| File name: | Reader_Install_Setup.exe |
| Full analysis: | https://app.any.run/tasks/2b8a426e-a87d-451d-bc45-0376b8c9ada1 |
| Verdict: | Malicious activity |
| Analysis date: | October 21, 2023, 03:05:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | FA8B28543C03F6CAE3A686141AD14B59 |
| SHA1: | D5534D9B5A0CBFDEAE27EF49C99C83F0BB27C2E9 |
| SHA256: | 78A8D882AE3BDDB9DEEC177C5E9C7D0DE2F09E466A9228CC851F55BB8A101520 |
| SSDEEP: | 49152:ByPHx+zd+TbTEqHFBqIGWEN3CxSyoYqLq2GMPjqGoeBxG3VhCKuuMXolNP8S6CYQ:ByPHxYAnQqHFBGFNyLtqFG0x4p9MXoPZ |
| .exe | | | Win64 Executable (generic) (43.7) |
|---|---|---|
| .exe | | | UPX compressed Win32 Executable (42.8) |
| .exe | | | Win32 Executable (generic) (7.1) |
| .exe | | | Generic Win/DOS Executable (3.1) |
| .exe | | | DOS Executable Generic (3.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:10:04 13:37:49+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.35 |
| CodeSize: | 1421312 |
| InitializedDataSize: | 20480 |
| UninitializedDataSize: | 3031040 |
| EntryPoint: | 0x43f0a0 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.707 |
| ProductVersionNumber: | 2.0.0.707 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Adobe Inc |
| FileDescription: | Adobe Download Manager |
| FileVersion: | 2.0.0.707s |
| InternalName: | Adobe Download Manager |
| LegalCopyright: | Copyright 2019 Adobe Inc. All rights reserved. |
| OriginalFileName: | Adobe Download Manager |
| ProductName: | Adobe Download Manager |
| ProductVersion: | 2.0.0.707s |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 556 | "C:\Users\admin\AppData\Local\Temp\Reader_Install_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Reader_Install_Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Adobe Inc Integrity Level: MEDIUM Description: Adobe Download Manager Exit code: 0 Version: 2.0.0.707s Modules
| |||||||||||||||
| 3676 | "C:\Users\admin\AppData\Local\Temp\Reader_Install_Setup.exe" --pipename={A1670FE9-41EA-4BC8-835F-85CD565CCC51} --pid=556 | C:\Users\admin\AppData\Local\Temp\Reader_Install_Setup.exe | Reader_Install_Setup.exe | ||||||||||||
User: admin Company: Adobe Inc Integrity Level: HIGH Description: Adobe Download Manager Exit code: 0 Version: 2.0.0.707s Modules
| |||||||||||||||
| (PID) Process: | (556) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (556) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (556) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (556) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3676) Reader_Install_Setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (556) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (556) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (556) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (556) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000056010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (556) Reader_Install_Setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 556 | Reader_Install_Setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | binary | |
MD5:D5DCA730DF319F765EB1B1CEE9C3708D | SHA256:D3F39B6306671BF1EAAE163B2C478E5E9900273187893DA4EB8BE7E72BCEE2CC | |||
| 556 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Temp\Adobe_ADMLogs\Adobe_ADM.log | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 556 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Adobe\6B3C7972-7947-48A5-A91C-1A7D5A11E63B\status_icon_caution_200.png | image | |
MD5:3683A511B9DBA974CD9F36A6B023E423 | SHA256:210F1B214ECCDE9E148072A10FC0E263FE6A443341BE4DC9630C47BC84796101 | |||
| 556 | Reader_Install_Setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89 | SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8 | |||
| 556 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Adobe\6B3C7972-7947-48A5-A91C-1A7D5A11E63B\status_icon_x_200.png | image | |
MD5:8E680B8EF37CFFCE4A9CD767D343A175 | SHA256:6B9CAE182EC085BD8CC7D52DE0FD175CE7CB0186119C8E6E85230FCF9D10E318 | |||
| 556 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\bxf0ivf[1].js | text | |
MD5:32294DAC4A42454945B628842529D064 | SHA256:BA47541514A1077E41059F3BAC6BEC055417971C461FA83BA747D928A5CCC08C | |||
| 556 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\d[1] | binary | |
MD5:DF0CD5EDE266E9EA694C3D28209FCE9F | SHA256:5ECD3C64E4C0D1A51D13E2762BECB9E7DA2ACD30D670058A6B16761BE3E017DB | |||
| 556 | Reader_Install_Setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:7733E95E9308C99EBBF7A23EDD43D081 | SHA256:34A3BDA261A487907CEED6CA2E5BBC24225980A1E5A1A6270D36806816AA1F05 | |||
| 556 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\d[1] | binary | |
MD5:83E5380B9DC2077B664E383CF6FCF47E | SHA256:741A4BC7D04FC8385F9A1DB0CCC586A224F14233B08D764D37EA165163A247A0 | |||
| 556 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\d[2] | binary | |
MD5:EE10AE517D40542F597A9E0E2852B52B | SHA256:ED1815F9829E1F6A710FCDC182613F614F4887E39281E095360BEEC1CCC72348 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
556 | Reader_Install_Setup.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4853f85560c27fc9 | unknown | compressed | 4.66 Kb | unknown |
556 | Reader_Install_Setup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
556 | Reader_Install_Setup.exe | 184.24.77.144:443 | use.typekit.net | Akamai International B.V. | DE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
556 | Reader_Install_Setup.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
556 | Reader_Install_Setup.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
556 | Reader_Install_Setup.exe | 23.35.236.137:443 | geo-dc.adobe.com | AKAMAI-AS | DE | unknown |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
556 | Reader_Install_Setup.exe | 184.24.77.146:443 | p.typekit.net | Akamai International B.V. | DE | unknown |
556 | Reader_Install_Setup.exe | 54.228.247.11:443 | rdc.adobe.io | AMAZON-02 | IE | unknown |
556 | Reader_Install_Setup.exe | 23.35.228.137:443 | platformdl.adobe.com | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
use.typekit.net |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
geo-dc.adobe.com |
| whitelisted |
p.typekit.net |
| shared |
rdc.adobe.io |
| unknown |
dlmping2.adobe.com |
| whitelisted |
platformdl.adobe.com |
| whitelisted |
ardownload2.adobe.com |
| whitelisted |