File name:

MidiEditor-3.3.0-Setup.exe

Full analysis: https://app.any.run/tasks/a987f674-2860-4129-bd10-f520fac0507d
Verdict: Malicious activity
Analysis date: February 23, 2025, 20:23:51
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, PECompact2 compressed, 2 sections
MD5:

2A80689EF41D5F3A728767D6594BEF0F

SHA1:

1267990DF9FA0070C49FBE754D8865EFCBB1F4FE

SHA256:

38F9DED6FE0AF635FB6598E167B29A7E9641A043FCEB0B1878F05C64EC4F63EE

SSDEEP:

98304:fnutgwAKEDNSPF/G30UTYvCMH8Hgt3i7bSoOF2ncRqPVD7hT5ct9TIidVKE1gvk6:SoHVTavYo3NHDt3RbRpufkH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • Executable content was dropped or overwritten

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • Creates a software uninstall entry

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
  • INFO

    • Creates files or folders in the user directory

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • Creates files in the program directory

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • Checks supported languages

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
      • MidiEditor.exe (PID: 7136)
    • Reads the computer name

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
      • MidiEditor.exe (PID: 7136)
    • The sample compiled with english language support

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • Manual execution by a user

      • MidiEditor.exe (PID: 7136)
    • Create files in a temporary directory

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (v2.x) (54.1)
.exe | Win32 EXE PECompact compressed (generic) (38)
.exe | Win32 Executable (generic) (4.1)
.exe | Generic Win/DOS Executable (1.8)
.exe | DOS Executable Generic (1.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:05:06 02:22:49+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.56
CodeSize: 1655296
InitializedDataSize: 2053632
UninitializedDataSize: 12800
EntryPoint: 0x12a0
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: MidiEditor 3.3.0 Setup
CompanyName: Markus Schwenk
ProductName: MidiEditor
FileVersion: 3.0.0.0
LegalCopyright: -
OriginalFileName: Windows-build.tmp
ProductVersion: 3.3.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start midieditor-3.3.0-setup.exe midieditor.exe no specs midieditor-3.3.0-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6408"C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exe" C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exeexplorer.exe
User:
admin
Company:
Markus Schwenk
Integrity Level:
MEDIUM
Description:
MidiEditor 3.3.0 Setup
Exit code:
3221226540
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\midieditor-3.3.0-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6576"C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exe" C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exe
explorer.exe
User:
admin
Company:
Markus Schwenk
Integrity Level:
HIGH
Description:
MidiEditor 3.3.0 Setup
Exit code:
0
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\midieditor-3.3.0-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7136"C:\Program Files (x86)\MidiEditor\MidiEditor.exe" C:\Program Files (x86)\MidiEditor\MidiEditor.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files (x86)\midieditor\midieditor.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
Total events
1 299
Read events
1 137
Write events
161
Delete events
1

Modification events

(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:NoModify
Value:
1
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:NoRepair
Value:
1
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\MidiEditor
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:InstallSource
Value:
C:\Users\admin\AppData\Local\Temp
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:QuietUninstallString
Value:
C:\Program Files (x86)\MidiEditor\uninstall.exe -S
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:URLUpdateInfo
Value:
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:URLInfoAbout
Value:
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:DisplayVersion
Value:
3.3.0
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:HelpTelephone
Value:
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:InstallDate
Value:
20250223
Executable files
4
Suspicious files
5
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
6576MidiEditor-3.3.0-Setup.exeC:\Program Files (x86)\MidiEditor\uninstall.exeexecutable
MD5:D5E52FF598AB36DFFA3EBA9497635675
SHA256:9724684721396E2BB72954ECAEF75453D34117C099FD383CFF21C0E5833DBC8A
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Local\Temp\ijtmp_BA26967B-5A93-45FA-9F57-E9A4A032FCF0\unpack.initext
MD5:EEF0653CB84F26C309D00A78912C9938
SHA256:8FC2F1779686DE20983F880548C722EE14F6ABBCA26E021CB469E95336BF6C8F
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Local\Temp\TCL50F2.tmpexecutable
MD5:A468DD92DC57984EC6CF6CF96AFAFE4E
SHA256:FE7BF5564228AE806002BCCB63122FD81C27ECBCEBFB061D7FF2DBD2AE5D5E4A
6576MidiEditor-3.3.0-Setup.exeC:\Program Files (x86)\MidiEditor\MidiEditor.exeexecutable
MD5:7EB105E83023EE8658A2997CC804FEF1
SHA256:6353C2FDB4E54668E7C8B23836763030435483FF3046107D144B381EABF615ED
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Local\Temp\ijtmp_BA26967B-5A93-45FA-9F57-E9A4A032FCF0\installkit.exeexecutable
MD5:47CE4717FE3B6FB704B74612F4116E6E
SHA256:FE7A43BD2A90E08514F188962F16C82811B3F703369EF5191907968FEAA3ACB7
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Local\Temp\ijtmp_BA26967B-5A93-45FA-9F57-E9A4A032FCF0\unpack.tcltext
MD5:0F0528968C6D4B5D4D0C030DB2628EDB
SHA256:029615D7DDD9D1AE1DFC711BB88550D4DE960B9A7BF70DB55DC58A98B094E942
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Local\Temp\ijtmp_BA26967B-5A93-45FA-9F57-E9A4A032FCF0\uninstall.tcltext
MD5:97861789EC599E1B308A53AF9ABAFB02
SHA256:221A0D6BA03E9DD155DC23B035578E034D49FDE01A7996CFC52CBD9CCE6F0172
6576MidiEditor-3.3.0-Setup.exeC:\Program Files (x86)\MidiEditor\metronome\metronome-01.wavbinary
MD5:4E9BC925131BB1DC90731AD08AA56BDD
SHA256:9BDA523044EE30F2064F1C4CB79903FDBF52CEC8301FFBE3FB32B5B7D5210EE8
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\Desktop\MidiEditor.lnkbinary
MD5:572DB0AA2A0ACDE85CE4AE868A16A22D
SHA256:88EAAA929DDE86CAFE0763D4D727A530AA1E71814E0A68D49D2B3151EE5FC50B
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MidiEditor\MidiEditor.lnkbinary
MD5:6C5BF574E01D6A8EFCAD7AB991C9D8AF
SHA256:0437914C48C3B47794335FC790F0715508084664DB46B737FCDC19F63715E44E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
31
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6668
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6208
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6208
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4536
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1612
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.163:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.166
  • 23.48.23.158
  • 23.48.23.176
  • 23.48.23.141
  • 23.48.23.161
  • 23.48.23.167
  • 23.48.23.173
  • 23.48.23.169
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 172.217.18.14
whitelisted
www.bing.com
  • 104.126.37.163
  • 104.126.37.144
  • 104.126.37.162
  • 104.126.37.139
  • 104.126.37.155
  • 104.126.37.154
  • 104.126.37.176
  • 104.126.37.145
  • 104.126.37.171
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.160.14
  • 20.190.160.5
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.2
  • 20.190.160.20
  • 20.190.160.130
  • 40.126.32.136
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
No debug info