| File name: | Uninstall iZotope Ozone 7 Advanced.exe |
| Full analysis: | https://app.any.run/tasks/f09b4854-a0b9-405e-bd48-b3dcf08f9b54 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2024, 19:14:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed |
| MD5: | CCE294B123F434F8B3D0E89D34A60AC1 |
| SHA1: | 1C62ED1C04EE63DBB68A47F533C492A89649759F |
| SHA256: | 25C45611E4E7EADBAFC5418A494017A4B3A70D68D82507C999C3B2298F52D51D |
| SSDEEP: | 98304:hzujhg8U9O0UUIeVs6kPuQjuwrD9e4oes8SjMoQDhm/GxP8tjn7KSGemd0AY3/DS:hz7NoDF3VjK0 |
| .exe | | | UPX compressed Win32 Executable (39.3) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (38.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (9.5) |
| .exe | | | Win32 Executable (generic) (6.5) |
| .exe | | | Generic Win/DOS Executable (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:04:10 15:42:38+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Large address aware, 32-bit, No debug |
| PEType: | PE32 |
| LinkerVersion: | 2.22 |
| CodeSize: | 905216 |
| InitializedDataSize: | 77824 |
| UninitializedDataSize: | 1994752 |
| EntryPoint: | 0x2c4190 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 7.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| ProductName: | iZotope Ozone 7 |
| LegalTrademarks: | - |
| FileDescription: | - |
| InternalName: | - |
| CompanyName: | iZotope, Inc. |
| FileVersion: | 1.0.0.0 |
| LegalCopyright: | Copyright iZotope, Inc. |
| OriginalFileName: | setup.exe |
| Comments: | - |
| ProductVersion: | 7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4004 | "C:\Users\admin\AppData\Local\Temp\Uninstall iZotope Ozone 7 Advanced.exe" | C:\Users\admin\AppData\Local\Temp\Uninstall iZotope Ozone 7 Advanced.exe | explorer.exe | ||||||||||||
User: admin Company: iZotope, Inc. Integrity Level: HIGH Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 4044 | C:\Users\admin\AppData\Local\Temp\_uninstall\_uninstall4004 | C:\Users\admin\AppData\Local\Temp\_uninstall\_uninstall4004 | Uninstall iZotope Ozone 7 Advanced.exe | ||||||||||||
User: admin Company: iZotope, Inc. Integrity Level: HIGH Exit code: 1 Version: 1.0.0.0 Modules
| |||||||||||||||
| 4060 | "C:\Users\admin\AppData\Local\Temp\Uninstall iZotope Ozone 7 Advanced.exe" | C:\Users\admin\AppData\Local\Temp\Uninstall iZotope Ozone 7 Advanced.exe | — | explorer.exe | |||||||||||
User: admin Company: iZotope, Inc. Integrity Level: MEDIUM Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (4004) Uninstall iZotope Ozone 7 Advanced.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment |
| Operation: | write | Name: | BitRock |
Value: 1 | |||
| (PID) Process: | (4004) Uninstall iZotope Ozone 7 Advanced.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment |
| Operation: | delete value | Name: | BitRock |
Value: 1 | |||
| (PID) Process: | (4044) _uninstall4004 | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment |
| Operation: | write | Name: | BitRock |
Value: 1 | |||
| (PID) Process: | (4044) _uninstall4004 | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment |
| Operation: | delete value | Name: | BitRock |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4004 | Uninstall iZotope Ozone 7 Advanced.exe | C:\Users\admin\AppData\Local\Temp\BR2420.tmp | executable | |
MD5:027491B39A7B16B116E780F55ABC288E | SHA256:EEF69D005BF1C0B715C8D6205400D4755C261DD38DDFBBFE918E6EE91F21F1F0 | |||
| 4004 | Uninstall iZotope Ozone 7 Advanced.exe | C:\Users\admin\AppData\Local\Temp\_uninstall\_uninstall4004 | executable | |
MD5:CCE294B123F434F8B3D0E89D34A60AC1 | SHA256:25C45611E4E7EADBAFC5418A494017A4B3A70D68D82507C999C3B2298F52D51D | |||
| 4004 | Uninstall iZotope Ozone 7 Advanced.exe | C:\Users\admin\AppData\Local\Temp\be29e7f1-71ae-4703-50cb-1d52be512f51\twapi-be29e7f1-71ae-4703-50cb-1d52be512f51.dll | executable | |
MD5:A210F1AC135E5331C314CE5F394FB5A5 | SHA256:65B32EA2982078FB9A18E88FEEC238CB76ED2AE6C2BB4DDB0F6A9C4F57B1D62B | |||
| 4044 | _uninstall4004 | C:\Users\admin\AppData\Local\Temp\BR2FBB.tmp | executable | |
MD5:924B90C3D9E645DFAD53F61EA4E91942 | SHA256:41788435F245133EC5511111E2C5D52F7515E359876180067E0B5BA85C729322 | |||
| 4044 | _uninstall4004 | C:\Users\admin\AppData\Local\Temp\BR2AB7.tmp | executable | |
MD5:027491B39A7B16B116E780F55ABC288E | SHA256:EEF69D005BF1C0B715C8D6205400D4755C261DD38DDFBBFE918E6EE91F21F1F0 | |||
| 4004 | Uninstall iZotope Ozone 7 Advanced.exe | C:\Users\admin\AppData\Local\Temp\BR23A1.tmp | executable | |
MD5:08AD4CD2A940379F1DCDBDB9884A1375 | SHA256:78827E2B1EF0AAD4F8B1B42D0964064819AA22BFCD537EBAACB30D817EDC06D8 | |||
| 4044 | _uninstall4004 | C:\Users\admin\AppData\Local\Temp\BR308A.tmp | executable | |
MD5:606F13D4D580B1F322B3F3D3DF423BBA | SHA256:C71A16B1056E522CD0365449448116D06F37A3273D77694D170340064511DD25 | |||
| 4044 | _uninstall4004 | C:\Users\admin\AppData\Local\Temp\BR2A19.tmp | executable | |
MD5:08AD4CD2A940379F1DCDBDB9884A1375 | SHA256:78827E2B1EF0AAD4F8B1B42D0964064819AA22BFCD537EBAACB30D817EDC06D8 | |||
| 4044 | _uninstall4004 | C:\Users\admin\AppData\Local\Temp\BR298C.tmp | executable | |
MD5:D31FA7D86A093997DA6252A984B7B6BD | SHA256:32D6CBFB9433BEDFA29CC46A0B7D2AB0FB6D084E8F2E9A8C55295065BBAD5128 | |||
| 4044 | _uninstall4004 | C:\Users\admin\AppData\Local\Temp\BR3068.tmp | executable | |
MD5:5BBF62FAF1E96DEA7752DC930AE150AD | SHA256:39CA391D58EC87F407227C5129194D747CC690BAC514BBE735346C23DB0A5462 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |