| File name: | Adobe Acrobate Reader Pro-HAv70.msi |
| Full analysis: | https://app.any.run/tasks/10c5d187-0f88-49c5-8055-b8c171ba3962 |
| Verdict: | Malicious activity |
| Threats: | Metamorfo is a trojan malware family that has been active since 2018. It remains a top threat, focusing on stealing victims’ financial information, including banking credentials and other data. The malware is known for targeting users in Brazil. |
| Analysis date: | December 10, 2023, 02:12:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {D69B9218-2190-4716-88FD-CE4B13CFF25A}, Number of Words: 10, Subject: Adobe Acrobat Reader, Author: Adobe Acrobat Reader, Name of Creating Application: Adobe Acrobat Reader (Evaluation Installer), Template: ;1046, Comments: A base dados do instalador contm a lgica e os dados necessrios para instalar o Adobe Acrobat Reader. (Evaluation Installer), Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Wed Nov 22 02:10:54 2023, Last Saved Time/Date: Wed Nov 22 02:10:54 2023, Last Printed: Wed Nov 22 02:10:54 2023, Number of Pages: 450 |
| MD5: | 9175FED68D5D38DEE94BBD059F9ED69A |
| SHA1: | CB094B6EB86A9FB8C8BCB5A3A7567CC72858EAAA |
| SHA256: | D8FC4F696F4BD1899ED92D8E9767646308C941CAC2EA826DBDD3E64F6926DB3D |
| SSDEEP: | 393216:Du1r1tF5xjBacTM63s8XzORZqtkhflkIEIGGaYIh:MH5PrZCxdGvc9Ih |
| .msi | | | Microsoft Windows Installer (81.9) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (9.2) |
| .msp | | | Windows Installer Patch (7.6) |
| .msi | | | Microsoft Installer (100) |
| Security: | None |
|---|---|
| CodePage: | Windows Latin 1 (Western European) |
| RevisionNumber: | {D69B9218-2190-4716-88FD-CE4B13CFF25A} |
| Words: | 10 |
| Subject: | Adobe Acrobat Reader |
| Author: | Adobe Acrobat Reader |
| LastModifiedBy: | - |
| Software: | Adobe Acrobat Reader (Evaluation Installer) |
| Template: | ;1046 |
| Comments: | A base dados do instalador contêm a lógica e os dados necessários para instalar o Adobe Acrobat Reader. (Evaluation Installer) |
| Title: | Installation Database |
| Keywords: | Installer, MSI, Database |
| CreateDate: | 2023:11:22 02:10:54 |
| ModifyDate: | 2023:11:22 02:10:54 |
| LastPrinted: | 2023:11:22 02:10:54 |
| Pages: | 450 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 332 | C:\Windows\syswow64\MsiExec.exe -Embedding 81F3D44952D9D051B6D0FC88A83115AD | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 996 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2736 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Adobe Acrobate Reader Pro-HAv70.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2800 | "C:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\Adobe Acrobat Pro.exe" | C:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\Adobe Acrobat Pro.exe | msiexec.exe | ||||||||||||
User: admin Company: VSO Software SARL Integrity Level: MEDIUM Description: Converter from almost all type of video/audio file to DVD that can be played on every standalone DVD players Exit code: 0 Version: 7.0.0.69 Modules
| |||||||||||||||
| (PID) Process: | (996) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000_CLASSES\Local Settings\MuiCache\15A\52C64B7E |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (996) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000_CLASSES\Local Settings\MuiCache\15A |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (996) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts |
| Operation: | delete value | Name: | C:\Config.Msi\22c745.rbs |
Value: 31075086 | |||
| (PID) Process: | (996) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (996) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (996) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (996) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 043D09D2EEBE71E4B13850711AC789ACD0E44E5C8D14C1F1CFA58FB5EC0FFC0C | |||
| (PID) Process: | (996) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: E40300000E9C9E5B0E2BDA01 | |||
| (PID) Process: | (996) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (996) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 996 | msiexec.exe | C:\Windows\Installer\22c742.msi | — | |
MD5:— | SHA256:— | |||
| 996 | msiexec.exe | C:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\avutil.dll | executable | |
MD5:EF6839E8DB67D6995EAD096D1AAB5976 | SHA256:3653B5ABEB9BE217A07E7BD669D59322923EB4EEB0C3E8258A8BA10AF0F94962 | |||
| 996 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF0A8D673A727BEC26.TMP | binary | |
MD5:73F93B40FC83EE4B48CA4360B4F6C55E | SHA256:EBCD2BEBED286D7C035FA9C09435194AEAC8E1F5E1E590821C580E4310F024B1 | |||
| 996 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF2AA22E5C7C3D09A5.TMP | binary | |
MD5:4D1AE14A6E1FBB398485DE70B2605A77 | SHA256:F44A79D7BD31734AD1B18C0956B47AF64B734C48CAC99718E23D9A4E503EE78D | |||
| 996 | msiexec.exe | C:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\Adobe Acrobat Pro.exe | executable | |
MD5:48D732A19514BEF06ACC712F43FA7D65 | SHA256:BA4612DB8CE37B8E64D163A4C8E236B0AD2DDC223B91383F270924846394BF95 | |||
| 996 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF3C0451DEFA863CD1.TMP | binary | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||
| 996 | msiexec.exe | C:\Windows\Installer\MSICA04.tmp | binary | |
MD5:21B15DB52F4C0ACFB7748E2E15766EBF | SHA256:3470BF9C9C1A681FD1F2254944ABD5A0E1E606A66CDB532D709768F4546DBD8A | |||
| 996 | msiexec.exe | C:\Windows\Installer\MSIC85C.tmp | executable | |
MD5:5A1F2196056C0A06B79A77AE981C7761 | SHA256:52F41817669AF7AC55B1516894EE705245C3148F2997FA0E6617E9CC6353E41E | |||
| 2800 | Adobe Acrobat Pro.exe | C:\Users\admin\AppData\Local\USER-PC | text | |
MD5:A733C6991D9A0A0786ACB24545F49FCA | SHA256:A05A536FC3DB5C8A0ACA48CE4E7670AA82F1028C9E8AA1117B02B38A2D4D1E82 | |||
| 2800 | Adobe Acrobat Pro.exe | C:\ProgramData\Vso\font.cache | binary | |
MD5:7238B02DC1DB1407720A4E19A52BCF56 | SHA256:11D6E83773A1AE77D8F2E95D560EDD3E6E366C24489EE3C09DA5AE890EB9D598 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2800 | Adobe Acrobat Pro.exe | POST | 200 | 185.228.72.212:80 | http://185.228.72.212/contador/serv.php | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2800 | Adobe Acrobat Pro.exe | 185.228.72.212:80 | — | Bursabil Teknoloji A.S. | ES | unknown |