File name:

Mini_KMS_Activator_Ultimate_1.9.sanet.st.zip

Full analysis: https://app.any.run/tasks/04819537-6f94-4a7f-88d3-0503a1d4edb7
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: December 04, 2019, 18:29:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ransomware
opendir
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

891A33EB6E098E0F1665AB08320F2630

SHA1:

10C4BC0E408953D8DC049104406274343DF73663

SHA256:

A856A626F79B00869C300F050D3ED200D6E39D8CF9F09159CE4AD4E0395DAD2B

SSDEEP:

98304:mOu4moPahA2iLejII/kxnuFb27ofD2flYx1Md:7uI+t5/Ynsb28aNC1Md

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Mini KMS Activator Ultimate 1.9 Setup.exe (PID: 2840)
      • Mini KMS Activator Ultimate 1.9 Setup.exe (PID: 3728)
      • Mini KMS Activator Ultimate 1.9.exe (PID: 2184)
    • Adds new firewall rule via NETSH.EXE

      • Mini KMS Activator Ultimate 1.9 Setup.tmp (PID: 3340)
    • Loads dropped or rewritten executable

      • Mini KMS Activator Ultimate 1.9.exe (PID: 2184)
    • Runs PING.EXE for delay simulation

      • cmd.exe (PID: 2056)
  • SUSPICIOUS

    • Creates files like Ransomware instruction

      • WinRAR.exe (PID: 2064)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2064)
      • Mini KMS Activator Ultimate 1.9 Setup.exe (PID: 3728)
      • Mini KMS Activator Ultimate 1.9 Setup.exe (PID: 2840)
      • Mini KMS Activator Ultimate 1.9 Setup.tmp (PID: 3340)
    • Modifies the phishing filter of IE

      • Mini KMS Activator Ultimate 1.9 Setup.tmp (PID: 3340)
    • Uses NETSH.EXE for network configuration

      • Mini KMS Activator Ultimate 1.9 Setup.tmp (PID: 3340)
    • Starts CMD.EXE for commands execution

      • Mini KMS Activator Ultimate 1.9.exe (PID: 2184)
    • Executes scripts

      • cmd.exe (PID: 3140)
      • cmd.exe (PID: 2056)
  • INFO

    • Application was dropped or rewritten from another process

      • Mini KMS Activator Ultimate 1.9 Setup.tmp (PID: 2516)
      • Mini KMS Activator Ultimate 1.9 Setup.tmp (PID: 3340)
    • Manual execution by user

      • Mini KMS Activator Ultimate 1.9 Setup.exe (PID: 2840)
      • Mini KMS Activator Ultimate 1.9.exe (PID: 2184)
    • Creates files in the program directory

      • Mini KMS Activator Ultimate 1.9 Setup.tmp (PID: 3340)
    • Creates a software uninstall entry

