File name:

Adobe Acrobat Pro DC v2020.009.20067 + Patch.zip

Full analysis: https://app.any.run/tasks/dc4e3232-2b48-46d1-ba61-1d9b2171c040
Verdict: Malicious activity
Analysis date: June 06, 2024, 13:45:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

10E77DB736C2D52BD86D1DF501DC00AC

SHA1:

A92CA976177A8794F16AEF31AE676E1753794E7D

SHA256:

A702981B8436872AF5A9963706912921E8484B41B8F0060C1D09EBDED9597813

SSDEEP:

98304:eV8DfojEP0spDkhBVTEog5hzVXqQhiY118D8wYLQPXqTrZn5x2dewdJ7IMdpS3gk:hcG6lLaGUH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • Setup.exe (PID: 1932)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 1788)
    • Checks for external IP

      • Setup.exe (PID: 1788)
    • Reads the Internet Settings

      • Setup.exe (PID: 1788)
    • Potential Corporate Privacy Violation

      • Setup.exe (PID: 1788)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 1116)
      • Setup.exe (PID: 1660)
      • Setup.exe (PID: 1932)
      • wmpnscfg.exe (PID: 1600)
    • Checks supported languages

      • Setup.exe (PID: 1932)
      • wmpnscfg.exe (PID: 1600)
      • Setup.exe (PID: 1788)
    • Reads the computer name

      • Setup.exe (PID: 1788)
      • wmpnscfg.exe (PID: 1600)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 1788)
    • Creates files or folders in the user directory

      • Setup.exe (PID: 1788)
    • Creates files in the program directory

      • Setup.exe (PID: 1788)
    • Checks proxy server information

      • Setup.exe (PID: 1788)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:06:06 15:36:08
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Adobe Acrobat Pro DC v2020.009.20067 + Patch/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs setup.exe no specs setup.exe setup.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1116"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Setup (password is THEPIRATEBAY007).zip" "C:\Users\admin\Desktop\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Setup (password is THEPIRATEBAY007)\"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1600"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1660"C:\Users\admin\Desktop\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Setup (password is THEPIRATEBAY007)\Setup.exe" C:\Users\admin\Desktop\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Setup (password is THEPIRATEBAY007)\Setup.exeexplorer.exe
User:
admin
Company:
Ilya Morozov
Integrity Level:
MEDIUM
Description:
Balabolka
Exit code:
3221226540
Version:
2.15.0.783
Modules
Images
c:\users\admin\desktop\adobe acrobat pro dc v2020.009.20067 + patch\setup (password is thepiratebay007)\setup.exe
c:\windows\system32\ntdll.dll
1788"C:\Users\admin\Desktop\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Setup (password is THEPIRATEBAY007)\Setup.exe" C:\Users\admin\Desktop\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Setup (password is THEPIRATEBAY007)\Setup.exe
Setup.exe
User:
admin
Company:
Ilya Morozov
Integrity Level:
HIGH
Description:
Balabolka
Version:
2.15.0.783
Modules
Images
c:\users\admin\desktop\adobe acrobat pro dc v2020.009.20067 + patch\setup (password is thepiratebay007)\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
1932"C:\Users\admin\Desktop\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Setup (password is THEPIRATEBAY007)\Setup.exe" C:\Users\admin\Desktop\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Setup (password is THEPIRATEBAY007)\Setup.exe
explorer.exe
User:
admin
Company:
Ilya Morozov
Integrity Level:
HIGH
Description:
Balabolka
Exit code:
0
Version:
2.15.0.783
Modules
Images
c:\users\admin\desktop\adobe acrobat pro dc v2020.009.20067 + patch\setup (password is thepiratebay007)\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3988"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Adobe Acrobat Pro DC v2020.009.20067 + Patch.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
4 499
Read events
4 454
Write events
39
Delete events
6

Modification events

(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3988) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Adobe Acrobat Pro DC v2020.009.20067 + Patch.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
0
Suspicious files
1
Text files
3
Unknown types
2

Dropped files

PID
Process
Filename
Type
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3988.38099\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Adobe Acrobat Pro DC v2020.009.20067 + Patch.dat
MD5:
SHA256:
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3988.38099\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Info.nfotxt
MD5:0569C35974881BADB2F24361DE14B378
SHA256:8AFB62F37C1C8C10FEF43FD9B8BE560EC7D5AAB6728CC35998B18B9FFE70640C
1788Setup.exeC:\ProgramData\krosqm.txttext
MD5:A77247F78AADDCB7512DAF55101C7292
SHA256:85385742F4F50A3C4AA1BE7ACFB0DE00BEEAD71A18861AB9254E5D69F7F14C85
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3988.38099\Adobe Acrobat Pro DC v2020.009.20067 + Patch\THEPIRATEBAY.ORG.urlurl
MD5:F0A05245942DF80720C52D58064731EE
SHA256:650CAE89065A9B00E4A7A1F3DFE4FB03A33F5BF96453A71DB1C05B30F5469F66
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3988.38099\Adobe Acrobat Pro DC v2020.009.20067 + Patch\READ HOW TO INSTALL.txttext
MD5:F0C167FF42EF37405C7E03BBCCB656CD
SHA256:8846AB9D218B3ACC19BBF05CC3442BD27E9D31AC2E36C2B5462ACDF0E6205E4E
3988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3988.38099\Adobe Acrobat Pro DC v2020.009.20067 + Patch\Setup (password is THEPIRATEBAY007).zipcompressed
MD5:5A7B05AF6BE77D411D38E4B9603DE6FB
SHA256:F9FF859F39A9E54D733F9C3DA77A0C42A4F9C6C53ECCCCFD7E874B8B5018EC96
1788Setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\UNPIQYHG.txttext
MD5:A77247F78AADDCB7512DAF55101C7292
SHA256:85385742F4F50A3C4AA1BE7ACFB0DE00BEEAD71A18861AB9254E5D69F7F14C85
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
19
DNS requests
1
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1788
Setup.exe
GET
200
104.26.12.205:80
http://api.ipify.org/?format=xml
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
1788
Setup.exe
104.26.12.205:80
api.ipify.org
CLOUDFLARENET
US
unknown
1788
Setup.exe
45.93.201.181:80
IT Resheniya LLC
RU
malicious

DNS requests

Domain
IP
Reputation
api.ipify.org
  • 104.26.12.205
  • 104.26.13.205
  • 172.67.74.152
shared

Threats

PID
Process
Class
Message
1088
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
1788
Setup.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup (ipify .org)
1788
Setup.exe
Device Retrieving External IP Address Detected
SUSPICIOUS [ANY.RUN] Received IP address from server as result of HTTP request
No debug info