File name: | Windows 11 Digital License Activator Plus 1.0 Setup.exe |
Full analysis: | https://app.any.run/tasks/4c6703dc-c124-47cc-a661-8f74804d268e |
Verdict: | Malicious activity |
Analysis date: | August 09, 2023, 19:13:12 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 5AF97EAA4B179F0BB87A0E42860B3ED8 |
SHA1: | 26CA9E238F8DDEC2B9B48E52BB286792B4274666 |
SHA256: | E48F4C4D82434BCF4962B843580B53A8E5DBDE18B67CF18AB173160B6401085E |
SSDEEP: | 393216:Rhid05VBEmK7T3CaqaHYrba+UV42+CYH0YTqCDrUkY/D:RhGOPEmxHr1UV+p0YTqCDrUvD |
.exe | | | Inno Setup installer (51.8) |
---|---|---|
.exe | | | InstallShield setup (20.3) |
.exe | | | Win32 EXE PECompact compressed (generic) (19.6) |
.dll | | | Win32 Dynamic Link Library (generic) (3.1) |
.exe | | | Win32 Executable (generic) (2.1) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2020:11:15 09:48:30+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 741376 |
InitializedDataSize: | 38400 |
UninitializedDataSize: | - |
EntryPoint: | 0xb5eec |
OSVersion: | 6.1 |
ImageVersion: | 6 |
SubsystemVersion: | 6.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 0.0.0.0 |
ProductVersionNumber: | 0.0.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | This installation was built with Inno Setup. |
CompanyName: | |
FileDescription: | Windows 11 Digital License Activator Plus 1.0 Setup |
FileVersion: | |
LegalCopyright: | |
OriginalFileName: | |
ProductName: | Windows 11 Digital License Activator Plus 1.0 |
ProductVersion: | v1.0 |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 15-Nov-2020 09:48:30 |
Detected languages: |
|
Comments: | This installation was built with Inno Setup. |
CompanyName: | - |
FileDescription: | Windows 11 Digital License Activator Plus 1.0 Setup |
FileVersion: | - |
LegalCopyright: | - |
OriginalFileName: | - |
ProductName: | Windows 11 Digital License Activator Plus 1.0 |
ProductVersion: | v1.0 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0050 |
Pages in file: | 0x0002 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x000F |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x001A |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000100 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 10 |
Time date stamp: | 15-Nov-2020 09:48:30 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000B361C | 0x000B3800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.35606 |
.itext | 0x000B5000 | 0x00001688 | 0x00001800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.97275 |
.data | 0x000B7000 | 0x000037A4 | 0x00003800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.0444 |
.bss | 0x000BB000 | 0x00006DE8 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x000C2000 | 0x00000F36 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.8987 |
.didata | 0x000C3000 | 0x000001A4 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.75636 |
.edata | 0x000C4000 | 0x0000009A | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.87222 |
.tls | 0x000C5000 | 0x00000018 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x000C6000 | 0x0000005D | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.38389 |
.rsrc | 0x000C7000 | 0x00004800 | 0x00004800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.42204 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.18295 | 1830 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 3.47151 | 1384 | UNKNOWN | Dutch - Netherlands | RT_ICON |
3 | 3.91708 | 744 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4 | 3.91366 | 2216 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4086 | 3.16547 | 864 | UNKNOWN | UNKNOWN | RT_STRING |
4087 | 3.40938 | 608 | UNKNOWN | UNKNOWN | RT_STRING |
4088 | 3.31153 | 1116 | UNKNOWN | UNKNOWN | RT_STRING |
4089 | 3.33977 | 1036 | UNKNOWN | UNKNOWN | RT_STRING |
4090 | 3.36723 | 724 | UNKNOWN | UNKNOWN | RT_STRING |
4091 | 3.33978 | 184 | UNKNOWN | UNKNOWN | RT_STRING |
advapi32.dll |
comctl32.dll |
kernel32.dll |
kernel32.dll (delay-loaded) |
netapi32.dll |
oleaut32.dll |
user32.dll |
version.dll |
Title | Ordinal | Address |
---|---|---|
dbkFCallWrapperAddr | 1 | 0x000BE63C |
__dbk_fcall_wrapper | 2 | 0x0000D0A0 |
TMethodImplementationIntercept | 3 | 0x00054060 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1388 | "C:\Users\admin\Desktop\Windows 11 Digital License Activator Plus 1.0 Setup.exe" | C:\Users\admin\Desktop\Windows 11 Digital License Activator Plus 1.0 Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Windows 11 Digital License Activator Plus 1.0 Setup Exit code: 0 Version: Modules
| |||||||||||||||
2472 | "C:\Users\admin\AppData\Local\Temp\is-L5BOC.tmp\Windows 11 Digital License Activator Plus 1.0 Setup.tmp" /SL5="$20148,13071814,780800,C:\Users\admin\Desktop\Windows 11 Digital License Activator Plus 1.0 Setup.exe" | C:\Users\admin\AppData\Local\Temp\is-L5BOC.tmp\Windows 11 Digital License Activator Plus 1.0 Setup.tmp | — | Windows 11 Digital License Activator Plus 1.0 Setup.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
3220 | "C:\Users\admin\Desktop\Windows 11 Digital License Activator Plus 1.0 Setup.exe" /SPAWNWND=$E0284 /NOTIFYWND=$20148 | C:\Users\admin\Desktop\Windows 11 Digital License Activator Plus 1.0 Setup.exe | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Windows 11 Digital License Activator Plus 1.0 Setup Exit code: 0 Version: Modules
| |||||||||||||||
3372 | "C:\Users\admin\AppData\Local\Temp\is-OC2AE.tmp\Windows 11 Digital License Activator Plus 1.0 Setup.tmp" /SL5="$C0286,13071814,780800,C:\Users\admin\Desktop\Windows 11 Digital License Activator Plus 1.0 Setup.exe" /SPAWNWND=$E0284 /NOTIFYWND=$20148 | C:\Users\admin\AppData\Local\Temp\is-OC2AE.tmp\Windows 11 Digital License Activator Plus 1.0 Setup.tmp | Windows 11 Digital License Activator Plus 1.0 Setup.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
552 | "C:\Windows\system32\cmd.exe" /C "C:\Program Files\Windows 11 Digital License Activator Plus 1.0\copy-changepk.cmd" | C:\Windows\System32\cmd.exe | — | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2896 | "C:\Windows\system32\netsh.exe" advfirewall firewall add rule name="Windows 11 Digital License Activator Plus 1.0" program="C:\Program Files\Windows 11 Digital License Activator Plus 1.0\Windows 11 Digital License Activator Plus 1.0.exe" dir=in action=allow enable=yes | C:\Windows\System32\netsh.exe | — | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3596 | "C:\Program Files\Windows 11 Digital License Activator Plus 1.0\Windows 11 Digital License Activator Plus 1.0.exe" | C:\Program Files\Windows 11 Digital License Activator Plus 1.0\Windows 11 Digital License Activator Plus 1.0.exe | — | explorer.exe | |||||||||||
User: admin Company: GetFreeCrack.com Integrity Level: MEDIUM Description: Windows 11 Digital License Activator Plus 2021 Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
2580 | "C:\Program Files\Windows 11 Digital License Activator Plus 1.0\Windows 11 Digital License Activator Plus 1.0.exe" | C:\Program Files\Windows 11 Digital License Activator Plus 1.0\Windows 11 Digital License Activator Plus 1.0.exe | explorer.exe | ||||||||||||
User: admin Company: GetFreeCrack.com Integrity Level: HIGH Description: Windows 11 Digital License Activator Plus 2021 Version: 1.0.0.0 Modules
| |||||||||||||||
3980 | "C:\Program Files\Internet Explorer\iexplore.exe" http://softwarez.best/GetKWin11.html | C:\Program Files\Internet Explorer\iexplore.exe | Windows 11 Digital License Activator Plus 1.0.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
2684 | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:3980 CREDAT:275457 /prefetch:2 | C:\Program Files (x86)\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
|
(PID) Process: | (2896) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\156\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3372) Windows 11 Digital License Activator Plus 1.0 Setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete value | Name: | RegFilesHash |
Value: E9FC889740EFB701CD37A7B484BFFF4460BBFCA31170A77128C3EEFD0795D07F | |||
(PID) Process: | (3372) Windows 11 Digital License Activator Plus 1.0 Setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Program Files\Windows 11 Digital License Activator Plus 1.0\Windows 11 Digital License Activator Plus 1.0.exe | |||
(PID) Process: | (3372) Windows 11 Digital License Activator Plus 1.0 Setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete value | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (3372) Windows 11 Digital License Activator Plus 1.0 Setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete value | Name: | SessionHash |
Value: CE462BB72A43667FCF0EC889A93885A4D82789A81D331874E082C3568930AD9E | |||
(PID) Process: | (3372) Windows 11 Digital License Activator Plus 1.0 Setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete value | Name: | Owner |
Value: 2C0D0000448E3395F5CAD901 | |||
(PID) Process: | (3372) Windows 11 Digital License Activator Plus 1.0 Setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete key | Name: | (default) |
Value: | |||
(PID) Process: | (3980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 5 | |||
