| File name: | ADBAppControl-1.8.3.zip |
| Full analysis: | https://app.any.run/tasks/b1a15252-449a-417b-88da-282115294d1b |
| Verdict: | Malicious activity |
| Analysis date: | October 31, 2023, 23:47:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 18AC0E92F8CB54D34E48126B7BAE2991 |
| SHA1: | 39FAAE068C920BB80A445CF0D48E8EDBBBD38C81 |
| SHA256: | 95194364E0076116008B04E80EDCF520A7ED172062C362949014F96E40E64B3B |
| SSDEEP: | 98304:biMjSLmcs/2Mi4Ql+RzPHkEoXyoannL5hRjGyUudW/1SSlkxayEk88xBsrZo90XP:FmvPM1oskbIUtY18 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2023:07:08 09:46:36 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | adb/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | "C:\Users\admin\Desktop\adb\adb.exe" devices | C:\Users\admin\Desktop\adb\adb.exe | — | ADBAppControl.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 372 | "C:\Users\admin\Desktop\ADBAppControl.exe" | C:\Users\admin\Desktop\ADBAppControl.exe | — | explorer.exe | |||||||||||
User: admin Company: Cyber.Cat Integrity Level: MEDIUM Description: ADB AppControl Exit code: 0 Version: 1.8.3 Modules
| |||||||||||||||
| 1036 | "C:\Users\admin\Desktop\adb\adb.exe" devices | C:\Users\admin\Desktop\adb\adb.exe | — | ADBAppControl.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1840 | "C:\Users\admin\Desktop\adb\adb.exe" devices -l | C:\Users\admin\Desktop\adb\adb.exe | — | ADBAppControl.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2004 | adb -L tcp:5037 fork-server server --reply-fd 216 | C:\Users\admin\Desktop\adb\adb.exe | — | adb.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2232 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ADBAppControl-1.8.3.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3032 | "C:\Users\admin\Desktop\ADBAppControl.exe" | C:\Users\admin\Desktop\ADBAppControl.exe | explorer.exe | ||||||||||||
User: admin Company: Cyber.Cat Integrity Level: HIGH Description: ADB AppControl Exit code: 0 Version: 1.8.3 Modules
| |||||||||||||||
| 3540 | "C:\Users\admin\Desktop\adb\adb.exe" devices -l | C:\Users\admin\Desktop\adb\adb.exe | — | ADBAppControl.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3960 | "C:\Users\admin\Desktop\ADBAppControl.exe" | C:\Users\admin\Desktop\ADBAppControl.exe | explorer.exe | ||||||||||||
User: admin Company: Cyber.Cat Integrity Level: MEDIUM Description: ADB AppControl Exit code: 0 Version: 1.8.3 Modules
| |||||||||||||||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3960) ADBAppControl.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3032) ADBAppControl.exe | Key: | HKEY_CURRENT_USER\Software\AdbAppControl |
| Operation: | write | Name: | Locale |
Value: en | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\AdbWinUsbApi.dll | executable | |
MD5:F67D9EC28D19316754D7ECB0E990197D | SHA256:13918FDAB0C3AC77D077453A6036247CFECA10910AEC845F188C41148C630BB2 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\bg.tsv | text | |
MD5:354FEB9C2ADDEAB5D510899C27FB1DBC | SHA256:0E0E7FCD36ACB2A25275978EA52DCFF2CCFC74B84961D69FB72B875413838C3E | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\fr.tsv | text | |
MD5:166904A820A8418E9D46E4897C5CC8F8 | SHA256:873987B940C27BB3A657D8E9F215E4438229515AF33F9604C238B0A18E2D5A36 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\cz.tsv | text | |
MD5:A0F2C74C326027BD6B2B51D7A5B4BF8E | SHA256:231C1BCE1D76ACF97DFFA7EAED8C1D18BC98C2E848B026A0F2056B476045D061 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\adb.exe | executable | |
MD5:F1F479BBA21298E758FC22D8D98F8E48 | SHA256:705DDC21F33AC52105D1B075B019962AD0E44FB3D560BDE69CE8CB3A36BCA183 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\es.tsv | text | |
MD5:F59D5CB58273951AE0C0DEC5973A0DDB | SHA256:158D573D59187091ABAE1D3449BD426AAD1FBCE9B51514BF7698594A776E67E0 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\de.tsv | text | |
MD5:CB8432F0C04C414710F1F40F87738A95 | SHA256:49F251C94E55092B7792EFC6771BCC472F5C0E56D28110E531E14A7CB0D4AE03 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\acupdate.exe | executable | |
MD5:6EB30DC3715E408042E2D34F3FAE753A | SHA256:23334245C184291AB809FED707541CD2B144DD9E7A5B5FC655658A6E29200A60 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\AdbWinApi.dll | executable | |
MD5:73030F38C867F5A7BD6EE331203F3D7A | SHA256:9FFACEDC41B2752075571E1A474FF50C5DCBE1F64DB56DB24AAEC78AEA1126DF | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\ADBAppControl.exe | executable | |
MD5:7E13882ACEC41D8F4528708C913D1EF6 | SHA256:5A1701E91905D29B893BCB712A648DC5C81CF86C38B5F844E1E1FC05958103CD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3960 | ADBAppControl.exe | GET | 200 | 67.27.159.254:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?144f824dd10d7a79 | unknown | compressed | 61.6 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3960 | ADBAppControl.exe | 195.201.90.171:443 | cs1.adbappcontrol.com | Hetzner Online GmbH | DE | unknown |
3960 | ADBAppControl.exe | 49.12.14.160:443 | adbappcontrol.com | Hetzner Online GmbH | DE | unknown |
3960 | ADBAppControl.exe | 67.27.159.254:80 | ctldl.windowsupdate.com | LEVEL3 | US | unknown |
3960 | ADBAppControl.exe | 198.51.233.2:443 | appcontrol.neocities.org | NEOCITIES | US | unknown |
3032 | ADBAppControl.exe | 195.201.90.171:443 | cs1.adbappcontrol.com | Hetzner Online GmbH | DE | unknown |
3032 | ADBAppControl.exe | 198.51.233.2:443 | appcontrol.neocities.org | NEOCITIES | US | unknown |
Domain | IP | Reputation |
|---|---|---|
cs1.adbappcontrol.com |
| unknown |
adbappcontrol.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
appcontrol.neocities.org |
| unknown |