| File name: | 35f855be2a5cb77effee001a12bdd940N.exe |
| Full analysis: | https://app.any.run/tasks/02b96d90-9eb1-42ba-8573-ac6500f3d7c0 |
| Verdict: | Malicious activity |
| Analysis date: | July 12, 2024, 06:28:50 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 35F855BE2A5CB77EFFEE001A12BDD940 |
| SHA1: | 44A9138F6FC9B3A616665EF93FD4658D01A953F2 |
| SHA256: | C62DDC1ECEBD58081C6B363550E9192DE5EE21D7C0BDF2F3D5555913F615B39C |
| SSDEEP: | 98304:/m9/MrCkWSO1K50PpwiuynkHLrKsPi4iyzsov75o:H2 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (46.3) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (41) |
| .exe | | | Win32 Executable (generic) (6.6) |
| .exe | | | Generic Win/DOS Executable (2.9) |
| .exe | | | DOS Executable Generic (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:02 01:39:58+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 1910272 |
| InitializedDataSize: | 1087488 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1bc645 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (Australian) |
| CharacterSet: | Unicode |
| CompanyName: | NCH Software |
| FileDescription: | Voxal 变声器 |
| FileVersion: | 8.04CN |
| ProductVersion: | 8.04CN |
| ProductName: | Voxal |
| LegalCopyright: | NCH Software |
| InternalName: | Voxal |
| OriginalFileName: | Voxal.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4032 | "C:\Program Files\RUXIM\PLUGscheduler.exe" | C:\Program Files\RUXIM\PLUGScheduler.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Update LifeCycle Component Scheduler Exit code: 0 Version: 10.0.19041.3623 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4684 | %ProgramFiles%\RUXIM\RUXIMICS.EXE /onlyloadcampaigns | C:\Program Files\RUXIM\RUXIMICS.exe | PLUGScheduler.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Reusable UX Interaction Manager Exit code: 0 Version: 10.0.19041.3623 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4844 | %ProgramFiles%\RUXIM\RUXIMICS.EXE /nonetwork | C:\Program Files\RUXIM\RUXIMICS.exe | — | PLUGScheduler.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Reusable UX Interaction Manager Exit code: 0 Version: 10.0.19041.3623 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5432 | "C:\Users\admin\Desktop\35f855be2a5cb77effee001a12bdd940N.exe" | C:\Users\admin\Desktop\35f855be2a5cb77effee001a12bdd940N.exe | — | explorer.exe | |||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: Voxal 变声器 Exit code: 1073807364 Version: 8.04CN Modules
| |||||||||||||||
| (PID) Process: | (5432) 35f855be2a5cb77effee001a12bdd940N.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\NCH Software\Voxal\Software |
| Operation: | write | Name: | SVar |
Value: LLIBControlon | |||
| (PID) Process: | (5432) 35f855be2a5cb77effee001a12bdd940N.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\NCH Software\Voxal\Registration |
| Operation: | write | Name: | Name |
Value: | |||
| (PID) Process: | (5432) 35f855be2a5cb77effee001a12bdd940N.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Registration\NCH |
| Operation: | write | Name: | Voxal |
Value: 1 | |||
| (PID) Process: | (5432) 35f855be2a5cb77effee001a12bdd940N.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\NCH Software\Voxal\Registration |
| Operation: | write | Name: | RD |
Value: 1720765746 | |||
| (PID) Process: | (5432) 35f855be2a5cb77effee001a12bdd940N.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\NCH Software\Voxal\Software |
| Operation: | write | Name: | SVar |
Value: LLIBControlonLLIBSpllnkulon | |||
| (PID) Process: | (5432) 35f855be2a5cb77effee001a12bdd940N.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\NCH Software\Voxal\Software |
| Operation: | write | Name: | SVar |
Value: LLIBControlonLLIBSpllnkulonLLIBSpltxtfadeoff | |||
| (PID) Process: | (5432) 35f855be2a5cb77effee001a12bdd940N.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\NCH Software\Voxal\Software |
| Operation: | write | Name: | SVar |
Value: LLIBControlonLLIBSpllnkulonLLIBSpltxtfadeoffVOXALDarkv3off | |||
| (PID) Process: | (5432) 35f855be2a5cb77effee001a12bdd940N.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\NCH Software\Voxal\Software |
| Operation: | write | Name: | SVar |
Value: LLIBControlonLLIBSpllnkulonLLIBSpltxtfadeoffVOXALDarkv3offVOXALTtbhamon | |||
| (PID) Process: | (5432) 35f855be2a5cb77effee001a12bdd940N.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\NCH Software\Voxal\Settings |
| Operation: | write | Name: | VoxalRunTimes |
Value: 1 | |||
