| download: | air.exe |
| Full analysis: | https://app.any.run/tasks/8265af34-b01c-4ca7-a677-e9e34f4fe44a |
| Verdict: | Malicious activity |
| Analysis date: | December 26, 2021, 22:44:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 80DDEC86FCEEF3016426BC50E85BE6A2 |
| SHA1: | 6386F9C48C45B722AA5B969FD2A50E2328E7ABBA |
| SHA256: | 709268F3B91DAEA6A168141E73B37BEE6CBD6988269804F5E2050EE4F5D00832 |
| SSDEEP: | 98304:9ESlNPufzFgK7ywGkZyfjJg2SHLvD2adHHnLJLosBV/BsP7wkkiumuLyugJh6vU5:BPIJgKBobaLLLOs/utkbNypKp4qX21 |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| ProductVersion: | 33.1 |
|---|---|
| ProductName: | Adobe AIR |
| OriginalFileName: | Adobe AIR Installer.exe |
| LegalCopyright: | Copyright 2007-2020, Adobe |
| InternalName: | Adobe AIR Installer.exe |
| FileVersion: | 33.1.1.533 |
| FileDescription: | Adobe AIR Installer |
| CompanyName: | Adobe |
| CharacterSet: | Unicode |
| LanguageCode: | English (U.S.) |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Windows NT 32-bit |
| FileFlags: | Pre-release |
| FileFlagsMask: | 0x0003 |
| ProductVersionNumber: | 33.1.1.533 |
| FileVersionNumber: | 33.1.1.533 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 6 |
| ImageVersion: | - |
| OSVersion: | 6 |
| EntryPoint: | 0x1360 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 350208 |
| CodeSize: | 92672 |
| LinkerVersion: | 14 |
| PEType: | PE32 |
| TimeStamp: | 2021:06:18 19:03:21+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 18-Jun-2021 17:03:21 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Adobe |
| FileDescription: | Adobe AIR Installer |
| FileVersion: | 33.1.1.533 |
| InternalName: | Adobe AIR Installer.exe |
| LegalCopyright: | Copyright 2007-2020, Adobe |
| OriginalFilename: | Adobe AIR Installer.exe |
| ProductName: | Adobe AIR |
| ProductVersion: | 33.1 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000110 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 18-Jun-2021 17:03:21 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00016869 | 0x00016A00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64168 |
.rdata | 0x00018000 | 0x00008CEC | 0x00008E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.87848 |
.data | 0x00021000 | 0x00003278 | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.1891 |
.rsrc | 0x00025000 | 0x00048088 | 0x00048200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.68245 |
.reloc | 0x0006E000 | 0x0000124C | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.33308 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.3298 | 822 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 3.6005 | 2216 | UNKNOWN | English - United States | RT_ICON |
3 | 2.66625 | 1384 | UNKNOWN | English - United States | RT_ICON |
4 | 3.53645 | 270376 | UNKNOWN | English - United States | RT_ICON |
5 | 3.82425 | 9640 | UNKNOWN | English - United States | RT_ICON |
6 | 4.05991 | 4264 | UNKNOWN | English - United States | RT_ICON |
7 | 4.41053 | 1128 | UNKNOWN | English - United States | RT_ICON |
100 | 2.71787 | 104 | UNKNOWN | English - United States | RT_GROUP_ICON |
KERNEL32.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 688 | "C:\Users\admin\Desktop\air.exe" | C:\Users\admin\Desktop\air.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.533 Modules
| |||||||||||||||
| 740 | "C:\Users\admin\Desktop\air.exe" | C:\Users\admin\Desktop\air.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.533 Modules
| |||||||||||||||
| 880 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1044 | "C:\Users\admin\Desktop\air.exe" | C:\Users\admin\Desktop\air.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.533 Modules
| |||||||||||||||
| 1072 | "C:\Users\admin\Desktop\air.exe" | C:\Users\admin\Desktop\air.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.533 Modules
| |||||||||||||||
| 1812 | "C:\Users\admin\Desktop\air.exe" | C:\Users\admin\Desktop\air.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.533 Modules
| |||||||||||||||
| 2200 | "C:\Users\admin\Desktop\air.exe" | C:\Users\admin\Desktop\air.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.533 Modules
| |||||||||||||||
| 2236 | "C:\Users\admin\Desktop\air.exe" | C:\Users\admin\Desktop\air.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.533 Modules
| |||||||||||||||
| 2276 | "C:\Users\admin\Desktop\air.exe" | C:\Users\admin\Desktop\air.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.533 Modules
| |||||||||||||||
| 2412 | "C:\Users\admin\Desktop\air.exe" | C:\Users\admin\Desktop\air.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.533 Modules
| |||||||||||||||
