| File name: | adb-setup-1.3.exe |
| Full analysis: | https://app.any.run/tasks/e9c76109-a87f-4889-b1f2-0338ac2ee695 |
| Verdict: | Malicious activity |
| Analysis date: | February 13, 2024, 18:22:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | A7027B44B7036BB12935AA0BDE764CD2 |
| SHA1: | 40F4C73EA92137361A11511A4C0A52AC8D99D345 |
| SHA256: | 4D479E6615ABAA7B443F5638AE7A2B2D3F92D53BCA9B7BC3B7FC452ABD5BD409 |
| SSDEEP: | 196608:NQhcmavTsC9iOAMYX9mecGxxcSLPZ7ztCawWooDRiuDALqHRBP8RatWRw:+hczTsLMWkecz2Zf6KQuxx11tEw |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:12:31 00:38:38+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 57344 |
| InitializedDataSize: | 307200 |
| UninitializedDataSize: | 389120 |
| EntryPoint: | 0x6ce00 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.0.0 |
| ProductVersionNumber: | 1.3.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Russian |
| CharacterSet: | Unicode |
| CompanyName: | - |
| FileDescription: | - |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| InternalName: | - |
| ProductName: | 15 seconds ADB Installer |
| OriginalFileName: | - |
| FileVersion: | 1.3 |
| ProductVersion: | 1.3 |
| Comments: | - |
| PrivateBuild: | - |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | PING localhost -n 2 | C:\Windows\System32\PING.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: TCP/IP Ping Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 680 | PING localhost -n 3 | C:\Windows\System32\PING.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: TCP/IP Ping Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 796 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 864 | FC /b adb\adb.exe C:\adb\adb.exe | C:\Windows\System32\fc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: DOS 5 File Compare Utility Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1692 | xcopy adb\AdbWinUsbApi.dll C:\adb\ /y /q | C:\Windows\System32\xcopy.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Extended Copy Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1824 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{4e1f11f9-ad74-51ac-2ded-5c6b1033e70d} Global\{2752b98d-7311-3df3-fdde-7b356e9b5366} C:\Windows\System32\DriverStore\Temp\{289cb3d3-c3e5-5f52-74ad-ac514b846310}\android_winusb.inf C:\Windows\System32\DriverStore\Temp\{289cb3d3-c3e5-5f52-74ad-ac514b846310}\androidwinusb86.cat | C:\Windows\System32\rundll32.exe | — | drvinst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1876 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\install.bat" " | C:\Windows\System32\cmd.exe | — | adb-setup-1.3.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2120 | xcopy adb\AdbWinApi.dll C:\adb\ /y /q | C:\Windows\System32\xcopy.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Extended Copy Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2420 | driver\DPInst_x86 /f | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\DPInst_x86.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 256 Version: 2.1 Modules
| |||||||||||||||
| 2752 | "C:\Users\admin\AppData\Local\Temp\adb-setup-1.3.exe" -sfxwaitall:0 "install.bat" | C:\Users\admin\AppData\Local\Temp\adb-setup-1.3.exe | — | adb-setup-1.3.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.3 Modules
| |||||||||||||||
| (PID) Process: | (3668) adb-setup-1.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3668) adb-setup-1.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3668) adb-setup-1.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3668) adb-setup-1.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2752) adb-setup-1.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2752) adb-setup-1.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2752) adb-setup-1.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2752) adb-setup-1.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3960) setx.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment |
| Operation: | write | Name: | PATH |
Value: C:\Program Files\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\PowerShell\7\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\adb | |||
| (PID) Process: | (2420) DPInst_x86.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2844 | adb-setup-1.3.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\install.bat | text | |
MD5:5C4440809A0D2E1A57790C43C3AA36B4 | SHA256:FE0542A6C96CB7BDE8913A7EEB69184E810432E8DA21DF84DEFD0941C2CA625B | |||
| 2844 | adb-setup-1.3.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\androidwinusba64.cat | binary | |
MD5:1DB49B8110F671821FD91E1DA29D36BF | SHA256:160C6809340675DD44AB36D32725418AF0FE5B8FD0893BBDA3660B1A92D779D5 | |||
| 2844 | adb-setup-1.3.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\androidwinusb86.cat | cat | |
MD5:E6F77F81452CA0BEF94F8EDC1731FA84 | SHA256:B1761DBC6B1FA1D10C3952DD0152B8EE6EDB62278908940B491B41EE71ADBF19 | |||
| 2844 | adb-setup-1.3.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\adb\AdbWinUsbApi.dll | executable | |
MD5:5F23F2F936BDFAC90BB0A4970AD365CF | SHA256:041C6859BB4FC78D3A903DD901298CD1ECFB75B6BE0646B74954CD722280A407 | |||
| 2844 | adb-setup-1.3.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\i386\WdfCoInstaller01009.dll | executable | |
MD5:A9970042BE512C7981B36E689C5F3F9F | SHA256:7A6BF1F950684381205C717A51AF2D9C81B203CB1F3DB0006A4602E2DF675C77 | |||
| 2844 | adb-setup-1.3.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\WdfCoInstaller01009.dll | executable | |
MD5:4DA5DA193E0E4F86F6F8FD43EF25329A | SHA256:18487B4FF94EDCCC98ED59D9FCA662D4A1331C5F1E14DF8DB3093256DD9F1C3E | |||
| 2844 | adb-setup-1.3.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\i386\winusbcoinstaller2.dll | executable | |
MD5:8E7B9F81E8823FEE2D82F7DE3A44300B | SHA256:EBE3B7708DD974EE87EFED3113028D266AF87CA8DBAE77C47C6F7612824D3D6C | |||
| 2844 | adb-setup-1.3.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\winusbcoinstaller2.dll | executable | |
MD5:246900CE6474718730ECD4F873234CF5 | SHA256:981A17EFFDDBC20377512DDAEC9F22C2B7067E17A3E2A8CCF82BB7BB7B2420B6 | |||
| 2844 | adb-setup-1.3.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\WUDFUpdate_01009.dll | executable | |
MD5:EBF9EE8A7671F3B260ED9B08FCEE0CC5 | SHA256:015F26BBCD619A0B67B5EAA985B69582BAC27D5CBCA99CE747A76532FCDE4AFF | |||
| 2844 | adb-setup-1.3.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\i386\WUDFUpdate_01009.dll | executable | |
MD5:E1BBE9E3568CF54598E9A8D23697B67E | SHA256:A902BB3BFF785FAAEB6432BE76F798627A80B2CC45441E16440E46E6D7340F2C | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |