File name:

KInstall.exe.7z

Full analysis: https://app.any.run/tasks/1049e191-1bd5-44ee-b2ab-526575579938
Verdict: Malicious activity
Analysis date: March 01, 2024, 18:31:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

51D1217CE12D6C5CFAEBD48DC88176CD

SHA1:

B297ADA2BF5FD687312ECF57E20B3879560C6531

SHA256:

B7EB20DCC834FD83352DA788AE532C1AEFE6A665F9A9FCB7A97D9907C625FCC8

SSDEEP:

98304:I07VK1cXLh8nHjBTRnFNft32kQue2HEp21f1XAfSEWaVKayNHa8M9Tg5ssagGOtc:ZKBEi4qKQkB4A0Cp6hGAgZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • KInstall.exe (PID: 3724)
      • WinRAR.exe (PID: 3240)
      • VC_redist.x64.exe (PID: 2724)
      • VC_redist.x64.exe (PID: 2744)
    • Changes the autorun value in the registry

      • KInstall.exe (PID: 3724)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • KInstall.exe (PID: 3724)
    • Executable content was dropped or overwritten

      • KInstall.exe (PID: 3724)
      • VC_redist.x64.exe (PID: 2724)
      • VC_redist.x64.exe (PID: 2744)
    • Reads the Internet Settings

      • KInstall.exe (PID: 3724)
    • Searches for installed software

      • KInstall.exe (PID: 3724)
      • VC_redist.x64.exe (PID: 2744)
    • Reads settings of System Certificates

      • KInstall.exe (PID: 3724)
    • Checks Windows Trust Settings

      • KInstall.exe (PID: 3724)
    • Starts a Microsoft application from unusual location

      • VC_redist.x64.exe (PID: 2744)
      • VC_redist.x64.exe (PID: 2724)
    • Process drops legitimate windows executable

      • VC_redist.x64.exe (PID: 2724)
      • KInstall.exe (PID: 3724)
  • INFO

    • Manual execution by a user

      • KInstall.exe (PID: 3392)
      • KInstall.exe (PID: 3724)
      • cmd.exe (PID: 2328)
      • wmpnscfg.exe (PID: 680)
    • Create files in a temporary directory

      • KInstall.exe (PID: 3724)
      • VC_redist.x64.exe (PID: 2744)
    • Reads the computer name

      • KInstall.exe (PID: 3724)
      • VC_redist.x64.exe (PID: 2744)
      • wmpnscfg.exe (PID: 680)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3240)
    • Reads the machine GUID from the registry

      • KInstall.exe (PID: 3724)
    • Checks supported languages

      • VC_redist.x64.exe (PID: 2724)
      • wmpnscfg.exe (PID: 680)
      • VC_redist.x64.exe (PID: 2744)
      • KInstall.exe (PID: 3724)
    • Checks proxy server information

      • KInstall.exe (PID: 3724)
    • Reads the software policy settings

      • KInstall.exe (PID: 3724)
    • Creates files or folders in the user directory

      • KInstall.exe (PID: 3724)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe cmd.exe kinstall.exe no specs kinstall.exe vc_redist.x64.exe vc_redist.x64.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2328"C:\Windows\System32\cmd.exe" C:\Windows\System32\cmd.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2724"C:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\{3F0609AB-9F5A-4252-869F-AFD6EF94631A}\VC_redist.x64.exe" /q /norestartC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\{3F0609AB-9F5A-4252-869F-AFD6EF94631A}\VC_redist.x64.exe
KInstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30153
Exit code:
1
Version:
14.29.30153.0
Modules
Images
c:\users\admin\appdata\local\temp\{3ea929bc-5f26-4d4d-a7d1-20c698d84359}\{3f0609ab-9f5a-4252-869f-afd6ef94631a}\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2744"C:\Windows\Temp\{37E575A6-69C4-4A7A-818C-3D56E891A47F}\.cr\VC_redist.x64.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\{3F0609AB-9F5A-4252-869F-AFD6EF94631A}\VC_redist.x64.exe" -burn.filehandle.attached=152 -burn.filehandle.self=160 /q /norestartC:\Windows\Temp\{37E575A6-69C4-4A7A-818C-3D56E891A47F}\.cr\VC_redist.x64.exe
VC_redist.x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30153
Exit code:
1
Version:
14.29.30153.0
Modules
Images
c:\windows\temp\{37e575a6-69c4-4a7a-818c-3d56e891a47f}\.cr\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3240"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\KInstall.exe.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3392"C:\Users\admin\Desktop\KInstall.exe" C:\Users\admin\Desktop\KInstall.exeexplorer.exe
User:
admin
Company:
Kaseya
Integrity Level:
MEDIUM
Description:
InstallScript Setup Launcher
Exit code:
3221226540
Version:
9.5.18.1105
Modules
Images
c:\users\admin\desktop\kinstall.exe
c:\windows\system32\ntdll.dll
3724"C:\Users\admin\Desktop\KInstall.exe" C:\Users\admin\Desktop\KInstall.exe
explorer.exe
User:
admin
Company:
Kaseya
Integrity Level:
HIGH
Description:
InstallScript Setup Launcher
Exit code:
0
Version:
9.5.18.1105
Modules
Images
c:\users\admin\desktop\kinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
12 939
Read events
12 836
Write events
88
Delete events
15

