File name:

DTS Sound Unbound.exe

Full analysis: https://app.any.run/tasks/8802fda5-1f09-46d3-a496-0ca8805ed551
Verdict: Malicious activity
Analysis date: July 22, 2024, 16:20:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

01EB2B3F248B6B5BF8D46B23DDBA5407

SHA1:

9C14BC310BF972D2F9F733EB73FF196160787675

SHA256:

5A766913A54FBAF59E6DADFC7C1F973D7BA5D638EBCB2734D417FC8B7666A20D

SSDEEP:

196608:t6oZuaZhvZUW+FooSbSGXfeaeo6RcGpIgn5Lspo:MoRZTUHaoSbSmfeaug0spo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DTS Sound Unbound.exe (PID: 3140)
  • SUSPICIOUS

    • The process executes VB scripts

      • cmd.exe (PID: 6576)
    • The process checks if it is being run in the virtual environment

      • tinstallwb.exe (PID: 5396)
    • Accesses computer name via WMI (SCRIPT)

      • wscript.exe (PID: 6580)
    • Executable content was dropped or overwritten

      • DTS Sound Unbound.exe (PID: 3140)
    • Reads the date of Windows installation

      • DTS Sound Unbound.exe (PID: 3140)
    • Reads security settings of Internet Explorer

      • DTS Sound Unbound.exe (PID: 3140)
    • Starts CMD.EXE for commands execution

      • tinstallwb.exe (PID: 5396)
    • Executing commands from a ".bat" file

      • tinstallwb.exe (PID: 5396)
    • Uses WMI to retrieve WMI-managed resources (SCRIPT)

      • wscript.exe (PID: 6580)
    • Access Product Name via WMI (SCRIPT)

      • wscript.exe (PID: 6580)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 6888)
  • INFO

    • Checks supported languages

      • DTS Sound Unbound.exe (PID: 3140)
      • tinstallwb.exe (PID: 5396)
      • DTSStudioSoundGUI.exe (PID: 4940)
      • msiexec.exe (PID: 3848)
      • msiexec.exe (PID: 6416)
    • Reads the computer name

      • DTS Sound Unbound.exe (PID: 3140)
      • tinstallwb.exe (PID: 5396)
      • DTSStudioSoundGUI.exe (PID: 4940)
      • msiexec.exe (PID: 6416)
      • msiexec.exe (PID: 3848)
    • Process checks computer location settings

      • DTS Sound Unbound.exe (PID: 3140)
    • Create files in a temporary directory

      • DTS Sound Unbound.exe (PID: 3140)
      • DTSStudioSoundGUI.exe (PID: 4940)
    • Creates files or folders in the user directory

      • DTSStudioSoundGUI.exe (PID: 4940)
      • msiexec.exe (PID: 6888)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 6888)
    • Checks proxy server information

      • msiexec.exe (PID: 6888)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 6888)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6888)
    • Reads Environment values

      • msiexec.exe (PID: 3848)
    • Reads the software policy settings

      • msiexec.exe (PID: 6888)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:03:20 23:03:19+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 77824
InitializedDataSize: 118784
UninitializedDataSize: -
EntryPoint: 0x8425
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
11
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start dts sound unbound.exe tinstallwb.exe no specs tinstallwb.exe cmd.exe no specs conhost.exe no specs wscript.exe no specs dtsstudiosoundgui.exe no specs slui.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1432"C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exe" C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exeDTS Sound Unbound.exe
User:
admin
Company:
TOSHIBA
Integrity Level:
MEDIUM
Description:
Installer
Exit code:
3221226540
Version:
55.13.0320.22
Modules
Images
c:\users\admin\appdata\local\temp\dts sound unbound.temp\tinstallwb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2380\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3140"C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.exe" C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\dts sound unbound.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
3848C:\Windows\syswow64\MsiExec.exe -Embedding AC3C7470716DCE494A50AEB51FB6328C CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4940"DTSStudioSoundGUI.exe"C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\DTSStudioSoundGUI.exetinstallwb.exe
User:
admin
Company:
DTS, Inc.
Integrity Level:
HIGH
Description:
Setup Launcher Unicode
Exit code:
1602
Version:
1.00.0079
Modules
Images
c:\users\admin\appdata\local\temp\dts sound unbound.temp\dtsstudiosoundgui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
4992C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5396"C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exe" C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exe
DTS Sound Unbound.exe
User:
admin
Company:
TOSHIBA
Integrity Level:
HIGH
Description:
Installer
Exit code:
1
Version:
55.13.0320.22
Modules
Images
c:\users\admin\appdata\local\temp\dts sound unbound.temp\tinstallwb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6416C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6576C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallb00.bat""C:\Windows\System32\cmd.exetinstallwb.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
6580"C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\No_SRS.vbs" if errorlevel 1 exit 1 exit 0C:\Windows\System32\wscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Windows Based Script Host
Exit code:
1
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
16 204
Read events
16 156
Write events
34
Delete events
14

