File name:

Best Free Keylogger Pro v8.0.1 Setup.exe

Full analysis: https://app.any.run/tasks/c8eaa620-6e94-4449-b7f0-275820c5764d
Verdict: Malicious activity
Analysis date: June 03, 2024, 01:54:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

DF3DE3660210CEF8BDACA24C513534AC

SHA1:

5F88E340793636FF4432073485B822BEAEDECB41

SHA256:

AC420F407B79A37A3AD79A85522E3CBD5E0F238ACD2617E989AF579DA54B6D51

SSDEEP:

98304:ufLIQ/Q+8j2h/FoBuTnmLcoU4G2KYtUj+cDIsahUr3skyEBlNalwYKwbhLxQiuMf:MOukxH7gzDaY2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
    • Create files in the Startup directory

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
      • syscrb.exe (PID: 2304)
    • Reads the Internet Settings

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
      • syscrb.exe (PID: 2304)
    • Reads Microsoft Outlook installation path

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
      • syscrb.exe (PID: 2304)
    • Reads Internet Explorer settings

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
      • syscrb.exe (PID: 2304)
    • Executable content was dropped or overwritten

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
    • Drops 7-zip archiver for unpacking

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
    • Uses TASKKILL.EXE to kill process

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
    • Process drops legitimate windows executable

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
    • Changes Internet Explorer settings (feature browser emulation)

      • syscrb.exe (PID: 2304)
    • Reads settings of System Certificates

      • syscrb.exe (PID: 2304)
  • INFO

    • Checks proxy server information

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
      • syscrb.exe (PID: 2304)
    • Checks supported languages

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
      • syscrb.exe (PID: 2304)
      • CBAccess.exe (PID: 1836)
      • 7za.exe (PID: 2476)
      • 7za.exe (PID: 2516)
    • Reads the computer name

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
      • syscrb.exe (PID: 2304)
      • CBAccess.exe (PID: 1836)
      • 7za.exe (PID: 2516)
      • 7za.exe (PID: 2476)
    • Reads the machine GUID from the registry

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
      • syscrb.exe (PID: 2304)
      • CBAccess.exe (PID: 1836)
    • Creates files in the program directory

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
      • 7za.exe (PID: 2476)
      • syscrb.exe (PID: 2304)
      • 7za.exe (PID: 2516)
    • Creates files or folders in the user directory

      • Best Free Keylogger Pro v8.0.1 Setup.exe (PID: 3980)
    • Create files in a temporary directory

      • syscrb.exe (PID: 2304)
    • Reads Environment values

      • syscrb.exe (PID: 2304)
    • Reads the software policy settings

      • syscrb.exe (PID: 2304)
    • Disables trace logs

      • syscrb.exe (PID: 2304)
    • Manual execution by a user

      • verclsid.exe (PID: 1344)
      • explorer.exe (PID: 2704)
      • rundll32.exe (PID: 3260)
      • notepad++.exe (PID: 3292)
      • WinRAR.exe (PID: 3440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:03 07:51:19+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.33
CodeSize: 214528
InitializedDataSize: 92672
UninitializedDataSize: -
EntryPoint: 0x21d50
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
11
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start best free keylogger pro v8.0.1 setup.exe taskkill.exe no specs syscrb.exe cbaccess.exe no specs 7za.exe no specs 7za.exe no specs verclsid.exe no specs explorer.exe no specs rundll32.exe no specs notepad++.exe winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Windows\System32\taskkill.exe" /f /im syscrb.exe /im CBAccess.exeC:\Windows\System32\taskkill.exeBest Free Keylogger Pro v8.0.1 Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1344"C:\Windows\system32\verclsid.exe" /S /C {0B2C9183-C9FA-4C53-AE21-C900B0C39965} /I {0C733A8A-2A1C-11CE-ADE5-00AA0044773D} /X 0x401C:\Windows\System32\verclsid.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Extension CLSID Verification Host
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\verclsid.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1836"C:\ProgramData\BFKData\bfk\CBAccess\CBAccess.exe" C:\ProgramData\BFKData\bfk\CBAccess\CBAccess.exesyscrb.exe
User:
admin
Integrity Level:
MEDIUM
Description:
CBAccess
Version:
1.0.0.0
Modules
Images
c:\programdata\bfkdata\bfk\cbaccess\cbaccess.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2304"C:\ProgramData\BFKData\bfk\syscrb.exe" C:\ProgramData\BFKData\bfk\syscrb.exe
Best Free Keylogger Pro v8.0.1 Setup.exe
User:
admin
Company:
bestxsoftware
Integrity Level:
MEDIUM
Description:
syscrb
Version:
6.0.0.0
Modules
Images
c:\programdata\bfkdata\bfk\syscrb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2476"C:\ProgramData\BFKData\bfk\7za.exe" a -pab99#88ZZaa@45Ghx098Vcxc "C:\ProgramData\bfkdata\dtfile\dvdata\USER-PC-Export-2024_06_03__02_56_58.bfklog" "C:\ProgramData\bfkdata\dtfile\dvdata\tmpforzip-Export" -tzip -mmt=16C:\ProgramData\BFKData\bfk\7za.exesyscrb.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
19.00
Modules
Images
c:\programdata\bfkdata\bfk\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2516"C:\ProgramData\BFKData\bfk\7za.exe" a -pb99#88ZZaa@45Ghx098Vcxc "C:\ProgramData\bfkdata\dtfile\dvdata\USER-PC-Export-2024_06_03__02_56_35.bfklog" "C:\ProgramData\bfkdata\dtfile\dvdata\tmpforzip-Export" -tzip -mmt=16C:\ProgramData\BFKData\bfk\7za.exesyscrb.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
19.00
Modules
Images
c:\programdata\bfkdata\bfk\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2704"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
3221225547
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3260"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\ProgramData\BFKData\dtfile\dvdata\USER-PC-Export-2024_06_03__02_56_35.bfklogC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3292"C:\Program Files\Notepad++\notepad++.exe" "C:\ProgramData\BFKData\dtfile\dvdata\USER-PC-Export-2024_06_03__02_56_35.bfklog"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3440"C:\Program Files\WinRAR\WinRAR.exe" "C:\ProgramData\BFKData\dtfile\dvdata\USER-PC-Export-2024_06_03__02_56_35.bfklog.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
19 197
Read events
19 010
Write events
174
Delete events
13

Modification events

(PID) Process:(3980) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3980) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3980) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3980) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3980) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3980) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3980) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3980) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International
Operation:writeName:CNum_CpCache
Value:
1
(PID) Process:(3980) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International
Operation:writeName:CpCache
Value:
E9FD0000
(PID) Process:(3980) Best Free Keylogger Pro v8.0.1 Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
Executable files
36
Suspicious files
113
Text files
50
Unknown types
0

Dropped files

PID
Process
Filename
Type
3980Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\CBAccess\Newtonsoft.Json.xmlxml
MD5:76B0457C71F838783D774DF1C8DAA3E6
SHA256:1B2239DD13B34AD94B1E70D7BD07E4110A3BB7F286666E61D6DD53C732C29882
3980Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\delbase.dllbinary
MD5:BF9D7421313EAB501A9A112A980FA21B
SHA256:A4FA5FB539675B7FB32EC81F6CBE1DC2C8A9214C6981ACE33E864C7D641685DB
3980Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\actstc32.dllexecutable
MD5:B1A439A923122DC65A2521394F2A30E7
SHA256:F57035608B7F69C76805BDE109EFF4D2ED25B24FE112AFBA7249EBC9A50CFE32
3980Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\Newtonsoft.Json.xmlxml
MD5:D398FFE9FDAC6A53A8D8BB26F29BBB3C
SHA256:79EE87D4EDE8783461DE05B93379D576F6E8575D4AB49359F15897A854B643C4
3980Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\syscrb.xmlxml
MD5:1961CA780816A5C2C3E589D6FCCFBE02
SHA256:F6E8BD4CD8F32A3C78ABB41A26E52E190ED82CCA60FF482A751C78143D77E90B
3980Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\System.Data.SQLite.xmlxml
MD5:5C6D3D38B1EBF5B912FDFA9225CCEEB4
SHA256:5A580235C06D48FF2C4F27CE1570D07739BC48CEA96F93BD3A36D67DEBB4E295
3980Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\EntityFramework.SqlServer.xmlxml
MD5:2D1549C365902D6CBEE20E02A985B68B
SHA256:902F57044BAF104DD9A491DADCBA4C787B6F64531880DC3B11345D5758D7BD81
3980Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\EntityFramework.xmlxml
MD5:0A5E4E13DF59E4473A58C1E2643675A8
SHA256:521A3343FB43F50FDE1108C047559D7B3FDD348A08AC56ACD6116C2122A1D282
3980Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\srcimg\res\css_source.csstext
MD5:F22E6503BB26138DC1E94BE2A8093FE1
SHA256:467ED22281F2F33FE599DEC00A555112C7EF7ECAB5706E2A31D0380D73A14960
3980Best Free Keylogger Pro v8.0.1 Setup.exeC:\ProgramData\BFKData\bfk\EntityFramework.SqlServer.dllexecutable
MD5:0A63136CDDCBA92209170ABA6915613C
SHA256:BD780BF0EDC07A01AE381BDD874A87F0143AC7D1D3A5C74BFF870D4F46AF2587
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
2304
syscrb.exe
49.13.77.253:443
bfk.bestxsoftware.com
Hetzner Online GmbH
DE
unknown
2304
syscrb.exe
172.67.134.71:443
license.bestxsoftware.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
bfk.bestxsoftware.com
  • 49.13.77.253
unknown
dns.msftncsi.com
  • 131.107.255.255
unknown
license.bestxsoftware.com
  • 172.67.134.71
  • 104.21.25.137
unknown

Threats

No threats detected
Process
Message
syscrb.exe
Native library pre-loader is trying to load native SQLite library "C:\ProgramData\BFKData\bfk\x86\SQLite.Interop.dll"...
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe