File name:

opener(1).exe

Full analysis: https://app.any.run/tasks/3394d377-7319-437d-80de-c86d81cba82a
Verdict: Malicious activity
Analysis date: May 09, 2025, 11:27:27
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
python
evasion
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

C1EB92FEE8B6423ED79570F75D519152

SHA1:

63F41AA86943FEE372D45D26B97B0B8693EFDC89

SHA256:

85D3B43C024F732E55D49A04DBC9DAEB0231F9D92E9ECBDC5DD19BE39F069736

SSDEEP:

98304:BKY7YbSb4Y6ZhkDQet54nHZUMtHfktEzafhOsE+XZ0Ommp43vOrPKjejYuAnZCrl:+crfk881mw2/ki73V

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops python dynamic module

      • opener(1).exe (PID: 5256)
    • Executable content was dropped or overwritten

      • opener(1).exe (PID: 5256)
      • CCleaner64.exe (PID: 7616)
      • CCleaner64.exe (PID: 7768)
      • uninstall.exe (PID: 9416)
      • Un_A.exe (PID: 9820)
      • CCleaner64.exe (PID: 8400)
    • Process drops legitimate windows executable

      • opener(1).exe (PID: 5256)
    • Application launched itself

      • opener(1).exe (PID: 5256)
      • AdobeCollabSync.exe (PID: 6476)
      • Acrobat.exe (PID: 7704)
      • CCleaner64.exe (PID: 7604)
      • CCleaner64.exe (PID: 5956)
      • CCleaner64.exe (PID: 7768)
      • CCleaner64.exe (PID: 7616)
    • The process drops C-runtime libraries

      • opener(1).exe (PID: 5256)
    • Loads Python modules

      • opener(1).exe (PID: 2384)
    • Reads security settings of Internet Explorer

      • AdobeCollabSync.exe (PID: 6476)
      • Eula.exe (PID: 6272)
      • AdobeCollabSync.exe (PID: 7724)
      • CCleaner64.exe (PID: 5956)
      • CCleaner64.exe (PID: 7604)
      • CCleaner64.exe (PID: 7768)
      • CCleaner64.exe (PID: 7616)
      • OfficeC2RClient.exe (PID: 2108)
      • officesvcmgr.exe (PID: 5400)
      • OfficeC2RClient.exe (PID: 8816)
      • IntegratedOffice.exe (PID: 8284)
      • culauncher.exe (PID: 9204)
    • Reads Microsoft Outlook installation path

      • Eula.exe (PID: 6272)
    • Reads Internet Explorer settings

      • Eula.exe (PID: 6272)
      • CCleaner64.exe (PID: 7616)
      • CCleaner64.exe (PID: 7768)
    • Executes application which crashes

      • adobe_licensing_wf_helper_acro.exe (PID: 7472)
      • chrome_pwa_launcher.exe (PID: 9608)
    • Reads the date of Windows installation

      • CCleaner64.exe (PID: 5956)
      • CCleaner64.exe (PID: 7604)
      • CCleaner64.exe (PID: 7768)
      • CCleaner64.exe (PID: 7616)
    • Searches for installed software

      • CCleaner64.exe (PID: 7616)
      • OfficeC2RClient.exe (PID: 8816)
      • OfficeC2RClient.exe (PID: 8432)
    • Checks for external IP

      • CCleaner64.exe (PID: 7768)
      • CCleaner64.exe (PID: 7616)
    • Starts itself from another location

      • uninstall.exe (PID: 9416)
  • INFO

    • Checks supported languages

      • opener(1).exe (PID: 5256)
      • opener(1).exe (PID: 2384)
      • AcrobatInfo.exe (PID: 3332)
      • acrobat_sl.exe (PID: 4200)
      • AcroBroker.exe (PID: 2504)
      • AcroTextExtractor.exe (PID: 5204)
      • ADNotificationManager.exe (PID: 960)
      • AdobeCollabSync.exe (PID: 6476)
      • CRWindowsClientService.exe (PID: 5556)
      • CRLogTransport.exe (PID: 2108)
      • Eula.exe (PID: 6272)
      • SingleClientServicesUpdater.exe (PID: 7184)
      • adobe_licensing_wf_helper_acro.exe (PID: 7472)
      • SingleClientServicesUpdater.exe (PID: 7296)
      • WCChromeNativeMessagingHost.exe (PID: 7344)
      • adobe_licensing_wf_acro.exe (PID: 7352)
      • AcroCEF.exe (PID: 7148)
      • Acrobat.exe (PID: 7364)
      • FullTrustNotifier.exe (PID: 7608)
      • AdobeCollabSync.exe (PID: 7724)
      • Acrobat.exe (PID: 7704)
      • MSRMSPIBroker.exe (PID: 7600)
      • 64BitMAPIBroker.exe (PID: 7524)
      • 32BitMAPIBroker.exe (PID: 7488)
      • CCleanerReactivator.exe (PID: 632)
      • CCleaner.exe (PID: 8188)
      • CCleaner64.exe (PID: 5956)
      • CCleaner64.exe (PID: 7604)
      • wa_3rd_party_host_64.exe (PID: 6972)
      • CCleaner64.exe (PID: 7616)
      • CCleaner64.exe (PID: 7768)
      • CCleanerBugReport.exe (PID: 8148)
      • CCleanerPerformanceOptimizerService.exe (PID: 1128)
      • AppVShNotify.exe (PID: 6512)
      • InspectorOfficeGadget.exe (PID: 5756)
      • appvcleaner.exe (PID: 5436)
      • officesvcmgr.exe (PID: 5400)
      • IntegratedOffice.exe (PID: 1764)
      • MavInject32.exe (PID: 7184)
      • OfficeClickToRun.exe (PID: 7436)
      • AppVShNotify.exe (PID: 7968)
      • OfficeC2RClient.exe (PID: 2108)
      • MavInject32.exe (PID: 8328)
      • InspectorOfficeGadget.exe (PID: 2800)
      • appvcleaner.exe (PID: 2552)
      • InputPersonalization.exe (PID: 8756)
      • OfficeC2RClient.exe (PID: 8816)
      • OfficeC2RClient.exe (PID: 8440)
      • IntegratedOffice.exe (PID: 8284)
      • IMESharePointDictionary.exe (PID: 8664)
      • OfficeClickToRun.exe (PID: 8608)
      • msinfo32.exe (PID: 9092)
      • ShapeCollector.exe (PID: 8884)
      • mip.exe (PID: 8804)
      • VSTOInstaller.exe (PID: 9148)
      • ShapeCollector.exe (PID: 9032)
      • LICLUA.EXE (PID: 9132)
      • culauncher.exe (PID: 9204)
      • OfficeC2RClient.exe (PID: 8432)
      • CCleaner64.exe (PID: 8300)
    • Reads the computer name

      • opener(1).exe (PID: 5256)
      • AcroBroker.exe (PID: 2504)
      • AdobeCollabSync.exe (PID: 6476)
      • Eula.exe (PID: 6272)
      • AdobeCollabSync.exe (PID: 7724)
      • FullTrustNotifier.exe (PID: 7608)
      • Acrobat.exe (PID: 7364)
      • Acrobat.exe (PID: 7704)
      • CCleaner.exe (PID: 8188)
      • CCleaner64.exe (PID: 5956)
      • CCleaner64.exe (PID: 7604)
      • CCleanerBugReport.exe (PID: 8148)
      • CCleaner64.exe (PID: 7616)
      • CCleanerPerformanceOptimizerService.exe (PID: 1128)
      • CCleaner64.exe (PID: 7768)
      • AppVShNotify.exe (PID: 6512)
      • InspectorOfficeGadget.exe (PID: 5756)
      • AppVShNotify.exe (PID: 7968)
      • InspectorOfficeGadget.exe (PID: 2800)
      • officesvcmgr.exe (PID: 5400)
      • InputPersonalization.exe (PID: 8756)
      • OfficeC2RClient.exe (PID: 8816)
      • IntegratedOffice.exe (PID: 1764)
      • mip.exe (PID: 8804)
      • ShapeCollector.exe (PID: 8884)
      • msinfo32.exe (PID: 9092)
      • LICLUA.EXE (PID: 9132)
      • CCleaner64.exe (PID: 8300)
    • Create files in a temporary directory

