| File name: | HearSetup_101739.exe |
| Full analysis: | https://app.any.run/tasks/c46ab83c-f8ed-4f67-966d-d69472c0d05c |
| Verdict: | Malicious activity |
| Analysis date: | January 29, 2019, 21:46:03 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | AB34D0B5EE50C96F14F4BCEF86B44FF8 |
| SHA1: | 70B1BBC9605130D7F5292D15E6F112B38E0715D6 |
| SHA256: | C25E669E1EB8AC7D2134C2E7DBB2A6084177AD9E9AB77E018A78E0062BBEC7C8 |
| SSDEEP: | 98304:TSIMnfvaCZ5BODdWNBcPJpC/okGSMDZ1YqxrStFi9ztXUn4Ovnebxt/dexuQe:TqnVZ/ODANBZGSMDkvtF0SPfe3iu/ |
| .exe | | | Inno Setup installer (81.5) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10.5) |
| .exe | | | Win32 Executable (generic) (3.3) |
| .exe | | | Win16/32 Executable Delphi generic (1.5) |
| .exe | | | Generic Win/DOS Executable (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2011:03:17 11:22:54+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 86016 |
| InitializedDataSize: | 188928 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x16478 |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Prosoft |
| FileDescription: | Hear Setup |
| FileVersion: | |
| LegalCopyright: | Copyright © 2012 Prosoft. |
| ProductName: | Hear |
| ProductVersion: |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 17-Mar-2011 10:22:54 |
| Detected languages: |
|
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Prosoft |
| FileDescription: | Hear Setup |
| FileVersion: | - |
| LegalCopyright: | Copyright © 2012 Prosoft. |
| ProductName: | Hear |
| ProductVersion: | - |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0050 |
| Pages in file: | 0x0002 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x000F |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x001A |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000100 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 8 |
| Time date stamp: | 17-Mar-2011 10:22:54 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000143F0 | 0x00014400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.4822 |
.itext | 0x00016000 | 0x00000BE8 | 0x00000C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.00929 |
.data | 0x00017000 | 0x00000D9C | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.67375 |
.bss | 0x00018000 | 0x00005710 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x0001E000 | 0x00000F9E | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.96778 |
.tls | 0x0001F000 | 0x00000008 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x00020000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.190489 |
.rsrc | 0x00021000 | 0x0002C184 | 0x0002C200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.02211 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.05007 | 1376 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 4.49148 | 67624 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 4.99263 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 4.8988 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 5.39544 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
4091 | 3.13038 | 196 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4092 | 3.36196 | 204 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4093 | 3.34841 | 372 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4094 | 3.29351 | 924 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4095 | 3.34579 | 844 | Latin 1 / Western European | UNKNOWN | RT_STRING |
advapi32.dll |
comctl32.dll |
kernel32.dll |
oleaut32.dll |
user32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1728 | "C:\Program Files\Hear\Hear.exe" | C:\Program Files\Hear\Hear.exe | HearSetup_101739.tmp | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2168 | "C:\Program Files\Hear\setacl\SetACL.exe" -on "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{07187d84-b142-4eb1-832a-7ba8015e0f89}" -ot reg -rec yes -actn ace -ace "n:Administrators;p:full" | C:\Program Files\Hear\setacl\SetACL.exe | — | Hear.exe | |||||||||||
