File name:

PreSonus.Studio.One.5.Professional.v5.1.0.Incl.Patched.and.Keygen-R2R.rar

Full analysis: https://app.any.run/tasks/73fe8ad6-12f3-4df9-b666-55c84ed94694
Verdict: Malicious activity
Analysis date: March 27, 2021, 09:17:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

4024057C2914ABA20641B1E5174C145D

SHA1:

5CADC15FB6D7C8F16C8BD81FA09C1E8E073F388C

SHA256:

D5C78D4A0148FEB59FAD7AA7B1443A2CE1D8ABFD9EFDBC60519795BFEFC4756D

SSDEEP:

49152:ZAJypSisycYZ+mpNDwiEzDQ/lpD3sgSc52UptDxsEoSnIVSscE:ZK3yR2iEvcpogPcUfDxshSIVSu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • keygen.exe (PID: 3300)
    • Drops executable file immediately after starts

      • StudioOne_Keygen.exe (PID: 1944)
      • StudioOne_Keygen.exe (PID: 2156)
    • Application was dropped or rewritten from another process

      • keygen.exe (PID: 3300)
      • keygen.exe (PID: 2308)
  • SUSPICIOUS

    • Drops a file with too old compile date

      • StudioOne_Keygen.exe (PID: 1944)
      • StudioOne_Keygen.exe (PID: 2156)
    • Executable content was dropped or overwritten

      • StudioOne_Keygen.exe (PID: 2156)
      • StudioOne_Keygen.exe (PID: 1944)
  • INFO

    • Manual execution by user

      • StudioOne_Keygen.exe (PID: 2728)
      • StudioOne_Keygen.exe (PID: 2156)
      • StudioOne_Keygen.exe (PID: 1944)
      • NOTEPAD.EXE (PID: 3276)
      • StudioOne_Keygen.exe (PID: 3272)
    • Dropped object may contain Bitcoin addresses

      • keygen.exe (PID: 3300)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 699
UncompressedSize: 1218
OperatingSystem: Win32
ModifyDate: 2021:03:27 10:16:28
PackingMethod: Normal
ArchivedFileName: PreSonus.Studio.One.5.Professional.v5.1.0.Incl.Patched.and.Keygen-R2R\R2R\R2R.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
8
Malicious processes
0
Suspicious processes
4

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs studioone_keygen.exe no specs studioone_keygen.exe keygen.exe no specs notepad.exe no specs studioone_keygen.exe no specs studioone_keygen.exe keygen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1944"C:\Users\admin\Desktop\R2R\StudioOne_Keygen.exe" C:\Users\admin\Desktop\R2R\StudioOne_Keygen.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\r2r\studioone_keygen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2156"C:\Users\admin\Desktop\R2R\StudioOne_Keygen.exe" C:\Users\admin\Desktop\R2R\StudioOne_Keygen.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\r2r\studioone_keygen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2308C:\Users\admin\AppData\Local\Temp\keygen.exeC:\Users\admin\AppData\Local\Temp\keygen.exeStudioOne_Keygen.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\keygen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2632"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\PreSonus.Studio.One.5.Professional.v5.1.0.Incl.Patched.and.Keygen-R2R.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2728"C:\Users\admin\Desktop\R2R\StudioOne_Keygen.exe" C:\Users\admin\Desktop\R2R\StudioOne_Keygen.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\r2r\studioone_keygen.exe
c:\systemroot\system32\ntdll.dll
3272"C:\Users\admin\Desktop\R2R\StudioOne_Keygen.exe" C:\Users\admin\Desktop\R2R\StudioOne_Keygen.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\r2r\studioone_keygen.exe
c:\systemroot\system32\ntdll.dll
3276"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\R2R\R2R.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3300C:\Users\admin\AppData\Local\Temp\keygen.exeC:\Users\admin\AppData\Local\Temp\keygen.exeStudioOne_Keygen.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225547
Modules
Images
c:\users\admin\appdata\local\temp\keygen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
Total events
525
Read events
502
Write events
23
Delete events
0

Modification events

(PID) Process:(2632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2632) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\PreSonus.Studio.One.5.Professional.v5.1.0.Incl.Patched.and.Keygen-R2R.rar
(PID) Process:(2632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2632) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\msinfo32.exe,-10001
Value:
System Information File
(PID) Process:(2632) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
6
Suspicious files
1
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
2632WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2632.3610\PreSonus.Studio.One.5.Professional.v5.1.0.Incl.Patched.and.Keygen-R2R\R2R\R2R.txt
MD5:
SHA256:
2632WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2632.3610\PreSonus.Studio.One.5.Professional.v5.1.0.Incl.Patched.and.Keygen-R2R\R2R\StudioOne_Keygen.exe
MD5:
SHA256:
2632WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2632.3610\PreSonus.Studio.One.5.Professional.v5.1.0.Incl.Patched.and.Keygen-R2R\R2R.nfo
MD5:
SHA256:
2632WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2632.3610\PreSonus.Studio.One.5.Professional.v5.1.0.Incl.Patched.and.Keygen-R2R\Runtime.txt
MD5:
SHA256:
1944StudioOne_Keygen.exeC:\Users\admin\AppData\Local\Temp\nss4D11.tmp
MD5:
SHA256:
2156StudioOne_Keygen.exeC:\Users\admin\AppData\Local\Temp\BASSMOD.dllexecutable
MD5:E4EC57E8508C5C4040383EBE6D367928
SHA256:8AD9E47693E292F381DA42DDC13724A3063040E51C26F4CA8E1F8E2F1DDD547F
3300keygen.exeC:\Users\admin\AppData\Local\Temp\~DFA5077BFCCF624C3F.TMPbinary
MD5:D849794F93CF53A5F9B756D3DA9D3BAB
SHA256:A7EBFB52D1F76EEB98FE609E78F71304DF3B109822222967CABC046E2FC2F8BA
2156StudioOne_Keygen.exeC:\Users\admin\AppData\Local\Temp\keygen.exeexecutable
MD5:1B0ACE2AB92EA46ABBE258CD0BC326DC
SHA256:CD1E48DCA42BF121442AB1ED745F2D8395A6FE2938031EEB84D4DBA638C6E3C1
2156StudioOne_Keygen.exeC:\Users\admin\AppData\Local\Temp\bgm.xmxm
MD5:6D0A27BFAA520C9CBE3807FAB1F7DCE4
SHA256:44B9FE8532CA48D6E6087BE588EC3CD8CEA15FC93B08192C7FB8D151740326A1
1944StudioOne_Keygen.exeC:\Users\admin\AppData\Local\Temp\bgm.xmxm
MD5:6D0A27BFAA520C9CBE3807FAB1F7DCE4
SHA256:44B9FE8532CA48D6E6087BE588EC3CD8CEA15FC93B08192C7FB8D151740326A1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info