| File name: | 15 Second ADB Installer v1.5.6.exe |
| Full analysis: | https://app.any.run/tasks/114dae9d-3fca-48cd-b7f0-466a85b9ffea |
| Verdict: | Malicious activity |
| Analysis date: | November 28, 2023, 10:58:04 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | A4705082D17A2081A47F47A3D28711C7 |
| SHA1: | 037A52083E8634748224D224E6B068970EC7B6A4 |
| SHA256: | 6AEDB17D951F24FA20496EC01639AD54AA9B82968102CF5EBF2DB1426500A2E4 |
| SSDEEP: | 196608:GOQ7CgNq3j1nlwp8J3BoYzFeGjF/nwqLLkzJ1S1nRp+9H51j3qZLqNjHNpVAZCRm:cCc0j3KsFB5wqUzOf8ZNqxSJAZW2LcU |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:12:31 01:38:38+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 57344 |
| InitializedDataSize: | 307200 |
| UninitializedDataSize: | 389120 |
| EntryPoint: | 0x6cad0 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.4.3.0 |
| ProductVersionNumber: | 1.4.3.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Snoop05 |
| FileDescription: | 15 seconds ADB Installer |
| FileVersion: | 1.4.3 |
| InternalName: | adb-installer |
| LegalCopyright: | - |
| OriginalFileName: | adb-installer-1.4.3.exe |
| PrivateBuild: | December 30, 2012 |
| ProductName: | 15 seconds ADB Installer |
| ProductVersion: | 1.4.3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1900 | "C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe" -sfxelevation | C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe | 15 Second ADB Installer v1.5.6.exe | ||||||||||||
User: admin Company: Snoop05 Integrity Level: HIGH Description: 15 seconds ADB Installer Exit code: 0 Version: 1.4.3 Modules
| |||||||||||||||
| 2496 | "C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe" | C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe | — | explorer.exe | |||||||||||
User: admin Company: Snoop05 Integrity Level: MEDIUM Description: 15 seconds ADB Installer Exit code: 0 Version: 1.4.3 Modules
| |||||||||||||||
| 2820 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\install.bat" " | C:\Windows\System32\cmd.exe | — | 15 Second ADB Installer v1.5.6.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3056 | "C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe" -sfxwaitall:0 "install.bat" | C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe | — | 15 Second ADB Installer v1.5.6.exe | |||||||||||
User: admin Company: Snoop05 Integrity Level: HIGH Description: 15 seconds ADB Installer Exit code: 0 Version: 1.4.3 Modules
| |||||||||||||||
| 3136 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2496) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2496) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2496) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2496) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3056) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3056) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3056) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3056) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3136) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{19A995EC-DD24-4100-BA5B-D925A56657A9}\{EBAD9665-5843-44A2-944B-1E14A043EC21} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3136) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{D558F9A1-FC60-4DE0-9C0C-5F2928D62120}\{EBAD9665-5843-44A2-944B-1E14A043EC21} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\i386\NOTICE.txt | text | |
MD5:EA7F2158B930BAF2C0FE799566489716 | SHA256:A19B767B9DDDA7306C78232E4A223D0BA966471B74DCE3C0C995307CAB5BF7B7 | |||
| 1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\NOTICE.txt | text | |
MD5:EA7F2158B930BAF2C0FE799566489716 | SHA256:A19B767B9DDDA7306C78232E4A223D0BA966471B74DCE3C0C995307CAB5BF7B7 | |||
| 1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\androidwinusba64.cat | binary | |
MD5:B83F9FA084F11007C7E6C668E6FA9E54 | SHA256:8F3F15BAEAF50AE7388562BE0303F5AC7EE3CB255448A24E3D33E1F094E0680E | |||
| 1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\WdfCoInstaller01009.dll | executable | |
MD5:4DA5DA193E0E4F86F6F8FD43EF25329A | SHA256:18487B4FF94EDCCC98ED59D9FCA662D4A1331C5F1E14DF8DB3093256DD9F1C3E | |||
| 1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\adb\mke2fs.conf | text | |
MD5:699098CA95F87BA48BB94A3E848549B3 | SHA256:AD58A58DCDD24D85055814CA9CAC67DB89D4E67C434E96774BDCE0D0A007D067 | |||
| 1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\install.bat | text | |
MD5:6F6EDB4834BD4AFE36503A447BFFECCF | SHA256:151A3EA2B30720D1462109CA4563E42EC6A6709C502941AA533476858A6F3657 | |||
| 1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\androidwinusb86.cat | binary | |
MD5:76CFE751E17119F352C29F9FCE83D24F | SHA256:15A39B14E5FA4EC4BBE16632DBB19C7E0159649702BF98F9F77B2ABD7EBCC4DE | |||
| 1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\i386\WdfCoInstaller01009.dll | executable | |
MD5:A9970042BE512C7981B36E689C5F3F9F | SHA256:7A6BF1F950684381205C717A51AF2D9C81B203CB1F3DB0006A4602E2DF675C77 | |||
| 1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\adb\NOTICE.txt | text | |
MD5:44968B93DCB7403A731E89ED14CAA252 | SHA256:9652A7629CC5115B890759F7AA15A614F39CE7B4B76A5A299768351F2CBD0998 | |||
| 1900 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\adb\source.properties | text | |
MD5:6926A4FADAD84D753C1731CFF5FF29B1 | SHA256:0BBDFC51086C50BDCCF263E5D103FF3ACD6560B04DCB6D03CBFFBA10059A06C1 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
868 | svchost.exe | 95.101.148.135:80 | armmf.adobe.com | Akamai International B.V. | NL | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
armmf.adobe.com |
| whitelisted |