File name:

AdobeAcroCleaner_DC2021.exe

Full analysis: https://app.any.run/tasks/8601221f-4610-4e64-9381-9837dd0532c4
Verdict: Malicious activity
Analysis date: November 18, 2025, 00:09:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
phishing
phish-img
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 9 sections
MD5:

8690F654B1F942BA8D534136F5F01F8A

SHA1:

AD712610550F794D8E57D037AB6ECCD9F1CD4F3B

SHA256:

AF48D67AC8F753EE0A9784E0FE17E4C0419849CEB3A80A3E4533FD9AA2D0AA78

SSDEEP:

49152:pkRk+53lh3xP+oxrjLAxvg8MWLVKLR5S1vk8:Ek+53lh3xP+oxrjLAxvg8MWLoLj6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Phishing has been detected

      • msiexec.exe (PID: 7716)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7716)
    • Application launched itself

      • msiexec.exe (PID: 7716)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 8124)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 7716)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 7716)
    • Reads the date of Windows installation

      • msiexec.exe (PID: 7716)
    • Executes application which crashes

      • AdobeAcroCleaner_DC2021.exe (PID: 7560)
    • Reads security settings of Internet Explorer

      • AdobeAcroCleaner_DC2021.exe (PID: 7560)
  • INFO

    • The sample compiled with english language support

      • AdobeAcroCleaner_DC2021.exe (PID: 7560)
      • msiexec.exe (PID: 7716)
    • Reads the computer name

      • AdobeAcroCleaner_DC2021.exe (PID: 7560)
      • msiexec.exe (PID: 7716)
      • msiexec.exe (PID: 7796)
      • msiexec.exe (PID: 8124)
      • msiexec.exe (PID: 7992)
      • FullTrustNotifier.exe (PID: 2500)
      • MSI69E3.tmp (PID: 8180)
    • Checks supported languages

      • AdobeAcroCleaner_DC2021.exe (PID: 7560)
      • msiexec.exe (PID: 7796)
      • msiexec.exe (PID: 7716)
      • msiexec.exe (PID: 7992)
      • MSI69E3.tmp (PID: 8180)
      • FullTrustNotifier.exe (PID: 2500)
      • msiexec.exe (PID: 8124)
    • Create files in a temporary directory

      • AdobeAcroCleaner_DC2021.exe (PID: 7560)
    • Reads Environment values

      • msiexec.exe (PID: 7796)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7716)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 7716)
    • Checks proxy server information

      • WerFault.exe (PID: 7400)
    • Reads the software policy settings

      • WerFault.exe (PID: 7400)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 7400)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2021:02:02 03:36:53+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.24
CodeSize: 1265152
InitializedDataSize: 1608192
UninitializedDataSize: -
EntryPoint: 0x5349
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.0.0.27840
ProductVersionNumber: 4.0.0.27840
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 4, 0, 0, 421056
OriginalFileName: AdbeArCleaner.exe
ProductVersion: 4, 0, 0, 421056
FileDescription: Adobe Acrobat DC Cleaner Tool
InternalName: Adobe Acrobat DC ® Cleaner Tool
LegalCopyright: Copyright © 2021 Adobe Systems Incorporated
ProductName: Adobe Acrobat DC Cleaner Tool
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
11
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start adobeacrocleaner_dc2021.exe THREAT msiexec.exe msiexec.exe no specs msiexec.exe no specs msi69e3.tmp no specs fulltrustnotifier.exe rundll32.exe no specs slui.exe no specs msiexec.exe no specs werfault.exe adobeacrocleaner_dc2021.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
464C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2500"C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe" ClearToastsC:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe
msiexec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\rdcnotificationclient\fulltrustnotifier.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6360C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\ANCUtility.dll",removeAppxInUserContextC:\Windows\System32\rundll32.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7396"C:\Users\admin\AppData\Local\Temp\AdobeAcroCleaner_DC2021.exe" C:\Users\admin\AppData\Local\Temp\AdobeAcroCleaner_DC2021.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Adobe Acrobat DC Cleaner Tool
Exit code:
3221226540
Version:
4, 0, 0, 421056
Modules
Images
c:\users\admin\appdata\local\temp\adobeacrocleaner_dc2021.exe
c:\windows\system32\ntdll.dll
7400C:\WINDOWS\system32\WerFault.exe -u -p 7560 -s 912C:\Windows\System32\WerFault.exe
AdobeAcroCleaner_DC2021.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\oleaut32.dll
7560"C:\Users\admin\AppData\Local\Temp\AdobeAcroCleaner_DC2021.exe" C:\Users\admin\AppData\Local\Temp\AdobeAcroCleaner_DC2021.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Adobe Acrobat DC Cleaner Tool
Exit code:
3221226356
Version:
4, 0, 0, 421056
Modules
Images
c:\users\admin\appdata\local\temp\adobeacrocleaner_dc2021.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\msi.dll
c:\windows\system32\win32u.dll
7716C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7796C:\Windows\System32\MsiExec.exe -Embedding E70B4736F6FE97A14C8898573E680293C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7992C:\Windows\syswow64\MsiExec.exe -Embedding 5D375E0DED140321B62E192465456B25 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
8124C:\Windows\System32\MsiExec.exe -Embedding DB5E7A8C1B147284F321462541C7F20A E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
28 297
Read events
25 496
Write events
195
Delete events
2 606

