File name:

SoundBoosterSetup.exe

Full analysis: https://app.any.run/tasks/e1b85b0e-cbb2-4438-9ede-b944b2254618
Verdict: Malicious activity
Analysis date: June 20, 2024, 14:10:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
vmprotect
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

99AA185A295411F72303FA9B7A497795

SHA1:

04CBAB9197165B1648EF6FCBF0D1B60D2E0F7A95

SHA256:

4C00A2F66BB1D2470B17EF277F5F12A90FF2FC86A258CB82BF294835B87D4E02

SSDEEP:

98304:hgVrBdoUFz1tgDp5uw27QaYrvBX4+YgnFOt+s0y1m9MRVPCC+RJUrLO5nGj1ysQd:G/rXKWDFWolprO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SoundBoosterSetup.exe (PID: 2748)
      • SoundBoosterSetup.exe (PID: 3392)
      • SoundBoosterSetup.tmp (PID: 2936)
    • Registers / Runs the DLL via REGSVR32.EXE

      • SoundBoosterTaskHost.exe (PID: 2348)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • SoundBoosterSetup.tmp (PID: 2936)
    • Executable content was dropped or overwritten

      • SoundBoosterSetup.exe (PID: 2748)
      • SoundBoosterSetup.exe (PID: 3392)
      • SoundBoosterSetup.tmp (PID: 2936)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 996)
    • Reads the Internet Settings

      • SoundBooster.exe (PID: 2512)
      • SoundBoosterTaskHost.exe (PID: 2348)
    • Reads security settings of Internet Explorer

      • SoundBoosterTaskHost.exe (PID: 2348)
      • SoundBooster.exe (PID: 2512)
  • INFO

    • Creates files in the program directory

      • SoundBoosterSetup.tmp (PID: 2936)
      • SoundBoosterTaskHost.exe (PID: 3716)
      • SoundBooster.exe (PID: 2512)
    • Reads the computer name

      • SoundBoosterSetup.tmp (PID: 2936)
      • SoundBoosterTaskHost.exe (PID: 2348)
      • SoundBoosterSetup.tmp (PID: 3424)
      • SoundBoosterTaskHost.exe (PID: 3716)
      • SoundBoosterService.exe (PID: 3672)
      • SoundBooster.exe (PID: 2512)
    • Create files in a temporary directory

      • SoundBoosterSetup.tmp (PID: 2936)
      • SoundBoosterSetup.exe (PID: 2748)
      • SoundBoosterSetup.exe (PID: 3392)
    • Checks supported languages

      • SoundBoosterTaskHost.exe (PID: 2348)
      • SoundBoosterSetup.exe (PID: 2748)
      • SoundBoosterSetup.tmp (PID: 3424)
      • SoundBoosterSetup.tmp (PID: 2936)
      • SoundBoosterSetup.exe (PID: 3392)
      • SoundBoosterTaskHost.exe (PID: 3716)
      • SoundBoosterService.exe (PID: 3672)
      • SoundBooster.exe (PID: 2512)
    • Creates a software uninstall entry

      • SoundBoosterSetup.tmp (PID: 2936)
    • Manual execution by a user

      • SoundBooster.exe (PID: 2512)
      • SoundBooster.exe (PID: 1596)
    • Checks proxy server information

      • SoundBooster.exe (PID: 2512)
    • Reads the machine GUID from the registry

      • SoundBooster.exe (PID: 2512)
    • Creates files or folders in the user directory

      • SoundBooster.exe (PID: 2512)
    • VMProtect has been detected

      • SoundBooster.exe (PID: 2512)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:06 14:39:04+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 344576
UninitializedDataSize: -
EntryPoint: 0x117dc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.12.0.538
ProductVersionNumber: 1.12.0.538
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Letasoft LLC
FileDescription: Letasoft Sound Booster Setup
FileVersion: 1.12.0.538
LegalCopyright: Copyright © Letasoft LLC
ProductName: Letasoft Sound Booster
ProductVersion: 1.12.0.538
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
11
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
996"C:\Windows\System32\regsvr32.exe" /s "C:\Program Files\Letasoft Sound Booster\Sbapo.dll"C:\Windows\System32\regsvr32.exeSoundBoosterTaskHost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1596"C:\Program Files\Letasoft Sound Booster\SoundBooster.exe" C:\Program Files\Letasoft Sound Booster\SoundBooster.exeexplorer.exe
User:
admin
Company:
Letasoft
Integrity Level:
MEDIUM
Description:
Sound Booster Application
Exit code:
3221226540
Version:
1.12.0.538
Modules
Images
c:\program files\letasoft sound booster\soundbooster.exe
c:\windows\system32\ntdll.dll
2348"C:\Program Files\Letasoft Sound Booster\SoundBoosterTaskHost.exe" -InstallAPOC:\Program Files\Letasoft Sound Booster\SoundBoosterTaskHost.exeSoundBoosterSetup.tmp
User:
admin
Company:
Letasoft
Integrity Level:
HIGH
Description:
Sound Booster Task Host Application
Exit code:
0
Version:
1.12.0.538
Modules
Images
c:\program files\letasoft sound booster\soundboostertaskhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2512"C:\Program Files\Letasoft Sound Booster\SoundBooster.exe" C:\Program Files\Letasoft Sound Booster\SoundBooster.exe
explorer.exe
User:
admin
Company:
Letasoft
Integrity Level:
HIGH
Description:
Sound Booster Application
Version:
1.12.0.538
Modules
Images
c:\program files\letasoft sound booster\soundbooster.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2748"C:\Users\admin\AppData\Local\Temp\SoundBoosterSetup.exe" /SPAWNWND=$F0168 /NOTIFYWND=$5010A C:\Users\admin\AppData\Local\Temp\SoundBoosterSetup.exe
SoundBoosterSetup.tmp
User:
admin
Company:
Letasoft LLC
Integrity Level:
HIGH
Description:
Letasoft Sound Booster Setup
Exit code:
0
Version:
1.12.0.538
Modules
Images
c:\users\admin\appdata\local\temp\soundboostersetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2936"C:\Users\admin\AppData\Local\Temp\is-UD52G.tmp\SoundBoosterSetup.tmp" /SL5="$7015A,6484768,412160,C:\Users\admin\AppData\Local\Temp\SoundBoosterSetup.exe" /SPAWNWND=$F0168 /NOTIFYWND=$5010A C:\Users\admin\AppData\Local\Temp\is-UD52G.tmp\SoundBoosterSetup.tmp
SoundBoosterSetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ud52g.tmp\soundboostersetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3296"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3392"C:\Users\admin\AppData\Local\Temp\SoundBoosterSetup.exe" C:\Users\admin\AppData\Local\Temp\SoundBoosterSetup.exe
explorer.exe
User:
admin
Company:
Letasoft LLC
Integrity Level:
MEDIUM
Description:
Letasoft Sound Booster Setup
Exit code:
0
Version:
1.12.0.538
Modules
Images
c:\users\admin\appdata\local\temp\soundboostersetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3424"C:\Users\admin\AppData\Local\Temp\is-J16PH.tmp\SoundBoosterSetup.tmp" /SL5="$5010A,6484768,412160,C:\Users\admin\AppData\Local\Temp\SoundBoosterSetup.exe" C:\Users\admin\AppData\Local\Temp\is-J16PH.tmp\SoundBoosterSetup.tmpSoundBoosterSetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-j16ph.tmp\soundboostersetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3672"C:\Program Files\Letasoft Sound Booster\SoundBoosterService.exe" -installC:\Program Files\Letasoft Sound Booster\SoundBoosterService.exeSoundBoosterSetup.tmp
User:
admin
Company:
Letasoft
Integrity Level:
HIGH
Description:
Sound Booster Service
Exit code:
0
Version:
1.12.0.538
Modules
Images
c:\program files\letasoft sound booster\soundboosterservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
5 692
Read events
5 587
Write events
95
Delete events
10

