File name: | XLN_KeyGen.exe |
Full analysis: | https://app.any.run/tasks/f2801cb2-288a-440d-aadb-02bf42cc7db6 |
Verdict: | Malicious activity |
Analysis date: | January 23, 2024, 01:28:09 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
MD5: | 952D893926DF7A8D5879F2FFEB96E96E |
SHA1: | 2A2F3FAA2C7670A52E27B838C81737E6C9B4F965 |
SHA256: | 0C10769B277CF217DAE2877ECD476E70413907F4EB7A70DE55C2FBA4EDC947EA |
SSDEEP: | 24576:UcLjNw85Iyerj0xe41VExk6DVPiFeoMkPr4Q:UAemLEj0xeuqifPr4Q |
.exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
---|---|---|
.exe | | | Win64 Executable (generic) (37.3) |
.dll | | | Win32 Dynamic Link Library (generic) (8.8) |
.exe | | | Win32 Executable (generic) (6) |
.exe | | | Generic Win/DOS Executable (2.7) |
Subsystem: | Windows GUI |
---|---|
SubsystemVersion: | 4 |
ImageVersion: | 6 |
OSVersion: | 4 |
EntryPoint: | 0x326c |
UninitializedDataSize: | 1024 |
InitializedDataSize: | 120320 |
CodeSize: | 24064 |
LinkerVersion: | 6 |
PEType: | PE32 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
TimeStamp: | 2016:04:02 05:20:09+02:00 |
MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
124 | "C:\Users\admin\AppData\Local\Temp\XLN_KeyGen.exe" | C:\Users\admin\AppData\Local\Temp\XLN_KeyGen.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
2408 | "C:\Users\admin\AppData\Local\Temp\XLN_KeyGen.exe" | C:\Users\admin\AppData\Local\Temp\XLN_KeyGen.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
1392 | C:\Users\admin\AppData\Local\Temp\keygen.exe | C:\Users\admin\AppData\Local\Temp\keygen.exe | — | XLN_KeyGen.exe | |||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
2628 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\LicensesOI.txt | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (1392) keygen.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
Operation: | write | Name: | NodeSlots |
Value: 020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
(PID) Process: | (1392) keygen.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
Operation: | write | Name: | MRUListEx |
Value: 06000000000000000B0000000100000002000000070000000C0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF | |||
(PID) Process: | (1392) keygen.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (1392) keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU |
Operation: | write | Name: | MRUListEx |
Value: 020000000100000000000000FFFFFFFF | |||
(PID) Process: | (1392) keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\* |
Operation: | write | Name: | MRUListEx |
Value: 0B0000000A00000009000000080000000700000006000000050000000400000003000000020000000100000000000000FFFFFFFF | |||
(PID) Process: | (1392) keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
Operation: | delete value | Name: | 4 |
Value: 6B0065007900670065006E002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000 | |||
(PID) Process: | (1392) keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
Operation: | delete value | Name: | 4 |
Value: 6B0065007900670065006E002E00650078006500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000D020000950000008D04000075020000000000000000000000000000000000000100000000000000 | |||
(PID) Process: | (1392) keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
Operation: | write | Name: | MRUListEx |
Value: 02000000030000000000000001000000FFFFFFFF | |||
(PID) Process: | (1392) keygen.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} |
Operation: | write | Name: | Mode |
Value: 6 | |||
(PID) Process: | (1392) keygen.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} |
Operation: | write | Name: | LogicalViewMode |
Value: 2 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2408 | XLN_KeyGen.exe | C:\Users\admin\AppData\Local\Temp\bgm.mod | binary | |
MD5:179949DB15DC96C6F242C1969A033543 | SHA256:7AA1E2789C5222A5CDD09125CB268A28569A482E7CED85B150B27E0C57AD1E9A | |||
2408 | XLN_KeyGen.exe | C:\Users\admin\AppData\Local\Temp\keygen.exe | executable | |
MD5:2CF51F0737FF7C3B804F5C9646B627C7 | SHA256:5C9509349F39B2FCADE22EB219126D45831920FCB4F319191F2F4A9E7643371A | |||
2408 | XLN_KeyGen.exe | C:\Users\admin\AppData\Local\Temp\R2RXLNKG.dll | executable | |
MD5:EDC9D719C3BDB5702E28ABF9DF8359B6 | SHA256:76D9FFEEB89773C56D58FD8935C2D310AACDAE3B590F3CC7AA24ED267339A735 | |||
2408 | XLN_KeyGen.exe | C:\Users\admin\AppData\Local\Temp\BASSMOD.dll | executable | |
MD5:E4EC57E8508C5C4040383EBE6D367928 | SHA256:8AD9E47693E292F381DA42DDC13724A3063040E51C26F4CA8E1F8E2F1DDD547F | |||
1392 | keygen.exe | C:\ProgramData\XLN Audio\XLN Online Installer\App\Licenses\LicensesOI.txt | text | |
MD5:80FE1291C4C9C4F93657051578BA54B8 | SHA256:1D4FE5A826AFA323EDA7AC3543FAFE8A3F1CA2ED1FD5E2114CC13A6CAE67C158 | |||
1392 | keygen.exe | C:\Users\admin\Desktop\LicensesOI.txt | text | |
MD5:85CE02BAC7739CAE56CD2AF64CAFE379 | SHA256:7325DBAE77E29D903BBF44B082E46F0F3B43F3F27A0FC01203ED431BC429B53B |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |