File name:

Adobe 2020.zip

Full analysis: https://app.any.run/tasks/55dfdece-d899-43b7-94b0-e7ec1cd5dd0e
Verdict: Malicious activity
Analysis date: March 04, 2020, 00:48:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

707C53F62319DEC08D29FD030D5735B1

SHA1:

5E8C2EDB40528FD050853EE49635CD4C4AFB6212

SHA256:

558AA08EB8DBEA715B111A710793FDC68134C1BE72116AB4D4A88E58B37307AD

SSDEEP:

393216:NObNrmsaXa1vM9t4Y0zWqISeKZ/TsTGXKt+w73:NOxTwa1HLFjfPX/E3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ASP_v2_0_P.exe (PID: 2336)
      • ASP_v2_0_P.exe (PID: 4076)
      • ASP_v2_0_P.exe (PID: 2120)
      • Adobe_2020_Home_Screen_FIX_v2.5.exe (PID: 1232)
      • ASP_v2_0_P.exe (PID: 1556)
      • ASP_v2_0_P.exe (PID: 3988)
      • ASP_v2_0_P.exe (PID: 3172)
      • ASP_v2_0_P.exe (PID: 2972)
      • Adobe_2020_Home_Screen_FIX_v2.5.exe (PID: 2012)
      • ASP_v2_0_P.exe (PID: 664)
    • Loads dropped or rewritten executable

      • ASP_v2_0_P.exe (PID: 664)
      • ASP_v2_0_P.exe (PID: 2120)
      • ASP_v2_0_P.exe (PID: 3988)
      • ASP_v2_0_P.exe (PID: 2972)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1928)
      • ASP_v2_0_P.exe (PID: 664)
      • WinRAR.exe (PID: 3680)
    • Creates files in the program directory

      • Adobe_2020_Home_Screen_FIX_v2.5.exe (PID: 2012)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 2944)
      • ASP_v2_0_P.exe (PID: 664)
      • ASP_v2_0_P.exe (PID: 4076)
      • ASP_v2_0_P.exe (PID: 2120)
      • Adobe_2020_Home_Screen_FIX_v2.5.exe (PID: 1232)
      • WinRAR.exe (PID: 3680)
      • ASP_v2_0_P.exe (PID: 3988)
      • ASP_v2_0_P.exe (PID: 1556)
      • ASP_v2_0_P.exe (PID: 3172)
      • ASP_v2_0_P.exe (PID: 2972)
      • ASP_v2_0_P.exe (PID: 2336)
      • Adobe_2020_Home_Screen_FIX_v2.5.exe (PID: 2012)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:01:03 02:41:23
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Adobe 2020/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
13
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe winrar.exe no specs winrar.exe adobe_2020_home_screen_fix_v2.5.exe no specs adobe_2020_home_screen_fix_v2.5.exe asp_v2_0_p.exe no specs asp_v2_0_p.exe asp_v2_0_p.exe no specs asp_v2_0_p.exe asp_v2_0_p.exe no specs asp_v2_0_p.exe asp_v2_0_p.exe no specs asp_v2_0_p.exe

Process information

PID
CMD
Path
Indicators
Parent process
664"C:\Users\admin\Desktop\Adobe 2020\Adobe 2020\Resources\ASP_v2_0_P.exe" C:\Users\admin\Desktop\Adobe 2020\Adobe 2020\Resources\ASP_v2_0_P.exe
explorer.exe
User:
admin
Company:
PainteR
Integrity Level:
HIGH
Description:
Universal Adobe Patcher
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\adobe 2020\adobe 2020\resources\asp_v2_0_p.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
1232"C:\Users\admin\Desktop\Adobe 2020\Adobe 2020\Adobe_2020_Home_Screen_FIX_v2.5.exe" C:\Users\admin\Desktop\Adobe 2020\Adobe 2020\Adobe_2020_Home_Screen_FIX_v2.5.exeexplorer.exe
User:
admin
Company:
Oleg N. Scherbakov
Integrity Level:
MEDIUM
Description:
7z Setup SFX (x86)
Exit code:
3221226540
Version:
1.4.1.2100
Modules
Images
c:\users\admin\desktop\adobe 2020\adobe 2020\adobe_2020_home_screen_fix_v2.5.exe
c:\systemroot\system32\ntdll.dll
1556"C:\Users\admin\Desktop\Adobe 2020\Resources\ASP_v2_0_P.exe" C:\Users\admin\Desktop\Adobe 2020\Resources\ASP_v2_0_P.exeexplorer.exe
User:
admin
Company:
PainteR
Integrity Level:
MEDIUM
Description:
Universal Adobe Patcher
Exit code:
3221226540
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\adobe 2020\resources\asp_v2_0_p.exe
c:\systemroot\system32\ntdll.dll
1928"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Adobe 2020.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2012"C:\Users\admin\Desktop\Adobe 2020\Adobe 2020\Adobe_2020_Home_Screen_FIX_v2.5.exe" C:\Users\admin\Desktop\Adobe 2020\Adobe 2020\Adobe_2020_Home_Screen_FIX_v2.5.exe
explorer.exe
User:
admin
Company:
Oleg N. Scherbakov
Integrity Level:
HIGH
Description:
7z Setup SFX (x86)
Exit code:
0
Version:
1.4.1.2100
Modules
Images
c:\users\admin\desktop\adobe 2020\adobe 2020\adobe_2020_home_screen_fix_v2.5.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2120"C:\Users\admin\Desktop\Adobe 2020\Adobe 2020\Resources\ASP_v2_0_P.exe" C:\Users\admin\Desktop\Adobe 2020\Adobe 2020\Resources\ASP_v2_0_P.exe
explorer.exe
User:
admin
Company:
PainteR
Integrity Level:
HIGH
Description:
Universal Adobe Patcher
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\adobe 2020\adobe 2020\resources\asp_v2_0_p.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2336"C:\Users\admin\Desktop\Adobe 2020\Adobe 2020\Resources\ASP_v2_0_P.exe" C:\Users\admin\Desktop\Adobe 2020\Adobe 2020\Resources\ASP_v2_0_P.exeexplorer.exe
User:
admin
Company:
PainteR
Integrity Level:
MEDIUM
Description:
Universal Adobe Patcher
Exit code:
3221226540
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\adobe 2020\adobe 2020\resources\asp_v2_0_p.exe
c:\systemroot\system32\ntdll.dll
2944"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Adobe 2020\Adobe 2020.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2972"C:\Users\admin\Desktop\Adobe 2020\Resources\ASP_v2_0_P.exe" C:\Users\admin\Desktop\Adobe 2020\Resources\ASP_v2_0_P.exe
explorer.exe
User:
admin
Company:
PainteR
Integrity Level:
HIGH
Description:
Universal Adobe Patcher
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\adobe 2020\resources\asp_v2_0_p.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3172"C:\Users\admin\Desktop\Adobe 2020\Resources\ASP_v2_0_P.exe" C:\Users\admin\Desktop\Adobe 2020\Resources\ASP_v2_0_P.exeexplorer.exe
User:
admin
Company:
PainteR
Integrity Level:
MEDIUM
Description:
Universal Adobe Patcher
Exit code:
3221226540
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\adobe 2020\resources\asp_v2_0_p.exe
c:\systemroot\system32\ntdll.dll
Total events
1 488
Read events
1 421
Write events
66
Delete events
1

Modification events

(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1928) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Adobe 2020.zip
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
Executable files
11
Suspicious files
3
Text files
975
Unknown types
31

Dropped files

PID
Process
Filename
Type
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1928.42761\Adobe 2020\Resources\GenPPP.exe
MD5:
SHA256:
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1928.42761\Adobe 2020\Resources\ICONS\Ac.ico
MD5:
SHA256:
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1928.42761\Adobe 2020\Resources\ICONS\ACC.ico
MD5:
SHA256:
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1928.42761\Adobe 2020\Resources\ICONS\ae.ico
MD5:
SHA256:
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1928.42761\Adobe 2020\Resources\ICONS\Ai.ico
MD5:
SHA256:
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1928.42761\Adobe 2020\Resources\ICONS\an.ico
MD5:
SHA256:
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1928.42761\Adobe 2020\Resources\ICONS\Au.ico
MD5:
SHA256:
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1928.42761\Adobe 2020\Resources\ICONS\Br.ico
MD5:
SHA256:
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1928.42761\Adobe 2020\Resources\ICONS\Ch.ico
MD5:
SHA256:
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1928.42761\Adobe 2020\Resources\ICONS\Cure.bmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info