File name:

Adobe Acrobate Reader Pro-HAv70.msi

Full analysis: https://app.any.run/tasks/10c5d187-0f88-49c5-8055-b8c171ba3962
Verdict: Malicious activity
Threats:

Metamorfo is a trojan malware family that has been active since 2018. It remains a top threat, focusing on stealing victims’ financial information, including banking credentials and other data. The malware is known for targeting users in Brazil.

Analysis date: December 10, 2023, 02:12:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
generated-doc
metamorfo
trojan
opendir
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {D69B9218-2190-4716-88FD-CE4B13CFF25A}, Number of Words: 10, Subject: Adobe Acrobat Reader, Author: Adobe Acrobat Reader, Name of Creating Application: Adobe Acrobat Reader (Evaluation Installer), Template: ;1046, Comments: A base dados do instalador contm a lgica e os dados necessrios para instalar o Adobe Acrobat Reader. (Evaluation Installer), Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Wed Nov 22 02:10:54 2023, Last Saved Time/Date: Wed Nov 22 02:10:54 2023, Last Printed: Wed Nov 22 02:10:54 2023, Number of Pages: 450
MD5:

9175FED68D5D38DEE94BBD059F9ED69A

SHA1:

CB094B6EB86A9FB8C8BCB5A3A7567CC72858EAAA

SHA256:

D8FC4F696F4BD1899ED92D8E9767646308C941CAC2EA826DBDD3E64F6926DB3D

SSDEEP:

393216:Du1r1tF5xjBacTM63s8XzORZqtkhflkIEIGGaYIh:MH5PrZCxdGvc9Ih

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 996)
    • METAMORFO has been detected (YARA)

      • Adobe Acrobat Pro.exe (PID: 2800)
    • Connects to the CnC server

      • Adobe Acrobat Pro.exe (PID: 2800)
    • METAMORFO has been detected (SURICATA)

      • Adobe Acrobat Pro.exe (PID: 2800)
  • SUSPICIOUS

    • Connects to the server without a host name

      • Adobe Acrobat Pro.exe (PID: 2800)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 996)
      • msiexec.exe (PID: 332)
      • Adobe Acrobat Pro.exe (PID: 2800)
    • Checks supported languages

      • msiexec.exe (PID: 996)
      • msiexec.exe (PID: 332)
      • Adobe Acrobat Pro.exe (PID: 2800)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 996)
      • msiexec.exe (PID: 332)
      • Adobe Acrobat Pro.exe (PID: 2800)
    • Create files in a temporary directory

      • msiexec.exe (PID: 996)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 996)
      • Adobe Acrobat Pro.exe (PID: 2800)
    • Reads Environment values

      • Adobe Acrobat Pro.exe (PID: 2800)
    • Creates files in the program directory

      • Adobe Acrobat Pro.exe (PID: 2800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {D69B9218-2190-4716-88FD-CE4B13CFF25A}
Words: 10
Subject: Adobe Acrobat Reader
Author: Adobe Acrobat Reader
LastModifiedBy: -
Software: Adobe Acrobat Reader (Evaluation Installer)
Template: ;1046
Comments: A base dados do instalador contêm a lógica e os dados necessários para instalar o Adobe Acrobat Reader. (Evaluation Installer)
Title: Installation Database
Keywords: Installer, MSI, Database
CreateDate: 2023:11:22 02:10:54
ModifyDate: 2023:11:22 02:10:54
LastPrinted: 2023:11:22 02:10:54
Pages: 450
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs #METAMORFO adobe acrobat pro.exe

Process information

PID
CMD
Path
Indicators
Parent process
332C:\Windows\syswow64\MsiExec.exe -Embedding 81F3D44952D9D051B6D0FC88A83115ADC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
996C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2736"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Adobe Acrobate Reader Pro-HAv70.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2800"C:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\Adobe Acrobat Pro.exe"C:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\Adobe Acrobat Pro.exe
msiexec.exe
User:
admin
Company:
VSO Software SARL
Integrity Level:
MEDIUM
Description:
Converter from almost all type of video/audio file to DVD that can be played on every standalone DVD players
Exit code:
0
Version:
7.0.0.69
Modules
Images
c:\users\admin\appdata\roaming\adobe acrobat reader\adobe acrobat reader\adobe acrobat reader\x64\reader-pdf\adobe acrobat pro.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
2 566
Read events
2 555
Write events
1
Delete events
10