| (PID) Process: | (2548) air.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2548) air.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2548) air.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2548) air.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3988) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3988) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3988) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3988) Adobe AIR Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (880) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (880) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 7003000035EC942DAAFAD701 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2548 | air.exe | C:\Users\admin\AppData\Local\Temp\AIR3BF6.tmp\Adobe AIR\Versions\1.0\Resources\template.msi | executable | |
MD5:0672DFE2C8A187C4B653E52D7918BE07 | SHA256:278CC10D24DF117B008D93C3C97D93146206358C4C8FEB83BEF6B4E7E54CE485 | |||
| 2548 | air.exe | C:\Users\admin\AppData\Local\Temp\AIR3BF6.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.swf | swf | |
MD5:7604DE354DC60A4DCE3920EE673072BF | SHA256:7388E603EB203E6712125D12EB0472A7FF96E1646156C9B8608493EDB82406C7 | |||
| 2548 | air.exe | C:\Users\admin\AppData\Local\Temp\AIR3BF6.tmp\Adobe AIR\sentinel | text | |
MD5:A5C11CA014FE30B8085EA2E95F7196C4 | SHA256:096E4BFD9F7E1FAF15058C0A0FE45E6DBD00E3E1360F21F2CA92BCE16A9A919A | |||
| 2548 | air.exe | C:\Users\admin\AppData\Local\Temp\AIR3BF6.tmp\setup.msi | executable | |
MD5:DC89127BF1180F8C084F562F3ED0D348 | SHA256:D00990BBD6CA8FC91FA8B6929E21843AFF855A6B97ADF4CBFD5690468E08CEEE | |||
| 2548 | air.exe | C:\Users\admin\AppData\Local\Temp\AIR3BF6.tmp\Adobe AIR\Versions\1.0\Resources\setup.swf | swf | |
MD5:971811F8B0C5869EF44ABA78AEDEF020 | SHA256:C587CB2198A8F278D810584FBDAD88E91BBFE6C6A2C75FD6B2C2CAC113D30938 | |||
| 2548 | air.exe | C:\Users\admin\AppData\Local\Temp\AIR3BF6.tmp\setup.swf | swf | |
MD5:971811F8B0C5869EF44ABA78AEDEF020 | SHA256:C587CB2198A8F278D810584FBDAD88E91BBFE6C6A2C75FD6B2C2CAC113D30938 | |||
| 2548 | air.exe | C:\Users\admin\AppData\Local\Temp\AIR3BF6.tmp\Adobe AIR\Versions\1.0\Resources\Licenses\pixman\COPYING | text | |
MD5:1168F6DA9F901D48731A7D51940FECAD | SHA256:6E9F39A63E6E8AE87DE8AFDF5E7E9571B964A52717614EDB84675016042F6AFC | |||
| 2548 | air.exe | C:\Users\admin\AppData\Local\Temp\AIR3BF6.tmp\Adobe AIR\Versions\1.0\Resources\Licenses\cairo\COPYING | text | |
MD5:EF5A4E944085278EB1A7B7A881CCEAF6 | SHA256:4FDCDE2E1F6AEB1DF3D767A8330AFF6ED6E6C0031D3C8EA72E95620613B4F827 | |||
| 2548 | air.exe | C:\Users\admin\AppData\Local\Temp\AIR3BF6.tmp\Adobe AIR\Versions\1.0\Resources\Adobe AIR Installer.exe | executable | |
MD5:15EF6186ECE47EDD15B0E63B0DDCDD4D | SHA256:825B4A0F291CC7976D5F17539ABD1E8EA87FD0E3747429356AD0A1EAC3D8BED4 | |||
| 2548 | air.exe | C:\Users\admin\AppData\Local\Temp\AIR3BF6.tmp\Adobe AIR\Versions\1.0\Resources\digest.s | cat | |
MD5:0F5295089E4EF5A7396007407EE21113 | SHA256:4571EAD5D878568C4082003D21F50A39B8687F08E8F631AA20351014373ED2B1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4008 | Adobe AIR Updater.exe | GET | 200 | 52.222.206.35:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
4008 | Adobe AIR Updater.exe | GET | 200 | 52.222.206.73:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D | US | der | 1.39 Kb | shared |
4008 | Adobe AIR Updater.exe | GET | 200 | 18.66.242.94:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | US | der | 1.70 Kb | whitelisted |
4008 | Adobe AIR Updater.exe | GET | 200 | 108.156.253.141:80 | http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEArnLp9awM69gd%2BIe6rguv0%3D | US | der | 471 b | whitelisted |
4008 | Adobe AIR Updater.exe | GET | 200 | 2.18.213.112:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?0ff84088e801b768 | unknown | compressed | 4.70 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4008 | Adobe AIR Updater.exe | 52.222.206.73:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
4008 | Adobe AIR Updater.exe | 108.156.253.141:80 | ocsp.sca1b.amazontrust.com | — | US | whitelisted |
3288 | Adobe AIR Updater.exe | 107.21.40.85:443 | airsdk.harman.com | Amazon.com, Inc. | US | unknown |
4008 | Adobe AIR Updater.exe | 18.66.242.94:80 | o.ss2.us | Massachusetts Institute of Technology | US | unknown |
4008 | Adobe AIR Updater.exe | 52.222.206.35:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
4008 | Adobe AIR Updater.exe | 2.18.213.112:80 | ctldl.windowsupdate.com | Akamai International B.V. | — | whitelisted |
4008 | Adobe AIR Updater.exe | 107.21.40.85:443 | airsdk.harman.com | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
airsdk.harman.com |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
ocsp.sca1b.amazontrust.com |
| whitelisted |