File name:

Kon-Boot for Windows 2.5.0 Retail [deepstatus].rar

Full analysis: https://app.any.run/tasks/4637219e-5601-44a2-bcc4-260a856e52f8
Verdict: Malicious activity
Analysis date: January 22, 2020, 05:45:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32, flags: Locked Solid
MD5:

A58A6564514758205556D36287BA19BE

SHA1:

374C3331A95882F2656860F2E74F40EF8248E0F5

SHA256:

9F0F7365E3950C38CFC4A1285633089D80E404EEEAECD27368DA323B3BAD1258

SSDEEP:

24576:RGwQFb18yIaPOwRbCV6OtwR8YNAS9/FbIpda6V:4wob1jItObDR8YNP9b+Yy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • KonBootInstaller.exe (PID: 2608)
      • KonBootInstaller.exe (PID: 3540)
      • KonBootInstaller.exe (PID: 2768)
      • KonBootInstaller.exe (PID: 2528)
      • grubinst.exe (PID: 2644)
      • grubinst.exe (PID: 3868)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2880)
    • Executes scripts

      • cmd.exe (PID: 3652)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 252)
  • INFO

    • Manual execution by user

      • AcroRd32.exe (PID: 2748)
      • KonBootInstaller.exe (PID: 2768)
      • KonBootInstaller.exe (PID: 2528)
      • grubinst.exe (PID: 3868)
      • grubinst.exe (PID: 2644)
      • cmd.exe (PID: 252)
    • Application launched itself

      • RdrCEF.exe (PID: 3420)
      • AcroRd32.exe (PID: 2748)
    • Reads the hosts file

      • RdrCEF.exe (PID: 3420)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 540
UncompressedSize: 690
OperatingSystem: Win32
ModifyDate: 2013:01:03 12:52:21
PackingMethod: Best Compression
ArchivedFileName: kon-bootUSB\README.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
19
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe konbootinstaller.exe no specs konbootinstaller.exe notepad.exe no specs notepad.exe no specs konbootinstaller.exe no specs konbootinstaller.exe notepad.exe no specs notepad.exe no specs acrord32.exe acrord32.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs cmd.exe no specs cmd.exe no specs wscript.exe no specs grubinst.exe no specs grubinst.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
252cmd /c ""C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\kon-bootUSB\usb_install_RUNASADMIN.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225547
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1416"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3420.0.476202095\1527989536" --allow-no-sandbox-job /prefetch:673131151C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
15.23.20053.211670
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2004"C:\Windows\System32\notepad.exe" konlog.txtC:\Windows\System32\notepad.exeKonBootInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2336"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\konbootWIN_guide.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
2432"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3420.1.1429735793\2092356898" --allow-no-sandbox-job /prefetch:673131151C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
15.23.20053.211670
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2528"C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\KonBootInstaller.exe" C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\KonBootInstaller.exe
explorer.exe
User:
admin
Company:
LEAD 82 - http://thelead82.com
Integrity Level:
HIGH
Description:
Kon-Boot Windows Installer
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\kon-boot for windows 2.5.0 retail [deepstatus]\konbootinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2608"C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\KonBootInstaller.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\KonBootInstaller.exeWinRAR.exe
User:
admin
Company:
LEAD 82 - http://thelead82.com
Integrity Level:
MEDIUM
Description:
Kon-Boot Windows Installer
Exit code:
3221226540
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2880.47739\konbootinstaller.exe
c:\systemroot\system32\ntdll.dll
2644"C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\kon-bootUSB\grubinst.exe" C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\kon-bootUSB\grubinst.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\kon-boot for windows 2.5.0 retail [deepstatus]\kon-bootusb\grubinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
2748"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\konbootWIN_guide.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
explorer.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2768"C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\KonBootInstaller.exe" C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\KonBootInstaller.exeexplorer.exe
User:
admin
Company:
LEAD 82 - http://thelead82.com
Integrity Level:
MEDIUM
Description:
Kon-Boot Windows Installer
Exit code:
3221226540
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\kon-boot for windows 2.5.0 retail [deepstatus]\konbootinstaller.exe
c:\systemroot\system32\ntdll.dll
Total events
1 007
Read events
846
Write events
160
Delete events
1

Modification events

(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2880) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2880) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Kon-Boot for Windows 2.5.0 Retail [deepstatus].rar
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2880) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
24
Suspicious files
13
Text files
26
Unknown types
32

Dropped files

PID
Process
Filename
Type
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\USBFILES\konboot.lsttext
MD5:EA054BD25BEBAAC0DEB06D05CA1759DD
SHA256:C0B5EDA0F737B700BC9ED5547D1DF8C864002B62BEDB998879AC6866811693D0
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\grubinst.exeexecutable
MD5:3158819B990A49FC563E61C549A86628
SHA256:515B56B3AAC6CC65187CF833608192DF11D4F7D9056D8AEA6158C35DCAF4893C
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\usb_install2_NEEDADMIN.battext
MD5:94F9670AF51853F38BEAD6DA6DE49055
SHA256:DC906B7E350320AE48A7274136A1E0EFDB5FC17E01163E366583594E3C69E64B
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\README.txttext
MD5:9DEFE5F30ED23B5E2F711FEF43D25C6D
SHA256:AC7AECE9B2709A695490E85E44BA6305FE49672F10B010C36E9E061076E96055
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\usb_install_RUNASADMIN.battext
MD5:9E28DBD61E80402AB7BCC212617762EE
SHA256:D0326645FBB7D9F1A1A6EBA8B4109C5ECDB6E4CD80396360B50A8EEF381E8263
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\USBFILES\konexec32.exeexecutable
MD5:36807F8598EB5A5259B2C45B5147E44F
SHA256:8A576F5EC0B9626000D0AF77D6BAD759F11C71ECA0A36CAD2A0C28EF6302D6AC
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\Thumbs.dbbinary
MD5:3692E42E723C2F0319792EFB0CD8C725
SHA256:5789748A6AB5E7A1E056CE2AD3BDA8E91FFFE61C2E9A0E559471A337B8FA9703
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\KonBootInstaller.exeexecutable
MD5:A91D7ACCCE50352F3FB8ECBEFEF5C935
SHA256:B7A8A43D7BB586A8406C9A4084A5441224CFF50079E9D11AD48B0BCB66AD91F1
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\USBFILES\grldrbinary
MD5:816F503F4442A1271EDE3758AB357CF0
SHA256:A58C97735FC0812867F11F9A1C931C4D07D7074568A4A9078C7061AF5F9C10BC
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\COPYINGtext
MD5:94D55D512A9BA36CAA9B7DF079BAE19F
SHA256:32B1062F7DA84967E7019D01AB805935CAA7AB7321A7CED0E30EBE75E5DF1670
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
5
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2748
AcroRd32.exe
GET
304
2.16.106.186:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/277_15_23_20070.zip
unknown
whitelisted
2748
AcroRd32.exe
GET
304
2.16.106.186:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/281_15_23_20070.zip
unknown
whitelisted
2748
AcroRd32.exe
GET
304
2.16.106.186:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/280_15_23_20070.zip
unknown
whitelisted
2748
AcroRd32.exe
GET
200
2.16.106.186:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/message.zip
unknown
compressed
9.36 Kb
whitelisted
2748
AcroRd32.exe
GET
304
2.16.106.186:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/278_15_23_20070.zip
unknown
whitelisted
2528
KonBootInstaller.exe
POST
200
18.194.160.188:80
http://thelead82.com/kon-bootNEWS/index.php
DE
text
87 b
suspicious
3540
KonBootInstaller.exe
POST
200
18.194.160.188:80
http://thelead82.com/kon-bootNEWS/index.php
DE
text
87 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3540
KonBootInstaller.exe
18.194.160.188:80
thelead82.com
Amazon.com, Inc.
DE
unknown
2528
KonBootInstaller.exe
18.194.160.188:80
thelead82.com
Amazon.com, Inc.
DE
unknown
2748
AcroRd32.exe
2.16.106.186:80
acroipm2.adobe.com
Akamai International B.V.
whitelisted
2748
AcroRd32.exe
23.210.248.251:443
armmf.adobe.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
thelead82.com
  • 18.194.160.188
suspicious
acroipm2.adobe.com
  • 2.16.106.186
  • 2.16.106.203
whitelisted
armmf.adobe.com
  • 23.210.248.251
whitelisted

Threats

No threats detected
No debug info