File name:

ADE_4.5_Installer.exe

Full analysis: https://app.any.run/tasks/ca69fe6a-58a9-4636-b030-27caca90483e
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: March 08, 2021, 02:45:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

1EFCD0C92784169FC1EEC4E87788F6E8

SHA1:

585E9EB828859EC005A5C280FF99408E65DF1CB8

SHA256:

A21A9D5389728FDAC6A7288953DDDEEA774EF2BEE07F1CAF7EA20BBED8F5A2C6

SSDEEP:

196608:/MUfuaC/K12qiyD6dmS/qY2fvYG2zZ8igA7Tt:EUWaK8iU6AsevY9ZUKt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • ADE_4.5_Installer.exe (PID: 3792)
      • ADE_4.5_Installer.exe (PID: 1352)
      • DigitalEditions.exe (PID: 2352)
    • Changes settings of System certificates

      • ADE_4.5_Installer.exe (PID: 1352)
      • DigitalEditions.exe (PID: 2352)
    • Loads the Task Scheduler DLL interface

      • ADE_4.5_Installer.exe (PID: 1352)
    • Application was dropped or rewritten from another process

      • DigitalEditions.exe (PID: 2352)
      • ADEAutoUpdater_450.exe (PID: 2484)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ADE_4.5_Installer.exe (PID: 3792)
      • ADE_4.5_Installer.exe (PID: 1352)
    • Application launched itself

      • ADE_4.5_Installer.exe (PID: 3792)
    • Creates a directory in Program Files

      • ADE_4.5_Installer.exe (PID: 1352)
    • Drops a file that was compiled in debug mode

      • ADE_4.5_Installer.exe (PID: 1352)
    • Creates a software uninstall entry

      • ADE_4.5_Installer.exe (PID: 1352)
    • Creates files in the program directory

      • ADE_4.5_Installer.exe (PID: 1352)
    • Adds / modifies Windows certificates

      • ADE_4.5_Installer.exe (PID: 1352)
      • DigitalEditions.exe (PID: 2352)
    • Creates files in the user directory

      • ADE_4.5_Installer.exe (PID: 1352)
    • Changes default file association

      • ADE_4.5_Installer.exe (PID: 1352)
  • INFO

    • Reads settings of System Certificates

      • ADE_4.5_Installer.exe (PID: 1352)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:12:11 22:50:45+01:00
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x32bf
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.5.11.0
ProductVersionNumber: 4.5.11.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Adobe Systems Incorporated
Debugger: -
FileDescription: Adobe Digital Editions 4.5.11
FileVersion: 1
InternalName: Adobe Digital Editions 4.5.11
LegalCopyright: © 2006-2018 Adobe Systems Incorporated and its licensors. All rights reserved.
LegalTrademarks: Adobe® Digital Editions
OriginalFileName: DigitalEditions.exe
ProductName: Adobe Digital Editions 4.5.11
ProductVersion: 4.5.11.0

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 11-Dec-2016 21:50:45
Detected languages:
  • English - United States
CompanyName: Adobe Systems Incorporated
Debugger: 0
FileDescription: Adobe Digital Editions 4.5.11
FileVersion: 1.0
InternalName: Adobe Digital Editions 4.5.11
LegalCopyright: © 2006-2018 Adobe Systems Incorporated and its licensors. All rights reserved.
LegalTrademarks: Adobe® Digital Editions
OriginalFilename: DigitalEditions.exe
ProductName: Adobe Digital Editions 4.5.11
ProductVersion: 4.5.11.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000D8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 11-Dec-2016 21:50:45
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00005E59
0x00006000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.42419
.rdata
0x00007000
0x00001246
0x00001400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.0004
.data
0x00009000
0x0001A818
0x00000400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.21193
.ndata
0x00024000
0x0000C000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x00030000
0x00009CE8
0x00009E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.93043

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.29934
830
UNKNOWN
English - United States
RT_MANIFEST
2
4.44842
9640
UNKNOWN
English - United States
RT_ICON
3
4.79013
4264
UNKNOWN
English - United States
RT_ICON
4
5.17999
1128
UNKNOWN
English - United States
RT_ICON
103
2.44608
62
UNKNOWN
English - United States
RT_GROUP_ICON
104
2.6935
316
UNKNOWN
English - United States
RT_DIALOG
105
2.66174
256
UNKNOWN
English - United States
RT_DIALOG
106
2.88094
284
UNKNOWN
English - United States
RT_DIALOG
107
2.62276
196
UNKNOWN
English - United States
RT_DIALOG
109
3.05474
182
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
4
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ade_4.5_installer.exe ade_4.5_installer.exe digitaleditions.exe adeautoupdater_450.exe

