File name:

EqualizerAPO-x64-1.4.1.exe

Full analysis: https://app.any.run/tasks/abdfa548-e998-4bfa-9e38-2fc399ef6aa0
Verdict: Malicious activity
Analysis date: December 23, 2024, 00:57:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

4E940C6866D072047388F6FA7A1672A7

SHA1:

4D66E845754FA67B538186D0C50F39FC22046CBB

SHA256:

8793693663B17089063788235583D08A18016D20422B76AC39A6DC08DBC8ECB7

SSDEEP:

98304:wP/+9gUk9C3XLchmOKns075OYXVSXhSktnr/vzrRUOnSGRFs6gxyC7iUOZyV6hpm:x2a2W4chtwtXia+Q8EaqDa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Executable content was dropped or overwritten

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • The process drops C-runtime libraries

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Process drops legitimate windows executable

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Creates a software uninstall entry

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 6620)
  • INFO

    • Reads the computer name

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
      • DeviceSelector.exe (PID: 6648)
      • UpdateChecker.exe (PID: 7068)
    • Checks supported languages

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
      • DeviceSelector.exe (PID: 6648)
      • UpdateChecker.exe (PID: 7068)
    • Create files in a temporary directory

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Creates files in the program directory

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Creates files or folders in the user directory

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • The sample compiled with english language support

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:08:01 02:43:48+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25600
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x3461
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start equalizerapo-x64-1.4.1.exe regsvr32.exe no specs regsvr32.exe no specs deviceselector.exe no specs updatechecker.exe no specs equalizerapo-x64-1.4.1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2132"C:\Users\admin\Desktop\EqualizerAPO-x64-1.4.1.exe" C:\Users\admin\Desktop\EqualizerAPO-x64-1.4.1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\equalizerapo-x64-1.4.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6164"C:\Users\admin\Desktop\EqualizerAPO-x64-1.4.1.exe" C:\Users\admin\Desktop\EqualizerAPO-x64-1.4.1.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\equalizerapo-x64-1.4.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6608"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\EqualizerAPO\EqualizerAPO.dll"C:\Windows\SysWOW64\regsvr32.exeEqualizerAPO-x64-1.4.1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6620 /s "C:\Program Files\EqualizerAPO\EqualizerAPO.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6648"C:\Program Files\EqualizerAPO\DeviceSelector.exe" /iC:\Program Files\EqualizerAPO\DeviceSelector.exeEqualizerAPO-x64-1.4.1.exe
User:
admin
Integrity Level:
HIGH
Description:
Equalizer APO Device Selector
Exit code:
0
Version:
1.4.1.0
Modules
Images
c:\program files\equalizerapo\deviceselector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7068"C:\Program Files\EqualizerAPO\UpdateChecker.exe" -iC:\Program Files\EqualizerAPO\UpdateChecker.exeEqualizerAPO-x64-1.4.1.exe
User:
admin
Integrity Level:
HIGH
Description:
Equalizer APO Update Checker
Exit code:
0
Version:
1.4.1.0
Modules
Images
c:\program files\equalizerapo\updatechecker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
Total events
665
Read events
619
Write events
46
Delete events
0

Modification events

(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EqualizerAPO
Operation:writeName:InstallPath
Value:
C:\Program Files\EqualizerAPO
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EqualizerAPO
Operation:writeName:ConfigPath
Value:
C:\Program Files\EqualizerAPO\config
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EqualizerAPO
Operation:writeName:EnableTrace
Value:
false
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EqualizerAPO
Operation:writeName:Start Menu Folder
Value:
Equalizer APO 1.4.1
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EqualizerAPO
Operation:writeName:DisplayName
Value:
Equalizer APO
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EqualizerAPO
Operation:writeName:DisplayVersion
Value:
1.4.1
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EqualizerAPO
Operation:writeName:UninstallString
Value:
"C:\Program Files\EqualizerAPO\Uninstall.exe"
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EqualizerAPO
Operation:writeName:NoModify
Value:
1
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EqualizerAPO
Operation:writeName:NoRepair
Value:
1
(PID) Process:(6620) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AudioEngine\AudioProcessingObjects\{EC1CC9CE-FAED-4822-828A-82A81A6F018F}
Operation:writeName:FriendlyName
Value:
EqualizerAPO
Executable files
31
Suspicious files
8
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
6164EqualizerAPO-x64-1.4.1.exeC:\Users\admin\AppData\Local\Temp\nsv58E3.tmp\NSISpcre.dllexecutable
MD5:BFE060C22B44914E05D3F5367DE6C9FE
SHA256:43041F8540DCCBC33268BFBEF53037D17170B037F6393E77C21429F303AE828F
6164EqualizerAPO-x64-1.4.1.exeC:\Users\admin\AppData\Local\Temp\nsv58E3.tmp\System.dllexecutable
MD5:FCCFF8CB7A1067E23FD2E2B63971A8E1
SHA256:6FCEA34C8666B06368379C6C402B5321202C11B00889401C743FB96C516C679E
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\fftw3f.dllexecutable
MD5:AB7C771CA686E5780A20BB5088DD4911
SHA256:FC2D8CFA77A8579CD856E821C5702772E86349516734B41A8E55BE7B7D3AABBB
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\EqualizerAPO.dllexecutable
MD5:1AC6C9A4AE2DF9906D6C69F129C8E3DA
SHA256:4809136FD2EC9A1C3F010B3319D397A0D8BDC2C836C6B7BE9457DB839417AD1E
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\UpdateChecker.exeexecutable
MD5:0793749253A2986FDB4C76202D80EFE5
SHA256:E001BBDC0928F9F02AD0A6D265C8BA8112BCA41A4977F0833F87D8EEA9A1F0E2
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\sndfile.dllexecutable
MD5:D88AB95C18FAE89BE495E3E21ABF5C1D
SHA256:4E3BD2DE8E1485110EAEBEF8E1239471F73D608773831C323BF528E05645655E
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\msvcp140_1.dllexecutable
MD5:34A0EE0318A6BE3F4A17826E5C17F8E3
SHA256:91CD05C16C61C39788C47434602A59C17F5B08DBB3EEE04CE85F8D5B70E8E604
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\DeviceSelector.exeexecutable
MD5:0E0D130272EF982B525AFA9B9B52D4BE
SHA256:77B7E5ECEA2A592E97B47CAFC72597B6F60095B75A2263326EF19E3709E86AA8
6164EqualizerAPO-x64-1.4.1.exeC:\Users\admin\AppData\Local\Temp\nsv58E3.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\VoicemeeterClient.exeexecutable
MD5:8E9EB153525FD270CA234F8738BA24FB
SHA256:2EE8E01930F27906A31475C7A5E475C655CF9D1167B62B9BF51086241776B474
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
23
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1016
svchost.exe
20.106.86.13:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
192.168.100.255:137
unknown
20.106.86.13:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
88.221.125.143:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
20.106.86.13:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3976
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1016
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
104.126.37.176:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.106.86.13
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
unknown
www.microsoft.com
  • 88.221.125.143
unknown
www.bing.com
  • 104.126.37.176
  • 104.126.37.137
  • 104.126.37.131
  • 104.126.37.179
  • 104.126.37.145
  • 104.126.37.178
  • 104.126.37.123
  • 104.126.37.154
  • 104.126.37.155
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.134
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.68
  • 20.190.160.17
  • 40.126.32.72
whitelisted
go.microsoft.com
  • 184.30.17.189
whitelisted

Threats

No threats detected
No debug info