| File name: | KMSPico 10.0.exe |
| Full analysis: | https://app.any.run/tasks/fc4b29bf-5af1-422f-a397-ab04fc04ce61 |
| Verdict: | Malicious activity |
| Analysis date: | September 26, 2023, 07:43:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | A17D65B10DF020998C97E824C7FD7112 |
| SHA1: | D804EB918BD0F11D913C0B93AD06BE4C7D470715 |
| SHA256: | A594695D0DDA69AC7A9E1B85E68FD52C40BE713EB10891CB1011F42F78512EBB |
| SSDEEP: | 49152:pQI8lKsEhdeHpe2fYErYjN+nqNHVbnPJ3:pQRlKsUdCMXAnqNHVLN |
| .exe | | | NSIS - Nullsoft Scriptable Install System (94.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.5) |
| .exe | | | Generic Win/DOS Executable (0.2) |
| Subsystem: | Windows GUI |
|---|---|
| SubsystemVersion: | 4 |
| ImageVersion: | - |
| OSVersion: | 4 |
| EntryPoint: | 0x1d20 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 102400 |
| CodeSize: | 4096 |
| LinkerVersion: | 6 |
| PEType: | PE32 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| TimeStamp: | 2011:01:31 17:44:13+00:00 |
| MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 268 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1092 --field-trial-handle=1152,i,1048685805450544340,8323885582296739455,131072 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 276 | "KMSPico__11516_il289527.exe" | C:\Program Files\KMSPico\KMSPico__11516_il289527.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.1.5.26 Modules
| |||||||||||||||
| 572 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1448 --field-trial-handle=1280,i,18028845084348280831,988362953463504791,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 668 | C:\Users\admin\AppData\Local\Temp/oo2.exe /PID=10058 /SUBPID=0 /DISTID=25537 /VM=2 /NETWORDK=1 /CID=0 /PRODUCT_ID=24725 /RETURNING_USER_DAYS=2 /SERVER_URL=http://installer.ppdownload.com | C:\Users\admin\AppData\Local\Temp\oo2.exe | KMSPico.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Exit code: 3221225477 Version: 2015.329.1239.2 Modules
| |||||||||||||||
| 788 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1452 --field-trial-handle=1152,i,1048685805450544340,8323885582296739455,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 916 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1260 --field-trial-handle=1280,i,18028845084348280831,988362953463504791,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 956 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1020 --field-trial-handle=1152,i,1048685805450544340,8323885582296739455,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 988 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2088 --field-trial-handle=1188,i,10951399113625869128,7342944445187946413,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1020 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2116 --field-trial-handle=1152,i,1048685805450544340,8323885582296739455,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1040 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3376 --field-trial-handle=1188,i,10951399113625869128,7342944445187946413,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| (PID) Process: | (3528) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3528) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3528) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3528) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3528) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3528) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 1 | |||
| (PID) Process: | (3528) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3528) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3528) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_installdate |
Value: 0 | |||
| (PID) Process: | (3528) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_enableddate |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2752 | KMSPico 10.0.exe | C:\Users\admin\AppData\Local\Temp\genteert.dll | executable | |
MD5:6CE814FD1AD7AE07A9E462C26B3A0F69 | SHA256:54C0DA1735BB1CB02B60C321DE938488345F8D1D26BF389C8CB2ACAD5D01B831 | |||
| 2752 | KMSPico 10.0.exe | C:\Users\admin\AppData\Local\Temp\genteeE8\3default - 1.bmp | image | |
MD5:14A455E9EEF9FE7FEA4DE14D579A3E84 | SHA256:B666E6BD71EFF3547FB2F5580AC61C64527F6F9BE6A2178FA00F80E32431460A | |||
