File name:

Glary Utilities 6 Keymaker.exe

Full analysis: https://app.any.run/tasks/98a051b1-4f3a-436e-a583-79165e4c2ae6
Verdict: Malicious activity
Analysis date: November 12, 2023, 19:12:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E6FE6CD510A7C62F3E4542318944FD84

SHA1:

D18AA46AA89A8F86CAB2BFE3EE631307D21417BB

SHA256:

EE81A8BBDB37CCED80E1116A6D3A7E68AE6420D907C7851E2FC6F836317D8499

SSDEEP:

98304:2NswfRwncVBZE3piMPFio1ynWldJ63S13btt/2tWFDAzZx8cak03Sl29HKMU/+I8:xN9joUFqw1lumlj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file the system directory

      • Glary Utilities 6 Keymaker.exe (PID: 3496)
    • Drops the executable file immediately after the start

      • Glary Utilities 6 Keymaker.exe (PID: 3496)
  • SUSPICIOUS

    • Reads the BIOS version

      • Glary Utilities 6 Keymaker.exe (PID: 3496)
  • INFO

    • Process checks are UAC notifies on

      • Glary Utilities 6 Keymaker.exe (PID: 3496)
    • Checks supported languages

      • Glary Utilities 6 Keymaker.exe (PID: 3496)
    • Reads the computer name

      • Glary Utilities 6 Keymaker.exe (PID: 3496)
    • Reads the machine GUID from the registry

      • Glary Utilities 6 Keymaker.exe (PID: 3496)
    • Create files in a temporary directory

      • Glary Utilities 6 Keymaker.exe (PID: 3496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2038:07:05 12:46:46+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 3535360
InitializedDataSize: 22528
UninitializedDataSize: -
EntryPoint: 0x8b81b8
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Jasi2169
CompanyName: Jasi2169
FileDescription: Glary Utilities 6 Keygen
FileVersion: 1.0.0.0
InternalName: Glary Utilities 6 Keygen.exe
LegalCopyright: Copyright © 2023
LegalTrademarks: All Rights Reserved
OriginalFileName: Glary Utilities 6 Keygen.exe
ProductName: Glary Utilities 6 Keygen
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start glary utilities 6 keymaker.exe glary utilities 6 keymaker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3436"C:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keymaker.exe" C:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keymaker.exeexplorer.exe
User:
admin
Company:
Jasi2169
Integrity Level:
MEDIUM
Description:
Glary Utilities 6 Keygen
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\glary utilities 6 keymaker.exe
c:\windows\system32\ntdll.dll
3496"C:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keymaker.exe" C:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keymaker.exe
explorer.exe
User:
admin
Company:
Jasi2169
Integrity Level:
HIGH
Description:
Glary Utilities 6 Keygen
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\glary utilities 6 keymaker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
182
Read events
182
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
2
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3496Glary Utilities 6 Keymaker.exeC:\Windows\system32\bassmod.dllexecutable
MD5:E4EC57E8508C5C4040383EBE6D367928
SHA256:8AD9E47693E292F381DA42DDC13724A3063040E51C26F4CA8E1F8E2F1DDD547F
3496Glary Utilities 6 Keymaker.exeC:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keygen.X86.1.0.0.0\keygen_cursor.curbinary
MD5:FC9B2E18A0E21C712E227E88248882C1
SHA256:FE802DB4DE68C9340F7A211DDF694109FD983478454CCB925A06F68851276C69
3496Glary Utilities 6 Keymaker.exeC:\Users\admin\AppData\Local\Temp\Glary Utilities 6 Keygen.X86.1.0.0.0\Native.dllexecutable
MD5:36FDE2466FEA08328EDB8744EE01981E
SHA256:AC3D757539AF3AC2103803F5F058FCF05D4082498DCB02F42EBF322A5AC9D9D6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info