File name:

MidiEditor-3.3.0-Setup.exe

Full analysis: https://app.any.run/tasks/a987f674-2860-4129-bd10-f520fac0507d
Verdict: Malicious activity
Analysis date: February 23, 2025, 20:23:51
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, PECompact2 compressed, 2 sections
MD5:

2A80689EF41D5F3A728767D6594BEF0F

SHA1:

1267990DF9FA0070C49FBE754D8865EFCBB1F4FE

SHA256:

38F9DED6FE0AF635FB6598E167B29A7E9641A043FCEB0B1878F05C64EC4F63EE

SSDEEP:

98304:fnutgwAKEDNSPF/G30UTYvCMH8Hgt3i7bSoOF2ncRqPVD7hT5ct9TIidVKE1gvk6:SoHVTavYo3NHDt3RbRpufkH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • Creates a software uninstall entry

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • There is functionality for taking screenshot (YARA)

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
  • INFO

    • The sample compiled with english language support

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • Checks supported languages

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
      • MidiEditor.exe (PID: 7136)
    • Reads the computer name

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
      • MidiEditor.exe (PID: 7136)
    • Creates files or folders in the user directory

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • Create files in a temporary directory

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • Creates files in the program directory

      • MidiEditor-3.3.0-Setup.exe (PID: 6576)
    • Manual execution by a user

      • MidiEditor.exe (PID: 7136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (v2.x) (54.1)
.exe | Win32 EXE PECompact compressed (generic) (38)
.exe | Win32 Executable (generic) (4.1)
.exe | Generic Win/DOS Executable (1.8)
.exe | DOS Executable Generic (1.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:05:06 02:22:49+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.56
CodeSize: 1655296
InitializedDataSize: 2053632
UninitializedDataSize: 12800
EntryPoint: 0x12a0
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: MidiEditor 3.3.0 Setup
CompanyName: Markus Schwenk
ProductName: MidiEditor
FileVersion: 3.0.0.0
LegalCopyright: -
OriginalFileName: Windows-build.tmp
ProductVersion: 3.3.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start midieditor-3.3.0-setup.exe midieditor.exe no specs midieditor-3.3.0-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6408"C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exe" C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exeexplorer.exe
User:
admin
Company:
Markus Schwenk
Integrity Level:
MEDIUM
Description:
MidiEditor 3.3.0 Setup
Exit code:
3221226540
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\midieditor-3.3.0-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6576"C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exe" C:\Users\admin\AppData\Local\Temp\MidiEditor-3.3.0-Setup.exe
explorer.exe
User:
admin
Company:
Markus Schwenk
Integrity Level:
HIGH
Description:
MidiEditor 3.3.0 Setup
Exit code:
0
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\midieditor-3.3.0-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7136"C:\Program Files (x86)\MidiEditor\MidiEditor.exe" C:\Program Files (x86)\MidiEditor\MidiEditor.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files (x86)\midieditor\midieditor.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
Total events
1 299
Read events
1 137
Write events
161
Delete events
1

Modification events

(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:NoModify
Value:
1
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:NoRepair
Value:
1
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\MidiEditor
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:InstallSource
Value:
C:\Users\admin\AppData\Local\Temp
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:QuietUninstallString
Value:
C:\Program Files (x86)\MidiEditor\uninstall.exe -S
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:URLUpdateInfo
Value:
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:URLInfoAbout
Value:
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:DisplayVersion
Value:
3.3.0
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:HelpTelephone
Value:
(PID) Process:(6576) MidiEditor-3.3.0-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1
Operation:writeName:InstallDate
Value:
20250223
Executable files
4
Suspicious files
5
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Local\Temp\ijtmp_BA26967B-5A93-45FA-9F57-E9A4A032FCF0\installkit.exeexecutable
MD5:47CE4717FE3B6FB704B74612F4116E6E
SHA256:FE7A43BD2A90E08514F188962F16C82811B3F703369EF5191907968FEAA3ACB7
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\Desktop\MidiEditor.lnkbinary
MD5:572DB0AA2A0ACDE85CE4AE868A16A22D
SHA256:88EAAA929DDE86CAFE0763D4D727A530AA1E71814E0A68D49D2B3151EE5FC50B
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MidiEditor\MidiEditor.lnkbinary
MD5:6C5BF574E01D6A8EFCAD7AB991C9D8AF
SHA256:0437914C48C3B47794335FC790F0715508084664DB46B737FCDC19F63715E44E
6576MidiEditor-3.3.0-Setup.exeC:\Program Files (x86)\InstallJammer Registry\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1\76180E35-BB51-472D-A895-970ED11513E1.infotext
MD5:0F139586EAC8C990668FE01B6E1C8430
SHA256:7FB625471B58DBF878B8114F17AEF2CE8556B03EF49B748F8524BBA11027DE02
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MidiEditor\Uninstall MidiEditor.lnkbinary
MD5:582641C3EA36E39BD0C41C6AA859B3AC
SHA256:2A854FEE89FEECFEE38F6FA95EE5F62D4F681E94E354FB34216004ECCA0C7E9D
6576MidiEditor-3.3.0-Setup.exeC:\Program Files (x86)\InstallJammer Registry\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1\76180E35-BB51-472D-A895-970ED11513E1.vertext
MD5:79B2AF9AF2AE0483D8A0F1F57A3FEAC4
SHA256:DED3FA85DC7BA6BFD0A3921CD9BF4081D529AEF3ECF437A8A73C3DBB9F6318C5
6576MidiEditor-3.3.0-Setup.exeC:\Program Files (x86)\InstallJammer Registry\D4338446-FFE6-1A12-ACFF-CB6F6A6A70A1\76180E35-BB51-472D-A895-970ED11513E1.logtext
MD5:3F5E9ADD84B3F853C3226FAFF6D5ED0F
SHA256:DC8A91CFFD5D35407560676B22BD69637062194A4B4AFB0216F3C7F4F67018B5
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Local\Temp\ijtmp_BA26967B-5A93-45FA-9F57-E9A4A032FCF0\unpack.tcltext
MD5:0F0528968C6D4B5D4D0C030DB2628EDB
SHA256:029615D7DDD9D1AE1DFC711BB88550D4DE960B9A7BF70DB55DC58A98B094E942
6576MidiEditor-3.3.0-Setup.exeC:\Program Files (x86)\MidiEditor\uninstall.exeexecutable
MD5:D5E52FF598AB36DFFA3EBA9497635675
SHA256:9724684721396E2BB72954ECAEF75453D34117C099FD383CFF21C0E5833DBC8A
6576MidiEditor-3.3.0-Setup.exeC:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MidiEditor.lnkbinary
MD5:419F8682C78A864B851049C6D0F2FDC4
SHA256:3BB926A8D3906FF5CE4AC36C507A88271DB71F86D12822A92EC2DC509F453A65
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
31
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6208
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6208
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6668
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4536
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1612
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.163:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.166
  • 23.48.23.158
  • 23.48.23.176
  • 23.48.23.141
  • 23.48.23.161
  • 23.48.23.167
  • 23.48.23.173
  • 23.48.23.169
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 172.217.18.14
whitelisted
www.bing.com
  • 104.126.37.163
  • 104.126.37.144
  • 104.126.37.162
  • 104.126.37.139
  • 104.126.37.155
  • 104.126.37.154
  • 104.126.37.176
  • 104.126.37.145
  • 104.126.37.171
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.160.14
  • 20.190.160.5
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.2
  • 20.190.160.20
  • 20.190.160.130
  • 40.126.32.136
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
No debug info