| File name: | SoundPad.4.0.9.x64.rar |
| Full analysis: | https://app.any.run/tasks/c51bc695-e909-4d12-9900-51ef05bd4d56 |
| Verdict: | Malicious activity |
| Analysis date: | March 23, 2025, 19:27:02 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 0AD8CEBA5CC47F33BF3E6E6AFE9B2EAD |
| SHA1: | 91F80C1581C38DDA625362045C8546FCA40C360A |
| SHA256: | 189331AE1FBFD9F6DB51E77DA24C6C136CC1594D3EA3530D7F984E9F8062E879 |
| SSDEEP: | 98304:Fnv4sb5ax9L+xZl8H21a7j8lPArimi63r5HmZLtgCgRyIGDQt39BP13CKaCFJHWf:PARuysXmxcuTS |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
| FileVersion: | RAR v5 |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1164 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1228 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\SoundPad.4.0.9.x64.rar | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 2284 | "C:\Program Files (x86)\Leppsoft SoundPad\SoundpadService.exe" | C:\Program Files (x86)\Leppsoft SoundPad\SoundpadService.exe | Soundpad.exe | ||||||||||||
User: admin Company: Leppsoft Integrity Level: HIGH Description: Soundpad Service Version: 4.0.9 Modules
| |||||||||||||||
| 2384 | "C:\Program Files (x86)\Leppsoft SoundPad\Soundpad.exe" | C:\Program Files (x86)\Leppsoft SoundPad\Soundpad.exe | Setup_cracked.tmp | ||||||||||||
User: admin Company: Leppsoft Integrity Level: MEDIUM Description: Soundpad Version: 4.0.9 Modules
| |||||||||||||||
| 2564 | "C:\WINDOWS\system32\msinfo32.exe" C:\Users\admin\Desktop\FEELiNNERS.nfo | C:\Windows\System32\msinfo32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: System Information Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2984 | "C:\Program Files (x86)\Leppsoft SoundPad\SoundpadService.exe" | C:\Program Files (x86)\Leppsoft SoundPad\SoundpadService.exe | — | Soundpad.exe | |||||||||||
User: admin Company: Leppsoft Integrity Level: MEDIUM Description: Soundpad Service Exit code: 3221226540 Version: 4.0.9 Modules
| |||||||||||||||
| 6048 | "C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\FiLE_iD.DIZ | C:\Windows\System32\OpenWith.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Pick an app Exit code: 2147943623 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6068 | "C:\Users\admin\Desktop\Setup_cracked.exe" /SPAWNWND=$902C6 /NOTIFYWND=$5026A | C:\Users\admin\Desktop\Setup_cracked.exe | Setup_cracked.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Leppsoft SoundPad Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 6112 | "C:\Users\admin\Desktop\Setup_cracked.exe" | C:\Users\admin\Desktop\Setup_cracked.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Leppsoft SoundPad Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 6944 | "C:\Users\admin\AppData\Local\Temp\is-PQMQQ.tmp\Setup_cracked.tmp" /SL5="$60294,8134020,832512,C:\Users\admin\Desktop\Setup_cracked.exe" /SPAWNWND=$902C6 /NOTIFYWND=$5026A | C:\Users\admin\AppData\Local\Temp\is-PQMQQ.tmp\Setup_cracked.tmp | Setup_cracked.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\SoundPad.4.0.9.x64.rar | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Comment |
| Operation: | write | Name: | LeftBorder |
Value: 472 | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 256 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6112 | Setup_cracked.exe | C:\Users\admin\AppData\Local\Temp\is-7HKBO.tmp\Setup_cracked.tmp | executable | |
MD5:3268F5488A7A5D619E843DA659617822 | SHA256:6FF4528F355E3532BC4F1552C345DB2AD25D4D5CA9FFB4B07D4C478BB8C276EF | |||
| 6944 | Setup_cracked.tmp | C:\Program Files (x86)\Leppsoft SoundPad\is-68G21.tmp | executable | |
MD5:C830C0BEC2B3E128FB12FF6529853009 | SHA256:544958647DC10F4EE92800AC99BA04700DA337AD426D106A387A57383DC5DD82 | |||
| 6944 | Setup_cracked.tmp | C:\Program Files (x86)\Leppsoft SoundPad\SoundpadService.exe | executable | |
MD5:C830C0BEC2B3E128FB12FF6529853009 | SHA256:544958647DC10F4EE92800AC99BA04700DA337AD426D106A387A57383DC5DD82 | |||
| 6944 | Setup_cracked.tmp | C:\Program Files (x86)\Leppsoft SoundPad\is-V29CS.tmp | executable | |
MD5:C68F3F2622C4B536EEC4DA473C294190 | SHA256:17E162EAE3204595E6E0806599FBB9E12F721AEA16597307DCA0EE9C25204D39 | |||
| 6944 | Setup_cracked.tmp | C:\Program Files (x86)\Leppsoft SoundPad\TTS.dll | executable | |
MD5:8F1B8DC26A9531F76D3057C7A9F0B5DA | SHA256:A6BAEE91F8392FE62A0A9071082E86B9B42237682280BBDA0F3887B12A9CE1FF | |||
| 6944 | Setup_cracked.tmp | C:\Program Files (x86)\Leppsoft SoundPad\unins000.exe | executable | |
MD5:1E3ED997FF4EAEB69019D416401D34F7 | SHA256:5993A5B1852BEE40ACC1AE2A3C5D365C7F140E1CECAF81664EED085F7ED70046 | |||
| 6068 | Setup_cracked.exe | C:\Users\admin\AppData\Local\Temp\is-PQMQQ.tmp\Setup_cracked.tmp | executable | |
MD5:3268F5488A7A5D619E843DA659617822 | SHA256:6FF4528F355E3532BC4F1552C345DB2AD25D4D5CA9FFB4B07D4C478BB8C276EF | |||
| 6944 | Setup_cracked.tmp | C:\Program Files (x86)\Leppsoft SoundPad\is-V2EVU.tmp | executable | |
MD5:C68F3F2622C4B536EEC4DA473C294190 | SHA256:17E162EAE3204595E6E0806599FBB9E12F721AEA16597307DCA0EE9C25204D39 | |||
| 6944 | Setup_cracked.tmp | C:\Program Files (x86)\Leppsoft SoundPad\is-I2UPS.tmp | text | |
MD5:8FB99E6A51B370954779F04E730CE20E | SHA256:69661C0AD3FDC0A0C09AD36F9C2B1B583780D7E961E63F144121A5E52FD6270A | |||
| 6944 | Setup_cracked.tmp | C:\Program Files (x86)\Leppsoft SoundPad\steamconfig.ini | text | |
MD5:207E293DE83AF7C2529107FB086F2EC5 | SHA256:BB8D065118EEE9DF2C138AD8E0296A62D3BFF222CB0B897AC26381B39315F3B2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 500 | 20.83.72.98:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | unknown | xml | 512 b | whitelisted |
— | — | POST | 500 | 40.91.76.224:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | unknown | xml | 512 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
896 | slui.exe | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
1164 | slui.exe | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| unknown |
google.com |
| unknown |
activation-v2.sls.microsoft.com |
| unknown |