| URL: | https://crackedpc.org/scrivener-crack-keygen/ |
| Full analysis: | https://app.any.run/tasks/753fab7f-4b06-4c03-8f6b-cb0f908a8cbc |
| Verdict: | Malicious activity |
| Threats: | Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks. |
| Analysis date: | October 02, 2021, 02:27:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 04A97678CE22AF82F1EAD5D1ED8F1A61 |
| SHA1: | F78DFAB3FCD165C21F25AB9889C9CE807D6B6EF6 |
| SHA256: | 9B5D66BD6F6F68863CDE9F100DC7E36828E2B2730EC7AFA450818D0483369863 |
| SSDEEP: | 3:N8KhkjKAXTEGrALKn:2K6jKAXTEGSKn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe" | C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe | — | Garbage Cleaner.exe | |||||||||||
User: admin Company: XmlSchemaChoice Corporation. Integrity Level: HIGH Description: HeaderBackground PartialTrustVisibleAssembliesSection App Exit code: 0 Version: 140.292.587.639 Modules
| |||||||||||||||
| 120 | "C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe" | C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe | — | Garbage Cleaner.exe | |||||||||||
User: admin Company: XmlSchemaChoice Corporation. Integrity Level: HIGH Description: HeaderBackground PartialTrustVisibleAssembliesSection App Exit code: 0 Version: 140.292.587.639 Modules
| |||||||||||||||
| 124 | C:\Windows\system32\cmd.exe /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\Users\admin\AppData\Local\Temp" | C:\Windows\system32\cmd.exe | — | setup_install.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 128 | "C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe" | C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe | — | Garbage Cleaner.exe | |||||||||||
User: admin Company: XmlSchemaChoice Corporation. Integrity Level: HIGH Description: HeaderBackground PartialTrustVisibleAssembliesSection App Exit code: 0 Version: 140.292.587.639 Modules
| |||||||||||||||
| 272 | "C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe" | C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe | — | Garbage Cleaner.exe | |||||||||||
User: admin Company: XmlSchemaChoice Corporation. Integrity Level: HIGH Description: HeaderBackground PartialTrustVisibleAssembliesSection App Exit code: 0 Version: 140.292.587.639 Modules
| |||||||||||||||
| 272 | "C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe" | C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe | — | Garbage Cleaner.exe | |||||||||||
User: admin Company: XmlSchemaChoice Corporation. Integrity Level: HIGH Description: HeaderBackground PartialTrustVisibleAssembliesSection App Exit code: 0 Version: 140.292.587.639 Modules
| |||||||||||||||
| 284 | "C:\Windows\System32\cmd.exe" /c taskkill /im "Sat000c135e5403db.exe" /f & erase "C:\Users\admin\AppData\Local\Temp\7zSCF8E84F0\Sat000c135e5403db.exe" & exit | C:\Windows\System32\cmd.exe | — | Sat000c135e5403db.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 288 | "C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe" | C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe | — | Garbage Cleaner.exe | |||||||||||
User: admin Company: XmlSchemaChoice Corporation. Integrity Level: HIGH Description: HeaderBackground PartialTrustVisibleAssembliesSection App Exit code: 0 Version: 140.292.587.639 Modules
| |||||||||||||||
| 288 | timeout /t 6 | C:\Windows\system32\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 296 | "C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe" | C:\ProgramData\Garbage Cleaner\Garbage Cleaner.exe | — | Garbage Cleaner.exe | |||||||||||
User: admin Company: XmlSchemaChoice Corporation. Integrity Level: HIGH Description: HeaderBackground PartialTrustVisibleAssembliesSection App Exit code: 0 Version: 140.292.587.639 Modules
