| File name: | adobe-master-cs4-keygen.exe |
| Full analysis: | https://app.any.run/tasks/15f887ad-ff5e-4c98-8666-1be3d4c1ec57 |
| Verdict: | Malicious activity |
| Analysis date: | February 13, 2024, 00:24:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 24AACC8010D8B25D3807D7EB2320245E |
| SHA1: | C7ABBC465DCC3FA57FEAC2D68890ACA4448D06F8 |
| SHA256: | 8368F9FE9D358B098D52A905819156A73638F3D2548B8CDA36702DFD7453BA2E |
| SSDEEP: | 3072:kle8Cj35gmJ3m4jsGO2W5poM9WMNewaKu9hZO:krK/sGO2WD9WMO9bO |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2007:03:31 15:09:36+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 23040 |
| InitializedDataSize: | 3785216 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x3141 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Users\admin\AppData\Local\Temp\adobe-master-cs4-keygen.exe" | C:\Users\admin\AppData\Local\Temp\adobe-master-cs4-keygen.exe | — | adobe-master-cs4-keygen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 | |||||||||||||||
| 116 | "C:\Users\admin\AppData\Local\Temp\svchost.exe" | C:\Users\admin\AppData\Local\Temp\svchost.exe | — | adobe-master-cs4-keygen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 | |||||||||||||||
| 116 | "C:\Users\admin\AppData\Local\Temp\adobe-master-cs4-keygen.exe" | C:\Users\admin\AppData\Local\Temp\adobe-master-cs4-keygen.exe | — | adobe-master-cs4-keygen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 | |||||||||||||||
| 116 | "C:\Users\admin\AppData\Local\Temp\svchost.exe" | C:\Users\admin\AppData\Local\Temp\svchost.exe | — | adobe-master-cs4-keygen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 | |||||||||||||||
| 120 | "C:\Users\admin\AppData\Local\Temp\svchost.exe" | C:\Users\admin\AppData\Local\Temp\svchost.exe | — | adobe-master-cs4-keygen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 | |||||||||||||||
| 120 | "C:\Users\admin\AppData\Local\Temp\adobe-master-cs4-keygen.exe" | C:\Users\admin\AppData\Local\Temp\adobe-master-cs4-keygen.exe | — | adobe-master-cs4-keygen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 | |||||||||||||||
| 120 | "C:\Users\admin\AppData\Local\Temp\svchost.exe" | C:\Users\admin\AppData\Local\Temp\svchost.exe | — | adobe-master-cs4-keygen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 | |||||||||||||||
| 124 | "C:\Users\admin\AppData\Local\Temp\svchost.exe" | C:\Users\admin\AppData\Local\Temp\svchost.exe | — | adobe-master-cs4-keygen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 124 | "C:\Users\admin\AppData\Local\Temp\adobe-master-cs4-keygen.exe" | C:\Users\admin\AppData\Local\Temp\adobe-master-cs4-keygen.exe | — | adobe-master-cs4-keygen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 | |||||||||||||||
| 128 | "C:\Users\admin\AppData\Local\Temp\svchost.exe" | C:\Users\admin\AppData\Local\Temp\svchost.exe | — | adobe-master-cs4-keygen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2036) adobe-master-cs4-keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2036) adobe-master-cs4-keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2036) adobe-master-cs4-keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2036) adobe-master-cs4-keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2848) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\svchost.exe | |||
| (PID) Process: | (2840) adobe-master-cs4-keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2840) adobe-master-cs4-keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2840) adobe-master-cs4-keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2840) adobe-master-cs4-keygen.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3464) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\svchost.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2848 | svchost.exe | C:\Users\admin\AppData\Local\Temp\vbruntime.tmp | executable | |
MD5:A28E2B5647C32A10D8BEE6BA25AB508C | SHA256:95DC7CB4BAD0C76C17D00332AC948BB0197DAA816978382FEB7B8F9D061495E5 | |||
| 2036 | adobe-master-cs4-keygen.exe | C:\Users\admin\AppData\Local\Temp\svchost.exe | executable | |
MD5:718DE4A9FE3CBF0287576E0EFC9CCDB9 | SHA256:92AF86E47C42E0B226010FAFDC3A0761BDA57CE420469382A60040F0C5E59F66 | |||
| 2848 | svchost.exe | C:\Users\admin\AppData\Local\Temp\1568375_res.tmp | executable | |
MD5:A28E2B5647C32A10D8BEE6BA25AB508C | SHA256:95DC7CB4BAD0C76C17D00332AC948BB0197DAA816978382FEB7B8F9D061495E5 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
onestopstation.net |
| unknown |