| File name: | MidiEditor-3.3.0-Setup.exe |
| Full analysis: | https://app.any.run/tasks/a987f674-2860-4129-bd10-f520fac0507d |
| Verdict: | Malicious activity |
| Analysis date: | February 23, 2025, 20:23:51 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, PECompact2 compressed, 2 sections |
| MD5: | 2A80689EF41D5F3A728767D6594BEF0F |
| SHA1: | 1267990DF9FA0070C49FBE754D8865EFCBB1F4FE |
| SHA256: | 38F9DED6FE0AF635FB6598E167B29A7E9641A043FCEB0B1878F05C64EC4F63EE |
| SSDEEP: | 98304:fnutgwAKEDNSPF/G30UTYvCMH8Hgt3i7bSoOF2ncRqPVD7hT5ct9TIidVKE1gvk6:SoHVTavYo3NHDt3RbRpufkH |
| .exe | | | Win32 EXE PECompact compressed (v2.x) (54.1) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (38) |
| .exe | | | Win32 Executable (generic) (4.1) |
| .exe | | | Generic Win/DOS Executable (1.8) |
| .exe | | | DOS Executable Generic (1.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:05:06 02:22:49+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, 32-bit, No debug |
| PEType: | PE32 |
| LinkerVersion: | 2.56 |
| CodeSize: | 1655296 |
| InitializedDataSize: | 2053632 |
| UninitializedDataSize: | 12800 |
| EntryPoint: | 0x12a0 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileDescription: | MidiEditor 3.3.0 Setup |
| CompanyName: | Markus Schwenk |
| ProductName: | MidiEditor |
| FileVersion: | 3.0.0.0 |
| LegalCopyright: | - |
| OriginalFileName: | Windows-build.tmp |
| ProductVersion: | 3.3.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6408 | "C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exe" | C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exe | — | explorer.exe | |||||||||||
User: admin Company: Markus Schwenk Integrity Level: MEDIUM Description: MidiEditor 3.3.0 Setup Exit code: 3221226540 Version: 3.0.0.0 Modules
| |||||||||||||||
| 6576 | "C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exe" | C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Markus Schwenk Integrity Level: HIGH Description: MidiEditor 3.3.0 Setup Exit code: 0 Version: 3.0.0.0 Modules
| |||||||||||||||
| 7136 | "C:\Program Files (x86)\MidiEditor\MidiEditor.exe" | C:\Program Files (x86)\MidiEditor\MidiEditor.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (6576) MidiEditor-3.3.0-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1 |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (6576) MidiEditor-3.3.0-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1 |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
| (PID) Process: | (6576) MidiEditor-3.3.0-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files (x86)\MidiEditor | |||
| (PID) Process: | (6576) MidiEditor-3.3.0-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1 |
| Operation: | write | Name: | InstallSource |
Value: C:\Users\admin\AppData\Local\Temp | |||
| (PID) Process: | (6576) MidiEditor-3.3.0-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1 |
| Operation: | write | Name: | QuietUninstallString |
Value: C:\Program Files (x86)\MidiEditor\uninstall.exe -S | |||
| (PID) Process: | (6576) MidiEditor-3.3.0-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1 |
| Operation: | write | Name: | URLUpdateInfo |
Value: | |||
| (PID) Process: | (6576) MidiEditor-3.3.0-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1 |
| Operation: | write | Name: | URLInfoAbout |
Value: | |||
| (PID) Process: | (6576) MidiEditor-3.3.0-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1 |
| Operation: | write | Name: | DisplayVersion |
