| File name: | 15 Second ADB Installer v1.5.6.exe |
| Full analysis: | https://app.any.run/tasks/452f4ddb-2f43-44e5-8c13-6ec2ff995f3a |
| Verdict: | Malicious activity |
| Analysis date: | March 06, 2024, 15:41:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | A4705082D17A2081A47F47A3D28711C7 |
| SHA1: | 037A52083E8634748224D224E6B068970EC7B6A4 |
| SHA256: | 6AEDB17D951F24FA20496EC01639AD54AA9B82968102CF5EBF2DB1426500A2E4 |
| SSDEEP: | 196608:GOQ7CgNq3j1nlwp8J3BoYzFeGjF/nwqLLkzJ1S1nRp+9H51j3qZLqNjHNpVAZCRm:cCc0j3KsFB5wqUzOf8ZNqxSJAZW2LcU |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:12:31 00:38:38+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 57344 |
| InitializedDataSize: | 307200 |
| UninitializedDataSize: | 389120 |
| EntryPoint: | 0x6cad0 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.4.3.0 |
| ProductVersionNumber: | 1.4.3.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Snoop05 |
| FileDescription: | 15 seconds ADB Installer |
| FileVersion: | 1.4.3 |
| InternalName: | adb-installer |
| LegalCopyright: | - |
| OriginalFileName: | adb-installer-1.4.3.exe |
| PrivateBuild: | December 30, 2012 |
| ProductName: | 15 seconds ADB Installer |
| ProductVersion: | 1.4.3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1236 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1656 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1692 | FIND "5.1" | C:\Windows\System32\find.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (grep) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1836 | C:\Windows\system32\cmd.exe /S /D /c" VER " | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2096 | PING localhost -n 2 | C:\Windows\System32\PING.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: TCP/IP Ping Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2232 | SETX PATH "C:\Program Files\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\PowerShell\7\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\adb" /m | C:\Windows\System32\setx.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Setx - Sets environment variables Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2256 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{0d0d5c13-a51b-4d68-8c23-4361c60c5d13} Global\{7e477283-24e1-27a6-57d2-b413d5197523} C:\Windows\System32\DriverStore\Temp\{1c245d6c-7925-063a-a30f-6a2f4376cb57}\android_winusb.inf C:\Windows\System32\DriverStore\Temp\{1c245d6c-7925-063a-a30f-6a2f4376cb57}\androidwinusb86.cat | C:\Windows\System32\rundll32.exe | — | drvinst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2340 | XCOPY adb\AdbWinUsbApi.dll C:\adb\ /y /q | C:\Windows\System32\xcopy.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Extended Copy Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2624 | XCOPY adb\adb.exe C:\adb\ /y /q | C:\Windows\System32\xcopy.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Extended Copy Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2840 | "C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe" -sfxwaitall:0 "install.bat" | C:\Users\admin\AppData\Local\Temp\15 Second ADB Installer v1.5.6.exe | — | 15 Second ADB Installer v1.5.6.exe | |||||||||||
User: admin Company: Snoop05 Integrity Level: HIGH Description: 15 seconds ADB Installer Exit code: 0 Version: 1.4.3 Modules
| |||||||||||||||
| (PID) Process: | (3672) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3672) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3672) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3672) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2840) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2840) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2840) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2840) 15 Second ADB Installer v1.5.6.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2232) setx.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment |
| Operation: | write | Name: | PATH |
Value: C:\Program Files\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\PowerShell\7\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\adb | |||
| (PID) Process: | (2908) DPInst_x86.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2852 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\androidwinusba64.cat | cat | |
MD5:B83F9FA084F11007C7E6C668E6FA9E54 | SHA256:8F3F15BAEAF50AE7388562BE0303F5AC7EE3CB255448A24E3D33E1F094E0680E | |||
| 2852 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\androidwinusb86.cat | cat | |
MD5:76CFE751E17119F352C29F9FCE83D24F | SHA256:15A39B14E5FA4EC4BBE16632DBB19C7E0159649702BF98F9F77B2ABD7EBCC4DE | |||
| 2852 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\DPInst_x64.exe | executable | |
MD5:4192A5B905374E423EC1E545599AA86E | SHA256:567F40A09F1D9E72396296AD194FA7CF48B72361D6E259D6B99DA774C2CD8981 | |||
| 2852 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\DPInst_x86.exe | executable | |
MD5:9568538CEF3A955A88811250C7B9F053 | SHA256:CB7F00F91AE5F7D88277AC2EE5CFB5D3A9F8E9E629C3DE317ABF226A8B6B76B6 | |||
| 2852 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\WUDFUpdate_01009.dll | executable | |
MD5:EBF9EE8A7671F3B260ED9B08FCEE0CC5 | SHA256:015F26BBCD619A0B67B5EAA985B69582BAC27D5CBCA99CE747A76532FCDE4AFF | |||
| 2852 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\i386\WdfCoInstaller01009.dll | executable | |
MD5:A9970042BE512C7981B36E689C5F3F9F | SHA256:7A6BF1F950684381205C717A51AF2D9C81B203CB1F3DB0006A4602E2DF675C77 | |||
| 2852 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\i386\winusbcoinstaller2.dll | executable | |
MD5:8E7B9F81E8823FEE2D82F7DE3A44300B | SHA256:EBE3B7708DD974EE87EFED3113028D266AF87CA8DBAE77C47C6F7612824D3D6C | |||
| 2852 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\adb\adb.exe | executable | |
MD5:F6E68C4CC8CC3288FD5A411F54D8CAE2 | SHA256:FD488A4E13D4C71ACCE69E209164398A056FBA5A559B7F00C1351390604E5B98 | |||
| 2852 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\xp\SETX.exe | executable | |
MD5:5C04E0E82A5CF2288512BA35DE3223C3 | SHA256:0AB71E83950C682A0EAB6B35E9BACE97EDFDB25E909988B0D5D0A6EA5C3E4D40 | |||
| 2852 | 15 Second ADB Installer v1.5.6.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\driver\amd64\NOTICE.txt | text | |
MD5:EA7F2158B930BAF2C0FE799566489716 | SHA256:A19B767B9DDDA7306C78232E4A223D0BA966471B74DCE3C0C995307CAB5BF7B7 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |