| File name: | Setup PreSonus Sphere Manager v2.0.0.exe |
| Full analysis: | https://app.any.run/tasks/3d663d0a-0430-4970-af0f-6324b7df8ef8 |
| Verdict: | Malicious activity |
| Analysis date: | March 01, 2025, 17:10:35 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections |
| MD5: | 845A03D9666086B227B9A57DC64A746D |
| SHA1: | 8AEE1823062B960CB8F3E1B7FD9A080699ED36D0 |
| SHA256: | ECEF8B1C9DD550B1489657395895161F17A8E8F68F33AC9547F5C03DC7EFE66F |
| SSDEEP: | 98304:o0BukgDZXTKbXSj81IrJy0PnNKUDIAhNrciH9utzME2ScVy0+Z7uD83Au70T8MJF:R9Pf4 |
| .exe | | | Inno Setup installer (36.5) |
|---|---|---|
| .exe | | | InstallShield setup (14.3) |
| .exe | | | Win32 Executable Delphi generic (4.7) |
| .dll | | | Win32 Dynamic Link Library (generic) (2.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:06:14 13:27:46+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 66560 |
| InitializedDataSize: | 53760 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1181c |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.0 |
| ProductVersionNumber: | 2.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | TEAM R2R |
| FileDescription: | TEAM R2R PreSonus Sphere Manager Setup |
| FileVersion: | 2.0.0 |
| LegalCopyright: | TEAM R2R |
| ProductName: | PreSonus Sphere Manager |
| ProductVersion: | 2.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 672 | "C:\Program Files\TEAM R2R\PreSonus Sphere Manager\SphereManager.exe" magicS1 /regkey "Studio One 7" | C:\Program Files\TEAM R2R\PreSonus Sphere Manager\SphereManager.exe | — | cmd.exe | |||||||||||
User: admin Company: TEAM R2R Integrity Level: MEDIUM Description: PreSonus Sphere Manager Exit code: 3221226540 Version: 2.0.0.1 Modules
| |||||||||||||||
| 1168 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1276 | "C:\Users\admin\AppData\Local\Temp\Setup PreSonus Sphere Manager v2.0.0.exe" | C:\Users\admin\AppData\Local\Temp\Setup PreSonus Sphere Manager v2.0.0.exe | explorer.exe | ||||||||||||
User: admin Company: TEAM R2R Integrity Level: MEDIUM Description: TEAM R2R PreSonus Sphere Manager Setup Exit code: 0 Version: 2.0.0 Modules
| |||||||||||||||
| 1280 | C:\WINDOWS\system32\cmd.exe /c ""C:\Program Files\TEAM R2R\PreSonus Sphere Manager\commands\Install Magic - Studio One 7.cmd" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2384 | "C:\Users\admin\AppData\Local\Temp\is-NVGV0.tmp\Setup PreSonus Sphere Manager v2.0.0.tmp" /SL5="$802CC,5102344,121344,C:\Users\admin\AppData\Local\Temp\Setup PreSonus Sphere Manager v2.0.0.exe" | C:\Users\admin\AppData\Local\Temp\is-NVGV0.tmp\Setup PreSonus Sphere Manager v2.0.0.tmp | — | Setup PreSonus Sphere Manager v2.0.0.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2852 | ..\\SphereManager.exe magicS1 /regkey "Studio One 7" | C:\Program Files\TEAM R2R\PreSonus Sphere Manager\SphereManager.exe | — | cmd.exe | |||||||||||
User: admin Company: TEAM R2R Integrity Level: MEDIUM Description: PreSonus Sphere Manager Exit code: 3221226540 Version: 2.0.0.1 Modules
| |||||||||||||||
| 3888 | ..\\SphereManager.exe renew | C:\Program Files\TEAM R2R\PreSonus Sphere Manager\SphereManager.exe | — | cmd.exe | |||||||||||
User: admin Company: TEAM R2R Integrity Level: MEDIUM Description: PreSonus Sphere Manager Exit code: 3221226540 Version: 2.0.0.1 Modules
| |||||||||||||||
| 4756 | "C:\Program Files\TEAM R2R\PreSonus Sphere Manager\SphereManager.exe" renew | C:\Program Files\TEAM R2R\PreSonus Sphere Manager\SphereManager.exe | cmd.exe | ||||||||||||
User: admin Company: TEAM R2R Integrity Level: HIGH Description: PreSonus Sphere Manager Exit code: 0 Version: 2.0.0.1 Modules
| |||||||||||||||
