File name:

readerdc64_br_xa_cra_mdr_install.exe

Full analysis: https://app.any.run/tasks/53de438a-e03a-48f0-8ef8-cd75293192cd
Verdict: Malicious activity
Analysis date: January 19, 2024, 14:43:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed
MD5:

8ABB981279DAD6371AD9526D9FCD5DF8

SHA1:

571D964F8D27859C0773C7747378B4C0139FFFCA

SHA256:

04CB991F7C25F60ABC3773CCDC93595C272F0471B04FABF574839AC023B66989

SSDEEP:

49152:qOs4xMxY7+hTNkB13fKLHPgdPtB0gFMqQ0re4fIz0Ym1VdTZPM1Vx2Ha9rTEQpsN:i4B+hTQ0DstB0gaUIQYm1V2TrivNpuxu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
    • Application launched itself

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
    • Reads the Internet Settings

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
    • Reads Internet Explorer settings

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
    • Checks Windows Trust Settings

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 2016)
    • Reads security settings of Internet Explorer

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 2016)
    • Reads settings of System Certificates

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
      • readerdc64_br_xa_cra_mdr_install.exe (PID: 2016)
    • Process requests binary or script from the Internet

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
  • INFO

    • Create files in a temporary directory

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
    • Creates files or folders in the user directory

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
    • Checks supported languages

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
      • readerdc64_br_xa_cra_mdr_install.exe (PID: 2016)
    • Reads the computer name

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
      • readerdc64_br_xa_cra_mdr_install.exe (PID: 2016)
    • Checks proxy server information

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
    • Reads the machine GUID from the registry

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 2016)
      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
    • Reads Environment values

      • readerdc64_br_xa_cra_mdr_install.exe (PID: 128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (v2.x) (54.1)
.exe | Win32 EXE PECompact compressed (generic) (38)
.exe | Win32 Executable (generic) (4.1)
.exe | Generic Win/DOS Executable (1.8)
.exe | DOS Executable Generic (1.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:07 13:13:22+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 2126848
InitializedDataSize: 2222592
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.629
ProductVersionNumber: 2.0.0.629
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Adobe Inc
FileDescription: Adobe Download Manager
FileVersion: 2.0.0.629s
InternalName: Adobe Download Manager
LegalCopyright: Copyright 2019 Adobe Inc. All rights reserved.
OriginalFileName: Adobe Download Manager
ProductName: Adobe Download Manager
ProductVersion: 2.0.0.629s
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start readerdc64_br_xa_cra_mdr_install.exe readerdc64_br_xa_cra_mdr_install.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Users\admin\AppData\Local\Temp\readerdc64_br_xa_cra_mdr_install.exe" C:\Users\admin\AppData\Local\Temp\readerdc64_br_xa_cra_mdr_install.exe
explorer.exe
User:
admin
Company:
Adobe Inc
Integrity Level:
MEDIUM
Description:
Adobe Download Manager
Exit code:
0
Version:
2.0.0.629s
Modules
Images
c:\users\admin\appdata\local\temp\readerdc64_br_xa_cra_mdr_install.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2016"C:\Users\admin\AppData\Local\Temp\readerdc64_br_xa_cra_mdr_install.exe" --pipename={C1CF990C-6AA6-42E3-943F-E23CD6371C41} --pid=128C:\Users\admin\AppData\Local\Temp\readerdc64_br_xa_cra_mdr_install.exe
readerdc64_br_xa_cra_mdr_install.exe
User:
admin
Company:
Adobe Inc
Integrity Level:
HIGH
Description:
Adobe Download Manager
Exit code:
0
Version:
2.0.0.629s
Modules
Images
c:\users\admin\appdata\local\temp\readerdc64_br_xa_cra_mdr_install.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
7 135
Read events
7 085
Write events
50
Delete events
0

Modification events

(PID) Process:(128) readerdc64_br_xa_cra_mdr_install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(128) readerdc64_br_xa_cra_mdr_install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(128) readerdc64_br_xa_cra_mdr_install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(128) readerdc64_br_xa_cra_mdr_install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(128) readerdc64_br_xa_cra_mdr_install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(128) readerdc64_br_xa_cra_mdr_install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2016) readerdc64_br_xa_cra_mdr_install.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(128) readerdc64_br_xa_cra_mdr_install.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(128) readerdc64_br_xa_cra_mdr_install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(128) readerdc64_br_xa_cra_mdr_install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
0
Suspicious files
0
Text files
44
Unknown types
0

Dropped files

PID
Process
Filename
Type
128readerdc64_br_xa_cra_mdr_install.exeC:\Users\admin\AppData\Local\Adobe\5593F31A-AE1D-4BD8-9149-8828CF29D036\status_icon_caution_200.pngimage
MD5:3683A511B9DBA974CD9F36A6B023E423
SHA256:210F1B214ECCDE9E148072A10FC0E263FE6A443341BE4DC9630C47BC84796101
128readerdc64_br_xa_cra_mdr_install.exeC:\Users\admin\AppData\Local\Adobe\5593F31A-AE1D-4BD8-9149-8828CF29D036\status_icon_caution_100.pngimage
MD5:784ABEA138D9F1E5A1026162AF5BF2CD
SHA256:5C7B6B5456CAABC9D5A928AC892D9903836693960517C4E534A5DE1ACD6AE428
128readerdc64_br_xa_cra_mdr_install.exeC:\Users\admin\AppData\Local\Adobe\5593F31A-AE1D-4BD8-9149-8828CF29D036\status_icon_x_150.pngimage
MD5:5CC222F110ED5839F910FBBA15F35368
SHA256:EEE6E710161A3AA8488FB4C1F118B43FA5C377ECDEDFFAAE78A81865F16CF288
128readerdc64_br_xa_cra_mdr_install.exeC:\Users\admin\AppData\Local\Temp\Adobe_ADMLogs\Adobe_ADM.logtext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
128readerdc64_br_xa_cra_mdr_install.exeC:\Users\admin\AppData\Local\Adobe\5593F31A-AE1D-4BD8-9149-8828CF29D036\status_icon_check_100.pngimage
MD5:74172250EC6AA49412189DBC0C1ED6E2
SHA256:B7771AC44AB547A772787C6DB58AFCAB0E603E8F9127F3A486A7792EE3E04A90
128readerdc64_br_xa_cra_mdr_install.exeC:\Users\admin\AppData\Local\Adobe\5593F31A-AE1D-4BD8-9149-8828CF29D036\status_icon_x_100.pngimage
MD5:BD94C635B00CC2EA4872591AE3DAC517
SHA256:AACA1B27A5186DF31E60AB0BCFE35D411E03FD7CD069FAFB92314947FD92F256
128readerdc64_br_xa_cra_mdr_install.exeC:\Users\admin\AppData\Local\Adobe\5593F31A-AE1D-4BD8-9149-8828CF29D036\status_icon_caution_125.pngimage
MD5:4A2BF8C96F910B1B2AE63A9F4A0D4B8F
SHA256:0CB2F4EE1C451A8825EB8EDB45858B28345F73423C7A7AEF4168C46F7E3638BF
128readerdc64_br_xa_cra_mdr_install.exeC:\Users\admin\AppData\Local\Adobe\5593F31A-AE1D-4BD8-9149-8828CF29D036\status_icon_x_125.pngimage
MD5:B33C312C95B36E4A3B0F4984B9FE09F2
SHA256:BA0D355243271CB79F5E3EAA3BCAA8BF9169C2E5B0B8E98C6E8418CF6F15AB9D
128readerdc64_br_xa_cra_mdr_install.exeC:\Users\admin\AppData\Local\Adobe\5593F31A-AE1D-4BD8-9149-8828CF29D036\status_icon_check_200.pngimage
MD5:1B00A6BCC425DBD0ACB92E3664488B0D
SHA256:48BEE3671DED91AEE651F5CAC0CBEFD83D760F02EFD376F77364C238F1B14389
128readerdc64_br_xa_cra_mdr_install.exeC:\Users\admin\AppData\Local\Adobe\5593F31A-AE1D-4BD8-9149-8828CF29D036\progressbar_blue_active_200.pngimage
MD5:0F78C8C46DAD3F68D060B406AA0BBF1F
SHA256:C08F7720960B2E21B1F8F106D80BCB1AF7C11433E3B35D7AE2994254A2A2583C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
13
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
128
readerdc64_br_xa_cra_mdr_install.exe
GET
302
63.140.62.22:80
http://stats.adobe.com/b/ss/adbacdcprod,adbadobenonacdcprod/1/H.25.4/s28492432761098?AQB=1&ndh=1&t=19%2F0%2F2024%2014%3A44%3A9%205%200&ce=UTF-8&ns=adobecorp&g=res%3A%2F%2FC%3A%5CUsers%5Cadmin%5CAppData%5CLocal%5CTemp%5Creaderdc64_br_xa_cra_mdr_install.exe%2F160&c.&digitalData.&page.&pageInfo.&pageName=get.adobe.com%3Areader%3Ainstaller&language=en-US&template=ADM&variant=Type1&siteSection=ADM&.pageInfo&.page&getAdobe.&productFamily=ACDC%20Downloads&platformEnvironment=ACDC_Reader&productBitInfo=Rdr64&productVars=Reader%7C&eventActionList=ADM%20Launched%7C&.getAdobe&adobe.&experienceCloud.&visitorService.&info.&version=VisitorAPI%20Not%20Present&.info&.visitorService&.experienceCloud&.adobe&.digitalData&.c&products=%3BReader%3B%3B&v18=New&v22=Friday%20-%207%3A30AM&s=1280x720&c=32&j=1.5&v=Y&k=N&bw=620&bh=358&ct=lan&hp=Y&AQE=1
unknown
unknown
128
readerdc64_br_xa_cra_mdr_install.exe
GET
200
63.140.62.22:80
http://stats.adobe.com/b/ss/adbacdcprod,adbadobenonacdcprod/1/H.25.4/s28492432761098?AQB=1&pccr=true&vidn=32D5455CCCE1ED10-60000F53229E4B83&ndh=1&t=19%2F0%2F2024%2014%3A44%3A9%205%200&ce=UTF-8&ns=adobecorp&g=res%3A%2F%2FC%3A%5CUsers%5Cadmin%5CAppData%5CLocal%5CTemp%5Creaderdc64_br_xa_cra_mdr_install.exe%2F160&c.&digitalData.&page.&pageInfo.&pageName=get.adobe.com%3Areader%3Ainstaller&language=en-US&template=ADM&variant=Type1&siteSection=ADM&.pageInfo&.page&getAdobe.&productFamily=ACDC%20Downloads&platformEnvironment=ACDC_Reader&productBitInfo=Rdr64&productVars=Reader%7C&eventActionList=ADM%20Launched%7C&.getAdobe&adobe.&experienceCloud.&visitorService.&info.&version=VisitorAPI%20Not%20Present&.info&.visitorService&.experienceCloud&.adobe&.digitalData&.c&products=%3BReader%3B%3B&v18=New&v22=Friday%20-%207%3A30AM&s=1280x720&c=32&j=1.5&v=Y&k=N&bw=620&bh=358&ct=lan&hp=Y&AQE=1
unknown
image
43 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
128
readerdc64_br_xa_cra_mdr_install.exe
23.211.8.250:443
geo-dc.adobe.com
AKAMAI-AS
DE
whitelisted
128
readerdc64_br_xa_cra_mdr_install.exe
54.194.243.238:443
rdc.adobe.io
AMAZON-02
IE
unknown
128
readerdc64_br_xa_cra_mdr_install.exe
2.18.96.131:443
dlmping2.adobe.com
Akamai International B.V.
FR
unknown
128
readerdc64_br_xa_cra_mdr_install.exe
63.140.62.22:80
stats.adobe.com
AMAZON-02
US
unknown
128
readerdc64_br_xa_cra_mdr_install.exe
23.53.232.142:443
platformdl.adobe.com
AKAMAI-AS
DE
unknown
128
readerdc64_br_xa_cra_mdr_install.exe
23.212.88.135:443
ardownload2.adobe.com
AKAMAI-AS
MX
unknown

DNS requests

Domain
IP
Reputation
geo-dc.adobe.com
  • 23.211.8.250
whitelisted
rdc.adobe.io
  • 54.194.243.238
  • 34.250.67.152
  • 54.195.71.107
unknown
dlmping2.adobe.com
  • 2.18.96.131
whitelisted
stats.adobe.com
  • 63.140.62.22
  • 63.140.62.214
  • 63.140.62.164
  • 63.140.62.135
  • 63.140.62.160
  • 63.140.62.108
whitelisted
platformdl.adobe.com
  • 23.53.232.142
whitelisted
ardownload2.adobe.com
  • 23.212.88.135
whitelisted

Threats

No threats detected
No debug info