| File name: | sdcnm_setup_x86.zip |
| Full analysis: | https://app.any.run/tasks/fe944ebb-6363-46fc-a988-d3408a94ef29 |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | October 21, 2020, 19:40:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | E9AF50591D18AB786A2F7CCEB45558C7 |
| SHA1: | 1400B3D725A7E8E603CBED2E80BCCFACE17AC924 |
| SHA256: | CCCF11968C15F602A17750C7BBC35BD0C547A539A606863612743417E9A7BBEB |
| SSDEEP: | 196608:XPZM7LCge8aQ2iCL+sTpUuIzTpJNqBqTQGfPhfZslH7w/Hsfjma:XPZlgBaQTyfMvpQqsGfPhfGlH8fcqa |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2020:09:18 10:34:18 |
| ZipCRC: | 0x88eca5b2 |
| ZipCompressedSize: | 9247976 |
| ZipUncompressedSize: | 9320586 |
| ZipFileName: | sdcnm_setup_x86.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 308 | "C:\Windows\SAFE-DOC\PrtSetupX.exe" /VERYSILENT /PASSWORD=ActMask_PrtSetupX140516.lice@acessodigital.com.br Install ActPrint1234 "ActMask PDF Virtual Printer SDK" ActMask_DPI300 http://www.all2pdf.com disupdate | C:\Windows\SAFE-DOC\PrtSetupX.exe | — | actmask34.tmp | |||||||||||
User: admin Company: ActMask Co.,Ltd Integrity Level: HIGH Description: ActPrint Virtual Printer Driver X Exit code: 0 Version: 3.3 Modules
| |||||||||||||||
| 832 | "C:\Program Files\Common Files\ActPrint\PrintDisp.exe" /uninstall | C:\Program Files\Common Files\ActPrint\PrintDisp.exe | — | PrtSetupX.tmp | |||||||||||
User: admin Company: ActMask Co.,Ltd - http://www.all2pdf.com Integrity Level: HIGH Description: PrintDisp Exit code: 0 Version: 3.4.39.139 Modules
| |||||||||||||||
| 2116 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3288.11454\sdcnm_setup_x86.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3288.11454\sdcnm_setup_x86.exe | WinRAR.exe | ||||||||||||
User: admin Company: Acesso Digital Integrity Level: MEDIUM Description: SAFE-DOC Capture Setup Exit code: 0 Version: 20.3.0 Modules
| |||||||||||||||
| 2156 | C:\Windows\system32\net1 stop "Printer Control" | C:\Windows\system32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2236 | "C:\Users\admin\AppData\Local\Temp\is-LLRII.tmp\actmask34.exe" /VERYSILENT /PASSWORD=140516.lice@acessodigital.com.br | C:\Users\admin\AppData\Local\Temp\is-LLRII.tmp\actmask34.exe | sdcnm_setup_x86.tmp | ||||||||||||
User: admin Company: ActMask Co.,Ltd Integrity Level: HIGH Description: ActMask PDF Virtual Printer SDK Exit code: 0 Version: Modules
| |||||||||||||||
| 2284 | "C:\Program Files\Common Files\ActPrint\InstPrtX.exe" Install ActPrint1234 "2k,xp,2k3,vta,w7,2k8,w8,w8.1,2k12,2k12.1," "acessodigital.com.br" | C:\Program Files\Common Files\ActPrint\InstPrtX.exe | — | PrtSetupX.tmp | |||||||||||
User: admin Company: ActMask Co.,Ltd Integrity Level: HIGH Exit code: 0 Version: 3.3.9.227 Modules
| |||||||||||||||
| 2300 | "C:\Users\admin\AppData\Local\Temp\is-Q9O3M.tmp\sdcnm_setup_x86.tmp" /SL5="$1001B2,8920971,121344,C:\Users\admin\AppData\Local\Temp\Rar$EXa3288.11454\sdcnm_setup_x86.exe" /SPAWNWND=$B01CA /NOTIFYWND=$B0198 | C:\Users\admin\AppData\Local\Temp\is-Q9O3M.tmp\sdcnm_setup_x86.tmp | sdcnm_setup_x86.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2360 | "C:\Windows\system32\net.exe" stop "Printer Control" | C:\Windows\system32\net.exe | — | PrtSetupX.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2480 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3288.11454\sdcnm_setup_x86.exe" /SPAWNWND=$B01CA /NOTIFYWND=$B0198 | C:\Users\admin\AppData\Local\Temp\Rar$EXa3288.11454\sdcnm_setup_x86.exe | sdcnm_setup_x86.tmp | ||||||||||||
