File name:

Soundpad 4.0.9 Portable Release by S.T.Project (with alternative crack).rar

Full analysis: https://app.any.run/tasks/3add64ef-1aad-44bd-9837-ecc48e0130c4
Verdict: Malicious activity
Analysis date: April 19, 2025, 04:06:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C3196632988EF865CE9ACDCA89A391A8

SHA1:

074989ADA43978A7AB2D2FC501583E8A937CAB8D

SHA256:

1A20B4293849B5BFA633CD5B8EBBCC38821EDDDEC531463775740CF5FCD58429

SSDEEP:

98304:b4n2PbGfyUnKJBoAy65l/w9BEX6sUMY3fBT33te93HEGUqK4uk8NvxfLnXEzXlZP:27go6fd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7496)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 516)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 1812)
      • Soundpad Portable (Enigma Virtual Box).exe (PID: 516)
    • Starts application with an unusual extension

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 1812)
    • Executable content was dropped or overwritten

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 1812)
      • Soundpad Portable (Enigma Virtual Box).exe (PID: 516)
    • Application launched itself

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 1812)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 7496)
      • Soundpad Portable (Enigma Virtual Box).exe (PID: 516)
    • Checks supported languages

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 1812)
      • evb260F.tmp (PID: 1164)
      • Soundpad Portable (Enigma Virtual Box).exe (PID: 516)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7496)
    • Reads the software policy settings

      • slui.exe (PID: 7648)
    • Create files in a temporary directory

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 1812)
      • evb260F.tmp (PID: 1164)
      • Soundpad Portable (Enigma Virtual Box).exe (PID: 516)
    • Manual execution by a user

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 1812)
    • Reads the computer name

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 1812)
      • Soundpad Portable (Enigma Virtual Box).exe (PID: 516)
    • Reads Environment values

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 1812)
    • Reads the machine GUID from the registry

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 1812)
      • Soundpad Portable (Enigma Virtual Box).exe (PID: 516)
    • Creates files in the program directory

      • Soundpad Portable (Enigma Virtual Box).exe (PID: 516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 5047534
UncompressedSize: 18092504
OperatingSystem: Win32
ArchivedFileName: Soundpad Portable (Enigma Virtual Box).exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
10
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe slui.exe no specs rundll32.exe no specs soundpad portable (enigma virtual box).exe evb260f.tmp no specs soundpad portable (enigma virtual box).exe regsvr32.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
516"C:\Users\admin\Desktop\Soundpad 4.0.9 Portable Release by S.T.Project (with alternative crack)\Soundpad Portable (Enigma Virtual Box).exe" -s -riC:\Users\admin\Desktop\Soundpad 4.0.9 Portable Release by S.T.Project (with alternative crack)\Soundpad Portable (Enigma Virtual Box).exe
Soundpad Portable (Enigma Virtual Box).exe
User:
admin
Company:
Leppsoft
Integrity Level:
HIGH
Description:
Soundpad
Exit code:
0
Version:
4.0.9
Modules
Images
c:\users\admin\desktop\soundpad 4.0.9 portable release by s.t.project (with alternative crack)\soundpad portable (enigma virtual box).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1164"C:\Users\admin\Desktop\Soundpad 4.0.9 Portable Release by S.T.Project (with alternative crack)\SoundpadService.exe" C:\Users\admin\AppData\Local\Temp\evb260F.tmpSoundpad Portable (Enigma Virtual Box).exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\evb260f.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1812"C:\Users\admin\Desktop\Soundpad 4.0.9 Portable Release by S.T.Project (with alternative crack)\Soundpad Portable (Enigma Virtual Box).exe" C:\Users\admin\Desktop\Soundpad 4.0.9 Portable Release by S.T.Project (with alternative crack)\Soundpad Portable (Enigma Virtual Box).exe
explorer.exe
User:
admin
Company:
Leppsoft
Integrity Level:
MEDIUM
Description:
Soundpad
Version:
4.0.9
Modules
Images
c:\users\admin\desktop\soundpad 4.0.9 portable release by s.t.project (with alternative crack)\soundpad portable (enigma virtual box).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2284C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5776"C:\Windows\System32\regsvr32.exe" /s "C:\WINDOWS\system32\UniteFx1.8.0.dll"C:\Windows\System32\regsvr32.exeSoundpad Portable (Enigma Virtual Box).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6068"C:\Windows\System32\regsvr32.exe" /s "C:\WINDOWS\system32\UniteFx1.8.0.dll"C:\Windows\System32\regsvr32.exeSoundpad Portable (Enigma Virtual Box).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7416C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7496"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Soundpad 4.0.9 Portable Release by S.T.Project (with alternative crack).rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7616C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7648"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 650
Read events
3 591
Write events
45
Delete events
14

Modification events

(PID) Process:(7496) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7496) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7496) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7496) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Soundpad 4.0.9 Portable Release by S.T.Project (with alternative crack).rar
(PID) Process:(7496) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7496) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7496) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7496) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7496) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(7496) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
7
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
7496WinRAR.exeC:\Users\admin\Desktop\Soundpad 4.0.9 Portable Release by S.T.Project (with alternative crack)\Soundpad Portable (Enigma Virtual Box).exeexecutable
MD5:CA997ACAD71D33BEE90F82657D6F0270
SHA256:B89CFD54251B80A1441CE9C3A213B2A83A134F461E8395C99F7C4634F5AFB6E8
1812Soundpad Portable (Enigma Virtual Box).exeC:\Users\admin\AppData\Local\Temp\evb260F.tmpexecutable
MD5:F8AEC84B7D79B2BC849664D2235B312A
SHA256:7FCBE6ADAC40C45165645ADCA136DC57F9296AC9BBB6189E5E8056958AF4BCF5
1812Soundpad Portable (Enigma Virtual Box).exeC:\Users\admin\AppData\Local\Temp\evb2768.tmpexecutable
MD5:A1E7C567A2B49392FC38D419DDAF91AA
SHA256:6DCC863334C227A8C9C27E1EFE6DB78ACE872F1A8EF97DB0D6303D4AC6C327DE
516Soundpad Portable (Enigma Virtual Box).exeC:\Windows\System32\UniteFx1.8.0.dllexecutable
MD5:89A39302A860EACD8BF48EECFFC93DB2
SHA256:C5A0747634EC69825FCC7616A0122305E9A342C92EB1F2564997CA778C801ADE
516Soundpad Portable (Enigma Virtual Box).exeC:\Users\admin\AppData\Local\Temp\evb32C1.tmpexecutable
MD5:09F68529C8EE541118B396262508FE26
SHA256:0B486128C51E8ADE7531BEB9EFCF1559C87E1FD2876FA37C070196EC2FAA11DE
516Soundpad Portable (Enigma Virtual Box).exeC:\Users\admin\AppData\Local\Temp\evb32D2.tmpexecutable
MD5:09F68529C8EE541118B396262508FE26
SHA256:0B486128C51E8ADE7531BEB9EFCF1559C87E1FD2876FA37C070196EC2FAA11DE
516Soundpad Portable (Enigma Virtual Box).exeC:\Program Files\Common Files\Soundpad\SoundpadService.exeexecutable
MD5:3C30B2B43303A5A4AA63CA5F1D54D116
SHA256:EB217E98E8C28F690B0A31CD1432B1289C35591922FCF5CD2B3B3385268ECF78
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
19
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8184
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8184
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.66:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.49
whitelisted
google.com
  • 142.250.185.206
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.66
  • 20.190.160.17
  • 40.126.32.76
  • 20.190.160.14
  • 40.126.32.72
  • 20.190.160.2
  • 40.126.32.134
  • 20.190.160.131
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info