User: admin Company: Integrity Level: HIGH Description: SetACL 2 Exit code: 0 Version: 2, 0, 3, 0 Modules
| |||||||||||||||
| 2192 | "C:\Program Files\Hear\certmgr.exe" CertMgr.exe -all -add 4FrontTech.cer -s -r localMachine TrustedPublisher | C:\Program Files\Hear\certmgr.exe | — | HearSetup_101739.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: ECM Certificate Manager Exit code: 4294967295 Version: 6.0.6001.18000 (longhorn_rtm.080118-1840) Modules
| |||||||||||||||
| 2288 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{4fb096f4-fcb6-542c-90ee-8171d323aa56} Global\{1fb53105-851d-6aa2-cd1d-163933493453} C:\Windows\System32\DriverStore\Temp\{283af87f-0ea0-2152-c1bf-0f1c90ee8171}\ren2cap.inf C:\Windows\System32\DriverStore\Temp\{283af87f-0ea0-2152-c1bf-0f1c90ee8171}\ren2cap.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2372 | "C:\Program Files\Hear\setacl\SetACL.exe" -on "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{e502e76e-f3ae-4642-a5c3-f103c57e2ebc}" -ot reg -rec yes -actn setowner -ownr "n:Administrators" | C:\Program Files\Hear\setacl\SetACL.exe | — | Hear.exe | |||||||||||
User: admin Company: Integrity Level: HIGH Description: SetACL 2 Exit code: 0 Version: 2, 0, 3, 0 Modules
| |||||||||||||||
| 2612 | DrvInst.exe "2" "211" "ROOT\MEDIA\0000" "C:\Windows\INF\oem4.inf" "ren2cap.inf:MicrosoftDS:REN2CAP_DRIVER:1.2.8.0::*ren2cap" "675eb56cb" "00000330" "000005D8" "000005EC" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2640 | "C:\Program Files\Hear\setacl\SetACL.exe" -on "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{e502e76e-f3ae-4642-a5c3-f103c57e2ebc}" -ot reg -rec yes -actn ace -ace "n:Administrators;p:full" | C:\Program Files\Hear\setacl\SetACL.exe | — | Hear.exe | |||||||||||
User: admin Company: Integrity Level: HIGH Description: SetACL 2 Exit code: 0 Version: 2, 0, 3, 0 Modules
| |||||||||||||||
| 2648 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{229a150a-fd5a-0ae8-5ae2-d96bfb647715}\ren2cap.inf" "0" "675eb56cb" "00000330" "WinSta0\Default" "00000554" "208" "c:\program files\hear\driver" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2780 | "C:\Program Files\Hear\Hear.exe" defaultDeviceDetect | C:\Program Files\Hear\Hear.exe | — | HearSetup_101739.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2804 | "C:\Program Files\Hear\Hear.exe" | C:\Program Files\Hear\Hear.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3776) HearSetup_101739.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Prosoft\Hear |
| Operation: | write | Name: | Serial |
Value: | |||
| (PID) Process: | (3608) devcon.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus |
| Operation: | write | Name: | setupapi.app.log |
Value: 4096 | |||
| (PID) Process: | (3608) devcon.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus |
| Operation: | write | Name: | setupapi.dev.log |
Value: 4096 | |||
| (PID) Process: | (3608) devcon.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2648) DrvInst.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2288) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2648) DrvInst.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\77B94E507862471AF2C712A80CC3D88C42DD9DC3 |
| Operation: | write | Name: | Blob |
Value: 03000000010000001400000077B94E507862471AF2C712A80CC3D88C42DD9DC304000000010000001000000070AE5133D2F60D0484E95F998BF07C031400000001000000140000001D5E45B1C443FEDDE427F31B7935394CA48126C81900000001000000100000008D267569E00CE87A587F1D936B1979210F0000000100000014000000A35A3A9D086FBDB51B0AD49B747312AB4F319B592000000001000000830400003082047F30820367A003020102020B01000000000129CCE72C36300D06092A864886F70D01010505003063310B300906035504061302424531193017060355040A1310476C6F62616C5369676E206E762D736131163014060355040B130D4F626A6563745369676E2043413121301F06035504031318476C6F62616C5369676E204F626A6563745369676E204341301E170D3130303731333137313532345A170D3133303731333137313532315A3055310B300906035504061302555331223020060355040A13193446726F6E7420546563686E6F6C6F676965732C20496E632E31223020060355040313193446726F6E7420546563686E6F6C6F676965732C20496E632E30820122300D06092A864886F70D01010105000382010F003082010A0282010100C460B21249B60193DA763F9A29B00C81C5F61F0F066C54CA1585ACA77DC6DBB1450561863B1D3198766658EA5A55734BB80F3406E5F48AD1FC734B39233C0D37F01C24E47061759720814899B05ACC7F7CE88A2C8724EDF9C05BF8FF66AF09247111AAD7D991142DC36E6911D03E02FC36C669A9019598329C91B30905C031C0AE80075B221C1196770A5B910C9B170FAEAFF7BC294E2F6E221601C945910BCC74142A6BC7D6FA28AB0E76CFBD3C63AA85FA8AEBA2DC8AB6F8FF240AB2EE78A92CD09C71980D5C06A4FE9ECEA110C698A17CB643E5317D0C9800BF14BE113DD75BE4C01A32C9D65A148655ECC60E51465C2AADAE81E1A2D475DBD60BEBB0289B0203010001A38201403082013C301F0603551D23041830168014D25BF34B264BA5B0E75DFD567FF6F12E384E53A0304E06082B0601050507010104423040303E06082B060105050730028632687474703A2F2F7365637572652E676C6F62616C7369676E2E6E65742F6361636572742F4F626A6563745369676E2E63727430390603551D1F04323030302EA02CA02A8628687474703A2F2F63726C2E676C6F62616C7369676E2E6E65742F4F626A6563745369676E2E63726C30090603551D1304023000300E0603551D0F0101FF04040302078030130603551D25040C300A06082B06010505070303304B0603551D2004443042304006092B06010401A03201323033303106082B060105050702011625687474703A2F2F7777772E676C6F62616C7369676E2E6E65742F7265706F7369746F72792F301106096086480186F8420101040403020410300D06092A864886F70D010105050003820101005787BD71AEB048D061FFEF03780DCC50D9278C5749CB44D58F2C36DCAA042C0D89AF45ECFF682F48584641A486EC42552FAE129FA87834A0EBBB6A96446F502D5386235A4EC9A4CF7EA71C897F28A1E412FFE78EB208AB817D5050F79D28C7F1D21239DC23047DCFBD396BEA1789C7354634CAF198AA0379B5F79004C20CAAA6FBA0E7D95E7E90B5A426DD411DBA27744D55CBFD1D1DF151685B52B9E35E108B4676727369CA5591DF51B3438508452ADDD1F895C6B6D1228AE42B6D1C7ABC76BA492CA8AD521F658C02DC2C78851BC390152D30AD4237C9296C928833650AD8D13E108CF745E0F8D89E84BD22EF19C631CC22B8AD13D0BAD69935869011E5EB | |||
| (PID) Process: | (2648) DrvInst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000008A6477251CB8D401580A0000680A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2648) DrvInst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000008A6477251CB8D401580A0000680A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2648) DrvInst.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 20 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3776 | HearSetup_101739.tmp | C:\Program Files\Hear\is-OPMB9.tmp | — | |
MD5:— | SHA256:— | |||
| 3776 | HearSetup_101739.tmp | C:\Program Files\Hear\is-Q1IID.tmp | — | |
MD5:— | SHA256:— | |||
| 3776 | HearSetup_101739.tmp | C:\Program Files\Hear\setacl\is-M7F65.tmp | — | |
MD5:— | SHA256:— | |||
| 3776 | HearSetup_101739.tmp | C:\Program Files\Hear\setacl\is-KLJQ6.tmp | — | |
MD5:— | SHA256:— | |||
| 3776 | HearSetup_101739.tmp | C:\Program Files\Hear\devcon\is-V8UKM.tmp | — | |
MD5:— | SHA256:— | |||
| 3776 | HearSetup_101739.tmp | C:\Program Files\Hear\driver\x86\is-U6V8A.tmp | — | |
MD5:— | SHA256:— | |||
| 3776 | HearSetup_101739.tmp | C:\Program Files\Hear\driver\amd64\is-O6UMM.tmp | — | |
MD5:— | SHA256:— | |||
| 3776 | HearSetup_101739.tmp | C:\Program Files\Hear\driver\ia64\is-3CHRU.tmp | — | |
MD5:— | SHA256:— | |||
| 3776 | HearSetup_101739.tmp | C:\Program Files\Hear\driver\is-GA78A.tmp | — | |
MD5:— | SHA256:— | |||
| 3776 | HearSetup_101739.tmp | C:\Program Files\Hear\driver\is-6161H.tmp | — | |
MD5:— | SHA256:— | |||
Process | Message |
|---|---|
Hear.exe | opening dsound out device: Primary Sound Driver rate=44100 bits=16 buf=1152
|
Hear.exe | opening dsound out step 2
|
Hear.exe | opening dsound out step 3
|
Hear.exe | closing dsound out: Primary Sound Driver
|
Hear.exe | opening dsound out device: Speakers (Realtek AC'97 Audio) rate=44100 bits=16 buf=1152
|
Hear.exe | opening dsound out step 2
|
Hear.exe | opening dsound out step 3
|
Hear.exe | opening dsound in device: Primary Sound Capture Driver rate=44100 bits=16 buf=1152
|
Hear.exe | opening dsound in step 2
|
Hear.exe | closing dsound in: Primary Sound Capture Driver
|