| File name: | Driver MVCI_X64.rar |
| Full analysis: | https://app.any.run/tasks/ee1feef1-55ba-4701-b058-aa2a4772a740 |
| Verdict: | Malicious activity |
| Analysis date: | November 23, 2024, 15:35:36 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | AD70019EFB806A01E518C3741FA16CBB |
| SHA1: | B314DB126C1BE563636DD878F536AEB826352373 |
| SHA256: | BC7E527CAA3D64A6209DEF8A98294580F81CFBF8DFD5DEEC34C4C48021A8CA5B |
| SSDEEP: | 98304:2XNVavfwN4YY7MbVs87GbgTH69kvbm8y6SmorgR+:ch4YkUTHEkvq85ww+ |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
| FileVersion: | RAR v5 |
|---|---|
| CompressedSize: | 3730722 |
| UncompressedSize: | 3761081 |
| OperatingSystem: | Win32 |
| ArchivedFileName: | AutokentMultiDriverMVCI_X64.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1596 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe | WinRAR.exe | ||||||||||||
User: admin Company: Autokent Integrity Level: MEDIUM Description: Autokent MVCI MultiDriver X64 Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3208 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe" /SPAWNWND=$901FE /NOTIFYWND=$50316 | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe | AutokentMultiDriverMVCI_X64.tmp | ||||||||||||
User: admin Company: Autokent Integrity Level: HIGH Description: Autokent MVCI MultiDriver X64 Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3992 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Driver MVCI_X64.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 4228 | "C:\Program Files (x86)\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe" | C:\Program Files (x86)\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe | — | AutokentMultiDriverMVCI_X64.tmp | |||||||||||
User: admin Integrity Level: MEDIUM Description: MVCI_MultiX64 Version: 1.0.0.0 Modules
| |||||||||||||||
| 4544 | "C:\Users\admin\AppData\Local\Temp\is-9M29V.tmp\AutokentMultiDriverMVCI_X64.tmp" /SL5="$702B4,3506206,69120,C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe" /SPAWNWND=$901FE /NOTIFYWND=$50316 | C:\Users\admin\AppData\Local\Temp\is-9M29V.tmp\AutokentMultiDriverMVCI_X64.tmp | AutokentMultiDriverMVCI_X64.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 5728 | "C:\Users\admin\AppData\Local\Temp\is-MUP55.tmp\AutokentMultiDriverMVCI_X64.tmp" /SL5="$50316,3506206,69120,C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe" | C:\Users\admin\AppData\Local\Temp\is-MUP55.tmp\AutokentMultiDriverMVCI_X64.tmp | — | AutokentMultiDriverMVCI_X64.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Driver MVCI_X64.rar | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (4544) AutokentMultiDriverMVCI_X64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D3A3A607-D612-4854-B3F1-4836D9490871}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.6 (a) | |||
| (PID) Process: | (4544) AutokentMultiDriverMVCI_X64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D3A3A607-D612-4854-B3F1-4836D9490871}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files (x86)\Autokent MVCI MultiDriver X64 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3208 | AutokentMultiDriverMVCI_X64.exe | C:\Users\admin\AppData\Local\Temp\is-9M29V.tmp\AutokentMultiDriverMVCI_X64.tmp | executable | |
MD5:B4EBC9B42BD39411AB6A75B3E7442F95 | SHA256:3834C8EE40F71FA1DC8C3B236588E2FF9926D773609B8B806E1F26AE975B2B48 | |||
| 4544 | AutokentMultiDriverMVCI_X64.tmp | C:\Users\admin\AppData\Local\Temp\is-76MHC.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 4544 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files (x86)\Autokent MVCI MultiDriver X64\is-9J60P.tmp | executable | |
MD5:63D913D5878954F6B40750EC05954EF8 | SHA256:2A3D1FF8C02C9F14D547E1D3D94243CFF4F180E5DE7BD3490582A15DB5FA09FC | |||
| 4544 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files (x86)\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe | executable | |
MD5:0A27417A233561F63DB1CFAF05EC90B4 | SHA256:D2AB675DF5792130ED26E5FC3B50F159FD3EA2DDCCE9681ABFB56EAA158F2014 | |||
| 3992 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe | executable | |
MD5:D8EEE94E8F2526738972F75EFAA62877 | SHA256:A58FB038D398B06061907D4CA63B48E7D5C7F8ED1BDB93741A4009CCEAA77CF6 | |||
| 1596 | AutokentMultiDriverMVCI_X64.exe | C:\Users\admin\AppData\Local\Temp\is-MUP55.tmp\AutokentMultiDriverMVCI_X64.tmp | executable | |
MD5:B4EBC9B42BD39411AB6A75B3E7442F95 | SHA256:3834C8EE40F71FA1DC8C3B236588E2FF9926D773609B8B806E1F26AE975B2B48 | |||
| 4544 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files (x86)\Autokent MVCI MultiDriver X64\unins000.exe | executable | |
MD5:63D913D5878954F6B40750EC05954EF8 | SHA256:2A3D1FF8C02C9F14D547E1D3D94243CFF4F180E5DE7BD3490582A15DB5FA09FC | |||
| 4544 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files (x86)\Autokent MVCI MultiDriver X64\1.4.4\is-M0HHD.tmp | executable | |
MD5:5C46E1B62BA9BED54C339CB28FC978EA | SHA256:381117C743766E3A696609BB29CA075772AA603CFF196E16C3854C06EE1AB254 | |||
| 4544 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files (x86)\Autokent MVCI MultiDriver X64\1.4.4\is-H5MHE.tmp | executable | |
MD5:DEF91FB3AC2DED4A564B2CCAAFF5B4F8 | SHA256:32CD7C8ED249D3A04D1488008FC4965BBC2B8285FDE70D481DC8580E5B58B399 | |||
| 4544 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files (x86)\Autokent MVCI MultiDriver X64\1.4.4\MVCI32.dll | executable | |
MD5:DEF91FB3AC2DED4A564B2CCAAFF5B4F8 | SHA256:32CD7C8ED249D3A04D1488008FC4965BBC2B8285FDE70D481DC8580E5B58B399 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5240 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5472 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5472 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4976 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 104.126.37.186:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |