File name:

DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe

Full analysis: https://app.any.run/tasks/a8542df1-5e16-44f3-8d12-b2e0ed02b72a
Verdict: Malicious activity
Threats:

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.

Analysis date: March 25, 2024, 21:21:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
redline
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E784871B03036596699BD694D137E685

SHA1:

31785A76AC15BCF2EF1E701A8619421531C34EF2

SHA256:

2B50B78F45AEB5D3F395719518E62E68A4F64FE4B94F62837FFBF22D11879023

SSDEEP:

12288:VtIAlouyt8wNKgLnXYGaO113YWCvCYmRPy/+vgnFWvAWQ9ypHnwOf:VtIAlouyt8wNKgLnXTaI13YWCvCYoPyA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe (PID: 1836)
    • REDLINE has been detected (YARA)

      • Usermode Font Driver Host.exe (PID: 2208)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe (PID: 1836)
    • Reads the date of Windows installation

      • DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe (PID: 1836)
    • The process creates files with name similar to system file names

      • DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe (PID: 1836)
    • Reads security settings of Internet Explorer

      • DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe (PID: 1836)
    • Reads the Internet Settings

      • DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe (PID: 1836)
    • Application launched itself

      • Usermode Font Driver Host.exe (PID: 2892)
  • INFO

    • Reads the computer name

      • DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe (PID: 1836)
      • DDDL_Activator.exe (PID: 3940)
    • Create files in a temporary directory

      • DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe (PID: 1836)
    • Reads the machine GUID from the registry

      • DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe (PID: 1836)
      • DDDL_Activator.exe (PID: 3940)
    • Checks supported languages

      • DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe (PID: 1836)
      • DDDL_Activator.exe (PID: 3940)
      • Usermode Font Driver Host.exe (PID: 2208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

RedLine

(PID) Process(2208) Usermode Font Driver Host.exe
C2 (1)85.209.88.31:54041
Botnetr1
Keys
Xor
Options
ErrorMessage
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.3)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:12:29 12:41:30+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 1.73
CodeSize: 160768
InitializedDataSize: 135168
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 1
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileDescription: KeygenApp
ProductName: KeygenApp
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
LegalCopyright: Copyright © 2022
OriginalFileName: KeygenApp.exe
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start dddl 8.15, 8.16 keygen level 10 pc unlocked.exe dddl_activator.exe no specs usermode font driver host.exe no specs #REDLINE usermode font driver host.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1836"C:\Users\admin\Desktop\DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe" C:\Users\admin\Desktop\DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\dddl 8.15, 8.16 keygen level 10 pc unlocked.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2208"C:\Users\admin\AppData\Local\Temp\Usermode Font Driver Host.exe"C:\Users\admin\AppData\Local\Temp\Usermode Font Driver Host.exe
Usermode Font Driver Host.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\usermode font driver host.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
RedLine
(PID) Process(2208) Usermode Font Driver Host.exe
C2 (1)85.209.88.31:54041
Botnetr1
Keys
Xor
Options
ErrorMessage
2892"C:\Users\admin\AppData\Local\Temp\Usermode Font Driver Host.exe" C:\Users\admin\AppData\Local\Temp\Usermode Font Driver Host.exeDDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\usermode font driver host.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
3940"C:\Users\admin\AppData\Local\Temp\DDDL_Activator.exe" C:\Users\admin\AppData\Local\Temp\DDDL_Activator.exeDDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exe
User:
admin
Integrity Level:
MEDIUM
Description:
KeygenApp
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\dddl_activator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
6 054
Read events
5 934
Write events
120
Delete events
0

Modification events

(PID) Process:(1836) DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1836) DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1836) DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1836) DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1836) DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
2
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1836DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exeC:\Users\admin\AppData\Local\Temp\DDDL_Activator.exeexecutable
MD5:FA533C92DFE96A0868A8C13E05A44C13
SHA256:AB0A3E042C1E321A242221F1EAD7100EE34EC84276B4ADE88B2895708E78C614
1836DDDL 8.15, 8.16 KEYGEN LEVEL 10 PC UNLOCKED.exeC:\Users\admin\AppData\Local\Temp\Usermode Font Driver Host.exeexecutable
MD5:810570D755E60DF665D900B150491484
SHA256:771517244569A6C9FB07C5D7647AC81ACE7E0471ED4EBD6BCA30777DC6F71E4F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info