File name:

ADBAppControl-1.8.3.zip

Full analysis: https://app.any.run/tasks/b1a15252-449a-417b-88da-282115294d1b
Verdict: Malicious activity
Analysis date: October 31, 2023, 23:47:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

18AC0E92F8CB54D34E48126B7BAE2991

SHA1:

39FAAE068C920BB80A445CF0D48E8EDBBBD38C81

SHA256:

95194364E0076116008B04E80EDCF520A7ED172062C362949014F96E40E64B3B

SSDEEP:

98304:biMjSLmcs/2Mi4Ql+RzPHkEoXyoannL5hRjGyUudW/1SSlkxayEk88xBsrZo90XP:FmvPM1oskbIUtY18

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • adb.exe (PID: 1036)
    • Reads the Internet Settings

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
    • Reads settings of System Certificates

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
  • INFO

    • Checks supported languages

      • ADBAppControl.exe (PID: 3960)
      • adb.exe (PID: 1036)
      • adb.exe (PID: 2004)
      • adb.exe (PID: 1840)
      • ADBAppControl.exe (PID: 3032)
      • adb.exe (PID: 188)
      • adb.exe (PID: 3540)
      • ADBAppControl.exe (PID: 372)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2232)
    • Manual execution by a user

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 372)
      • ADBAppControl.exe (PID: 3032)
    • Reads product name

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
    • Reads Environment values

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
    • Create files in a temporary directory

      • adb.exe (PID: 2004)
      • ADBAppControl.exe (PID: 3960)
    • Reads the computer name

      • adb.exe (PID: 2004)
      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
      • ADBAppControl.exe (PID: 372)
    • Reads the machine GUID from the registry

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 372)
      • ADBAppControl.exe (PID: 3032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:07:08 09:46:36
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: adb/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs adbappcontrol.exe adb.exe no specs adb.exe no specs adb.exe no specs adbappcontrol.exe adb.exe no specs adb.exe no specs adbappcontrol.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
188"C:\Users\admin\Desktop\adb\adb.exe" devicesC:\Users\admin\Desktop\adb\adb.exeADBAppControl.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
372"C:\Users\admin\Desktop\ADBAppControl.exe" C:\Users\admin\Desktop\ADBAppControl.exeexplorer.exe
User:
admin
Company:
Cyber.Cat
Integrity Level:
MEDIUM
Description:
ADB AppControl
Exit code:
0
Version:
1.8.3
Modules
Images
c:\users\admin\desktop\adbappcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1036"C:\Users\admin\Desktop\adb\adb.exe" devicesC:\Users\admin\Desktop\adb\adb.exeADBAppControl.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
1840"C:\Users\admin\Desktop\adb\adb.exe" devices -lC:\Users\admin\Desktop\adb\adb.exeADBAppControl.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
2004adb -L tcp:5037 fork-server server --reply-fd 216C:\Users\admin\Desktop\adb\adb.exeadb.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
2232"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ADBAppControl-1.8.3.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3032"C:\Users\admin\Desktop\ADBAppControl.exe" C:\Users\admin\Desktop\ADBAppControl.exe
explorer.exe
User:
admin
Company:
Cyber.Cat
Integrity Level:
HIGH
Description:
ADB AppControl
Exit code:
0
Version:
1.8.3
Modules
Images
c:\users\admin\desktop\adbappcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3540"C:\Users\admin\Desktop\adb\adb.exe" devices -lC:\Users\admin\Desktop\adb\adb.exeADBAppControl.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
3960"C:\Users\admin\Desktop\ADBAppControl.exe" C:\Users\admin\Desktop\ADBAppControl.exe
explorer.exe
User:
admin
Company:
Cyber.Cat
Integrity Level:
MEDIUM
Description:
ADB AppControl
Exit code:
0
Version:
1.8.3
Modules
Images
c:\users\admin\desktop\adbappcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
10 380
Read events
10 332
Write events
48
Delete events
0

Modification events

(PID) Process:(2232) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3960) ADBAppControl.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3032) ADBAppControl.exeKey:HKEY_CURRENT_USER\Software\AdbAppControl
Operation:writeName:Locale
Value:
en
Executable files
7
Suspicious files
6
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\bg.tsvtext
MD5:354FEB9C2ADDEAB5D510899C27FB1DBC
SHA256:0E0E7FCD36ACB2A25275978EA52DCFF2CCFC74B84961D69FB72B875413838C3E
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\hu.tsvtext
MD5:AF74414529DA7047368142AC4D7DA7C8
SHA256:51589B0E7DFC49C9C7F9395EC9167DF42D8C59B8A3FB7057E3FA3DB731A89BB6
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\pl.tsvtext
MD5:8A8797939E211C3A766D557F6CF0AE0E
SHA256:148FCBC5E3733C12C85E3E335FCC0448C06DE81AC1DFE5DAC9C2E4CA3D7B6464
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\ADBAppControl.exeexecutable
MD5:7E13882ACEC41D8F4528708C913D1EF6
SHA256:5A1701E91905D29B893BCB712A648DC5C81CF86C38B5F844E1E1FC05958103CD
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\ka.tsvtext
MD5:E769DBABDF7EB2322AE38E854B490329
SHA256:2641F5BA8F667578E18377CD726C96E95FC20CFCA79260F14E2657631CC4C2E1
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\it.tsvtext
MD5:CBBB745034DA234C5180F8151E5395A1
SHA256:6672C3AA4DDCCB56871C39B5F11C78F85190CC61907300197D5446BA7CDC29E2
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\cz.tsvtext
MD5:A0F2C74C326027BD6B2B51D7A5B4BF8E
SHA256:231C1BCE1D76ACF97DFFA7EAED8C1D18BC98C2E848B026A0F2056B476045D061
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\AdbWinApi.dllexecutable
MD5:73030F38C867F5A7BD6EE331203F3D7A
SHA256:9FFACEDC41B2752075571E1A474FF50C5DCBE1F64DB56DB24AAEC78AEA1126DF
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\fr.tsvtext
MD5:166904A820A8418E9D46E4897C5CC8F8
SHA256:873987B940C27BB3A657D8E9F215E4438229515AF33F9604C238B0A18E2D5A36
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\fastboot.exeexecutable
MD5:898B4FAC03BEEA8D8ED8C034F3DC7756
SHA256:377FF87EC40A2A9B947E00B487F4F4A42B03E195612BDCD8A526B70A1B0A918A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
11
DNS requests
4
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3960
ADBAppControl.exe
GET
200
67.27.159.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?144f824dd10d7a79
US
compressed
61.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
3960
ADBAppControl.exe
195.201.90.171:443
cs1.adbappcontrol.com
Hetzner Online GmbH
DE
unknown
3960
ADBAppControl.exe
49.12.14.160:443
adbappcontrol.com
Hetzner Online GmbH
DE
unknown
3960
ADBAppControl.exe
67.27.159.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3960
ADBAppControl.exe
198.51.233.2:443
appcontrol.neocities.org
NEOCITIES
US
unknown
3032
ADBAppControl.exe
195.201.90.171:443
cs1.adbappcontrol.com
Hetzner Online GmbH
DE
unknown
3032
ADBAppControl.exe
198.51.233.2:443
appcontrol.neocities.org
NEOCITIES
US
unknown

DNS requests

Domain
IP
Reputation
cs1.adbappcontrol.com
  • 195.201.90.171
unknown
adbappcontrol.com
  • 49.12.14.160
unknown
ctldl.windowsupdate.com
  • 67.27.159.254
  • 67.27.235.254
  • 8.241.9.126
  • 8.241.11.254
  • 67.27.233.254
whitelisted
appcontrol.neocities.org
  • 198.51.233.2
unknown

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info