File name:

ADBAppControl-1.8.3.zip

Full analysis: https://app.any.run/tasks/b1a15252-449a-417b-88da-282115294d1b
Verdict: Malicious activity
Analysis date: October 31, 2023, 23:47:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

18AC0E92F8CB54D34E48126B7BAE2991

SHA1:

39FAAE068C920BB80A445CF0D48E8EDBBBD38C81

SHA256:

95194364E0076116008B04E80EDCF520A7ED172062C362949014F96E40E64B3B

SSDEEP:

98304:biMjSLmcs/2Mi4Ql+RzPHkEoXyoannL5hRjGyUudW/1SSlkxayEk88xBsrZo90XP:FmvPM1oskbIUtY18

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads settings of System Certificates

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
    • Application launched itself

      • adb.exe (PID: 1036)
    • Reads the Internet Settings

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
  • INFO

    • Checks supported languages

      • ADBAppControl.exe (PID: 3960)
      • adb.exe (PID: 2004)
      • adb.exe (PID: 1840)
      • adb.exe (PID: 1036)
      • ADBAppControl.exe (PID: 3032)
      • adb.exe (PID: 188)
      • adb.exe (PID: 3540)
      • ADBAppControl.exe (PID: 372)
    • Manual execution by a user

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
      • ADBAppControl.exe (PID: 372)
    • Reads the computer name

      • ADBAppControl.exe (PID: 3960)
      • adb.exe (PID: 2004)
      • ADBAppControl.exe (PID: 3032)
      • ADBAppControl.exe (PID: 372)
    • Reads the machine GUID from the registry

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
      • ADBAppControl.exe (PID: 372)
    • Reads product name

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2232)
    • Create files in a temporary directory

      • adb.exe (PID: 2004)
      • ADBAppControl.exe (PID: 3960)
    • Reads Environment values

      • ADBAppControl.exe (PID: 3960)
      • ADBAppControl.exe (PID: 3032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:07:08 09:46:36
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: adb/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs adbappcontrol.exe adb.exe no specs adb.exe no specs adb.exe no specs adbappcontrol.exe adb.exe no specs adb.exe no specs adbappcontrol.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
188"C:\Users\admin\Desktop\adb\adb.exe" devicesC:\Users\admin\Desktop\adb\adb.exeADBAppControl.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
372"C:\Users\admin\Desktop\ADBAppControl.exe" C:\Users\admin\Desktop\ADBAppControl.exeexplorer.exe
User:
admin
Company:
Cyber.Cat
Integrity Level:
MEDIUM
Description:
ADB AppControl
Exit code:
0
Version:
1.8.3
Modules
Images
c:\users\admin\desktop\adbappcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1036"C:\Users\admin\Desktop\adb\adb.exe" devicesC:\Users\admin\Desktop\adb\adb.exeADBAppControl.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
1840"C:\Users\admin\Desktop\adb\adb.exe" devices -lC:\Users\admin\Desktop\adb\adb.exeADBAppControl.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
2004adb -L tcp:5037 fork-server server --reply-fd 216C:\Users\admin\Desktop\adb\adb.exeadb.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
2232"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ADBAppControl-1.8.3.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3032"C:\Users\admin\Desktop\ADBAppControl.exe" C:\Users\admin\Desktop\ADBAppControl.exe
explorer.exe
User:
admin
Company:
Cyber.Cat
Integrity Level:
HIGH
Description:
ADB AppControl
Exit code:
0
Version:
1.8.3
Modules
Images
c:\users\admin\desktop\adbappcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3540"C:\Users\admin\Desktop\adb\adb.exe" devices -lC:\Users\admin\Desktop\adb\adb.exeADBAppControl.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
3960"C:\Users\admin\Desktop\ADBAppControl.exe" C:\Users\admin\Desktop\ADBAppControl.exe
explorer.exe
User:
admin
Company:
Cyber.Cat
Integrity Level:
MEDIUM
Description:
ADB AppControl
Exit code:
0
Version:
1.8.3
Modules
Images
c:\users\admin\desktop\adbappcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
10 380
Read events
10 332
Write events
48
Delete events
0

