File name:

Glary Utilities 6 Keymaker.exe

Full analysis: https://app.any.run/tasks/970a6881-b09c-4bcf-8057-1a405f4e1a4f
Verdict: Malicious activity
Analysis date: November 07, 2023, 22:49:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E6FE6CD510A7C62F3E4542318944FD84

SHA1:

D18AA46AA89A8F86CAB2BFE3EE631307D21417BB

SHA256:

EE81A8BBDB37CCED80E1116A6D3A7E68AE6420D907C7851E2FC6F836317D8499

SSDEEP:

98304:2NswfRwncVBZE3piMPFio1ynWldJ63S13btt/2tWFDAzZx8cak03Sl29HKMU/+I8:xN9joUFqw1lumlj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file the system directory

      • Glary Utilities 6 Keymaker.exe (PID: 3228)
    • Drops the executable file immediately after the start

      • Glary Utilities 6 Keymaker.exe (PID: 3228)
  • SUSPICIOUS

    • Reads the BIOS version

      • Glary Utilities 6 Keymaker.exe (PID: 3228)
  • INFO

    • Checks supported languages

      • Glary Utilities 6 Keymaker.exe (PID: 3228)
    • Process checks are UAC notifies on

      • Glary Utilities 6 Keymaker.exe (PID: 3228)
    • Reads the computer name

      • Glary Utilities 6 Keymaker.exe (PID: 3228)
    • Reads the machine GUID from the registry

      • Glary Utilities 6 Keymaker.exe (PID: 3228)
    • Create files in a temporary directory

      • Glary Utilities 6 Keymaker.exe (PID: 3228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2038:07:05 12:46:46+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 3535360
InitializedDataSize: 22528
UninitializedDataSize: -
EntryPoint: 0x8b81b8
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Jasi2169
CompanyName: Jasi2169
FileDescription: Glary Utilities 6 Keygen
FileVersion: 1.0.0.0
InternalName: Glary Utilities 6 Keygen.exe
LegalCopyright: Copyright © 2023
LegalTrademarks: All Rights Reserved
OriginalFileName: Glary Utilities 6 Keygen.exe
ProductName: Glary Utilities 6 Keygen
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start glary utilities 6 keymaker.exe glary utilities 6 keymaker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3228"C:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keymaker.exe" C:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keymaker.exe
explorer.exe
User:
admin
Company:
Jasi2169
Integrity Level:
HIGH
Description:
Glary Utilities 6 Keygen
Exit code:
3221225547
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\glary utilities 6 keymaker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3460"C:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keymaker.exe" C:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keymaker.exeexplorer.exe
User:
admin
Company:
Jasi2169
Integrity Level:
MEDIUM
Description:
Glary Utilities 6 Keygen
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\glary utilities 6 keymaker.exe
c:\windows\system32\ntdll.dll
Total events
373
Read events
370
Write events
3
Delete events
0

Modification events

(PID) Process:(3228) Glary Utilities 6 Keymaker.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3228) Glary Utilities 6 Keymaker.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(3228) Glary Utilities 6 Keymaker.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
Executable files
2
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3228Glary Utilities 6 Keymaker.exeC:\Windows\system32\bassmod.dllexecutable
MD5:E4EC57E8508C5C4040383EBE6D367928
SHA256:8AD9E47693E292F381DA42DDC13724A3063040E51C26F4CA8E1F8E2F1DDD547F
3228Glary Utilities 6 Keymaker.exeC:\Windows\System32\drivers\etc\hoststext
MD5:890A28D5A384BA97DD3475CB97BB9980
SHA256:845EFC820DF39097BBAF40107B73B10E24E3C24E53A46B7B311E27C211EA61AE
3228Glary Utilities 6 Keymaker.exeC:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keygen.X86.1.0.0.0\Native.dllexecutable
MD5:36FDE2466FEA08328EDB8744EE01981E
SHA256:AC3D757539AF3AC2103803F5F058FCF05D4082498DCB02F42EBF322A5AC9D9D6
3228Glary Utilities 6 Keymaker.exeC:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keygen.X86.1.0.0.0\keygen_cursor.curbinary
MD5:FC9B2E18A0E21C712E227E88248882C1
SHA256:FE802DB4DE68C9340F7A211DDF694109FD983478454CCB925A06F68851276C69
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info