(PID) Process: | (3980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: 91676960 | |||
(PID) Process: | (3980) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31049115 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3372 | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | C:\Users\admin\AppData\Local\Temp\is-EJUPT.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
2684 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K78MRVB5\3bJ3rGn[1].htm | html | |
MD5:FC505B1022E9CDAEB24C90F2CDFD7364 | SHA256:37760B2D65851CC11D81CB71B8D8A3138580D10D85AEEA741E1DAB0A81BCF1D3 | |||
2684 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HQYU0XHJ\SjIvLId7GwK5MkIA[1].htm | html | |
MD5:2FAEEA47EA164623D07C8AD01FC6469C | SHA256:C44704DE4BC832D3D79746312534E253B0E3DE35A02A3F2BFF4EC902A6EB87C9 | |||
3372 | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | C:\Program Files\Windows 11 Digital License Activator Plus 1.0\is-D87KU.tmp | text | |
MD5:62A54C8C463CCAC00DDA9623D79729A4 | SHA256:BD2D8040E52AFEF0976E46B3AB126A81B98EEB837C36B81BE166C2A54980AA4E | |||
3372 | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | C:\Program Files\Windows 11 Digital License Activator Plus 1.0\unins000.dat | binary | |
MD5:BE1C45833B4A0DFCF1102298F46E792A | SHA256:8C1CB45C022F90E1EFFFB4F6155D565625C6112B5E4E6B1AAE3F1AEF891CC901 | |||
3372 | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | C:\Program Files\Windows 11 Digital License Activator Plus 1.0\Windows 11 Digital License Activator Plus 1.0.exe | executable | |
MD5:9BCDB23222A540F7837F900241CAF322 | SHA256:57B47B232BBEE8C213800013950A4F1C39999E6E571E7D246635B90DC6083193 | |||
3372 | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | C:\Program Files\Windows 11 Digital License Activator Plus 1.0\Readme.txt | text | |
MD5:3677D3B15F3EE5E2AC08151293CA68CB | SHA256:09D4A2C92CF6909D7082BB4D4B87E9F4F84A04BAB0383A3A41F1CCE9A9B39331 | |||
3372 | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | C:\Program Files\Windows 11 Digital License Activator Plus 1.0\copy-changepk.cmd | text | |
MD5:62A54C8C463CCAC00DDA9623D79729A4 | SHA256:BD2D8040E52AFEF0976E46B3AB126A81B98EEB837C36B81BE166C2A54980AA4E | |||
3372 | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | C:\Users\Public\Desktop\Windows 11 Digital License Activator Plus 1.0.lnk | binary | |
MD5:00A976249039E56FB61964E3323C286B | SHA256:75DA607EFF772727D16616F49C2F1BFE7AC6F295F466FA951DBA6D4065E1306F | |||
3372 | Windows 11 Digital License Activator Plus 1.0 Setup.tmp | C:\Program Files\Windows 11 Digital License Activator Plus 1.0\unins000.exe | executable | |
MD5:3C01F508A492B1911DD94D4125028158 | SHA256:2D01C511CE76B9FCE5BF4129645E9D92BACBC74A9D74DD3DA4DBE53C150FD206 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2684 | iexplore.exe | GET | 301 | 162.0.209.199:80 | http://softwarez.best/GetKWin11.html | CA | html | 707 b | suspicious |
2580 | Windows 11 Digital License Activator Plus 1.0.exe | GET | 200 | 162.0.209.199:80 | http://renewsoftware.com/win11digitallicense/Version.txt | CA | text | 7 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
332 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1208 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2684 | iexplore.exe | 162.0.209.199:443 | renewsoftware.com | NAMECHEAP-NET | US | suspicious |
2684 | iexplore.exe | 67.199.248.11:443 | bit.ly | GOOGLE-CLOUD-PLATFORM | US | shared |
2580 | Windows 11 Digital License Activator Plus 1.0.exe | 162.0.209.199:80 | renewsoftware.com | NAMECHEAP-NET | US | suspicious |
2684 | iexplore.exe | 149.154.167.99:443 | t.me | Telegram Messenger Inc | GB | malicious |
2684 | iexplore.exe | 162.0.209.199:80 | renewsoftware.com | NAMECHEAP-NET | US | suspicious |
2684 | iexplore.exe | 34.111.35.152:443 | cdn4.telegram-cdn.org | GOOGLE | US | unknown |
Domain | IP | Reputation |
---|---|---|
renewsoftware.com |
| malicious |
softwarez.best |
| suspicious |
bit.ly |
| shared |
t.me |
| whitelisted |
telegram.org |
| whitelisted |
cdn4.telegram-cdn.org |
| suspicious |
www.bing.com |
| whitelisted |
api.bing.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
PID | Process | Class | Message |
---|---|---|---|
— | — | Device Retrieving External IP Address Detected | SUSPICIOUS [ANY.RUN] Received IP address from server as result of HTTP request |
— | — | Misc activity | ET INFO Observed Telegram Domain (t .me in TLS SNI) |
— | — | Misc activity | ET INFO Observed Telegram Domain (t .me in TLS SNI) |
— | — | Misc activity | ET INFO Observed Telegram Domain (t .me in TLS SNI) |