| File name: | KMSpico v10.1.5 Final.exe |
| Full analysis: | https://app.any.run/tasks/7542a745-1e83-453b-bbc0-d57ef3ec76ac |
| Verdict: | Malicious activity |
| Analysis date: | February 06, 2024, 23:20:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 88B9FE947CDA28E202DC252F2A008608 |
| SHA1: | 58C66B0735E5A11E2E055633476581BF09E8D9E1 |
| SHA256: | 9C875DACDF050020E1085C6F3A109D29D45A9CB7E960A803F9920AF2A851F60B |
| SSDEEP: | 98304:Tp7EUEwLN41avFf7mZQh13SqAMbjK9JquCm/LOwQHe0PJN8JcQxef8k4LB1rkoBQ:BXeX0 |
| .exe | | | Inno Setup installer (71.1) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (9.1) |
| .scr | | | Windows screen saver (8.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.2) |
| .exe | | | Win32 Executable (generic) (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 40448 |
| InitializedDataSize: | 27648 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa5f8 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.1.5.0 |
| ProductVersionNumber: | 10.1.5.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | KMSpico Setup |
| FileVersion: | 10.1.5 |
| LegalCopyright: | ByELDI |
| ProductName: | KMSpico |
| ProductVersion: | 10.1.5 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 324 | "C:\Users\admin\AppData\Local\Temp\KMSpico v10.1.5 Final.exe" /SPAWNWND=$100166 /NOTIFYWND=$F0184 | C:\Users\admin\AppData\Local\Temp\KMSpico v10.1.5 Final.exe | KMSpico v10.1.5 Final.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: KMSpico Setup Exit code: 0 Version: 10.1.5 Modules
| |||||||||||||||
| 668 | "C:\Users\admin\AppData\Local\Temp\is-B7CVQ.tmp\KMSpico v10.1.5 Final.tmp" /SL5="$1301B4,2867584,69120,C:\Users\admin\AppData\Local\Temp\KMSpico v10.1.5 Final.exe" /SPAWNWND=$100166 /NOTIFYWND=$F0184 | C:\Users\admin\AppData\Local\Temp\is-B7CVQ.tmp\KMSpico v10.1.5 Final.tmp | KMSpico v10.1.5 Final.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 1028 | "C:\Windows\system32\cmd.exe" /C ""C:\Program Files\KMSpico\scripts\Install_Task.cmd"" | C:\Windows\System32\cmd.exe | — | KMSpico v10.1.5 Final.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1380 | "C:\Users\admin\AppData\Local\Temp\KMSpico v10.1.5 Final.exe" | C:\Users\admin\AppData\Local\Temp\KMSpico v10.1.5 Final.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: KMSpico Setup Exit code: 0 Version: 10.1.5 Modules
| |||||||||||||||
| 1392 | "C:\Users\admin\AppData\Local\Temp\is-JHC9Q.tmp\KMSpico v10.1.5 Final.tmp" /SL5="$F0184,2867584,69120,C:\Users\admin\AppData\Local\Temp\KMSpico v10.1.5 Final.exe" | C:\Users\admin\AppData\Local\Temp\is-JHC9Q.tmp\KMSpico v10.1.5 Final.tmp | — | KMSpico v10.1.5 Final.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 1932 | "C:\Program Files\KMSpico\KMSELDI.exe" /silent /backup | C:\Program Files\KMSpico\KMSELDI.exe | KMSpico v10.1.5 Final.tmp | ||||||||||||
User: admin Company: @ByELDI Integrity Level: HIGH Description: KMS GUI ELDI Exit code: 0 Version: 36.0.0.4 Modules
| |||||||||||||||
| 2768 | sc create "Service KMSELDI" binPath= "C:\Program Files\KMSpico\Service_KMS.exe" type= own error= normal start= auto DisplayName= "Service KMSELDI" | C:\Windows\System32\sc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2776 | "C:\Windows\system32\cmd.exe" /C ""C:\Program Files\KMSpico\scripts\Install_Service.cmd"" | C:\Windows\System32\cmd.exe | — | KMSpico v10.1.5 Final.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3048 | SCHTASKS /Create /TN "AutoPico Daily Restart" /TR "'C:\Program Files\KMSpico\AutoPico.exe' /silent" /SC DAILY /ST 23:59:59 /RU "NT AUTHORITY\SYSTEM" /RL Highest /F | C:\Windows\System32\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3156 | "C:\Program Files\KMSpico\UninsHs.exe" /r0=KMSpico,default,C:\Users\admin\AppData\Local\Temp\KMSpico v10.1.5 Final.exe | C:\Program Files\KMSpico\UninsHs.exe | — | KMSpico v10.1.5 Final.tmp | |||||||||||
