File name:

Keygen SmartDraw 2012-2013.exe

Full analysis: https://app.any.run/tasks/bd510aeb-1399-4528-94d5-ab42086ee2b9
Verdict: Malicious activity
Analysis date: January 01, 2024, 20:09:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B9D7618F196FD90325BD4DFDAEA0B58B

SHA1:

64246B870A1BAB096D21676371B97576D1555F1F

SHA256:

BB88B031ACDF2F4C13B41AFF74474C2247952044F7A0F5FDB6A939C6C54FF8E7

SSDEEP:

98304:1vFrtZK7cLcMGDspvnMhH3uZRd1QVaVHBB7/20rAq+A5Y3q/nYvq/fVfpgacqLqn:DuUUA2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • Keygen SmartDraw 2012-2013.exe (PID: 2420)
  • SUSPICIOUS

    • Reads Internet Explorer settings

      • Keygen SmartDraw 2012-2013.exe (PID: 2420)
  • INFO

    • Reads the computer name

      • Keygen SmartDraw 2012-2013.exe (PID: 2420)
    • Checks supported languages

      • Keygen SmartDraw 2012-2013.exe (PID: 2420)
    • Drops the executable file immediately after the start

      • Keygen SmartDraw 2012-2013.exe (PID: 2420)
    • Reads the machine GUID from the registry

      • Keygen SmartDraw 2012-2013.exe (PID: 2420)
    • Create files in a temporary directory

      • Keygen SmartDraw 2012-2013.exe (PID: 2420)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:10:13 14:58:56+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 2763776
InitializedDataSize: 375296
UninitializedDataSize: -
EntryPoint: 0x52a000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileDescription: Keygen SmartDraw 2013 (4 October)
FileVersion: 1.0.0.0
InternalName: Keygen SmartDraw 2012-2013.exe
LegalCopyright: Copyright © 2012
OriginalFileName: Keygen SmartDraw 2012-2013.exe
ProductName: Keygen SmartDraw 2013 (4 October)
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start keygen smartdraw 2012-2013.exe keygen smartdraw 2012-2013.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2036"C:\Users\admin\AppData\Local\Temp\Keygen SmartDraw 2012-2013.exe" C:\Users\admin\AppData\Local\Temp\Keygen SmartDraw 2012-2013.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Keygen SmartDraw 2013 (4 October)
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\keygen smartdraw 2012-2013.exe
c:\windows\system32\ntdll.dll
2420"C:\Users\admin\AppData\Local\Temp\Keygen SmartDraw 2012-2013.exe" C:\Users\admin\AppData\Local\Temp\Keygen SmartDraw 2012-2013.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Keygen SmartDraw 2013 (4 October)
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\keygen smartdraw 2012-2013.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
Total events
1 072
Read events
1 059
Write events
13
Delete events
0

Modification events

(PID) Process:(2420) Keygen SmartDraw 2012-2013.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\DirectSound\Speaker Configuration
Operation:writeName:Speaker Configuration
Value:
4
(PID) Process:(2420) Keygen SmartDraw 2012-2013.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2420) Keygen SmartDraw 2012-2013.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(2420) Keygen SmartDraw 2012-2013.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
Executable files
2
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2420Keygen SmartDraw 2012-2013.exeC:\Users\admin\AppData\Local\Temp\Bass.dllexecutable
MD5:8005750EC63EB5292884AD6183AE2E77
SHA256:DF9F56C4DA160101567B0526845228EE481EE7D2F98391696FA27FE41F8ACF15
2420Keygen SmartDraw 2012-2013.exeC:\Users\admin\AppData\Local\Temp\Bass.Net.dllexecutable
MD5:5A8BA687CE7AE47B8CE2AB429D7D75ED
SHA256:5A610A3789ABB045B9C6757C4CEF38404834FC6370F756624D1B894679849BA7
2420Keygen SmartDraw 2012-2013.exeC:\Users\admin\AppData\Local\Temp\tmp105.tmpbinary
MD5:491651474FCDA81D3B03FC2D777FEF37
SHA256:8FA195205F9C72EAF538543C0507DB9636B1F7F1E867F4449E0B935A7D4A9BB0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
Keygen SmartDraw 2012-2013.exe
%s------------------------------------------------ --- Themida Professional --- --- (c)2010 Oreans Technologies --- ------------------------------------------------