File name:

DTS Sound Unbound.exe

Full analysis: https://app.any.run/tasks/8802fda5-1f09-46d3-a496-0ca8805ed551
Verdict: Malicious activity
Analysis date: July 22, 2024, 16:20:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

01EB2B3F248B6B5BF8D46B23DDBA5407

SHA1:

9C14BC310BF972D2F9F733EB73FF196160787675

SHA256:

5A766913A54FBAF59E6DADFC7C1F973D7BA5D638EBCB2734D417FC8B7666A20D

SSDEEP:

196608:t6oZuaZhvZUW+FooSbSGXfeaeo6RcGpIgn5Lspo:MoRZTUHaoSbSmfeaug0spo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DTS Sound Unbound.exe (PID: 3140)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • DTS Sound Unbound.exe (PID: 3140)
    • Executable content was dropped or overwritten

      • DTS Sound Unbound.exe (PID: 3140)
    • Reads the date of Windows installation

      • DTS Sound Unbound.exe (PID: 3140)
    • The process checks if it is being run in the virtual environment

      • tinstallwb.exe (PID: 5396)
    • Executing commands from a ".bat" file

      • tinstallwb.exe (PID: 5396)
    • Starts CMD.EXE for commands execution

      • tinstallwb.exe (PID: 5396)
    • The process executes VB scripts

      • cmd.exe (PID: 6576)
    • Accesses computer name via WMI (SCRIPT)

      • wscript.exe (PID: 6580)
    • Access Product Name via WMI (SCRIPT)

      • wscript.exe (PID: 6580)
    • Uses WMI to retrieve WMI-managed resources (SCRIPT)

      • wscript.exe (PID: 6580)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 6888)
  • INFO

    • Checks supported languages

      • DTS Sound Unbound.exe (PID: 3140)
      • tinstallwb.exe (PID: 5396)
      • DTSStudioSoundGUI.exe (PID: 4940)
      • msiexec.exe (PID: 3848)
      • msiexec.exe (PID: 6416)
    • Create files in a temporary directory

      • DTS Sound Unbound.exe (PID: 3140)
      • DTSStudioSoundGUI.exe (PID: 4940)
    • Process checks computer location settings

      • DTS Sound Unbound.exe (PID: 3140)
    • Reads the computer name

      • DTS Sound Unbound.exe (PID: 3140)
      • tinstallwb.exe (PID: 5396)
      • DTSStudioSoundGUI.exe (PID: 4940)
      • msiexec.exe (PID: 6416)
      • msiexec.exe (PID: 3848)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 6888)
    • Reads the software policy settings

      • msiexec.exe (PID: 6888)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6888)
      • DTSStudioSoundGUI.exe (PID: 4940)
    • Checks proxy server information

      • msiexec.exe (PID: 6888)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 6888)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6888)
    • Reads Environment values

      • msiexec.exe (PID: 3848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:03:20 23:03:19+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 77824
InitializedDataSize: 118784
UninitializedDataSize: -
EntryPoint: 0x8425
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
11
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start dts sound unbound.exe tinstallwb.exe no specs tinstallwb.exe cmd.exe no specs conhost.exe no specs wscript.exe no specs dtsstudiosoundgui.exe no specs slui.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1432"C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exe" C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exeDTS Sound Unbound.exe
User:
admin
Company:
TOSHIBA
Integrity Level:
MEDIUM
Description:
Installer
Exit code:
3221226540
Version:
55.13.0320.22
Modules
Images
c:\users\admin\appdata\local\temp\dts sound unbound.temp\tinstallwb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2380\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3140"C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.exe" C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\dts sound unbound.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
3848C:\Windows\syswow64\MsiExec.exe -Embedding AC3C7470716DCE494A50AEB51FB6328C CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4940"DTSStudioSoundGUI.exe"C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\DTSStudioSoundGUI.exetinstallwb.exe
User:
admin
Company:
DTS, Inc.
Integrity Level:
HIGH
Description:
Setup Launcher Unicode
Exit code:
1602
Version:
1.00.0079
Modules
Images
c:\users\admin\appdata\local\temp\dts sound unbound.temp\dtsstudiosoundgui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
4992C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5396"C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exe" C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exe
DTS Sound Unbound.exe
User:
admin
Company:
TOSHIBA
Integrity Level:
HIGH
Description:
Installer
Exit code:
1
Version:
55.13.0320.22
Modules
Images
c:\users\admin\appdata\local\temp\dts sound unbound.temp\tinstallwb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6416C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6576C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallb00.bat""C:\Windows\System32\cmd.exetinstallwb.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
6580"C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\No_SRS.vbs" if errorlevel 1 exit 1 exit 0C:\Windows\System32\wscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Windows Based Script Host
Exit code:
1
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
16 204
Read events
16 156
Write events
34
Delete events
14

Modification events

(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:writeName:DMIValid
Value:
0
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNMODEL
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNPRODUCT
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNPARTNUM
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNDOWNLID
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNSOFTNUM
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNOEMSTRING
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:writeName:VNMODEL
Value:
DELL
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:writeName:VNPRODUCT
Value:
DELL
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:writeName:VNPARTNUM
Value:
1.0.0
Executable files
9
Suspicious files
12
Text files
38
Unknown types
30

Dropped files

PID
Process
Filename
Type
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallb00.battext
MD5:0A99DBF106FF749CC3DFBBC1B866CE12
SHA256:F03D6C1F19551D2E36BFF23CA74C0FE45C4A6013099D1966626F8E8232538EAD
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exeexecutable
MD5:56B357A8518A60623490D673E2B857F8
SHA256:39D59E59634C6CFE82645BE74845D21A90793A8D379C01B077C133AFA1C5950F
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\DTSStudioSoundGUI.exeexecutable
MD5:A2CBA32354C7E4F3185D088F8898B516
SHA256:B4C58C8D247CCD9EB18A546221F7BBC8C3293819C07591B29D1879EEF9063048
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstall.exeexecutable
MD5:9A836AC3EE31C0491F0E0B6B103216CD
SHA256:2EEB8AF521E1EC77D67C5F527A38840E6545DFC25DE63B279C2F4090CF3BE9F1
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\WBDJA44I.DLLexecutable
MD5:D8E4ECD7351EEDB725600502E3B33B89
SHA256:A2F9A8928887E3DEDE3D97C36EE7BC5BDD363F937BB8D98279F8734FE5FB59BA
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\Bluestream.bmpimage
MD5:7FDE6771C64AC3B14FEE4997509D1735
SHA256:6F6045A6E3449DF05DEF5542C0A79127D2688A49672AD820A42EF659A81409F4
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\WBTOS45I.DLLexecutable
MD5:129426A036B6B1F454FC24FF3F121021
SHA256:9F15E302E09A56AEAF66C376B5031856A99AC836272735473AE710266703F2AE
4940DTSStudioSoundGUI.exeC:\Users\admin\AppData\Local\Temp\_is407F.tmppz
MD5:5D608855CF6AB86D402D9F6C108CB00F
SHA256:DDCE6DF68CE3C6F7E1217C3175FC451483AB0A96B5EDF5F63BEAA9248CC104C5
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exe.initext
MD5:D549F778757AA695F9DA8F7C95E03FCC
SHA256:4F2A3EF0BC2CF1743427C3E1582B29A1B89277CB6E8E480A89FCBF6CE4420436
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\No_SRS.vbstext
MD5:20640293DF4E9AB4A8099B526833451F
SHA256:D16159E7AC2A8E1661C99ECF45C52A81497E6792D1BC83439C42C62DA3E6339C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
40
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6888
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAgcV%2B5dcOuboLFSDHKcGwk%3D
unknown
whitelisted
6888
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAgcV%2B5dcOuboLFSDHKcGwk%3D
unknown
whitelisted
6888
msiexec.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl
unknown
whitelisted
6888
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRm%2FrYSaqNr0YBIv29H4pMHhv2XmQQUl0gD6xUIa7myWCPMlC7xxmXSZI4CEAuSOCbCwBNfFHp%2FCnGn6vo%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4204
svchost.exe
4.209.32.198:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
239.255.255.250:1900
whitelisted
2248
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6012
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4424
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
4424
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6384
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6888
msiexec.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.110
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
www.public-trust.com
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl3.digicert.com
  • 192.229.221.95
whitelisted
www.bing.com
  • 92.123.104.59
  • 92.123.104.43
  • 92.123.104.52
  • 92.123.104.61
  • 92.123.104.42
  • 92.123.104.54
  • 92.123.104.56
  • 92.123.104.62
  • 92.123.104.50
whitelisted
login.live.com
  • 20.190.159.2
  • 40.126.31.67
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.64
  • 40.126.31.69
  • 20.190.159.4
  • 40.126.31.71
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info