Modification events

(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000_CLASSES\Local Settings\MuiCache\15A\52C64B7E
Operation:delete keyName:(default)
Value:
(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000_CLASSES\Local Settings\MuiCache\15A
Operation:delete keyName:(default)
Value:
(PID) Process:(996) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:delete valueName:C:\Config.Msi\22c745.rbs
Value:
31075086
(PID) Process:(996) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:delete keyName:(default)
Value:
(PID) Process:(996) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
Operation:delete keyName:(default)
Value:
(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
043D09D2EEBE71E4B13850711AC789ACD0E44E5C8D14C1F1CFA58FB5EC0FFC0C
(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
E40300000E9C9E5B0E2BDA01
(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(996) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
Operation:delete keyName:(default)
Value:
Executable files
5
Suspicious files
8
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
996msiexec.exeC:\Windows\Installer\22c742.msi
MD5:
SHA256:
996msiexec.exeC:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\avutil.dllexecutable
MD5:EF6839E8DB67D6995EAD096D1AAB5976
SHA256:3653B5ABEB9BE217A07E7BD669D59322923EB4EEB0C3E8258A8BA10AF0F94962
996msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF0A8D673A727BEC26.TMPbinary
MD5:73F93B40FC83EE4B48CA4360B4F6C55E
SHA256:EBCD2BEBED286D7C035FA9C09435194AEAC8E1F5E1E590821C580E4310F024B1
996msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF2AA22E5C7C3D09A5.TMPbinary
MD5:4D1AE14A6E1FBB398485DE70B2605A77
SHA256:F44A79D7BD31734AD1B18C0956B47AF64B734C48CAC99718E23D9A4E503EE78D
996msiexec.exeC:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\Adobe Acrobat Pro.exeexecutable
MD5:48D732A19514BEF06ACC712F43FA7D65
SHA256:BA4612DB8CE37B8E64D163A4C8E236B0AD2DDC223B91383F270924846394BF95
996msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF3C0451DEFA863CD1.TMPbinary
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
996msiexec.exeC:\Windows\Installer\MSICA04.tmpbinary
MD5:21B15DB52F4C0ACFB7748E2E15766EBF
SHA256:3470BF9C9C1A681FD1F2254944ABD5A0E1E606A66CDB532D709768F4546DBD8A
996msiexec.exeC:\Windows\Installer\MSIC85C.tmpexecutable
MD5:5A1F2196056C0A06B79A77AE981C7761
SHA256:52F41817669AF7AC55B1516894EE705245C3148F2997FA0E6617E9CC6353E41E
2800Adobe Acrobat Pro.exeC:\Users\admin\AppData\Local\USER-PCtext
MD5:A733C6991D9A0A0786ACB24545F49FCA
SHA256:A05A536FC3DB5C8A0ACA48CE4E7670AA82F1028C9E8AA1117B02B38A2D4D1E82
2800Adobe Acrobat Pro.exeC:\ProgramData\Vso\font.cachebinary
MD5:7238B02DC1DB1407720A4E19A52BCF56
SHA256:11D6E83773A1AE77D8F2E95D560EDD3E6E366C24489EE3C09DA5AE890EB9D598
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
0
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2800
Adobe Acrobat Pro.exe
POST
200
185.228.72.212:80
http://185.228.72.212/contador/serv.php
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2800
Adobe Acrobat Pro.exe
185.228.72.212:80
Bursabil Teknoloji A.S.
ES
unknown

DNS requests

No data

Threats

Found threats are available for the paid subscriptions
2 ETPRO signatures available at the full report
No debug info