File name:

Activator Adguard Premium lifetime.exe

Full analysis: https://app.any.run/tasks/1b11e7a1-af6b-4276-b5b9-a85aa00e15d2
Verdict: No threats detected
Analysis date: December 22, 2019, 21:16:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E21FED337F45846CFF969845EBA8C184

SHA1:

4F627F607F07868C19B428D722E17ED60672A434

SHA256:

97C5BB17D6707884820AFF3911DAD289866782435A01E2F84856A671DBBF6B58

SSDEEP:

196608:DBooXCQ209PA/JZP1aDSHQqvI7mET2exNdHqMV280qtTu:9XX8JZdaDSH78mu2eHdH128Dq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Engine.exe (PID: 1728)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Activator Adguard Premium lifetime.exe (PID: 3652)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (49.2)
.exe | Win32 Executable Delphi generic (16.2)
.scr | Windows screen saver (14.9)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
PEType: PE32
LinkerVersion: 2.25
CodeSize: 218112
InitializedDataSize: 41984
UninitializedDataSize: -
EntryPoint: 0x36278
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.4.1814.4903
ProductVersionNumber: 6.4.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments:
CompanyName: Rjkzy
FileDescription: License Adguard Premium lifetime
FileVersion: 6.4.1814.4903
LegalCopyright: Copyright © 2019 by Rjkzy
LegalTrademarks:
ProductName: Activator Adguard for Windows
ProductVersion: 6.4
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start activator adguard premium lifetime.exe engine.exe no specs activator adguard premium lifetime.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1728C:\Users\admin\AppData\Local\Temp\SETUP_43542\Engine.exe /TH_ID=_3744 /OriginExe="C:\Users\admin\AppData\Local\Temp\Activator Adguard Premium lifetime.exe"C:\Users\admin\AppData\Local\Temp\SETUP_43542\Engine.exeActivator Adguard Premium lifetime.exe
User:
admin
Company:
Pantaray Research Ltd.
Integrity Level:
HIGH
Description:
Setup/Uninstall Engine
Exit code:
0
Version:
12.0.0.5
Modules
Images
c:\users\admin\appdata\local\temp\setup_43542\engine.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cabinet.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
2440"C:\Users\admin\AppData\Local\Temp\Activator Adguard Premium lifetime.exe" C:\Users\admin\AppData\Local\Temp\Activator Adguard Premium lifetime.exeexplorer.exe
User:
admin
Company:
Rjkzy
Integrity Level:
MEDIUM
Description:
License Adguard Premium lifetime
Exit code:
3221226540
Version:
6.4.1814.4903
Modules
Images
c:\users\admin\appdata\local\temp\activator adguard premium lifetime.exe
c:\systemroot\system32\ntdll.dll
3652"C:\Users\admin\AppData\Local\Temp\Activator Adguard Premium lifetime.exe" C:\Users\admin\AppData\Local\Temp\Activator Adguard Premium lifetime.exe
explorer.exe
User:
admin
Company:
Rjkzy
Integrity Level:
HIGH
Description:
License Adguard Premium lifetime
Exit code:
0
Version:
6.4.1814.4903
Modules
Images
c:\users\admin\appdata\local\temp\activator adguard premium lifetime.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
72
Read events
72
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
1
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
3652Activator Adguard Premium lifetime.exeC:\Users\admin\AppData\Local\Temp\SETUP_43542\00000#adguard.db
MD5:
SHA256:
3652Activator Adguard Premium lifetime.exeC:\Users\admin\AppData\Local\Temp\SETUP_43542\Classic_Setup.bmpimage
MD5:49AB1F0D51BAB8728FFBDF875C3A7321
SHA256:F0E0754CFE3A6B1FBACA3D779D2EAAB500A7651AF6E3032106A29FFF564B5BC4
3652Activator Adguard Premium lifetime.exeC:\Users\admin\AppData\Local\Temp\SETUP_43542\Setup.txttext
MD5:69793F9F1911218A84E4E9A3DA567E66
SHA256:14F4464A9BDC068A1AF675AC9656257947657D4AB2D04792F3E702800C9D3400
3652Activator Adguard Premium lifetime.exeC:\Users\admin\AppData\Local\Temp\SETUP_43542\Activator Adguard 6.4 Premium lifetime.qsptext
MD5:90361F0D0E3E68FF39CDC9183B94E863
SHA256:03A17CA86889B75EF5FD7E4D567D7349A363FCA823F3C85AFE0B0B9E42FA7978
3652Activator Adguard Premium lifetime.exeC:\Users\admin\AppData\Local\Temp\SETUP_43542\English.lngtext
MD5:9355ACA21FA49D4C535610C38D3EA17F
SHA256:62D172351EA2440C8EF1783656D7C098EC597E100D5D0C8E0058819787FFE311
3652Activator Adguard Premium lifetime.exeC:\Users\admin\AppData\Local\Temp\SETUP_43542\Engine.exeexecutable
MD5:FD4BF64316FFBB30ABD317996E13B280
SHA256:00FA5F447C5C0CF3FF292C2F617688C6EF992583232B2868A9ED4DEAD13AF2CE
3652Activator Adguard Premium lifetime.exeC:\Users\admin\AppData\Local\Temp\SETUP_43542\64.regtext
MD5:1517D7A719562DEF3633627ED0CCA6EB
SHA256:7067B8F6314331C431CF92438CD88AF62BDBD01C89B8FBFA1789260AE260774C
3652Activator Adguard Premium lifetime.exeC:\Users\admin\AppData\Local\Temp\SETUP_43542\Addhosts.battext
MD5:7C810D161A4B7E591B9E564BB8029469
SHA256:0B837F5D04D2B4E031A7462EC303B1A16E03266191E8AAC4A03C907772EA2CF5
3652Activator Adguard Premium lifetime.exeC:\Users\admin\AppData\Local\Temp\SETUP_43542\32.regtext
MD5:6917A57C9174ABBBADF28A9733511D40
SHA256:03F079DF606EA9AF45B3A8C8F4E8A3E6151936A0C7E5B5EECF7500F8A6606215
3652Activator Adguard Premium lifetime.exeC:\Users\admin\AppData\Local\Temp\SETUP_43542\Russian.lngtext
MD5:723F32838B744B78D46233BC6DC4F409
SHA256:ED326E4747F8FDF3205BAC98315693A0E1E1FB834D45D5AA8393010F2105C4AB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info