File name:

Adobe-GenP-3.3.10.exe

Full analysis: https://app.any.run/tasks/b23abfaa-a266-496a-b055-ad90df0f3766
Verdict: Malicious activity
Analysis date: February 16, 2025, 11:19:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
adobegenp
crack
autoit
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

2775C961FA031D03825179C4E7749F3D

SHA1:

7BA13448CABDAE6C9573ED95FBA841A10B687CC9

SHA256:

77B56700BF5D1CC5530D72D4800825B46D719FFF11B36F2A02305E89CB2E48E7

SSDEEP:

49152:pE/XUraxm5O9QMal0QRO8t/p/QOWVorID1:p9rem5OidDRn9rID1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • ADOBEGENP mutex has been found

      • Adobe-GenP-3.3.10.exe (PID: 6436)
    • There is functionality for taking screenshot (YARA)

      • Adobe-GenP-3.3.10.exe (PID: 6436)
  • INFO

    • Checks supported languages

      • Adobe-GenP-3.3.10.exe (PID: 6436)
    • Reads mouse settings

      • Adobe-GenP-3.3.10.exe (PID: 6436)
    • The sample compiled with english language support

      • Adobe-GenP-3.3.10.exe (PID: 6436)
    • Create files in a temporary directory

      • Adobe-GenP-3.3.10.exe (PID: 6436)
    • The process uses AutoIt

      • Adobe-GenP-3.3.10.exe (PID: 6436)
    • Creates files in the program directory

      • Adobe-GenP-3.3.10.exe (PID: 6436)
    • Reads the computer name

      • Adobe-GenP-3.3.10.exe (PID: 6436)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:05:30 22:53:20+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.16
CodeSize: 734208
InitializedDataSize: 549888
UninitializedDataSize: -
EntryPoint: 0x2549c
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 3.3.16.1
ProductVersionNumber: 3.3.16.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Unicode
FileVersion: 3.3.16.1
Comments: AdobeGenP
FileDescription: AdobeGenP
ProductName: AdobeGenP
ProductVersion: 3.3.16.1
CompanyName: AdobeGenP
LegalCopyright: AdobeGenP
LegalTradeMarks: AdobeGenP
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start adobe-genp-3.3.10.exe adobe-genp-3.3.10.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6332"C:\Users\admin\AppData\Local\Temp\Adobe-GenP-3.3.10.exe" C:\Users\admin\AppData\Local\Temp\Adobe-GenP-3.3.10.exeexplorer.exe
User:
admin
Company:
AdobeGenP
Integrity Level:
MEDIUM
Description:
AdobeGenP
Exit code:
3221226540
Version:
3.3.16.1
Modules
Images
c:\users\admin\appdata\local\temp\adobe-genp-3.3.10.exe
c:\windows\system32\ntdll.dll
6436"C:\Users\admin\AppData\Local\Temp\Adobe-GenP-3.3.10.exe" C:\Users\admin\AppData\Local\Temp\Adobe-GenP-3.3.10.exe
explorer.exe
User:
admin
Company:
AdobeGenP
Integrity Level:
HIGH
Description:
AdobeGenP
Version:
3.3.16.1
Modules
Images
c:\users\admin\appdata\local\temp\adobe-genp-3.3.10.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
Total events
21
Read events
21
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
6436Adobe-GenP-3.3.10.exeC:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.dll.bak
MD5:
SHA256:
6436Adobe-GenP-3.3.10.exeC:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.dll
MD5:
SHA256:
6436Adobe-GenP-3.3.10.exeC:\Users\admin\AppData\Local\Temp\aut7255.tmpbinary
MD5:5A3B63C3201FCE7B20F367F5B8792626
SHA256:44D1ACCC9DD583BC5BFCBE8CFDAD201ADB312C3B8D6396E532238EBC741D217B
6436Adobe-GenP-3.3.10.exeC:\Users\admin\AppData\Local\Temp\config.initext
MD5:ECED1675BE4E760362325CEA0DF7B4A3
SHA256:CD95B22FF63207CD4182D9F9A50A700739DFCAEDB0589E02C677C00BB8077A0A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
26
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6420
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6892
backgroundTaskHost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6420
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1296
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5892
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
40.126.31.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
2.19.106.8:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
6420
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
  • 2.23.246.101
  • 23.52.120.96
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
login.live.com
  • 40.126.31.131
  • 40.126.31.129
  • 40.126.31.3
  • 20.190.159.64
  • 40.126.31.0
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.0
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 23.54.109.203
whitelisted
go.microsoft.com
  • 2.19.106.8
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.74.19.45
whitelisted

Threats

No threats detected
No debug info