File name:

Soundpad 3.3.2.0.exe

Full analysis: https://app.any.run/tasks/5864eb89-059c-428c-94b8-331c367fb33f
Verdict: Malicious activity
Analysis date: August 31, 2024, 18:26:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C6B4D0286B390A50DB10B243B562EE10

SHA1:

3F69CC6E6DF955A878EE8F5A4200869410F9FC10

SHA256:

137895A9632EECA5CFF29DECA350850B8AD86221819EF528E69C88390A86816A

SSDEEP:

98304:6rriRyXVUnqmtdRT5rjxI9T4X6N4EYeOMhEpfSwPeL4QylCyvORu9ENT8ra+aNPg:FsEqECy7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • msiexec.exe (PID: 5712)
      • Soundpad.exe (PID: 5184)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Soundpad 3.3.2.0.tmp (PID: 6788)
    • Executable content was dropped or overwritten

      • Soundpad 3.3.2.0.tmp (PID: 6788)
      • Soundpad 3.3.2.0.exe (PID: 5088)
    • Drops the executable file immediately after the start

      • Soundpad 3.3.2.0.exe (PID: 5088)
      • Soundpad 3.3.2.0.tmp (PID: 6788)
      • msiexec.exe (PID: 5712)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 5712)
      • Soundpad 3.3.2.0.tmp (PID: 6788)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 5712)
    • Uses REG/REGEDIT.EXE to modify registry

      • Soundpad 3.3.2.0.tmp (PID: 6788)
    • Reads security settings of Internet Explorer

      • Soundpad.exe (PID: 5184)
    • Reads the date of Windows installation

      • Soundpad.exe (PID: 5184)
  • INFO

    • Checks supported languages

      • Soundpad 3.3.2.0.exe (PID: 5088)
      • Soundpad 3.3.2.0.tmp (PID: 6788)
      • msiexec.exe (PID: 5712)
      • msiexec.exe (PID: 4876)
      • msiexec.exe (PID: 2700)
      • Soundpad.exe (PID: 5184)
    • Reads the computer name

      • Soundpad 3.3.2.0.tmp (PID: 6788)
      • msiexec.exe (PID: 5712)
      • msiexec.exe (PID: 4876)
      • msiexec.exe (PID: 2700)
      • Soundpad.exe (PID: 5184)
    • Create files in a temporary directory

      • Soundpad 3.3.2.0.exe (PID: 5088)
      • Soundpad 3.3.2.0.tmp (PID: 6788)
    • Creates files in the program directory

      • Soundpad 3.3.2.0.tmp (PID: 6788)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5712)
    • Application launched itself

      • msiexec.exe (PID: 5712)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 5712)
    • Process checks computer location settings

      • Soundpad.exe (PID: 5184)
    • The process uses the downloaded file

      • Soundpad.exe (PID: 5184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 28160
UninitializedDataSize: -
EntryPoint: 0x9c14
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.3.2.0
ProductVersionNumber: 3.3.2.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: lrepacks.ru
FileDescription: Soundpad Setup
FileVersion: 3.3.2.0.0
LegalCopyright: Copyright 2007-2021. LRepacks. All rights reserved.
ProductName: Soundpad
ProductVersion: 3.3.2.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
12
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start soundpad 3.3.2.0.exe soundpad 3.3.2.0.tmp msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs regsvr32.exe no specs regsvr32.exe no specs soundpad.exe no specs regsvr32.exe regedit.exe soundpad 3.3.2.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2700C:\Windows\System32\MsiExec.exe -Embedding E997AB2A3EBA6746699A1C4DD86B2619 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4444"msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\setup.msi" /qn /norestart ALL_USERS=1 INSTALLDESKTOPSHORTCUT=1 INSTALLDIR="C:\Program Files\Soundpad"C:\Windows\System32\msiexec.exeSoundpad 3.3.2.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
3010
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4784"C:\Windows\System32\regsvr32.exe" /s "C:\WINDOWS\system32\UniteFx.dll"C:\Windows\System32\regsvr32.exe
Soundpad.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4876C:\Windows\System32\MsiExec.exe -Embedding 4D5D323A88275AE8711B5F3AD126AFC6C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5088"C:\Users\admin\AppData\Local\Temp\Soundpad 3.3.2.0.exe" C:\Users\admin\AppData\Local\Temp\Soundpad 3.3.2.0.exe
explorer.exe
User:
admin
Company:
lrepacks.ru
Integrity Level:
HIGH
Description:
Soundpad Setup
Exit code:
0
Version:
3.3.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\soundpad 3.3.2.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5184"C:\Program Files\Soundpad\Soundpad.exe" -i -sC:\Program Files\Soundpad\Soundpad.exemsiexec.exe
User:
admin
Company:
Leppsoft
Integrity Level:
HIGH
Description:
Soundpad
Exit code:
0
Version:
3.3.2
Modules
Images
c:\program files\soundpad\soundpad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msvcp_win.dll
5532regsvr32.exe /s "C:\Program Files\Soundpad\UniteFx.dll"C:\Windows\System32\regsvr32.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5548regsvr32.exe /s /u "C:\Program Files\Soundpad\UniteFx.dll"C:\Windows\System32\regsvr32.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5712C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6324"C:\WINDOWS\regedit.exe" /S "C:\Users\admin\AppData\Local\Temp\settings.reg"C:\Windows\regedit.exe
Soundpad 3.3.2.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
7 008
Read events
6 742
Write events
232
Delete events
34

