| File name: | KORG Software Pass.exe |
| Full analysis: | https://app.any.run/tasks/9f8dc0f4-153e-437c-9bb4-a8b972919062 |
| Verdict: | Malicious activity |
| Analysis date: | November 03, 2023, 14:09:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C21EF6AC3C88E7BB66C1F10E3467F33C |
| SHA1: | 2DE3AF69884293C0BCFB083ECE6C5AF12658C05C |
| SHA256: | DE45FA9BB8BF469037A3B8232AB516602C9A8E0429BC8953B18D29CCA0C5AAE6 |
| SSDEEP: | 98304:d+QQmDM5JOiNrl9rqrUDXH7UWgIiXB390ENQFwcWeu/EISoA1htP1TANt/9Fl6GM:yPCZXMDa/MMqXVUFDIpDl |
| .exe | | | Inno Setup installer (51.8) |
|---|---|---|
| .exe | | | InstallShield setup (20.3) |
| .exe | | | Win32 EXE PECompact compressed (generic) (19.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (3.1) |
| .exe | | | Win32 Executable (generic) (2.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:05:21 07:56:23+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741376 |
| InitializedDataSize: | 38400 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.2.3.0 |
| ProductVersionNumber: | 1.2.3.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | KORG Inc. |
| FileDescription: | KORG Software Pass Setup |
| FileVersion: | 1.2.3 |
| LegalCopyright: | |
| OriginalFileName: | |
| ProductName: | KORG Software Pass |
| ProductVersion: | 1.2.3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2424 | "C:\Users\admin\AppData\Local\Temp\is-VGAGP.tmp\KORG Software Pass.tmp" /SL5="$70186,9491019,780800,C:\Users\admin\AppData\Local\Temp\KORG Software Pass.exe" /SPAWNWND=$501F4 /NOTIFYWND=$60134 | C:\Users\admin\AppData\Local\Temp\is-VGAGP.tmp\KORG Software Pass.tmp | — | KORG Software Pass.exe | |||||||||||
User: admin Company: KORG Inc. Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3152 | "C:\Users\admin\AppData\Local\Temp\KORG Software Pass.exe" | C:\Users\admin\AppData\Local\Temp\KORG Software Pass.exe | — | explorer.exe | |||||||||||
User: admin Company: KORG Inc. Integrity Level: MEDIUM Description: KORG Software Pass Setup Exit code: 0 Version: 1.2.3 Modules
| |||||||||||||||
| 3228 | "C:\Users\admin\AppData\Local\Temp\KORG Software Pass.exe" /SPAWNWND=$501F4 /NOTIFYWND=$60134 | C:\Users\admin\AppData\Local\Temp\KORG Software Pass.exe | KORG Software Pass.tmp | ||||||||||||
User: admin Company: KORG Inc. Integrity Level: HIGH Description: KORG Software Pass Setup Exit code: 0 Version: 1.2.3 Modules
| |||||||||||||||
| 3428 | "C:\Users\admin\AppData\Local\Temp\is-9ED6V.tmp\KORG Software Pass.tmp" /SL5="$60134,9491019,780800,C:\Users\admin\AppData\Local\Temp\KORG Software Pass.exe" | C:\Users\admin\AppData\Local\Temp\is-9ED6V.tmp\KORG Software Pass.tmp | — | KORG Software Pass.exe | |||||||||||
User: admin Company: KORG Inc. Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2424) KORG Software Pass.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 8905ADECFA0A4E89EA46F2B0DEEF997C6503734516AB1F9E1712EDF05ADC7181 | |||
| (PID) Process: | (2424) KORG Software Pass.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Program Files\KORG\KORG Software Pass.exe | |||
| (PID) Process: | (2424) KORG Software Pass.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2424) KORG Software Pass.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 85CEFF9F7A6AA6EB8ED705DA8936258CF03A85D301A8D0558AE02F9CEA4C5728 | |||
| (PID) Process: | (2424) KORG Software Pass.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: 7809000012C982625F0EDA01 | |||
| (PID) Process: | (2424) KORG Software Pass.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3228 | KORG Software Pass.exe | C:\Users\admin\AppData\Local\Temp\is-VGAGP.tmp\KORG Software Pass.tmp | executable | |
MD5:BC65479C7B7A5072E63BBBAC60B0BCB5 | SHA256:F637F4574EA83FA30C5B3DAF5C069F9C4CC0254D51F476587089F43016B2F03B | |||
| 3152 | KORG Software Pass.exe | C:\Users\admin\AppData\Local\Temp\is-9ED6V.tmp\KORG Software Pass.tmp | executable | |
MD5:BC65479C7B7A5072E63BBBAC60B0BCB5 | SHA256:F637F4574EA83FA30C5B3DAF5C069F9C4CC0254D51F476587089F43016B2F03B | |||
| 2424 | KORG Software Pass.tmp | C:\Program Files\KORG\is-J2DOD.tmp | executable | |
MD5:D117A4C03B2B12A39E7A978EA4EC889D | SHA256:BC160602CC3EA18E6EE659F97EE4411B30B25E75398A37928783B8DD9DABADA6 | |||
| 2424 | KORG Software Pass.tmp | C:\Program Files\KORG\KORG Software Pass.exe | executable | |
MD5:8B3BD7037D4226BC8C7B7F932721FDF5 | SHA256:033A0334C1BEFBAC6518431AA3C12515641CDD373CC545722F2BBE7301CFD567 | |||
| 2424 | KORG Software Pass.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KORG\Uninstall KORG Software Pass.lnk | binary | |
MD5:35F055FFD31B3A4940F200126CF9C054 | SHA256:975CC3C5B9A9B2393EB26515CA7B8CB375FD4B3192F02C21C0B8085F51A23704 | |||
| 2424 | KORG Software Pass.tmp | C:\Program Files\KORG\cpprest141_2_10.dll | executable | |
MD5:D117A4C03B2B12A39E7A978EA4EC889D | SHA256:BC160602CC3EA18E6EE659F97EE4411B30B25E75398A37928783B8DD9DABADA6 | |||
| 2424 | KORG Software Pass.tmp | C:\Program Files\KORG\unins000.msg | binary | |
MD5:0703191AB20F3F74FA2DE82A99CFB818 | SHA256:67DE824F2EDEE19782A93CECDA6466BA1991620116B0200AF99774C65CCA96C6 | |||
| 2424 | KORG Software Pass.tmp | C:\Program Files\KORG\unins000.dat | binary | |
MD5:7DB6035A5513BC1F85231EB37106BF7D | SHA256:08C52363DF26AEBDA6460DDA2A49D9F46416E2F656DA9C85FCA913CE7FF26E77 | |||
| 2424 | KORG Software Pass.tmp | C:\Program Files\KORG\is-FF8MT.tmp | executable | |
MD5:8B3BD7037D4226BC8C7B7F932721FDF5 | SHA256:033A0334C1BEFBAC6518431AA3C12515641CDD373CC545722F2BBE7301CFD567 | |||
| 2424 | KORG Software Pass.tmp | C:\Program Files\KORG\is-1S6K1.tmp | executable | |
MD5:BC65479C7B7A5072E63BBBAC60B0BCB5 | SHA256:F637F4574EA83FA30C5B3DAF5C069F9C4CC0254D51F476587089F43016B2F03B | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |