| URL: | https://crackfullkey.net/krisp-1-2-4-0-crack/ |
| Full analysis: | https://app.any.run/tasks/a6b31476-6cf9-4a7e-96e8-3ec56058f99b |
| Verdict: | Malicious activity |
| Threats: | Ficker Stealer is a malware that steals passwords, files, credit card details, and other types of sensitive information on Windows systems. It is most often distributed via phishing emails and can perform keylogging, process injection, and browser tracking. |
| Analysis date: | May 12, 2021, 12:59:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 87F60D33A225DD6ABB7106F96649AC8C |
| SHA1: | 335B4ACCE4E15653140F48044F0994D0B015439A |
| SHA256: | 3A6E2FE14CF43376A0979B7AED8A6903C92A4BB6F6D693617065646DFFAD0384 |
| SSDEEP: | 3:N8KXAhz4MWVImK:2KXAh0MWLK |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=1020,13835415206607230711,2177565802310897027,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3860 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 328 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=1020,13835415206607230711,2177565802310897027,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1768 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 544 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.FileUtilService --field-trial-handle=1020,13835415206607230711,2177565802310897027,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=3144 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 560 | C:\Windows\system32\cmd.exe /c metina_10.exe | C:\Windows\system32\cmd.exe | — | setup_install.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 620 | metina_4.exe | C:\Users\admin\AppData\Local\Temp\7zS44AC4362\metina_4.exe | cmd.exe | ||||||||||||
User: admin Company: SAystemStrAing Integrity Level: HIGH Description: SAystemStrAing Exit code: 0 Version: 1.0.11.1 Modules
| |||||||||||||||
| 668 | C:\Windows\system32\cmd.exe /c metina_9.exe | C:\Windows\system32\cmd.exe | — | setup_install.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 696 | metina_8.exe | C:\Users\admin\AppData\Local\Temp\7zS44AC4362\metina_8.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Loader Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 880 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\system32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1060 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,13835415206607230711,2177565802310897027,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3836 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1120 | C:\Windows\system32\cmd.exe /c metina_2.exe | C:\Windows\system32\cmd.exe | — | setup_install.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3056) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3056) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3056) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (3056) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3056) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3056) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3056) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3056) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3056) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid |
Value: | |||
| (PID) Process: | (3056) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_installdate |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3056 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-609BD137-BF0.pma | — | |
MD5:— | SHA256:— | |||
| 3056 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\127d5f7a-4e42-41e5-bb2e-1ed1fd155565.tmp | text | |
MD5:— | SHA256:— | |||
| 3056 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences | text | |
MD5:— | SHA256:— | |||
| 2400 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma | binary | |
MD5:03C4F648043A88675A920425D824E1B3 | SHA256:F91DBB7C64B4582F529C968C480D2DCE1C8727390482F31E4355A27BB3D9B450 | |||
| 3056 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF11c5dd.TMP | text | |
MD5:936EB7280DA791E6DD28EF3A9B46D39C | SHA256:CBAF2AFD831B32F6D1C12337EE5D2F090D6AE1F4DCB40B08BEF49BF52AD9721F | |||
| 3056 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:9C016064A1F864C8140915D77CF3389A | SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787 | |||
| 3056 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:5BD3C311F2136A7A88D3E197E55CF902 | SHA256:FA331915E1797E59979A3E4BCC2BD0D3DEAA039B94D4DB992BE251FD02A224B9 | |||
| 3056 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF11c5ed.TMP | text | |
MD5:81F483F77EE490F35306A4F94DB2286B | SHA256:82434CE3C9D13F509EBEEBE3A7A1A1DE9AB4557629D9FC855761E0CFA45E8BCE | |||
