| File name: | flashplayer_install_cn.exe |
| Full analysis: | https://app.any.run/tasks/a743ae60-0ab9-47f9-aca1-b32314237fc1 |
| Verdict: | Malicious activity |
| Analysis date: | July 24, 2021, 10:51:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 6A465EFC602AFC2636643C2462CC52F1 |
| SHA1: | 02EEAB6D4EDCC1716C49F74665B31B630B320D1F |
| SHA256: | 84FC0009A1DC691228F46FC1D88A00D6AB4B20298F948681CA27E6319ED0D38A |
| SSDEEP: | 49152:284K0AkoYFr7EzfWuJWpvHsfhKer4jgGAje+coxjo1SbEnWf5BIECvrFhBtaccAP:2toYp4qHsfoerG+Lcg81SbEnWfHfCzBL |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| Subsystem: | Windows GUI |
|---|---|
| SubsystemVersion: | 5.1 |
| ImageVersion: | - |
| OSVersion: | 5.1 |
| EntryPoint: | 0x1eef0 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 76800 |
| CodeSize: | 201728 |
| LinkerVersion: | 14 |
| PEType: | PE32 |
| TimeStamp: | 2021:06:11 11:16:47+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 11-Jun-2021 09:16:47 |
| Detected languages: |
|
| Debug artifacts: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000110 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 11-Jun-2021 09:16:47 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000313BA | 0x00031400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.70981 |
.rdata | 0x00033000 | 0x0000A622 | 0x0000A800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.22268 |
.data | 0x0003E000 | 0x00023728 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.70882 |
.didat | 0x00062000 | 0x0000018C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.35543 |
.rsrc | 0x00063000 | 0x00004CC0 | 0x00004E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.78174 |
.reloc | 0x00068000 | 0x0000227C | 0x00002400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.56418 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.25329 | 1875 | Latin 1 / Western European | Chinese - PRC | RT_MANIFEST |
7 | 5.24197 | 182 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
8 | 5.27357 | 214 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
9 | 5.21038 | 188 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
10 | 5.11103 | 116 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
11 | 5.38329 | 642 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
12 | 4.71863 | 148 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
13 | 4.90272 | 136 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
14 | 4.39475 | 124 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
15 | 4.33363 | 82 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
KERNEL32.dll |
USER32.dll (delay-loaded) |
gdiplus.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 284 | taskkill /F /IM "FCLogin.exe" | C:\Windows\system32\taskkill.exe | — | nsE757.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 440 | "C:\windows\temp\flashplayerpp_ax_install_cn_fc.exe" | C:\windows\temp\flashplayerpp_ax_install_cn_fc.exe | flashplayer_install_cn.exe | ||||||||||||
User: admin Company: Adobe Inc Integrity Level: MEDIUM Description: Adobe Download Manager Exit code: 0 Version: 3.0.0.616s Modules
| |||||||||||||||
| 884 | "C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\0286EE96-C4B4-40F8-9BE9-100B261293C5\17FECBD4-118D-4ED0-A225-9E8777D2790E" /S=0 /InstallPath="C:\Program Files\FlashCenter" /Bootup=1 /TaskBarShortcut=1 /DeskShortcut=1 | C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\0286EE96-C4B4-40F8-9BE9-100B261293C5\17FECBD4-118D-4ED0-A225-9E8777D2790E | flashplayerpp_ax_install_cn_fc.exe | ||||||||||||
User: admin Company: Chongqing Zhongcheng Network Technology Co., Ltd Integrity Level: HIGH Description: FlashCenter Installer Exit code: 0 Version: 2.3.5.20 Modules
| |||||||||||||||
| 1284 | "C:\Users\admin\AppData\Local\Temp\nsvC8EB.tmp\nsE3B7.tmp" taskkill /F /IM "FlashCenter.exe" | C:\Users\admin\AppData\Local\Temp\nsvC8EB.tmp\nsE3B7.tmp | — | 17FECBD4-118D-4ED0-A225-9E8777D2790E | |||||||||||
User: admin Integrity Level: HIGH Exit code: 128 Modules
| |||||||||||||||
| 1284 | "C:\Program Files\FlashCenter\FlashCenter.exe" --type=gpu-process --field-trial-handle=1200,16847975949317905413,9637307051906734042,131072 --enable-features=CastMediaRouteProvider,CookieDeprecationMessages,CrossOriginEmbedderPolicy,CrossOriginOpenerPolicy,DocumentPolicy,FeaturePolicyForClientHints,OriginIsolationHeader,OriginPolicy,UserAgentClientHint --disable-features=OutOfBlinkCors --no-sandbox --log-file="C:\Program Files\FlashCenter\debug.log" --log-severity=disable --user-agent="Mozilla/5.0 (Windows NT 7; X86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36 FCBrowser/2.3.5.20" --lang=zh-CN --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --log-file="C:\Program Files\FlashCenter\debug.log" --mojo-platform-channel-handle=1344 /prefetch:2 | C:\Program Files\FlashCenter\FlashCenter.exe | — | FlashCenter.exe | |||||||||||
User: admin Company: Chongqing Zhongcheng Network Technology Co., Ltd Integrity Level: HIGH Description: Flash Center Exit code: 0 Version: 2.3.5.20 Modules
| |||||||||||||||
| 1400 | "C:\Program Files\FlashCenter\FCBrowser.exe" --type=renderer --no-sandbox --autoplay-policy=no-user-gesture-required --log-file="C:\Program Files\FlashCenter\debug.log" --override-plugin-power-saver-for-testing=never --field-trial-handle=1212,273707823749874584,4312473285014310842,131072 --enable-features=CastMediaRouteProvider --disable-features=OutOfBlinkCors --lang=zh-CN --log-file="C:\Program Files\FlashCenter\debug.log" --log-severity=disable --user-agent="Mozilla/5.0 (Windows NT 7; X86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36 FCBrowser/2.3.5.20" --enable-system-flash --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=3 --mojo-platform-channel-handle=1812 /prefetch:1 | C:\Program Files\FlashCenter\FCBrowser.exe | — | FCBrowser.exe | |||||||||||
User: admin Company: Chongqing Zhongcheng Network Technology Co., Ltd Integrity Level: HIGH Description: Flash Center Exit code: 0 Version: 2.3.5.20 Modules
| |||||||||||||||
| 1712 | "C:\Windows\system32\cmd.exe" /c del "C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\0304B30A-539F-4D3E-80BD-D1EB5F3D7EC9\4EC3CFD5-7014-4A66-80BC-BE88B5AA4308" >> NUL | C:\Windows\system32\cmd.exe | — | 4EC3CFD5-7014-4A66-80BC-BE88B5AA4308 | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1740 | "C:\Program Files\FlashCenter\FCBrowserManager.exe" 60956CF02C6DDCD5DE68A4D7829255191B7E6536E3A8DAED910712D868C7D65F120D81BF3F6B7853840CA674C08CCBBFCBD3CE72B298C40DC390A4EF26041FFDFC4E02AE9A698864DB2FB908F5C8F8E46FE19B02C86923E02292C5BFDAA745547140D08216A68735CFADF60F055230A5E06B7A21C81522EB9975900F38C892687D4D32CE280932316DDAEB2BE2AF4B25356DABFCD81E145D5D10ABA532E8FD9F8B313BECF6DEA79270ACDEC1C84BDFD050A0C22CCEC3746F869973A7CFBF386049D5279DB347F32B7D5266E7F0325B0A40ED64D02C1F7286C672214A711E9839A8261F12BE8AC50B10C6D35A77BC1B043C94B6798CED23E7F0129BA347A5421B4CFD04488DFEB5A04199CC57A70A43C1B62C82AEF8707EFDF3E25CD2164482AA | C:\Program Files\FlashCenter\FCBrowserManager.exe | FlashCenter.exe | ||||||||||||