Value: 3.3.0 | |||
| (PID) Process: | (6576) MidiEditor-3.3.0-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1 |
| Operation: | write | Name: | HelpTelephone |
Value: | |||
| (PID) Process: | (6576) MidiEditor-3.3.0-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1 |
| Operation: | write | Name: | InstallDate |
Value: 20250223 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6576 | MidiEditor-3.3.0-Setup.exe | C:\Users\admin\AppData\Local\Temp\ijtmp_BA26967B-5A93-45FA-9F57-E9A4A032FCF0\installkit.exe | executable | |
MD5:47CE4717FE3B6FB704B74612F4116E6E | SHA256:FE7A43BD2A90E08514F188962F16C82811B3F703369EF5191907968FEAA3ACB7 | |||
| 6576 | MidiEditor-3.3.0-Setup.exe | C:\Users\admin\Desktop\MidiEditor.lnk | binary | |
MD5:572DB0AA2A0ACDE85CE4AE868A16A22D | SHA256:88EAAA929DDE86CAFE0763D4D727A530AA1E71814E0A68D49D2B3151EE5FC50B | |||
| 6576 | MidiEditor-3.3.0-Setup.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MidiEditor\MidiEditor.lnk | binary | |
MD5:6C5BF574E01D6A8EFCAD7AB991C9D8AF | SHA256:0437914C48C3B47794335FC790F0715508084664DB46B737FCDC19F63715E44E | |||
| 6576 | MidiEditor-3.3.0-Setup.exe | C:\Program Files (x86)\InstallJammer Registry\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1\76180E35-BB51-472D-A895-970ED11513E1.info | text | |
MD5:0F139586EAC8C990668FE01B6E1C8430 | SHA256:7FB625471B58DBF878B8114F17AEF2CE8556B03EF49B748F8524BBA11027DE02 | |||
| 6576 | MidiEditor-3.3.0-Setup.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MidiEditor\Uninstall MidiEditor.lnk | binary | |
MD5:582641C3EA36E39BD0C41C6AA859B3AC | SHA256:2A854FEE89FEECFEE38F6FA95EE5F62D4F681E94E354FB34216004ECCA0C7E9D | |||
| 6576 | MidiEditor-3.3.0-Setup.exe | C:\Program Files (x86)\InstallJammer Registry\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1\76180E35-BB51-472D-A895-970ED11513E1.ver | text | |
MD5:79B2AF9AF2AE0483D8A0F1F57A3FEAC4 | SHA256:DED3FA85DC7BA6BFD0A3921CD9BF4081D529AEF3ECF437A8A73C3DBB9F6318C5 | |||
| 6576 | MidiEditor-3.3.0-Setup.exe | C:\Program Files (x86)\InstallJammer Registry\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1\76180E35-BB51-472D-A895-970ED11513E1.log | text | |
MD5:3F5E9ADD84B3F853C3226FAFF6D5ED0F | SHA256:DC8A91CFFD5D35407560676B22BD69637062194A4B4AFB0216F3C7F4F67018B5 | |||
| 6576 | MidiEditor-3.3.0-Setup.exe | C:\Users\admin\AppData\Local\Temp\ijtmp_BA26967B-5A93-45FA-9F57-E9A4A032FCF0\unpack.tcl | text | |
MD5:0F0528968C6D4B5D4D0C030DB2628EDB | SHA256:029615D7DDD9D1AE1DFC711BB88550D4DE960B9A7BF70DB55DC58A98B094E942 | |||
| 6576 | MidiEditor-3.3.0-Setup.exe | C:\Program Files (x86)\MidiEditor\uninstall.exe | executable | |
MD5:D5E52FF598AB36DFFA3EBA9497635675 | SHA256:9724684721396E2BB72954ECAEF75453D34117C099FD383CFF21C0E5833DBC8A | |||
| 6576 | MidiEditor-3.3.0-Setup.exe | C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MidiEditor.lnk | binary | |
MD5:419F8682C78A864B851049C6D0F2FDC4 | SHA256:3BB926A8D3906FF5CE4AC36C507A88271DB71F86D12822A92EC2DC509F453A65 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6208 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6208 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6668 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4536 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1612 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 104.126.37.163:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 20.190.160.14:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |