| File name: | flashplayer_install_cn.exe |
| Full analysis: | https://app.any.run/tasks/e834c191-6d76-40c8-aed8-ffa554806b7c |
| Verdict: | Malicious activity |
| Analysis date: | July 23, 2021, 10:04:23 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 6A465EFC602AFC2636643C2462CC52F1 |
| SHA1: | 02EEAB6D4EDCC1716C49F74665B31B630B320D1F |
| SHA256: | 84FC0009A1DC691228F46FC1D88A00D6AB4B20298F948681CA27E6319ED0D38A |
| SSDEEP: | 49152:284K0AkoYFr7EzfWuJWpvHsfhKer4jgGAje+coxjo1SbEnWf5BIECvrFhBtaccAP:2toYp4qHsfoerG+Lcg81SbEnWfHfCzBL |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| Subsystem: | Windows GUI |
|---|---|
| SubsystemVersion: | 5.1 |
| ImageVersion: | - |
| OSVersion: | 5.1 |
| EntryPoint: | 0x1eef0 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 76800 |
| CodeSize: | 201728 |
| LinkerVersion: | 14 |
| PEType: | PE32 |
| TimeStamp: | 2021:06:11 11:16:47+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 11-Jun-2021 09:16:47 |
| Detected languages: |
|
| Debug artifacts: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000110 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 11-Jun-2021 09:16:47 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000313BA | 0x00031400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.70981 |
.rdata | 0x00033000 | 0x0000A622 | 0x0000A800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.22268 |
.data | 0x0003E000 | 0x00023728 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.70882 |
.didat | 0x00062000 | 0x0000018C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.35543 |
.rsrc | 0x00063000 | 0x00004CC0 | 0x00004E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.78174 |
.reloc | 0x00068000 | 0x0000227C | 0x00002400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.56418 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.25329 | 1875 | Latin 1 / Western European | Chinese - PRC | RT_MANIFEST |
7 | 5.24197 | 182 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
8 | 5.27357 | 214 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
9 | 5.21038 | 188 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
10 | 5.11103 | 116 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
11 | 5.38329 | 642 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
12 | 4.71863 | 148 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
13 | 4.90272 | 136 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
14 | 4.39475 | 124 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
15 | 4.33363 | 82 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
KERNEL32.dll |
USER32.dll (delay-loaded) |
gdiplus.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 568 | "C:\Users\admin\AppData\Local\Temp\flashplayer_install_cn.exe" | C:\Users\admin\AppData\Local\Temp\flashplayer_install_cn.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2924 | "C:\windows\temp\flashplayerpp_ax_install_cn_fc.exe" | C:\windows\temp\flashplayerpp_ax_install_cn_fc.exe | flashplayer_install_cn.exe | ||||||||||||
User: admin Company: Adobe Inc Integrity Level: MEDIUM Description: Adobe Download Manager Exit code: 0 Version: 3.0.0.616s Modules
| |||||||||||||||
| 3584 | "C:\windows\temp\flashplayerpp_ax_install_cn_fc.exe" --pipename={4EAD5177-CC93-4731-B4D7-0C3A96FB9506} --type=web --pid=2924 --isrunbyfc=false | C:\windows\temp\flashplayerpp_ax_install_cn_fc.exe | flashplayerpp_ax_install_cn_fc.exe | ||||||||||||
User: admin Company: Adobe Inc Integrity Level: HIGH Description: Adobe Download Manager Exit code: 0 Version: 3.0.0.616s Modules
| |||||||||||||||
| (PID) Process: | (568) flashplayer_install_cn.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (568) flashplayer_install_cn.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (568) flashplayer_install_cn.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (568) flashplayer_install_cn.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2924) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2924) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2924) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2924) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2924) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2924) flashplayerpp_ax_install_cn_fc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 568 | flashplayer_install_cn.exe | C:\windows\temp\1.ico | image | |
MD5:— | SHA256:— | |||
| 568 | flashplayer_install_cn.exe | C:\windows\temp\flashplayerpp_ax_install_cn_fc.exe | executable | |
MD5:— | SHA256:— | |||
| 568 | flashplayer_install_cn.exe | C:\windows\temp\payload.exe | executable | |
MD5:— | SHA256:— | |||
| 2924 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\2E59C96D-25A8-42E8-8BD1-BC3931E87386\status_icon_caution_100.png | image | |
MD5:56F804DB5509B1CF08BE5C994AFC2322 | SHA256:C4768FC9A84B0D3ECDEEE93820703D769737B992EFD1F0CBE9F7A9D3BBDFA0FB | |||
| 2924 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Temp\Adobe_CDMLogs\Adobe_CDM.log | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 2924 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\2E59C96D-25A8-42E8-8BD1-BC3931E87386\warning_icon.png | image | |
MD5:DE6D8A7F831194025F1CCF4B7054E6E5 | SHA256:0E7D5E9CF99C1D02047153D81A3C2A2C30CF8E15122776E0C0A982A036A48091 | |||
| 2924 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\2E59C96D-25A8-42E8-8BD1-BC3931E87386\status_icon_caution_150.png | image | |
MD5:CA3872EAE64C5BFD8D41198990B11950 | SHA256:3438623C461F8F141976A931D3C00F6877D07CF4A8B534AF1EF9FDFE8B0C6174 | |||
| 2924 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\2E59C96D-25A8-42E8-8BD1-BC3931E87386\status_icon_x_200.png | image | |
MD5:40A32023DBFCCA1A80B69408735E15C2 | SHA256:D5A9BFE6D64F5C09F1DE3DCC74B30520DB5F78BCC6FC1E9A87EB141D9B46EA61 | |||
| 2924 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\2E59C96D-25A8-42E8-8BD1-BC3931E87386\status_icon_caution_200.png | image | |
MD5:213238D4F6EFEC2B8CD0D76D318EBF8E | SHA256:90B2DCFA026B942AF56635150A0E7A28FBF111C4790519B8F43EECE8EB287FB7 | |||
| 2924 | flashplayerpp_ax_install_cn_fc.exe | C:\Users\admin\AppData\Local\Adobe\2E59C96D-25A8-42E8-8BD1-BC3931E87386\status_icon_caution_125.png | image | |
MD5:4A2BF8C96F910B1B2AE63A9F4A0D4B8F | SHA256:0CB2F4EE1C451A8825EB8EDB45858B28345F73423C7A7AEF4168C46F7E3638BF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2924 | flashplayerpp_ax_install_cn_fc.exe | GET | 302 | 15.236.176.210:80 | http://stats.adobe.com/b/ss/adbacdcprod/1/H.25.4/s15631549016195?AQB=1&ndh=1&t=23%2F6%2F2021%2011%3A4%3A53%205%20-60&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_launched&g=res%3A%2F%2FC%3A%5Cwindows%5Ctemp%5Cflashplayerpp_ax_install_cn_fc.exe%2F319&ch=acdc_flashplayer&events=event96&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_launched&v18=new&v22=friday%20-%204%3A00am&v73=acdc_flashplayer&s=1280x720&c=32&j=1.5&v=Y&k=N&bw=622&bh=402&ct=lan&hp=Y&AQE=1 | US | — | — | whitelisted |
2924 | flashplayerpp_ax_install_cn_fc.exe | GET | 200 | 15.236.176.210:80 | http://stats.adobe.com/b/ss/adbacdcprod/1/H.25.4/s15631549016195?AQB=1&pccr=true&vidn=307D4A22B59F0411-60001F0CC25EB9AB&ndh=1&t=23%2F6%2F2021%2011%3A4%3A53%205%20-60&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_launched&g=res%3A%2F%2FC%3A%5Cwindows%5Ctemp%5Cflashplayerpp_ax_install_cn_fc.exe%2F319&ch=acdc_flashplayer&events=event96&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_launched&v18=new&v22=friday%20-%204%3A00am&v73=acdc_flashplayer&s=1280x720&c=32&j=1.5&v=Y&k=N&bw=622&bh=402&ct=lan&hp=Y&AQE=1 | US | image | 43 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2924 | flashplayerpp_ax_install_cn_fc.exe | 180.97.251.174:443 | www.flash.cn | No.31,Jin-rong Street | CN | unknown |
2924 | flashplayerpp_ax_install_cn_fc.exe | 203.205.224.59:443 | api.flash.cn | Tencent Building, Kejizhongyi Avenue | CN | suspicious |
2924 | flashplayerpp_ax_install_cn_fc.exe | 104.111.214.232:443 | fusionpings.adobe.com | Akamai International B.V. | NL | whitelisted |
— | — | 180.97.251.174:443 | www.flash.cn | No.31,Jin-rong Street | CN | unknown |
2924 | flashplayerpp_ax_install_cn_fc.exe | 15.236.176.210:80 | stats.adobe.com | Hewlett-Packard Company | US | suspicious |
2924 | flashplayerpp_ax_install_cn_fc.exe | 180.97.251.173:443 | www.flash.cn | No.31,Jin-rong Street | CN | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.flash.cn |
| whitelisted |
api.flash.cn |
| suspicious |
fusionpings.adobe.com |
| whitelisted |
stats.adobe.com |
| whitelisted |