File name:

Mini.KMS.AU.2.0.rar

Full analysis: https://app.any.run/tasks/f35e9d35-8119-4332-88d8-a066eab0d208
Verdict: Malicious activity
Analysis date: January 27, 2020, 14:01:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

C27C1D1E58DC48F1980164C301E3C0B8

SHA1:

4C646DDA39DA81B8AB3F665B005108963FA60683

SHA256:

D09679D72109E586E0BBDA2BB4EE2EEC27432666C534445D68A4CF6018026F48

SSDEEP:

49152:G3sr36Mq8oAtQQFrcqz3uemSexO/lW0bezjzHDxPZoCq7fz/10tMCZ87/txovd:EsL6n8oAKqrcvi8LQ/7fJ0txQ/md

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Mini KMS Activator Ultimate 2.0 Setup.exe (PID: 2884)
      • Mini KMS Activator Ultimate 2.0 Setup.exe (PID: 3100)
      • Mini KMS Activator Ultimate 2.0.exe (PID: 2456)
      • digital.license.activation.exe (PID: 3612)
      • AutoHotkey.exe (PID: 2752)
    • Adds new firewall rule via NETSH.EXE

      • Mini KMS Activator Ultimate 2.0 Setup.tmp (PID: 3392)
    • Runs PING.EXE for delay simulation

      • cmd.exe (PID: 3884)
    • Loads dropped or rewritten executable

      • Mini KMS Activator Ultimate 2.0.exe (PID: 2456)
      • digital.license.activation.exe (PID: 3612)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Mini KMS Activator Ultimate 2.0 Setup.exe (PID: 3100)
      • WinRAR.exe (PID: 1168)
      • Mini KMS Activator Ultimate 2.0 Setup.exe (PID: 2884)
      • Mini KMS Activator Ultimate 2.0 Setup.tmp (PID: 3392)
      • Mini KMS Activator Ultimate 2.0.exe (PID: 2456)
      • digital.license.activation.exe (PID: 3612)
    • Modifies the phishing filter of IE

      • Mini KMS Activator Ultimate 2.0 Setup.tmp (PID: 3392)
    • Uses NETSH.EXE for network configuration

      • Mini KMS Activator Ultimate 2.0 Setup.tmp (PID: 3392)
    • Executes scripts

      • cmd.exe (PID: 3884)
      • cmd.exe (PID: 1780)
      • cmd.exe (PID: 3020)
    • Starts CMD.EXE for commands execution

      • Mini KMS Activator Ultimate 2.0.exe (PID: 2456)
  • INFO

    • Manual execution by user

      • Mini KMS Activator Ultimate 2.0 Setup.exe (PID: 2884)
      • Mini KMS Activator Ultimate 2.0.exe (PID: 2456)
    • Application was dropped or rewritten from another process

      • Mini KMS Activator Ultimate 2.0 Setup.tmp (PID: 3392)
      • Mini KMS Activator Ultimate 2.0 Setup.tmp (PID: 944)
    • Creates files in the program directory

      • Mini KMS Activator Ultimate 2.0 Setup.tmp (PID: 3392)
    • Creates a software uninstall entry

