File name:

acrotray.exe

Full analysis: https://app.any.run/tasks/40c5d868-e454-4b63-a932-357cf277f706
Verdict: Malicious activity
Analysis date: June 15, 2025, 22:26:50
OS: Windows 10 Professional (build: 19044, 64 bit)
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 8 sections
MD5:

689DA9580D82BEF5387D8DC69427DF14

SHA1:

1854A9269FC2C416830EB58E9DCECC9767763CCA

SHA256:

272B7849C65785DC6F6B99BF37C84552B11CCCAB92D59304785A79F49949ED0E

SSDEEP:

98304:CkBfLwWBuu4q2jrwbOfSz4EEk3I2qDgDm2TQYd6WI70JAe/kABrbBK41dhZVQHY1:IGF502O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • acrotray.exe (PID: 7048)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • acrotray.exe (PID: 7048)
  • INFO

    • Reads the computer name

      • acrotray.exe (PID: 7048)
    • The sample compiled with english language support

      • acrotray.exe (PID: 7048)
    • Checks supported languages

      • acrotray.exe (PID: 7048)
    • Create files in a temporary directory

      • acrotray.exe (PID: 7048)
    • Checks proxy server information

      • acrotray.exe (PID: 7048)
    • Reads the machine GUID from the registry

      • acrotray.exe (PID: 7048)
    • Reads the software policy settings

      • acrotray.exe (PID: 7048)
    • Creates files or folders in the user directory

      • acrotray.exe (PID: 7048)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:06:06 08:24:44+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.38
CodeSize: 7305728
InitializedDataSize: 3504128
UninitializedDataSize: -
EntryPoint: 0x59e950
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 25.1.20531.0
ProductVersionNumber: 25.1.20531.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: -
CompanyName: Adobe Systems Inc.
FileDescription: Acrobat Licensing Service
FileVersion: 25.1.20531.0
InternalName: AcroTray
LegalCopyright: Copyright © Adobe Systems Inc. 1992-2025
LegalTrademarks: -
OriginalFileName: AcroTray.exe
PrivateBuild: -
ProductName: AcroTray - Adobe Acrobat Distiller helper application.
ProductVersion: 25.1.20531.0
SpecialBuild: -
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
2
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start acrotray.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3720C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7048"C:\Users\admin\AppData\Local\Temp\acrotray.exe" C:\Users\admin\AppData\Local\Temp\acrotray.exe
explorer.exe
User:
admin
Company:
Adobe Systems Inc.
Integrity Level:
MEDIUM
Description:
Acrobat Licensing Service
Version:
25.1.20531.0
Modules
Images
c:\users\admin\appdata\local\temp\acrotray.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
4 057
Read events
4 044
Write events
13
Delete events
0

Modification events

(PID) Process:(7048) acrotray.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer
Operation:writeName:Launched
Value:
1
(PID) Process:(7048) acrotray.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer
Operation:writeName:EULAAcceptedForBrowser
Value:
1
(PID) Process:(7048) acrotray.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:sAppEntitlementStatus
Value:
4E4F56414C554500
(PID) Process:(7048) acrotray.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:sUserEmail
Value:
00
(PID) Process:(7048) acrotray.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:sUserGUID
Value:
00
(PID) Process:(7048) acrotray.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:sDeviceID
Value:
00
(PID) Process:(7048) acrotray.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:sProductGUID
Value:
4143524F4241545F475549445F4E474C5F44554D4D5900
(PID) Process:(7048) acrotray.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:sProductGUID
Value:
4143524F5F5245534944554500
(PID) Process:(7048) acrotray.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:iEntitlementLevel
Value:
1
Executable files
0
Suspicious files
6
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7048acrotray.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_54359052731E413C60F1C59EABAD4E05binary
MD5:FE444870A5B59CD7E6B5524EE7C801FE
SHA256:840B9B737B1E6968187BF49F2B4C15AD21CCFAAEEBB561A47044555951E3F883
7048acrotray.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:3060E1776FA7286C94DFB22610C280E6
SHA256:2F1647918A7AA2C14B47FBB2B273D0A08C90270E053DDFD98D66E6F11159EB59
7048acrotray.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:8ECEE8A124904EF28D6D090E565C486C
SHA256:FE0290ADFD9F72016D34B8C544C4A9BE396725D4A9DE38DCE49A28084CEF422B
7048acrotray.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:14CAA4CF42ECDF8603D976A060F2431D
SHA256:5441248E74C1559FA5738A3A6FD82A729732F917433447B9708A66F3F47F9548
7048acrotray.exeC:\Users\admin\AppData\Local\Temp\distNGLLog.txttext
MD5:456D81486B21E2B6F13782CDB36E49E1
SHA256:FD95BA16BAF330BD67D14389CC8586E1157DB95176946F58C7CA0E58F699E1E5
7048acrotray.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:F99FBC7278257DE2810AE83A914BFC6D
SHA256:654F5B448AB3A999CD50BFA3FB7D16EB576D8FD361EAE8EF607E9271AD6E798A
7048acrotray.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_54359052731E413C60F1C59EABAD4E05binary
MD5:600748E05546538A030D3B6D7FFD443F
SHA256:F67D2FEE59190541480ECA9F9DDE2C649C075388446678CCB6CEBDA2A3768DAA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
333
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7048
acrotray.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
7048
acrotray.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
7048
acrotray.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA0aNA9419AA4In9uq1lIt8%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7048
acrotray.exe
54.194.243.238:443
cc-api-data.adobe.io
AMAZON-02
IE
whitelisted
7048
acrotray.exe
54.77.72.255:443
lcs-cops.adobe.io
AMAZON-02
IE
whitelisted
7048
acrotray.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6024
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7048
acrotray.exe
34.250.67.152:443
cc-api-data.adobe.io
AMAZON-02
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.78
whitelisted
lcs-cops.adobe.io
  • 54.77.72.255
  • 3.248.26.100
  • 54.74.179.44
whitelisted
cc-api-data.adobe.io
  • 54.194.243.238
  • 34.250.67.152
  • 54.195.71.107
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
lcs-robs.adobe.io
  • 54.195.71.107
  • 34.250.67.152
  • 54.194.243.238
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.134
  • 20.190.160.67
  • 40.126.32.72
  • 20.190.160.4
  • 20.190.160.20
  • 40.126.32.140
  • 40.126.32.74
  • 20.190.160.5
  • 20.190.160.22
  • 40.126.32.136
  • 40.126.32.138
  • 20.190.160.2
  • 20.190.160.64
  • 40.126.32.133
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.11
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
  • 4.175.87.197
  • 20.109.210.53
whitelisted

Threats

No threats detected
No debug info