Process information

PID
CMD
Path
Indicators
Parent process
1352"C:\Users\admin\AppData\Local\Temp\ADE_4.5_Installer.exe" /UAC:30158 /NCRC C:\Users\admin\AppData\Local\Temp\ADE_4.5_Installer.exe
ADE_4.5_Installer.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
HIGH
Description:
Adobe Digital Editions 4.5.11
Exit code:
1223
Version:
1.0
Modules
Images
c:\users\admin\appdata\local\temp\ade_4.5_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2352"C:\Program Files\Adobe\Adobe Digital Editions 4.5\DigitalEditions.exe" C:\Program Files\Adobe\Adobe Digital Editions 4.5\DigitalEditions.exe
ADE_4.5_Installer.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Digital Editions 4.5.11
Exit code:
0
Version:
4.5.11.0
Modules
Images
c:\program files\adobe\adobe digital editions 4.5\digitaleditions.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2484"C:\Program Files\Adobe\Adobe Digital Editions 4.5\ADEAutoUpdater_450.exe" -checkForUpdate https://adedownload.adobe.com/pub/adobe/digitaleditions/sha2/adeupdaterconfig.cfg 4.5.11.187303 en_USC:\Program Files\Adobe\Adobe Digital Editions 4.5\ADEAutoUpdater_450.exe
DigitalEditions.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
4294967295
Modules
Images
c:\program files\adobe\adobe digital editions 4.5\adeautoupdater_450.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3792"C:\Users\admin\AppData\Local\Temp\ADE_4.5_Installer.exe" C:\Users\admin\AppData\Local\Temp\ADE_4.5_Installer.exe
explorer.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Digital Editions 4.5.11
Exit code:
1223
Version:
1.0
Modules
Images
c:\users\admin\appdata\local\temp\ade_4.5_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
1 001
Read events
878
Write events
121
Delete events
2

Modification events

(PID) Process:(1352) ADE_4.5_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Digital Editions 4.5
Operation:writeName:InstallDir
Value:
C:\Program Files\Adobe\Adobe Digital Editions 4.5
(PID) Process:(1352) ADE_4.5_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Digital Editions 4.5
Operation:writeName:InstallPath
Value:
C:\Program Files\Adobe\Adobe Digital Editions 4.5\DigitalEditions.exe
(PID) Process:(1352) ADE_4.5_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Digital Editions 4.5
Operation:writeName:FileVersion
Value:
1.1
(PID) Process:(1352) ADE_4.5_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Digital Editions 4.5
Operation:writeName:ProductVersion
Value:
4.5.11.0
(PID) Process:(1352) ADE_4.5_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Digital Editions 4.5
Operation:writeName:DisplayName
Value:
Adobe Digital Editions 4.5
(PID) Process:(1352) ADE_4.5_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Digital Editions 4.5
Operation:writeName:UninstallString
Value:
"C:\Program Files\Adobe\Adobe Digital Editions 4.5\uninstall.exe"
(PID) Process:(1352) ADE_4.5_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Digital Editions 4.5
Operation:writeName:NoModify
Value:
1
(PID) Process:(1352) ADE_4.5_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Digital Editions 4.5
Operation:writeName:NoRepair
Value:
1
(PID) Process:(1352) ADE_4.5_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Digital Editions 4.5
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Adobe\Adobe Digital Editions 4.5\DigitalEditions.exe,-101
(PID) Process:(1352) ADE_4.5_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Digital Editions 4.5
Operation:writeName:Publisher
Value:
Adobe Systems Incorporated
Executable files
34
Suspicious files
8
Text files
31
Unknown types
23

Dropped files

PID
Process
Filename
Type
3792ADE_4.5_Installer.exeC:\Users\admin\Documents\My Digital Editions\Manifest\welcome.epub.xmlxml
MD5:
SHA256:
3792ADE_4.5_Installer.exeC:\Users\admin\AppData\Local\Temp\nsq981C.tmp\System.dllexecutable
MD5:3F176D1EE13B0D7D6BD92E1C7A0B9BAE
SHA256:FA4AB1D6F79FD677433A31ADA7806373A789D34328DA46CCB0449BBF347BD73E
1352ADE_4.5_Installer.exeC:\Program Files\Adobe\Adobe Digital Editions 4.5\migration.exeexecutable
MD5:78437B77D33DDEA1FEC5135086E5D62D
SHA256:81C7A5A0548EE0FBCA7E20AFDCD4AF7344021634B284D477CA1E00E0926E2980
1352ADE_4.5_Installer.exeC:\Users\admin\AppData\Local\Temp\nsm9B58.tmp\UAC.dllexecutable
MD5:4814167AA1C7EC892E84907094646FAA
SHA256:32DD7269ABF5A0E5DB888E307D9DF313E87CEF4F1B597965A9D8E00934658822
1352ADE_4.5_Installer.exeC:\Program Files\Adobe\Adobe Digital Editions 4.5\ADEAutoUpdater_450.exeexecutable
MD5:092EC1A7666EBCAF151CDF4F70FE1661
SHA256:92AD71D67349611E9774928221456D01F79B635CAA3047334F26B684B89A43EB
1352ADE_4.5_Installer.exeC:\Program Files\Adobe\Adobe Digital Editions 4.5\log4net.dllexecutable
MD5:CFC32BC27AC2DA0188C7F21D1A08AC6E
SHA256:E3A6686D85F44DFCA0F3096C75C30DA658DFB7137A4E078EB2778B07F19C1DE6
1352ADE_4.5_Installer.exeC:\Program Files\Adobe\Adobe Digital Editions 4.5\resources\userStyle.csstext
MD5:37FBA8D8DFE04C8E360E0375FC2FEB47
SHA256:D01DF0BBD8AC3888DC8DE422BF3CEAF55945367468EBC7CF314BFFD3D7F80339
1352ADE_4.5_Installer.exeC:\Program Files\Adobe\Adobe Digital Editions 4.5\resources\fonts\CourierStd-Bold.otfotf
MD5:377489E8B89B1BDA9749DD72E60501C8
SHA256:63D957D38000D412C4BA75D2ADDDDECF8ABBB8DDA17B0D8F719C8AF3F2151C43
1352ADE_4.5_Installer.exeC:\Program Files\Adobe\Adobe Digital Editions 4.5\resources\fonts\CourierStd-BoldOblique.otfotf
MD5:8B2096A673CEEEBB2B20C076C6785232
SHA256:BD9A592B4B45E77BAF7F728A0C8B6EA27A35C0179A66E541ACFA0FF64E10964C
1352ADE_4.5_Installer.exeC:\Program Files\Adobe\Adobe Digital Editions 4.5\resources\ReaderClientCert.sigtext
MD5:E9BE14F4CBC17BFEF75A69DBECA0B225
SHA256:E6CA43FC446DCC03CE6ABE82D6DCB8BE52262F84431EC1EA66BC694AB75D8446
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
9
DNS requests
6
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1352
ADE_4.5_Installer.exe
GET
200
52.234.215.129:80
http://stats.norton.com/n/p?module=9151&product=SymCCIS&version=2.1.3.25&language=09.01&os=6.1.7601.1.0&y=1033&b=adobeebook&a=SetProductOfferStatus&f=ns&o=0&error=0&i=1
US
text
13 b
whitelisted
1352
ADE_4.5_Installer.exe
GET
200
52.234.215.129:80
http://stats.norton.com/n/p?module=9151&product=SymCCIS&version=2.1.3.25&language=09.01&os=6.1.7601.1.0&y=1033&b=adobeebook&a=CallCriteriaChecker&f=10&c=false&d=false&e=0x0&error=0&j=ns&k=ns=1000&g=-1&l=0.000
US
text
13 b
whitelisted
2352
DigitalEditions.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAzAqnCcf7sVVqCydoKAqRo%3D
US
der
471 b
whitelisted
1352
ADE_4.5_Installer.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAcEvqr23o5WlD7AKgPMHDw%3D
US
der
471 b
whitelisted
1352
ADE_4.5_Installer.exe
GET
400
52.234.215.129:443
http://stats.norton.com:443/n/p?module=9160&product=SCC&version=4.7.2.36&language=09.01&os=6.1.7601.1.0&y=1033&a=adobeebook&b=local&c=ns&d=ns=1000&e=0x0&error=0&n=0&j=0&k=0&l=none&m=none&o=none&q=none&t=none&u=-1&v=none
US
html
248 b
whitelisted
1352
ADE_4.5_Installer.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1352
ADE_4.5_Installer.exe
2.18.233.74:443
adedownload.adobe.com
Akamai International B.V.
whitelisted
1352
ADE_4.5_Installer.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1352
ADE_4.5_Installer.exe
52.234.215.129:443
stats.norton.com
Microsoft Corporation
US
whitelisted
2352
DigitalEditions.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2484
ADEAutoUpdater_450.exe
2.18.233.74:443
adedownload.adobe.com
Akamai International B.V.
whitelisted
1352
ADE_4.5_Installer.exe
192.147.130.117:443
adeinstall.adobe.com
Adobe Systems Inc.
US
unknown
2352
DigitalEditions.exe
192.147.130.145:443
adeactivate.adobe.com
Adobe Systems Inc.
US
unknown
1352
ADE_4.5_Installer.exe
52.234.215.129:80
stats.norton.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
adedownload.adobe.com
  • 2.18.233.74
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
stats.norton.com
  • 52.234.215.129
unknown
adeinstall.adobe.com
  • 192.147.130.117
whitelisted
adeactivate.adobe.com
  • 192.147.130.145
whitelisted

Threats

PID
Process
Class
Message
1352
ADE_4.5_Installer.exe
Misc activity
ADWARE [PTsecurity] NSIS.DealPly.xiazai
1352
ADE_4.5_Installer.exe
A Network Trojan was detected
ET POLICY Norton Update User-Agent (Install Stub)
1352
ADE_4.5_Installer.exe
Misc activity
ADWARE [PTsecurity] NSIS.DealPly.xiazai
1352
ADE_4.5_Installer.exe
A Network Trojan was detected
ET POLICY Norton Update User-Agent (Install Stub)
1352
ADE_4.5_Installer.exe
Misc activity
ADWARE [PTsecurity] NSIS.DealPly.xiazai
No debug info