| File name: | musicmaker.exe |
| Full analysis: | https://app.any.run/tasks/a192a356-3411-4a3d-85c9-631d766b3f8a |
| Verdict: | Malicious activity |
| Analysis date: | January 19, 2024, 18:07:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 32FEBE631DAB33650596593F8E1A2CA2 |
| SHA1: | 013E6D68EDE542D09F264E629C0D896DA8B1A519 |
| SHA256: | B06B0E5B5702A0C08DCC7C189F64CCEE04D92F34BAF833F2BACDCC5DFBFE54E0 |
| SSDEEP: | 98304:/skV4+x0SCivy//N+uT5+jqIBvjRZenxojE1eM+y63cv5uxpJIxcsGf0xgbgTu2Y:Lyy3C8 |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:03:04 15:58:39+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 1325568 |
| InitializedDataSize: | 2109440 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9f922 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.62.54 |
| ProductVersionNumber: | 1.3.62.54 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | MAGIX Software GmbH |
| FileDescription: | MUSIC MAKER (en-US) |
| FileVersion: | 1.3.62.54 |
| LegalCopyright: | Copyright © MAGIX Software GmbH |
| ProductName: | MUSIC MAKER (en-US) |
| ProductVersion: | 1.3.62.54 |
| MX_Culture: | en-US |
| MX_StubConfig: | Release |
| MX_StubVersion: | 1.9.1.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Users\admin\AppData\Local\Temp\musicmaker.exe" | C:\Users\admin\AppData\Local\Temp\musicmaker.exe | — | explorer.exe | |||||||||||
User: admin Company: MAGIX Software GmbH Integrity Level: MEDIUM Description: MUSIC MAKER (en-US) Exit code: 3221226540 Version: 1.3.62.54 Modules
| |||||||||||||||
| 532 | "C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\MxDownloadManager.exe" -m C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\SetupValues.dat -s mm32 -r | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\MxDownloadManager.exe | musicmaker.exe | ||||||||||||
User: admin Company: MAGIX Software GmbH Integrity Level: HIGH Description: Installationsmanager Exit code: 0 Version: 1.3.62.54 Modules
| |||||||||||||||
| 2416 | "C:\Users\admin\AppData\Local\Temp\musicmaker.exe" | C:\Users\admin\AppData\Local\Temp\musicmaker.exe | explorer.exe | ||||||||||||
User: admin Company: MAGIX Software GmbH Integrity Level: HIGH Description: MUSIC MAKER (en-US) Exit code: 0 Version: 1.3.62.54 Modules
| |||||||||||||||
| (PID) Process: | (532) MxDownloadManager.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (532) MxDownloadManager.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (532) MxDownloadManager.exe | Key: | HKEY_CURRENT_USER\Software\MAGIX\MAGIX Installation manager\Internet_Settings |
| Operation: | write | Name: | Timeout |
Value: 20000 | |||
| (PID) Process: | (532) MxDownloadManager.exe | Key: | HKEY_CURRENT_USER\Software\MAGIX\MAGIX Installation manager\Internet_Settings |
| Operation: | write | Name: | Retries |
Value: 3 | |||
| (PID) Process: | (532) MxDownloadManager.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (532) MxDownloadManager.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (532) MxDownloadManager.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (532) MxDownloadManager.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (532) MxDownloadManager.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (532) MxDownloadManager.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2416 | musicmaker.exe | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\Bitmaps\mxgui.4.0\generalTemplates.INI | text | |
MD5:D8ACCCB39FA2BCBC59AE3B7D26B1BC6F | SHA256:C1DE2A676BF7C42F2626A7F9DD63B79774E8D8D39D3716D4E14372172B816608 | |||
| 2416 | musicmaker.exe | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\Bitmaps\mxgui.4.0\Logo.png | image | |
MD5:0E4712A4E4EBA8B6B6829CA21FD6DEF8 | SHA256:63A0002EFBBB5698778CA16E61CD47654450614423BBD75D20F3F6E2BC3AC8AD | |||
| 2416 | musicmaker.exe | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\Bitmaps\mxgui.4.0\CMxDownloadManagerDlg.ini | text | |
MD5:F5763A04B92889A6F8C08172451CFDC3 | SHA256:F733D9056C7C9E47E8E835518A677A1D75E2654F05698EA684790F3AF7D9117A | |||
| 2416 | musicmaker.exe | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\Bitmaps\mxgui.4.0\CMxDownloadManagerDlg_2.ini | text | |