      • Mini KMS Activator Ultimate 2.0 Setup.tmp (PID: 3392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 3897181
UncompressedSize: 3916355
OperatingSystem: Win32
ModifyDate: 2020:01:20 11:17:02
PackingMethod: Normal
ArchivedFileName: Mini.KMS.Activator.Ultimate.2.0.KaranPC\Mini KMS Activator Ultimate 2.0 Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
108
Monitored processes
46
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe mini kms activator ultimate 2.0 setup.exe mini kms activator ultimate 2.0 setup.tmp no specs mini kms activator ultimate 2.0 setup.exe mini kms activator ultimate 2.0 setup.tmp netsh.exe no specs mini kms activator ultimate 2.0.exe cmd.exe cscript.exe no specs cscript.exe no specs wmic.exe no specs findstr.exe no specs wmic.exe no specs findstr.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs find.exe no specs cscript.exe no specs cscript.exe no specs find.exe no specs cscript.exe no specs cscript.exe no specs find.exe no specs cmd.exe cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs find.exe no specs ping.exe no specs digital.license.activation.exe autohotkey.exe no specs cmd.exe cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs find.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
816cscript //nologo c:\windows\system32\slmgr.vbs /ato C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
944"C:\Users\admin\AppData\Local\Temp\is-CTPN1.tmp\Mini KMS Activator Ultimate 2.0 Setup.tmp" /SL5="$701EA,3655766,57856,C:\Users\admin\Desktop\Mini.KMS.AU.2.0\Mini.KMS.Activator.Ultimate.2.0.KaranPC\Mini KMS Activator Ultimate 2.0 Setup.exe" C:\Users\admin\AppData\Local\Temp\is-CTPN1.tmp\Mini KMS Activator Ultimate 2.0 Setup.tmpMini KMS Activator Ultimate 2.0 Setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ctpn1.tmp\mini kms activator ultimate 2.0 setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1168"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Mini.KMS.AU.2.0.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1356cscript //nologo slmgr.vbs /cpky C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1456cscript //nologo c:\windows\system32\slmgr.vbs /skms kms8.MSGuides.com C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1780"C:\Windows\System32\cmd.exe" /C "C:\Users\admin\AppData\Local\Temp\office2010kms.cmd" C:\Windows\System32\cmd.exe
Mini KMS Activator Ultimate 2.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1836cscript //nologo ospp.vbs /inpkey:V7QKV-4XVVR-XYV4D-F7DFM-8R6BM C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1876cscript //nologo slmgr.vbs /skms kms.chinancce.com C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2132cscript //nologo c:\windows\system32\slmgr.vbs /ipk YDRBP-3D83W-TY26F-D46B2-XCKRJ C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
3221549077
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2148cscript //nologo slmgr.vbs /ipk MH37W-N47XK-V7XM9-C7227-GCQG9 C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
3221549136
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
1 797
Read events
1 662
Write events
129
Delete events
6

Modification events

(PID) Process:(1168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1168) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Mini.KMS.AU.2.0.rar
(PID) Process:(1168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Mini.KMS.AU.2.0
(PID) Process:(1168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
12
Suspicious files
0
Text files
6
Unknown types
2

Dropped files

PID
Process
Filename
Type
3392Mini KMS Activator Ultimate 2.0 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 2.0\is-ATRT7.tmp
MD5:
SHA256:
3392Mini KMS Activator Ultimate 2.0 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 2.0\is-S4CGA.tmp
MD5:
SHA256:
3392Mini KMS Activator Ultimate 2.0 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 2.0\is-C7FH0.tmp
MD5:
SHA256:
3392Mini KMS Activator Ultimate 2.0 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 2.0\is-4CMQM.tmp
MD5:
SHA256:
3612digital.license.activation.exeC:\Users\admin\AppData\Local\Temp\nsu8C8B.tmp
MD5:
SHA256:
3392Mini KMS Activator Ultimate 2.0 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 2.0\unins000.exeexecutable
MD5:
SHA256:
3392Mini KMS Activator Ultimate 2.0 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 2.0\unins000.datdat
MD5:
SHA256:
3392Mini KMS Activator Ultimate 2.0 Setup.tmpC:\Program Files\Mini KMS Activator Ultimate 2.0\Mini KMS Activator Ultimate 2.0.exeexecutable
MD5:
SHA256:
2456Mini KMS Activator Ultimate 2.0.exeC:\Users\admin\AppData\Local\Temp\win7kms.cmdtext
MD5:
SHA256:
2456Mini KMS Activator Ultimate 2.0.exeC:\Users\admin\AppData\Local\Temp\win10kms.cmdtext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
4
DNS requests
5
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3784
wmiprvse.exe
POST
302
2.19.153.179:80
http://go.microsoft.com/fwlink/?LinkID=120750
unknown
whitelisted
2456
Mini KMS Activator Ultimate 2.0.exe
GET
200
104.219.248.105:80
http://renewsoftware.com/2019win10kms/Version.txt
US
text
7 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2456
Mini KMS Activator Ultimate 2.0.exe
104.219.248.105:80
renewsoftware.com
Namecheap, Inc.
US
malicious
3784
wmiprvse.exe
2.19.153.179:80
go.microsoft.com
Akamai Technologies, Inc.
whitelisted
3052
sppsvc.exe
193.29.63.133:1688
kms8.MSGuides.com
suspicious
3784
wmiprvse.exe
52.230.223.232:443
activation.sls.microsoft.com
Microsoft Corporation
US
unknown

DNS requests

Domain
IP
Reputation
renewsoftware.com
  • 104.219.248.105
malicious
kms8.MSGuides.com
  • 193.29.63.133
suspicious
go.microsoft.com
  • 2.19.153.179
whitelisted
activation.sls.microsoft.com
  • 52.230.223.232
whitelisted

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info