File name:

Soundpad 3.3.2.0.exe

Full analysis: https://app.any.run/tasks/5864eb89-059c-428c-94b8-331c367fb33f
Verdict: Malicious activity
Analysis date: August 31, 2024, 18:26:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C6B4D0286B390A50DB10B243B562EE10

SHA1:

3F69CC6E6DF955A878EE8F5A4200869410F9FC10

SHA256:

137895A9632EECA5CFF29DECA350850B8AD86221819EF528E69C88390A86816A

SSDEEP:

98304:6rriRyXVUnqmtdRT5rjxI9T4X6N4EYeOMhEpfSwPeL4QylCyvORu9ENT8ra+aNPg:FsEqECy7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • msiexec.exe (PID: 5712)
      • Soundpad.exe (PID: 5184)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • Soundpad 3.3.2.0.exe (PID: 5088)
      • Soundpad 3.3.2.0.tmp (PID: 6788)
      • msiexec.exe (PID: 5712)
    • Executable content was dropped or overwritten

      • Soundpad 3.3.2.0.exe (PID: 5088)
      • Soundpad 3.3.2.0.tmp (PID: 6788)
    • Reads the Windows owner or organization settings

      • Soundpad 3.3.2.0.tmp (PID: 6788)
      • msiexec.exe (PID: 5712)
    • Process drops legitimate windows executable

      • Soundpad 3.3.2.0.tmp (PID: 6788)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 5712)
    • Reads security settings of Internet Explorer

      • Soundpad.exe (PID: 5184)
    • Reads the date of Windows installation

      • Soundpad.exe (PID: 5184)
    • Uses REG/REGEDIT.EXE to modify registry

      • Soundpad 3.3.2.0.tmp (PID: 6788)
  • INFO

    • Create files in a temporary directory

      • Soundpad 3.3.2.0.exe (PID: 5088)
      • Soundpad 3.3.2.0.tmp (PID: 6788)
    • Checks supported languages

      • Soundpad 3.3.2.0.exe (PID: 5088)
      • Soundpad 3.3.2.0.tmp (PID: 6788)
      • msiexec.exe (PID: 5712)
      • msiexec.exe (PID: 4876)
      • msiexec.exe (PID: 2700)
      • Soundpad.exe (PID: 5184)
    • Reads the computer name

      • Soundpad 3.3.2.0.tmp (PID: 6788)
      • msiexec.exe (PID: 5712)
      • msiexec.exe (PID: 4876)
      • msiexec.exe (PID: 2700)
      • Soundpad.exe (PID: 5184)
    • Creates files in the program directory

      • Soundpad 3.3.2.0.tmp (PID: 6788)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5712)
    • Application launched itself

      • msiexec.exe (PID: 5712)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 5712)
    • The process uses the downloaded file

      • Soundpad.exe (PID: 5184)
    • Process checks computer location settings

      • Soundpad.exe (PID: 5184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 28160
UninitializedDataSize: -
EntryPoint: 0x9c14
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.3.2.0
ProductVersionNumber: 3.3.2.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: lrepacks.ru
FileDescription: Soundpad Setup
FileVersion: 3.3.2.0.0
LegalCopyright: Copyright 2007-2021. LRepacks. All rights reserved.
ProductName: Soundpad
ProductVersion: 3.3.2.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
12
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start soundpad 3.3.2.0.exe soundpad 3.3.2.0.tmp msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs regsvr32.exe no specs regsvr32.exe no specs soundpad.exe no specs regsvr32.exe regedit.exe soundpad 3.3.2.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2700C:\Windows\System32\MsiExec.exe -Embedding E997AB2A3EBA6746699A1C4DD86B2619 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4444"msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\setup.msi" /qn /norestart ALL_USERS=1 INSTALLDESKTOPSHORTCUT=1 INSTALLDIR="C:\Program Files\Soundpad"C:\Windows\System32\msiexec.exeSoundpad 3.3.2.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
3010
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4784"C:\Windows\System32\regsvr32.exe" /s "C:\WINDOWS\system32\UniteFx.dll"C:\Windows\System32\regsvr32.exe
Soundpad.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4876C:\Windows\System32\MsiExec.exe -Embedding 4D5D323A88275AE8711B5F3AD126AFC6C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5088"C:\Users\admin\AppData\Local\Temp\Soundpad 3.3.2.0.exe" C:\Users\admin\AppData\Local\Temp\Soundpad 3.3.2.0.exe
explorer.exe
User:
admin
Company:
lrepacks.ru
Integrity Level:
HIGH
Description:
Soundpad Setup
Exit code:
0
Version:
3.3.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\soundpad 3.3.2.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5184"C:\Program Files\Soundpad\Soundpad.exe" -i -sC:\Program Files\Soundpad\Soundpad.exemsiexec.exe
User:
admin
Company:
Leppsoft
Integrity Level:
HIGH
Description:
Soundpad
Exit code:
0
Version:
3.3.2
Modules
Images
c:\program files\soundpad\soundpad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msvcp_win.dll
5532regsvr32.exe /s "C:\Program Files\Soundpad\UniteFx.dll"C:\Windows\System32\regsvr32.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5548regsvr32.exe /s /u "C:\Program Files\Soundpad\UniteFx.dll"C:\Windows\System32\regsvr32.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5712C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6324"C:\WINDOWS\regedit.exe" /S "C:\Users\admin\AppData\Local\Temp\settings.reg"C:\Windows\regedit.exe
Soundpad 3.3.2.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
7 008
Read events
6 742
Write events
232
Delete events
34