| (PID) Process: | (5432) 35f855be2a5cb77effee001a12bdd940N.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\NCH Software\Voxal\Audio |
| Operation: | write | Name: | LiveModeDefault |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4032 | PLUGScheduler.exe | C:\ProgramData\PLUG\Logs\RUXIMLog.028.etl | etl | |
MD5:FA358BFEE9B4E1FFB7394D13CBBC4898 | SHA256:6FF97BBF8A56286A4C71623829514CC14B7F8CBBCF09748D939F733968478A22 | |||
| 4032 | PLUGScheduler.exe | C:\ProgramData\PLUG\Logs\RUXIMLog.016.etl | etl | |
MD5:A7A21FBC9D00F33F186B34A50E170C13 | SHA256:64CAC91E46D4FC832958232A658431CBF9D8D9F265653ACA2BEB32428D4688EC | |||
| 4032 | PLUGScheduler.exe | C:\ProgramData\PLUG\Logs\RUXIMLog.022.etl | etl | |
MD5:44A0E917AD0C126931B1BCD959285A9A | SHA256:DDFBE47E7DFD6D8B7517F2F6FF9808ECF3C0A25F588A9F96D04F4E2B4A578573 | |||
| 4032 | PLUGScheduler.exe | C:\ProgramData\PLUG\Logs\RUXIMLog.019.etl | etl | |
MD5:5EA68411BF8E9EAF4621BAF73F61449E | SHA256:9D4CA5A1D871F819C139A498BB910A63576C2FE6367853544F8D172D8B6EBFF7 | |||
| 4032 | PLUGScheduler.exe | C:\ProgramData\PLUG\Logs\RUXIMLog.017.etl | etl | |
MD5:FED961067F664B5381B65A534B7AB728 | SHA256:652F31A8284AE812D1D9D24192BC800976BF74C240591C6AC443A28C4709FB7C | |||
| 4032 | PLUGScheduler.exe | C:\ProgramData\PLUG\Logs\RUXIMLog.020.etl | etl | |
MD5:C8834D365FAE073DEDE1F1620454CE71 | SHA256:C6DD793EEE1D5551CA507A3C5BFFECA82DD3E29C63C2C6DD218A7D4BFB37046B | |||
| 4032 | PLUGScheduler.exe | C:\ProgramData\PLUG\Logs\RUXIMLog.011.etl | etl | |
MD5:09359EE89B0634478ADFF73CDA7BFB12 | SHA256:4D800AC7C55960B107C9D3E40F63130407835E69DF4F5C558C500FC0BD20D8ED | |||
| 4032 | PLUGScheduler.exe | C:\ProgramData\PLUG\Logs\RUXIMLog.015.etl | binary | |
MD5:89BD161BF7B46C9078937CF832786737 | SHA256:2B83DF5532E9F54ED301C8F82E2CDD489799C8D5222A2D44C97DCB151A96FAA9 | |||
| 4032 | PLUGScheduler.exe | C:\ProgramData\PLUG\Logs\RUXIMLog.014.etl | etl | |
MD5:B53B2070E686FFB1FBC8B06994E7C8D7 | SHA256:A3ABD06F4E40CB700B1908AB6BCD2E27455E13EF076E0BF2345BB2FA369EF802 | |||
| 4032 | PLUGScheduler.exe | C:\ProgramData\PLUG\Logs\RUXIMLog.009.etl | etl | |
MD5:0DE8B8CBE71A7CD60D67AFE279E1ACB9 | SHA256:D17A442ABEB021BFA77E5EDAB3D7F3C6FFEA9C33B8D04409D149B518C5FDB57C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 52.113.194.132:443 | https://ecs.office.com/config/v2/Office/officeclicktorun/16.0.16026.20140/Production/CC?&Clientid=%7b48BA7FDF-353C-4FE5-8D8F-9E31911A3891%7d&Application=officeclicktorun&Platform=win32&Version=16.0.16026.20140&MsoVersion=16.0.16026.20140&ProcessName=officeclicktorun.exe&Audience=Production&Build=ship&Architecture=x64&OsVersion=10.0&OsBuild=19045&Channel=CC&InstallType=C2R&SessionId=%7bAEDD9124-9B12-400D-8C5C-5D905C8D4402%7d&LabMachine=false | unknown | text | 334 Kb | — |
— | — | GET | 200 | 52.109.28.46:443 | https://officeclient.microsoft.com/config16/?syslcid=1033&build=16.0.16026&crev=3 | unknown | xml | 170 Kb | — |
— | — | GET | 200 | 104.126.37.153:443 | https://r.bing.com/rb/16/jnc,nj/VhBuVeELUODW7ZIeVxh355D0F-g.js?bu=DygxcoQBiAGMAYEBe36_AcIBMbIBMcUB&or=w | unknown | s | 21.8 Kb | — |
— | — | GET | 200 | 104.126.37.160:443 | https://www.bing.com/rb/18/jnc,nj/6hU_LneafI_NFLeDvM367ebFaKQ.js?bu=DyIrb3t-gQF4cnWyAbUBK6UBK7gB&or=w | unknown | s | 21.3 Kb | — |
— | — | POST | 200 | 20.189.173.16:443 | https://self.events.data.microsoft.com/OneCollector/1.0/ | unknown | binary | 9 b | — |
— | — | GET | 200 | 104.126.37.131:443 | https://r.bing.com/rb/19/cir3,ortl,cc,nc/CYGXBN1kkA_ojDY5vKbCoG4Zy0E.css?bu=C9gIigOJBLIJmQiDCLgGWFhYWA&or=w | unknown | text | 19.9 Kb | — |
— | — | POST | — | 104.126.37.153:443 | https://www.bing.com/threshold/xls.aspx | unknown | — | — | — |
— | — | POST | 200 | 13.89.179.10:443 | https://self.events.data.microsoft.com/OneCollector/1.0/ | unknown | binary | 9 b | — |
— | — | GET | 200 | 104.126.37.160:443 | https://www.bing.com/manifest/threshold.appcache | unknown | text | 3.76 Kb | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2056 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
376 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3164 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.116.246.105:443 | self.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | DE | unknown |
— | — | 239.255.255.250:3702 | — | — | — | whitelisted |
— | — | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
officeclient.microsoft.com |
| whitelisted |
ecs.office.com |
| whitelisted |
www.bing.com |
| whitelisted |
r.bing.com |
| whitelisted |