Modification events

(PID) Process:(2232) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3960) ADBAppControl.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3032) ADBAppControl.exeKey:HKEY_CURRENT_USER\Software\AdbAppControl
Operation:writeName:Locale
Value:
en
Executable files
7
Suspicious files
6
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\AdbWinUsbApi.dllexecutable
MD5:F67D9EC28D19316754D7ECB0E990197D
SHA256:13918FDAB0C3AC77D077453A6036247CFECA10910AEC845F188C41148C630BB2
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\adb.exeexecutable
MD5:F1F479BBA21298E758FC22D8D98F8E48
SHA256:705DDC21F33AC52105D1B075B019962AD0E44FB3D560BDE69CE8CB3A36BCA183
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\hu.tsvtext
MD5:AF74414529DA7047368142AC4D7DA7C8
SHA256:51589B0E7DFC49C9C7F9395EC9167DF42D8C59B8A3FB7057E3FA3DB731A89BB6
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\ADBAppControl.exeexecutable
MD5:7E13882ACEC41D8F4528708C913D1EF6
SHA256:5A1701E91905D29B893BCB712A648DC5C81CF86C38B5F844E1E1FC05958103CD
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\de.tsvtext
MD5:CB8432F0C04C414710F1F40F87738A95
SHA256:49F251C94E55092B7792EFC6771BCC472F5C0E56D28110E531E14A7CB0D4AE03
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\AdbWinApi.dllexecutable
MD5:73030F38C867F5A7BD6EE331203F3D7A
SHA256:9FFACEDC41B2752075571E1A474FF50C5DCBE1F64DB56DB24AAEC78AEA1126DF
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\es.tsvtext
MD5:F59D5CB58273951AE0C0DEC5973A0DDB
SHA256:158D573D59187091ABAE1D3449BD426AAD1FBCE9B51514BF7698594A776E67E0
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\fastboot.exeexecutable
MD5:898B4FAC03BEEA8D8ED8C034F3DC7756
SHA256:377FF87EC40A2A9B947E00B487F4F4A42B03E195612BDCD8A526B70A1B0A918A
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\fr.tsvtext
MD5:166904A820A8418E9D46E4897C5CC8F8
SHA256:873987B940C27BB3A657D8E9F215E4438229515AF33F9604C238B0A18E2D5A36
2232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\it.tsvtext
MD5:CBBB745034DA234C5180F8151E5395A1
SHA256:6672C3AA4DDCCB56871C39B5F11C78F85190CC61907300197D5446BA7CDC29E2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
11
DNS requests
4
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3960
ADBAppControl.exe
GET
200
67.27.159.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?144f824dd10d7a79
unknown
compressed
61.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
3960
ADBAppControl.exe
195.201.90.171:443
cs1.adbappcontrol.com
Hetzner Online GmbH
DE
unknown
3960
ADBAppControl.exe
49.12.14.160:443
adbappcontrol.com
Hetzner Online GmbH
DE
unknown
3960
ADBAppControl.exe
67.27.159.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3960
ADBAppControl.exe
198.51.233.2:443
appcontrol.neocities.org
NEOCITIES
US
unknown
3032
ADBAppControl.exe
195.201.90.171:443
cs1.adbappcontrol.com
Hetzner Online GmbH
DE
unknown
3032
ADBAppControl.exe
198.51.233.2:443
appcontrol.neocities.org
NEOCITIES
US
unknown

DNS requests

Domain
IP
Reputation
cs1.adbappcontrol.com
  • 195.201.90.171
unknown
adbappcontrol.com
  • 49.12.14.160
unknown
ctldl.windowsupdate.com
  • 67.27.159.254
  • 67.27.235.254
  • 8.241.9.126
  • 8.241.11.254
  • 67.27.233.254
whitelisted
appcontrol.neocities.org
  • 198.51.233.2
unknown

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info