.213.161.20:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1755803802&P2=404&P3=2&P4=VDqAh4qrs1TjZvc35u5I%2bw00gpNxBucjUxI4k1t8LQapud80nhCJZ7NyybR2ToI7ykBTHsCJzIhHrQ568T7v0g%3d%3d
DE
whitelisted
4036
svchost.exe
GET
206
23.213.161.20:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1755803802&P2=404&P3=2&P4=VDqAh4qrs1TjZvc35u5I%2bw00gpNxBucjUxI4k1t8LQapud80nhCJZ7NyybR2ToI7ykBTHsCJzIhHrQ568T7v0g%3d%3d
DE
binary
1.09 Kb
whitelisted
4036
svchost.exe
GET
206
23.213.161.20:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1755803802&P2=404&P3=2&P4=VDqAh4qrs1TjZvc35u5I%2bw00gpNxBucjUxI4k1t8LQapud80nhCJZ7NyybR2ToI7ykBTHsCJzIhHrQ568T7v0g%3d%3d
DE
compressed
764 b
whitelisted
4036
svchost.exe
HEAD
200
23.213.161.20:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/4c4fdee0-d69c-42b7-bf5c-3ec046e9dfc9?P1=1755803808&P2=404&P3=2&P4=ZM7Hi3p%2fGVeUaYGbEoffPWqePpKAujDe3eZ%2fB4SI3BFepU3bpXA%2b7AxoFKhbapSiUccUHoBXBrBs48i10onong%3d%3d
DE
compressed
764 b
whitelisted
4036
svchost.exe
GET
200
23.213.161.20:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/550117a4-8c0f-4d0d-8ff8-7c3caccb0e8a?P1=1755991573&P2=404&P3=2&P4=jjmea9sIzVVCu%2bY2Rya%2bbGw2%2b5r3RkHiP1DK3mMEhznNRvR%2br5Qje6dNlMkzi3DPDUnSJ%2bG6uAFKYHCKBF58qQ%3d%3d
DE
binary
6.24 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2992
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4520
svchost.exe
20.190.160.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
www.baidu.com
  • 103.235.46.115
  • 103.235.46.102
whitelisted
login.live.com
  • 20.190.160.131
  • 20.190.160.128
  • 40.126.32.76
  • 20.190.160.4
  • 40.126.32.68
  • 20.190.160.3
  • 20.190.160.65
  • 40.126.32.140
  • 20.190.159.68
  • 40.126.31.131
  • 20.190.159.129
  • 40.126.31.2
  • 40.126.31.71
  • 40.126.31.3
  • 20.190.159.64
  • 20.190.159.2
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
slscr.update.microsoft.com
  • 74.179.77.204
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
activation.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
Process
Message
Dism.exe
PID=2220 TID=3872 Instantiating the Provider Store. - CDISMImageSession::get_ProviderStore
Dism.exe
PID=2220 TID=3872 Initializing a provider store for the LOCAL session type. - CDISMProviderStore::Final_OnConnect
Dism.exe
PID=2220 TID=3872 Attempting to initialize the logger from the Image Session. - CDISMProviderStore::Final_OnConnect
Dism.exe
PID=2220 TID=3872 Provider has not previously been encountered. Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
Dism.exe
PID=2220 TID=3872 Loading Provider from location C:\WINDOWS\system32\Dism\LogProvider.dll - CDISMProviderStore::Internal_GetProvider
Dism.exe
PID=2220 TID=3872 Connecting to the provider located at C:\WINDOWS\system32\Dism\LogProvider.dll. - CDISMProviderStore::Internal_LoadProvider
DismHost.exe
PID=1636 TID=504 Disconnecting the provider store - CDISMImageSession::Final_OnDisconnect
DismHost.exe
PID=1636 TID=504 Encountered a loaded provider DISMLogger. - CDISMProviderStore::Internal_DisconnectProvider
DismHost.exe
PID=1636 TID=504 Disconnecting Provider: DISMLogger - CDISMProviderStore::Internal_DisconnectProvider
Dism.exe
PID=2220 TID=3872 Disconnecting the provider store - CDISMImageSession::Final_OnDisconnect