| 5416 | "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | C:\Windows\System32\BackgroundTransferHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Download/Upload Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5728 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (7876) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7876) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7876) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (8088) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (8088) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (8088) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (5988) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (5988) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (5988) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (5416) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 8088 | BackgroundTransferHost.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\50267a3c-db8f-434a-a0b9-f23aecf2ba24.down_data | — | |
MD5:— | SHA256:— | |||
| 7212 | Setup PreSonus Sphere Manager v2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-AG8CI.tmp\ISSKINU.DLL | executable | |
MD5:F30AFCCD6FAFC1CAD4567ADA824C9358 | SHA256:E28D16FAD16BCA8198C47D7DD44ACFD362DD6BA1654F700ADD8AAF2C0732622D | |||
| 7212 | Setup PreSonus Sphere Manager v2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-AG8CI.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 7212 | Setup PreSonus Sphere Manager v2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-AG8CI.tmp\SKIN.CJSTYLES | executable | |
MD5:5F87CAF3F7CF63DDE8E6AF53BDF31289 | SHA256:4731982B02B067D3F5A5A7518279A9265A49FB0F7B3F8DC3D61B82A5359D4940 | |||
| 7184 | Setup PreSonus Sphere Manager v2.0.0.exe | C:\Users\admin\AppData\Local\Temp\is-QPA68.tmp\Setup PreSonus Sphere Manager v2.0.0.tmp | executable | |
MD5:34ACC2BDB45A9C436181426828C4CB49 | SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07 | |||
| 1276 | Setup PreSonus Sphere Manager v2.0.0.exe | C:\Users\admin\AppData\Local\Temp\is-NVGV0.tmp\Setup PreSonus Sphere Manager v2.0.0.tmp | executable | |
MD5:34ACC2BDB45A9C436181426828C4CB49 | SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07 | |||
| 7212 | Setup PreSonus Sphere Manager v2.0.0.tmp | C:\Program Files\TEAM R2R\PreSonus Sphere Manager\commands\is-B815S.tmp | text | |
MD5:1E64AF066082A47CB90DBD232587E01C | SHA256:7CCA04E2553FC00A5530CF18BE79CCCBEC21E3B2FE4552C8357F8029854BE99D | |||
| 7212 | Setup PreSonus Sphere Manager v2.0.0.tmp | C:\Program Files\TEAM R2R\PreSonus Sphere Manager\is-Q5UCR.tmp | text | |
MD5:28DAE603EEB7735B5BE5BA93258112C6 | SHA256:4054347A02CF344D9ACA9D3D0D84220D6C51B7EC44E9685705C467E2464414CB | |||
| 7212 | Setup PreSonus Sphere Manager v2.0.0.tmp | C:\Program Files\TEAM R2R\PreSonus Sphere Manager\unins000.exe | executable | |
MD5:7288BCCB404EA193911C22A097967900 | SHA256:D0FD09DB97E35701FA1F5EF7B00BFB4206CD070BA1083841D53037A09FB89ABD | |||
| 7212 | Setup PreSonus Sphere Manager v2.0.0.tmp | C:\Program Files\TEAM R2R\PreSonus Sphere Manager\PreSonusCloud.dll | executable | |
MD5:18707444A1072D92D7CE9E79B28B524A | SHA256:6E412B051078A5DAC72740904FA056F6BFBB8AE4D06D4EEDB7E7E225E91DADCA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
8088 | BackgroundTransferHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
664 | SIHClient.exe | GET | 200 | 23.209.214.100:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
664 | SIHClient.exe | GET | 200 | 23.209.214.100:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2112 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 20.190.160.22:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 40.113.110.67:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3008 | backgroundTaskHost.exe | 2.19.122.59:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
2040 | backgroundTaskHost.exe | 20.223.35.26:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2040 | backgroundTaskHost.exe | 20.103.156.88:443 | fd.api.iris.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
www.bing.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |