File name:

Keygen.exe

Full analysis: https://app.any.run/tasks/0efca782-247e-4cee-b760-6a6364570783
Verdict: Malicious activity
Analysis date: May 31, 2024, 09:46:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A9548D1B4BA54CB31F7EF2D64DA69B61

SHA1:

08E658D5B7B6099B91454E2E9F1615987C364E76

SHA256:

43B03A7E39A5F695BED5F76A422DBF117A5DD04982D44574DDF4FFA0F248154B

SSDEEP:

12288:qVv1b4VoN2ATgnYmKW0HEQq38vEMcCL7U:qVv1kqgnYDFHEQq38vhcCLg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Keygen.exe (PID: 4088)
      • portmapper_setup.exe (PID: 328)
      • portmapper_setup.exe (PID: 588)
      • portmapper_setup.tmp (PID: 1664)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • portmapper_setup.exe (PID: 328)
      • portmapper_setup.tmp (PID: 1664)
      • portmapper_setup.exe (PID: 588)
      • Keygen.exe (PID: 4088)
    • Reads the Windows owner or organization settings

      • portmapper_setup.tmp (PID: 1664)
    • Creates file in the systems drive root

      • Keygen.exe (PID: 4088)
    • Reads the Internet Settings

      • NSMapGUI.exe (PID: 1640)
  • INFO

    • Checks supported languages

      • Keygen.exe (PID: 4088)
      • portmapper_setup.exe (PID: 328)
      • portmapper_setup.tmp (PID: 1440)
      • portmapper_setup.tmp (PID: 1664)
      • portmapper_setup.exe (PID: 588)
      • NSMapGUI.exe (PID: 1640)
      • NSMapGUI.exe (PID: 2448)
    • Reads the computer name

      • Keygen.exe (PID: 4088)
      • portmapper_setup.tmp (PID: 1440)
      • portmapper_setup.tmp (PID: 1664)
      • NSMapGUI.exe (PID: 1640)
      • NSMapGUI.exe (PID: 2448)
    • Create files in a temporary directory

      • portmapper_setup.exe (PID: 588)
      • portmapper_setup.exe (PID: 328)
    • Manual execution by a user

      • portmapper_setup.exe (PID: 328)
      • NSMapGUI.exe (PID: 1640)
      • notepad++.exe (PID: 2528)
      • explorer.exe (PID: 2564)
      • NSMapGUI.exe (PID: 2448)
      • WINWORD.EXE (PID: 676)
    • Creates files in the program directory

      • portmapper_setup.tmp (PID: 1664)
      • Keygen.exe (PID: 4088)
    • Reads the machine GUID from the registry

      • NSMapGUI.exe (PID: 1640)
    • Creates a software uninstall entry

      • portmapper_setup.tmp (PID: 1664)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (38.3)
.exe | Win32 Executable (generic) (26.2)
.exe | Win16/32 Executable Delphi generic (12)
.exe | Generic Win/DOS Executable (11.6)
.exe | DOS Executable Generic (11.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:09:25 09:23:48+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 221184
InitializedDataSize: 40960
UninitializedDataSize: 442368
EntryPoint: 0xa1e90
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: RadiXX11
FileDescription: Softperfect Products Keygen
FileVersion: 1.0.0.0
InternalName: Keygen.exe
LegalCopyright: © 2018, RadiXX11
LegalTrademarks: -
OriginalFileName: Keygen.exe
ProductName: Softperfect Products Keygen
ProductVersion: 1.0.0.0
Comments: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
13
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start keygen.exe portmapper_setup.exe portmapper_setup.tmp no specs portmapper_setup.exe portmapper_setup.tmp nsmapgui.exe no specs notepad++.exe nsmapgui.exe no specs winword.exe no specs PhotoViewer.dll no specs explorer.exe no specs PhotoViewer.dll no specs keygen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
328"C:\Users\admin\Desktop\portmapper_setup.exe" C:\Users\admin\Desktop\portmapper_setup.exe
explorer.exe
User:
admin
Company:
SoftPerfect Pty Ltd
Integrity Level:
MEDIUM
Description:
SoftPerfect Switch Port Mapper
Exit code:
0
Version:
2.1.1
Modules
Images
c:\users\admin\desktop\portmapper_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
588"C:\Users\admin\Desktop\portmapper_setup.exe" /SPAWNWND=$2017C /NOTIFYWND=$20178 C:\Users\admin\Desktop\portmapper_setup.exe
portmapper_setup.tmp
User:
admin
Company:
SoftPerfect Pty Ltd
Integrity Level:
HIGH
Description:
SoftPerfect Switch Port Mapper
Exit code:
0
Version:
2.1.1
Modules
Images
c:\users\admin\desktop\portmapper_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
676"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\requirementsengineering.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
904C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1440"C:\Users\admin\AppData\Local\Temp\is-H0NMS.tmp\portmapper_setup.tmp" /SL5="$20178,4841627,121344,C:\Users\admin\Desktop\portmapper_setup.exe" C:\Users\admin\AppData\Local\Temp\is-H0NMS.tmp\portmapper_setup.tmpportmapper_setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-h0nms.tmp\portmapper_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1640"C:\Program Files\SoftPerfect Switch Port Mapper\NSMapGUI.exe" C:\Program Files\SoftPerfect Switch Port Mapper\NSMapGUI.exeexplorer.exe
User:
admin
Company:
SoftPerfect Pty Ltd
Integrity Level:
MEDIUM
Description:
SoftPerfect Switch Port Mapper (32-bit)
Exit code:
0
Version:
2.1.1.0
Modules
Images
c:\program files\softperfect switch port mapper\nsmapgui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1664"C:\Users\admin\AppData\Local\Temp\is-H4QED.tmp\portmapper_setup.tmp" /SL5="$3017E,4841627,121344,C:\Users\admin\Desktop\portmapper_setup.exe" /SPAWNWND=$2017C /NOTIFYWND=$20178 C:\Users\admin\AppData\Local\Temp\is-H4QED.tmp\portmapper_setup.tmp
portmapper_setup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-h4qed.tmp\portmapper_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2448"C:\Program Files\SoftPerfect Switch Port Mapper\NSMapGUI.exe" C:\Program Files\SoftPerfect Switch Port Mapper\NSMapGUI.exeexplorer.exe
User:
admin
Company:
SoftPerfect Pty Ltd
Integrity Level:
MEDIUM
Description:
SoftPerfect Switch Port Mapper (32-bit)
Exit code:
0
Version:
2.1.1.0
Modules
Images
c:\program files\softperfect switch port mapper\nsmapgui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2528"C:\Program Files\Notepad++\notepad++.exe" "C:\Users\admin\Desktop\NSMapCon.key"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2564"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
24 166
Read events
23 263
Write events
580
Delete events
323

Modification events

(PID) Process:(4088) Keygen.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4088) Keygen.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(4088) Keygen.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
(PID) Process:(1664) portmapper_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AAB4DDA3-D705-4D91-9AFC-46F43422E46A}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.6.1 (u)
(PID) Process:(1664) portmapper_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AAB4DDA3-D705-4D91-9AFC-46F43422E46A}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\SoftPerfect Switch Port Mapper
(PID) Process:(1664) portmapper_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AAB4DDA3-D705-4D91-9AFC-46F43422E46A}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\SoftPerfect Switch Port Mapper\
(PID) Process:(1664) portmapper_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AAB4DDA3-D705-4D91-9AFC-46F43422E46A}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
SoftPerfect Switch Port Mapper
(PID) Process:(1664) portmapper_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AAB4DDA3-D705-4D91-9AFC-46F43422E46A}_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(1664) portmapper_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AAB4DDA3-D705-4D91-9AFC-46F43422E46A}_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
desktopicon
(PID) Process:(1664) portmapper_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AAB4DDA3-D705-4D91-9AFC-46F43422E46A}_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
Executable files
13
Suspicious files
11
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1664portmapper_setup.tmpC:\Program Files\SoftPerfect Switch Port Mapper\unins000.exeexecutable
MD5:940343CA52C14BC9FED04B3A6FBED3BE
SHA256:B52BA6C1C5057840AD39701441A4C8E80884ECA114DC3D2D3E800252C1A8284A
1664portmapper_setup.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftPerfect Switch Port Mapper\Console Version.lnklnk
MD5:D7A2212644B6B714DD33122D2298DE0F
SHA256:EE68DF7BBCF34230F607B9764C1F1D50E1383A57E1B3DBA30A4274CDC550E231
676WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR5A63.tmp.cvr
MD5:
SHA256:
1664portmapper_setup.tmpC:\Program Files\SoftPerfect Switch Port Mapper\NSMapCon.exeexecutable
MD5:D04A667E1E76746B188763C0D6D11E69
SHA256:58A0E82066C2F4995B1F6C247C578F8414840BB2A8701D14B225B47D8E9F5BB8
1664portmapper_setup.tmpC:\Program Files\SoftPerfect Switch Port Mapper\NSMapGUI.exeexecutable
MD5:B627237644ED56E05733843480536A2F
SHA256:C90FEAA919B30D3C3D1BB558D4799BA7E21C5F28C474EE06BF5A6136284D7D09
1664portmapper_setup.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftPerfect Switch Port Mapper\Switch Port Mapper.lnkbinary
MD5:8B0BDDBE8F4355278FC343B1835EF4E4
SHA256:EE22379EE3B3536949A7BE7AEA42EC938E009158D699DA6136DB94BD3E71263B
1664portmapper_setup.tmpC:\Program Files\SoftPerfect Switch Port Mapper\sqlite3.dllexecutable
MD5:D89B961E758FC76DA26E7520D41ACBFB
SHA256:4F23DA2E051C6454C8960E238B161863D0E50456E1DA9F866126FFBDD3EFCE5F
1664portmapper_setup.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftPerfect Switch Port Mapper\Uninstall Switch Port Mapper.lnklnk
MD5:C27920A764CE717DA1E7E13DB946D0D0
SHA256:D7EF9824BBAAEBEB75D2217DEE857755B4898D6117A3DB3D940CCFC8E3CC3FDD
4088Keygen.exeC:\Program Files\SoftPerfect Switch Port Mapper\NSMapCon.exe.BAKexecutable
MD5:D04A667E1E76746B188763C0D6D11E69
SHA256:58A0E82066C2F4995B1F6C247C578F8414840BB2A8701D14B225B47D8E9F5BB8
4088Keygen.exeC:\Program Files\SoftPerfect Switch Port Mapper\NSMapGUI.exe.BAKexecutable
MD5:B627237644ED56E05733843480536A2F
SHA256:C90FEAA919B30D3C3D1BB558D4799BA7E21C5F28C474EE06BF5A6136284D7D09
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled