File name:

SoulseekQt-2024-2-1-32bit.exe

Full analysis: https://app.any.run/tasks/46256374-1da0-4213-8022-122d2f023926
Verdict: Malicious activity
Analysis date: March 27, 2024, 23:22:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F95B5D026B139764DF7BBC6619AAE09C

SHA1:

60ECCBCC0E291F98C28906FCC7C3DA21B308E197

SHA256:

4CAB5706B3A865B2550FC69A33B179AF75086BDDEDC617A7A0BD0AE36A72D056

SSDEEP:

98304:J+cD4dneHkcxMwqlgnPnqRNeS/c4xs3HGS9xgd8KNSzUFXMuGb2V5qgtGwmtveAT:cl1XLf6zICe79uut65HRasat6UyJw2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SoulseekQt-2024-2-1-32bit.exe (PID: 2120)
      • SoulseekQt-2024-2-1-32bit.exe (PID: 2672)
      • SoulseekQt-2024-2-1-32bit.tmp (PID: 956)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • SoulseekQt-2024-2-1-32bit.tmp (PID: 956)
    • Reads the Internet Settings

      • SoulseekQt.exe (PID: 1740)
      • SoulseekQt.exe (PID: 2564)
    • Connects to unusual port

      • SoulseekQt.exe (PID: 1740)
      • SoulseekQt.exe (PID: 2564)
    • Non-standard symbols in registry

      • SoulseekQt-2024-2-1-32bit.tmp (PID: 956)
  • INFO

    • Create files in a temporary directory

      • SoulseekQt-2024-2-1-32bit.exe (PID: 2120)
      • SoulseekQt.exe (PID: 1740)
      • SoulseekQt-2024-2-1-32bit.exe (PID: 2672)
    • Checks supported languages

      • SoulseekQt-2024-2-1-32bit.exe (PID: 2120)
      • SoulseekQt-2024-2-1-32bit.tmp (PID: 956)
      • SoulseekQt.exe (PID: 1740)
      • SoulseekQt.exe (PID: 2804)
      • SoulseekQt.exe (PID: 2564)
      • SoulseekQt.exe (PID: 568)
      • SoulseekQt.exe (PID: 1864)
      • SoulseekQt-2024-2-1-32bit.tmp (PID: 3956)
      • SoulseekQt-2024-2-1-32bit.exe (PID: 2672)
      • SoulseekQt.exe (PID: 3088)
      • SoulseekQt.exe (PID: 2592)
      • SoulseekQt.exe (PID: 968)
    • Reads the computer name

      • SoulseekQt-2024-2-1-32bit.tmp (PID: 3956)
      • SoulseekQt.exe (PID: 2564)
      • SoulseekQt.exe (PID: 2592)
      • SoulseekQt.exe (PID: 1740)
      • SoulseekQt.exe (PID: 2804)
      • SoulseekQt.exe (PID: 1864)
      • SoulseekQt.exe (PID: 3088)
      • SoulseekQt.exe (PID: 968)
      • SoulseekQt-2024-2-1-32bit.tmp (PID: 956)
      • SoulseekQt.exe (PID: 568)
    • Creates a software uninstall entry

      • SoulseekQt-2024-2-1-32bit.tmp (PID: 956)
    • Creates files in the program directory

      • SoulseekQt-2024-2-1-32bit.tmp (PID: 956)
    • Creates files or folders in the user directory

      • SoulseekQt.exe (PID: 1740)
    • Reads the machine GUID from the registry

      • SoulseekQt.exe (PID: 1740)
      • SoulseekQt.exe (PID: 2564)
      • SoulseekQt.exe (PID: 2804)
      • SoulseekQt.exe (PID: 568)
      • SoulseekQt.exe (PID: 2592)
      • SoulseekQt.exe (PID: 3088)
      • SoulseekQt.exe (PID: 1864)
      • SoulseekQt.exe (PID: 968)
    • Manual execution by a user

