| File name: | Premiere_Pro_Set-Up.exe |
| Full analysis: | https://app.any.run/tasks/05ce053a-0a4e-4704-8ea9-a6e571033d9f |
| Verdict: | Malicious activity |
| Analysis date: | December 14, 2024, 12:32:52 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections |
| MD5: | 4752608DDFC13ED7BD42175FA2ABBE2D |
| SHA1: | 08EACA0A97A22667E5932574AF7D05393128DA29 |
| SHA256: | A6485EFFA3A11B6AFA219FA131587433263DA36F9EE28FDC8F7CD24C8E38F870 |
| SSDEEP: | 98304:khrrrAZbJJcNChltm1kO0U2qcJtWYhcU91jTJ7bWu7Cw28/H/EDOjdmRFva3opug:BQn3xQj3C |
| .exe | | | UPX compressed Win32 Executable (76) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.6) |
| .exe | | | Generic Win/DOS Executable (5.6) |
| .exe | | | DOS Executable Generic (5.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:10:30 03:14:41+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.23 |
| CodeSize: | 2072576 |
| InitializedDataSize: | 45056 |
| UninitializedDataSize: | 3280896 |
| EntryPoint: | 0x51b390 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.3.5.13 |
| ProductVersionNumber: | 5.3.5.13 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Adobe Inc. |
| FileDescription: | Adobe Installer |
| FileVersion: | 5.3.5.13 |
| InternalName: | Adobe Installer |
| LegalCopyright: | © 2015-2020 Adobe. All rights reserved. |
| OriginalFileName: | Adobe Installer |
| ProductName: | Adobe Installer |
| ProductVersion: | 5.3.5.13 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | "C:\Users\admin\AppData\Local\Temp\Premiere_Pro_Set-Up.exe" | C:\Users\admin\AppData\Local\Temp\Premiere_Pro_Set-Up.exe | explorer.exe | ||||||||||||
User: admin Company: Adobe Inc. Integrity Level: MEDIUM Description: Adobe Installer Version: 5.3.5.13 Modules
| |||||||||||||||
| 236 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | RuntimeCustomHook.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 236 | "C:\Windows\System32\icacls.exe" "C:\Users\admin\AppData\Roaming\Adobe\UPI\Configuration" /setowner admin | C:\Windows\System32\icacls.exe | — | UPICustomHook.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 420 | "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Runtime\customhook\vc10\64bit\vcredist_x64.exe" /q /norestart | C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\Runtime\customhook\vc10\64bit\vcredist_x64.exe | RuntimeCustomHook.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2010 x64 Redistributable Setup Exit code: 0 Version: 10.0.40219.325 Modules
| |||||||||||||||
| 420 | "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\customhook\ADSCustomHook.exe" --install=1 | C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\customHook\ADSCustomHook.exe | — | Premiere_Pro_Set-Up.exe | |||||||||||
User: admin Company: Adobe Inc. Integrity Level: HIGH Description: ADSCustomHook Exit code: 0 Version: 5.5.0.617 Modules
| |||||||||||||||
| 628 | "C:\Windows\System32\icacls.exe" "C:\Users\Administrator\AppData\Roaming\Adobe\UPI\Configuration\DB" /setowner Administrator | C:\Windows\System32\icacls.exe | — | UPICustomHook.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1016 | C:\WINDOWS\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1192 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1200 | "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeServiceInstaller.exe" --register=1 --servicePath="C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe" --serviceLabel=AdobeUpdateService | C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeServiceInstaller.exe | Premiere_Pro_Set-Up.exe | ||||||||||||
User: admin Company: Adobe Inc. Integrity Level: HIGH Description: Adobe Install Helper Exit code: 0 Version: 5.5.0.617 Modules
| |||||||||||||||
| 1216 | "C:\Windows\System32\icacls.exe" "C:\ProgramData\Adobe\UPI\EM Store" /inheritance:r /grant SYSTEM:(F) /grant ADMINISTRATORS:(F) /grant *S-1-5-32-545:(RX) /T /C | C:\Windows\System32\icacls.exe | — | UPICustomHook.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (188) Premiere_Pro_Set-Up.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (188) Premiere_Pro_Set-Up.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (188) Premiere_Pro_Set-Up.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (188) Premiere_Pro_Set-Up.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\DOMStorage\adobe.com |
| Operation: | write | Name: | NumberOfSubdomains |
Value: 1 | |||
| (PID) Process: | (188) Premiere_Pro_Set-Up.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\DOMStorage\adobe.com |
| Operation: | write | Name: | Total |
Value: 48 | |||
| (PID) Process: | (188) Premiere_Pro_Set-Up.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\DOMStorage\arkoselabs.com |
| Operation: | write | Name: | NumberOfSubdomains |
Value: 1 | |||
| (PID) Process: | (188) Premiere_Pro_Set-Up.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\MediaPlayer\Health\{6F171A55-97E4-494D-B6D7-15D8C69656AF} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (188) Premiere_Pro_Set-Up.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\MediaPlayer\Health\{EE708116-5C90-4EF1-90C0-4ED753B9BAB8} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (188) Premiere_Pro_Set-Up.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch |
| Operation: | write | Name: | Version |
Value: WS not running | |||
| (PID) Process: | (188) Premiere_Pro_Set-Up.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | DisableFirstRunCustomize |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 188 | Premiere_Pro_Set-Up.exe | C:\Users\admin\AppData\Local\Temp\{52B9FE7B-4F75-4856-BE99-78CB51D1E9BC}\lib\jquery.min.js | s | |
MD5:9AC39DC31635A363E377EDA0F6FBE03F | SHA256:9A2723C21FB1B7DFF0E2AA5DC6BE24A9670220A17AE21F70FDBC602D1F8ACD38 | |||
| 188 | Premiere_Pro_Set-Up.exe | C:\Users\admin\AppData\Local\Adobe\OOBE\temp_ins_lbs_wid | text | |
MD5:F03DF0244A09AB500188AA75B70931B0 | SHA256:79FA555C198A71E230AAEC7D2A92CBB094C0036B90E03C0B8B69A82117EC252B | |||
| 188 | Premiere_Pro_Set-Up.exe | C:\Users\admin\AppData\Local\Temp\{52B9FE7B-4F75-4856-BE99-78CB51D1E9BC}\js\mainController.js | binary | |
MD5:51BDCC0E7D53C59FF20FF2F6E276E321 | SHA256:EC5B0CEDE51F5FD48C341CD27D42433BB9A2ADB04836433FEE5A90B101E4B1B2 | |||
| 188 | Premiere_Pro_Set-Up.exe | C:\Users\admin\AppData\Local\Temp\{52B9FE7B-4F75-4856-BE99-78CB51D1E9BC}\js\overlayController.js | binary | |
MD5:B610650C4D826B14C225CFBECA89B8C1 | SHA256:79D00458B49A02ACEE141B53DCF026AA1302AB6B48A745B57E1215BD3B20501C | |||
| 188 | Premiere_Pro_Set-Up.exe | C:\Users\admin\AppData\Local\Temp\{52B9FE7B-4F75-4856-BE99-78CB51D1E9BC}\lib\IE8\jquery.min.js | s | |
MD5:E1288116312E4728F98923C79B034B67 | SHA256:BA6EDA7945AB8D7E57B34CC5A3DD292FA2E4C60A5CED79236ECF1A9E0F0C2D32 | |||
| 188 | Premiere_Pro_Set-Up.exe | C:\Users\admin\AppData\Local\Temp\{52B9FE7B-4F75-4856-BE99-78CB51D1E9BC}\lib\jquery.custom-scrollbar.min.js | binary | |
MD5:AB3ADF4AFF09A1C562A29DB05795C8AB | SHA256:D05E193674C6FC31DE0503CBC0B152600F22689AD7AD72ADB35FCC7C25D4B01B | |||
| 188 | Premiere_Pro_Set-Up.exe | C:\Users\admin\AppData\Local\Temp\{52B9FE7B-4F75-4856-BE99-78CB51D1E9BC}\main.html | html | |
MD5:A501355E23582CBC6C8C2835FE076F52 | SHA256:4BE92DEE71936C52319D441434992895818586ACAB859000341AF74D0175AB54 | |||
| 188 | Premiere_Pro_Set-Up.exe | C:\Users\admin\AppData\Local\Temp\CreativeCloud\ACC\WAM.log | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 188 | Premiere_Pro_Set-Up.exe | C:\Users\admin\AppData\Local\Temp\{52B9FE7B-4F75-4856-BE99-78CB51D1E9BC}\js\utils.js | txt | |
MD5:11671543588B007E7BE2AF6C784CB8AC | SHA256:BC354F2E25FE40AE21745C51B06D8F34643E238EE67FB94F5CD59C9B56AC17F5 | |||
| 188 | Premiere_Pro_Set-Up.exe | C:\Users\admin\AppData\Local\Temp\{52B9FE7B-4F75-4856-BE99-78CB51D1E9BC}\clean.css | text | |
MD5:4F3364AF3E396F92A8826532BFB1A7E5 | SHA256:45B9B77499356527E9047256DB96A542A720BF075D67E9F6BA55D51FD562339E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5340 | svchost.exe | GET | 200 | 23.48.23.164:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5340 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
188 | Premiere_Pro_Set-Up.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D | unknown | — | — | whitelisted |
188 | Premiere_Pro_Set-Up.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | — | — | whitelisted |
188 | Premiere_Pro_Set-Up.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAEIBkgh7xl%2BVJhmzHsukM0%3D | unknown | — | — | whitelisted |
188 | Premiere_Pro_Set-Up.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAMXnzAk6xrhhz5OEWuk8sk%3D | unknown | — | — | whitelisted |
188 | Premiere_Pro_Set-Up.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAfATp7LIVYw4gbHcu36vds%3D | unknown | — | — | whitelisted |
188 | Premiere_Pro_Set-Up.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5340 | svchost.exe | 23.48.23.164:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5340 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 104.126.37.138:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
188 | Premiere_Pro_Set-Up.exe | 52.26.194.234:443 | na1e-acc.services.adobe.com | AMAZON-02 | US | whitelisted |
188 | Premiere_Pro_Set-Up.exe | 52.31.218.129:443 | cc-api-data.adobe.io | AMAZON-02 | IE | whitelisted |
6480 | Premiere_Pro_Set-Up.exe | 52.31.218.129:443 | cc-api-data.adobe.io | AMAZON-02 | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
na1e-acc.services.adobe.com |
| whitelisted |
cc-api-data.adobe.io |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ims-prod07.adobelogin.com |
| whitelisted |
Process | Message |
|---|---|
Setup.exe | The operation completed successfully.
|
Setup.exe | The operation completed successfully.
|