| URL: | https://vb-audio.com/Voicemeeter/banana.htm |
| Full analysis: | https://app.any.run/tasks/5ba18691-0de7-4f50-8e19-1af9e1547f96 |
| Verdict: | Malicious activity |
| Analysis date: | March 05, 2025, 21:47:06 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | F13D2D37A91027DA9BAF679FA03FF4D9 |
| SHA1: | 729233E0CABB49E0717825755A236F3AAC11D08F |
| SHA256: | D847420F425D7410D5AF1F45E5625ED2518E1F70C7968B65FCA1688010EFBB5B |
| SSDEEP: | 3:N83U/gSJKHL:23p0cL |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 616 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6652 --field-trial-handle=2024,i,11065218798642078691,2987784404725231857,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 632 | "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | C:\Windows\System32\BackgroundTransferHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Download/Upload Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 928 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=38 --mojo-platform-channel-handle=6912 --field-trial-handle=2024,i,11065218798642078691,2987784404725231857,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1040 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=7140 --field-trial-handle=2024,i,11065218798642078691,2987784404725231857,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1116 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=8180 --field-trial-handle=2024,i,11065218798642078691,2987784404725231857,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1244 | DrvInst.exe "2" "211" "ROOT\MEDIA\0000" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:c14ce8840c48fa1f:VBCableInst.NTamd64:3.3.1.9:vbvoicemeetervaio," "43914f2f7" "00000000000001F8" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2040 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2088 | "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | C:\Windows\System32\BackgroundTransferHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Download/Upload Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2136 | -fC:\Program Files (x86)\VB\Voicemeeter\vbvmins_asiodriver64.dll | C:\Program Files (x86)\VB\Voicemeeter\vbregsvr64.exe | — | voicemeeterprosetup.exe | |||||||||||
User: admin Company: Audio Mechanic & Sound Breeder Integrity Level: HIGH Description: Local Application Runner Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 2268 | -fC:\Program Files (x86)\VB\Voicemeeter\vbvm_asiodriver64.dll | C:\Program Files (x86)\VB\Voicemeeter\vbregsvr64.exe | — | voicemeeterprosetup.exe | |||||||||||
User: admin Company: Audio Mechanic & Sound Breeder Integrity Level: HIGH Description: Local Application Runner Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| (PID) Process: | (5376) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (5376) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (5376) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (5376) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (5376) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: 2679729D358E2F00 | |||
| (PID) Process: | (5376) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: 8DC0AF9D358E2F00 | |||
| (PID) Process: | (5376) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262994 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {9AB37859-DDAA-4BDF-8DD3-6E9F9C2B1D50} | |||
| (PID) Process: | (5376) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262994 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {6887A3AC-50D7-4AD7-83E8-26123B91187D} | |||
| (PID) Process: | (5376) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262994 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {E2E7FC8E-F3DF-48B7-B68A-077E532B0F8F} | |||
| (PID) Process: | (5376) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262994 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {3F7242DB-6EF3-4C19-92F2-D67D660E92C5} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5376 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF10c064.TMP | — | |
MD5:— | SHA256:— | |||
| 5376 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF10c073.TMP | — | |
MD5:— | SHA256:— | |||
| 5376 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF10c073.TMP | — | |
MD5:— | SHA256:— | |||
| 5376 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5376 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5376 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10c073.TMP | — | |
MD5:— | SHA256:— | |||
| 5376 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5376 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5376 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF10c093.TMP | — | |
MD5:— | SHA256:— | |||
| 5376 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
8468 | svchost.exe | GET | 206 | 217.20.57.36:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1741806579&P2=404&P3=2&P4=IYEjfItgp599zPIv%2bPK7Nxt7o9f%2fnp8ym%2bionzJFcLFU2yx6xzx1AY9m%2bPnbk8qyZ0gFK4ytdb%2fDtyPY6NqTog%3d%3d | unknown | — | — | whitelisted |
8468 | svchost.exe | HEAD | 200 | 217.20.57.36:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/6ca9004c-2afd-40c0-a9b1-4fec460952e5?P1=1741810180&P2=404&P3=2&P4=lmIzzp6ITqMDLeu1zhbmM5aKJNZvzN0RoHoQkBLgeoW3s0moH2eHsuIpCBZ6cvs9V9LjglUolrAbITMbRVXuog%3d%3d | unknown | — | — | whitelisted |
8468 | svchost.exe | GET | 206 | 217.20.57.36:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1741806579&P2=404&P3=2&P4=IYEjfItgp599zPIv%2bPK7Nxt7o9f%2fnp8ym%2bionzJFcLFU2yx6xzx1AY9m%2bPnbk8qyZ0gFK4ytdb%2fDtyPY6NqTog%3d%3d | unknown | — | — | whitelisted |
8468 | svchost.exe | GET | 206 | 217.20.57.36:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/6ca9004c-2afd-40c0-a9b1-4fec460952e5?P1=1741810180&P2=404&P3=2&P4=lmIzzp6ITqMDLeu1zhbmM5aKJNZvzN0RoHoQkBLgeoW3s0moH2eHsuIpCBZ6cvs9V9LjglUolrAbITMbRVXuog%3d%3d | unknown | — | — | whitelisted |
8468 | svchost.exe | GET | 206 | 217.20.57.36:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/6ca9004c-2afd-40c0-a9b1-4fec460952e5?P1=1741810180&P2=404&P3=2&P4=lmIzzp6ITqMDLeu1zhbmM5aKJNZvzN0RoHoQkBLgeoW3s0moH2eHsuIpCBZ6cvs9V9LjglUolrAbITMbRVXuog%3d%3d | unknown | — | — | whitelisted |
8468 | svchost.exe | HEAD | 200 | 217.20.57.36:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/fb6dd03b-99d7-4cc8-a878-91c8e655c2d3?P1=1741806580&P2=404&P3=2&P4=ZvawyPAqvpKNlamCiOcL1bnjYnAKzLIV4KXzYrSJAmqwsY%2frUtgTN5kRbhp1bUY82mbca1%2fqcRaMuNlw0AyWhA%3d%3d | unknown | — | — | whitelisted |
8468 | svchost.exe | GET | 206 | 217.20.57.36:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/6ca9004c-2afd-40c0-a9b1-4fec460952e5?P1=1741810180&P2=404&P3=2&P4=lmIzzp6ITqMDLeu1zhbmM5aKJNZvzN0RoHoQkBLgeoW3s0moH2eHsuIpCBZ6cvs9V9LjglUolrAbITMbRVXuog%3d%3d | unknown | — | — | whitelisted |
8468 | svchost.exe | GET | 200 | 217.20.57.36:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e97d85e8-2e6f-4c6c-8a9a-1d07973733be?P1=1741581834&P2=404&P3=2&P4=NgMNRVQeLr%2fJhuJQshRsZMpX1q2cmZ7BmgPjIMA80sZB%2fV8TI80UM8S4EOx0YtH0K8YsMae1%2fFoDmzYok2dvJw%3d%3d | unknown | — | — | whitelisted |
8468 | svchost.exe | GET | 200 | 217.20.57.36:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/fb6dd03b-99d7-4cc8-a878-91c8e655c2d3?P1=1741806580&P2=404&P3=2&P4=ZvawyPAqvpKNlamCiOcL1bnjYnAKzLIV4KXzYrSJAmqwsY%2frUtgTN5kRbhp1bUY82mbca1%2fqcRaMuNlw0AyWhA%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5376 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
7264 | msedge.exe | 51.68.204.93:443 | vb-audio.com | OVH SAS | FR | whitelisted |
7264 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7264 | msedge.exe | 13.107.21.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7264 | msedge.exe | 13.107.6.158:443 | business.bing.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7264 | msedge.exe | 13.107.246.60:443 | edge-mobile-static.azureedge.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
vb-audio.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
business.bing.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| whitelisted |
bzib.nelreports.net |
| whitelisted |
www.bing.com |
| whitelisted |
www.youtube.com |
| whitelisted |