Modification events

(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
841A0000C618944FD3FBDA01
(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
36B40A32DD80D7AC8CBC10EF55386CC935EEDD35D9B7851FA9783C2BD9FAA7EA
(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\Soundpad.exe
(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
480AC3B10BBAA2373F41E562A082C28BE05967AC30ACC6FB37974F6E58095F1C
(PID) Process:(6788) Soundpad 3.3.2.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Leppsoft\UniteFx
Operation:writeName:serial
Value:
1
(PID) Process:(5712) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
50160000D3721055D3FBDA01
(PID) Process:(5712) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
ADC026CAEE22A5DD089F4466200FE53C26A51E51080C33EB9FF6F4811CA7E1B7
(PID) Process:(5712) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
Executable files
25
Suspicious files
127
Text files
6
Unknown types
48

Dropped files

PID
Process
Filename
Type
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\_isetup\_RegDLL.tmpexecutable
MD5:0EE914C6F0BB93996C75941E1AD629C6
SHA256:4DC09BAC0613590F1FAC8771D18AF5BE25A1E1CB8FDBF4031AA364F3057E74A2
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\ISTask.dllexecutable
MD5:86A1311D51C00B278CB7F27796EA442E
SHA256:E916BDF232744E00CBD8D608168A019C9F41A68A7E8390AA48CFB525276C483D
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\is-EM9EI.tmpexecutable
MD5:FB9CE50362247606B9D29946FA269A71
SHA256:739F0E33201669B2EDBDEA74A92EAAE023581138EA4019212C9E8621C76109CE
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\MetroBlue.vsfbinary
MD5:295D085196B3DA13BFCD53373F82F8EE
SHA256:CBDC95EB9E7269E0C3E3BDDFD37B0918962795D80BDBA932E46EA16FF5E6CDBF
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\WizardForm.BitmapImage1.bmpimage
MD5:48386BC24D46A3FAC0056AB765A597A1
SHA256:55E4D15D42D4983C2D3A4E0ABD07EFF703929FAE4DD33115F008BE346D501036
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\is-K5U6B.tmpexecutable
MD5:08E546BBA42DA99F41096E54708ACD9F
SHA256:C1DC3D8F4DCC63962E563EE667E6A8B94657D5DE8235621BCF60E4AB82A9586E
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\Soundpad\Soundpad.exeexecutable
MD5:A3318AC35188C55F0CA2F67B5220A6F2
SHA256:028C6326F7065891761750621E9DCB0BAD0499E88F8C37BD35E91AD54AC2F1B6
6788Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-5LSVH.tmp\SPAD\setup.msiexecutable
MD5:08E546BBA42DA99F41096E54708ACD9F
SHA256:C1DC3D8F4DCC63962E563EE667E6A8B94657D5DE8235621BCF60E4AB82A9586E
5088Soundpad 3.3.2.0.exeC:\Users\admin\AppData\Local\Temp\is-914OB.tmp\Soundpad 3.3.2.0.tmpexecutable
MD5:2A95107004A04C3DC3E442F09FDAD9F9
SHA256:343E1FBBE4A568CA4A1A2996C5B15CA1AFD3142487203460C677DB4477C1C10F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
22
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3164
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3164
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3832
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4364
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1356
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4364
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3164
SIHClient.exe
13.85.23.86:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3164
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
  • 20.72.205.209
whitelisted
google.com
  • 142.250.184.238
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
login.live.com
  • 40.126.29.12
  • 40.126.29.13
  • 40.126.29.10
  • 40.126.29.14
  • 40.126.29.6
  • 40.126.29.7
  • 40.126.29.15
  • 20.190.157.11
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
Process
Message
regedit.exe
REGEDIT: CreateFile failed, GetLastError() = 2