| File name: | Reader_uk_install.exe |
| Full analysis: | https://app.any.run/tasks/c9adfce8-c53d-4837-8411-290083f28cd2 |
| Verdict: | Malicious activity |
| Analysis date: | August 07, 2024, 22:16:25 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | EEA127EA11BC00332042801B5BDDEDEB |
| SHA1: | 95C8A2CE7AD5E565A53D30BED39105738F47A816 |
| SHA256: | 16C02B4FF7662EFFEC062F21C96A8D48F63CA8347D49F3427A4A509F0DA8AB4B |
| SSDEEP: | 49152:0bw5pHIYAEj1LnGsklGlPmbBTQ1VlshJEQ7+cvHcbdSuX89kQ5zJBFNBzV380ub6:ow5pHI2jVnoZBTmILtpfcJ5XWkQTzNbP |
| .exe | | | Win64 Executable (generic) (43.7) |
|---|---|---|
| .exe | | | UPX compressed Win32 Executable (42.8) |
| .exe | | | Win32 Executable (generic) (7.1) |
| .exe | | | Generic Win/DOS Executable (3.1) |
| .exe | | | DOS Executable Generic (3.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:08:02 10:55:04+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.35 |
| CodeSize: | 1601536 |
| InitializedDataSize: | 20480 |
| UninitializedDataSize: | 3080192 |
| EntryPoint: | 0x476e40 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.783 |
| ProductVersionNumber: | 2.0.0.783 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Adobe Inc |
| FileDescription: | Adobe Download Manager |
| FileVersion: | 2.0.0.783s |
| InternalName: | Adobe Download Manager |
| LegalCopyright: | Copyright 2019 Adobe Inc. All rights reserved. |
| OriginalFileName: | Adobe Download Manager |
| ProductName: | Adobe Download Manager |
| ProductVersion: | 2.0.0.783s |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 420 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=5844 --field-trial-handle=2480,i,7272472039740981864,15546109875472107179,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 888 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7136 --field-trial-handle=2480,i,7272472039740981864,15546109875472107179,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 888 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6664 --field-trial-handle=2480,i,7272472039740981864,15546109875472107179,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1020 | "C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6780 --field-trial-handle=2480,i,7272472039740981864,15546109875472107179,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: PWA Identity Proxy Host Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1076 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5580 --field-trial-handle=2480,i,7272472039740981864,15546109875472107179,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1224 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6908 --field-trial-handle=2480,i,7272472039740981864,15546109875472107179,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2480 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe" ClearToasts | C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | msiexec.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2700 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3304 --field-trial-handle=2480,i,7272472039740981864,15546109875472107179,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 3360 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6436 --field-trial-handle=2480,i,7272472039740981864,15546109875472107179,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 3508 | "C:\Users\admin\Desktop\Reader_uk_install.exe" --pipename={7B1AE556-49A0-4266-A82C-B7CDDD99C9A2} --pid=5084 | C:\Users\admin\Desktop\Reader_uk_install.exe | Reader_uk_install.exe | ||||||||||||
User: admin Company: Adobe Inc Integrity Level: HIGH Description: Adobe Download Manager Version: 2.0.0.783s Modules
| |||||||||||||||
| (PID) Process: | (6240) Reader_uk_install.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6240) Reader_uk_install.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6240) Reader_uk_install.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6240) Reader_uk_install.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6240) Reader_uk_install.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6240) Reader_uk_install.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6240) Reader_uk_install.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6240) Reader_uk_install.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (6788) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6240 | Reader_uk_install.exe | C:\Users\admin\AppData\Local\Temp\Adobe_ADMLogs\Adobe_ADM.log | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 6344 | Reader_uk_install.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141 | binary | |
MD5:3438EDE2AA00838A0D35F2905F258A83 | SHA256:C9D090E3899280B7A09617B17946C2A93FA6F10A07B13C5CC4781B353A9EB8F0 | |||
| 6344 | Reader_uk_install.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141 | der | |
MD5:519F47CA386A53C372D32C745E3FF3D3 | SHA256:1CC9A63B647EC23C31782940811AFCE8F2F9C9CF1A54172C63A308B109051E23 | |||
| 6240 | Reader_uk_install.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | der | |
MD5:51C34A0CDB87F64A7841CEFD85029335 | SHA256:FA1748E9FDF2B364092853D8F8AF63FA45BC1C2BB3B720763F10A8E071AAD187 | |||
| 6344 | Reader_uk_install.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB | binary | |
MD5:82624CE71E3E4FE36DC7FBDC0DE2BDF9 | SHA256:3A1EC1EAAF462E5AF5F95C0A02A65CD90270B4C3ECB42026845239867C699882 | |||
| 6240 | Reader_uk_install.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\d[6] | woff | |
MD5:590A9EEBC0AC0BA776529CBA1D5B718A | SHA256:28195F698F74D701F5B253495756F7ECD70C50047C1F795952587E6F3E742B19 | |||
| 6240 | Reader_uk_install.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\d[7] | woff | |
MD5:C26C1B68EDD07AB0069CF2EFE0886C1F | SHA256:72073CA6C71BCC781491B054C4325A663834082457FD896CB6E1E9931BF6E013 | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFe70e6.TMP | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFe70d6.TMP | — | |
MD5:— | SHA256:— | |||
| 6788 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFe70e6.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6344 | Reader_uk_install.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | whitelisted |
6344 | Reader_uk_install.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA5uMvyw4DoMCyvAS1byA4s%3D | unknown | — | — | whitelisted |
8340 | AdobeARM.exe | GET | 304 | 2.19.126.149:80 | http://acroipm2.adobe.com/assets/Owner/arm/ProcessMAU.txt | unknown | — | — | whitelisted |
6240 | Reader_uk_install.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | — | — | whitelisted |
6344 | Reader_uk_install.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
8340 | AdobeARM.exe | GET | 404 | 2.19.126.149:80 | http://acroipm2.adobe.com/assets/Owner/arm/2024/8/OwnerAPI/Rdr.txt | unknown | — | — | whitelisted |
8340 | AdobeARM.exe | GET | 304 | 2.19.126.149:80 | http://acroipm2.adobe.com/assets/Owner/arm/ReportOwner.txt | unknown | — | — | whitelisted |
8340 | AdobeARM.exe | GET | 404 | 2.19.126.149:80 | http://acroipm2.adobe.com/assets/Owner/arm/2024/8/UC/Other.txt | unknown | — | — | whitelisted |
8340 | AdobeARM.exe | GET | 404 | 2.19.126.149:80 | http://acroipm2.adobe.com/assets/Owner/arm/32/adnme/NoValidReasonForAdnme.txt | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2340 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1060 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
6344 | Reader_uk_install.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
6240 | Reader_uk_install.exe | 2.19.126.206:443 | use.typekit.net | Akamai International B.V. | DE | unknown |
6240 | Reader_uk_install.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
6240 | Reader_uk_install.exe | 184.28.88.176:443 | geo-dc.adobe.com | AKAMAI-AS | US | unknown |
6240 | Reader_uk_install.exe | 34.246.54.182:443 | rdc.adobe.io | AMAZON-02 | IE | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
use.typekit.net |
| whitelisted |
geo-dc.adobe.com |
| whitelisted |
rdc.adobe.io |
| whitelisted |
p.typekit.net |
| shared |
dlmping2.adobe.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
Process | Message |
|---|---|
FullTrustNotifier.exe | FullTrustNotifier |
FullTrustNotifier.exe | |
FullTrustNotifier.exe | FN ConnectToAppService create the async task |
FullTrustNotifier.exe | |
FullTrustNotifier.exe | FN ClearToasts |
FullTrustNotifier.exe | |
FullTrustNotifier.exe | FN ConnectToAppServiceAsync |
FullTrustNotifier.exe | |
FullTrustNotifier.exe |
ConnectToAppServiceAsync AppNotInstalled |
FullTrustNotifier.exe | FullTrustNotifier Exit |