File name:

SmartAudio3.exe

Full analysis: https://app.any.run/tasks/f8abbc5a-02b3-4589-8986-cfd26116ae2b
Verdict: Malicious activity
Analysis date: April 18, 2025, 06:03:20
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

86FDB0AE2945323BE4FF0478A7EC07F2

SHA1:

6806EEC878B406E77AF10E7F338BD5438EDC1B22

SHA256:

22C250C30BB4AAA6CBF40F1321EF7DBF477DBE768A44BA1CF12A0F99CE2ADE92

SSDEEP:

6144:DVZBU7XNPlbeAATV4oTaWGGYpZTV4oTaWGGYpL4wrniWS4wrniRTw4oMsWSYYpAP:DohATKakpZTKakprVTLfOpxm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • SmartAudio3.exe (PID: 7000)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • SmartAudio3.exe (PID: 7000)
    • Reads the date of Windows installation

      • dw20.exe (PID: 4776)
  • INFO

    • Checks proxy server information

      • SmartAudio3.exe (PID: 7000)
      • dw20.exe (PID: 4776)
    • Checks supported languages

      • SmartAudio3.exe (PID: 7000)
      • dw20.exe (PID: 4776)
    • Reads the computer name

      • SmartAudio3.exe (PID: 7000)
      • dw20.exe (PID: 4776)
    • Creates files or folders in the user directory

      • SmartAudio3.exe (PID: 7000)
      • dw20.exe (PID: 4776)
    • Reads the machine GUID from the registry

      • SmartAudio3.exe (PID: 7000)
      • dw20.exe (PID: 4776)
    • Reads the software policy settings

      • SmartAudio3.exe (PID: 7000)
      • dw20.exe (PID: 4776)
    • Reads product name

      • dw20.exe (PID: 4776)
    • Reads Environment values

      • dw20.exe (PID: 4776)
    • Process checks computer location settings

      • dw20.exe (PID: 4776)
    • Reads CPU info

      • dw20.exe (PID: 4776)
    • Creates files in the program directory

      • dw20.exe (PID: 4776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2019:12:10 08:10:22+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 492032
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.0.136.0
ProductVersionNumber: 4.0.136.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Audio Controls
CompanyName: Conexant Systems LLC.
FileDescription: Audio Controls Control Panel
FileVersion: 4.0.136.0
InternalName: SmartAudio3.exe
LegalCopyright: © 2011-2019 Conexant Systems LLC.
LegalTrademarks: -
OriginalFileName: SmartAudio3.exe
ProductName: SmartAudio3
ProductVersion: 4.0.136.0
AssemblyVersion: 4.0.136.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start smartaudio3.exe dw20.exe sppextcomobj.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2852C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
4380"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4776dw20.exe -x -s 1792C:\Windows\Microsoft.NET\Framework64\v2.0.50727\dw20.exe
SmartAudio3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Error Reporting Shim
Exit code:
0
Version:
2.0.50727.9149 (WinRelRS6.050727-9100)
Modules
Images
c:\windows\microsoft.net\framework64\v2.0.50727\dw20.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\msvcr80.dll
7000"C:\Users\admin\AppData\Local\Temp\SmartAudio3.exe" C:\Users\admin\AppData\Local\Temp\SmartAudio3.exe
explorer.exe
User:
admin
Company:
Conexant Systems LLC.
Integrity Level:
MEDIUM
Description:
Audio Controls Control Panel
Exit code:
3762507597
Version:
4.0.136.0
Modules
Images
c:\users\admin\appdata\local\temp\smartaudio3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
6 342
Read events
6 342
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
13
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4776dw20.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_SmartAudio3.exe_80419241f9dd758dca2a315d3d48cfa49185cc42_00000000_acab61c8-6517-4be3-b696-0dc37063c6bb\Report.wer
MD5:
SHA256:
7000SmartAudio3.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40C68D5626484A90937F0752C8B950ABbinary
MD5:4A4A5596EBC8465E160BCDFC0B6DBAA1
SHA256:5E9D428FEBBD16EFB568213AB5758D9483269D954358939B692E08DBEADFEE3E
7000SmartAudio3.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EA618097E393409AFA316F0F87E2C202_D620C07D0DD01583926B76876728A36Dbinary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
7000SmartAudio3.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40C68D5626484A90937F0752C8B950ABbinary
MD5:2AB172E9398A3F429D22A89DB10F024D
SHA256:4DFCA5F2F4907EFD537D7DB7D4A8B5D57A14B551EE62A0F4F3EF6B795C438262
4776dw20.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:3B5E0BD6640456A749D9155E6C135727
SHA256:C362A3D2B661C6066A02FC169FAAA1976C2F6160DA5837C7E68B7E0F67B794ED
7000SmartAudio3.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_6043FC604A395E1485AF7AC16D16B7CEbinary
MD5:AAC27A229CBBF75F6507A6B73E5C2D4A
SHA256:72E1497CF2C83D07129FF41E4F6C86809AA4FDFCB1DD3B2BAD5FFB99FE43ABED
7000SmartAudio3.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_6043FC604A395E1485AF7AC16D16B7CEbinary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
7000SmartAudio3.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\ECF3006D44DA211141391220EE5049F4binary
MD5:EA76383755F13428A897A66BE26A0DD9
SHA256:0A57129B893E28132135CF822FFBD9BDC0B6D0A059AE7569A6A2A2292671F04B
7000SmartAudio3.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EA618097E393409AFA316F0F87E2C202_D620C07D0DD01583926B76876728A36Dbinary
MD5:EFE117A8594866941B2A9A3A7C3574F6
SHA256:75D5E819347A13ADFF4F280039CB85A18536F7398A1604C721B3FCD3A354EBF2
4776dw20.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:3EC5CEA0DBCDF8AE76B12A13EE044DA1
SHA256:2E8C5208E521FE95E1A15F1DF735859A0D1674CEB75D1C5454918C99AC3F73AF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
28
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7000
SmartAudio3.exe
GET
200
2.17.189.192:80
http://s1.symcb.com/pca3-g5.crl
unknown
whitelisted
7000
SmartAudio3.exe
GET
200
2.17.189.192:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
unknown
whitelisted
7000
SmartAudio3.exe
GET
200
2.17.189.192:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
unknown
whitelisted
7000
SmartAudio3.exe
GET
200
2.17.189.192:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEGIQrA0d9NAl%2FxNnW1SqdXU%3D
unknown
whitelisted
7000
SmartAudio3.exe
GET
200
2.17.189.192:80
http://sv.symcb.com/sv.crl
unknown
whitelisted
2340
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2340
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7000
SmartAudio3.exe
GET
200
2.17.189.192:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEGIQrA0d9NAl%2FxNnW1SqdXU%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
7000
SmartAudio3.exe
2.17.189.192:80
s2.symcb.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4776
dw20.exe
20.42.73.29:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
s2.symcb.com
  • 2.17.189.192
whitelisted
s1.symcb.com
  • 2.17.189.192
whitelisted
sv.symcd.com
  • 2.17.189.192
whitelisted
sv.symcb.com
  • 2.17.189.192
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.68
  • 20.190.160.132
  • 40.126.32.74
  • 20.190.160.66
  • 40.126.32.134
  • 20.190.160.65
  • 20.190.160.64
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

No threats detected
No debug info