Modification events

(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3240) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\KInstall.exe.7z
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
23
Suspicious files
8
Text files
64
Unknown types
3

Dropped files

PID
Process
Filename
Type
3724KInstall.exeC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\Disk1\ISSetup.dllexecutable
MD5:C5E7C495ED4644F46DEC884CDD2ACD54
SHA256:DA30A9E6304C22FEB626E5FB41F44AED11AE3AD36D50676F97250C6A1DA6D052
3724KInstall.exeC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\Disk1\ISSetupPrerequisites\Microsoft .NET Framework 4.0 Full.prqxml
MD5:C500D7636C74A40F8E47CEBEFB5EAF4A
SHA256:B5F37B1260E6133D7939909FA02BB451CF298F6A2D3FE404F097592E3A520D99
3724KInstall.exeC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\Disk1\ISSetupPrerequisites\Microsoft Visual C++ 2019 Redistributable Package (x86).prqxml
MD5:668AFF0BA02B718616F2E3F7B9062898
SHA256:41ABB4A97C61F0D8B7846C1F40DACD0A695A670E800BFE9AB6B74E5BF75A6771
3724KInstall.exeC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\Disk1\ISSetupPrerequisites\Windows Imaging Component (x64).prqxml
MD5:D62628E0FF64047B5062B039C9ED483C
SHA256:48BF0BD3F2288621BFFE796A0CFDB2F6C8C513CBAA06A5AAE502164ABCA419D4
3724KInstall.exeC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\Disk1\ISSetupPrerequisites\Microsoft Visual C++ 2019 Redistributable Package (x64).prqxml
MD5:6032D6BC4CCF96C506530DA1F0DA320E
SHA256:C592A864EA5200035EEAB100D63E0AB4F9A3107FFDD01A8554377A8385FB38A7
3724KInstall.exeC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\Disk1\data1.cabcompressed
MD5:80FA14D9C02B2652D5D6E4F50C4BE971
SHA256:53E6AAFDBB88B48C1299C5CBD2C83166C5CC4F39DDA9C8E6DF2BD28CA259468B
3724KInstall.exeC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\Disk1\ISSetupPrerequisites\Microsoft .NET Framework 4.7.2 Full.prqxml
MD5:4D8F22DAAD858E87EC34DBABC9291FD8
SHA256:7CA40E58BF8069D462A18DFD6A465B0A75E6FDF18D96CC039E67625CE2E73D5E
3724KInstall.exeC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\Disk1\ISSetupPrerequisites\Microsoft .NET Framework 3.5 SP1.prqxml
MD5:3303B85D71D9C3B959F960E88153C777
SHA256:D471AA7CECBDB930273473BC04BBAD06A067BEC4EA87311E12C038ED12AC8BD2
3724KInstall.exeC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\Disk1\ISSetupPrerequisites\Microsoft .NET Framework 2.0 SP2 (x64).prqxml
MD5:742D3DCC987D8FE31CC2CDE2EA5B9DD3
SHA256:6F40A10436CA8A63E44C83F22C6FDC45CB6FDA5F83166FB5D8D1B13942340C4E
3724KInstall.exeC:\Users\admin\AppData\Local\Temp\{3EA929BC-5F26-4D4D-A7D1-20C698D84359}\Disk1\ISSetupPrerequisites\Microsoft .NET Framework 2.0 SP2.prqxml
MD5:82718CDB9029782463D386C9384B8829
SHA256:3F7BAA00B860558C550D88B8EBB530B8B593DED1A48DB19C32CF952BAB89E7A8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
10
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3724
KInstall.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?dc05e2f1193aa105
unknown
unknown
3724
KInstall.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?89bca2e7018c82c0
unknown
compressed
67.5 Kb
unknown
3724
KInstall.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3724
KInstall.exe
184.24.201.247:443
aka.ms
AKAMAI-AS
IE
unknown
3724
KInstall.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
3724
KInstall.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3724
KInstall.exe
68.232.34.200:443
download.visualstudio.microsoft.com
EDGECAST
US
whitelisted
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
aka.ms
  • 184.24.201.247
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
download.visualstudio.microsoft.com
  • 68.232.34.200
whitelisted

Threats

No threats detected
No debug info