| 3056 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF11c716.TMP | text | |
MD5:B628564B8042F6E2CC2F53710AAECDC0 | SHA256:1D3B022BDEE9F48D79E3EC1E93F519036003642D3D72D10B05CFD47F43EFBF13 | |||
| 3056 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old | text | |
MD5:7721CDA9F5B73CE8A135471EB53B4E0E | SHA256:DD730C576766A46FFC84E682123248ECE1FF1887EC0ACAB22A5CE93A450F4500 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1624 | chrome.exe | GET | 301 | 104.21.51.176:80 | http://centomor.xyz/?s=163&q=Krisp-1233-Crack---Registration-Key-Free-Download-2021&g=53bebb64b81758ebdb9ed81a986196da&mode= | US | — | — | malicious |
2800 | setup_install.exe | GET | — | 172.67.165.117:80 | http://estrix.xyz/addInstall.php?key=125478824515ADNxu2ccbwe&ip=&oid=139&oname[]=12MAY325PM&oname[]=7&oname[]=1&oname[]=2&oname[]=3&oname[]=4&oname[]=5&oname[]=6&oname[]=8&cnt=8 | US | — | — | malicious |
1624 | chrome.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D | US | der | 471 b | whitelisted |
1624 | chrome.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEAqN7HPiQ2%2F4c3rdXE3uHG8%3D | US | der | 471 b | whitelisted |
1624 | chrome.exe | GET | 302 | 54.188.82.217:80 | http://54.188.82.217/?t=163&q=Krisp-1233-Crack---Registration-Key-Free-Download-2021&dedica= | US | html | 1.47 Kb | unknown |
1624 | chrome.exe | POST | 200 | 54.188.82.217:80 | http://54.188.82.217/?d09c9ed9433387c0d616645fedc99409472b5059=16604ae0a30a008b14b&dedica=&q=Krisp-1233-Crack---Registration-Key-Free-Download-2021&verify-id=163&vh=b7e004f766620da405f0a6ba3bb08c2663a9a4f3%3E | US | html | 4.38 Kb | unknown |
1624 | chrome.exe | GET | 200 | 54.188.82.217:80 | http://54.188.82.217/?cloudx=96a0e3d02e19e&dedica=&verify-id=163&verify-hash=fd93751649ac3ea8f8772ba49c8c1fe068002835&verify-msch=S3Jpc3AtMTIzMy1DcmFjay0tLVJlZ2lzdHJhdGlvbi1LZXktRnJlZS1Eb3dubG9hZC0yMDIx&download=1&xtrans=MTM4 | US | compressed | 3.18 Mb | unknown |
2800 | setup_install.exe | GET | 200 | 172.67.165.117:80 | http://estrix.xyz/addInstallImpression.php?key=125478824515ADNxu2ccbwe&ip=&oid=139 | US | — | — | malicious |
1624 | chrome.exe | GET | 200 | 104.16.19.94:80 | http://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/4.1.0/css/bootstrap.min.css | US | text | 20.4 Kb | whitelisted |
1624 | chrome.exe | GET | 200 | 104.16.19.94:80 | http://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css | US | text | 6.71 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1624 | chrome.exe | 142.250.186.129:443 | 4.bp.blogspot.com | Google Inc. | US | whitelisted |
1624 | chrome.exe | 172.217.16.142:443 | clients2.google.com | Google Inc. | US | whitelisted |
1624 | chrome.exe | 142.250.186.45:443 | accounts.google.com | Google Inc. | US | suspicious |
1624 | chrome.exe | 80.82.77.242:443 | crackfullkey.net | Quasi Networks LTD. | SC | suspicious |
1624 | chrome.exe | 142.250.184.234:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
1624 | chrome.exe | 192.0.77.37:443 | c0.wp.com | Automattic, Inc | US | suspicious |
1624 | chrome.exe | 67.199.248.11:443 | bit.ly | Bitly Inc | US | shared |
1624 | chrome.exe | 142.250.185.110:443 | encrypted-tbn0.gstatic.com | Google Inc. | US | whitelisted |
1624 | chrome.exe | 92.122.244.64:80 | ctldl.windowsupdate.com | GTT Communications Inc. | FR | unknown |
1624 | chrome.exe | 142.250.186.35:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clients2.google.com |
| whitelisted |
crackfullkey.net |
| malicious |
accounts.google.com |
| shared |
c0.wp.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
s.w.org |
| whitelisted |
bit.ly |
| shared |
ctldl.windowsupdate.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
encrypted-tbn0.gstatic.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1624 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2800 | setup_install.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2800 | setup_install.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
1592 | metina_5.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup ip-api.com |
1592 | metina_5.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
696 | metina_8.exe | A Network Trojan was detected | ET INFO Executable Download from dotted-quad Host |
696 | metina_8.exe | Potential Corporate Privacy Violation | AV POLICY HTTP request for .exe file with no User-Agent |
— | — | Potentially Bad Traffic | ET DNS Query to a *.pw domain - Likely Hostile |
696 | metina_8.exe | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 22 |
696 | metina_8.exe | A Network Trojan was detected | ET INFO Executable Download from dotted-quad Host |