User: admin Company: Chongqing Zhongcheng Network Technology Co., Ltd Integrity Level: HIGH Description: Flash Center Exit code: 0 Version: 2.3.5.20 Modules
| |||||||||||||||
| 1936 | "C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\0304B30A-539F-4D3E-80BD-D1EB5F3D7EC9\4EC3CFD5-7014-4A66-80BC-BE88B5AA4308" -install -iv 8 | C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\0304B30A-539F-4D3E-80BD-D1EB5F3D7EC9\4EC3CFD5-7014-4A66-80BC-BE88B5AA4308 | flashplayerpp_ax_install_cn_fc.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: HIGH Description: Adobe� Flash� Player Installer/Uninstaller 34.0 r0* Exit code: 0 Version: 34,0,0,175 Modules
| |||||||||||||||
| 1992 | "C:\Users\admin\AppData\Local\Temp\nsvC8EB.tmp\nsE67B.tmp" taskkill /F /IM "FCTips.exe" | C:\Users\admin\AppData\Local\Temp\nsvC8EB.tmp\nsE67B.tmp | — | 17FECBD4-118D-4ED0-A225-9E8777D2790E | |||||||||||
User: admin Integrity Level: HIGH Exit code: 128 Modules
| |||||||||||||||
| (PID) Process: | (2772) flashplayer_install_cn.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2772) flashplayer_install_cn.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2772) flashplayer_install_cn.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2772) flashplayer_install_cn.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (440) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (440) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (440) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (440) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (440) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (440) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2772 | flashplayer_install_cn.exe | C:\windows\temp\flashplayerpp_ax_install_cn_fc.exe | executable | |
MD5:— | SHA256:— | |||
| 2772 | flashplayer_install_cn.exe | C:\windows\temp\1.ico | image | |
MD5:— | SHA256:— | |||
| 440 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Temp\Adobe_CDMLogs\Adobe_CDM.log | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 2772 | flashplayer_install_cn.exe | C:\windows\temp\payload.exe | executable | |
MD5:— | SHA256:— | |||
| 440 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\status_icon_caution_125.png | image | |
MD5:4A2BF8C96F910B1B2AE63A9F4A0D4B8F | SHA256:0CB2F4EE1C451A8825EB8EDB45858B28345F73423C7A7AEF4168C46F7E3638BF | |||
| 440 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\status_icon_x_200.png | image | |
MD5:40A32023DBFCCA1A80B69408735E15C2 | SHA256:D5A9BFE6D64F5C09F1DE3DCC74B30520DB5F78BCC6FC1E9A87EB141D9B46EA61 | |||
| 440 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\status_icon_caution_150.png | image | |
MD5:CA3872EAE64C5BFD8D41198990B11950 | SHA256:3438623C461F8F141976A931D3C00F6877D07CF4A8B534AF1EF9FDFE8B0C6174 | |||
| 440 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\status_icon_caution_100.png | image | |
MD5:56F804DB5509B1CF08BE5C994AFC2322 | SHA256:C4768FC9A84B0D3ECDEEE93820703D769737B992EFD1F0CBE9F7A9D3BBDFA0FB | |||
