analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Adobe AIR Installer.exe

Full analysis: https://app.any.run/tasks/357f9937-d891-471a-940d-63cee5b14fcf
Verdict: Malicious activity
Analysis date: October 04, 2022, 23:02:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows, MZ for MS-DOS
MD5:

DE9C3DD3F3FB4503D7015489ABF90DCE

SHA1:

D38FAAA4D24AB180BE143F890BCACFC1CD6C6F16

SHA256:

5F85EAF8622ADDA6E7196E7E1662362B49C35DC4FDFE08DC42E8AADC3B9DC968

SSDEEP:

98304:y/Wi5KjT/rfzOikWN5uLj/skLfZ3XekT3mI/jl/LUqUHUsKnzZwLT1kyR8Q1s:s1aTrLO8CjVLfZnvljS4sKzQT1hRi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Adobe AIR Installer.exe (PID: 2240)
      • msiexec.exe (PID: 1164)
      • Adobe AIR Installer.exe (PID: 3060)
    • Loads dropped or rewritten executable

      • Adobe AIR Installer.exe (PID: 3060)
      • adobe air installer.exe (PID: 3996)
    • Application was dropped or rewritten from another process

      • Adobe AIR Installer.exe (PID: 3060)
      • adobe air installer.exe (PID: 3996)
    • Changes settings of System certificates

      • msiexec.exe (PID: 1164)
  • SUSPICIOUS

    • Reads the computer name

      • Adobe AIR Installer.exe (PID: 2240)
      • Adobe AIR Installer.exe (PID: 3060)
      • adobe air installer.exe (PID: 3996)
      • msiexec.exe (PID: 1164)
    • Checks supported languages

      • Adobe AIR Installer.exe (PID: 2240)
      • Adobe AIR Installer.exe (PID: 3060)
      • adobe air installer.exe (PID: 3996)
      • msiexec.exe (PID: 1164)
    • Drops a file with a compile date too recent

      • Adobe AIR Installer.exe (PID: 2240)
      • msiexec.exe (PID: 1164)
      • Adobe AIR Installer.exe (PID: 3060)
    • Executable content was dropped or overwritten

      • Adobe AIR Installer.exe (PID: 2240)
      • msiexec.exe (PID: 1164)
      • Adobe AIR Installer.exe (PID: 3060)
    • Reads CPU info

      • Adobe AIR Installer.exe (PID: 3060)
      • adobe air installer.exe (PID: 3996)
    • Creates files in the user directory

      • Adobe AIR Installer.exe (PID: 3060)
    • Application launched itself

      • Adobe AIR Installer.exe (PID: 3060)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 1164)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 1164)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 1164)
    • Adds / modifies Windows certificates

      • msiexec.exe (PID: 1164)
    • Changes default file association

      • msiexec.exe (PID: 1164)
  • INFO

    • Reads settings of System Certificates

      • msiexec.exe (PID: 1164)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 1164)
    • Creates files in the program directory

      • msiexec.exe (PID: 1164)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2008-Jan-07 16:19:09
Comments: -
FileVersion: 2.0.0.20
ProductVersion: 2.0.0.20
CompanyName: -
LegalCopyright: -
ProductName: NOSSO(R)

DOS Header

e_magic: MZ
e_cblp: 60
e_cp: 1
e_crlc: -
e_cparhdr: 2
e_minalloc: -
e_maxalloc: 65535
e_ss: -
e_sp: 152
e_csum: -
e_ip: -
e_cs: -
e_ovno: -
e_oemid: 46080
e_oeminfo: 52489
e_lfanew: 64

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 3
TimeDateStamp: 2008-Jan-07 16:19:09
PointerToSymbolTable: -
NumberOfSymbols: 323440
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.nos
4096
241664
0
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.text
245760
82298
82432
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.96105
.rsrc
331776
24584
24584
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.15475