      • Mini KMS Activator Ultimate 1.9 Setup.tmp (PID: 3340)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0002
ZipCompression: Deflated
ZipModifyDate: 2019:12:04 00:33:14
ZipCRC: 0x87db6bf0
ZipCompressedSize: 3890868
ZipUncompressedSize: 3916849
ZipFileName: Mini KMS Activator Ultimate 1.9 Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
22
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe notepad.exe no specs mini kms activator ultimate 1.9 setup.exe mini kms activator ultimate 1.9 setup.tmp no specs mini kms activator ultimate 1.9 setup.exe mini kms activator ultimate 1.9 setup.tmp netsh.exe no specs mini kms activator ultimate 1.9.exe cmd.exe cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs find.exe no specs ping.exe no specs cmd.exe cscript.exe no specs cscript.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
328cscript //nologo c:\windows\system32\slmgr.vbs /ipk W82YF-2Q76Y-63HXB-FGJG9-GF7QX C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
3221549077
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
688cscript //nologo c:\windows\system32\slmgr.vbs /ipk MRPKT-YTG23-K7D7T-X2JMM-QY7MG C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1048cscript //nologo c:\windows\system32\slmgr.vbs /ipk MRPKT-YTG23-K7D7T-X2JMM-QY7MG C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
3221549077
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1484"C:\Windows\system32\netsh.exe" advfirewall firewall add rule name="Mini KMS Activator Ultimate 1.9" program="C:\Program Files\Mini KMS Activator Ultimate 1.9\Mini KMS Activator Ultimate 1.9.exe" dir=in action=allow enable=yesC:\Windows\system32\netsh.exeMini KMS Activator Ultimate 1.9 Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1928cscript //nologo c:\windows\system32\slmgr.vbs /skms kms8.MSGuides.com C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2056"C:\Windows\System32\cmd.exe" /C "C:\Users\admin\AppData\Local\Temp\win7kms.cmd" C:\Windows\System32\cmd.exe
Mini KMS Activator Ultimate 1.9.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2064"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Mini_KMS_Activator_Ultimate_1.9.sanet.st.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2184"C:\Program Files\Mini KMS Activator Ultimate 1.9\Mini KMS Activator Ultimate 1.9.exe" C:\Program Files\Mini KMS Activator Ultimate 1.9\Mini KMS Activator Ultimate 1.9.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Win and Office Mini KMS Activator
Exit code:
0
Version:
1.9.0.0
Modules
Images
c:\program files\mini kms activator ultimate 1.9\mini kms activator ultimate 1.9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2492"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa2064.22521\Readme.txtC:\Windows\system32\NOTEPAD.EXEWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2516"C:\Users\admin\AppData\Local\Temp\is-HEAMC.tmp\Mini KMS Activator Ultimate 1.9 Setup.tmp" /SL5="$5013A,3656259,57856,C:\Users\admin\Desktop\Mini KMS Activator Ultimate 1.9 Setup.exe" C:\Users\admin\AppData\Local\Temp\is-HEAMC.tmp\Mini KMS Activator Ultimate 1.9 Setup.tmpMini KMS Activator Ultimate 1.9 Setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-heamc.tmp\mini kms activator ultimate 1.9 setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
1 463
Read events
1 331
Write events
126
Delete events
6

Modification events

(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2064) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Mini_KMS_Activator_Ultimate_1.9.sanet.st.zip
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(2492) NOTEPAD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosX
Value:
154
Executable files
6
Suspicious files
0
Text files
4
Unknown types
2

Dropped files

PID
Process
Filename
Type
3340Mini KMS Activator Ultimate 1.9 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 1.9\is-ASG76.tmp
MD5:
SHA256:
3340Mini KMS Activator Ultimate 1.9 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 1.9\is-9G4M3.tmp
MD5:
SHA256:
3340Mini KMS Activator Ultimate 1.9 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 1.9\is-PJ5HU.tmp
MD5:
SHA256:
3340Mini KMS Activator Ultimate 1.9 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 1.9\is-SVMJA.tmp
MD5:
SHA256:
3340Mini KMS Activator Ultimate 1.9 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 1.9\Mini KMS Activator Ultimate 1.9.exeexecutable
MD5:
SHA256:
2064WinRAR.exeC:\Users\admin\Desktop\Readme.txttext
MD5:
SHA256:
2064WinRAR.exeC:\Users\admin\Desktop\Mini KMS Activator Ultimate 1.9 Setup.exeexecutable
MD5:
SHA256:
3340Mini KMS Activator Ultimate 1.9 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 1.9\unins000.exeexecutable
MD5:
SHA256:
2840Mini KMS Activator Ultimate 1.9 Setup.exeC:\Users\admin\AppData\Local\Temp\is-HEAMC.tmp\Mini KMS Activator Ultimate 1.9 Setup.tmpexecutable
MD5:832DAB307E54AA08F4B6CDD9B9720361
SHA256:CC783A04CCBCA4EDD06564F8EC88FE5A15F1E3BB26CEC7DE5E090313520D98F3
3340Mini KMS Activator Ultimate 1.9 Setup.tmpC:\Users\Public\Desktop\Mini KMS Activator Ultimate 1.9.lnklnk
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
2
DNS requests
4
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2184
Mini KMS Activator Ultimate 1.9.exe
GET
200
104.219.248.105:80
http://renewsoftware.com/2019win10kms/Version.txt
US
text
7 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2184
Mini KMS Activator Ultimate 1.9.exe
104.219.248.105:80
renewsoftware.com
Namecheap, Inc.
US
malicious
2128
sppsvc.exe
193.29.63.133:1688
kms8.MSGuides.com
suspicious

DNS requests

Domain
IP
Reputation
renewsoftware.com
  • 104.219.248.105
malicious
kms8.MSGuides.com
  • 193.29.63.133
suspicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info