File name:

SoundCloud manager 3.334(Cracked).rar

Full analysis: https://app.any.run/tasks/84d75b7e-9454-4701-afca-983ef67c0226
Verdict: Malicious activity
Analysis date: January 25, 2020, 14:44:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

F99CAFBFBA9D69503AC29A226BAEB9EF

SHA1:

9035B5AD9CD06D190151D1397312F1B636241011

SHA256:

99AA3A9150B9CD7F566057609B13DBFE2A1264CE089ED32A4EE60A0DA30025F6

SSDEEP:

196608:+8gFMcnt0OA7C206Ja4Ytkt7elzAEekJ2o4b7Q4z5GWZ0:+83y0OyG6CtkQlzAk8N7h5RZ0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • SoundcloudManager.exe (PID: 2252)
      • SoundcloudManager.exe (PID: 3556)
    • Loads dropped or rewritten executable

      • SoundcloudManager.exe (PID: 2252)
      • explorer.exe (PID: 372)
      • SearchProtocolHost.exe (PID: 3548)
      • SoundcloudManager.exe (PID: 3556)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • soundcloudmanagersetup_v3.334.exe (PID: 3200)
      • soundcloudmanagersetup_v3.334.exe (PID: 2548)
      • soundcloudmanagersetup_v3.334.tmp (PID: 3504)
      • DllHost.exe (PID: 2744)
    • Reads Environment values

      • SoundcloudManager.exe (PID: 2252)
      • SoundcloudManager.exe (PID: 3556)
    • Creates files in the user directory

      • SoundcloudManager.exe (PID: 2252)
      • explorer.exe (PID: 372)
      • SoundcloudManager.exe (PID: 3556)
    • Starts Internet Explorer

      • SoundcloudManager.exe (PID: 2252)
    • Executed via COM

      • DllHost.exe (PID: 2744)
  • INFO

    • Manual execution by user

      • soundcloudmanagersetup_v3.334.exe (PID: 2548)
      • NOTEPAD.EXE (PID: 3324)
    • Application was dropped or rewritten from another process

      • soundcloudmanagersetup_v3.334.tmp (PID: 2564)
      • soundcloudmanagersetup_v3.334.tmp (PID: 3504)
    • Loads dropped or rewritten executable

      • soundcloudmanagersetup_v3.334.tmp (PID: 3504)
    • Creates files in the program directory

      • soundcloudmanagersetup_v3.334.tmp (PID: 3504)
    • Creates a software uninstall entry

      • soundcloudmanagersetup_v3.334.tmp (PID: 3504)
    • Reads settings of System Certificates

      • SoundcloudManager.exe (PID: 2252)
      • SoundcloudManager.exe (PID: 3556)
      • iexplore.exe (PID: 2396)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 1872)
      • iexplore.exe (PID: 2396)
    • Application launched itself

      • iexplore.exe (PID: 1872)
    • Changes internet zones settings

      • iexplore.exe (PID: 1872)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 17575
UncompressedSize: 41472
OperatingSystem: Win32
ModifyDate: 2017:05:14 07:38:11
PackingMethod: Normal
ArchivedFileName: SoundCloud manager 3.334(Cracked)\Crack\LibLicense.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
13
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs soundcloudmanagersetup_v3.334.exe soundcloudmanagersetup_v3.334.tmp no specs soundcloudmanagersetup_v3.334.exe soundcloudmanagersetup_v3.334.tmp soundcloudmanager.exe notepad.exe no specs iexplore.exe no specs iexplore.exe explorer.exe no specs Copy/Move/Rename/Delete/Link Object searchprotocolhost.exe no specs soundcloudmanager.exe

Process information

PID
CMD
Path
Indicators
Parent process
372C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1504"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SoundCloud manager 3.334(Cracked).rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1872"C:\Program Files\Internet Explorer\iexplore.exe" https://soundcloudmanager.com/download_v3.htmlC:\Program Files\Internet Explorer\iexplore.exeSoundcloudManager.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2252"C:\Program Files\Soundcloud Manager\SoundcloudManager.exe"C:\Program Files\Soundcloud Manager\SoundcloudManager.exe
soundcloudmanagersetup_v3.334.tmp
User:
admin
Company:
Rootjazz
Integrity Level:
MEDIUM
Description:
Soundcloud Manager
Exit code:
0
Version:
3.3.3.4
Modules
Images
c:\program files\soundcloud manager\soundcloudmanager.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2396"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1872 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2548"C:\Users\admin\Desktop\SoundCloud manager 3.334(Cracked)\Installation\soundcloudmanagersetup_v3.334.exe" C:\Users\admin\Desktop\SoundCloud manager 3.334(Cracked)\Installation\soundcloudmanagersetup_v3.334.exe
explorer.exe
User:
admin
Company:
Rootjazz
Integrity Level:
MEDIUM
Description:
Soundcloud Manager Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\soundcloud manager 3.334(cracked)\installation\soundcloudmanagersetup_v3.334.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2564"C:\Users\admin\AppData\Local\Temp\is-KVUP6.tmp\soundcloudmanagersetup_v3.334.tmp" /SL5="$70216,7873725,56832,C:\Users\admin\Desktop\SoundCloud manager 3.334(Cracked)\Installation\soundcloudmanagersetup_v3.334.exe" C:\Users\admin\AppData\Local\Temp\is-KVUP6.tmp\soundcloudmanagersetup_v3.334.tmpsoundcloudmanagersetup_v3.334.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-kvup6.tmp\soundcloudmanagersetup_v3.334.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2744C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\system32\DllHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3200"C:\Users\admin\Desktop\SoundCloud manager 3.334(Cracked)\Installation\soundcloudmanagersetup_v3.334.exe" /SPAWNWND=$90152 /NOTIFYWND=$70216 C:\Users\admin\Desktop\SoundCloud manager 3.334(Cracked)\Installation\soundcloudmanagersetup_v3.334.exe
soundcloudmanagersetup_v3.334.tmp
User:
admin
Company:
Rootjazz
Integrity Level:
HIGH
Description:
Soundcloud Manager Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\soundcloud manager 3.334(cracked)\installation\soundcloudmanagersetup_v3.334.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3324"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\SoundCloud manager 3.334(Cracked)\Read Me!!!.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
5 727
Read events
4 941
Write events
771
Delete events
15

Modification events

(PID) Process:(372) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1504) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SoundCloud manager 3.334(Cracked).rar
(PID) Process:(1504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(372) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
Operation:writeName:a
Value:
WinRAR.exe
Executable files
31
Suspicious files
12
Text files
115
Unknown types
7

Dropped files

PID
Process
Filename
Type
1504WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1504.48806\SoundCloud manager 3.334(Cracked)\Crack\LibLicense.dll
MD5:
SHA256:
1504WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1504.48806\SoundCloud manager 3.334(Cracked)\Installation\soundcloudmanagersetup_v3.334.exe
MD5:
SHA256:
1504WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1504.48806\SoundCloud manager 3.334(Cracked)\Read Me!!!.txt
MD5:
SHA256:
372explorer.exeC:\Users\admin\Desktop\SoundCloud manager 3.334(Cracked)
MD5:
SHA256:
3504soundcloudmanagersetup_v3.334.tmpC:\Program Files\Soundcloud Manager\is-TNE06.tmp
MD5:
SHA256:
3504soundcloudmanagersetup_v3.334.tmpC:\Program Files\Soundcloud Manager\is-3EAOB.tmp
MD5:
SHA256:
3504soundcloudmanagersetup_v3.334.tmpC:\Program Files\Soundcloud Manager\is-GD1NB.tmp
MD5:
SHA256:
3504soundcloudmanagersetup_v3.334.tmpC:\Program Files\Soundcloud Manager\is-KI0HN.tmp
MD5:
SHA256:
3504soundcloudmanagersetup_v3.334.tmpC:\Program Files\Soundcloud Manager\is-PAUHP.tmp
MD5:
SHA256:
3504soundcloudmanagersetup_v3.334.tmpC:\Program Files\Soundcloud Manager\is-5CFVC.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2252
SoundcloudManager.exe
GET
301
23.254.165.218:80
http://soundcloudmanager.com/update.xml
US
html
248 b
malicious
3556
SoundcloudManager.exe
GET
301
23.254.165.218:80
http://soundcloudmanager.com/update.xml
US
html
248 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2252
SoundcloudManager.exe
23.254.165.218:80
soundcloudmanager.com
Hostwinds LLC.
US
malicious
2252
SoundcloudManager.exe
23.254.165.218:443
soundcloudmanager.com
Hostwinds LLC.
US
malicious
2396
iexplore.exe
23.254.165.218:443
soundcloudmanager.com
Hostwinds LLC.
US
malicious
3556
SoundcloudManager.exe
23.254.165.218:80
soundcloudmanager.com
Hostwinds LLC.
US
malicious
3556
SoundcloudManager.exe
23.254.165.218:443
soundcloudmanager.com
Hostwinds LLC.
US
malicious

DNS requests

Domain
IP
Reputation
soundcloudmanager.com
  • 23.254.165.218
malicious

Threats

No threats detected
No debug info