| |||||||||||||||
| (PID) Process: | (2828) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2828) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2828) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2828) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2828) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2828) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2828) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2828) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (2828) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid |
Value: | |||
| (PID) Process: | (2828) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_installdate |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2828 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-6157C39B-B0C.pma | — | |
MD5:— | SHA256:— | |||
| 2828 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\763b354f-53c6-43ad-8288-14abebf1af64.tmp | text | |
MD5:— | SHA256:— | |||
| 2828 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences | text | |
MD5:— | SHA256:— | |||
| 2828 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF103ac9.TMP | text | |
MD5:81F483F77EE490F35306A4F94DB2286B | SHA256:82434CE3C9D13F509EBEEBE3A7A1A1DE9AB4557629D9FC855761E0CFA45E8BCE | |||
| 2828 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT | text | |
MD5:46295CAC801E5D4857D09837238A6394 | SHA256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443 | |||
| 2828 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old~RF103ba3.TMP | text | |
MD5:109A25C32EE1132ECD6D9F3ED9ADF01A | SHA256:DA6028DB9485C65E683643658326F02B1D0A1566DE14914EF28E5248EB94F0DD | |||
| 2828 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:5BD3C311F2136A7A88D3E197E55CF902 | SHA256:FA331915E1797E59979A3E4BCC2BD0D3DEAA039B94D4DB992BE251FD02A224B9 | |||
| 2828 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:8FF312A95D60ED89857FEB720D80D4E1 | SHA256:946A57FAFDD28C3164D5AB8AB4971B21BD5EC5BFFF7554DBF832CB58CC37700B | |||
| 2828 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000001.dbtmp | text | |
MD5:46295CAC801E5D4857D09837238A6394 | SHA256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443 | |||
| 2828 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old | text | |
MD5:EF1D5606A483BB6C72C81A3F649BEB18 | SHA256:BA083E7585ADA9936944FE56BC0141A544F18A01C3424E5C9F02375B34FE3D45 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4088 | chrome.exe | GET | 301 | 104.21.64.211:80 | http://ljhjdh.xyz/?s=7&q=Scrivener+3.2.2+Crack+++Keygen+For+%7BMac+Windows%7D+2021&dedica=18&hmac=WyJkMjBhZWIyNzcxNDRkNmIxNmFkMzdhNmU0YjhjYjJkMzA5YzMxMGE5IiwiYjdiODdiZTFkYThiZWI0YmQwZDhhZDA3MThhM2E3NjI2MThmMTNkYyIsIjljYjcwMjU4OWIyODg2ODQ0OWExNzIwY2Q3ZDAxOTQ1MjQ2NGMyODkiLCI2MDRiNjIzNzM1OTg2NzViZGExMmJlYzUxZjA0ZjcyNzRjZjI2YjhiIiwiNTMxZDAyMDAwMGEzYjdjYWY0NDRhOWMzYjg5NjU3YTgxMWZjODIwMSIsImU2MTQ5OTg4ZDJiMTc2YzU4MGJiYTg2N2E0NTJhMjFjNmE0NDNiNGMiLCIzMmMyNTA4OGZlMDYxYmQ3YmJmODNkMjZjOTkwMGUzZDExMmRjNmI1IiwiZTE0NzRlZDU3ZjZjMWIzYjhmNDRhM2E1Y2JjMzgyNjc4MTczYmFjMyIsIjFlY2JiYjk0ODllNGZiZjQ5ZTY5YzM5OTA1YWE0Njk0ZDEyZTI5MjYiLCJmOTRlZGY0ZGYzYzFkMTQ3Yzc5NDA3YjJhODIyNTUyZWQ2NGU1ODRlIiwiMjdiYzc0NWEwYWZlZDg1NzVkOTJjMzM2NGRjYWNlZTMzODBiM2E5MyJd | US | — | — | malicious |
3916 | Sat00845da4b2.tmp | HEAD | 200 | 162.0.214.42:80 | http://safialinks.com/Installer_Provider/UltraMediaBurner.exe | CA | — | — | whitelisted |
2832 | Sat000a5957f3.exe | GET | 200 | 45.133.1.182:80 | http://45.133.1.182/proxies.txt | unknown | text | 2.45 Kb | suspicious |
4088 | chrome.exe | POST | 200 | 3.144.151.101:80 | http://3.144.151.101/?go=8aa72f36ae98bf38812359&dedica=18 | US | html | 726 b | unknown |
3916 | Sat00845da4b2.tmp | GET | 200 | 162.0.214.42:80 | http://safialinks.com/Installer_Provider/UltraMediaBurner.exe | CA | executable | 475 Kb | whitelisted |
3716 | setup_install.exe | GET | 200 | 104.21.87.76:80 | http://hsiens.xyz/addInstall.php?key=125478824515ADNxu2ccbwe&ip=&oid=150&oname[]=02Oct1236AM_UPD-1-OCT&oname[]=Too&oname[]=lyl&oname[]=tra&oname[]=Pyi&oname[]=you&oname[]=ult&oname[]=Der&oname[]=dir&oname[]=GCl&oname[]=liv&oname[]=Ebo&oname[]=jog&cnt=12 | US | text | 10 b | malicious |
4088 | chrome.exe | GET | 302 | 3.144.151.101:80 | http://3.144.151.101/?6157c3a50bdc0=6461cc27aafd451fdd71c46e3cec3418cd31e9b4Array&m=7&q=Scrivener%203.2.2%20Crack%20%20%20Keygen%20For%20{Mac%20Windows}%202021&dedica=18& | US | html | 19.0 Kb | unknown |
2584 | Sat0094908d75b8.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAWAJn8G8pVTNI4cGFpe7i4%3D | US | der | 471 b | whitelisted |
4088 | chrome.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?7240ded3e91ec4a5 | US | compressed | 59.7 Kb | whitelisted |
2832 | Sat000a5957f3.exe | GET | 200 | 37.0.8.119:80 | http://37.0.8.119/base/api/statistics.php | NL | binary | 94 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4088 | chrome.exe | 142.250.186.141:443 | accounts.google.com | Google Inc. | US | whitelisted |
4088 | chrome.exe | 104.21.23.244:443 | crackedpc.org | Cloudflare Inc | US | unknown |
4088 | chrome.exe | 142.250.186.132:443 | www.google.com | Google Inc. | US | whitelisted |
4088 | chrome.exe | 192.0.76.3:443 | stats.wp.com | Automattic, Inc | US | suspicious |
4088 | chrome.exe | 104.21.83.183:443 | vbdhjtgve.xyz | Cloudflare Inc | US | malicious |
4088 | chrome.exe | 142.250.181.234:443 | content-autofill.googleapis.com | Google Inc. | US | whitelisted |
4088 | chrome.exe | 192.0.77.2:443 | i1.wp.com | Automattic, Inc | US | suspicious |
4088 | chrome.exe | 35.190.80.1:443 | a.nel.cloudflare.com | Google Inc. | US | suspicious |
4088 | chrome.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | Highwinds Network Group, Inc. | US | whitelisted |
4088 | chrome.exe | 142.250.186.110:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clients2.google.com |
| whitelisted |
crackedpc.org |
| whitelisted |
accounts.google.com |
| shared |
stats.wp.com |
| whitelisted |
www.google.com |
| malicious |
vbdhjtgve.xyz |
| malicious |
c0.wp.com |
| whitelisted |
content-autofill.googleapis.com |
| whitelisted |
connect.facebook.net |
| whitelisted |
i1.wp.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
4088 | chrome.exe | A Network Trojan was detected | ET TROJAN Fake Software Download Redirect Leading to Malware M3 |
4088 | chrome.exe | A Network Trojan was detected | AV TROJAN Malware Dropper As a Service Download Request |
4088 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2832 | Sat000a5957f3.exe | Generic Protocol Command Decode | SURICATA Applayer Mismatch protocol both directions |
2832 | Sat000a5957f3.exe | Generic Protocol Command Decode | SURICATA Applayer Mismatch protocol both directions |
3716 | setup_install.exe | A Network Trojan was detected | AV TROJAN GCleaner Downloader CnC Activity |
3716 | setup_install.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
3916 | Sat00845da4b2.tmp | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2832 | Sat000a5957f3.exe | A Network Trojan was detected | ET POLICY Possible External IP Lookup Domain Observed in SNI (ipinfo. io) |
2832 | Sat000a5957f3.exe | Potential Corporate Privacy Violation | ET POLICY Possible External IP Lookup SSL Cert Observed (ipinfo.io) |