File name: | 6812d2c704a12a02c87a5b7152ebc3294d71f31262460115a23a4d8b5e4cb5b3.exe |
Full analysis: | https://app.any.run/tasks/ca3e3a71-6416-47cb-b19d-22a6d3ef00af |
Verdict: | Malicious activity |
Threats: | Netwire is an advanced RAT — it is a malware that takes control of infected PCs and allows its operators to perform various actions. Unlike many RATs, this one can target every major operating system, including Windows, Linux, and MacOS. |
Analysis date: | January 22, 2024, 09:45:48 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
MD5: | DF44DF4CD65C0B0909EE7DCFBB8DC4AD |
SHA1: | 8D8C88430D7A43ABB1B3772DE1E5BA7093E46697 |
SHA256: | 6812D2C704A12A02C87A5B7152EBC3294D71F31262460115A23A4D8B5E4CB5B3 |
SSDEEP: | 98304:8Iw2pqdgvKXysVNTXrSpBTwJhIoiMWpXbe5bi0VgEkE6pmT2WEhSGQGSkng5Kx8n:VYgJtR+HXjiVG |
.exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (14.2) |
.exe | | | Win32 Executable (generic) (9.7) |
.exe | | | Generic Win/DOS Executable (4.3) |
.exe | | | DOS Executable Generic (4.3) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2023:07:02 04:09:48+02:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 27136 |
InitializedDataSize: | 184832 |
UninitializedDataSize: | 2048 |
EntryPoint: | 0x3532 |
OSVersion: | 4 |
ImageVersion: | 6 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2360 | "C:\Users\admin\AppData\Local\Temp\6812d2c704a12a02c87a5b7152ebc3294d71f31262460115a23a4d8b5e4cb5b3.exe" | C:\Users\admin\AppData\Local\Temp\6812d2c704a12a02c87a5b7152ebc3294d71f31262460115a23a4d8b5e4cb5b3.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
976 | "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\AppData\Local\Temp\poryadok-deystviy-i-opoveshcheniya-grazhdanskoy-oborony.pdf" | C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | 6812d2c704a12a02c87a5b7152ebc3294d71f31262460115a23a4d8b5e4cb5b3.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe Acrobat Reader DC Version: 15.7.20033.133275 Modules
| |||||||||||||||
916 | "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --channel=976.0.399732949 --type=renderer "C:\Users\admin\AppData\Local\Temp\poryadok-deystviy-i-opoveshcheniya-grazhdanskoy-oborony.pdf" | C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | — | AcroRd32.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe Acrobat Reader DC Version: 15.7.20033.133275 Modules
| |||||||||||||||
2124 | C:\Users\admin\AppData\Roaming\Symlink.exe | C:\Users\admin\AppData\Roaming\Symlink.exe | — | 6812d2c704a12a02c87a5b7152ebc3294d71f31262460115a23a4d8b5e4cb5b3.exe | |||||||||||
User: admin Company: GIGA-BYTE TECHNOLOGY CO., LTD. Integrity Level: MEDIUM Description: OcButtonService Exit code: 4294967276 Version: 8.0.2.2 Modules
| |||||||||||||||
776 | "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" | C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | AcroRd32.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe RdrCEF Version: 15.7.20033.133275 Modules
| |||||||||||||||
828 | "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-delegated-renderer --disable-desktop-notifications --disable-file-system --disable-shared-workers --disable-speech-input --disable-threaded-compositing --disable-webaudio --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.7.20033 Chrome/35.0.1916.138" --disable-accelerated-compositing --disable-accelerated-video-decode --enable-software-compositing --disable-gpu-compositing --channel="776.0.640805668\785442941" --allow-no-sandbox-job /prefetch:673131151 | C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | — | RdrCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe RdrCEF Version: 15.7.20033.133275 Modules
| |||||||||||||||
1424 | "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-delegated-renderer --disable-desktop-notifications --disable-file-system --disable-shared-workers --disable-speech-input --disable-threaded-compositing --disable-webaudio --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.7.20033 Chrome/35.0.1916.138" --disable-accelerated-compositing --disable-accelerated-video-decode --enable-software-compositing --disable-gpu-compositing --channel="776.1.637720957\2023221583" --allow-no-sandbox-job /prefetch:673131151 | C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | — | RdrCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe RdrCEF Version: 15.7.20033.133275 Modules
| |||||||||||||||
1764 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | — | Symlink.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: AddInProcess.exe Exit code: 4294967216 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
2236 | "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" /PRODUCT:Reader /VERSION:15.0 /MODE:3 | C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe | AcroRd32.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe Reader and Acrobat Manager Version: 1.821.13.2315 Modules
| |||||||||||||||
972 | "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Reader_sl.exe" | C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Reader_sl.exe | — | AdobeARM.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe Acrobat SpeedLauncher Exit code: 0 Version: 15.7.20033.133275 Modules
|
(PID) Process: | (916) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection |
Operation: | write | Name: | bLastExitNormal |
Value: 1 | |||
(PID) Process: | (2124) Symlink.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (2124) Symlink.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 46000000C5000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (776) RdrCEF.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\15A\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (976) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (976) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 46000000C6000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (916) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs |
Operation: | write | Name: | bForms_AdhocWorkflowBackup |
Value: 0 | |||
(PID) Process: | (916) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs |
Operation: | write | Name: | bJSCache_GlobSettings |
Value: 1 | |||
(PID) Process: | (916) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs |
Operation: | write | Name: | bJSCache_GlobData |
Value: 1 | |||
(PID) Process: | (976) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
916 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R1932.tmp | — | |
MD5:— | SHA256:— | |||
916 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R1931.tmp | — | |
MD5:— | SHA256:— | |||
916 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R1930.tmp | — | |
MD5:— | SHA256:— | |||
916 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R192F.tmp | — | |
MD5:— | SHA256:— | |||
776 | RdrCEF.exe | C:\Users\admin\AppData\Local\Temp\scoped_dir776_2754\data_1 | binary | |
MD5:259E7ED5FB3C6C90533B963DA5B2FC1B | SHA256:35BB2F189C643DCF52ECF037603D104035ECDC490BF059B7736E58EF7D821A09 | |||
2360 | 6812d2c704a12a02c87a5b7152ebc3294d71f31262460115a23a4d8b5e4cb5b3.exe | C:\Users\admin\AppData\Local\Temp\poryadok-deystviy-i-opoveshcheniya-grazhdanskoy-oborony.pdf | ||
MD5:76E7CBAB1955FAA81BA0DDA824EBB31D | SHA256:E69596BD26E466F11A05ABCDF70D84EEB2CF31D4021B0F13AD991D8ED2444EDF | |||
916 | AcroRd32.exe | C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg | text | |
MD5:2BD4B1E5E05FF88A44DECFE3EC917933 | SHA256:864DDDCAC6BFCE12DF19EF8C75E7856AF5B90F898F04F06BEADC63C5A9960BA4 | |||
776 | RdrCEF.exe | C:\Users\admin\AppData\Local\Temp\scoped_dir776_2754\data_3 | binary | |
MD5:41876349CB12D6DB992F1309F22DF3F0 | SHA256:E09F42C398D688DCE168570291F1F92D079987DEDA3099A34ADB9E8C0522B30C | |||
916 | AcroRd32.exe | C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl | binary | |
MD5:974E8536B8767AC5BE204F35D16F73E8 | SHA256:D1BB4B163FE01ACC368A92B385BB0BD3A9FC2340B6D485B77A20553A713166D3 | |||
2360 | 6812d2c704a12a02c87a5b7152ebc3294d71f31262460115a23a4d8b5e4cb5b3.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Symlink.lnk | binary | |
MD5:68745E57E16A557B5DD44038679CF936 | SHA256:6555931B272E908B2656254A03C79E21B61EE9D760189477ECD66A18CF05B676 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
864 | svchost.exe | HEAD | 200 | 23.48.23.53:80 | http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp | unknown | — | — | — |
976 | AcroRd32.exe | GET | 304 | 23.48.23.34:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/281.zip | unknown | — | — | — |
— | — | GET | 304 | 23.48.23.34:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/278.zip | unknown | — | — | — |
976 | AcroRd32.exe | GET | 304 | 23.48.23.34:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/280.zip | unknown | — | — | — |
976 | AcroRd32.exe | GET | 304 | 23.48.23.34:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/277.zip | unknown | — | — | — |
864 | svchost.exe | GET | 206 | 23.48.23.53:80 | http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp | unknown | — | 5.81 Kb | — |
976 | AcroRd32.exe | GET | 200 | 23.48.23.34:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/message.zip | unknown | compressed | 9.54 Kb | — |
864 | svchost.exe | GET | 206 | 23.48.23.53:80 | http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp | unknown | binary | 7.74 Kb | — |
864 | svchost.exe | GET | 206 | 23.48.23.53:80 | http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp | unknown | binary | 10.0 Kb | — |
864 | svchost.exe | GET | 206 | 23.48.23.53:80 | http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp | unknown | binary | 11.3 Kb | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
352 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1220 | svchost.exe | 239.255.255.250:3702 | — | — | — | unknown |
776 | RdrCEF.exe | 3.233.142.19:443 | cloud.acrobat.com | AMAZON-AES | US | unknown |
976 | AcroRd32.exe | 23.48.23.34:80 | acroipm2.adobe.com | Akamai International B.V. | DE | unknown |
1220 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
864 | svchost.exe | 95.101.148.135:443 | armmf.adobe.com | Akamai International B.V. | NL | unknown |
864 | svchost.exe | 23.48.23.53:80 | ardownload.adobe.com | Akamai International B.V. | DE | unknown |
2652 | AddInProcess32.exe | 185.12.14.32:666 | — | Serverius Holding B.V. | NL | unknown |
2012 | AddInProcess32.exe | 45.142.122.192:16503 | — | AEZA GROUP Ltd | RU | unknown |
Domain | IP | Reputation |
---|---|---|
cloud.acrobat.com |
| unknown |
acroipm2.adobe.com |
| unknown |
armmf.adobe.com |
| unknown |
ardownload.adobe.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | A Network Trojan was detected | ET MALWARE NetWire / Ozone / Darktrack Alien RAT - Client KeepAlive |