analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Premiere_Pro_Set-Up.exe

Full analysis: https://app.any.run/tasks/63338195-b179-4751-9517-f653ef2b9a04
Verdict: Malicious activity
Analysis date: January 24, 2022, 19:32:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

108EF1B61BC2352CA043701040667ADA

SHA1:

B0407F2B80A7B202BF3C6024F958CD5E7AA07740

SHA256:

21AB446EBF6527DB10B35DED207B40BCCD51633EEF7F84D7C68FAF139E1E33F6

SSDEEP:

24576:jTqEtpUGqBK5vO39HKOk7b6JDR/4pWtaqyQ+96C4b1YOUEsuxPq4luZgQXgcSqF+:WB+OqOS+lPta7QbdlAg/3hnFZZD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks supported languages

      • Premiere_Pro_Set-Up.exe (PID: 3052)
    • Reads the computer name

      • Premiere_Pro_Set-Up.exe (PID: 3052)
    • Changes IE settings (feature browser emulation)

      • Premiere_Pro_Set-Up.exe (PID: 3052)
    • Reads internet explorer settings

      • Premiere_Pro_Set-Up.exe (PID: 3052)
    • Reads Microsoft Outlook installation path

      • Premiere_Pro_Set-Up.exe (PID: 3052)
  • INFO

    • Reads settings of System Certificates

      • Premiere_Pro_Set-Up.exe (PID: 3052)
    • Checks supported languages

      • taskmgr.exe (PID: 3448)
    • Reads the computer name

      • taskmgr.exe (PID: 3448)
    • Checks Windows Trust Settings

      • Premiere_Pro_Set-Up.exe (PID: 3052)
    • Manual execution by user

      • taskmgr.exe (PID: 3448)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (43.5)
.exe | Win32 EXE Yoda's Crypter (42.7)
.exe | Win32 Executable (generic) (7.2)
.exe | Generic Win/DOS Executable (3.2)
.exe | DOS Executable Generic (3.2)

EXIF

EXE

ProductVersion: 2.7.0.15
ProductName: Adobe Installer
OriginalFileName: Adobe Installer
LegalCopyright: © 2015-2022 Adobe. All rights reserved.
InternalName: Adobe Installer
FileVersion: 2.7.0.15
FileDescription: Adobe Installer
CompanyName: Adobe Inc.
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Dynamic link library
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 2.7.0.15
FileVersionNumber: 2.7.0.15
Subsystem: Windows GUI
SubsystemVersion: 5.1
ImageVersion: -
OSVersion: 5.1
EntryPoint: 0x77e8f0
UninitializedDataSize: 5378048
InitializedDataSize: 45056
CodeSize: 2478080
LinkerVersion: 14.23
PEType: PE32
TimeStamp: 2022:01:12 14:38:47+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 12-Jan-2022 13:38:47
Detected languages:
  • English - United States
CompanyName: Adobe Inc.
FileDescription: Adobe Installer
FileVersion: 2.7.0.15
InternalName: Adobe Installer
LegalCopyright: © 2015-2022 Adobe. All rights reserved.
OriginalFilename: Adobe Installer
ProductName: Adobe Installer
ProductVersion: 2.7.0.15

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000120

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 12-Jan-2022 13:38:47
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
UPX0
0x00001000
0x00521000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
UPX1
0x00522000
0x0025D000
0x0025CC00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.895
.rsrc
0x0077F000
0x0000B000
0x0000A600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.15994

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.14505
1907
UNKNOWN
English - United States
RT_MANIFEST
2
2.15946
2440
UNKNOWN
English - United States
RT_ICON
3
2.07363
4264
UNKNOWN
English - United States
RT_ICON
4
1.98677
9640
UNKNOWN
English - United States
RT_ICON
5
1.9383
16936
UNKNOWN
English - United States
RT_ICON
6
7.42075
2793
UNKNOWN
English - United States
RT_ICON
101
2.79371
90
UNKNOWN
English - United States
RT_GROUP_ICON
105
7.44247
469
UNKNOWN
English - United States
XML
121
7.34786
426
UNKNOWN
English - United States
RT_HTML
122
0
884186
UNKNOWN
English - United States
CSS

Imports

KERNEL32.DLL
WS2_32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start premiere_pro_set-up.exe taskmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3052"C:\Users\admin\AppData\Local\Temp\Premiere_Pro_Set-Up.exe" C:\Users\admin\AppData\Local\Temp\Premiere_Pro_Set-Up.exe
Explorer.EXE
User:
admin
Company:
Adobe Inc.
Integrity Level:
MEDIUM
Description:
Adobe Installer
Version:
2.7.0.15
3448"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
7 780
Read events
7 745
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
1
Text files
5
Unknown types
4

Dropped files

PID
Process
Filename
Type
3052Premiere_Pro_Set-Up.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
MD5:
SHA256:
3052Premiere_Pro_Set-Up.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
MD5:
SHA256:
3052Premiere_Pro_Set-Up.exeC:\Users\admin\AppData\Local\Temp\{76ECC9B3-4BAA-4088-B96D-08A1D43CDEC1}\CCDInstaller.jsbinary
MD5:76D91BE7BDB92E541B3FACE5B94E9F0A
SHA256:302B9BAB186ED0E233F55CB660E0D0E326479E84855F0BB68E7632313238BF11
3052Premiere_Pro_Set-Up.exeC:\Users\admin\AppData\Local\Adobe\OOBE\temp_ins_lbs_widtext
MD5:B52FF654790587320A359B08D8015774
SHA256:942E0168233F9557FC8D65F967480D65172211CCC2267A66905554160B684B70
3052Premiere_Pro_Set-Up.exeC:\Users\admin\AppData\Local\Adobe\OOBE\temp_lbs_widtext
MD5:5B867906AAD886998A1585F720D86E28
SHA256:8B5EAE6793B4F33A3E3767F55835AB56CB9DBFB91055A307D24DE13FEAD5D824
3052Premiere_Pro_Set-Up.exeC:\Users\admin\AppData\Local\Temp\CreativeCloud\ACC\WAM.logtext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
3052Premiere_Pro_Set-Up.exeC:\Users\admin\AppData\Local\Temp\dat8F09.tmpwoff
MD5:E204643042591AEEC2043C5EAE255099
SHA256:7F58F56A7A353F8FC78EC2757394A7C7F28165E6BBF2A37D6A6E48E845874F3E
3052Premiere_Pro_Set-Up.exeC:\Users\admin\AppData\Local\Temp\dat8ED8.tmpwoff
MD5:FA794EC12D353C26805FF53821331FC2
SHA256:CFDBD8A2AA463C11E483DC10C480ACD274E9786632F5571A3970E8A20A2D8237
3052Premiere_Pro_Set-Up.exeC:\Users\admin\AppData\Local\Temp\dat8F29.tmpwoff
MD5:DFCE51814CF6D2F42375F948602CD99D
SHA256:7A8A945586A1D21D2922CB4AED9E28D872129F6C396AC69F47EF3E32EA972BA0
3052Premiere_Pro_Set-Up.exeC:\Users\admin\AppData\Local\Temp\dat8EE9.tmpwoff
MD5:D070306A9062178AFDFA98FCC06D2525
SHA256:8F5CCDFD3DA9185D4AD262EC386EBB64B3EB6C0521EC5BD1662CEC04E1E0F895
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
31
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3052
Premiere_Pro_Set-Up.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
3052
Premiere_Pro_Set-Up.exe
GET
200
8.248.145.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2d9965c7d279bdbf
US
compressed
4.70 Kb
whitelisted
3052
Premiere_Pro_Set-Up.exe
GET
200
8.248.145.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1ba0f600512acc6f
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3052
Premiere_Pro_Set-Up.exe
44.235.133.210:443
na1e-acc.services.adobe.com
University of California, San Diego
US
unknown
3052
Premiere_Pro_Set-Up.exe
54.203.138.127:443
na1e-acc.services.adobe.com
Amazon.com, Inc.
US
unknown
3052
Premiere_Pro_Set-Up.exe
100.20.96.5:443
na1e-acc.services.adobe.com
US
unknown
3052
Premiere_Pro_Set-Up.exe
34.252.184.159:443
cc-api-data.adobe.io
Amazon.com, Inc.
IE
unknown
3052
Premiere_Pro_Set-Up.exe
54.192.86.113:443
client.messaging.adobe.com
Amazon.com, Inc.
US
unknown
3052
Premiere_Pro_Set-Up.exe
52.48.8.54:443
cc-api-data.adobe.io
Amazon.com, Inc.
IE
suspicious
3052
Premiere_Pro_Set-Up.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3052
Premiere_Pro_Set-Up.exe
8.248.145.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
34.252.184.159:443
cc-api-data.adobe.io
Amazon.com, Inc.
IE
unknown

DNS requests

Domain
IP
Reputation
cc-api-data.adobe.io
  • 34.252.184.159
  • 52.48.8.54
  • 52.31.218.129
whitelisted
na1e-acc.services.adobe.com
  • 44.235.133.210
  • 54.203.138.127
  • 54.186.66.156
  • 52.41.254.153
  • 34.210.227.226
  • 35.83.103.178
  • 50.112.174.125
  • 35.166.116.185
  • 100.20.96.5
  • 44.241.252.106
  • 52.36.184.129
  • 44.240.237.60
  • 52.34.20.210
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
client.messaging.adobe.com
  • 54.192.86.113
  • 54.192.86.97
  • 54.192.86.123
  • 54.192.86.29
whitelisted
ctldl.windowsupdate.com
  • 8.248.145.254
  • 67.26.83.254
  • 8.253.207.120
  • 8.253.207.121
  • 8.248.137.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
No debug info