File name:

VirtualDJ_KeyGen.exe

Full analysis: https://app.any.run/tasks/8c07bf38-6981-4f94-a23c-5e3a5d4569de
Verdict: Malicious activity
Analysis date: November 01, 2023, 17:04:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

F6B15182821BDC689260C26167770450

SHA1:

EDEBC463E55FE37757B73BED680E0569071807AC

SHA256:

FAAE2E579886631EFE055C322911C6D48CB535FA21DC2076660C70B5334B1D91

SSDEEP:

12288:Uc9t2SllJIhBKdb5Yu3XPtT7FlQMUuQp4sX8woIMQFg0MoL0V2oPpiqyt:UcLjIjybxtP7/ieG8woQDtLI6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • VirtualDJ_KeyGen.exe (PID: 1576)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • VirtualDJ_KeyGen.exe (PID: 1576)
      • keygen.exe (PID: 3268)
    • Reads the computer name

      • VirtualDJ_KeyGen.exe (PID: 1576)
      • keygen.exe (PID: 3268)
    • Create files in a temporary directory

      • VirtualDJ_KeyGen.exe (PID: 1576)
      • keygen.exe (PID: 3268)
    • Reads the machine GUID from the registry

      • keygen.exe (PID: 3268)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:02 05:20:09+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24064
InitializedDataSize: 120320
UninitializedDataSize: 1024
EntryPoint: 0x326c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start virtualdj_keygen.exe keygen.exe no specs virtualdj_keygen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1576"C:\Users\admin\AppData\Local\Temp\VirtualDJ_KeyGen.exe" C:\Users\admin\AppData\Local\Temp\VirtualDJ_KeyGen.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\virtualdj_keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2908"C:\Users\admin\AppData\Local\Temp\VirtualDJ_KeyGen.exe" C:\Users\admin\AppData\Local\Temp\VirtualDJ_KeyGen.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\virtualdj_keygen.exe
c:\windows\system32\ntdll.dll
3268C:\Users\admin\AppData\Local\Temp\keygen.exeC:\Users\admin\AppData\Local\Temp\keygen.exeVirtualDJ_KeyGen.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
Total events
813
Read events
813
Write events
0
Delete events
0

Modification events

No data
Executable files
3
Suspicious files
2
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1576VirtualDJ_KeyGen.exeC:\Users\admin\AppData\Local\Temp\BASSMOD.dllexecutable
MD5:E4EC57E8508C5C4040383EBE6D367928
SHA256:8AD9E47693E292F381DA42DDC13724A3063040E51C26F4CA8E1F8E2F1DDD547F
1576VirtualDJ_KeyGen.exeC:\Users\admin\AppData\Local\Temp\keygen.exeexecutable
MD5:150FB221AC0C42F753B681894B243BEB
SHA256:0841EACBC8A146EA9C667E72D66CEEEBA620FCFB9E27BA1C67223C65D6FBA8CB
1576VirtualDJ_KeyGen.exeC:\Users\admin\AppData\Local\Temp\bgm.s3mbinary
MD5:14D6F6900D9C779D5EFE426039844647
SHA256:FA8DE36CC701A75F0BFB762C6C7FC70EB5677827157EEA36D45BB5F035346398
1576VirtualDJ_KeyGen.exeC:\Users\admin\AppData\Local\Temp\R2RVDJKG.dllexecutable
MD5:06A96A2A4DEFBF54A1A86C3526A6A5BB
SHA256:BA099AF0F631D3C55157C5A8726ABED3556BF01431B6022FA97A8C8BB845A555
3268keygen.exeC:\Users\admin\Documents\VirtualDJ\license.datbinary
MD5:73CC93B89D7A38B8E5B95880DB03E598
SHA256:08CD80C0BC98E29B6B946611E033A44B68F40B741EAFF76288E3305F09F82830
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1088
svchost.exe
224.0.0.252:5355
unknown
2656
svchost.exe
239.255.255.250:1900
unknown
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown

DNS requests

No data

Threats

No threats detected
No debug info