File name:

EqualizerAPO-x64-1.4.1.exe

Full analysis: https://app.any.run/tasks/abdfa548-e998-4bfa-9e38-2fc399ef6aa0
Verdict: Malicious activity
Analysis date: December 23, 2024, 00:57:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

4E940C6866D072047388F6FA7A1672A7

SHA1:

4D66E845754FA67B538186D0C50F39FC22046CBB

SHA256:

8793693663B17089063788235583D08A18016D20422B76AC39A6DC08DBC8ECB7

SSDEEP:

98304:wP/+9gUk9C3XLchmOKns075OYXVSXhSktnr/vzrRUOnSGRFs6gxyC7iUOZyV6hpm:x2a2W4chtwtXia+Q8EaqDa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Process drops legitimate windows executable

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • The process drops C-runtime libraries

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • The process creates files with name similar to system file names

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Creates a software uninstall entry

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 6620)
  • INFO

    • Create files in a temporary directory

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Checks supported languages

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
      • DeviceSelector.exe (PID: 6648)
      • UpdateChecker.exe (PID: 7068)
    • Creates files in the program directory

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Reads the computer name

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
      • DeviceSelector.exe (PID: 6648)
      • UpdateChecker.exe (PID: 7068)
    • The sample compiled with english language support

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
    • Creates files or folders in the user directory

      • EqualizerAPO-x64-1.4.1.exe (PID: 6164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:08:01 02:43:48+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25600
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x3461
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start equalizerapo-x64-1.4.1.exe regsvr32.exe no specs regsvr32.exe no specs deviceselector.exe no specs updatechecker.exe no specs equalizerapo-x64-1.4.1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2132"C:\Users\admin\Desktop\EqualizerAPO-x64-1.4.1.exe" C:\Users\admin\Desktop\EqualizerAPO-x64-1.4.1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\equalizerapo-x64-1.4.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6164"C:\Users\admin\Desktop\EqualizerAPO-x64-1.4.1.exe" C:\Users\admin\Desktop\EqualizerAPO-x64-1.4.1.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\equalizerapo-x64-1.4.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6608"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\EqualizerAPO\EqualizerAPO.dll"C:\Windows\SysWOW64\regsvr32.exeEqualizerAPO-x64-1.4.1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6620 /s "C:\Program Files\EqualizerAPO\EqualizerAPO.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6648"C:\Program Files\EqualizerAPO\DeviceSelector.exe" /iC:\Program Files\EqualizerAPO\DeviceSelector.exeEqualizerAPO-x64-1.4.1.exe
User:
admin
Integrity Level:
HIGH
Description:
Equalizer APO Device Selector
Exit code:
0
Version:
1.4.1.0
Modules
Images
c:\program files\equalizerapo\deviceselector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7068"C:\Program Files\EqualizerAPO\UpdateChecker.exe" -iC:\Program Files\EqualizerAPO\UpdateChecker.exeEqualizerAPO-x64-1.4.1.exe
User:
admin
Integrity Level:
HIGH
Description:
Equalizer APO Update Checker
Exit code:
0
Version:
1.4.1.0
Modules
Images
c:\program files\equalizerapo\updatechecker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
Total events
665
Read events
619
Write events
46
Delete events
0

Modification events

(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EqualizerAPO
Operation:writeName:InstallPath
Value:
C:\Program Files\EqualizerAPO
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EqualizerAPO
Operation:writeName:ConfigPath
Value:
C:\Program Files\EqualizerAPO\config
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EqualizerAPO
Operation:writeName:EnableTrace
Value:
false
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\EqualizerAPO
Operation:writeName:Start Menu Folder
Value:
Equalizer APO 1.4.1
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EqualizerAPO
Operation:writeName:DisplayName
Value:
Equalizer APO
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EqualizerAPO
Operation:writeName:DisplayVersion
Value:
1.4.1
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EqualizerAPO
Operation:writeName:UninstallString
Value:
"C:\Program Files\EqualizerAPO\Uninstall.exe"
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EqualizerAPO
Operation:writeName:NoModify
Value:
1
(PID) Process:(6164) EqualizerAPO-x64-1.4.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EqualizerAPO
Operation:writeName:NoRepair
Value:
1
(PID) Process:(6620) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AudioEngine\AudioProcessingObjects\{EC1CC9CE-FAED-4822-828A-82A81A6F018F}
Operation:writeName:FriendlyName
Value:
EqualizerAPO
Executable files
31
Suspicious files
8
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\EqualizerAPO.dllexecutable
MD5:1AC6C9A4AE2DF9906D6C69F129C8E3DA
SHA256:4809136FD2EC9A1C3F010B3319D397A0D8BDC2C836C6B7BE9457DB839417AD1E
6164EqualizerAPO-x64-1.4.1.exeC:\Users\admin\AppData\Local\Temp\nsv58E3.tmp\nsDialogs.dllexecutable
MD5:1C8B2B40C642E8B5A5B3FF102796FB37
SHA256:8780095AA2F49725388CDDF00D79A74E85C9C4863B366F55C39C606A5FB8440C
6164EqualizerAPO-x64-1.4.1.exeC:\Users\admin\AppData\Local\Temp\nsv58E3.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
6164EqualizerAPO-x64-1.4.1.exeC:\Users\admin\AppData\Local\Temp\nsv58E3.tmp\NSISpcre.dllexecutable
MD5:BFE060C22B44914E05D3F5367DE6C9FE
SHA256:43041F8540DCCBC33268BFBEF53037D17170B037F6393E77C21429F303AE828F
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\DeviceSelector.exeexecutable
MD5:0E0D130272EF982B525AFA9B9B52D4BE
SHA256:77B7E5ECEA2A592E97B47CAFC72597B6F60095B75A2263326EF19E3709E86AA8
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\UpdateChecker.exeexecutable
MD5:0793749253A2986FDB4C76202D80EFE5
SHA256:E001BBDC0928F9F02AD0A6D265C8BA8112BCA41A4977F0833F87D8EEA9A1F0E2
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\fftw3f.dllexecutable
MD5:AB7C771CA686E5780A20BB5088DD4911
SHA256:FC2D8CFA77A8579CD856E821C5702772E86349516734B41A8E55BE7B7D3AABBB
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\Editor.exeexecutable
MD5:148B90251F75D83EAFFCE1B076217539
SHA256:46D84E1792DFDE6C2693FFB09D8091878FD8E6114870E8013A8A4A1E60D9F9C6
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\msvcp140_2.dllexecutable
MD5:0C462AFE7502E3646086EA7783022C11
SHA256:713F17B253D802D283D306CE75647E37D83A546AEB1A881E5D9E529E856C007E
6164EqualizerAPO-x64-1.4.1.exeC:\Program Files\EqualizerAPO\sndfile.dllexecutable
MD5:D88AB95C18FAE89BE495E3E21ABF5C1D
SHA256:4E3BD2DE8E1485110EAEBEF8E1239471F73D608773831C323BF528E05645655E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
23
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1016
svchost.exe
20.106.86.13:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
192.168.100.255:137
unknown
20.106.86.13:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
88.221.125.143:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
20.106.86.13:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3976
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1016
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
104.126.37.176:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.106.86.13
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
unknown
www.microsoft.com
  • 88.221.125.143
unknown
www.bing.com
  • 104.126.37.176
  • 104.126.37.137
  • 104.126.37.131
  • 104.126.37.179
  • 104.126.37.145
  • 104.126.37.178
  • 104.126.37.123
  • 104.126.37.154
  • 104.126.37.155
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.134
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.68
  • 20.190.160.17
  • 40.126.32.72
whitelisted
go.microsoft.com
  • 184.30.17.189
whitelisted

Threats

No threats detected
No debug info