Modification events

(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:writeName:DMIValid
Value:
0
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNMODEL
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNPRODUCT
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNPARTNUM
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNDOWNLID
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNSOFTNUM
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:delete valueName:VNOEMSTRING
Value:
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:writeName:VNMODEL
Value:
DELL
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:writeName:VNPRODUCT
Value:
DELL
(PID) Process:(5396) tinstallwb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TOSHIBA\swtos
Operation:writeName:VNPARTNUM
Value:
1.0.0
Executable files
9
Suspicious files
12
Text files
38
Unknown types
30

Dropped files

PID
Process
Filename
Type
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exeexecutable
MD5:56B357A8518A60623490D673E2B857F8
SHA256:39D59E59634C6CFE82645BE74845D21A90793A8D379C01B077C133AFA1C5950F
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\DTSStudioSoundGUI.exeexecutable
MD5:A2CBA32354C7E4F3185D088F8898B516
SHA256:B4C58C8D247CCD9EB18A546221F7BBC8C3293819C07591B29D1879EEF9063048
4940DTSStudioSoundGUI.exeC:\Users\admin\AppData\Local\Temp\{DA84CD26-BDA0-4390-BF10-50C79DC4B100}\Setup.INIini
MD5:11BF67E6FAA8F137C07CDBEADF9D48D7
SHA256:DE302E365460739AB961EAB9380C50438594C015EA47BF85508947BE02752B63
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallwb.exe.initext
MD5:D549F778757AA695F9DA8F7C95E03FCC
SHA256:4F2A3EF0BC2CF1743427C3E1582B29A1B89277CB6E8E480A89FCBF6CE4420436
4940DTSStudioSoundGUI.exeC:\Users\admin\AppData\Local\Temp\{DA84CD26-BDA0-4390-BF10-50C79DC4B100}\0x040a.initext
MD5:904E608FAC7FE03715FF59FC86F4500D
SHA256:6D2BB08B04F4E14E7CAE934FBDA846760A8DA20090A86A411EEB1E0FAA634F3C
4940DTSStudioSoundGUI.exeC:\Users\admin\AppData\Local\Temp\_is409F.tmppz
MD5:AE10F061AF304517F6E3F3157795A5B7
SHA256:C1C419BE1398ADDBD82F88BE6C3FF810ED04B8C970AB7349B07EC11B07368043
4940DTSStudioSoundGUI.exeC:\Users\admin\AppData\Local\Temp\{DA84CD26-BDA0-4390-BF10-50C79DC4B100}\_ISMSIDEL.INIini
MD5:14D9D895DACD261F47C47FD99EFB85F3
SHA256:BC00D4F94886683F8C5DD9AA7F44BC0876FC46CA6D9C72C76B3B4FD22A90C3E5
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\WBTOS45I.DLLexecutable
MD5:129426A036B6B1F454FC24FF3F121021
SHA256:9F15E302E09A56AEAF66C376B5031856A99AC836272735473AE710266703F2AE
3140DTS Sound Unbound.exeC:\Users\admin\AppData\Local\Temp\DTS Sound Unbound.temp\tinstallb00.battext
MD5:0A99DBF106FF749CC3DFBBC1B866CE12
SHA256:F03D6C1F19551D2E36BFF23CA74C0FE45C4A6013099D1966626F8E8232538EAD
4940DTSStudioSoundGUI.exeC:\Users\admin\AppData\Local\Temp\_is40B0.tmppz
MD5:3C55994652FC918CFF1C21E3C02B658D
SHA256:4AE311E127B1717E7AE0618354648850D4536F31234F4C99212E06D103980D58
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
40
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6888
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRm%2FrYSaqNr0YBIv29H4pMHhv2XmQQUl0gD6xUIa7myWCPMlC7xxmXSZI4CEAuSOCbCwBNfFHp%2FCnGn6vo%3D
unknown
whitelisted
6888
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAgcV%2B5dcOuboLFSDHKcGwk%3D
unknown
whitelisted
6888
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAgcV%2B5dcOuboLFSDHKcGwk%3D
unknown
whitelisted
6888
msiexec.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4204
svchost.exe
4.209.32.198:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
239.255.255.250:1900
whitelisted
2248
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6012
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4424
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
4424
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6384
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6888
msiexec.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.110
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
www.public-trust.com
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl3.digicert.com
  • 192.229.221.95
whitelisted
www.bing.com
  • 92.123.104.59
  • 92.123.104.43
  • 92.123.104.52
  • 92.123.104.61
  • 92.123.104.42
  • 92.123.104.54
  • 92.123.104.56
  • 92.123.104.62
  • 92.123.104.50
whitelisted
login.live.com
  • 20.190.159.2
  • 40.126.31.67
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.64
  • 40.126.31.69
  • 20.190.159.4
  • 40.126.31.71
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info