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.85494
3752
UNKNOWN
UNKNOWN
RT_ICON
2
4.81516
2216
UNKNOWN
UNKNOWN
RT_ICON
3
3.42962
1384
UNKNOWN
UNKNOWN
RT_ICON
4
4.57131
9640
UNKNOWN
UNKNOWN
RT_ICON
5
4.95168
4264
UNKNOWN
UNKNOWN
RT_ICON
6
5.07596
1128
UNKNOWN
UNKNOWN
RT_ICON
101
2.69913
90
UNKNOWN
UNKNOWN
RT_GROUP_ICON
1 (#2)
2.65359
876
UNKNOWN
UNKNOWN
RT_VERSION
1 (#3)
5.06714
676
UNKNOWN
UNKNOWN
RT_MANIFEST

Imports

kernel32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
5
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start adobe air installer.exe no specs adobe air installer.exe adobe air installer.exe adobe air installer.exe no specs msiexec.exe

Process information

PID
CMD
Path
Indicators
Parent process
3492"C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe" C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exeExplorer.EXE
User:
admin
Company:
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
2.0.0.20
2240"C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe" C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe
Explorer.EXE
User:
admin
Company:
Integrity Level:
HIGH
Exit code:
0
Version:
2.0.0.20
3060"C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR Installer.exe" C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR Installer.exe
Adobe AIR Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225547
3996"C:\Users\admin\appdata\local\nos\adobe air installer\adobe air installer.exe" -stdio \\.\pipe\AIR_3060_0 -silentC:\Users\admin\appdata\local\nos\adobe air installer\adobe air installer.exeAdobe AIR Installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225547
1164C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Total events
7 345
Read events
7 191
Write events
0
Delete events
0

Modification events

No data
Executable files
21
Suspicious files
5
Text files
2
Unknown types
27

Dropped files

PID
Process
Filename
Type
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\setup.swfswf
MD5:5A933EAA6F248C06A2FF42410720E243
SHA256:B1DEA74CFA75B57B37F14E678B86A7BE35F42A8A2A9C808AC4E6CE6E78B31188
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\setup.msiexecutable
MD5:89681670507C9C1506037522B6DC1E45
SHA256:0D990492081936B6C45BDC67B510157BBE2AF27AC2DFAC02E436EE4BA079AC8F
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\digest.scat
MD5:C400A73A2B181103530B9DEF6715099D
SHA256:930818F85EADBF1855ADF534DEBAFC72AA8F5C32BCDA85BD09A20AC93F1079D5
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\setup.swfswf
MD5:5A933EAA6F248C06A2FF42410720E243
SHA256:B1DEA74CFA75B57B37F14E678B86A7BE35F42A8A2A9C808AC4E6CE6E78B31188
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe AIR.dllexecutable
MD5:479DFEB6BFDB8035DD2BF79CABB39E65
SHA256:814728159D8E316EB6BC09FB1DAFEF911B708D1D1F51E8E866FEE8E7965CE05E
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\template.exeexecutable
MD5:F3EA2F1D80738777C226C7D0C4212662
SHA256:0350407FD5C8DF439EAA1450F66428933ADA5F4AAE01743F219D43FDDC668A8B
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe Root Certificate.cerder
MD5:BF70913FF8D6D60A47FE825330815DB4
SHA256:944E66AA967BD390952D22426BF1DFCD379A2C87A21B942FBCA79F41F0354AAC
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\sentineltext
MD5:A5C11CA014FE30B8085EA2E95F7196C4
SHA256:096E4BFD9F7E1FAF15058C0A0FE45E6DBD00E3E1360F21F2CA92BCE16A9A919A
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.swfswf
MD5:8599589CB2F1CFAD899F0E95C3CF2BC9
SHA256:101140C8DF33CD81AF64000549872EF9E48AF5913A27367E0865A4F83BECC509
2240Adobe AIR Installer.exeC:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\template.msiexecutable
MD5:D4A1A427AE17047055186395CA873089
SHA256:A7438FBE8C8996D966CAFF507C77114A861833B4C1BC1248A71271762005A2C8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.2:53
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
whitelisted

Threats

No threats detected
No debug info