File name: | 15 Second ADB Installer v1.5.6.exe |
Full analysis: | https://app.any.run/tasks/114dae9d-3fca-48cd-b7f0-466a85b9ffea |
Verdict: | Malicious activity |
Analysis date: | November 28, 2023, 10:58:04 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
MD5: | A4705082D17A2081A47F47A3D28711C7 |
SHA1: | 037A52083E8634748224D224E6B068970EC7B6A4 |
SHA256: | 6AEDB17D951F24FA20496EC01639AD54AA9B82968102CF5EBF2DB1426500A2E4 |
SSDEEP: | 196608:GOQ7CgNq3j1nlwp8J3BoYzFeGjF/nwqLLkzJ1S1nRp+9H51j3qZLqNjHNpVAZCRm:cCc0j3KsFB5wqUzOf8ZNqxSJAZW2LcU |
.exe | | | Generic Win/DOS Executable (50) |
---|---|---|
.exe | | | DOS Executable Generic (49.9) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2012:12:31 01:38:38+01:00 |
ImageFileCharacteristics: | No relocs, Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 8 |
CodeSize: | 57344 |
InitializedDataSize: | 307200 |
UninitializedDataSize: | 389120 |
EntryPoint: | 0x6cad0 |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.4.3.0 |
ProductVersionNumber: | 1.4.3.0 |
FileFlagsMask: | 0x003f |
FileFlags: | Private build |
FileOS: | Windows NT 32-bit |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
CompanyName: | Snoop05 |
FileDescription: | 15 seconds ADB Installer |
FileVersion: | 1.4.3 |
InternalName: | adb-installer |
LegalCopyright: | - |
OriginalFileName: | adb-installer-1.4.3.exe |
PrivateBuild: | December 30, 2012 |
ProductName: | 15 seconds ADB Installer |
ProductVersion: | 1.4.3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1900 | "C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe" -sfxelevation | C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe | 15 Second ADB Installer v1.5.6.exe | ||||||||||||
User: admin Company: Snoop05 Integrity Level: HIGH Description: 15 seconds ADB Installer Exit code: 0 Version: 1.4.3 Modules
| |||||||||||||||
2496 | "C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe" | C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe | — | explorer.exe | |||||||||||
User: admin Company: Snoop05 Integrity Level: MEDIUM Description: 15 seconds ADB Installer Exit code: 0 Version: 1.4.3 Modules
| |||||||||||||||
2820 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\install.bat" " | C:\Windows\System32\cmd.exe | — | 15 Second ADB Installer v1.5.6.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3056 | "C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe" -sfxwaitall:0 "install.bat" | C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe | — | 15 Second ADB Installer v1.5.6.exe | |||||||||||
User: admin Company: Snoop05 Integrity Level: HIGH Description: 15 seconds ADB Installer Exit code: 0 Version: 1.4.3 Modules
| |||||||||||||||
3136 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (2496) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2496) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2496) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2496) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (3056) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (3056) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (3056) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (3056) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (3136) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{19A995EC-DD24-4100-BA5B-D925A56657A9}\{EBAD9665-5843-44A2-944B-1E14A043EC21} |
Operation: | delete key | Name: | (default) |
Value: | |||
(PID) Process: | (3136) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{D558F9A1-FC60-4DE0-9C0C-5F2928D62120}\{EBAD9665-5843-44A2-944B-1E14A043EC21} |
Operation: | delete key | Name: | (default) |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\NOTICE.txt | text | |
MD5:EA7F2158B930BAF2C0FE799566489716 | SHA256:A19B767B9DDDA7306C78232E4A223D0BA966471B74DCE3C0C995307CAB5BF7B7 | |||
1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\i386\NOTICE.txt | text | |
MD5:EA7F2158B930BAF2C0FE799566489716 | SHA256:A19B767B9DDDA7306C78232E4A223D0BA966471B74DCE3C0C995307CAB5BF7B7 | |||
1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\adb\mke2fs.conf | text | |
MD5:699098CA95F87BA48BB94A3E848549B3 | SHA256:AD58A58DCDD24D85055814CA9CAC67DB89D4E67C434E96774BDCE0D0A007D067 | |||
1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\androidwinusb86.cat | binary | |
MD5:76CFE751E17119F352C29F9FCE83D24F | SHA256:15A39B14E5FA4EC4BBE16632DBB19C7E0159649702BF98F9F77B2ABD7EBCC4DE | |||
1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\androidwinusba64.cat | binary | |
MD5:B83F9FA084F11007C7E6C668E6FA9E54 | SHA256:8F3F15BAEAF50AE7388562BE0303F5AC7EE3CB255448A24E3D33E1F094E0680E | |||
1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\adb\source.properties | text | |
MD5:6926A4FADAD84D753C1731CFF5FF29B1 | SHA256:0BBDFC51086C50BDCCF263E5D103FF3ACD6560B04DCB6D03CBFFBA10059A06C1 | |||
1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\adb\NOTICE.txt | text | |
MD5:44968B93DCB7403A731E89ED14CAA252 | SHA256:9652A7629CC5115B890759F7AA15A614F39CE7B4B76A5A299768351F2CBD0998 | |||
1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\WUDFUpdate_01009.dll | executable | |
MD5:EBF9EE8A7671F3B260ED9B08FCEE0CC5 | SHA256:015F26BBCD619A0B67B5EAA985B69582BAC27D5CBCA99CE747A76532FCDE4AFF | |||
1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\winusbcoinstaller2.dll | executable | |
MD5:246900CE6474718730ECD4F873234CF5 | SHA256:981A17EFFDDBC20377512DDAEC9F22C2B7067E17A3E2A8CCF82BB7BB7B2420B6 | |||
1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\WdfCoInstaller01009.dll | executable | |
MD5:4DA5DA193E0E4F86F6F8FD43EF25329A | SHA256:18487B4FF94EDCCC98ED59D9FCA662D4A1331C5F1E14DF8DB3093256DD9F1C3E |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
868 | svchost.exe | 95.101.148.135:80 | armmf.adobe.com | Akamai International B.V. | NL | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
armmf.adobe.com |
| unknown |