User: admin Company: Acesso Digital Integrity Level: HIGH Description: SAFE-DOC Capture Setup Exit code: 0 Version: 20.3.0 Modules
| |||||||||||||||
| 2696 | "C:\Program Files\Common Files\ActPrint\PrintDisp.exe" /uninstall | C:\Program Files\Common Files\ActPrint\PrintDisp.exe | — | PrtSetupX.tmp | |||||||||||
User: admin Company: ActMask Co.,Ltd - http://www.all2pdf.com Integrity Level: HIGH Description: PrintDisp Exit code: 0 Version: 3.4.39.139 Modules
| |||||||||||||||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\sdcnm_setup_x86.zip | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2300 | sdcnm_setup_x86.tmp | C:\Users\admin\AppData\Local\Temp\CabAADB.tmp | — | |
MD5:— | SHA256:— | |||
| 2300 | sdcnm_setup_x86.tmp | C:\Users\admin\AppData\Local\Temp\TarAADC.tmp | — | |
MD5:— | SHA256:— | |||
| 3344 | actmask34.tmp | C:\Users\admin\AppData\Local\Temp\is-IJLRI.tmp\gdiplus.dll | — | |
MD5:— | SHA256:— | |||
| 3344 | actmask34.tmp | C:\Windows\SAFE-DOC\is-6FR1I.tmp | — | |
MD5:— | SHA256:— | |||
| 3344 | actmask34.tmp | C:\Windows\SAFE-DOC\is-I286Q.tmp | — | |
MD5:— | SHA256:— | |||
| 3344 | actmask34.tmp | C:\Windows\SAFE-DOC\is-39I5A.tmp | — | |
MD5:— | SHA256:— | |||
| 3344 | actmask34.tmp | C:\Windows\SAFE-DOC\is-UIKIV.tmp | — | |
MD5:— | SHA256:— | |||
| 3344 | actmask34.tmp | C:\Windows\system32\is-QJS1G.tmp | — | |
MD5:— | SHA256:— | |||
| 3344 | actmask34.tmp | C:\Windows\system32\is-IFHTF.tmp | — | |
MD5:— | SHA256:— | |||
| 3344 | actmask34.tmp | C:\Windows\system32\is-S0Q9H.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2300 | sdcnm_setup_x86.tmp | HEAD | 301 | 45.223.19.56:80 | http://download.acessodigital.com.br/1F6C1DA1-CD0E-45EE-8F4C-24C1DC9B9824/actmask34.exe | US | — | — | malicious |
2300 | sdcnm_setup_x86.tmp | GET | 301 | 45.223.19.56:80 | http://download.acessodigital.com.br/1F6C1DA1-CD0E-45EE-8F4C-24C1DC9B9824/actmask34.exe | US | — | — | malicious |
2300 | sdcnm_setup_x86.tmp | HEAD | 301 | 45.223.19.56:80 | http://download.acessodigital.com.br/1F6C1DA1-CD0E-45EE-8F4C-24C1DC9B9824/kodaki900215.exe | US | — | — | malicious |
2300 | sdcnm_setup_x86.tmp | GET | 301 | 45.223.19.56:80 | http://download.acessodigital.com.br/1F6C1DA1-CD0E-45EE-8F4C-24C1DC9B9824/kodaki900215.exe | US | — | — | malicious |
2300 | sdcnm_setup_x86.tmp | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/rootr1/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDkbwjNvPLFRm7zMB3V80 | US | der | 1.49 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2300 | sdcnm_setup_x86.tmp | 45.223.19.56:80 | download.acessodigital.com.br | — | US | malicious |
2300 | sdcnm_setup_x86.tmp | 45.223.19.56:443 | download.acessodigital.com.br | — | US | malicious |
— | — | 45.223.19.56:80 | download.acessodigital.com.br | — | US | malicious |
2300 | sdcnm_setup_x86.tmp | 104.18.20.226:80 | ocsp.globalsign.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
download.acessodigital.com.br |
| malicious |
ocsp.globalsign.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2300 | sdcnm_setup_x86.tmp | Misc activity | ADWARE [PTsecurity] PUP.Win32/Freemake.A UserAgent |
2300 | sdcnm_setup_x86.tmp | Misc activity | ADWARE [PTsecurity] PUP.Win32/Freemake.A UserAgent |
2300 | sdcnm_setup_x86.tmp | Misc activity | ADWARE [PTsecurity] PUP.Win32/Freemake.A UserAgent |
2300 | sdcnm_setup_x86.tmp | Misc activity | ADWARE [PTsecurity] PUP.Win32/Freemake.A UserAgent |