User: admin Company: Han-soft Integrity Level: HIGH Description: Uninstall for InnoSetup by Han-soft Exit code: 0 Version: 2.1.0.283 Modules
| |||||||||||||||
| (PID) Process: | (1932) KMSELDI.exe | Key: | HKEY_CURRENT_USER\Control Panel\Desktop |
| Operation: | write | Name: | PaintDesktopVersion |
Value: 0 | |||
| (PID) Process: | (3284) AutoPico.exe | Key: | HKEY_CURRENT_USER\Control Panel\Desktop |
| Operation: | write | Name: | PaintDesktopVersion |
Value: 0 | |||
| (PID) Process: | (668) KMSpico v10.1.5 Final.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 36201CC9F54348D582553CE954A77555AADA376B11E03E4EC86AE15ABC4901C2 | |||
| (PID) Process: | (668) KMSpico v10.1.5 Final.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Program Files\KMSpico\AutoPico.exe | |||
| (PID) Process: | (668) KMSpico v10.1.5 Final.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (668) KMSpico v10.1.5 Final.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 575E3379E4EFE81D1EECD4F4156BEA83ED61023F3BBB9801F6BC9197973DF18B | |||
| (PID) Process: | (668) KMSpico v10.1.5 Final.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: 9C020000A2485E1F5359DA01 | |||
| (PID) Process: | (668) KMSpico v10.1.5 Final.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 668 | KMSpico v10.1.5 Final.tmp | C:\Users\admin\AppData\Local\Temp\is-9JT7E.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 1380 | KMSpico v10.1.5 Final.exe | C:\Users\admin\AppData\Local\Temp\is-JHC9Q.tmp\KMSpico v10.1.5 Final.tmp | executable | |
MD5:1778C1F66FF205875A6435A33229AB3C | SHA256:95C06ACAC4FE4598840E5556F9613D43AA1039C52DAC64536F59E45A70F79DA6 | |||
| 668 | KMSpico v10.1.5 Final.tmp | C:\Program Files\KMSpico\is-L8N3M.tmp | executable | |
MD5:3D733144477CADCF77009EF614413630 | SHA256:392D73617FD0A55218261572ECE2F50301E0CFA29B5ED24C3F692130AA406AF3 | |||
| 668 | KMSpico v10.1.5 Final.tmp | C:\Windows\system32\is-3P1RB.tmp | executable | |
MD5:3D733144477CADCF77009EF614413630 | SHA256:392D73617FD0A55218261572ECE2F50301E0CFA29B5ED24C3F692130AA406AF3 | |||
| 668 | KMSpico v10.1.5 Final.tmp | C:\Windows\System32\Vestris.ResourceLib.dll | executable | |
MD5:3D733144477CADCF77009EF614413630 | SHA256:392D73617FD0A55218261572ECE2F50301E0CFA29B5ED24C3F692130AA406AF3 | |||
| 324 | KMSpico v10.1.5 Final.exe | C:\Users\admin\AppData\Local\Temp\is-B7CVQ.tmp\KMSpico v10.1.5 Final.tmp | executable | |
MD5:1778C1F66FF205875A6435A33229AB3C | SHA256:95C06ACAC4FE4598840E5556F9613D43AA1039C52DAC64536F59E45A70F79DA6 | |||
| 668 | KMSpico v10.1.5 Final.tmp | C:\Program Files\KMSpico\Vestris.ResourceLib.dll | executable | |
MD5:3D733144477CADCF77009EF614413630 | SHA256:392D73617FD0A55218261572ECE2F50301E0CFA29B5ED24C3F692130AA406AF3 | |||
| 668 | KMSpico v10.1.5 Final.tmp | C:\Program Files\KMSpico\UninsHs.exe | executable | |
MD5:245824502AEFE21B01E42F61955AA7F4 | SHA256:0A265B4BB8ACCEAFAFFB001632FA7E4C3F8AC39A71EDA37F253E15BC1B8DB90D | |||
| 668 | KMSpico v10.1.5 Final.tmp | C:\Program Files\KMSpico\is-J9172.tmp | executable | |
MD5:30C7E8E918403B9247315249A8842CE5 | SHA256:6D4FA6727CA952B7B44FA9F3538D84B64E06C76908C76FADE7846532A7115A49 | |||
| 668 | KMSpico v10.1.5 Final.tmp | C:\Program Files\KMSpico\DevComponents.DotNetBar2.dll | executable | |
MD5:FE64F54BB78C093EDD5C50E82C737244 | SHA256:13AB7226D85B1168A86CD6FCC0E0759CBEA155BE4DE12F1ED4C387A22D8B49BD | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1932 | KMSELDI.exe | 91.205.174.83:123 | 1.pool.ntp.org | — | — | unknown |
3284 | AutoPico.exe | 193.203.3.171:123 | 3.pool.ntp.org | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
1.pool.ntp.org |
| whitelisted |
3.pool.ntp.org |
| whitelisted |