File name:

PatrikZeros_Sound_Mixer_v1.1d_installer.exe

Full analysis: https://app.any.run/tasks/49447b41-c703-45e5-8fd7-61c9b3ce029d
Verdict: Malicious activity
Analysis date: June 26, 2024, 22:50:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

88EF1CFA1417656449675ED10A2C47AE

SHA1:

079AF1B7B0B2C9D06E3BB89306BAC33057B37F05

SHA256:

1ACB7BA203289A8A73D33B50F1DB836EE98AAADC0FA88A7B0CCFA6B35F9C6B52

SSDEEP:

98304:K+cD4dnynBk9xDK5U5YViR+XrIVWoNMglEVMMNux6HiYoxSaI9HK7mGOejl8ZVuM:Pwk00N47wJCdHBhqfqjVb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PatrikZeros_Sound_Mixer_v1.1d_installer.exe (PID: 3344)
      • PatrikZeros_Sound_Mixer_v1.1d_installer.tmp (PID: 3392)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PatrikZeros_Sound_Mixer_v1.1d_installer.exe (PID: 3344)
      • PatrikZeros_Sound_Mixer_v1.1d_installer.tmp (PID: 3392)
    • Reads the Windows owner or organization settings

      • PatrikZeros_Sound_Mixer_v1.1d_installer.tmp (PID: 3392)
    • Process drops python dynamic module

      • PatrikZeros_Sound_Mixer_v1.1d_installer.tmp (PID: 3392)
    • Process drops legitimate windows executable

      • PatrikZeros_Sound_Mixer_v1.1d_installer.tmp (PID: 3392)
    • The process drops C-runtime libraries

      • PatrikZeros_Sound_Mixer_v1.1d_installer.tmp (PID: 3392)
  • INFO

    • Checks supported languages

      • PatrikZeros_Sound_Mixer_v1.1d_installer.exe (PID: 3344)
      • PatrikZeros_Sound_Mixer_v1.1d_installer.tmp (PID: 3392)
    • Create files in a temporary directory

      • PatrikZeros_Sound_Mixer_v1.1d_installer.exe (PID: 3344)
    • Reads the computer name

      • PatrikZeros_Sound_Mixer_v1.1d_installer.tmp (PID: 3392)
    • Creates files or folders in the user directory

      • PatrikZeros_Sound_Mixer_v1.1d_installer.tmp (PID: 3392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 280576
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Patrik Žúdel
FileDescription: PatrikZero's Sound Mixer Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: PatrikZero's Sound Mixer
ProductVersion: 1.1d
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start patrikzeros_sound_mixer_v1.1d_installer.exe patrikzeros_sound_mixer_v1.1d_installer.tmp

Process information

PID
CMD
Path
Indicators
Parent process
3344"C:\Users\admin\AppData\Local\Temp\PatrikZeros_Sound_Mixer_v1.1d_installer.exe" C:\Users\admin\AppData\Local\Temp\PatrikZeros_Sound_Mixer_v1.1d_installer.exe
explorer.exe
User:
admin
Company:
Patrik Žúdel
Integrity Level:
MEDIUM
Description:
PatrikZero's Sound Mixer Setup
Version:
Modules
Images
c:\users\admin\appdata\local\temp\patrikzeros_sound_mixer_v1.1d_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3392"C:\Users\admin\AppData\Local\Temp\is-QOB5H.tmp\PatrikZeros_Sound_Mixer_v1.1d_installer.tmp" /SL5="$6015A,10634135,1023488,C:\Users\admin\AppData\Local\Temp\PatrikZeros_Sound_Mixer_v1.1d_installer.exe" C:\Users\admin\AppData\Local\Temp\is-QOB5H.tmp\PatrikZeros_Sound_Mixer_v1.1d_installer.tmp
PatrikZeros_Sound_Mixer_v1.1d_installer.exe
User:
admin
Company:
Patrik Žúdel
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-qob5h.tmp\patrikzeros_sound_mixer_v1.1d_installer.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
422
Read events
417
Write events
5
Delete events
0

Modification events

(PID) Process:(3392) PatrikZeros_Sound_Mixer_v1.1d_installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
400D0000B05815451BC8DA01
(PID) Process:(3392) PatrikZeros_Sound_Mixer_v1.1d_installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
8139ED0643B4A845E2ABEC7EC3D57CE2FBF16780D39BC88721B628584C1A64E4
(PID) Process:(3392) PatrikZeros_Sound_Mixer_v1.1d_installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3392) PatrikZeros_Sound_Mixer_v1.1d_installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\PatrikZeros_Sound_Mixer.exe
(PID) Process:(3392) PatrikZeros_Sound_Mixer_v1.1d_installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
2A73FD57D2341DE9F27EB09F503A8981D360CCE72ADD148EEE1D0DD18A1DD859
Executable files
60
Suspicious files
74
Text files
1 053
Unknown types
0

Dropped files

PID
Process
Filename
Type
3392PatrikZeros_Sound_Mixer_v1.1d_installer.tmpC:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\unins000.exeexecutable
MD5:D163499964811EC5C67B7F001B50165E
SHA256:F65E2193E876EE972E83CD6D10675E9441EE92A6780565B6086F926695ACD6C8
3392PatrikZeros_Sound_Mixer_v1.1d_installer.tmpC:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\is-00NIU.tmpexecutable
MD5:63C4F445B6998E63A1414F5765C18217
SHA256:664C3E52F914E351BB8A66CE2465EE0D40ACAB1D2A6B3167AE6ACF6F1D1724D2
3392PatrikZeros_Sound_Mixer_v1.1d_installer.tmpC:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\libffi-7.dllexecutable
MD5:EEF7981412BE8EA459064D3090F4B3AA
SHA256:F60DD9F2FCBD495674DFC1555EFFB710EB081FC7D4CAE5FA58C438AB50405081
3392PatrikZeros_Sound_Mixer_v1.1d_installer.tmpC:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\is-QIUUH.tmpexecutable
MD5:D163499964811EC5C67B7F001B50165E
SHA256:F65E2193E876EE972E83CD6D10675E9441EE92A6780565B6086F926695ACD6C8
3392PatrikZeros_Sound_Mixer_v1.1d_installer.tmpC:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\is-HO5OO.tmpcompressed
MD5:9AE9AD9E688F857FCADF6A8C31F57BBB
SHA256:40468ADC7CAB6AE91035C67D12522772F523EE5D2026E7E4A72F8985BBE3E3CE
3392PatrikZeros_Sound_Mixer_v1.1d_installer.tmpC:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\is-PNR4C.tmpexecutable
MD5:D29E61BD72F13D8FF79748406A7852B3
SHA256:B66FA88EB68824EEE2CE22ABC805E615B0F2A4C575DA8A8493FD10EBE66F10E9
3392PatrikZeros_Sound_Mixer_v1.1d_installer.tmpC:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\PatrikZeros_Sound_Mixer.exeexecutable
MD5:D29E61BD72F13D8FF79748406A7852B3
SHA256:B66FA88EB68824EEE2CE22ABC805E615B0F2A4C575DA8A8493FD10EBE66F10E9
3392PatrikZeros_Sound_Mixer_v1.1d_installer.tmpC:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\libcrypto-1_1.dllexecutable
MD5:63C4F445B6998E63A1414F5765C18217
SHA256:664C3E52F914E351BB8A66CE2465EE0D40ACAB1D2A6B3167AE6ACF6F1D1724D2
3392PatrikZeros_Sound_Mixer_v1.1d_installer.tmpC:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\LICENSE.txttext
MD5:DB90078E6FCF77C4E3150276F4FCD56F
SHA256:DA66448F212E5DC51B8424B676DFB04605A5A86E9CFB8C7DD48DE5875690472D
3392PatrikZeros_Sound_Mixer_v1.1d_installer.tmpC:\Users\admin\AppData\Local\Programs\PatrikZero's Sound Mixer\is-BA7R3.tmpexecutable
MD5:EEF7981412BE8EA459064D3090F4B3AA
SHA256:F60DD9F2FCBD495674DFC1555EFFB710EB081FC7D4CAE5FA58C438AB50405081
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
10
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
1372
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1372
svchost.exe
GET
200
2.18.97.123:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
1060
svchost.exe
GET
304
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a9f83325acc8ca75
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1372
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1060
svchost.exe
224.0.0.252:5355
unknown
1372
svchost.exe
2.19.126.163:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
unknown
1372
svchost.exe
2.18.97.123:80
www.microsoft.com
Akamai International B.V.
FR
unknown
1060
svchost.exe
2.19.126.163:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
ctldl.windowsupdate.com
  • 2.19.126.163
  • 2.19.126.137
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 2.18.97.123
whitelisted

Threats

No threats detected
No debug info