File name:

Driver MVCI_X64.rar

Full analysis: https://app.any.run/tasks/6d909fee-0f68-45f4-b061-5c6dc5e33ebb
Verdict: Malicious activity
Analysis date: July 08, 2023, 21:28:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

AD70019EFB806A01E518C3741FA16CBB

SHA1:

B314DB126C1BE563636DD878F536AEB826352373

SHA256:

BC7E527CAA3D64A6209DEF8A98294580F81CFBF8DFD5DEEC34C4C48021A8CA5B

SSDEEP:

98304:2XNVavfwN4YY7MbVs87GbgTH69kvbm8y6SmorgR+:ch4YkUTHEkvq85ww+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • AutokentMultiDriverMVCI_X64.exe (PID: 2236)
      • AutokentMultiDriverMVCI_X64.exe (PID: 3164)
      • MVCI_MultiX64.exe (PID: 3004)
      • MVCI_MultiX64.exe (PID: 240)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • AutokentMultiDriverMVCI_X64.tmp (PID: 2104)
    • Drops a system driver (possible attempt to evade defenses)

      • AutokentMultiDriverMVCI_X64.tmp (PID: 2104)
    • Reads Internet Explorer settings

      • MVCI_MultiX64.exe (PID: 3004)
      • MVCI_MultiX64.exe (PID: 240)
    • Executable content was dropped or overwritten

      • AutokentMultiDriverMVCI_X64.tmp (PID: 2104)
      • AutokentMultiDriverMVCI_X64.exe (PID: 3164)
      • AutokentMultiDriverMVCI_X64.exe (PID: 2236)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3528)
    • Create files in a temporary directory

      • AutokentMultiDriverMVCI_X64.exe (PID: 2236)
      • AutokentMultiDriverMVCI_X64.tmp (PID: 2104)
      • AutokentMultiDriverMVCI_X64.exe (PID: 3164)
    • Checks supported languages

      • AutokentMultiDriverMVCI_X64.tmp (PID: 2104)
      • AutokentMultiDriverMVCI_X64.exe (PID: 3164)
      • MVCI_MultiX64.exe (PID: 3004)
      • MVCI_MultiX64.exe (PID: 240)
      • AutokentMultiDriverMVCI_X64.exe (PID: 2236)
      • AutokentMultiDriverMVCI_X64.tmp (PID: 3636)
    • Application was dropped or rewritten from another process

      • AutokentMultiDriverMVCI_X64.tmp (PID: 3636)
      • AutokentMultiDriverMVCI_X64.tmp (PID: 2104)
    • Creates files in the program directory

      • AutokentMultiDriverMVCI_X64.tmp (PID: 2104)
    • Reads the computer name

      • MVCI_MultiX64.exe (PID: 3004)
      • AutokentMultiDriverMVCI_X64.tmp (PID: 2104)
      • MVCI_MultiX64.exe (PID: 240)
      • AutokentMultiDriverMVCI_X64.tmp (PID: 3636)
    • The process checks LSA protection

      • MVCI_MultiX64.exe (PID: 3004)
      • AutokentMultiDriverMVCI_X64.tmp (PID: 2104)
      • MVCI_MultiX64.exe (PID: 240)
      • mmc.exe (PID: 3204)
      • AutokentMultiDriverMVCI_X64.tmp (PID: 3636)
    • Reads the machine GUID from the registry

      • MVCI_MultiX64.exe (PID: 3004)
      • MVCI_MultiX64.exe (PID: 240)
    • Manual execution by a user

      • MVCI_MultiX64.exe (PID: 240)
      • mmc.exe (PID: 2828)
      • mmc.exe (PID: 3204)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
9
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start winrar.exe autokentmultidrivermvci_x64.exe autokentmultidrivermvci_x64.tmp no specs autokentmultidrivermvci_x64.exe autokentmultidrivermvci_x64.tmp mvci_multix64.exe no specs mvci_multix64.exe mmc.exe no specs mmc.exe