Modification events

(PID) Process:(7716) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(7716) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\16529b.rbs
Value:
31217695
(PID) Process:(7716) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\16529b.rbsLow
Value:
(PID) Process:(7716) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\TempPackages
Operation:writeName:C:\WINDOWS\Installer\41457.msi
Value:
0
(PID) Process:(7716) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-1033-FF00-7760-BC15014EA700}
Operation:delete valueName:AuthorizedCDFPrefix
Value:
(PID) Process:(7716) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-1033-FF00-7760-BC15014EA700}
Operation:delete valueName:Comments
Value:
(PID) Process:(7716) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-1033-FF00-7760-BC15014EA700}
Operation:delete valueName:Contact
Value:
Customer Support
(PID) Process:(7716) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-1033-FF00-7760-BC15014EA700}
Operation:delete valueName:DisplayVersion
Value:
23.001.20093
(PID) Process:(7716) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-1033-FF00-7760-BC15014EA700}
Operation:delete valueName:HelpLink
Value:
http://www.adobe.com/support/main.html
(PID) Process:(7716) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-1033-FF00-7760-BC15014EA700}
Operation:delete valueName:HelpTelephone
Value:
Executable files
315
Suspicious files
99
Text files
504
Unknown types
1

Dropped files

PID
Process
Filename
Type
7716msiexec.exeC:\Windows\Installer\MSI5DF4.tmpexecutable
MD5:F1D358E969B4C81A0565A5530BF620E7
SHA256:36C1BA6137DEC0B6BFCFF7198B019418537504A1CB74BDEBF3BDE69F230748FF
7716msiexec.exeC:\Windows\Installer\MSI5598.tmpexecutable
MD5:F1D358E969B4C81A0565A5530BF620E7
SHA256:36C1BA6137DEC0B6BFCFF7198B019418537504A1CB74BDEBF3BDE69F230748FF
7716msiexec.exeC:\Windows\Installer\MSI5820.tmpexecutable
MD5:0FB71A79C1269E2BA50FB92EB92866D6
SHA256:E9E4ADFA160CE9BBEDA6A083C42562FDB33A8C9261F85EDC682528333813B7B6
7716msiexec.exeC:\Windows\Installer\MSI5A28.tmpexecutable
MD5:51A8DEC0247B569E10042F1543FBDB32
SHA256:8EBA0B040FB6DBB0F5DACBDFA9E2929CBAAAB12865012ED7DDA9CCDC09124A48
7716msiexec.exeC:\Windows\Installer\MSI54DB.tmpexecutable
MD5:F1D358E969B4C81A0565A5530BF620E7
SHA256:36C1BA6137DEC0B6BFCFF7198B019418537504A1CB74BDEBF3BDE69F230748FF
7716msiexec.exeC:\Windows\Installer\MSI5E33.tmpexecutable
MD5:0FB71A79C1269E2BA50FB92EB92866D6
SHA256:E9E4ADFA160CE9BBEDA6A083C42562FDB33A8C9261F85EDC682528333813B7B6
7716msiexec.exeC:\Windows\Installer\MSI5F31.tmp
MD5:
SHA256:
7716msiexec.exeC:\Windows\Installer\MSI5EB2.tmpexecutable
MD5:F1D358E969B4C81A0565A5530BF620E7
SHA256:36C1BA6137DEC0B6BFCFF7198B019418537504A1CB74BDEBF3BDE69F230748FF
7716msiexec.exeC:\Windows\Installer\MSI5626.tmpexecutable
MD5:F1D358E969B4C81A0565A5530BF620E7
SHA256:36C1BA6137DEC0B6BFCFF7198B019418537504A1CB74BDEBF3BDE69F230748FF
7716msiexec.exeC:\Windows\Installer\165299.mstbinary
MD5:856151CCCC50F9B0CF75793DB8ACD1CB
SHA256:1E60EDD8B2B37BE5FBEE076F74F7F2EEABB66B03D254049414087304D796EF8C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
32
DNS requests
19
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1936
svchost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5596
MoUsoCoreWorker.exe
GET
200
95.101.35.8:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4316
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4316
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.3.crl
unknown
whitelisted
4316
SIHClient.exe
GET
200
95.101.35.8:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
4316
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
4316
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.3.crl
unknown
whitelisted
4316
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.2.crl
unknown
whitelisted
4316
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
unknown
whitelisted
7400
WerFault.exe
GET
200
23.3.109.244:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5596
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1936
svchost.exe
40.126.31.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.241.218:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
1936
svchost.exe
20.190.159.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1936
svchost.exe
172.66.2.5:80
ocsp.digicert.com
US
whitelisted
5596
MoUsoCoreWorker.exe
95.101.35.8:80
crl.microsoft.com
Orange
NL
whitelisted
2388
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3440
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
login.live.com
  • 40.126.31.3
  • 20.190.159.130
  • 40.126.31.0
  • 20.190.159.68
  • 20.190.159.2
  • 40.126.31.71
  • 40.126.31.129
  • 20.190.159.75
  • 20.190.159.73
  • 20.190.159.71
  • 20.190.159.128
  • 40.126.31.67
  • 40.126.31.1
  • 40.126.31.131
whitelisted
www.bing.com
  • 2.16.241.218
  • 2.16.241.201
whitelisted
google.com
  • 142.250.181.238
whitelisted
ocsp.digicert.com
  • 172.66.2.5
  • 162.159.142.9
whitelisted
crl.microsoft.com
  • 95.101.35.8
  • 95.101.35.35
  • 2.20.245.137
  • 2.20.245.138
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 74.178.240.61
whitelisted
www.microsoft.com
  • 2.23.181.156
  • 23.3.109.244
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
FullTrustNotifier.exe
FullTrustNotifier.exe
FN ClearToasts
FullTrustNotifier.exe
FullTrustNotifier.exe
FullTrustNotifier
FullTrustNotifier.exe
FullTrustNotifier.exe
FN ConnectToAppService create the async task
FullTrustNotifier.exe
FullTrustNotifier.exe
ConnectToAppServiceAsync AppNotInstalled
FullTrustNotifier.exe
FullTrustNotifier.exe
FullTrustNotifier Exit