Modification events

(PID) Process:(2936) SoundBoosterSetup.tmpKey:HKEY_CURRENT_USER\Software\Letasoft\Sound Booster
Operation:writeName:LangGUI
Value:
1033
(PID) Process:(2936) SoundBoosterSetup.tmpKey:HKEY_CURRENT_USER\Software\Letasoft\Sound Booster\Options
Operation:writeName:SoundLevel
Value:
300
(PID) Process:(2936) SoundBoosterSetup.tmpKey:HKEY_CURRENT_USER\Software\Letasoft\Sound Booster\Options
Operation:writeName:BoostIsEnabled
Value:
1
(PID) Process:(2936) SoundBoosterSetup.tmpKey:HKEY_CURRENT_USER\Software\Letasoft\Sound Booster\Options
Operation:writeName:BoostMethod
Value:
1
(PID) Process:(2936) SoundBoosterSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Letasoft\Sound Booster
Operation:writeName:LangGUI
Value:
1033
(PID) Process:(2936) SoundBoosterSetup.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client
Operation:writeName:DisabledByDefault
Value:
0
(PID) Process:(2936) SoundBoosterSetup.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client
Operation:writeName:Enabled
Value:
1
(PID) Process:(2936) SoundBoosterSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6C6CF38B-11DD-45C6-A15E-A3A0C4CE60F8}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.9 (u)
(PID) Process:(2936) SoundBoosterSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6C6CF38B-11DD-45C6-A15E-A3A0C4CE60F8}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Letasoft Sound Booster
(PID) Process:(2936) SoundBoosterSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6C6CF38B-11DD-45C6-A15E-A3A0C4CE60F8}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Letasoft Sound Booster\
Executable files
38
Suspicious files
8
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
2936SoundBoosterSetup.tmpC:\Program Files\Letasoft Sound Booster\is-NJ0M0.tmpexecutable
MD5:73284BAC5AE39DDC8A67EFFE040A3349
SHA256:E0DD2F06DD96E8167168517CFB611456E3FBEA57A116916D4C4A1AA4D84D35CA
2748SoundBoosterSetup.exeC:\Users\admin\AppData\Local\Temp\is-UD52G.tmp\SoundBoosterSetup.tmpexecutable
MD5:A5E43FF07BF378503CF45D6EE7778021
SHA256:48CC8C44E665CC3A24A1EF0807BCD87BDCC0AD9FF179C8D5C96924EBA48888F2
3392SoundBoosterSetup.exeC:\Users\admin\AppData\Local\Temp\is-J16PH.tmp\SoundBoosterSetup.tmpexecutable
MD5:A5E43FF07BF378503CF45D6EE7778021
SHA256:48CC8C44E665CC3A24A1EF0807BCD87BDCC0AD9FF179C8D5C96924EBA48888F2
2936SoundBoosterSetup.tmpC:\Program Files\Letasoft Sound Booster\is-MBEVN.tmpexecutable
MD5:A5E43FF07BF378503CF45D6EE7778021
SHA256:48CC8C44E665CC3A24A1EF0807BCD87BDCC0AD9FF179C8D5C96924EBA48888F2
2936SoundBoosterSetup.tmpC:\Program Files\Letasoft Sound Booster\unins000.exeexecutable
MD5:A5E43FF07BF378503CF45D6EE7778021
SHA256:48CC8C44E665CC3A24A1EF0807BCD87BDCC0AD9FF179C8D5C96924EBA48888F2
2936SoundBoosterSetup.tmpC:\Program Files\Letasoft Sound Booster\SoundBooster.exeexecutable
MD5:73284BAC5AE39DDC8A67EFFE040A3349
SHA256:E0DD2F06DD96E8167168517CFB611456E3FBEA57A116916D4C4A1AA4D84D35CA
2936SoundBoosterSetup.tmpC:\Program Files\Letasoft Sound Booster\Lang\is-E1MN4.tmpexecutable
MD5:56916EA3B9A10D00FEB9818C3068F4A8
SHA256:C64E4820A0B8A29ECC71B4EF43C318D7CF2682270D39C53CB3980BEF0E24D2CC
2936SoundBoosterSetup.tmpC:\Program Files\Letasoft Sound Booster\is-374BK.tmpexecutable
MD5:FEDE08587BCE8D2931BAECC55BF2D0C1
SHA256:9508EEBBDBAE1FC2EB6A4D3D3CF7E12B4EA2CC05DF7F7219B259D5AFC2A7C8CC
2936SoundBoosterSetup.tmpC:\Program Files\Letasoft Sound Booster\Lang\SoundBoosterRU.dllexecutable
MD5:56916EA3B9A10D00FEB9818C3068F4A8
SHA256:C64E4820A0B8A29ECC71B4EF43C318D7CF2682270D39C53CB3980BEF0E24D2CC
2936SoundBoosterSetup.tmpC:\Program Files\Letasoft Sound Booster\UltraActivate.dllexecutable
MD5:FEDE08587BCE8D2931BAECC55BF2D0C1
SHA256:9508EEBBDBAE1FC2EB6A4D3D3CF7E12B4EA2CC05DF7F7219B259D5AFC2A7C8CC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
12
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
unknown
1372
svchost.exe
GET
304
2.16.100.168:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
DE
unknown
1372
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
unknown
2512
SoundBooster.exe
GET
200
70.32.23.76:80
http://files.letasoft.com/updates/soundbooster/appver
US
text
46 b
unknown
2512
SoundBooster.exe
GET
200
70.32.23.76:80
http://files.letasoft.com/updates/soundbooster/changelog
US
text
2.05 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
239.255.255.250:3702
unknown
1372
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1060
svchost.exe
224.0.0.252:5355
unknown
1372
svchost.exe
2.16.100.168:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
whitelisted
1372
svchost.exe
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
unknown
1372
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2512
SoundBooster.exe
70.32.23.76:80
files.letasoft.com
A2HOSTING
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
ctldl.windowsupdate.com
  • 2.16.100.168
  • 88.221.110.91
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.106
  • 2.16.164.43
  • 2.16.164.51
  • 2.16.164.72
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
files.letasoft.com
  • 70.32.23.76
unknown

Threats

No threats detected
No debug info