| File name: | MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe |
| Full analysis: | https://app.any.run/tasks/d6f523e2-8566-47f4-9913-e39471a06ec3 |
| Verdict: | Malicious activity |
| Analysis date: | February 11, 2025, 20:41:33 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 060EF13B53A591137F4CC702803F3707 |
| SHA1: | 5CBEE39DE6198C9E4CB84D890DA74CFE8B35BD06 |
| SHA256: | 7085EDA03BE0270EE47B9BA2109EE2980B8179685C99589009D6FB47879B064C |
| SSDEEP: | 98304:5ayfnIwx5xsHTovMiZkGYoGUVEE8IQW8Hm/e6lpXp1GQaPD+pDcJzRj6C3JJThX6:gBHmq0L24 |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:08:30 14:59:22+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 1588224 |
| InitializedDataSize: | 610304 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x12c431 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.10.0.0 |
| ProductVersionNumber: | 0.10.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Debug |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | maxon.net |
| FileDescription: | MAXON Cinema R25.010 fixer [MONTER GROUP©] Installer |
| FileVersion: | 0.1 |
| InternalName: | MAXON Cinema R25.010 fixer [MONTER GROUP©] |
| LegalCopyright: | Copyright (C) 2021 maxon.net |
| OriginalFileName: | MAXON Cinema R25.010 fixer [MONTER GROUP©].exe |
| ProductName: | MAXON Cinema R25.010 fixer [MONTER GROUP©] |
| ProductVersion: | 0.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2676 | C:\Windows\syswow64\MsiExec.exe -Embedding D2B5028CB01EF5D518B76BCF8CDDD728 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5588 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SrTasks.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5712 | C:\WINDOWS\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5788 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11 | C:\Windows\System32\SrTasks.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Windows System Protection background tasks. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6216 | "C:\Users\admin\AppData\Local\Temp\MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe" | C:\Users\admin\AppData\Local\Temp\MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe | — | explorer.exe | |||||||||||
User: admin Company: maxon.net Integrity Level: MEDIUM Description: MAXON Cinema R25.010 fixer [MONTER GROUP©] Installer Exit code: 3221226540 Version: 0.10 Modules
| |||||||||||||||
| 6392 | "C:\Users\admin\AppData\Local\Temp\MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe" | C:\Users\admin\AppData\Local\Temp\MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe | explorer.exe | ||||||||||||
User: admin Company: maxon.net Integrity Level: HIGH Description: MAXON Cinema R25.010 fixer [MONTER GROUP©] Installer Exit code: 0 Version: 0.10 Modules
| |||||||||||||||
| 6572 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6624 | C:\Windows\syswow64\MsiExec.exe -Embedding 275C2F005459DD690C3410696517DA59 C | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6668 | "C:\WINDOWS\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\maxon.net\MAXON Cinema R25.010 fixer [MONTER GROUP©] 0.10\install\61704E9\MAXON Cinema R25.010 fixer [MG©].msi" AI_SETUPEXEPATH="C:\Users\admin\AppData\Local\Temp\MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe" SETUPEXEDIR=C:\Users\admin\AppData\Local\Temp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1739305232 " | C:\Windows\SysWOW64\msiexec.exe | MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6768 | C:\Windows\syswow64\MsiExec.exe -Embedding 4EF35FA9197C40E574CE23EE0AD6B647 C | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6668) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.1 | |||
| (PID) Process: | (6668) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.1 | |||
| (PID) Process: | (6668) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.1 | |||
| (PID) Process: | (6668) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.1 | |||
| (PID) Process: | (6572) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Leave) |
Value: 48000000000000000967F95EC57CDB01AC190000C0150000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (6572) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Enter) |
Value: 48000000000000000967F95EC57CDB01AC190000C0150000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (6572) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Leave) |
Value: 480000000000000012CAFB5EC57CDB01AC190000C0150000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (6572) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 48000000000000004491005FC57CDB01AC190000C0150000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (6572) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4800000000000000C998C25EC57CDB01AC190000C0150000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (6572) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Enter) |
Value: 4800000000000000C998C25EC57CDB01AC190000C0150000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6572 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 6392 | MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe | C:\Users\admin\AppData\Local\Temp\MSI5F5A.tmp | executable | |
MD5:07CE413B1AF6342187514871DC112C74 | SHA256:0BA7E90FE2A0005E1E0DAD53E2678916650C3B95FF9B666B802D128276C8EC46 | |||
| 6668 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI623B.tmp | executable | |
MD5:07CE413B1AF6342187514871DC112C74 | SHA256:0BA7E90FE2A0005E1E0DAD53E2678916650C3B95FF9B666B802D128276C8EC46 | |||
| 6392 | MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe | C:\Users\admin\AppData\Roaming\maxon.net\MAXON Cinema R25.010 fixer [MONTER GROUP©] 0.10\install\61704E9\MAXON Cinema R25.010 fixer [MG©].msi | executable | |
MD5:1D083FD4D8DBA5055742F7CF6EFC96FF | SHA256:C23A14772E44D1D0D1B01235542266392FAF4C4540919B9996723D55C203EE07 | |||
| 6392 | MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe | C:\Users\admin\AppData\Roaming\maxon.net\MAXON Cinema R25.010 fixer [MONTER GROUP©] 0.10\install\holder0.aiph | binary | |
MD5:A9E0F2D46A33155A1136A56BB66E6DE3 | SHA256:E4DDD8A3CC0E72DF3C008BAAE0F0F5A38C1F80CBD0396C70684422126A480FE8 | |||
| 6572 | msiexec.exe | C:\Windows\Installer\13ae44.msi | executable | |
MD5:1D083FD4D8DBA5055742F7CF6EFC96FF | SHA256:C23A14772E44D1D0D1B01235542266392FAF4C4540919B9996723D55C203EE07 | |||
| 6668 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI610F.tmp | executable | |
MD5:07CE413B1AF6342187514871DC112C74 | SHA256:0BA7E90FE2A0005E1E0DAD53E2678916650C3B95FF9B666B802D128276C8EC46 | |||
| 6668 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI6307.tmp | executable | |
MD5:07CE413B1AF6342187514871DC112C74 | SHA256:0BA7E90FE2A0005E1E0DAD53E2678916650C3B95FF9B666B802D128276C8EC46 | |||
| 6572 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{9afc15f6-50ad-4834-a766-b7fffe63bd8f}_OnDiskSnapshotProp | binary | |
MD5:3EB770DCB77F6AB6FC3E2BE04027D141 | SHA256:A6316208995FA0D8726590E2D7040A497F972A5B7803E5FECCFE07231AB1118B | |||
| 6572 | msiexec.exe | C:\Windows\Installer\MSIB355.tmp | executable | |
MD5:07CE413B1AF6342187514871DC112C74 | SHA256:0BA7E90FE2A0005E1E0DAD53E2678916650C3B95FF9B666B802D128276C8EC46 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.19.11.105:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6460 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5872 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5872 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 2.19.11.105:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
— | — | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
5064 | SearchApp.exe | 2.19.96.120:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
4308 | svchost.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 20.190.160.5:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |