File name:

Soundpad 3.3.2.0.exe

Full analysis: https://app.any.run/tasks/f62e3215-44ab-46b8-acdd-f284546fd7b0
Verdict: Malicious activity
Analysis date: July 20, 2024, 10:39:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C6B4D0286B390A50DB10B243B562EE10

SHA1:

3F69CC6E6DF955A878EE8F5A4200869410F9FC10

SHA256:

137895A9632EECA5CFF29DECA350850B8AD86221819EF528E69C88390A86816A

SSDEEP:

98304:6rriRyXVUnqmtdRT5rjxI9T4X6N4EYeOMhEpfSwPeL4QylCyvORu9ENT8ra+aNPg:FsEqECy7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Soundpad 3.3.2.0.exe (PID: 6976)
      • Soundpad 3.3.2.0.tmp (PID: 7464)
      • msiexec.exe (PID: 6932)
    • Registers / Runs the DLL via REGSVR32.EXE

      • msiexec.exe (PID: 6932)
      • Soundpad.exe (PID: 1884)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Soundpad 3.3.2.0.exe (PID: 6976)
      • Soundpad 3.3.2.0.tmp (PID: 7464)
    • Reads the Windows owner or organization settings

      • Soundpad 3.3.2.0.tmp (PID: 7464)
      • msiexec.exe (PID: 6932)
    • Process drops legitimate windows executable

      • Soundpad 3.3.2.0.tmp (PID: 7464)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 6932)
    • Uses REG/REGEDIT.EXE to modify registry

      • Soundpad 3.3.2.0.tmp (PID: 7464)
    • Reads security settings of Internet Explorer

      • Soundpad.exe (PID: 1884)
    • Reads the date of Windows installation

      • Soundpad.exe (PID: 1884)
  • INFO

    • Checks supported languages

      • Soundpad 3.3.2.0.exe (PID: 6976)
      • Soundpad 3.3.2.0.tmp (PID: 7464)
      • msiexec.exe (PID: 6932)
      • msiexec.exe (PID: 3868)
      • msiexec.exe (PID: 7236)
      • Soundpad.exe (PID: 1884)
    • Create files in a temporary directory

      • Soundpad 3.3.2.0.exe (PID: 6976)
      • Soundpad 3.3.2.0.tmp (PID: 7464)
    • Reads the computer name

      • Soundpad 3.3.2.0.tmp (PID: 7464)
      • msiexec.exe (PID: 6932)
      • msiexec.exe (PID: 3868)
      • msiexec.exe (PID: 7236)
      • Soundpad.exe (PID: 1884)
    • Creates files in the program directory

      • Soundpad 3.3.2.0.tmp (PID: 7464)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6932)
    • Process checks computer location settings

      • Soundpad.exe (PID: 1884)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6932)
    • Application launched itself

      • msiexec.exe (PID: 6932)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 28160
UninitializedDataSize: -
EntryPoint: 0x9c14
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.3.2.0
ProductVersionNumber: 3.3.2.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: lrepacks.ru
FileDescription: Soundpad Setup
FileVersion: 3.3.2.0.0
LegalCopyright: Copyright 2007-2021. LRepacks. All rights reserved.
ProductName: Soundpad
ProductVersion: 3.3.2.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
12
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start soundpad 3.3.2.0.exe soundpad 3.3.2.0.tmp msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs regsvr32.exe no specs regsvr32.exe no specs soundpad.exe no specs regsvr32.exe regedit.exe no specs soundpad 3.3.2.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1332"msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\is-427SO.tmp\SPAD\setup.msi" /qn /norestart ALL_USERS=1 INSTALLDESKTOPSHORTCUT=1 INSTALLDIR="C:\Program Files\Soundpad"C:\Windows\System32\msiexec.exeSoundpad 3.3.2.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
3010
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1884"C:\Program Files\Soundpad\Soundpad.exe" -i -sC:\Program Files\Soundpad\Soundpad.exemsiexec.exe
User:
admin
Company:
Leppsoft
Integrity Level:
HIGH
Description:
Soundpad
Exit code:
0
Version:
3.3.2
Modules
Images
c:\program files\soundpad\soundpad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcrt.dll
1964regsvr32.exe /s "C:\Program Files\Soundpad\UniteFx.dll"C:\Windows\System32\regsvr32.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3868C:\Windows\System32\MsiExec.exe -Embedding 98137BD13CE71FC7041299E82D0EB0CEC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4500"C:\WINDOWS\regedit.exe" /S "C:\Users\admin\AppData\Local\Temp\settings.reg"C:\Windows\regedit.exeSoundpad 3.3.2.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5336"C:\Windows\System32\regsvr32.exe" /s "C:\WINDOWS\system32\UniteFx.dll"C:\Windows\System32\regsvr32.exe
Soundpad.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6932C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6976"C:\Users\admin\AppData\Local\Temp\Soundpad 3.3.2.0.exe" C:\Users\admin\AppData\Local\Temp\Soundpad 3.3.2.0.exe
explorer.exe
User:
admin
Company:
lrepacks.ru
Integrity Level:
HIGH
Description:
Soundpad Setup
Exit code:
0
Version:
3.3.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\soundpad 3.3.2.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7236C:\Windows\System32\MsiExec.exe -Embedding 54EEF2219FFECF2094EC7D4C94566DC6 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7380regsvr32.exe /s /u "C:\Program Files\Soundpad\UniteFx.dll"C:\Windows\System32\regsvr32.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
7 007
Read events
6 741
Write events
232
Delete events
34

Modification events

(PID) Process:(7464) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
281D00002159512591DADA01
(PID) Process:(7464) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
19E5866066007735BC7AC970A9140E00FA4FFD487BCAD940AD94C7E4A2ABE26F
(PID) Process:(7464) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(7464) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Temp\is-427SO.tmp\SPAD\Soundpad\Soundpad.exe
(PID) Process:(7464) Soundpad 3.3.2.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
69779597970C90FA05EB59CA249207D8D14E3F7D0BFAD4E771331C95778874D8
(PID) Process:(7464) Soundpad 3.3.2.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Leppsoft\UniteFx
Operation:writeName:serial
Value:
1
(PID) Process:(6932) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
141B0000755A872E91DADA01
(PID) Process:(6932) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
21227D8691A81638F774452D10954A0157A53C090F1F19503FE301B34CE8054E
(PID) Process:(6932) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(6932) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
Executable files
25
Suspicious files
58
Text files
6
Unknown types
117

Dropped files

PID
Process
Filename
Type
7464Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-427SO.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
7464Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-427SO.tmp\MetroBlue.vsfbinary
MD5:295D085196B3DA13BFCD53373F82F8EE
SHA256:CBDC95EB9E7269E0C3E3BDDFD37B0918962795D80BDBA932E46EA16FF5E6CDBF
7464Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-427SO.tmp\SPAD\Soundpad\is-MF9AM.tmpexecutable
MD5:A3318AC35188C55F0CA2F67B5220A6F2
SHA256:028C6326F7065891761750621E9DCB0BAD0499E88F8C37BD35E91AD54AC2F1B6
7464Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-427SO.tmp\ISTask.dllexecutable
MD5:86A1311D51C00B278CB7F27796EA442E
SHA256:E916BDF232744E00CBD8D608168A019C9F41A68A7E8390AA48CFB525276C483D
7464Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-427SO.tmp\VclStylesInno.dllexecutable
MD5:B0CA93CEB050A2FEFF0B19E65072BBB5
SHA256:0E93313F42084D804B9AC4BE53D844E549CFCAF19E6F276A3B0F82F01B9B2246
7464Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-427SO.tmp\SPAD\Soundpad\SoundpadService.exeexecutable
MD5:FB9CE50362247606B9D29946FA269A71
SHA256:739F0E33201669B2EDBDEA74A92EAAE023581138EA4019212C9E8621C76109CE
7464Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-427SO.tmp\SPAD\Soundpad\languages\bg_BG\translation.mogmo
MD5:25974906456297B8539E2DC326B013F5
SHA256:51B10F128921BFD4C40EE3213D7A1B5451E152C913E489807C3A61B7091481EB
7464Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-427SO.tmp\SPAD\Soundpad\Soundpad.exeexecutable
MD5:A3318AC35188C55F0CA2F67B5220A6F2
SHA256:028C6326F7065891761750621E9DCB0BAD0499E88F8C37BD35E91AD54AC2F1B6
7464Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-427SO.tmp\WizardForm.BitmapImage1.bmpimage
MD5:48386BC24D46A3FAC0056AB765A597A1
SHA256:55E4D15D42D4983C2D3A4E0ABD07EFF703929FAE4DD33115F008BE346D501036
7464Soundpad 3.3.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-427SO.tmp\SPAD\setup.msiexecutable
MD5:08E546BBA42DA99F41096E54708ACD9F
SHA256:C1DC3D8F4DCC63962E563EE667E6A8B94657D5DE8235621BCF60E4AB82A9586E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
35
DNS requests
15
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4716
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5620
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.209.32.67:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2760
svchost.exe
40.113.103.199:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4716
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.159.73
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.75
  • 20.190.159.2
  • 20.190.159.68
  • 20.190.159.71
  • 20.190.159.4
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 40.127.240.158
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
google.com
  • 142.250.186.46
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info