AhnLab

  • Privacy & Security
  • EULA
  • Contact Us
  • Terms of Use
  • Sitemap

Subscribe to Our Newsletter

Stay informed with AhnLab’s latest threat intelligence
and security insights delivered monthly to your inbox.

Country
AhnLab V3 Engine VersionOES :
Update Engine Now →
  • Visit our LinkedIn Profile
  • Visit our Twitter page
  • Visit our YouTube channel
  • © AhnLab, Inc. All rights reserved.
  • ASEC
  • MyCompany(ELS)
  • AhnLab Document Center
    • Contact Us
    • My Company
    • Security Map
Article
12-13-2018

Malware Disguised as a Windows Activator

Malware that disguises itself as an official Windows activation tool has been found. It is designed to target users of pirated Windows software who are not using the genuine Windows activation software. 

 

  

[Figure 1] Overall execution process of the malware

 

As shown in Figure 1, the ransomware runs the KMSPico10.2.1.exe file to create a batch file, KMSPICO_SETUP.bat, which conducts malicious behavior. The created batch file executes KMSPicoActivator.exe, which conducts the activation of Windows to deceive users with a fake activation process. Then it executes the Registry_Activation.exe file that registers to the registry and the Activation.exe file, which is a miner. 

 

 

[Figure 2] KMSPICO_SETUP Batch File

 

Looking at the contents of the generated batch file in Figure 2, this malware displays the progress, such as 47% and 78% to make it seem that the installation and patching are in progress. But, in fact, it is internally executing the, Registry_Activation.exe and activation.exe files. 

 

Activation.exe uses a configuration file similar to that of a Windows-based mining program called XMRig- which mines Monero. Moreover, this file is assumed to have the role of a miner as it continuously attempts to connect to xmr.pool.minergate.com and sends the mining information to cryptocurrency wallets. 

 

This malware is disguised as a Windows activator on the surface, but internally it is a miner engaging in mining activities using the resources of the user's PC. Many malwares are disguised as popular programs or cracked versions of such programs and spread through unofficial sites, such as file sharing websites. Therefore, in order to prevent infections, it is safest to download software from the official website.

 

The alias identified by AhnLab's anti-malware solution, AhnLab V3, is as below:

- Malware/Win32.Generic

List

Related Content

Article

AhnLab V3 Earns VB100 Certification with Grade A+

AhnLab V3 Earns VB100 Certification with Grade A+

White Paper

How Agentic AI Is Reshaping the Role of Security Admins

How Agentic AI Is Reshaping the Role of Security Admins

Article

AhnLab Partners with the Korean National Police Agency to Combat Phishing Crimes

AhnLab Partners with the Korean National Police Agency to Combat Phishing Crimes

Article

The Evolution of AI-Powered Hacking Tools

The Evolution of AI-Powered Hacking Tools

skip navigation
  • 메뉴
  • 본문
  • 하단 정보(링크)
  • Products
    • AhnLab PLUS Platform
    • AhnLab Endpoint PLUS
      • Anti-Malware
      • EPP
      • Sandbox (ATD)
      • EDR
      • SMB Security
      • Mobile Security
    • AhnLab Network PLUS
      • NGFW
      • IPS
      • DDoS Mitigation
      • Sandbox (ATD)
      • Threat Management
    • AhnLab Cloud PLUS
      • CWPP
      • Cloud NGFW
      • Cloud IPS
      • Cloud Threat Management
    • AhnLab Connect PLUS
      • XDR
      • Threat Intelligence
      • SOAR
    • AhnLab CPS PLUS
      • CPS Protection Management
      • OT Endpoint Protection
      • OT IDS
      • OT Portable AV
      • OT Firewall
      • OT Data Diode
      • OT Network Sandbox
      • IT Endpoint Protection
      • IT Anti-Malware
      • CPS Threat Intelligence
    • AhnLab AI PLUS
    • All Products and Services
  • Services
    • AhnLab Service PLUS
      • MDR
      • MSS
      • Professional Service
      • Security Consulting
      • Digital Forensics
      • Cloud Managed Service
      • Global Partners
    • All Products and Services
  • Solution
    • Ransomware Protection
    • Hybrid Cloud Security
    • Zero Trust
    • CPS Protection
    • SOC Modernization
    • TDR
    • DDoS Mitigation
  • Support
    • Technical Support
    • Threat Inquiry
    • Online Support
      • Q&A
    • Notice
    • Download
    • AhnLab Document Center
  • Content Center
    • Content Center
    • ASEC
      • Threat Descriptions
      • Threat Actor Naming
      • ASEC Security Advisory
      • ASEC Blog
    • Highlights
      • MITRE ATT&CK Eval Round 7
      • AhnLab 30th Anniversary
      • Frost Radar CPS Security Leader
  • Partners
  • Company
    • About Us
    • Strategic Materials
my page
Sign InSign Up
언어 선택

No recent searches