File name:

Driver MVCI_X64.rar

Full analysis: https://app.any.run/tasks/ee1feef1-55ba-4701-b058-aa2a4772a740
Verdict: Malicious activity
Analysis date: November 23, 2024, 15:35:36
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

AD70019EFB806A01E518C3741FA16CBB

SHA1:

B314DB126C1BE563636DD878F536AEB826352373

SHA256:

BC7E527CAA3D64A6209DEF8A98294580F81CFBF8DFD5DEEC34C4C48021A8CA5B

SSDEEP:

98304:2XNVavfwN4YY7MbVs87GbgTH69kvbm8y6SmorgR+:ch4YkUTHEkvq85ww+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 3992)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • AutokentMultiDriverMVCI_X64.tmp (PID: 4544)
    • Executable content was dropped or overwritten

      • AutokentMultiDriverMVCI_X64.exe (PID: 1596)
      • AutokentMultiDriverMVCI_X64.exe (PID: 3208)
      • AutokentMultiDriverMVCI_X64.tmp (PID: 4544)
    • Drops a system driver (possible attempt to evade defenses)

      • AutokentMultiDriverMVCI_X64.tmp (PID: 4544)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 3730722
UncompressedSize: 3761081
OperatingSystem: Win32
ArchivedFileName: AutokentMultiDriverMVCI_X64.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
6
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe autokentmultidrivermvci_x64.exe autokentmultidrivermvci_x64.tmp no specs autokentmultidrivermvci_x64.exe autokentmultidrivermvci_x64.tmp mvci_multix64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1596"C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe
WinRAR.exe
User:
admin
Company:
Autokent
Integrity Level:
MEDIUM
Description:
Autokent MVCI MultiDriver X64 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3992.46830\autokentmultidrivermvci_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
3208"C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe" /SPAWNWND=$901FE /NOTIFYWND=$50316 C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe
AutokentMultiDriverMVCI_X64.tmp
User:
admin
Company:
Autokent
Integrity Level:
HIGH
Description:
Autokent MVCI MultiDriver X64 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3992.46830\autokentmultidrivermvci_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3992"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Driver MVCI_X64.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4228"C:\Program Files (x86)\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe"C:\Program Files (x86)\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exeAutokentMultiDriverMVCI_X64.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
MVCI_MultiX64
Version:
1.0.0.0
Modules
Images
c:\program files (x86)\autokent mvci multidriver x64\mvci_multix64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4544"C:\Users\admin\AppData\Local\Temp\is-9M29V.tmp\AutokentMultiDriverMVCI_X64.tmp" /SL5="$702B4,3506206,69120,C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe" /SPAWNWND=$901FE /NOTIFYWND=$50316 C:\Users\admin\AppData\Local\Temp\is-9M29V.tmp\AutokentMultiDriverMVCI_X64.tmp
AutokentMultiDriverMVCI_X64.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9m29v.tmp\autokentmultidrivermvci_x64.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5728"C:\Users\admin\AppData\Local\Temp\is-MUP55.tmp\AutokentMultiDriverMVCI_X64.tmp" /SL5="$50316,3506206,69120,C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exe" C:\Users\admin\AppData\Local\Temp\is-MUP55.tmp\AutokentMultiDriverMVCI_X64.tmpAutokentMultiDriverMVCI_X64.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-mup55.tmp\autokentmultidrivermvci_x64.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
Total events
2 473
Read events
2 446
Write events
27
Delete events
0

Modification events

(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Driver MVCI_X64.rar
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4544) AutokentMultiDriverMVCI_X64.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D3A3A607-D612-4854-B3F1-4836D9490871}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.6 (a)
(PID) Process:(4544) AutokentMultiDriverMVCI_X64.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D3A3A607-D612-4854-B3F1-4836D9490871}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\Autokent MVCI MultiDriver X64
Executable files
175
Suspicious files
27
Text files
0
Unknown types
16