| 2752 | KMSPico 10.0.exe | C:\Program Files\KMSPico\jaykms.bat | text | |
MD5:3CA814C0D756D5C4AC163CC95E8309E9 | SHA256:F23785C19AC7637A9990F8D91B7E431F8C3AD86EE0D81964DAFD699B4724CE9F | |||
| 3528 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF101e57.TMP | — | |
MD5:— | SHA256:— | |||
| 3528 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2752 | KMSPico 10.0.exe | C:\Program Files\KMSPico\KMSPico__11516_il289527.exe | executable | |
MD5:A0AF20D9464C490189852E11893E45EA | SHA256:E904FAE018E4E8AC4D273736966D3ED8D7820C6B52FA762BFE4479D402848B12 | |||
| 4076 | WMIC.exe | C:\Users\admin\AppData\Local\Temp\81695714202.txt | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 2752 | KMSPico 10.0.exe | C:\Program Files\KMSPico\KMSPico.exe | executable | |
MD5:8A02449D202243027583A9BBA88FFD65 | SHA256:B4C9EDD9AD21DDB04CC1C2545A6FB123E0BACE7DC5CE489B561DEDBCE29EEC46 | |||
| 2944 | WMIC.exe | C:\Users\admin\AppData\Local\Temp\81695714202.txt | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 1636 | WMIC.exe | C:\Users\admin\AppData\Local\Temp\81695714202.txt | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
668 | oo2.exe | GET | 302 | 54.161.222.85:80 | http://installer.ppdownload.com/Installer/Flow?pubid=10058&distid=25537&productid=24725&subpubid=0&campaignid=0&networkid=&dfb=-1&os=6.1&ospv=-1&iev=9.11&ffv=115.0&chromev=109.0&macaddress=12:A9:86:6C:77:DE&netv=&systembit=32&vm=0&machineguid=90059c37-1320-41a4-b58d-2b75a9850d2f&welcomeimgurl=&downloadip=&downloadtime=&clickid=&version=6.12 | unknown | — | — | unknown |
868 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/delta-update/gcmjkmgdlgnkkcocmoeiminaijmmjnii/1.283f61dc5c8c0f4f6ca2979adb45d79401932496f88f528e55cf40eff6badbcb/1.4c67e9ab7c30c48322e5f6fe5acbd64132c054ebb91bd510b414b1506167ffc9/f98c39662a6a1bd65140e9a68abe02e76b89d7eb7e1a5f99529e88e752736576.crxd | unknown | — | — | unknown |
3380 | msedge.exe | GET | — | 13.107.6.158:80 | http://edge-http.microsoft.com/captiveportal/generate_204 | unknown | — | — | unknown |
868 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/delta-update/gcmjkmgdlgnkkcocmoeiminaijmmjnii/1.283f61dc5c8c0f4f6ca2979adb45d79401932496f88f528e55cf40eff6badbcb/1.4c67e9ab7c30c48322e5f6fe5acbd64132c054ebb91bd510b414b1506167ffc9/f98c39662a6a1bd65140e9a68abe02e76b89d7eb7e1a5f99529e88e752736576.crxd | unknown | binary | 6.96 Kb | unknown |
868 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/delta-update/gcmjkmgdlgnkkcocmoeiminaijmmjnii/1.283f61dc5c8c0f4f6ca2979adb45d79401932496f88f528e55cf40eff6badbcb/1.4c67e9ab7c30c48322e5f6fe5acbd64132c054ebb91bd510b414b1506167ffc9/f98c39662a6a1bd65140e9a68abe02e76b89d7eb7e1a5f99529e88e752736576.crxd | unknown | binary | 1.67 Kb | unknown |
3380 | msedge.exe | GET | 301 | 52.49.176.91:80 | http://smarturl.it/kms3 | unknown | html | 134 b | unknown |
276 | KMSPico__11516_il289527.exe | POST | 502 | 45.43.206.9:80 | http://www.keenondownload.com/index.php | unknown | html | 568 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
668 | oo2.exe | 54.161.222.85:80 | installer.ppdownload.com | AMAZON-AES | US | unknown |
668 | oo2.exe | 104.26.7.37:443 | www.hugedomains.com | CLOUDFLARENET | US | shared |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
668 | oo2.exe | 172.67.70.191:443 | www.hugedomains.com | CLOUDFLARENET | US | unknown |
788 | chrome.exe | 142.250.186.67:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
3528 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
788 | chrome.exe | 142.250.186.45:443 | accounts.google.com | GOOGLE | US | unknown |
788 | chrome.exe | 142.250.185.164:443 | www.google.com | — | — | whitelisted |
788 | chrome.exe | 142.251.140.35:443 | www.gstatic.com | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
installer.ppdownload.com |
| malicious |
www.hugedomains.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
apis.google.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
optimizationguide-pa.googleapis.com |
| whitelisted |
dns.msftncsi.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
668 | oo2.exe | Possibly Unwanted Program Detected | ET ADWARE_PUP Downloader.NSIS.OutBrowse.b Checkin |
276 | KMSPico__11516_il289527.exe | Possibly Unwanted Program Detected | ET ADWARE_PUP SoundCloud Downloader Install Beacon |