URL:

https://crack4windows.com/crack?s=batch-subtitles-converter&id=45643

Full analysis: https://app.any.run/tasks/4e07fafe-43e8-4898-9bc8-63090da1319b
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: August 17, 2020, 04:22:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
Indicators:
MD5:

27ABDBEB313655E14C4190CFA4873740

SHA1:

B2E93688D7745A963351B8D1C3CFEE2DE5412E41

SHA256:

7B1A84D870AB7D2AD4C908FD36014553DBE7B0B66B350C45F8B0949EEE0B2915

SSDEEP:

3:N8KWD8SmGXWafYDWQxM77QxRQdW:2KWvxXWrDBMHQAU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Batch Subtitles Converter 2.9.exe (PID: 956)
      • Batch Subtitles Converter 2.9.exe (PID: 1728)
      • sihost.exe (PID: 1796)
    • Changes settings of System certificates

      • Batch Subtitles Converter 2.9.tmp (PID: 3336)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 2616)
      • schtasks.exe (PID: 3372)
    • Uses Task Scheduler to run other applications

      • sihost.exe (PID: 1796)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Batch Subtitles Converter 2.9.exe (PID: 1728)
      • Batch Subtitles Converter 2.9.exe (PID: 956)
      • Batch Subtitles Converter 2.9.tmp (PID: 3336)
      • 7za.exe (PID: 2924)
      • WinRAR.exe (PID: 1700)
    • Creates files in the program directory

      • firefox.exe (PID: 772)
    • Reads the Windows organization settings

      • Batch Subtitles Converter 2.9.tmp (PID: 3336)
    • Reads Windows owner or organization settings

      • Batch Subtitles Converter 2.9.tmp (PID: 3336)
    • Creates files in the user directory

      • sihost.exe (PID: 1796)
      • Batch Subtitles Converter 2.9.tmp (PID: 3336)
    • Adds / modifies Windows certificates

      • Batch Subtitles Converter 2.9.tmp (PID: 3336)
    • Executed via COM

      • explorer.exe (PID: 3548)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 2812)
      • firefox.exe (PID: 772)
    • Reads Internet Cache Settings

      • firefox.exe (PID: 772)
    • Manual execution by user

      • WinRAR.exe (PID: 1700)
      • Batch Subtitles Converter 2.9.exe (PID: 1728)
    • Application was dropped or rewritten from another process

      • Batch Subtitles Converter 2.9.tmp (PID: 2080)
      • Batch Subtitles Converter 2.9.tmp (PID: 3336)
      • 7za.exe (PID: 1944)
      • 7za.exe (PID: 2924)
      • 7za.exe (PID: 3940)
    • Creates files in the user directory

      • firefox.exe (PID: 772)
    • Reads CPU info

      • firefox.exe (PID: 772)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
22
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe notepad.exe no specs firefox.exe winrar.exe batch subtitles converter 2.9.exe batch subtitles converter 2.9.tmp no specs batch subtitles converter 2.9.exe batch subtitles converter 2.9.tmp 7za.exe no specs 7za.exe 7za.exe no specs sihost.exe no specs schtasks.exe no specs schtasks.exe no specs explorer.exe no specs explorer.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
252"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="772.13.1749067328\1148670940" -childID 2 -isForBrowser -prefsHandle 2820 -prefMapHandle 2824 -prefsLen 5997 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 772 "\\.\pipe\gecko-crash-server-pipe.772" 2848 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
692"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Batch Subtitles Converter_2.9_Crack.txtC:\Windows\system32\NOTEPAD.EXEfirefox.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
772"C:\Program Files\Mozilla Firefox\firefox.exe" https://crack4windows.com/crack?s=batch-subtitles-converter&id=45643C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
956"C:\Users\admin\Desktop\Batch Subtitles Converter 2.9\Batch Subtitles Converter 2.9.exe" /SPAWNWND=$101F6 /NOTIFYWND=$201E8 C:\Users\admin\Desktop\Batch Subtitles Converter 2.9\Batch Subtitles Converter 2.9.exe
Batch Subtitles Converter 2.9.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
14.41
Modules
Images
c:\users\admin\desktop\batch subtitles converter 2.9\batch subtitles converter 2.9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1700"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Batch Subtitles Converter 2.9.zip" "C:\Users\admin\Desktop\Batch Subtitles Converter 2.9\"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1728"C:\Users\admin\Desktop\Batch Subtitles Converter 2.9\Batch Subtitles Converter 2.9.exe" C:\Users\admin\Desktop\Batch Subtitles Converter 2.9\Batch Subtitles Converter 2.9.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
14.41
Modules
Images
c:\users\admin\desktop\batch subtitles converter 2.9\batch subtitles converter 2.9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1796"C:\Users\admin\AppData\Roaming\ToolSysHost\sihost.exe" -cr -tu 3C:\Users\admin\AppData\Roaming\ToolSysHost\sihost.exeBatch Subtitles Converter 2.9.tmp
User:
admin
Integrity Level:
HIGH
Description:
Host System Info
Exit code:
0
Version:
2.0.74.41
Modules
Images
c:\users\admin\appdata\roaming\toolsyshost\sihost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1944"C:\Users\admin\AppData\Local\Temp\is-9UA9V.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-9UA9V.tmp\sub.res" -p"b1lig@n_vl"C:\Users\admin\AppData\Local\Temp\is-9UA9V.tmp\7za.exeBatch Subtitles Converter 2.9.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
4.65
Modules
Images
c:\users\admin\appdata\local\temp\is-9ua9v.tmp\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
2080"C:\Users\admin\AppData\Local\Temp\is-ECDIT.tmp\Batch Subtitles Converter 2.9.tmp" /SL5="$201E8,369491,121344,C:\Users\admin\Desktop\Batch Subtitles Converter 2.9\Batch Subtitles Converter 2.9.exe" C:\Users\admin\AppData\Local\Temp\is-ECDIT.tmp\Batch Subtitles Converter 2.9.tmpBatch Subtitles Converter 2.9.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ecdit.tmp\batch subtitles converter 2.9.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2616"C:\Windows\system32\schtasks.exe" /Delete /tn "Microsoft\Windows\Windows Error Reporting\SysInfo" /fC:\Windows\system32\schtasks.exesihost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
2 192
Read events
2 060
Write events
132
Delete events
0

Modification events

(PID) Process:(772) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
B8B2AA2C00000000
(PID) Process:(2812) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
ACB2AA2C00000000
(PID) Process:(772) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(772) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(772) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A3000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(772) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(772) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(772) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
Operation:writeName:txtfile
Value:
(PID) Process:(692) NOTEPAD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosX
Value:
22
(PID) Process:(692) NOTEPAD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosY
Value:
22
Executable files
6
Suspicious files
91
Text files
46
Unknown types
70

Dropped files

PID
Process
Filename
Type
772firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
772firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
MD5:
SHA256:
772firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
MD5:
SHA256:
772firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
MD5:
SHA256:
772firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
MD5:
SHA256:
772firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
MD5:
SHA256:
772firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
MD5:
SHA256:
772firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp
MD5:
SHA256:
772firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:
SHA256:
772firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsontext
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
55
DNS requests
107
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
772
firefox.exe
GET
301
172.67.199.181:80
http://getfilekey.site/download?id=X0WL23umlrE&s=C0B24C23
US
suspicious
772
firefox.exe
POST
200
172.217.18.99:80
http://ocsp.pki.goog/gts1o1core
US
der
472 b
whitelisted
772
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
772
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
278 b
whitelisted
772
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
772
firefox.exe
POST
200
172.217.18.99:80
http://ocsp.pki.goog/gts1o1core
US
der
472 b
whitelisted
772
firefox.exe
POST
200
172.217.18.99:80
http://ocsp.pki.goog/gts1o1core
US
der
471 b
whitelisted
772
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
772
firefox.exe
POST
200
172.217.18.99:80
http://ocsp.pki.goog/gts1o1core
US
der
472 b
whitelisted
772
firefox.exe
GET
200
104.24.100.108:80
http://getfilekey.site/.well-known/http-opportunistic
US
text
94 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
772
firefox.exe
2.16.177.18:80
detectportal.firefox.com
Akamai International B.V.
unknown
772
firefox.exe
104.28.30.177:443
crack4windows.com
Cloudflare Inc
US
unknown
772
firefox.exe
35.161.199.137:443
search.services.mozilla.com
Amazon.com, Inc.
US
unknown
772
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
772
firefox.exe
52.26.240.56:443
push.services.mozilla.com
Amazon.com, Inc.
US
unknown
772
firefox.exe
143.204.94.64:443
snippets.cdn.mozilla.net
US
malicious
772
firefox.exe
216.58.207.42:443
safebrowsing.googleapis.com
Google Inc.
US
whitelisted
772
firefox.exe
13.224.193.78:443
firefox.settings.services.mozilla.com
US
suspicious
772
firefox.exe
216.58.206.14:443
www.google-analytics.com
Google Inc.
US
whitelisted
772
firefox.exe
2.18.235.40:443
z.moatads.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 2.16.177.18
  • 2.16.177.88
whitelisted
crack4windows.com
  • 104.28.30.177
  • 104.28.31.177
  • 172.67.150.48
malicious
a1089.dscd.akamai.net
  • 2.16.177.88
  • 2.16.177.18
whitelisted
search.services.mozilla.com
  • 35.161.199.137
  • 52.13.211.193
  • 54.148.7.60
whitelisted
search.r53-2.services.mozilla.com
  • 54.148.7.60
  • 52.13.211.193
  • 35.161.199.137
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
cs9.wac.phicdn.net
  • 93.184.220.29
whitelisted
push.services.mozilla.com
  • 52.26.240.56
whitelisted
autopush.prod.mozaws.net
  • 52.26.240.56
whitelisted
tiles.services.mozilla.com
whitelisted

Threats

PID
Process
Class
Message
1048
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .cloud TLD
1048
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .cloud TLD
1 ETPRO signatures available at the full report
No debug info