MD5:A7DFF513385F3DA702B2D20EDD55985C | SHA256:D3ADB922390B65726672EA7A6123866326F0887824DB6876881EDC437A87D197 | |||
| 2416 | musicmaker.exe | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\Bitmaps\mxgui.4.0\ProgressDialogTemplates.ini | text | |
MD5:A8AB1555DC45A8AB1FFA4CE0F75A9FB0 | SHA256:3CD528388545C659DBCE6317EF29B9833A9163E1C07FD44C11A87F942EFEBC90 | |||
| 2416 | musicmaker.exe | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\installed.xml | xml | |
MD5:AEA624768256AE1708E75309BF8299EE | SHA256:8F49354F824579622074CC96A4E85F0E0E003F17367B6426CF3C0226A7C46FD6 | |||
| 2416 | musicmaker.exe | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\MusicMaker32.ico | image | |
MD5:FECF6184FE0E8C02C4FD02DE5988E2EE | SHA256:A6687F6911BD833BB0F5CA612308061352DD0AF9B09749CD5312DD7ACBDF356E | |||
| 2416 | musicmaker.exe | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\magix.ico | image | |
MD5:6FDE1B06B71E06E44920107D08417550 | SHA256:7AEF260163ED2C620530BD10D8434860964908D6432A0F4AD1D8211ACB1280F8 | |||
| 2416 | musicmaker.exe | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\MFL_rel_u_vc12.dll | executable | |
MD5:10A2916057E394BDF133EC9FC1AF53A7 | SHA256:73CCAA16D2D51B91F13BF614BB58AB1C7E3E718F8F1B5D8CC7CC273C6975FC9F | |||
| 2416 | musicmaker.exe | C:\Users\admin\AppData\Local\Temp\mgxy2odq4xn\Bitmaps\mxgui.4.0\ProgressDialogTemplates.png | image | |
MD5:CBE0A7C1EE665C7272873C031A0C5D52 | SHA256:9CF7CE3D45C97311E6A400413C61BEFCCF9BF6E9820D5886414829D1D2F2CA86 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
532 | MxDownloadManager.exe | GET | 301 | 195.214.216.160:80 | http://www.magix.com/ | unknown | html | 230 b | unknown |
532 | MxDownloadManager.exe | GET | 301 | 195.214.216.160:80 | http://www.magix.com/ | unknown | html | 230 b | unknown |
532 | MxDownloadManager.exe | GET | 200 | 184.24.77.210:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a3ef554ed2256a8e | unknown | compressed | 4.66 Kb | unknown |
532 | MxDownloadManager.exe | GET | 301 | 195.214.216.160:80 | http://www.magix.com/user/client_redirects/service_api/extservices_crp.utf8.php | unknown | html | 288 b | unknown |
532 | MxDownloadManager.exe | GET | 301 | 195.214.216.160:80 | http://www.magix.com/user/client_redirects/service_api/extservices_crp.utf8.php | unknown | html | 288 b | unknown |
532 | MxDownloadManager.exe | GET | 301 | 195.214.216.160:80 | http://www.magix.com/ | unknown | html | 230 b | unknown |
532 | MxDownloadManager.exe | GET | 200 | 192.229.221.95:80 | http://status.geotrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTIyCPRUzvKHRw7iRE1lF%2BfcLu%2FjgQUypJnUmHervy6Iit%2FHIdMJftvmVgCEAo534UqBTG6Tl7coMJrriA%3D | unknown | binary | 471 b | unknown |
532 | MxDownloadManager.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAP%2B7xu1tkg0miCVD4vGl1M%3D | unknown | binary | 471 b | unknown |
532 | MxDownloadManager.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAkO6MXeW%2Fpi0q4v9wl8SFc%3D | unknown | binary | 471 b | unknown |
532 | MxDownloadManager.exe | GET | 200 | 184.24.77.210:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c8a6c3b57d016454 | unknown | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
532 | MxDownloadManager.exe | 195.214.216.160:80 | www.magix.com | GTT Communications Inc. | DE | unknown |
532 | MxDownloadManager.exe | 195.214.216.160:443 | www.magix.com | GTT Communications Inc. | DE | unknown |
532 | MxDownloadManager.exe | 184.24.77.210:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
532 | MxDownloadManager.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
532 | MxDownloadManager.exe | 195.214.216.83:443 | extapi.magix.com | GTT Communications Inc. | DE | unknown |
532 | MxDownloadManager.exe | 212.102.56.179:443 | 1066355124.rsc.cdn77.org | Datacamp Limited | DE | unknown |
532 | MxDownloadManager.exe | 23.192.153.142:80 | x1.c.lencr.org | AKAMAI-AS | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
www.magix.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
status.geotrust.com |
| whitelisted |
extapi.magix.com |
| unknown |
status.thawte.com |
| whitelisted |
1066355124.rsc.cdn77.org |
| unknown |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |