| File name: | Kon-Boot for Windows 2.5.0 Retail [deepstatus].rar |
| Full analysis: | https://app.any.run/tasks/4637219e-5601-44a2-bcc4-260a856e52f8 |
| Verdict: | Malicious activity |
| Analysis date: | January 22, 2020, 05:45:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32, flags: Locked Solid |
| MD5: | A58A6564514758205556D36287BA19BE |
| SHA1: | 374C3331A95882F2656860F2E74F40EF8248E0F5 |
| SHA256: | 9F0F7365E3950C38CFC4A1285633089D80E404EEEAECD27368DA323B3BAD1258 |
| SSDEEP: | 24576:RGwQFb18yIaPOwRbCV6OtwR8YNAS9/FbIpda6V:4wob1jItObDR8YNP9b+Yy |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 540 |
|---|---|
| UncompressedSize: | 690 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2013:01:03 12:52:21 |
| PackingMethod: | Best Compression |
| ArchivedFileName: | kon-bootUSB\README.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 252 | cmd /c ""C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\kon-bootUSB\usb_install_RUNASADMIN.bat" " | C:\Windows\system32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 3221225547 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1416 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3420.0.476202095\1527989536" --allow-no-sandbox-job /prefetch:673131151 | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | — | RdrCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe RdrCEF Exit code: 0 Version: 15.23.20053.211670 Modules
| |||||||||||||||
| 2004 | "C:\Windows\System32\notepad.exe" konlog.txt | C:\Windows\System32\notepad.exe | — | KonBootInstaller.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2336 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\konbootWIN_guide.pdf" | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | — | AcroRd32.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe Acrobat Reader DC Exit code: 1 Version: 15.23.20070.215641 Modules
| |||||||||||||||
| 2432 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3420.1.1429735793\2092356898" --allow-no-sandbox-job /prefetch:673131151 | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | — | RdrCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe RdrCEF Exit code: 0 Version: 15.23.20053.211670 Modules
| |||||||||||||||
| 2528 | "C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\KonBootInstaller.exe" | C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\KonBootInstaller.exe | explorer.exe | ||||||||||||
User: admin Company: LEAD 82 - http://thelead82.com Integrity Level: HIGH Description: Kon-Boot Windows Installer Exit code: 0 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 2608 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\KonBootInstaller.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\KonBootInstaller.exe | — | WinRAR.exe | |||||||||||
User: admin Company: LEAD 82 - http://thelead82.com Integrity Level: MEDIUM Description: Kon-Boot Windows Installer Exit code: 3221226540 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 2644 | "C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\kon-bootUSB\grubinst.exe" | C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\kon-bootUSB\grubinst.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 2748 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\konbootWIN_guide.pdf" | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | explorer.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe Acrobat Reader DC Exit code: 1 Version: 15.23.20070.215641 Modules
| |||||||||||||||
| 2768 | "C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\KonBootInstaller.exe" | C:\Users\admin\Desktop\Kon-Boot for Windows 2.5.0 Retail [deepstatus]\KonBootInstaller.exe | — | explorer.exe | |||||||||||
User: admin Company: LEAD 82 - http://thelead82.com Integrity Level: MEDIUM Description: Kon-Boot Windows Installer Exit code: 3221226540 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Kon-Boot for Windows 2.5.0 Retail [deepstatus].rar | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\USBFILES\konboot.lst | text | |
MD5:EA054BD25BEBAAC0DEB06D05CA1759DD | SHA256:C0B5EDA0F737B700BC9ED5547D1DF8C864002B62BEDB998879AC6866811693D0 | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\grubinst.exe | executable | |
MD5:3158819B990A49FC563E61C549A86628 | SHA256:515B56B3AAC6CC65187CF833608192DF11D4F7D9056D8AEA6158C35DCAF4893C | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\usb_install2_NEEDADMIN.bat | text | |
MD5:94F9670AF51853F38BEAD6DA6DE49055 | SHA256:DC906B7E350320AE48A7274136A1E0EFDB5FC17E01163E366583594E3C69E64B | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\README.txt | text | |
MD5:9DEFE5F30ED23B5E2F711FEF43D25C6D | SHA256:AC7AECE9B2709A695490E85E44BA6305FE49672F10B010C36E9E061076E96055 | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\usb_install_RUNASADMIN.bat | text | |
MD5:9E28DBD61E80402AB7BCC212617762EE | SHA256:D0326645FBB7D9F1A1A6EBA8B4109C5ECDB6E4CD80396360B50A8EEF381E8263 | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\USBFILES\konexec32.exe | executable | |
MD5:36807F8598EB5A5259B2C45B5147E44F | SHA256:8A576F5EC0B9626000D0AF77D6BAD759F11C71ECA0A36CAD2A0C28EF6302D6AC | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\Thumbs.db | binary | |
MD5:3692E42E723C2F0319792EFB0CD8C725 | SHA256:5789748A6AB5E7A1E056CE2AD3BDA8E91FFFE61C2E9A0E559471A337B8FA9703 | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\KonBootInstaller.exe | executable | |
MD5:A91D7ACCCE50352F3FB8ECBEFEF5C935 | SHA256:B7A8A43D7BB586A8406C9A4084A5441224CFF50079E9D11AD48B0BCB66AD91F1 | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\USBFILES\grldr | binary | |
MD5:816F503F4442A1271EDE3758AB357CF0 | SHA256:A58C97735FC0812867F11F9A1C931C4D07D7074568A4A9078C7061AF5F9C10BC | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2880.47739\kon-bootUSB\COPYING | text | |
MD5:94D55D512A9BA36CAA9B7DF079BAE19F | SHA256:32B1062F7DA84967E7019D01AB805935CAA7AB7321A7CED0E30EBE75E5DF1670 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2748 | AcroRd32.exe | GET | 304 | 2.16.106.186:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/277_15_23_20070.zip | unknown | — | — | whitelisted |
2748 | AcroRd32.exe | GET | 304 | 2.16.106.186:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/281_15_23_20070.zip | unknown | — | — | whitelisted |
2748 | AcroRd32.exe | GET | 304 | 2.16.106.186:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/280_15_23_20070.zip | unknown | — | — | whitelisted |
2748 | AcroRd32.exe | GET | 200 | 2.16.106.186:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/message.zip | unknown | compressed | 9.36 Kb | whitelisted |
2748 | AcroRd32.exe | GET | 304 | 2.16.106.186:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/278_15_23_20070.zip | unknown | — | — | whitelisted |
2528 | KonBootInstaller.exe | POST | 200 | 18.194.160.188:80 | http://thelead82.com/kon-bootNEWS/index.php | DE | text | 87 b | suspicious |
3540 | KonBootInstaller.exe | POST | 200 | 18.194.160.188:80 | http://thelead82.com/kon-bootNEWS/index.php | DE | text | 87 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3540 | KonBootInstaller.exe | 18.194.160.188:80 | thelead82.com | Amazon.com, Inc. | DE | unknown |
2528 | KonBootInstaller.exe | 18.194.160.188:80 | thelead82.com | Amazon.com, Inc. | DE | unknown |
2748 | AcroRd32.exe | 2.16.106.186:80 | acroipm2.adobe.com | Akamai International B.V. | — | whitelisted |
2748 | AcroRd32.exe | 23.210.248.251:443 | armmf.adobe.com | Akamai International B.V. | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
thelead82.com |
| suspicious |
acroipm2.adobe.com |
| whitelisted |
armmf.adobe.com |
| whitelisted |