Modification events

(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
841A0000C618944FD3FBDA01
(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
36B40A32DD80D7AC8CBC10EF55386CC935EEDD35D9B7851FA9783C2BD9FAA7EA
(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\Soundpad.exe
(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
480AC3B10BBAA2373F41E562A082C28BE05967AC30ACC6FB37974F6E58095F1C
(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Leppsoft\UniteFx
Operation:writeName:serial
Value:
1
(PID) Process:(5712) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
50160000D3721055D3FBDA01
(PID) Process:(5712) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
ADC026CAEE22A5DD089F4466200FE53C26A51E51080C33EB9FF6F4811CA7E1B7
(PID) Process:(5712) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
Executable files
25
Suspicious files
127
Text files
6
Unknown types
48

Dropped files

PID
Process
Filename
Type
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\_isetup\_setup64.tmpexecutable
MD5:4FF75F505FDDCC6A9AE62216446205D9
SHA256:A4C86FC4836AC728D7BD96E7915090FD59521A9E74F1D06EF8E5A47C8695FD81
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\_isetup\_RegDLL.tmpexecutable
MD5:0EE914C6F0BB93996C75941E1AD629C6
SHA256:4DC09BAC0613590F1FAC8771D18AF5BE25A1E1CB8FDBF4031AA364F3057E74A2
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\Soundpad.exeexecutable
MD5:A3318AC35188C55F0CA2F67B5220A6F2
SHA256:028C6326F7065891761750621E9DCB0BAD0499E88F8C37BD35E91AD54AC2F1B6
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\languages\cs\is-NU6IA.tmpbinary
MD5:D130476172FF551C0BE042D8F5C8733A
SHA256:EA4B443D238BEFABEEBF3A03A3ED971786F9007B8C88793236F48DCD2EADF9A5
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\is-UOLJM.tmpexecutable
MD5:A3318AC35188C55F0CA2F67B5220A6F2
SHA256:028C6326F7065891761750621E9DCB0BAD0499E88F8C37BD35E91AD54AC2F1B6
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\UniteFx.dllexecutable
MD5:3B75D3CC8D65C2C8B69DDA2CB2618FB6
SHA256:25812B045A4560427134006B1BF872CD515EC300B25A19E95272B6E1E5B6003D
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\is-0AEE9.tmpexecutable
MD5:3B75D3CC8D65C2C8B69DDA2CB2618FB6
SHA256:25812B045A4560427134006B1BF872CD515EC300B25A19E95272B6E1E5B6003D
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\languages\bg_BG\is-HGOB2.tmpbinary
MD5:25974906456297B8539E2DC326B013F5
SHA256:51B10F128921BFD4C40EE3213D7A1B5451E152C913E489807C3A61B7091481EB
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\languages\cs\translation.mobinary
MD5:D130476172FF551C0BE042D8F5C8733A
SHA256:EA4B443D238BEFABEEBF3A03A3ED971786F9007B8C88793236F48DCD2EADF9A5
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\languages\bg_BG\translation.mogmo
MD5:25974906456297B8539E2DC326B013F5
SHA256:51B10F128921BFD4C40EE3213D7A1B5451E152C913E489807C3A61B7091481EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
22
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3164
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3164
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3832
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4364
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1356
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4364
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3164
SIHClient.exe
13.85.23.86:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3164
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
  • 20.72.205.209
whitelisted
google.com
  • 142.250.184.238
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
login.live.com
  • 40.126.29.12
  • 40.126.29.13
  • 40.126.29.10
  • 40.126.29.14
  • 40.126.29.6
  • 40.126.29.7
  • 40.126.29.15
  • 20.190.157.11
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
Process
Message
regedit.exe
REGEDIT: CreateFile failed, GetLastError() = 2