File name:

Adobe AIR Installer.exe

Full analysis: https://app.any.run/tasks/357f9937-d891-471a-940d-63cee5b14fcf
Verdict: Malicious activity
Analysis date: October 04, 2022, 23:02:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows, MZ for MS-DOS
MD5:

DE9C3DD3F3FB4503D7015489ABF90DCE

SHA1:

D38FAAA4D24AB180BE143F890BCACFC1CD6C6F16

SHA256:

5F85EAF8622ADDA6E7196E7E1662362B49C35DC4FDFE08DC42E8AADC3B9DC968

SSDEEP:

98304:y/Wi5KjT/rfzOikWN5uLj/skLfZ3XekT3mI/jl/LUqUHUsKnzZwLT1kyR8Q1s:s1aTrLO8CjVLfZnvljS4sKzQT1hRi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Adobe AIR Installer.exe (PID: 3060)
      • adobe air installer.exe (PID: 3996)
    • Application was dropped or rewritten from another process

      • adobe air installer.exe (PID: 3996)
      • Adobe AIR Installer.exe (PID: 3060)
    • Drops executable file immediately after starts

      • Adobe AIR Installer.exe (PID: 2240)
      • msiexec.exe (PID: 1164)
      • Adobe AIR Installer.exe (PID: 3060)
    • Changes settings of System certificates

      • msiexec.exe (PID: 1164)
  • SUSPICIOUS

    • Checks supported languages

      • Adobe AIR Installer.exe (PID: 2240)
      • Adobe AIR Installer.exe (PID: 3060)
      • adobe air installer.exe (PID: 3996)
      • msiexec.exe (PID: 1164)
    • Reads the computer name

      • Adobe AIR Installer.exe (PID: 2240)
      • Adobe AIR Installer.exe (PID: 3060)
      • adobe air installer.exe (PID: 3996)
      • msiexec.exe (PID: 1164)
    • Executable content was dropped or overwritten

      • Adobe AIR Installer.exe (PID: 2240)
      • msiexec.exe (PID: 1164)
      • Adobe AIR Installer.exe (PID: 3060)
    • Drops a file with a compile date too recent

      • Adobe AIR Installer.exe (PID: 2240)
      • msiexec.exe (PID: 1164)
      • Adobe AIR Installer.exe (PID: 3060)
    • Application launched itself

      • Adobe AIR Installer.exe (PID: 3060)
    • Creates files in the user directory

      • Adobe AIR Installer.exe (PID: 3060)
    • Reads CPU info

      • Adobe AIR Installer.exe (PID: 3060)
      • adobe air installer.exe (PID: 3996)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 1164)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 1164)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 1164)
    • Changes default file association

      • msiexec.exe (PID: 1164)
    • Adds / modifies Windows certificates

      • msiexec.exe (PID: 1164)
  • INFO

    • Checks Windows Trust Settings

      • msiexec.exe (PID: 1164)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 1164)
    • Creates files in the program directory

      • msiexec.exe (PID: 1164)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2008-Jan-07 16:19:09
Comments: -
FileVersion: 2.0.0.20
ProductVersion: 2.0.0.20
CompanyName: -
LegalCopyright: -
ProductName: NOSSO(R)

DOS Header

e_magic: MZ
e_cblp: 60
e_cp: 1
e_crlc: -
e_cparhdr: 2
e_minalloc: -
e_maxalloc: 65535
e_ss: -
e_sp: 152
e_csum: -
e_ip: -
e_cs: -
e_ovno: -
e_oemid: 46080
e_oeminfo: 52489
e_lfanew: 64

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 3
TimeDateStamp: 2008-Jan-07 16:19:09
PointerToSymbolTable: -
NumberOfSymbols: 323440
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.nos
4096
241664
0
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.text
245760
82298
82432
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.96105
.rsrc
331776
24584
24584
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.15475

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.85494
3752
UNKNOWN
UNKNOWN
RT_ICON
2
4.81516
2216
UNKNOWN
UNKNOWN
RT_ICON
3
3.42962
1384
UNKNOWN
UNKNOWN
RT_ICON
4
4.57131
9640
UNKNOWN
UNKNOWN
RT_ICON
5
4.95168
4264
UNKNOWN
UNKNOWN
RT_ICON
6
5.07596
1128
UNKNOWN
UNKNOWN
RT_ICON
101
2.69913
90
UNKNOWN
UNKNOWN
RT_GROUP_ICON
1 (#2)
2.65359
876
UNKNOWN
UNKNOWN
RT_VERSION
1 (#3)
5.06714
676
UNKNOWN
UNKNOWN
RT_MANIFEST

Imports

kernel32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
5
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start adobe air installer.exe adobe air installer.exe adobe air installer.exe no specs msiexec.exe adobe air installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1164C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2240"C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe" C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe
Explorer.EXE
User:
admin
Company:
Integrity Level:
HIGH
Exit code:
0
Version:
2.0.0.20
Modules
Images
c:\users\admin\appdata\local\temp\adobe air installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3060"C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR Installer.exe" C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR Installer.exe
Adobe AIR Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225547
Modules
Images
c:\users\admin\appdata\local\nos\adobe air installer\adobe air installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3492"C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe" C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exeExplorer.EXE
User:
admin
Company:
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
2.0.0.20
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\adobe air installer.exe
3996"C:\Users\admin\appdata\local\nos\adobe air installer\adobe air installer.exe" -stdio \\.\pipe\AIR_3060_0 -silentC:\Users\admin\appdata\local\nos\adobe air installer\adobe air installer.exeAdobe AIR Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225547
Modules
Images
c:\users\admin\appdata\local\nos\adobe air installer\adobe air installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msi.dll
Total events
7 345
Read events
7 191
Write events
142
Delete events
12

Modification events

(PID) Process:(2240) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2240) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2240) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2240) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3060) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3060) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3060) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3060) Adobe AIR Installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1164) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1164) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2
Operation:writeName:Blob
Value:
04000000010000001000000010FC635DF6263E0DF325BE5F79CD676709000000010000002A000000302806082B0601050507030206082B0601050507030306082B0601050507030406082B060105050703010F0000000100000010000000D7C63BE0837DBABF881D4FBF5F986AD8030000000100000014000000742C3192E607E424EB4549542BE1BBC53E6174E27E0000000100000008000000000010C51E92D2017A000000010000000E000000300C060A2B0601040182375E01021D000000010000001000000027B3517667331CE2C1E74002B5FF2298140000000100000014000000E27F7BD877D5DF9E0A3F9EB4CB0E2EA9EFDB6977620000000100000020000000E7685634EFACF69ACE939A6B255B7B4FABEF42935B50A265ACB5CB6027E44E7053000000010000002400000030223020060A2B0601040182375E010130123010060A2B0601040182373C0101030200C00B000000010000004600000056006500720069005300690067006E00200043006C006100730073002000330020005000750062006C006900630020005000720069006D00610072007900200043004100000019000000010000001000000091161B894B117ECDC257628DB460CC0468000000010000000800000000003DB65BD9D5012000000001000000400200003082023C308201A5021070BAE41D10D92934B638CA7B03CCBABF300D06092A864886F70D0101020500305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479301E170D3936303132393030303030305A170D3238303830313233353935395A305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F7269747930819F300D06092A864886F70D010101050003818D0030818902818100C95C599EF21B8A0114B410DF0440DBE357AF6A45408F840C0BD133D9D911CFEE02581F25F72AA84405AAEC031F787F9E93B99A00AA237DD6AC85A26345C77227CCF44CC67571D239EF4F42F075DF0A90C68E206F980FF8AC235F702936A4C986E7B19A20CB53A585E73DBE7D9AFE244533DC7615ED0FA271644C652E816845A70203010001300D06092A864886F70D010102050003818100BB4C122BCF2C26004F1413DDA6FBFC0A11848CF3281C67922F7CB6C5FADFF0E895BC1D8F6C2CA851CC73D8A4C053F04ED626C076015781925E21F1D1B1FFE7D02158CD6917E3441C9C194439895CDC9C000F568D0299EDA290454CE4BB10A43DF032030EF1CEF8E8C9518CE6629FE69FC07DB7729CC9363A6B9F4EA8FF640D64
Executable files
21
Suspicious files
5
Text files
2
Unknown types
27

Dropped files

PID
Process
Filename
Type
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Thawte Root Certificate.cerder
MD5:7F667A71D3EB6978209A51149D83DA20
SHA256:6B6C1E01F590F5AFC5FCF85CD0B9396884048659FC2C6D1170D68B045216C3FD
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe Root Certificate.cerder
MD5:BF70913FF8D6D60A47FE825330815DB4
SHA256:944E66AA967BD390952D22426BF1DFCD379A2C87A21B942FBCA79F41F0354AAC
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\template.msiexecutable
MD5:D4A1A427AE17047055186395CA873089
SHA256:A7438FBE8C8996D966CAFF507C77114A861833B4C1BC1248A71271762005A2C8
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\setup.msiexecutable
MD5:89681670507C9C1506037522B6DC1E45
SHA256:0D990492081936B6C45BDC67B510157BBE2AF27AC2DFAC02E436EE4BA079AC8F
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\digest.scat
MD5:C400A73A2B181103530B9DEF6715099D
SHA256:930818F85EADBF1855ADF534DEBAFC72AA8F5C32BCDA85BD09A20AC93F1079D5
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\sentineltext
MD5:A5C11CA014FE30B8085EA2E95F7196C4
SHA256:096E4BFD9F7E1FAF15058C0A0FE45E6DBD00E3E1360F21F2CA92BCE16A9A919A
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe AIR Updater.exeexecutable
MD5:D598A0818EC112074E4ECADB7FD83414
SHA256:D8FDDA58DB1A84FF2868D0D24BDA9D9B496347A35008225F15C6599AA2F1C4BF
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe AIR.dllexecutable
MD5:479DFEB6BFDB8035DD2BF79CABB39E65
SHA256:814728159D8E316EB6BC09FB1DAFEF911B708D1D1F51E8E866FEE8E7965CE05E
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\airappinstaller.exeexecutable
MD5:9C5B124EFD76128D26D3BCF85A3F2092
SHA256:5FA546E912A3FEDEA19477BA68BB127CD2867170A2BDB831B78549C6190D55B9
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\WebKit.dllexecutable
MD5:7DDE37CD1B91865A2A202DE66E2B6FDA
SHA256:6C43E63A3E93144F5D3442B62E87545E43ADE86AA0C855A4ADDA89629D0B2646
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.2:53
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
whitelisted

Threats

No threats detected
No debug info