| URL: | http://keygenninja.com |
| Full analysis: | https://app.any.run/tasks/49d0776c-8901-41ae-b472-71265dca3f6d |
| Verdict: | Malicious activity |
| Threats: | AZORult can steal banking information, including passwords and credit card details, as well as cryptocurrency. This constantly updated information stealer malware should not be taken lightly, as it continues to be an active threat. |
| Analysis date: | January 06, 2024, 16:58:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 990905F0DCF0A02804B6F0EF810BFB8A |
| SHA1: | 338175D20F4CF8C12B271302536F1EF96A4CD250 |
| SHA256: | 69A8D22F3420AC36BEB01D15372AD1F5641C02B3BAA7F20A3E94E96E5342BC87 |
| SSDEEP: | 3:N1KVAVYI:CqiI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 532 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1404.0.527385228\2077348706" -parentBuildID 20230710165010 -prefsHandle 1120 -prefMapHandle 1112 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {42944129-1829-458d-89b5-24877b0116f5} 1404 "\\.\pipe\gecko-crash-server-pipe.1404" 1192 d9a9bd0 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 1 Version: 115.0.2 Modules
| |||||||||||||||
| 604 | "C:\Users\admin\Desktop\EASEUS_Data_Recovery_Wizard_keygen_by_KeyGenGuru\keygen-pj\key.exe" | C:\Users\admin\Desktop\EASEUS_Data_Recovery_Wizard_keygen_by_KeyGenGuru\keygen-pj\key.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 764 | ping 127.0.0.1 | C:\Windows\System32\PING.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: TCP/IP Ping Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 908 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\1005125.bat" "C:\Users\admin\AppData\Local\Temp\RarSFX1\key.exe" " | C:\Windows\System32\cmd.exe | — | key.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1404 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://keygenninja.com | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1504 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1404.1.1962492206\1947218195" -parentBuildID 20230710165010 -prefsHandle 1428 -prefMapHandle 1424 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a18074f0-2610-426c-985c-4f5a8ce33070} 1404 "\\.\pipe\gecko-crash-server-pipe.1404" 1440 f31bc20 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1628 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1404.9.1245331589\603468069" -childID 8 -isForBrowser -prefsHandle 2368 -prefMapHandle 3556 -prefsLen 29313 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {04b62999-939a-4aa6-9a96-90ceb7032c84} 1404 "\\.\pipe\gecko-crash-server-pipe.1404" 4452 17205c90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1632 | "C:\Users\admin\Desktop\EASEUS_Data_Recovery_Wizard_keygen_by_KeyGenGuru\keygen-step-1.exe" | C:\Users\admin\Desktop\EASEUS_Data_Recovery_Wizard_keygen_by_KeyGenGuru\keygen-step-1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1656 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa1776.32893\EASEUS_Data_Recovery_Wizard_keygen_by_KeyGenGuru.zip | C:\Program Files\WinRAR\WinRAR.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1740 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1404.2.1578992430\80149472" -childID 1 -isForBrowser -prefsHandle 2068 -prefMapHandle 2064 -prefsLen 24556 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f7b842fe-4bab-4c94-b816-6fbbf3824621} 1404 "\\.\pipe\gecko-crash-server-pipe.1404" 2080 1183a3f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (2036) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 2166C0A101000000 | |||
| (PID) Process: | (1404) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 044CC1A101000000 | |||
| (PID) Process: | (1404) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (1404) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (1404) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (1404) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (1404) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (1404) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (1404) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (1404) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: D14E5F3C23B0D901 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1404 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:B7A3C61D0C144CC5E166B1E769CA8F8C | SHA256:7FADCB77FFACA6B9E9F15C6F1CD3AAD4C20DCD90FA92429A627A3A7110CA2644 | |||
| 1404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 1404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 1404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal | binary | |
MD5:5989F90AF9AD0F218841C6AB99A3AE02 | SHA256:79113F38B2302765172E494437131BE3A3966B42F142BAAA61D485818F0B0763 | |||
| 1404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1404 | firefox.exe | GET | 301 | 188.114.96.3:80 | http://keygenninja.com/ | unknown | — | — | unknown |
1404 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
1404 | firefox.exe | POST | 200 | 142.250.185.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | unknown |
1404 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
1404 | firefox.exe | POST | 200 | 95.101.54.139:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
1404 | firefox.exe | POST | — | 95.101.54.139:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
1404 | firefox.exe | POST | — | 95.101.54.139:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
1404 | firefox.exe | POST | 200 | 95.101.54.139:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
1404 | firefox.exe | POST | 200 | 95.101.54.137:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
1404 | firefox.exe | POST | 200 | 95.101.54.139:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1404 | firefox.exe | 188.114.97.3:443 | keygenninja.com | — | — | unknown |
1404 | firefox.exe | 188.114.96.3:80 | keygenninja.com | CLOUDFLARENET | NL | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1404 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
1404 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
1404 | firefox.exe | 44.205.134.14:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
1404 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | GOOGLE | US | unknown |
1404 | firefox.exe | 142.250.186.74:443 | safebrowsing.googleapis.com | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
keygenninja.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
r3.o.lencr.org |
| shared |
firefox.settings.services.mozilla.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3688 | keygen-step-1.exe | Malware Command and Control Activity Detected | ET MALWARE Win32/AZORult V3.3 Client Checkin M2 |
3764 | keygen-step-3.exe | Misc activity | ET INFO Observed ZeroSSL SSL/TLS Certificate |
3660 | key.exe | Malware Command and Control Activity Detected | ET MALWARE Fareit/Pony Downloader Checkin 2 |
3660 | key.exe | A Network Trojan was detected | ET MALWARE Trojan Generic - POST To gate.php with no referer |
3660 | key.exe | Potentially Bad Traffic | ET MALWARE Generic -POST To gate.php w/Extended ASCII Characters (Likely Zeus Derivative) |
604 | key.exe | Malware Command and Control Activity Detected | ET MALWARE Fareit/Pony Downloader Checkin 2 |
604 | key.exe | A Network Trojan was detected | ET MALWARE Trojan Generic - POST To gate.php with no referer |
3452 | keygen-step-3.exe | Misc activity | ET INFO Observed ZeroSSL SSL/TLS Certificate |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/AZORult V3.3 Client Checkin M2 |