      • opener(1).exe (PID: 5256)
      • OfficeC2RClient.exe (PID: 2108)
      • OfficeClickToRun.exe (PID: 7436)
      • OfficeC2RClient.exe (PID: 8816)
      • OfficeC2RClient.exe (PID: 8432)
    • The sample compiled with english language support

      • opener(1).exe (PID: 5256)
      • CCleaner64.exe (PID: 7616)
      • CCleaner64.exe (PID: 7768)
      • CCleaner64.exe (PID: 8400)
      • uninstall.exe (PID: 9416)
    • Application launched itself

      • Acrobat.exe (PID: 300)
      • Acrobat.exe (PID: 5972)
      • AcroCEF.exe (PID: 7192)
      • chrome.exe (PID: 9780)
      • chrome.exe (PID: 9452)
    • Checks proxy server information

      • AdobeCollabSync.exe (PID: 6476)
      • Eula.exe (PID: 6272)
      • AdobeCollabSync.exe (PID: 7724)
      • OfficeC2RClient.exe (PID: 2108)
      • OfficeClickToRun.exe (PID: 7436)
      • officesvcmgr.exe (PID: 5400)
      • OfficeC2RClient.exe (PID: 8816)
      • IntegratedOffice.exe (PID: 8284)
    • Creates files or folders in the user directory

      • AdobeCollabSync.exe (PID: 7724)
      • WerFault.exe (PID: 7856)
      • InputPersonalization.exe (PID: 8756)
    • Reads the machine GUID from the registry

      • AdobeCollabSync.exe (PID: 7724)
      • CCleanerBugReport.exe (PID: 8148)
      • CCleaner64.exe (PID: 7616)
      • appvcleaner.exe (PID: 5436)
      • InspectorOfficeGadget.exe (PID: 5756)
      • CCleaner64.exe (PID: 7768)
      • InspectorOfficeGadget.exe (PID: 2800)
      • appvcleaner.exe (PID: 2552)
      • culauncher.exe (PID: 9204)
    • Reads Environment values

      • CCleaner.exe (PID: 8188)
      • CCleaner64.exe (PID: 5956)
      • CCleaner64.exe (PID: 7604)
      • CCleaner64.exe (PID: 7616)
      • CCleaner64.exe (PID: 7768)
      • culauncher.exe (PID: 9204)
      • CCleaner64.exe (PID: 8300)
    • Process checks computer location settings

      • CCleaner64.exe (PID: 5956)
      • CCleaner64.exe (PID: 7604)
      • OfficeC2RClient.exe (PID: 2108)
      • OfficeC2RClient.exe (PID: 8816)
      • CCleaner64.exe (PID: 7616)
      • CCleaner64.exe (PID: 7768)
      • IntegratedOffice.exe (PID: 8284)
      • OfficeC2RClient.exe (PID: 8432)
    • Reads CPU info

      • CCleanerBugReport.exe (PID: 8148)
      • CCleaner64.exe (PID: 7616)
      • CCleaner64.exe (PID: 7768)
    • Reads product name

      • CCleaner64.exe (PID: 7616)
      • CCleaner64.exe (PID: 7768)
    • Reads Microsoft Office registry keys

      • OfficeC2RClient.exe (PID: 2108)
      • OfficeClickToRun.exe (PID: 7436)
      • IntegratedOffice.exe (PID: 8284)
      • IntegratedOffice.exe (PID: 1764)
      • officesvcmgr.exe (PID: 5400)
      • OfficeC2RClient.exe (PID: 8816)
      • OfficeC2RClient.exe (PID: 8432)
    • Reads the software policy settings

      • CCleaner64.exe (PID: 7768)
      • CCleaner64.exe (PID: 7616)
      • IntegratedOffice.exe (PID: 1764)
      • culauncher.exe (PID: 9204)
    • FileZilla executable

      • uninstall.exe (PID: 9416)
      • opener(1).exe (PID: 2384)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:05:09 11:14:32+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 172032
InitializedDataSize: 154624
UninitializedDataSize: -
EntryPoint: 0xce10
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
274
Monitored processes
144
Malicious processes
6
Suspicious processes
3

Behavior graph

Click at the process to see the details
start opener(1).exe opener(1).exe no specs acrobat.exe acrobatinfo.exe no specs acrobat_sl.exe no specs acrobat.exe no specs acrobroker.exe no specs acrocef.exe no specs acrotextextractor.exe no specs adelrcp.exe no specs adnotificationmanager.exe no specs adobecollabsync.exe no specs crlogtransport.exe no specs acrobat.exe no specs crwindowsclientservice.exe no specs conhost.exe no specs eula.exe no specs logtransport2.exe no specs acrobat.exe no specs conhost.exe no specs acrocef.exe no specs singleclientservicesupdater.exe no specs acrocef.exe no specs singleclientservicesupdater.exe no specs wcchromenativemessaginghost.exe no specs adobe_licensing_wf_acro.exe no specs conhost.exe no specs adobe_licensing_wf_helper_acro.exe 32bitmapibroker.exe no specs 64bitmapibroker.exe no specs msrmspibroker.exe no specs fulltrustnotifier.exe no specs acrobat.exe no specs adobecollabsync.exe no specs werfault.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe acrocef.exe no specs acrocef.exe no specs ccleaner.exe no specs acrocef.exe no specs acrobat.exe no specs ccleaner64.exe no specs ccleaner64.exe no specs sppextcomobj.exe no specs slui.exe no specs ccleanerbugreport.exe no specs conhost.exe no specs ccleanerperformanceoptimizerservice.exe no specs conhost.exe no specs ccleanerreactivator.exe no specs ccupdate.exe no specs uninst.exe no specs wa_3rd_party_host_64.exe no specs conhost.exe no specs setup.exe no specs ccleaner64.exe ccleaner64.exe windowsinstaller-kb893803-v2-x86.exe no specs setup.exe no specs windowsinstaller-kb893803-v2-x86.exe no specs appvcleaner.exe no specs appvshnotify.exe no specs inspectorofficegadget.exe no specs conhost.exe no specs integratedoffice.exe mavinject32.exe no specs officec2rclient.exe officeclicktorun.exe officesvcmgr.exe acrocef.exe no specs conhost.exe no specs appvcleaner.exe no specs appvshnotify.exe no specs inspectorofficegadget.exe no specs conhost.exe no specs integratedoffice.exe mavinject32.exe no specs officec2rclient.exe no specs officeclicktorun.exe no specs officesvcmgr.exe no specs imesharepointdictionary.exe no specs conhost.exe no specs inputpersonalization.exe no specs mip.exe no specs officec2rclient.exe shapecollector.exe no specs tabtip.exe no specs shapecollector.exe no specs msinfo32.exe no specs liclua.exe no specs vstoinstaller.exe no specs culauncher.exe no specs filezilla.exe no specs officec2rclient.exe ccleaner64.exe ccleaner64.exe fzputtygen.exe no specs conhost.exe no specs fzsftp.exe no specs conhost.exe no specs fzstorj.exe no specs uninstall.exe conhost.exe no specs chrome.exe no specs chrome_proxy.exe no specs chrome_pwa_launcher.exe elevation_service.exe no specs notification_helper.exe no specs chrome.exe no specs chrmstp.exe no specs un_a.exe setup.exe no specs extexport.exe no specs werfault.exe no specs iediagcmd.exe no specs conhost.exe no specs ieinstal.exe no specs ielowutil.exe no specs iexplore.exe no specs jabswitch.exe no specs conhost.exe no specs java-rmi.exe no specs java.exe no specs conhost.exe no specs javacpl.exe no specs conhost.exe no specs javaw.exe no specs chrome.exe no specs javaws.exe no specs javaw.exe no specs jjs.exe no specs jp2launcher.exe no specs chrome.exe no specs conhost.exe no specs keytool.exe no specs conhost.exe no specs kinit.exe no specs conhost.exe no specs klist.exe no specs conhost.exe no specs ktab.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
