| File name: | ADBAppControl-1.8.3.zip |
| Full analysis: | https://app.any.run/tasks/b1a15252-449a-417b-88da-282115294d1b |
| Verdict: | Malicious activity |
| Analysis date: | October 31, 2023, 23:47:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 18AC0E92F8CB54D34E48126B7BAE2991 |
| SHA1: | 39FAAE068C920BB80A445CF0D48E8EDBBBD38C81 |
| SHA256: | 95194364E0076116008B04E80EDCF520A7ED172062C362949014F96E40E64B3B |
| SSDEEP: | 98304:biMjSLmcs/2Mi4Ql+RzPHkEoXyoannL5hRjGyUudW/1SSlkxayEk88xBsrZo90XP:FmvPM1oskbIUtY18 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2023:07:08 09:46:36 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | adb/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | "C:\Users\admin\Desktop\adb\adb.exe" devices | C:\Users\admin\Desktop\adb\adb.exe | — | ADBAppControl.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 372 | "C:\Users\admin\Desktop\ADBAppControl.exe" | C:\Users\admin\Desktop\ADBAppControl.exe | — | explorer.exe | |||||||||||
User: admin Company: Cyber.Cat Integrity Level: MEDIUM Description: ADB AppControl Exit code: 0 Version: 1.8.3 Modules
| |||||||||||||||
| 1036 | "C:\Users\admin\Desktop\adb\adb.exe" devices | C:\Users\admin\Desktop\adb\adb.exe | — | ADBAppControl.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1840 | "C:\Users\admin\Desktop\adb\adb.exe" devices -l | C:\Users\admin\Desktop\adb\adb.exe | — | ADBAppControl.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2004 | adb -L tcp:5037 fork-server server --reply-fd 216 | C:\Users\admin\Desktop\adb\adb.exe | — | adb.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2232 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ADBAppControl-1.8.3.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3032 | "C:\Users\admin\Desktop\ADBAppControl.exe" | C:\Users\admin\Desktop\ADBAppControl.exe | explorer.exe | ||||||||||||
User: admin Company: Cyber.Cat Integrity Level: HIGH Description: ADB AppControl Exit code: 0 Version: 1.8.3 Modules
| |||||||||||||||
| 3540 | "C:\Users\admin\Desktop\adb\adb.exe" devices -l | C:\Users\admin\Desktop\adb\adb.exe | — | ADBAppControl.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3960 | "C:\Users\admin\Desktop\ADBAppControl.exe" | C:\Users\admin\Desktop\ADBAppControl.exe | explorer.exe | ||||||||||||
User: admin Company: Cyber.Cat Integrity Level: MEDIUM Description: ADB AppControl Exit code: 0 Version: 1.8.3 Modules
| |||||||||||||||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3960) ADBAppControl.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3032) ADBAppControl.exe | Key: | HKEY_CURRENT_USER\Software\AdbAppControl |
| Operation: | write | Name: | Locale |
Value: en | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\AdbWinUsbApi.dll | executable | |
MD5:F67D9EC28D19316754D7ECB0E990197D | SHA256:13918FDAB0C3AC77D077453A6036247CFECA10910AEC845F188C41148C630BB2 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\adb.exe | executable | |
MD5:F1F479BBA21298E758FC22D8D98F8E48 | SHA256:705DDC21F33AC52105D1B075B019962AD0E44FB3D560BDE69CE8CB3A36BCA183 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\hu.tsv | text | |
MD5:AF74414529DA7047368142AC4D7DA7C8 | SHA256:51589B0E7DFC49C9C7F9395EC9167DF42D8C59B8A3FB7057E3FA3DB731A89BB6 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\ADBAppControl.exe | executable | |
MD5:7E13882ACEC41D8F4528708C913D1EF6 | SHA256:5A1701E91905D29B893BCB712A648DC5C81CF86C38B5F844E1E1FC05958103CD | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\de.tsv | text | |
MD5:CB8432F0C04C414710F1F40F87738A95 | SHA256:49F251C94E55092B7792EFC6771BCC472F5C0E56D28110E531E14A7CB0D4AE03 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\AdbWinApi.dll | executable | |
MD5:73030F38C867F5A7BD6EE331203F3D7A | SHA256:9FFACEDC41B2752075571E1A474FF50C5DCBE1F64DB56DB24AAEC78AEA1126DF | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\es.tsv | text | |
MD5:F59D5CB58273951AE0C0DEC5973A0DDB | SHA256:158D573D59187091ABAE1D3449BD426AAD1FBCE9B51514BF7698594A776E67E0 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\fastboot.exe | executable | |
MD5:898B4FAC03BEEA8D8ED8C034F3DC7756 | SHA256:377FF87EC40A2A9B947E00B487F4F4A42B03E195612BDCD8A526B70A1B0A918A | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\fr.tsv | text | |
MD5:166904A820A8418E9D46E4897C5CC8F8 | SHA256:873987B940C27BB3A657D8E9F215E4438229515AF33F9604C238B0A18E2D5A36 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.2939\adb\lang\it.tsv | text | |
MD5:CBBB745034DA234C5180F8151E5395A1 | SHA256:6672C3AA4DDCCB56871C39B5F11C78F85190CC61907300197D5446BA7CDC29E2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3960 | ADBAppControl.exe | GET | 200 | 67.27.159.254:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?144f824dd10d7a79 | unknown | compressed | 61.6 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3960 | ADBAppControl.exe | 195.201.90.171:443 | cs1.adbappcontrol.com | Hetzner Online GmbH | DE | unknown |
3960 | ADBAppControl.exe | 49.12.14.160:443 | adbappcontrol.com | Hetzner Online GmbH | DE | unknown |
3960 | ADBAppControl.exe | 67.27.159.254:80 | ctldl.windowsupdate.com | LEVEL3 | US | unknown |
3960 | ADBAppControl.exe | 198.51.233.2:443 | appcontrol.neocities.org | NEOCITIES | US | unknown |
3032 | ADBAppControl.exe | 195.201.90.171:443 | cs1.adbappcontrol.com | Hetzner Online GmbH | DE | unknown |
3032 | ADBAppControl.exe | 198.51.233.2:443 | appcontrol.neocities.org | NEOCITIES | US | unknown |
Domain | IP | Reputation |
|---|---|---|
cs1.adbappcontrol.com |
| unknown |
adbappcontrol.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
appcontrol.neocities.org |
| unknown |