| 440 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\progressbar_darkgray_base_200.png | image | |
MD5:CD614F26DD67507EF8C17E5A3133A45E | SHA256:30558D6E8D8F862D10D1DF81DBB6C54503F3ADE7DD134DC2CE1E3F0AC9C4D0BC | |||
| 440 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\F665A218-960D-46EC-A8EC-78BFFCB14CFA\status_icon_x_150.png | image | |
MD5:5CC222F110ED5839F910FBBA15F35368 | SHA256:EEE6E710161A3AA8488FB4C1F118B43FA5C377ECDEDFFAAE78A81865F16CF288 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
440 | flashplayerpp_ax_install_cn_fc.exe | GET | 302 | 13.36.218.177:80 | http://stats.adobe.com/b/ss/adbacdcprod/1/H.25.4/s92755819006378?AQB=1&ndh=1&t=24%2F6%2F2021%2011%3A52%3A0%206%20-60&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_launched&g=res%3A%2F%2FC%3A%5Cwindows%5Ctemp%5Cflashplayerpp_ax_install_cn_fc.exe%2F319&ch=acdc_flashplayer&events=event96&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_launched&v18=new&v22=saturday%20-%204%3A30am&v73=acdc_flashplayer&s=1280x720&c=32&j=1.5&v=Y&k=N&bw=622&bh=402&ct=lan&hp=Y&AQE=1 | US | — | — | whitelisted |
2860 | DBE9FD0C-BFEA-4654-B6C5-378674AB1C6C | GET | 404 | 92.123.143.240:80 | http://fpdownload2.macromedia.com/get/flashplayer/update/current/install/version.xml34.0.0.175~installVector=108&previousVersion=32.0.0.453&pProc=flashplayerpp_ax_install_cn_fc.exe&lang=en&cpuWordLength=32&playerType=pep&os=win&osVer=13&isDebug=0 | unknown | html | 442 b | whitelisted |
2860 | DBE9FD0C-BFEA-4654-B6C5-378674AB1C6C | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAd7GEG4ytDyMGN48mIEUNI%3D | US | der | 471 b | whitelisted |
2860 | DBE9FD0C-BFEA-4654-B6C5-378674AB1C6C | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | US | der | 471 b | whitelisted |
884 | 17FECBD4-118D-4ED0-A225-9E8777D2790E | GET | — | 42.63.21.158:80 | http://tongji.flash.cn/hm4.gif?product=FC&event=install&uid=533E95D3AA78C4092F0AA9C694122A75&um=72a64af6fe11aec591f7beeb2b99b756&platform=Windows&channel=10001&version=2.3.5.20&key=0&data={"osversion":"6.1.7601.24545","type":"0","time":"1627124014","success":"0"}&signature=818860798b8a6b7aef4b98ad07095111 | CN | — | — | whitelisted |
440 | flashplayerpp_ax_install_cn_fc.exe | GET | 200 | 67.26.75.254:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e3462f45b69fcfbd | US | compressed | 59.5 Kb | whitelisted |
2860 | DBE9FD0C-BFEA-4654-B6C5-378674AB1C6C | GET | 200 | 67.26.75.254:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9e426ef7e1947bd8 | US | compressed | 4.70 Kb | whitelisted |
440 | flashplayerpp_ax_install_cn_fc.exe | GET | 200 | 13.36.218.177:80 | http://stats.adobe.com/b/ss/adbacdcprod/1/H.25.4/s92755819006378?AQB=1&pccr=true&vidn=307DF868CE19E002-4000167763BCE67C&ndh=1&t=24%2F6%2F2021%2011%3A52%3A0%206%20-60&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_launched&g=res%3A%2F%2FC%3A%5Cwindows%5Ctemp%5Cflashplayerpp_ax_install_cn_fc.exe%2F319&ch=acdc_flashplayer&events=event96&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_launched&v18=new&v22=saturday%20-%204%3A30am&v73=acdc_flashplayer&s=1280x720&c=32&j=1.5&v=Y&k=N&bw=622&bh=402&ct=lan&hp=Y&AQE=1 | US | image | 43 b | whitelisted |
1936 | 4EC3CFD5-7014-4A66-80BC-BE88B5AA4308 | GET | 404 | 92.123.143.240:80 | http://fpdownload2.macromedia.com/get/flashplayer/update/current/install/version.xml34.0.0.175~installVector=108&previousVersion=32.0.0.453&pProc=flashplayerpp_ax_install_cn_fc.exe&lang=en&cpuWordLength=32&playerType=ax&os=win&osVer=13&isDebug=0 | unknown | html | 441 b | whitelisted |
440 | flashplayerpp_ax_install_cn_fc.exe | GET | 200 | 13.36.218.177:80 | http://stats.adobe.com/b/ss/adbacdcprod/1/H.25.4/s97336220360480?AQB=1&ndh=1&t=24%2F6%2F2021%2011%3A53%3A38%206%20-60&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_success_exitcode%3D0&g=res%3A%2F%2FC%3A%5Cwindows%5Ctemp%5Cflashplayerpp_ax_install_cn_fc.exe%2F319&ch=acdc_flashplayer&events=event95&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_success_exitcode%3D0&v18=new&v22=saturday%20-%204%3A30am&v73=acdc_flashplayer&s=1280x720&c=32&j=1.5&v=Y&k=N&bw=622&bh=402&ct=lan&hp=Y&AQE=1 | US | image | 43 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
440 | flashplayerpp_ax_install_cn_fc.exe | 101.33.11.29:443 | www.flash.cn | — | CN | unknown |
2860 | DBE9FD0C-BFEA-4654-B6C5-378674AB1C6C | 23.195.135.167:443 | fpdownload.macromedia.com | Akamai International B.V. | NL | unknown |
440 | flashplayerpp_ax_install_cn_fc.exe | 104.111.214.232:443 | fusionpings.adobe.com | Akamai International B.V. | NL | whitelisted |
440 | flashplayerpp_ax_install_cn_fc.exe | 13.36.218.177:80 | stats.adobe.com | — | US | suspicious |
2860 | DBE9FD0C-BFEA-4654-B6C5-378674AB1C6C | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2860 | DBE9FD0C-BFEA-4654-B6C5-378674AB1C6C | 92.123.143.240:80 | fpdownload2.macromedia.com | Akamai International B.V. | — | suspicious |
2860 | DBE9FD0C-BFEA-4654-B6C5-378674AB1C6C | 67.26.75.254:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | suspicious |
1936 | 4EC3CFD5-7014-4A66-80BC-BE88B5AA4308 | 92.123.143.240:80 | fpdownload2.macromedia.com | Akamai International B.V. | — | suspicious |
884 | 17FECBD4-118D-4ED0-A225-9E8777D2790E | 42.63.21.158:80 | tongji.flash.cn | CHINA UNICOM China169 Backbone | CN | suspicious |
1936 | 4EC3CFD5-7014-4A66-80BC-BE88B5AA4308 | 23.195.135.167:443 | fpdownload.macromedia.com | Akamai International B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
www.flash.cn |
| whitelisted |
api.flash.cn |
| suspicious |
fusionpings.adobe.com |
| whitelisted |
stats.adobe.com |
| whitelisted |
fpdownload.macromedia.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
fpdownload2.macromedia.com |
| whitelisted |
tongji.flash.cn |
| whitelisted |
apifc.flash.cn |
| malicious |
Process | Message |
|---|---|
FlashCenter.exe | QSqlQuery::value: not positioned on a valid record
|
FlashCenter.exe | QSqlQuery::value: not positioned on a valid record
|
FlashCenter.exe | QSqlQuery::value: not positioned on a valid record
|
FlashCenter.exe | QSqlQuery::value: not positioned on a valid record
|
FlashCenter.exe | QSqlQuery::value: not positioned on a valid record
|
FlashCenter.exe | QSqlQuery::value: not positioned on a valid record
|
FlashCenter.exe | QObject::connect: Cannot connect CUrlEvent::signalUrlFinished(QString) to (null)::(null)
|
FlashCenter.exe | QObject::connect: Cannot connect CUrlEvent::signalUrlError(QString) to (null)::(null)
|
FlashCenter.exe | QObject::connect: Cannot connect CUrlEvent::signalUrlSSLError(QString) to (null)::(null)
|
FlashCenter.exe | QSqlQuery::value: not positioned on a valid record
|