| File name: | acrobat_set-up.exe |
| Full analysis: | https://app.any.run/tasks/7c7ee2b7-9d64-4041-b94e-d8600fcb375a |
| Verdict: | Malicious activity |
| Analysis date: | November 08, 2023, 23:14:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | 98D97D9154BBE26D7F782ECAEED793CA |
| SHA1: | B59AD202F18AC1F7D3A2D9F831DE167DBC4A9E15 |
| SHA256: | 9298BE4D761B35A733E7B7C59DCC82D27E77EC96A24BDF83086805685B02E77E |
| SSDEEP: | 98304:HeAynNf+mgjnZHldqdDeqbX6ojfCAICSmEYK5mIqaFiGZehZ2Hyt71wadjwTbKcW:HJxV7ZVy |
| .exe | | | UPX compressed Win32 Executable (43.5) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (42.7) |
| .exe | | | Win32 Executable (generic) (7.2) |
| .exe | | | Generic Win/DOS Executable (3.2) |
| .exe | | | DOS Executable Generic (3.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:09:14 10:25:13+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.33 |
| CodeSize: | 2981888 |
| InitializedDataSize: | 45056 |
| UninitializedDataSize: | 6918144 |
| EntryPoint: | 0x971930 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.12.0.20 |
| ProductVersionNumber: | 2.12.0.20 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Adobe Inc. |
| FileDescription: | Adobe Installer |
| FileVersion: | 2.12.0.20 |
| InternalName: | Adobe Installer |
| LegalCopyright: | © 2015-2023 Adobe. All rights reserved. |
| OriginalFileName: | Adobe Installer |
| ProductName: | Adobe Installer |
| ProductVersion: | 2.12.0.20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 712 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=3508 --field-trial-handle=1292,i,15889226947993471840,16146033902681815862,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 988 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.PageScreenshotProcessor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=3380 --field-trial-handle=1292,i,15889226947993471840,16146033902681815862,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1016 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3980 --field-trial-handle=1292,i,15889226947993471840,16146033902681815862,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1152 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1600 --field-trial-handle=1292,i,15889226947993471840,16146033902681815862,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1432 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4296 --field-trial-handle=1292,i,15889226947993471840,16146033902681815862,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1756 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=3356 --field-trial-handle=1292,i,15889226947993471840,16146033902681815862,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2324 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2388 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3836 --field-trial-handle=1292,i,15889226947993471840,16146033902681815862,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2400 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3536 --field-trial-handle=1292,i,15889226947993471840,16146033902681815862,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2724 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3552 --field-trial-handle=1292,i,15889226947993471840,16146033902681815862,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3220) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{BB20AA45-962A-4FD4-8302-2B2E16BA500A}\{DF589A83-8585-499A-AF34-7A3E0539F270} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3220) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{BB20AA45-962A-4FD4-8302-2B2E16BA500A} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3220) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{CE71C939-5A07-4E13-9F8E-76C7F2D1DF58} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3460) acrobat_set-up.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3460) acrobat_set-up.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3460) acrobat_set-up.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3460) acrobat_set-up.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3460) acrobat_set-up.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3460) acrobat_set-up.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3652) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3460 | acrobat_set-up.exe | C:\Users\admin\AppData\Roaming\com.adobe.dunamis\f65a88c9-12b3-4201-a633-87cf11b91fa8\v1\0\meta_events\37ab78ff-20da-4be5-a9dc-b012d8718e1c | — | |
MD5:— | SHA256:— | |||
| 3460 | acrobat_set-up.exe | C:\Users\admin\AppData\Roaming\com.adobe.dunamis\f65a88c9-12b3-4201-a633-87cf11b91fa8\v1\0\anon_events\86e90083-1fa7-4ec2-9443-0a0f31bc4842 | — | |
MD5:— | SHA256:— | |||
| 3460 | acrobat_set-up.exe | C:\Users\admin\AppData\Local\Temp\Adobe\com.adobe.dunamis\dunamis-2023-11-08_23-14-11.log | text | |
MD5:A651265A56983E38613CD77EDD5B77B1 | SHA256:F397B21F61F6A3B6D8D0A0D5F6B469636AD658B7A4BEC06272649DFA01DF5106 | |||
| 3460 | acrobat_set-up.exe | C:\Users\admin\AppData\Roaming\com.adobe.dunamis\f65a88c9-12b3-4201-a633-87cf11b91fa8\v1\0\meta_events\manifest | binary | |
MD5:335ECF8B087703C67A4831976CDD382C | SHA256:A0C08679CC6D6592ABCE004BB4CEC199AECDE68678E9B9A634C01DA37D58A7DD | |||
| 3652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF16a5f9.TMP | — | |
MD5:— | SHA256:— | |||
| 3652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3460 | acrobat_set-up.exe | C:\Users\admin\AppData\Local\Temp\{151279F8-69C0-422B-817B-C81426D38FAE}\CCDInstaller.js | binary | |
MD5:E96BB3DA47F4A3319B80F23051BDEB16 | SHA256:D69D7E68A706C60146A5B530368D7818599DBD39D071F181963A89945CFF3C29 | |||
| 3460 | acrobat_set-up.exe | C:\Users\admin\AppData\Local\Temp\{151279F8-69C0-422B-817B-C81426D38FAE}\index.html | html | |
MD5:A28AB17B18FF254173DFEEF03245EFD0 | SHA256:886C0AB69E6E9D9D5B5909451640EA587ACCFCDF11B8369CAD8542D1626AC375 | |||
| 3460 | acrobat_set-up.exe | C:\Users\admin\AppData\Local\Temp\{151279F8-69C0-422B-817B-C81426D38FAE}\index.css | text | |
MD5:F8CB3329D8F3E59E61F4A2AAF100A4C3 | SHA256:5553856DA917ED6BF09DC1EAFBB336C22930FEC4B2383D3A5E9D76E19F39A9A6 | |||
| 3460 | acrobat_set-up.exe | C:\Users\admin\AppData\Local\Temp\dat6EAD.tmp | binary | |
MD5:FA794EC12D353C26805FF53821331FC2 | SHA256:CFDBD8A2AA463C11E483DC10C480ACD274E9786632F5571A3970E8A20A2D8237 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3764 | msedge.exe | GET | 301 | 2.21.20.214:80 | http://www.adobe.com/go/download_APRO_en_US?mv=product&mv2=accc | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3652 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3764 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3764 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3764 | msedge.exe | 2.21.20.214:80 | www.adobe.com | Akamai International B.V. | DE | unknown |
3764 | msedge.exe | 2.21.20.214:443 | www.adobe.com | Akamai International B.V. | DE | unknown |
3764 | msedge.exe | 108.138.26.12:443 | creativecloud.adobe.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.adobe.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
creativecloud.adobe.com |
| whitelisted |
wwwimages.adobe.com |
| whitelisted |
assets.adobedtm.com |
| whitelisted |
adobeid-na1.services.adobe.com |
| whitelisted |
use.typekit.net |
| whitelisted |
geo2.adobe.com |
| whitelisted |
www.youtube.com |
| whitelisted |