| File name: | Mini.KMS.AU.2.0.rar |
| Full analysis: | https://app.any.run/tasks/f35e9d35-8119-4332-88d8-a066eab0d208 |
| Verdict: | Malicious activity |
| Analysis date: | January 27, 2020, 14:01:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | C27C1D1E58DC48F1980164C301E3C0B8 |
| SHA1: | 4C646DDA39DA81B8AB3F665B005108963FA60683 |
| SHA256: | D09679D72109E586E0BBDA2BB4EE2EEC27432666C534445D68A4CF6018026F48 |
| SSDEEP: | 49152:G3sr36Mq8oAtQQFrcqz3uemSexO/lW0bezjzHDxPZoCq7fz/10tMCZ87/txovd:EsL6n8oAKqrcvi8LQ/7fJ0txQ/md |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 3897181 |
|---|---|
| UncompressedSize: | 3916355 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2020:01:20 11:17:02 |
| PackingMethod: | Normal |
| ArchivedFileName: | Mini.KMS.Activator.Ultimate.2.0.KaranPC\Mini KMS Activator Ultimate 2.0 Setup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 816 | cscript //nologo c:\windows\system32\slmgr.vbs /ato | C:\Windows\system32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 944 | "C:\Users\admin\AppData\Local\Temp\is-CTPN1.tmp\Mini KMS Activator Ultimate 2.0 Setup.tmp" /SL5="$701EA,3655766,57856,C:\Users\admin\Desktop\Mini.KMS.AU.2.0\Mini.KMS.Activator.Ultimate.2.0.KaranPC\Mini KMS Activator Ultimate 2.0 Setup.exe" | C:\Users\admin\AppData\Local\Temp\is-CTPN1.tmp\Mini KMS Activator Ultimate 2.0 Setup.tmp | — | Mini KMS Activator Ultimate 2.0 Setup.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 1168 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Mini.KMS.AU.2.0.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 1356 | cscript //nologo slmgr.vbs /cpky | C:\Windows\system32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 1456 | cscript //nologo c:\windows\system32\slmgr.vbs /skms kms8.MSGuides.com | C:\Windows\system32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 1780 | "C:\Windows\System32\cmd.exe" /C "C:\Users\admin\AppData\Local\Temp\office2010kms.cmd" | C:\Windows\System32\cmd.exe | Mini KMS Activator Ultimate 2.0.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1836 | cscript //nologo ospp.vbs /inpkey:V7QKV-4XVVR-XYV4D-F7DFM-8R6BM | C:\Windows\system32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 1876 | cscript //nologo slmgr.vbs /skms kms.chinancce.com | C:\Windows\system32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2132 | cscript //nologo c:\windows\system32\slmgr.vbs /ipk YDRBP-3D83W-TY26F-D46B2-XCKRJ | C:\Windows\system32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 3221549077 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2148 | cscript //nologo slmgr.vbs /ipk MH37W-N47XK-V7XM9-C7227-GCQG9 | C:\Windows\system32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 3221549136 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| (PID) Process: | (1168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1168) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Mini.KMS.AU.2.0.rar | |||
| (PID) Process: | (1168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Mini.KMS.AU.2.0 | |||
| (PID) Process: | (1168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3392 | Mini KMS Activator Ultimate 2.0 Setup.tmp | C:\Program Files\Mini KMS Activator Ultimate 2.0\is-ATRT7.tmp | — | |
MD5:— | SHA256:— | |||
| 3392 | Mini KMS Activator Ultimate 2.0 Setup.tmp | C:\Program Files\Mini KMS Activator Ultimate 2.0\is-S4CGA.tmp | — | |
MD5:— | SHA256:— | |||
| 3392 | Mini KMS Activator Ultimate 2.0 Setup.tmp | C:\Program Files\Mini KMS Activator Ultimate 2.0\is-C7FH0.tmp | — | |
MD5:— | SHA256:— | |||
| 3392 | Mini KMS Activator Ultimate 2.0 Setup.tmp | C:\Program Files\Mini KMS Activator Ultimate 2.0\is-4CMQM.tmp | — | |
MD5:— | SHA256:— | |||
| 3612 | digital.license.activation.exe | C:\Users\admin\AppData\Local\Temp\nsu8C8B.tmp | — | |
MD5:— | SHA256:— | |||
| 3392 | Mini KMS Activator Ultimate 2.0 Setup.tmp | C:\Program Files\Mini KMS Activator Ultimate 2.0\unins000.exe | executable | |
MD5:— | SHA256:— | |||
| 3392 | Mini KMS Activator Ultimate 2.0 Setup.tmp | C:\Program Files\Mini KMS Activator Ultimate 2.0\unins000.dat | dat | |
MD5:— | SHA256:— | |||
| 3392 | Mini KMS Activator Ultimate 2.0 Setup.tmp | C:\Program Files\Mini KMS Activator Ultimate 2.0\Mini KMS Activator Ultimate 2.0.exe | executable | |
MD5:— | SHA256:— | |||
| 2456 | Mini KMS Activator Ultimate 2.0.exe | C:\Users\admin\AppData\Local\Temp\win7kms.cmd | text | |
MD5:— | SHA256:— | |||
| 2456 | Mini KMS Activator Ultimate 2.0.exe | C:\Users\admin\AppData\Local\Temp\win10kms.cmd | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3784 | wmiprvse.exe | POST | 302 | 2.19.153.179:80 | http://go.microsoft.com/fwlink/?LinkID=120750 | unknown | — | — | whitelisted |
2456 | Mini KMS Activator Ultimate 2.0.exe | GET | 200 | 104.219.248.105:80 | http://renewsoftware.com/2019win10kms/Version.txt | US | text | 7 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2456 | Mini KMS Activator Ultimate 2.0.exe | 104.219.248.105:80 | renewsoftware.com | Namecheap, Inc. | US | malicious |
3784 | wmiprvse.exe | 2.19.153.179:80 | go.microsoft.com | Akamai Technologies, Inc. | — | whitelisted |
3052 | sppsvc.exe | 193.29.63.133:1688 | kms8.MSGuides.com | — | — | suspicious |
3784 | wmiprvse.exe | 52.230.223.232:443 | activation.sls.microsoft.com | Microsoft Corporation | US | unknown |
Domain | IP | Reputation |
|---|---|---|
renewsoftware.com |
| malicious |
kms8.MSGuides.com |
| suspicious |
go.microsoft.com |
| whitelisted |
activation.sls.microsoft.com |
| whitelisted |