File name:

AdobeUnlicensedPopupBlocker.zip

Full analysis: https://app.any.run/tasks/c0cfe6ea-2b90-4bb5-a6ca-60a0be8ee206
Verdict: Malicious activity
Analysis date: April 08, 2025, 17:57:23
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

65C82183C3E22469C475D787176547B8

SHA1:

E5F45711CE3037794ED12604FE3E9D72C5A5C437

SHA256:

5436AA7C6C8E183003A02ABB82F9F364C8F297A3386EF40AE09F2B89A7472C2C

SSDEEP:

98304:UR+n3gYYUhSt33hKVhFZFNt0f3R7mFDBP1nUgghHesMU9EI00RIaqQuZjW56HLE+:pt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7612)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 7968)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 7744)
      • WinRAR.exe (PID: 7612)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 7744)
      • cmd.exe (PID: 8060)
      • cmd.exe (PID: 8176)
      • cmd.exe (PID: 7340)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • cmd.exe (PID: 7744)
      • cmd.exe (PID: 7968)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 7744)
    • Application launched itself

      • cmd.exe (PID: 7744)
    • Hides command output

      • cmd.exe (PID: 8176)
      • cmd.exe (PID: 8060)
      • cmd.exe (PID: 7340)
    • Uses NSLOOKUP.EXE to check DNS info

      • cmd.exe (PID: 8060)
      • cmd.exe (PID: 8176)
      • cmd.exe (PID: 7340)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 4776)
      • schtasks.exe (PID: 3176)
    • Windows service management via SC.EXE

      • sc.exe (PID: 7320)
      • sc.exe (PID: 2560)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 7968)
    • Stops a currently running service

      • sc.exe (PID: 7292)
      • sc.exe (PID: 7260)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 7968)
    • Executing commands from a ".bat" file

      • WinRAR.exe (PID: 7612)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7612)
  • INFO

    • Manual execution by a user

      • cmd.exe (PID: 7744)
      • cmd.exe (PID: 7968)
      • notepad.exe (PID: 3132)
      • wget.exe (PID: 7392)
      • OpenWith.exe (PID: 6964)
      • notepad.exe (PID: 6036)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 6036)
      • notepad.exe (PID: 3132)
    • Checks supported languages

      • wget.exe (PID: 7392)
      • MpCmdRun.exe (PID: 7248)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 6964)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7612)
    • Create files in a temporary directory

      • MpCmdRun.exe (PID: 7248)
    • Reads the computer name

      • MpCmdRun.exe (PID: 7248)
    • Reads the software policy settings

      • slui.exe (PID: 8032)
    • Checks proxy server information

      • slui.exe (PID: 8032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:04:08 19:55:10
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: 1/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
168
Monitored processes
42
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe cmd.exe no specs conhost.exe no specs netsh.exe no specs ping.exe no specs findstr.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs nslookup.exe findstr.exe no specs schtasks.exe no specs cmd.exe no specs nslookup.exe findstr.exe no specs schtasks.exe no specs schtasks.exe no specs cmd.exe no specs nslookup.exe schtasks.exe no specs findstr.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs taskkill.exe no specs wget.exe no specs conhost.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs notepad.exe no specs notepad.exe no specs openwith.exe no specs slui.exe cmd.exe no specs conhost.exe no specs mpcmdrun.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
496schtasks /run /tn "Adobe Pop-up Blocker"C:\Windows\System32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
536taskkill /f /t /im AdobeCleanUpUtility.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
920taskkill /f /t /im AGMService.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1348findstr /i /l /c:"nameserver = "C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2100taskkill /f /t /im "Adobe Genuine Launcher.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2560sc delete AGSServiceC:\Windows\System32\sc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Service Control Manager Configuration Tool
Exit code:
1060
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
2600taskkill /f /t /im agshelper.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3020nslookup -type=ns ic.adobe.ioC:\Windows\System32\nslookup.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
nslookup
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\nslookup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\iphlpapi.dll
3132"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\iplist.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
3176schtasks /delete /f /tn "Adobe-Genuine-Software-Integrity-Scheduler-1.0"C:\Windows\System32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
8 938
Read events
8 928
Write events
10
Delete events
0