opener(1).exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
632"C:\Program Files\CCleaner\CCleanerReactivator.exe"C:\Program Files\CCleaner\CCleanerReactivator.exeopener(1).exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
CCleaner Reactivator
Exit code:
0
Version:
6.20.0.10897
Modules
Images
c:\program files\ccleaner\ccleanerreactivator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files\ccleaner\ccleanerreactivator.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
644\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exefzsftp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
728"C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe"C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exeopener(1).exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
LogTransport Application
Exit code:
4294967295
Version:
8.8.0.5
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\logtransport2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
960"C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe"C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exeopener(1).exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe Acrobat
Exit code:
0
Version:
15.0.0.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\adnotificationmanager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
976"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" --type=renderer /prefetch:1 /l /slModeC:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1128"C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe"C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exeopener(1).exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
CCleaner Performance Optimizer Service
Exit code:
0
Version:
6.20.0.10897
Modules
Images
c:\program files\ccleaner\ccleanerperformanceoptimizerservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1228"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" --type=renderer /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1568"C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-FF00-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe"C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-FF00-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exeopener(1).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Update Package
Exit code:
3221226540
Version:
3.1
Modules
Images
c:\program files\common files\adobe\acrobat\setup\{ac76ba86-1033-ff00-7760-bc15014ea700}\windowsinstaller-kb893803-v2-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1764"C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe"C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exeopener(1).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Update Package
Exit code:
3221226540
Version:
3.1
Modules
Images
c:\program files\common files\adobe\acrobat\setup\{ac76ba86-1033-1033-7760-bc15014ea700}\windowsinstaller-kb893803-v2-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
57 199
Read events
56 768
Write events
319
Delete events
112

Modification events

(PID) Process:(5972) Acrobat.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-2034283098-2252572593-1072577386-2659511007-3245387615-27016815-3920691934
Operation:writeName:DisplayName
Value:
Adobe Acrobat Reader Protected Mode
(PID) Process:(5972) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Privileged
Operation:writeName:bProtectedMode
Value:
1
(PID) Process:(300) Acrobat.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-2034283098-2252572593-1072577386-2659511007-3245387615-27016815-3920691934
Operation:writeName:DisplayName
Value:
Adobe Acrobat Reader Protected Mode
(PID) Process:(6476) AdobeCollabSync.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Privileged
Operation:writeName:syncFolderSetupDone
Value:
1
(PID) Process:(1228) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ExitSection
Operation:writeName:bLastExitNormal
Value:
0
(PID) Process:(6272) Eula.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6272) Eula.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6272) Eula.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6272) Eula.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
Operation:writeName:Version
Value:
WS not running
(PID) Process:(6272) Eula.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
Executable files
60
Suspicious files
144
Text files
15
Unknown types
0

Dropped files

PID
Process
Filename
Type
5256opener(1).exeC:\Users\admin\AppData\Local\Temp\_MEI52562\_bz2.pydexecutable
MD5:684D656AADA9F7D74F5A5BDCF16D0EDB
SHA256:A5DFB4A663DEF3D2276B88866F6D220F6D30CC777B5D841CF6DBB15C6858017C
5256opener(1).exeC:\Users\admin\AppData\Local\Temp\_MEI52562\_socket.pydexecutable
MD5:566CB4D39B700C19DBD7175BD4F2B649
SHA256:77EBA293FE03253396D7BB6E575187CD026C80766D7A345EB72AD92F0BBBC3AA
5256opener(1).exeC:\Users\admin\AppData\Local\Temp\_MEI52562\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:E8B9D74BFD1F6D1CC1D99B24F44DA796
SHA256:B1B3FD40AB437A43C8DB4994CCFFC7F88000CC8BB6E34A2BCBFF8E2464930C59
5256opener(1).exeC:\Users\admin\AppData\Local\Temp\_MEI52562\_lzma.pydexecutable
MD5:D63E2E743EA103626D33B3C1D882F419
SHA256:7C2D2030D5D246739C5D85F087FCF404BC36E1815E69A8AC7C9541267734FC28
5256opener(1).exeC:\Users\admin\AppData\Local\Temp\_MEI52562\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:EB0978A9213E7F6FDD63B2967F02D999
SHA256:AB25A1FE836FC68BCB199F1FE565C27D26AF0C390A38DA158E0D8815EFE1103E
5256opener(1).exeC:\Users\admin\AppData\Local\Temp\_MEI52562\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:33BBECE432F8DA57F17BF2E396EBAA58
SHA256:7CF0944901F7F7E0D0B9AD62753FC2FE380461B1CCE8CDC7E9C9867C980E3B0E
5256opener(1).exeC:\Users\admin\AppData\Local\Temp\_MEI52562\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:CFE0C1DFDE224EA5FED9BD5FF778A6E0
SHA256:0D0F80CBF476AF5B1C9FD3775E086ED0DFDB510CD0CC208EC1CCB04572396E3E
5256opener(1).exeC:\Users\admin\AppData\Local\Temp\_MEI52562\api-ms-win-core-handle-l1-1-0.dllexecutable
MD5:E89CDCD4D95CDA04E4ABBA8193A5B492
SHA256:1A489E0606484BD71A0D9CB37A1DC6CA8437777B3D67BFC8C0075D0CC59E6238
5256opener(1).exeC:\Users\admin\AppData\Local\Temp\_MEI52562\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:1C58526D681EFE507DEB8F1935C75487
SHA256:EF13DCE8F71173315DFC64AB839B033AB19A968EE15230E9D4D2C9D558EFEEE2
5256opener(1).exeC:\Users\admin\AppData\Local\Temp\_MEI52562\api-ms-win-core-file-l2-1-0.dllexecutable
MD5:BFFFA7117FD9B1622C66D949BAC3F1D7
SHA256:1EA267A2E6284F17DD548C6F2285E19F7EDB15D6E737A55391140CE5CB95225E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
37
DNS requests
22
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7616
CCleaner64.exe
GET
200
23.48.23.31:80
http://ncc.avast.com/ncc.txt
unknown
whitelisted
7768
CCleaner64.exe
GET
200
23.48.23.31:80
http://ncc.avast.com/ncc.txt
unknown
whitelisted
8400
CCleaner64.exe
GET
200
23.48.23.31:80
http://ncc.avast.com/ncc.txt
unknown
whitelisted
8300
CCleaner64.exe
GET
200
23.48.23.31:80
http://ncc.avast.com/ncc.txt
unknown
whitelisted
7768
CCleaner64.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
7768
CCleaner64.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAXfj0A2M0oL7zuU%2F%2F2jetU%3D
unknown
whitelisted
7616
CCleaner64.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAXfj0A2M0oL7zuU%2F%2F2jetU%3D
unknown
whitelisted
7768
CCleaner64.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7616
CCleaner64.exe
23.48.23.31:80
ncc.avast.com
Akamai International B.V.
DE
whitelisted
7768
CCleaner64.exe
23.48.23.31:80
ncc.avast.com
Akamai International B.V.
DE
whitelisted
7948
AcroCEF.exe
23.213.164.167:443
geo2.adobe.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
ncc.avast.com
  • 23.48.23.31
  • 23.48.23.10
whitelisted
geo2.adobe.com
  • 23.213.164.167
whitelisted
p13n.adobe.io
  • 52.202.204.11
  • 23.22.254.206
  • 54.227.187.23
  • 52.5.13.197
whitelisted
officeclient.microsoft.com
  • 52.109.32.97
whitelisted
analytics.avcdn.net
  • 34.117.223.223
whitelisted

Threats

PID
Process
Class
Message
7616
CCleaner64.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
7768
CCleaner64.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
2196
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
No debug info