File name:

Best Free Keylogger Pro v8.0.1 Setup.exe

Full analysis: https://app.any.run/tasks/e1e7efca-f33e-44c8-b224-c6047cea591b
Verdict: Malicious activity
Analysis date: June 03, 2024, 00:47:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

367CBE1516D306376D3F208BA6E6830A

SHA1:

C955668136BDBABEB763ED745F422F861EB1D43D

SHA256:

515387401F83719E9FB879B7B3DF9B2C945012CC1C46C841A91BD15114955104

SSDEEP:

98304:ufLIQ/I+8j2h/FoBATnoLcoU4G2KYtUj+cDIsahUr3skyEBlNalwYKwbhLxQiuML:sUujxuTgKD0Yz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
    • Create files in the Startup directory

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
      • syscrb.exe (PID: 1112)
    • Reads security settings of Internet Explorer

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
      • syscrb.exe (PID: 1112)
    • Reads Microsoft Outlook installation path

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
      • syscrb.exe (PID: 1112)
    • Reads Internet Explorer settings

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
      • syscrb.exe (PID: 1112)
    • Uses TASKKILL.EXE to kill process

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
    • Executable content was dropped or overwritten

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
    • Process drops legitimate windows executable

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
    • Drops 7-zip archiver for unpacking

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
    • Changes Internet Explorer settings (feature browser emulation)

      • syscrb.exe (PID: 1112)
    • Reads settings of System Certificates

      • syscrb.exe (PID: 1112)
  • INFO

    • Checks supported languages

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
      • syscrb.exe (PID: 1112)
      • CBAccess.exe (PID: 1596)
    • Checks proxy server information

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
      • syscrb.exe (PID: 1112)
    • Reads the computer name

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
      • syscrb.exe (PID: 1112)
      • CBAccess.exe (PID: 1596)
    • Reads the machine GUID from the registry

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
      • syscrb.exe (PID: 1112)
      • CBAccess.exe (PID: 1596)
    • Creates files in the program directory

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
      • syscrb.exe (PID: 1112)
    • Creates files or folders in the user directory

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3972)
    • Create files in a temporary directory

      • syscrb.exe (PID: 1112)
    • Disables trace logs

      • syscrb.exe (PID: 1112)
    • Reads Environment values

      • syscrb.exe (PID: 1112)
    • Reads the software policy settings

      • syscrb.exe (PID: 1112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:03 07:51:19+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.33
CodeSize: 214528
InitializedDataSize: 92672
UninitializedDataSize: -
EntryPoint: 0x21d50
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start best free keylogger pro v8.0.1 setup.exe taskkill.exe no specs syscrb.exe cbaccess.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864"C:\Windows\System32\taskkill.exe" /f /im syscrb.exe /im CBAccess.exeC:\Windows\System32\taskkill.exeBest Free Keylogger Pro v8.0.1 Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1112"C:\ProgramData\BFKData\bfk\syscrb.exe" C:\ProgramData\BFKData\bfk\syscrb.exe
Best Free Keylogger Pro v8.0.1 Setup.exe
User:
admin
Company:
bestxsoftware
Integrity Level:
MEDIUM
Description:
syscrb
Version:
6.0.0.0
Modules
Images
c:\programdata\bfkdata\bfk\syscrb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1596"C:\ProgramData\BFKData\bfk\CBAccess\CBAccess.exe" C:\ProgramData\BFKData\bfk\CBAccess\CBAccess.exesyscrb.exe
User:
admin
Integrity Level:
MEDIUM
Description:
CBAccess
Version:
1.0.0.0
Modules
Images
c:\programdata\bfkdata\bfk\cbaccess\cbaccess.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3972"C:\Users\admin\Desktop\Best Free Keylogger Pro v8.0.1 Setup.exe" C:\Users\admin\Desktop\Best Free Keylogger Pro v8.0.1 Setup.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\best free keylogger pro v8.0.1 setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
10 738
Read events
10 684
Write events
52
Delete events
2

Modification events

(PID) Process:(3972) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3972) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3972) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3972) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3972) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3972) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3972) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3972) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International
Operation:writeName:CNum_CpCache
Value:
1
(PID) Process:(3972) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International
Operation:writeName:CpCache
Value:
E9FD0000
(PID) Process:(3972) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
Executable files
36
Suspicious files
50
Text files
42
Unknown types
0

Dropped files

PID
Process
Filename
Type
3972Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\CBAccess\CBAccess.xmlxml
MD5:5608A97B2E87436561A08E89337C19BD
SHA256:0A1B526C45438984325158054229026DD036133493759C38F1A2222546AF8034
3972Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\Newtonsoft.Json.xmlxml
MD5:D398FFE9FDAC6A53A8D8BB26F29BBB3C
SHA256:79EE87D4EDE8783461DE05B93379D576F6E8575D4AB49359F15897A854B643C4
3972Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\BaseNm.dllbinary
MD5:DDA19770D88B7B549D3A44BD2121371C
SHA256:E4C3885600082174B422D471F8E36FFE3025E15F37E4479D5DE8BC1974A7A182
3972Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\srcimg\res\css_source.csstext
MD5:F22E6503BB26138DC1E94BE2A8093FE1
SHA256:467ED22281F2F33FE599DEC00A555112C7EF7ECAB5706E2A31D0380D73A14960
3972Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\KeyCapEngine.dllexecutable
MD5:083643570444D158735032F9DC798EA9
SHA256:BF1EBDBBC0F61937B1294809CB780F9B1BFB19E7E034C4B5AE2855FA57DB66D6
3972Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\CrypUtil.dllexecutable
MD5:FFE14CDF4C49193F62E04DC6A14C0F61
SHA256:4F6B6045AE012474BDD746D634B4627D0843595A9B4264251B3A056ACBA6D542
3972Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\delbase.dllbinary
MD5:BF9D7421313EAB501A9A112A980FA21B
SHA256:A4FA5FB539675B7FB32EC81F6CBE1DC2C8A9214C6981ACE33E864C7D641685DB
3972Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\hotkeyMan.dllexecutable
MD5:EA62C53CDC9FEFCD7D3EE0A41F7AC5FA
SHA256:4B19D2903B3C6476DA323BB4CDF125A8B0CAF7DA4D0FB9F1E0A8B1BF69C2A02C
3972Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\bwurcap.dllexecutable
MD5:1CC7D9C19D2188D0B3F2DFCD8DA90D82
SHA256:34BEDDA19921A184B2CAF9883D889359D40A9F321BBD45E6A080A90DAEB8731B
3972Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\actstc32.dllexecutable
MD5:B1A439A923122DC65A2521394F2A30E7
SHA256:F57035608B7F69C76805BDE109EFF4D2ED25B24FE112AFBA7249EBC9A50CFE32
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1088
svchost.exe
224.0.0.252:5355
unknown
1112
syscrb.exe
49.13.77.253:443
bfk.bestxsoftware.com
Hetzner Online GmbH
DE
unknown
1112
syscrb.exe
172.67.134.71:443
license.bestxsoftware.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
bfk.bestxsoftware.com
  • 49.13.77.253
unknown
dns.msftncsi.com
  • 131.107.255.255
shared
license.bestxsoftware.com
  • 172.67.134.71
  • 104.21.25.137
unknown

Threats

No threats detected
Process
Message
syscrb.exe
Native library pre-loader is trying to load native SQLite library "C:\ProgramData\BFKData\bfk\x86\SQLite.Interop.dll"...