Modification events

(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\AdobeUnlicensedPopupBlocker.zip
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList
Operation:writeName:ArcSort
Value:
32
(PID) Process:(7612) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\VirusScan
Operation:writeName:DefScanner
Value:
Windows Defender
Executable files
2
Suspicious files
1
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR7612.45064\AdobeUnlicensedPopupBlocker.zip\1\AdobeUnlicensedPopupBlocker\iplist.txttext
MD5:9E9EAA75D8A3BB90E24B62009A54D068
SHA256:1B59078D3D19BB7B9DBA9CB97C6A526976746EB9EB9075D5EF5B60D0E695EC48
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR7612.45064\AdobeUnlicensedPopupBlocker.zip\1\AdobeUnlicensedPopupBlocker\BlockIPs.cmdtext
MD5:D4C60D2D549FB0D94D026E0EB3C1177C
SHA256:991F75A4946FC7A151A5D3434E3540D0F8BBDAA9F9D7558B7562DE1D1FF046D7
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR7612.45064\AdobeUnlicensedPopupBlocker.zip\1\AdobeUnlicensedPopupBlocker\pihole.txttext
MD5:0E6998346E11345F9AA99DEADC5C2FA1
SHA256:4D68A640D0292F8F54F4E225396CF5150C091DB3F82813642AFBCA561511783C
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR7612.45064\AdobeUnlicensedPopupBlocker.zip\AdobeUnlicensedPopupBlocker.pimxxml
MD5:89E20C9115A8EEBEA95532FBEF6BBBE4
SHA256:ED149A19DADFBD442CC6D8ACADB688A0243AEF14DB4960CCBCCC1D62F5DCB765
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR7612.45064\Rar$Scan88960.battext
MD5:D49E705BC0731609E69464EFD2BE7469
SHA256:8AC9E83AE03B5BFB646DE85D47185F66E11FA27C0A1DB1FF1A70DD5EFC0CE4A5
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR7612.45064\AdobeUnlicensedPopupBlocker.zip\1\AdobeUnlicensedPopupBlocker\UnPP.xmlxml
MD5:6E919EA3448C1E74150CCA760A342374
SHA256:0F9947FB498E0F21A4AE9FC256BD34D524F8BE6E4697E09C4B696D758323852A
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR7612.45064\AdobeUnlicensedPopupBlocker.zip\1\AdobeUnlicensedPopupBlocker\RunOnce.cmdtext
MD5:935602FFC48E0FEE04DB8011ED902BC1
SHA256:E1CA97789C269AD8E1BDC2095D505ECD4AFC28985D1765C2E9569B5044F1CB6E
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR7612.45064\AdobeUnlicensedPopupBlocker.zip\1\AdobeUnlicensedPopupBlocker\dnsx.exeexecutable
MD5:47C028F041C83817250E3D49126A8C88
SHA256:9F7A353258017C04C5197379F5F5F6821E32712346C9AC4611313B2712805120
7248MpCmdRun.exeC:\Users\admin\AppData\Local\Temp\MpCmdRun.logbinary
MD5:8B3EC15FF91FE256DACC3F0F62780D4A
SHA256:CAFDA1A5117EDEFAA9DB020120081E52A931193EB9DA62F84A99DB569A5DF7B6
7612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR7612.45064\AdobeUnlicensedPopupBlocker.zip\1\AdobeUnlicensedPopupBlocker\wget.exeexecutable
MD5:B1F557BD6A97A95CFF5DBCC55BF6E9BB
SHA256:A6093F8F40F90AD576B0463FB352318416EA24265D3E8F43D4F7F3723F7E7F77
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
49
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
304
172.202.163.200:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
GET
200
172.202.163.200:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
6048
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
6048
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
6048
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.2.crl
unknown
whitelisted
6048
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
unknown
whitelisted
GET
200
172.202.163.200:443
https://slscr.update.microsoft.com/sls/ping
unknown
POST
200
40.126.31.0:443
https://login.live.com/RST2.srf
unknown
xml
1.24 Kb
whitelisted
GET
304
172.202.163.200:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4208
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
  • 2.16.168.114
  • 2.16.168.124
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.71
  • 40.126.31.1
  • 40.126.31.71
  • 20.190.159.4
  • 40.126.31.73
  • 40.126.31.2
  • 20.190.159.68
whitelisted
2.100.168.192.in-addr.arpa
whitelisted
ic.adobe.io
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
  • 4.175.87.197
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

No threats detected
No debug info