| File name: | PhotoshopCS6Portable.exe |
| Full analysis: | https://app.any.run/tasks/5b9a6e6c-412c-4334-84cc-f3079fd9bf92 |
| Verdict: | Malicious activity |
| Analysis date: | April 08, 2021, 23:38:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 73438A5E206BFEDDB6A6577A3BD8E049 |
| SHA1: | 6E7A21E8549CE2FF81E019ECD7773D76E8FEDA23 |
| SHA256: | A1273B7CBE4275366BC8E81910CB6B4D1367D04C198249B1958C66F9741B7AB2 |
| SSDEEP: | 1536:qQpQ5EP0ijnRTXJIQIQQQJQSOb4fy56nwQBVCw3Fwrpjk22mOw0mfLxpETR9UX:qQIURTXJIQIQQQJQDb+y56nwQBVCcwrP |
| .exe | | | NSIS - Nullsoft Scriptable Install System (94.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.5) |
| .exe | | | Generic Win/DOS Executable (0.2) |
| ProductVersion: | 2013.02.13.00 |
|---|---|
| ProductName: | Adobe Photoshop CS6 Portable |
| OriginalFileName: | PhotoshopCS6Portable.exe |
| LegalTrademarks: | PortableAppZ is a Trademark of Bernat |
| LegalCopyright: | Bernat |
| InternalName: | Adobe Photoshop CS6 Portable |
| FileVersion: | 2013.02.13.00 |
| FileDescription: | Adobe Photoshop CS6 Portable |
| CompanyName: | PortableAppZ.blogspot.com |
| Comments: | Allows Adobe Photoshop CS6 to be run from a removable drive. For additional details, visit http://portableappz.blogspot.com |
| CharacterSet: | Windows, Latin1 |
| LanguageCode: | Neutral |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Win32 |
| FileFlags: | (none) |
| FileFlagsMask: | 0x0000 |
| ProductVersionNumber: | 2013.2.13.0 |
| FileVersionNumber: | 2013.2.13.0 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 4 |
| ImageVersion: | 6 |
| OSVersion: | 4 |
| EntryPoint: | 0x323c |
| UninitializedDataSize: | 1024 |
| InitializedDataSize: | 119808 |
| CodeSize: | 23552 |
| LinkerVersion: | 6 |
| PEType: | PE32 |
| TimeStamp: | 2009:12:05 23:50:46+01:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 05-Dec-2009 22:50:46 |
| Detected languages: |
|
| Comments: | Allows Adobe Photoshop CS6 to be run from a removable drive. For additional details, visit http://portableappz.blogspot.com |
| CompanyName: | PortableAppZ.blogspot.com |
| FileDescription: | Adobe Photoshop CS6 Portable |
| FileVersion: | 2013.02.13.00 |
| InternalName: | Adobe Photoshop CS6 Portable |
| LegalCopyright: | Bernat |
| LegalTrademarks: | PortableAppZ is a Trademark of Bernat |
| OriginalFilename: | PhotoshopCS6Portable.exe |
| ProductName: | Adobe Photoshop CS6 Portable |
| ProductVersion: | 2013.02.13.00 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000D8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 05-Dec-2009 22:50:46 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00005A5A | 0x00005C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.4177 |
.rdata | 0x00007000 | 0x00001190 | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.18163 |
.data | 0x00009000 | 0x0001AF98 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.70903 |
.ndata | 0x00024000 | 0x00009000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x0002D000 | 0x00004730 | 0x00004800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.23867 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.19512 | 727 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 5.01672 | 4264 | UNKNOWN | English - United States | RT_ICON |
3 | 5.54755 | 1128 | UNKNOWN | English - United States | RT_ICON |
103 | 2.45849 | 48 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.66174 | 256 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.87228 | 248 | UNKNOWN | English - United States | RT_DIALOG |
111 | 2.48825 | 96 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 976 | "C:\Users\admin\AppData\Local\Temp\PhotoshopCS6Portable.exe" | C:\Users\admin\AppData\Local\Temp\PhotoshopCS6Portable.exe | explorer.exe | ||||||||||||
User: admin Company: PortableAppZ.blogspot.com Integrity Level: HIGH Description: Adobe Photoshop CS6 Portable Exit code: 0 Version: 2013.02.13.00 Modules
| |||||||||||||||
| 1512 | "C:\Users\admin\AppData\Local\Temp\PhotoshopCS6Portable.exe" | C:\Users\admin\AppData\Local\Temp\PhotoshopCS6Portable.exe | — | explorer.exe | |||||||||||
User: admin Company: PortableAppZ.blogspot.com Integrity Level: MEDIUM Description: Adobe Photoshop CS6 Portable Exit code: 3221226540 Version: 2013.02.13.00 Modules
| |||||||||||||||
| (PID) Process: | (976) PhotoshopCS6Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\PortableAppRegistryTest |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (976) PhotoshopCS6Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Adobe-BackupByPhotoshopCS6Portable\Acrobat Reader\DC |
| Operation: | write | Name: | (default) |
Value: | |||
| (PID) Process: | (976) PhotoshopCS6Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Adobe-BackupByPhotoshopCS6Portable\Acrobat Reader\DC\Capabilities |
| Operation: | write | Name: | ApplicationDescription |
Value: Adobe Acrobat Reader DC MUI is the trusted standard for reliably viewing, printing, signing and commenting on PDF documents. It's the only PDF viewer that can open and interact with all types of PDF content - including forms and multimedia - and is available across leading desktop and mobile device platforms. | |||
| (PID) Process: | (976) PhotoshopCS6Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Adobe-BackupByPhotoshopCS6Portable\Acrobat Reader\DC\Capabilities |
| Operation: | write | Name: | ApplicationName |
Value: Adobe Acrobat Reader DC | |||
| (PID) Process: | (976) PhotoshopCS6Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Adobe-BackupByPhotoshopCS6Portable\Acrobat Reader\DC\Capabilities\FileAssociations |
| Operation: | write | Name: | .xfdf |
Value: AcroExch.XFDFDoc | |||
| (PID) Process: | (976) PhotoshopCS6Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Adobe-BackupByPhotoshopCS6Portable\Acrobat Reader\DC\Capabilities\FileAssociations |
| Operation: | write | Name: | .acrobatsecuritysettings |
Value: AcroExch.acrobatsecuritysettings | |||
| (PID) Process: | (976) PhotoshopCS6Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Adobe-BackupByPhotoshopCS6Portable\Acrobat Reader\DC\Capabilities\FileAssociations |
| Operation: | write | Name: | .pdfxml |
Value: AcroExch.pdfxml | |||
| (PID) Process: | (976) PhotoshopCS6Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Adobe-BackupByPhotoshopCS6Portable\Acrobat Reader\DC\Capabilities\FileAssociations |
| Operation: | write | Name: | |
Value: AcroExch.Document.DC | |||
| (PID) Process: | (976) PhotoshopCS6Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Adobe-BackupByPhotoshopCS6Portable\Acrobat Reader\DC\Capabilities\FileAssociations |
| Operation: | write | Name: | .fdf |
Value: AcroExch.FDFDoc | |||
| (PID) Process: | (976) PhotoshopCS6Portable.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Adobe-BackupByPhotoshopCS6Portable\Acrobat Reader\DC\Capabilities\FileAssociations |
| Operation: | write | Name: | .xdp |
Value: AcroExch.XDPDoc | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 976 | PhotoshopCS6Portable.exe | C:\Users\admin\AppData\Roaming\Adobe-BackupByPhotoshopCS6Portable | — | |
MD5:— | SHA256:— | |||
| 976 | PhotoshopCS6Portable.exe | C:\Users\admin\AppData\Local\Adobe-BackupByPhotoshopCS6Portable | — | |
MD5:— | SHA256:— | |||
| 976 | PhotoshopCS6Portable.exe | C:\Program Files\Common Files\Adobe-BackupByPhotoshopCS6Portable | — | |
MD5:— | SHA256:— | |||
| 976 | PhotoshopCS6Portable.exe | C:\ProgramData\Adobe-BackupByPhotoshopCS6Portable | — | |
MD5:— | SHA256:— | |||
| 976 | PhotoshopCS6Portable.exe | C:\Users\admin\AppData\Roaming\Adobe | — | |
MD5:— | SHA256:— | |||
| 976 | PhotoshopCS6Portable.exe | C:\Users\admin\AppData\Local\Adobe | — | |
MD5:— | SHA256:— | |||
| 976 | PhotoshopCS6Portable.exe | C:\Program Files\Common Files\Adobe | — | |
MD5:— | SHA256:— | |||
| 976 | PhotoshopCS6Portable.exe | C:\ProgramData\Adobe | — | |
MD5:— | SHA256:— | |||
| 976 | PhotoshopCS6Portable.exe | C:\Users\admin\AppData\Local\Temp\nsp89E2.tmp | — | |
MD5:— | SHA256:— | |||
| 976 | PhotoshopCS6Portable.exe | C:\Users\admin\AppData\Local\Temp\~DF9EB4A1F38073954D.TMP | — | |
MD5:— | SHA256:— | |||