File name:

AdobePhotoshop-Autoplay [ FULL CRACK ].exe

Full analysis: https://app.any.run/tasks/1a210ac7-43b0-40c2-a8cd-f34a654c8fde
Verdict: Malicious activity
Analysis date: May 24, 2024, 15:15:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B90DE70C67A43AC4C7A1DDB5AABD6CD7

SHA1:

0E55FF2D5BC526683C7417646AC14FCB048B6329

SHA256:

CE93ADCC6E41113BB973D728AE161C91D9B742C6510CE3F9AEFD3DAD792DEAD1

SSDEEP:

12288:y8ZonSs9SlVbXUBg/NbMzPclGQ0TF2RN+NtcdoVrwTWD4Gv6Og2e7N0pyFLcbKj7:rhE20TZZlXrE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
      • sipnotify.exe (PID: 280)
    • Reads the Internet Settings

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
      • sipnotify.exe (PID: 280)
    • Reads security settings of Internet Explorer

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
    • Checks Windows Trust Settings

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 280)
      • ctfmon.exe (PID: 1816)
  • INFO

    • Checks supported languages

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
      • wmpnscfg.exe (PID: 1036)
      • wmpnscfg.exe (PID: 2364)
      • IMEKLMG.EXE (PID: 2128)
      • wmpnscfg.exe (PID: 2384)
      • IMEKLMG.EXE (PID: 2120)
    • Reads the computer name

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
      • wmpnscfg.exe (PID: 1036)
      • IMEKLMG.EXE (PID: 2120)
      • IMEKLMG.EXE (PID: 2128)
      • wmpnscfg.exe (PID: 2364)
      • wmpnscfg.exe (PID: 2384)
    • Checks proxy server information

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
    • Reads the software policy settings

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
      • sipnotify.exe (PID: 280)
    • Reads the machine GUID from the registry

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
    • Creates files or folders in the user directory

      • AdobePhotoshop-Autoplay [ FULL CRACK ].exe (PID: 3996)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1036)
      • IMEKLMG.EXE (PID: 2128)
      • wmpnscfg.exe (PID: 2364)
      • wmpnscfg.exe (PID: 2384)
      • IMEKLMG.EXE (PID: 2120)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 2120)
      • IMEKLMG.EXE (PID: 2128)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:05:19 12:02:11+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 1244160
InitializedDataSize: 75264
UninitializedDataSize: -
EntryPoint: 0x111237
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
88
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start adobephotoshop-autoplay [ full crack ].exe wmpnscfg.exe no specs msbuild.exe no specs ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1036"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1816C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2044"C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeAdobePhotoshop-Autoplay [ FULL CRACK ].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
MSBuild.exe
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\msbuild.exe
c:\windows\system32\ntdll.dll
2120"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2128"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2364"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2384"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3996"C:\Users\admin\Downloads\AdobePhotoshop-Autoplay [ FULL CRACK ].exe" C:\Users\admin\Downloads\AdobePhotoshop-Autoplay [ FULL CRACK ].exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\downloads\adobephotoshop-autoplay [ full crack ].exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
7 616
Read events
7 523
Write events
62
Delete events
31

Modification events

(PID) Process:(3996) AdobePhotoshop-Autoplay [ FULL CRACK ].exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3996) AdobePhotoshop-Autoplay [ FULL CRACK ].exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3996) AdobePhotoshop-Autoplay [ FULL CRACK ].exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(3996) AdobePhotoshop-Autoplay [ FULL CRACK ].exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(3996) AdobePhotoshop-Autoplay [ FULL CRACK ].exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(3996) AdobePhotoshop-Autoplay [ FULL CRACK ].exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3996) AdobePhotoshop-Autoplay [ FULL CRACK ].exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3996) AdobePhotoshop-Autoplay [ FULL CRACK ].exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3996) AdobePhotoshop-Autoplay [ FULL CRACK ].exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3996) AdobePhotoshop-Autoplay [ FULL CRACK ].exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
4
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3996AdobePhotoshop-Autoplay [ FULL CRACK ].exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:58377863B81AFAD039B264696070F3BE
SHA256:4B3269B1DF979B60097719E464C8F8122501F17840B88AAD450EFB58F0617EF4
3996AdobePhotoshop-Autoplay [ FULL CRACK ].exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619binary
MD5:6B59D314340CC6F14AB07AECEDC2D03B
SHA256:EAC8088A15EA73C47F1E162850C9D661064CC06981A881768A06886095FC43C7
280sipnotify.exeC:\Users\admin\AppData\Local\microsoft\windows\SipNotify\eoscontent\microsoft-logo.pngimage
MD5:B7C73A0CFBA68CC70C35EF9C63703CE4
SHA256:1D8B27A0266FF526CF95447F3701592A908848467D37C09A00A2516C1F29A013
280sipnotify.exeC:\Users\admin\AppData\Local\microsoft\windows\SipNotify\eoscontent\metadata.jsonbinary
MD5:E8A970BA6CE386EED9A5E724F26212A6
SHA256:7E06107D585D8FC7870998F3856DCC3E35800AA97E4406AAB83BC8444B6CBDE3
280sipnotify.exeC:\Users\admin\AppData\Local\microsoft\windows\SipNotify\eoscontent\script.jstext
MD5:A2682382967C351F7ED21762F9E5DE9E
SHA256:36B1D26F1EC69685648C0528C2FCE95A3C2DBECF828CDFA4A8B4239A15B644A2
280sipnotify.exeC:\Users\admin\AppData\Local\microsoft\windows\SipNotify\eoscontent\main.jpgimage
MD5:B342ACE63F77961249A084C61EABC884
SHA256:E5067BBA2095B5DA7C3171EC116E9A92337E24E471339B0860A160076EFE49B9
280sipnotify.exeC:\Users\admin\AppData\Local\microsoft\windows\SipNotify\eoscontent\styles.csstext
MD5:3383EEF350240253D7C2C2564381B3CB
SHA256:85443493D86D6D7FB0E07BC9705DFC9C858086FBA1B0E508092AB328D5F145E8
3996AdobePhotoshop-Autoplay [ FULL CRACK ].exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619binary
MD5:33F3570AE3776528E577C9AB382C1CD2
SHA256:D3280481F63CF7DF21C90D9D761746F4CBFDC9BF71670264BFB04E81D2D3AA81
280sipnotify.exeC:\Users\admin\AppData\Local\microsoft\windows\SipNotify\eoscontent\en-us.htmlhtml
MD5:9752942B57692148B9F614CF4C119A36
SHA256:E31B834DD53FA6815F396FC09C726636ABF98F3367F0CF1590EF5EB3801C75D1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
16
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3996
AdobePhotoshop-Autoplay [ FULL CRACK ].exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D
unknown
unknown
3996
AdobePhotoshop-Autoplay [ FULL CRACK ].exe
GET
304
23.73.136.138:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c011dc733c9fad8c
unknown
unknown
280
sipnotify.exe
HEAD
200
104.110.23.132:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133610410696870000
unknown
unknown
1088
svchost.exe
GET
304
23.213.230.89:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e3b3887a217ca203
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
3996
AdobePhotoshop-Autoplay [ FULL CRACK ].exe
104.192.141.1:443
bitbucket.org
AMAZON-02
US
unknown
3996
AdobePhotoshop-Autoplay [ FULL CRACK ].exe
23.73.136.138:80
ctldl.windowsupdate.com
Akamai International B.V.
GB
unknown
3996
AdobePhotoshop-Autoplay [ FULL CRACK ].exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1088
svchost.exe
23.213.230.89:80
ctldl.windowsupdate.com
Akamai International B.V.
CA
unknown
1084
svchost.exe
224.0.0.252:5355
unknown
1436
svchost.exe
239.255.255.250:3702
unknown
280
sipnotify.exe
104.110.23.132:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
NO
unknown

DNS requests

Domain
IP
Reputation
bitbucket.org
  • 104.192.141.1
shared
ctldl.windowsupdate.com
  • 23.73.136.138
  • 23.73.136.107
  • 23.73.136.123
  • 23.73.136.145
  • 23.73.136.139
  • 23.213.230.89
  • 23.213.230.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
query.prod.cms.rt.microsoft.com
  • 104.110.23.132
whitelisted

Threats

No threats detected
No debug info