Dropped files

PID
Process
Filename
Type
3208AutokentMultiDriverMVCI_X64.exeC:\Users\admin\AppData\Local\Temp\is-9M29V.tmp\AutokentMultiDriverMVCI_X64.tmpexecutable
MD5:B4EBC9B42BD39411AB6A75B3E7442F95
SHA256:3834C8EE40F71FA1DC8C3B236588E2FF9926D773609B8B806E1F26AE975B2B48
4544AutokentMultiDriverMVCI_X64.tmpC:\Users\admin\AppData\Local\Temp\is-76MHC.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
4544AutokentMultiDriverMVCI_X64.tmpC:\Program Files (x86)\Autokent MVCI MultiDriver X64\is-9J60P.tmpexecutable
MD5:63D913D5878954F6B40750EC05954EF8
SHA256:2A3D1FF8C02C9F14D547E1D3D94243CFF4F180E5DE7BD3490582A15DB5FA09FC
4544AutokentMultiDriverMVCI_X64.tmpC:\Program Files (x86)\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exeexecutable
MD5:0A27417A233561F63DB1CFAF05EC90B4
SHA256:D2AB675DF5792130ED26E5FC3B50F159FD3EA2DDCCE9681ABFB56EAA158F2014
3992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3992.46830\AutokentMultiDriverMVCI_X64.exeexecutable
MD5:D8EEE94E8F2526738972F75EFAA62877
SHA256:A58FB038D398B06061907D4CA63B48E7D5C7F8ED1BDB93741A4009CCEAA77CF6
1596AutokentMultiDriverMVCI_X64.exeC:\Users\admin\AppData\Local\Temp\is-MUP55.tmp\AutokentMultiDriverMVCI_X64.tmpexecutable
MD5:B4EBC9B42BD39411AB6A75B3E7442F95
SHA256:3834C8EE40F71FA1DC8C3B236588E2FF9926D773609B8B806E1F26AE975B2B48
4544AutokentMultiDriverMVCI_X64.tmpC:\Program Files (x86)\Autokent MVCI MultiDriver X64\unins000.exeexecutable
MD5:63D913D5878954F6B40750EC05954EF8
SHA256:2A3D1FF8C02C9F14D547E1D3D94243CFF4F180E5DE7BD3490582A15DB5FA09FC
4544AutokentMultiDriverMVCI_X64.tmpC:\Program Files (x86)\Autokent MVCI MultiDriver X64\1.4.4\is-M0HHD.tmpexecutable
MD5:5C46E1B62BA9BED54C339CB28FC978EA
SHA256:381117C743766E3A696609BB29CA075772AA603CFF196E16C3854C06EE1AB254
4544AutokentMultiDriverMVCI_X64.tmpC:\Program Files (x86)\Autokent MVCI MultiDriver X64\1.4.4\is-H5MHE.tmpexecutable
MD5:DEF91FB3AC2DED4A564B2CCAAFF5B4F8
SHA256:32CD7C8ED249D3A04D1488008FC4965BBC2B8285FDE70D481DC8580E5B58B399
4544AutokentMultiDriverMVCI_X64.tmpC:\Program Files (x86)\Autokent MVCI MultiDriver X64\1.4.4\MVCI32.dllexecutable
MD5:DEF91FB3AC2DED4A564B2CCAAFF5B4F8
SHA256:32CD7C8ED249D3A04D1488008FC4965BBC2B8285FDE70D481DC8580E5B58B399
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
33
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5240
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5472
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5472
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4976
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.186:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 172.217.18.110
whitelisted
www.bing.com
  • 104.126.37.186
  • 104.126.37.171
  • 104.126.37.162
  • 104.126.37.163
  • 104.126.37.137
  • 104.126.37.131
  • 104.126.37.153
  • 104.126.37.130
  • 104.126.37.170
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.71
  • 20.190.159.2
  • 20.190.159.0
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
No debug info