      • SoulseekQt.exe (PID: 2564)
      • SoulseekQt.exe (PID: 2592)
      • SoulseekQt.exe (PID: 968)
      • SoulseekQt.exe (PID: 568)
      • SoulseekQt.exe (PID: 1864)
      • SoulseekQt.exe (PID: 3088)
      • SoulseekQt.exe (PID: 2804)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Soulseek LLC
FileDescription: SoulseekQt Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: SoulseekQt
ProductVersion: 2024.2.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
12
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start soulseekqt-2024-2-1-32bit.exe no specs soulseekqt-2024-2-1-32bit.tmp no specs soulseekqt-2024-2-1-32bit.exe soulseekqt-2024-2-1-32bit.tmp no specs soulseekqt.exe soulseekqt.exe soulseekqt.exe no specs soulseekqt.exe no specs soulseekqt.exe no specs soulseekqt.exe no specs soulseekqt.exe no specs soulseekqt.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
568"C:\Program Files\SoulseekQt\SoulseekQt.exe" C:\Program Files\SoulseekQt\SoulseekQt.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\soulseekqt\soulseekqt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\soulseekqt\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\soulseekqt\libgcc_s_dw2-1.dll
956"C:\Users\admin\AppData\Local\Temp\is-RCOES.tmp\SoulseekQt-2024-2-1-32bit.tmp" /SL5="$100130,10837988,832512,C:\Users\admin\AppData\Local\Temp\SoulseekQt-2024-2-1-32bit.exe" /SPAWNWND=$E0214 /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-RCOES.tmp\SoulseekQt-2024-2-1-32bit.tmpSoulseekQt-2024-2-1-32bit.exe
User:
admin
Company:
Soulseek LLC
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rcoes.tmp\soulseekqt-2024-2-1-32bit.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
968"C:\Program Files\SoulseekQt\SoulseekQt.exe" C:\Program Files\SoulseekQt\SoulseekQt.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\soulseekqt\soulseekqt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\soulseekqt\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\soulseekqt\libgcc_s_dw2-1.dll
1740"C:\Program Files\SoulseekQt\SoulseekQt.exe"C:\Program Files\SoulseekQt\SoulseekQt.exe
SoulseekQt-2024-2-1-32bit.tmp
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\soulseekqt\soulseekqt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\soulseekqt\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\soulseekqt\libgcc_s_dw2-1.dll
1864"C:\Program Files\SoulseekQt\SoulseekQt.exe" C:\Program Files\SoulseekQt\SoulseekQt.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\soulseekqt\soulseekqt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\soulseekqt\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\soulseekqt\libgcc_s_dw2-1.dll
2120"C:\Users\admin\AppData\Local\Temp\SoulseekQt-2024-2-1-32bit.exe" C:\Users\admin\AppData\Local\Temp\SoulseekQt-2024-2-1-32bit.exeexplorer.exe
User:
admin
Company:
Soulseek LLC
Integrity Level:
MEDIUM
Description:
SoulseekQt Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\soulseekqt-2024-2-1-32bit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2564"C:\Program Files\SoulseekQt\SoulseekQt.exe" C:\Program Files\SoulseekQt\SoulseekQt.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\soulseekqt\soulseekqt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\soulseekqt\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\soulseekqt\libgcc_s_dw2-1.dll
2592"C:\Program Files\SoulseekQt\SoulseekQt.exe" C:\Program Files\SoulseekQt\SoulseekQt.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\soulseekqt\soulseekqt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\soulseekqt\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\soulseekqt\libgcc_s_dw2-1.dll
2672"C:\Users\admin\AppData\Local\Temp\SoulseekQt-2024-2-1-32bit.exe" /SPAWNWND=$E0214 /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\SoulseekQt-2024-2-1-32bit.exe
SoulseekQt-2024-2-1-32bit.tmp
User:
admin
Company:
Soulseek LLC
Integrity Level:
HIGH
Description:
SoulseekQt Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\soulseekqt-2024-2-1-32bit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2804"C:\Program Files\SoulseekQt\SoulseekQt.exe" C:\Program Files\SoulseekQt\SoulseekQt.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\soulseekqt\soulseekqt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\soulseekqt\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\soulseekqt\libgcc_s_dw2-1.dll
Total events
5 825
Read events
5 782
Write events
37
Delete events
6

Modification events

(PID) Process:(956) SoulseekQt-2024-2-1-32bit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
BC030000343199AC9D80DA01
(PID) Process:(956) SoulseekQt-2024-2-1-32bit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
0DEA1A2B11B7279A8D0B4537A7BC5EB7DAF4AAE29E3FE019D641A74B0081D450
(PID) Process:(956) SoulseekQt-2024-2-1-32bit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(956) SoulseekQt-2024-2-1-32bit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\SoulseekQt\libgcc_s_dw2-1.dll
(PID) Process:(956) SoulseekQt-2024-2-1-32bit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
9AA647D2046E45FBD999BF562CD8416C324675927865C27C76CE4D9D970FBD32
(PID) Process:(956) SoulseekQt-2024-2-1-32bit.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8A4E1646-488C-4E5B-AC31-F784400E8D2D}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.1
(PID) Process:(956) SoulseekQt-2024-2-1-32bit.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8A4E1646-488C-4E5B-AC31-F784400E8D2D}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\SoulseekQt
(PID) Process:(956) SoulseekQt-2024-2-1-32bit.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8A4E1646-488C-4E5B-AC31-F784400E8D2D}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\SoulseekQt\
(PID) Process:(956) SoulseekQt-2024-2-1-32bit.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8A4E1646-488C-4E5B-AC31-F784400E8D2D}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
SoulseekQt
(PID) Process:(956) SoulseekQt-2024-2-1-32bit.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8A4E1646-488C-4E5B-AC31-F784400E8D2D}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
26
Suspicious files
62
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2120SoulseekQt-2024-2-1-32bit.exeC:\Users\admin\AppData\Local\Temp\is-ND6LM.tmp\SoulseekQt-2024-2-1-32bit.tmpexecutable
MD5:
SHA256:
2672SoulseekQt-2024-2-1-32bit.exeC:\Users\admin\AppData\Local\Temp\is-RCOES.tmp\SoulseekQt-2024-2-1-32bit.tmpexecutable
MD5:
SHA256:
956SoulseekQt-2024-2-1-32bit.tmpC:\Program Files\SoulseekQt\is-VLPF1.tmpexecutable
MD5:
SHA256:
956SoulseekQt-2024-2-1-32bit.tmpC:\Program Files\SoulseekQt\unins000.exe
MD5:
SHA256:
956SoulseekQt-2024-2-1-32bit.tmpC:\Program Files\SoulseekQt\is-56BEK.tmpexecutable
MD5:
SHA256:
956SoulseekQt-2024-2-1-32bit.tmpC:\Program Files\SoulseekQt\libgcc_s_dw2-1.dllexecutable
MD5:
SHA256:
956SoulseekQt-2024-2-1-32bit.tmpC:\Program Files\SoulseekQt\is-4IA2O.tmpexecutable
MD5:
SHA256:
956SoulseekQt-2024-2-1-32bit.tmpC:\Program Files\SoulseekQt\libstdc++-6.dllexecutable
MD5:
SHA256:
956SoulseekQt-2024-2-1-32bit.tmpC:\Program Files\SoulseekQt\is-JA2ML.tmpexecutable
MD5:
SHA256:
956SoulseekQt-2024-2-1-32bit.tmpC:\Program Files\SoulseekQt\libwinpthread-1.dllexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
9
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1740
SoulseekQt.exe
239.255.255.250:1900
unknown
1740
SoulseekQt.exe
208.76.170.59:2416
server.slsknet.org
CIFNET
US
unknown
2564
SoulseekQt.exe
208.76.170.59:2416
server.slsknet.org
CIFNET
US
unknown
2564
SoulseekQt.exe
239.255.255.250:1900
unknown

DNS requests

Domain
IP
Reputation
server.slsknet.org
  • 208.76.170.59
unknown

Threats

No threats detected
Process
Message
SoulseekQt.exe
QObject::startTimer: Timers cannot have negative intervals
SoulseekQt.exe
QObject::startTimer: Timers cannot have negative intervals