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe" C:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
MVCI_MultiX64
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\autokent mvci multidriver x64\mvci_multix64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2104"C:\Users\admin\AppData\Local\Temp\is-URS7B.tmp\AutokentMultiDriverMVCI_X64.tmp" /SL5="$A0150,3506206,69120,C:\Users\admin\AppData\Local\Temp\Rar$EXa3528.19119\AutokentMultiDriverMVCI_X64.exe" /SPAWNWND=$7014C /NOTIFYWND=$E0172 C:\Users\admin\AppData\Local\Temp\is-URS7B.tmp\AutokentMultiDriverMVCI_X64.tmp
AutokentMultiDriverMVCI_X64.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-urs7b.tmp\autokentmultidrivermvci_x64.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2236"C:\Users\admin\AppData\Local\Temp\Rar$EXa3528.19119\AutokentMultiDriverMVCI_X64.exe" /SPAWNWND=$7014C /NOTIFYWND=$E0172 C:\Users\admin\AppData\Local\Temp\Rar$EXa3528.19119\AutokentMultiDriverMVCI_X64.exe
AutokentMultiDriverMVCI_X64.tmp
User:
admin
Company:
Autokent
Integrity Level:
HIGH
Description:
Autokent MVCI MultiDriver X64 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3528.19119\autokentmultidrivermvci_x64.exe
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
2828"C:\Windows\system32\mmc.exe" C:\Windows\system32\devmgmt.mscC:\Windows\System32\mmc.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Management Console
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mmc.exe
c:\windows\system32\ntdll.dll
3004"C:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe"C:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exeAutokentMultiDriverMVCI_X64.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
MVCI_MultiX64
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\autokent mvci multidriver x64\mvci_multix64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3164"C:\Users\admin\AppData\Local\Temp\Rar$EXa3528.19119\AutokentMultiDriverMVCI_X64.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3528.19119\AutokentMultiDriverMVCI_X64.exe
WinRAR.exe
User:
admin
Company:
Autokent
Integrity Level:
MEDIUM
Description:
Autokent MVCI MultiDriver X64 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3528.19119\autokentmultidrivermvci_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3204"C:\Windows\system32\mmc.exe" C:\Windows\system32\devmgmt.mscC:\Windows\System32\mmc.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Management Console
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mmc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
3528"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Driver MVCI_X64.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
3636"C:\Users\admin\AppData\Local\Temp\is-4MFOO.tmp\AutokentMultiDriverMVCI_X64.tmp" /SL5="$E0172,3506206,69120,C:\Users\admin\AppData\Local\Temp\Rar$EXa3528.19119\AutokentMultiDriverMVCI_X64.exe" C:\Users\admin\AppData\Local\Temp\is-4MFOO.tmp\AutokentMultiDriverMVCI_X64.tmpAutokentMultiDriverMVCI_X64.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\is-4mfoo.tmp\autokentmultidrivermvci_x64.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
Total events
2 473
Read events
2 436
Write events
30
Delete events
7

Modification events

(PID) Process:(3528) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
175
Suspicious files
42
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2104AutokentMultiDriverMVCI_X64.tmpC:\Users\admin\AppData\Local\Temp\is-D68AU.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3528.19119\AutokentMultiDriverMVCI_X64.exeexecutable
MD5:D8EEE94E8F2526738972F75EFAA62877
SHA256:A58FB038D398B06061907D4CA63B48E7D5C7F8ED1BDB93741A4009CCEAA77CF6
3164AutokentMultiDriverMVCI_X64.exeC:\Users\admin\AppData\Local\Temp\is-4MFOO.tmp\AutokentMultiDriverMVCI_X64.tmpexecutable
MD5:B4EBC9B42BD39411AB6A75B3E7442F95
SHA256:3834C8EE40F71FA1DC8C3B236588E2FF9926D773609B8B806E1F26AE975B2B48
2104AutokentMultiDriverMVCI_X64.tmpC:\Program Files\Autokent MVCI MultiDriver X64\is-IG89G.tmpexecutable
MD5:0A27417A233561F63DB1CFAF05EC90B4
SHA256:D2AB675DF5792130ED26E5FC3B50F159FD3EA2DDCCE9681ABFB56EAA158F2014
2104AutokentMultiDriverMVCI_X64.tmpC:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exeexecutable
MD5:0A27417A233561F63DB1CFAF05EC90B4
SHA256:D2AB675DF5792130ED26E5FC3B50F159FD3EA2DDCCE9681ABFB56EAA158F2014
2104AutokentMultiDriverMVCI_X64.tmpC:\Program Files\Autokent MVCI MultiDriver X64\is-GOU1Q.tmpexecutable
MD5:63D913D5878954F6B40750EC05954EF8
SHA256:2A3D1FF8C02C9F14D547E1D3D94243CFF4F180E5DE7BD3490582A15DB5FA09FC
2104AutokentMultiDriverMVCI_X64.tmpC:\Program Files\Autokent MVCI MultiDriver X64\1.4.3\is-2HR0U.tmpexecutable
MD5:5C46E1B62BA9BED54C339CB28FC978EA
SHA256:381117C743766E3A696609BB29CA075772AA603CFF196E16C3854C06EE1AB254
2104AutokentMultiDriverMVCI_X64.tmpC:\Program Files\Autokent MVCI MultiDriver X64\1.4.3\is-GIV2T.tmpexecutable
MD5:EAA0A5CBA5450C649435EE4C5CB31881
SHA256:7A239E9C3E64A896E675D8D946A888AE8C251A0727CAA897AC67C949247E26F0
2236AutokentMultiDriverMVCI_X64.exeC:\Users\admin\AppData\Local\Temp\is-URS7B.tmp\AutokentMultiDriverMVCI_X64.tmpexecutable
MD5:B4EBC9B42BD39411AB6A75B3E7442F95
SHA256:3834C8EE40F71FA1DC8C3B236588E2FF9926D773609B8B806E1F26AE975B2B48
2104AutokentMultiDriverMVCI_X64.tmpC:\Program Files\Autokent MVCI MultiDriver X64\1.4.3\ftd2xx.dllexecutable
MD5:5C46E1B62BA9BED54C339CB28FC978EA
SHA256:381117C743766E3A696609BB29CA075772AA603CFF196E16C3854C06EE1AB254
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2624
svchost.exe
239.255.255.250:1900
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info