| File name: | Adobe AIR Installer.exe |
| Full analysis: | https://app.any.run/tasks/357f9937-d891-471a-940d-63cee5b14fcf |
| Verdict: | Malicious activity |
| Analysis date: | October 04, 2022, 23:02:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows, MZ for MS-DOS |
| MD5: | DE9C3DD3F3FB4503D7015489ABF90DCE |
| SHA1: | D38FAAA4D24AB180BE143F890BCACFC1CD6C6F16 |
| SHA256: | 5F85EAF8622ADDA6E7196E7E1662362B49C35DC4FDFE08DC42E8AADC3B9DC968 |
| SSDEEP: | 98304:y/Wi5KjT/rfzOikWN5uLj/skLfZ3XekT3mI/jl/LUqUHUsKnzZwLT1kyR8Q1s:s1aTrLO8CjVLfZnvljS4sKzQT1hRi |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 2008-Jan-07 16:19:09 |
| Comments: | - |
| FileVersion: | 2.0.0.20 |
| ProductVersion: | 2.0.0.20 |
| CompanyName: | - |
| LegalCopyright: | - |
| ProductName: | NOSSO(R) |
| e_magic: | MZ |
|---|---|
| e_cblp: | 60 |
| e_cp: | 1 |
| e_crlc: | - |
| e_cparhdr: | 2 |
| e_minalloc: | - |
| e_maxalloc: | 65535 |
| e_ss: | - |
| e_sp: | 152 |
| e_csum: | - |
| e_ip: | - |
| e_cs: | - |
| e_ovno: | - |
| e_oemid: | 46080 |
| e_oeminfo: | 52489 |
| e_lfanew: | 64 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| NumberofSections: | 3 |
| TimeDateStamp: | 2008-Jan-07 16:19:09 |
| PointerToSymbolTable: | - |
| NumberOfSymbols: | 323440 |
| SizeOfOptionalHeader: | 224 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.nos | 4096 | 241664 | 0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
.text | 245760 | 82298 | 82432 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.96105 |
.rsrc | 331776 | 24584 | 24584 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.15475 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 4.85494 | 3752 | UNKNOWN | UNKNOWN | RT_ICON |
2 | 4.81516 | 2216 | UNKNOWN | UNKNOWN | RT_ICON |
3 | 3.42962 | 1384 | UNKNOWN | UNKNOWN | RT_ICON |
4 | 4.57131 | 9640 | UNKNOWN | UNKNOWN | RT_ICON |
5 | 4.95168 | 4264 | UNKNOWN | UNKNOWN | RT_ICON |
6 | 5.07596 | 1128 | UNKNOWN | UNKNOWN | RT_ICON |
101 | 2.69913 | 90 | UNKNOWN | UNKNOWN | RT_GROUP_ICON |
1 (#2) | 2.65359 | 876 | UNKNOWN | UNKNOWN | RT_VERSION |
1 (#3) | 5.06714 | 676 | UNKNOWN | UNKNOWN | RT_MANIFEST |
kernel32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1164 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2240 | "C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe" | C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe | Explorer.EXE | ||||||||||||
User: admin Company: Integrity Level: HIGH Exit code: 0 Version: 2.0.0.20 Modules
| |||||||||||||||
| 3060 | "C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR Installer.exe" | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR Installer.exe | Adobe AIR Installer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225547 Modules
| |||||||||||||||
| 3492 | "C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe" | C:\Users\admin\AppData\Local\Temp\Adobe AIR Installer.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Integrity Level: MEDIUM Exit code: 3221226540 Version: 2.0.0.20 Modules
| |||||||||||||||
| 3996 | "C:\Users\admin\appdata\local\nos\adobe air installer\adobe air installer.exe" -stdio \\.\pipe\AIR_3060_0 -silent | C:\Users\admin\appdata\local\nos\adobe air installer\adobe air installer.exe | — | Adobe AIR Installer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225547 Modules
| |||||||||||||||
| (PID) Process: | (2240) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2240) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2240) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2240) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3060) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3060) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3060) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3060) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1164) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1164) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2 |
| Operation: | write | Name: | Blob |
Value: 04000000010000001000000010FC635DF6263E0DF325BE5F79CD676709000000010000002A000000302806082B0601050507030206082B0601050507030306082B0601050507030406082B060105050703010F0000000100000010000000D7C63BE0837DBABF881D4FBF5F986AD8030000000100000014000000742C3192E607E424EB4549542BE1BBC53E6174E27E0000000100000008000000000010C51E92D2017A000000010000000E000000300C060A2B0601040182375E01021D000000010000001000000027B3517667331CE2C1E74002B5FF2298140000000100000014000000E27F7BD877D5DF9E0A3F9EB4CB0E2EA9EFDB6977620000000100000020000000E7685634EFACF69ACE939A6B255B7B4FABEF42935B50A265ACB5CB6027E44E7053000000010000002400000030223020060A2B0601040182375E010130123010060A2B0601040182373C0101030200C00B000000010000004600000056006500720069005300690067006E00200043006C006100730073002000330020005000750062006C006900630020005000720069006D00610072007900200043004100000019000000010000001000000091161B894B117ECDC257628DB460CC0468000000010000000800000000003DB65BD9D5012000000001000000400200003082023C308201A5021070BAE41D10D92934B638CA7B03CCBABF300D06092A864886F70D0101020500305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479301E170D3936303132393030303030305A170D3238303830313233353935395A305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F7269747930819F300D06092A864886F70D010101050003818D0030818902818100C95C599EF21B8A0114B410DF0440DBE357AF6A45408F840C0BD133D9D911CFEE02581F25F72AA84405AAEC031F787F9E93B99A00AA237DD6AC85A26345C77227CCF44CC67571D239EF4F42F075DF0A90C68E206F980FF8AC235F702936A4C986E7B19A20CB53A585E73DBE7D9AFE244533DC7615ED0FA271644C652E816845A70203010001300D06092A864886F70D010102050003818100BB4C122BCF2C26004F1413DDA6FBFC0A11848CF3281C67922F7CB6C5FADFF0E895BC1D8F6C2CA851CC73D8A4C053F04ED626C076015781925E21F1D1B1FFE7D02158CD6917E3441C9C194439895CDC9C000F568D0299EDA290454CE4BB10A43DF032030EF1CEF8E8C9518CE6629FE69FC07DB7729CC9363A6B9F4EA8FF640D64 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2240 | Adobe AIR Installer.exe | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Thawte Root Certificate.cer | der | |
MD5:7F667A71D3EB6978209A51149D83DA20 | SHA256:6B6C1E01F590F5AFC5FCF85CD0B9396884048659FC2C6D1170D68B045216C3FD | |||
| 2240 | Adobe AIR Installer.exe | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe Root Certificate.cer | der | |
MD5:BF70913FF8D6D60A47FE825330815DB4 | SHA256:944E66AA967BD390952D22426BF1DFCD379A2C87A21B942FBCA79F41F0354AAC | |||
| 2240 | Adobe AIR Installer.exe | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\template.msi | executable | |
MD5:D4A1A427AE17047055186395CA873089 | SHA256:A7438FBE8C8996D966CAFF507C77114A861833B4C1BC1248A71271762005A2C8 | |||
| 2240 | Adobe AIR Installer.exe | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\setup.msi | executable | |
MD5:89681670507C9C1506037522B6DC1E45 | SHA256:0D990492081936B6C45BDC67B510157BBE2AF27AC2DFAC02E436EE4BA079AC8F | |||
| 2240 | Adobe AIR Installer.exe | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\digest.s | cat | |
MD5:C400A73A2B181103530B9DEF6715099D | SHA256:930818F85EADBF1855ADF534DEBAFC72AA8F5C32BCDA85BD09A20AC93F1079D5 | |||
| 2240 | Adobe AIR Installer.exe | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\sentinel | text | |
MD5:A5C11CA014FE30B8085EA2E95F7196C4 | SHA256:096E4BFD9F7E1FAF15058C0A0FE45E6DBD00E3E1360F21F2CA92BCE16A9A919A | |||
| 2240 | Adobe AIR Installer.exe | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe | executable | |
MD5:D598A0818EC112074E4ECADB7FD83414 | SHA256:D8FDDA58DB1A84FF2868D0D24BDA9D9B496347A35008225F15C6599AA2F1C4BF | |||
| 2240 | Adobe AIR Installer.exe | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\Adobe AIR.dll | executable | |
MD5:479DFEB6BFDB8035DD2BF79CABB39E65 | SHA256:814728159D8E316EB6BC09FB1DAFEF911B708D1D1F51E8E866FEE8E7965CE05E | |||
| 2240 | Adobe AIR Installer.exe | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\airappinstaller.exe | executable | |
MD5:9C5B124EFD76128D26D3BCF85A3F2092 | SHA256:5FA546E912A3FEDEA19477BA68BB127CD2867170A2BDB831B78549C6190D55B9 | |||
| 2240 | Adobe AIR Installer.exe | C:\Users\admin\AppData\Local\nos\Adobe AIR Installer\Adobe AIR\Versions\1.0\WebKit.dll | executable | |
MD5:7DDE37CD1B91865A2A202DE66E2B6FDA | SHA256:6C43E63A3E93144F5D3442B62E87545E43ADE86AA0C855A4ADDA89629D0B2646 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.2:53 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.microsoft.com |
| whitelisted |