ariskkey.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
MD5:
13d256133e86aa782371b24ef09cd908

SHA-1:
b6d8634899e21ef785b8ae5273e6d19e1aba620c

SHA-256:
af38756c3e20d7f5616a453c56f8eba58994a90eaa28c02c35865d3934a0c36e

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/24/2024 4:57:30 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
SPR/Ariskkey.1
7.11.122.154

Sophos
Passware Password Recovery
4.91

Trend Micro House Call
HKTL_PASSVIEW
7.2.214

Trend Micro
HKTL_PASSVIEW
10.465.02

File size:
453 KB (463,842 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\ariskkey.exe

File PE Metadata
Compilation timestamp:
2/21/2009 2:46:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:gl6d6yDnfX05X8oOusCGSRduMg1gwRGNv6czpD:G6Vk5soOoGSRduMg1TkzF

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, ED, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Code size:
22.5 KB (23,040 bytes)

The file ariskkey.exe has been discovered within the following programs.

KoolPlaya  by AKi-Software
About 3% of users remove it
www.Toolwiz.com
About 1% of users remove it
 
Powered by Should I Remove It?

The file ariskkey.exe has been seen being distributed by the following 50 URLs.

https://dw.uptodown.com/dwn/XuCL3pesBebkywpJmnqcVBnAprgGTuz08VicSQdwB89l9T-taY4jPr3_iFjKW2BHw6_BAVy1-KmHt9h-Io9In5-Hp5PtysBJbIz8agRASEvNJ_3lMU17DGnt7GuJh9_g/dh9RqzysvgBlVIv_rNeP_6lTviz5LqdX4MBkb8VHp-iT0YLqKVpsrkqOpXaJW-177T7pUZBQxIQwYw3edFIFvBBe6AjsVc9XzKyNv_l-PyjoNYTz-fNNVueSlSYVgWsO/HIVI-hYBKJvYKpBynhjw2G9MxoTnjCxhP-j_unaZ1PJ7xT1j5MjT1ZHiJfYiyLO7fMX7D5hRTZNAftKf7IkglEwp3U0Qn4KFQoTr6XWCu259XhrbmTiekhV9M9hsWeLJ/.../

http://indir.gezginler.net/i/1054/.../

http://www.ranchsendgift.com/3O QNbHqPZP IMgvDGVxb5hojFT2z7PVdeL7i23nl3SzP887w0Sstwf_g5YuP i6iiBSbryI4puj i ZkhTR8bocDzQ1xs7WoXx 0RSAc9UA0LFiIJQmDjQra67c818qr0ymS525pTQhzBZV3Qfx_PhFarN2DL6 _fZ6wUl6yYnag4mYI6UivZMqPXeQsgA0l0QvunLo2b5aZUznc46gXEtfmV3T6Q==-GzwAAASccGiFHCw5Xn7HOGD_Bh2Wa6I9xs5wBOXSGiN8SL27MXpyzZ91 unwYOIA

http://indir.gezginler.net/i/1054/.../

http://indir.gezginler.net/i/1054/.../

http://indir.gezginler.net/i/1054/.../

http://www.download3k.com/DownloadLink3-Asterisk-Key.html

http://indir.gezginler.net/i/1054/.../

http://www.dostindir.com/kaydet.php?pid=MzcyAAA=

http://www.ranchsendgift.com/KrAwygk52FnH DKLpx55S4jam4sE21DtSwGJ_F4oyzISO1 Y5yW3sP YeoE_ow0dVo3BqTZ0ogQjOkqZ4beFO8DhvINjcWSFQVBruwkfdzgSVkkB 5AhPr0QhZXXqkKhwiucv9BDZIdihy3wOnNjNa3ovXto4 nozzhV5vAQKfdLOExsGX3wwqoyRWSmJu5ijF1YSSb_v_AFz0ZH5a1IPvbQ3XMzxg==-GzwAAASccGiFHCw5Xn7HOGD_Bh2Wa6I9xs5wBOXSGiN8SL27MXpyzZ91 unwYOIA

https://www.cleverbridge.com/156/cookie?affiliate=42674&x-at=iwa8r21isp00icfb036d7&redirectto=http://www.lostpassword.com/f/downloads/.../ariskkey.exe

http://indir.gezginler.net/i/1054/.../

http://downloads.ziddu.com/downloadfiless/.../ariskkey.exe

http://api.viglink.com/api/click?format=go&jsonp=vglnk_145473701402714&key=c4c1798756825e5b3fc1d47003f6a0f0&libId=ikaow2cc0100icfa000DAf0vlfvwj&loc=http://werooyalex.foroes.org/t11-mira-las-contrasenas-ocultas-bajo-los-asteriscos&v=1&exp=60:CI1C55A:7&type=U&out=http://www.lostpassword.com/f/downloads/.../ariskkey.exe&ref=https://www.google.com.pe/&title=Mira las Contraseñas Ocultas bajo los **** (asteriscos)&txt=http://www.lostpassword.com/f/downloads/.../ariskkey.exe

http://www.tamindir.com/indir/MjAxNS0xMi0wOCAxOTowMjoyNA==/asterisk-key/windows/.../

http://indir.gezginler.net/i/1054/.../

https://dw.uptodown.com/dwn/LRNRMF3tLUhXVDKeDt85TGI2qGWzA6p2VUyTdDfkR5_OEIKdPtVNxvycKf6qdNiAxw9f5B--3kuby8nb19-o-iwZLD6lMpHJYE2vePI2SCQIe3baUdYxxfaCQY6jwyNM/XUWN82K5AZOoKC4a-hy6jPNQdeG9d8ViyKxweXLSL0Let_iiNj17DZTlTyimdJ80fPtHUcnBHKOz43g1uc0iSNZNDAM1fnclbUM4xHsug6yA_mFab5LTm7fmssDZabRD/ogs9zGm-DIOd7G_skbAklMPqkM6UvfbmEiCny5ZjkDNboKJwvA_m_Hu56JrxAuEZ_fLUJj0GoaFlJcnCEsUwoPy9LC7aRfO-52QB9C7Bs7448Cw8DKDQiKYmFEyMJJjY/.../

http://www.ranchsendgift.com/YRoY9plVMDwlfXZvMeqYE015y2neTQLVz0dn2fAZZLAncbUAReBmkJEGXbnAbmClj7whvvSAIXWqztcm2zkNPXHEc_oxbplvD1LDKfKDYs9HL8zqh0RXrOuiKK2jPKyTVpFqOOLp1l7LUg I5SY7u7pKd_b1oSauwXqWT_Q1gqhQpXsGkvJH87AMTc8WhVZ07ZG3DDbDukS2NTC4CQ _453tja3qZw==-GzwAAASccGiFHCw5Xn7HOGD_Bh2Wa6I9xs5wBOXSGiN8SL27MXpyzZ91 unwYOIA

http://www.ranchsendgift.com/gRNH4Mvs_apcF__Q2TC8hejlnyuK4QCIPI t99_t4tQieV9HHh1Aj2MwMRqrKVF8exoE9R9Qm7l6IHe3BHwy_oWIvUQER5zeC3KNWE1DlKmCJY rTQuUwlnonvXA3gopgMt2clZaaxX5Ki2NR9nQFWQk64zhLW2CaMvswmRDT2KP_0wjlR5aI1rMwPADl7JkkBN6FrDEhmrgOBsDfEzzOY5Z NBKvQ==-GzwAAASccGiFHCw5Xn7HOGD_Bh2Wa6I9xs5wBOXSGiN8SL27MXpyzZ91 unwYOIA

http://gsf-cf.softonic.com/b6d/863/.../file?SD_used=0&channel=WEB&fdh=no&id_file=26757&instance=softonic_it&type=PROGRAM&Expires=1474060388&Signature=QSFBhrpnTBud2bz95uHDEptKucSD5TiP23QKoKI8rjWG3rSmAccM1qLcPLSAKqJaMyV8sLnc0dap71SBQi9bdt7CH94xQDvusnHinSRBXJv4eDDz0ionS~04bcLw~nsX7BM4o2oRSxb7HjkFdjewsW-Cv3PFAy0Z6zXx-sKNzYk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ariskkey.exe

http://files.downloadnow-5.com/s/software/11/42/25/.../ariskkey.exe

http://indir.gezginler.net/i/1054/.../

http://indir.gezginler.net/i/1054/.../

http://dw.uptodown.com/dwn/mHd0HCJruUnbK6lAF5I-BisoZ_RXLNGjzxZeLlEm8HAQKYwuIZEBAD1bJDnvxIlBRcyITbXGwwCpngdDbCoV1Hc3mS5P4BaiEsI15VOHtwfyPusUcb0KuS8X58f9gxHA/Paa_eLVBs3-a9qmTWPWdDRhS8eD4KWqEcboUIysMeT1WpzBxZ_F-2z65-ElBbEklNS12EkK3bK7cQ3sCAjGh4Qdd3eaP6ijzB7rVqHHcNjg-qj27OrgTNQ4Q1jTlaLER/.../

http://www.dallagherarda.it/.../ariskkey.exe

http://indir.gezginler.net/i/1054/.../

http://www.download3k.com/DownloadLink1-Asterisk-Key.html

temp:ariskkey.exe

Latest 30 of 62 download URLs

Scan ariskkey.exe - Powered by Reason Core Security