Submission Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.
Creates a startup registry entry.
Registers a Winlogon notification package so that the installed module is loaded into the address space of winlogon.exe.
Registers a 32-bit in-process server DLL.

 

Technical Details:

NOTICE: The content shown in the above window is captured automatically and is not controlled or endorsed by ThreatExpert.
Please contact us on this link should any material be offensive or inappropriate and we will ensure any such content is blocked from future viewers of the report.

 

File System Modifications

#Filename(s)File SizeFile Hash
1 %CommonAppData%\QFX Software\KeyScrambler\Settings.ini 63 bytes MD5: 0x559F6D071AF9DD53FD3313F35238302A
SHA-1: 0x273BCDF0FA388673232FCA13CA21073FD6DAF70D
2 %CommonPrograms%\KeyScrambler\Getting Started.lnk 762 bytes MD5: 0x765BD94BE01B58354EFFBA902ACADDF3
SHA-1: 0x7D75F16EBC033F2CE1CCE8898A141C5CADE412FE
3 %CommonPrograms%\KeyScrambler\KeyScrambler Options.lnk 748 bytes MD5: 0x24D478E73B9C41F902E864F71D8DD6C0
SHA-1: 0x91BF68278C850E4C37448718D39DD2B8333DA0EA
4 %CommonPrograms%\KeyScrambler\KeyScrambler User Manual.url 87 bytes MD5: 0x491933D7E3863785DBCC6BFF95EEBC12
SHA-1: 0xFB5A4DCEA4C33E4E6CDE003BB7F07BDB3B2D2CCE
5 %CommonPrograms%\KeyScrambler\KeyScrambler.lnk 742 bytes MD5: 0xC07CAD8979AF97CD0B8A83771001D8E1
SHA-1: 0x6C70E99ECF60F623D0378751470602ED16E3FC28
6 %CommonPrograms%\KeyScrambler\QFX Software Homepage.url 52 bytes MD5: 0x00EC84F1BCBFCE3EE376281C1BF39B2A
SHA-1: 0xA48D453BF9405F8B241E626E864C90A64547CDB5
7 %CommonPrograms%\KeyScrambler\Uninstall KeyScrambler.lnk 727 bytes MD5: 0xD4271FF13907209BCEB364806F7C01F0
SHA-1: 0xC7D0F811279616B88B5B06E51B43927B69ED9A56
8 %AppData%\QFX Software\KeyScrambler\Settings.ini 27 bytes MD5: 0x1A009973FE44DCEE0AEFE8D3F6D3F950
SHA-1: 0x8FF612174B212F9AF5E49FAF347B91A8F7A2717B
9 %Temp%\KeyScrambler-Mohamed-ASRAR\KeyScramblerPremium_Setup.exe 1,616,360 bytes MD5: 0x7E4147D1F582681E7FF1F06E64E60A59
SHA-1: 0x2FAA82CA8ECAEBFA87751C2B17D9B41562919D57
10 %Temp%\KeyScrambler-Mohamed-ASRAR\psbzyps.txt 646 bytes MD5: 0xF4DBDD0151C02E2E4B36F90EA8570DA4
SHA-1: 0x179BBEC969B6653E2DCAF70AC2B637E1B4447F9B
11 %Temp%\KeyScrambler_Update3e53874fef4369c0.exe 0 bytes MD5: 0xD41D8CD98F00B204E9800998ECF8427E
SHA-1: 0xDA39A3EE5E6B4B0D3255BFEF95601890AFD80709
12 %ProgramFiles%\KeyScrambler\DriverInstaller.exe 131,400 bytes MD5: 0x28212B3C0343F03FA2790E1A83693045
SHA-1: 0x59A53815C41219D4BE3C8D9D0A38318649124F72
13 %ProgramFiles%\KeyScrambler\getting_started.html 1,886 bytes MD5: 0xDA033601EE343EAA7F5D609A854B4BAA
SHA-1: 0xE279B127A9CE7582A626C29DD02A0B88FF10D966
14 %ProgramFiles%\KeyScrambler\KeyScrambler.exe 508,744 bytes MD5: 0x0F0283D25467376F85A927A50E6ED8AF
SHA-1: 0x095F9922F8AC9318F1B85561CB11AEEC44FFD91C
15 %ProgramFiles%\KeyScrambler\keyscrambler.ico 40,321 bytes MD5: 0xFDE5504BBF7620ACA9F3850511C13A45
SHA-1: 0x484382ECC232CEDC1651FBA5F9311E9164F43369
16 %ProgramFiles%\KeyScrambler\keyscrambler.sys
%System%\drivers\keyscrambler.sys
209,016 bytes MD5: 0xD9CA77A69473A93E40B7551A7DE425A9
SHA-1: 0x88A5145CDAAECC938783D0DEEA94842838012BD3
17 %ProgramFiles%\KeyScrambler\KeyScramblerIE.dll
%ProgramFiles%\KeyScrambler\nsz1D.tmp
1,284,936 bytes MD5: 0x0ABB59B53C2F4CBEC09F3FE48EA7B300
SHA-1: 0x9C497E83E4BAF830C17B49CE13D7C57A9A0EC658
18 %ProgramFiles%\KeyScrambler\KeyScramblerLogon.dll
%System%\KeyScramblerLogon.dll
90,952 bytes MD5: 0x7195B12D46499F73642D254CD46C8D79
SHA-1: 0xD9B9D0CD4FEF336362A3867F77046F299EBED7C5
19 %ProgramFiles%\KeyScrambler\KeyScramblerLogon.exe 508,744 bytes MD5: 0x0D6F9A70272781C21AAAB66B7C2D87AB
SHA-1: 0xA4D09E1B8AAAA398E85A33F18046CA1E70F00077
20 %ProgramFiles%\KeyScrambler\Languages\KSLangCHT.dll 10,568 bytes MD5: 0x46B09E5B281F1D6281883C83D360C21C
SHA-1: 0xBD13DCC9862A39E8B736816B0E2099456159B882
21 %ProgramFiles%\KeyScrambler\Languages\KSLangJPN.dll 11,080 bytes MD5: 0xB2BD885D4DEB0C9D35C7E4E956BA0BFA
SHA-1: 0x142B75AE16BB45FC725A7041CFFD7FE52A916330
22 %ProgramFiles%\KeyScrambler\license.htm 6,751 bytes MD5: 0xFBE23EF8575DD46EA36F06DD627E94AB
SHA-1: 0xD80929568026E2D1DB891742331229F1FD0C7E34
23 %ProgramFiles%\KeyScrambler\NSIS.Library.RegTool.v3.{04E18544-CDF4-4EA2-B6EF-6228A69922AE}.exe 5,120 bytes MD5: 0x1F694E53532EB452CE7AE7F4523FDE76
SHA-1: 0x59609431A30F3A01AA07003DD09E9600961FBC2F
24 %ProgramFiles%\KeyScrambler\Uninstall.exe 121,375 bytes MD5: 0xAEF3AEB83EE17AB88CB6808A1FF9B25A
SHA-1: 0x01B4CB2160BDEE885725600B297BB0CEF94FEA92
25 %ProgramFiles%\KeyScrambler\x64\DriverInstaller.exe 160,584 bytes MD5: 0x84D039C927F054564DD1AD511A98BFAA
SHA-1: 0xA109E30BF0882DE9BE41D696AE606BB7D2162014
26 %ProgramFiles%\KeyScrambler\x64\KeyScrambler.exe 563,016 bytes MD5: 0xC5E82E0516CA80FA8A0DD9EAA2E1766E
SHA-1: 0x38A140C95218AA667F34FA4955CC3E90D8B22C61
27 %ProgramFiles%\KeyScrambler\x64\keyscrambler.sys 222,200 bytes MD5: 0x783BEB99743BACB9586CCB70356449C5
SHA-1: 0x90E739292C9869382BA39606BC30EE823A68BC73
28 %ProgramFiles%\KeyScrambler\x64\KeyScramblerIE.dll 1,658,184 bytes MD5: 0x4C442123F283D367B2FA588F85963716
SHA-1: 0x43DC4E39EE25D961C989860B388FDE2288BEEA61
29 %ProgramFiles%\KeyScrambler\x64\KeyScramblerLogon.dll 105,800 bytes MD5: 0x7AAE364C0BC476A568ACCA6BC570FC3E
SHA-1: 0x43AAD155D68693809AC587C2CE9A2EDE979B679E
30 %ProgramFiles%\KeyScrambler\x64\KeyScramblerLogon.exe 563,016 bytes MD5: 0x6F7634CA479208E3711D1FCF29608A3F
SHA-1: 0xD08BB7E656F3AF83C245887574C14668B20831E8
31 %ProgramFiles%\KeyScrambler\x64\Languages\KSLangCHT.dll 10,568 bytes MD5: 0x03FCC146E893CD182B9F9C28AB5C11E0
SHA-1: 0xE445B0613F3AA5C48512B750BAB41465911F19FE
32 %ProgramFiles%\KeyScrambler\x64\Languages\KSLangJPN.dll 11,080 bytes MD5: 0x802E07C3833ED3240AD2A41A26827209
SHA-1: 0x272BE01DE0F65B9DA5D14E62B1845AA587095E29
33 [file and pathname of the sample #1] 1,588,447 bytes MD5: 0xE699A3AF946C3E2FDEF6728F17BF8D92
SHA-1: 0x2637BFCCBECFC82AB86F8DFD4DB89706E664A6E9

 

Memory Modifications

Process NameProcess FilenameMain Module Size
DriverInstaller.exe%ProgramFiles%\KeyScrambler\DriverInstaller.exe147,456 bytes
[generic host process][generic host process filename]20,480 bytes
ns28.tmp%Temp%\nsj1B.tmp\ns28.tmp20,480 bytes
ns2F.tmp%Temp%\nsj1B.tmp\ns2F.tmp20,480 bytes
ns32.tmp%Temp%\nsj1B.tmp\ns32.tmp20,480 bytes
KeyScrambler.exe%ProgramFiles%\KeyScrambler\KeyScrambler.exe520,192 bytes
nsA.tmp%Temp%\nso3.tmp\nsA.tmp20,480 bytes
KeyScramblerPremium_Setup.exe%Temp%\KeyScrambler-Mohamed-ASRAR\KeyScramblerPremium_Setup.exe274,432 bytes
ns10.tmp%Temp%\nso3.tmp\ns10.tmp20,480 bytes
ns13.tmp%Temp%\nso3.tmp\ns13.tmp20,480 bytes
ns4.tmp%Temp%\nso3.tmp\ns4.tmp20,480 bytes
nsD.tmp%Temp%\nso3.tmp\nsD.tmp20,480 bytes
ns7.tmp%Temp%\nso3.tmp\ns7.tmp20,480 bytes
keyscramblerlogon.exe%ProgramFiles%\keyscrambler\keyscramblerlogon.exe520,192 bytes
ns1E.tmp%Temp%\nsj1B.tmp\ns1E.tmp20,480 bytes
ns22.tmp%Temp%\nsj1B.tmp\ns22.tmp20,480 bytes
ns2B.tmp%Temp%\nsj1B.tmp\ns2B.tmp20,480 bytes
ns25.tmp%Temp%\nsj1B.tmp\ns25.tmp20,480 bytes

 

Registry Modifications

 

Other details

Hong Kong
Japan

Server NameServer PortConnect as UserConnection Password
www.qfxsoftware.com80www.qfxsoftware.comwww.qfxsoftware.com
download.qfxsoftware.com80download.qfxsoftware.comdownload.qfxsoftware.com

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2017 ThreatExpert. All rights reserved.