File name:

Adobe Acrobate Reader Pro-HAv70.msi

Full analysis: https://app.any.run/tasks/10c5d187-0f88-49c5-8055-b8c171ba3962
Verdict: Malicious activity
Threats:

Metamorfo is a trojan malware family that has been active since 2018. It remains a top threat, focusing on stealing victims’ financial information, including banking credentials and other data. The malware is known for targeting users in Brazil.

Analysis date: December 10, 2023, 02:12:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
generated-doc
metamorfo
trojan
opendir
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {D69B9218-2190-4716-88FD-CE4B13CFF25A}, Number of Words: 10, Subject: Adobe Acrobat Reader, Author: Adobe Acrobat Reader, Name of Creating Application: Adobe Acrobat Reader (Evaluation Installer), Template: ;1046, Comments: A base dados do instalador contm a lgica e os dados necessrios para instalar o Adobe Acrobat Reader. (Evaluation Installer), Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Wed Nov 22 02:10:54 2023, Last Saved Time/Date: Wed Nov 22 02:10:54 2023, Last Printed: Wed Nov 22 02:10:54 2023, Number of Pages: 450
MD5:

9175FED68D5D38DEE94BBD059F9ED69A

SHA1:

CB094B6EB86A9FB8C8BCB5A3A7567CC72858EAAA

SHA256:

D8FC4F696F4BD1899ED92D8E9767646308C941CAC2EA826DBDD3E64F6926DB3D

SSDEEP:

393216:Du1r1tF5xjBacTM63s8XzORZqtkhflkIEIGGaYIh:MH5PrZCxdGvc9Ih

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 996)
    • METAMORFO has been detected (YARA)

      • Adobe Acrobat Pro.exe (PID: 2800)
    • Connects to the CnC server

      • Adobe Acrobat Pro.exe (PID: 2800)
    • METAMORFO has been detected (SURICATA)

      • Adobe Acrobat Pro.exe (PID: 2800)
  • SUSPICIOUS

    • Connects to the server without a host name

      • Adobe Acrobat Pro.exe (PID: 2800)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 332)
      • msiexec.exe (PID: 996)
      • Adobe Acrobat Pro.exe (PID: 2800)
    • Reads the computer name

      • msiexec.exe (PID: 996)
      • msiexec.exe (PID: 332)
      • Adobe Acrobat Pro.exe (PID: 2800)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 332)
      • msiexec.exe (PID: 996)
      • Adobe Acrobat Pro.exe (PID: 2800)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 996)
      • Adobe Acrobat Pro.exe (PID: 2800)
    • Create files in a temporary directory

      • msiexec.exe (PID: 996)
    • Reads Environment values

      • Adobe Acrobat Pro.exe (PID: 2800)
    • Creates files in the program directory

      • Adobe Acrobat Pro.exe (PID: 2800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {D69B9218-2190-4716-88FD-CE4B13CFF25A}
Words: 10
Subject: Adobe Acrobat Reader
Author: Adobe Acrobat Reader
LastModifiedBy: -
Software: Adobe Acrobat Reader (Evaluation Installer)
Template: ;1046
Comments: A base dados do instalador contêm a lógica e os dados necessários para instalar o Adobe Acrobat Reader. (Evaluation Installer)
Title: Installation Database
Keywords: Installer, MSI, Database
CreateDate: 2023:11:22 02:10:54
ModifyDate: 2023:11:22 02:10:54
LastPrinted: 2023:11:22 02:10:54
Pages: 450
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs #METAMORFO adobe acrobat pro.exe

Process information

PID
CMD
Path
Indicators
Parent process
332C:\Windows\syswow64\MsiExec.exe -Embedding 81F3D44952D9D051B6D0FC88A83115ADC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
996C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2736"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Adobe Acrobate Reader Pro-HAv70.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2800"C:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\Adobe Acrobat Pro.exe"C:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\Adobe Acrobat Pro.exe
msiexec.exe
User:
admin
Company:
VSO Software SARL
Integrity Level:
MEDIUM
Description:
Converter from almost all type of video/audio file to DVD that can be played on every standalone DVD players
Exit code:
0
Version:
7.0.0.69
Modules
Images
c:\users\admin\appdata\roaming\adobe acrobat reader\adobe acrobat reader\adobe acrobat reader\x64\reader-pdf\adobe acrobat pro.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
2 566
Read events
2 555
Write events
1
Delete events
10

Modification events

(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000_CLASSES\Local Settings\MuiCache\15A\52C64B7E
Operation:delete keyName:(default)
Value:
(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000_CLASSES\Local Settings\MuiCache\15A
Operation:delete keyName:(default)
Value:
(PID) Process:(996) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:delete valueName:C:\Config.Msi\22c745.rbs
Value:
31075086
(PID) Process:(996) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:delete keyName:(default)
Value:
(PID) Process:(996) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
Operation:delete keyName:(default)
Value:
(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
043D09D2EEBE71E4B13850711AC789ACD0E44E5C8D14C1F1CFA58FB5EC0FFC0C
(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
E40300000E9C9E5B0E2BDA01
(PID) Process:(996) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(996) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
Operation:delete keyName:(default)
Value:
Executable files
5
Suspicious files
8
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
996msiexec.exeC:\Windows\Installer\22c742.msi
MD5:
SHA256:
996msiexec.exeC:\Windows\Installer\MSIC85C.tmpexecutable
MD5:5A1F2196056C0A06B79A77AE981C7761
SHA256:52F41817669AF7AC55B1516894EE705245C3148F2997FA0E6617E9CC6353E41E
996msiexec.exeC:\Windows\Installer\MSIC87C.tmpexecutable
MD5:5A1F2196056C0A06B79A77AE981C7761
SHA256:52F41817669AF7AC55B1516894EE705245C3148F2997FA0E6617E9CC6353E41E
996msiexec.exeC:\Config.Msi\22c745.rbsbinary
MD5:6C1151421C229D28734069B84189009F
SHA256:51E0CA209B9D13AB9B536699C92011513CC6715434AEC149D58C9526771AF56C
996msiexec.exeC:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\avutil.dllexecutable
MD5:EF6839E8DB67D6995EAD096D1AAB5976
SHA256:3653B5ABEB9BE217A07E7BD669D59322923EB4EEB0C3E8258A8BA10AF0F94962
996msiexec.exeC:\Windows\Installer\22c744.ipibinary
MD5:245A636ABEA2EC671A234EB25D6B0AA0
SHA256:3A9DA0E43074FCA4011E5D14D835FF22C7E7AA6EFAE7D985810EC599C06E5D58
996msiexec.exeC:\Users\admin\AppData\Roaming\Adobe Acrobat Reader\Adobe Acrobat Reader\Adobe Acrobat Reader\x64\Reader-pdf\Adobe Acrobat Pro.exeexecutable
MD5:48D732A19514BEF06ACC712F43FA7D65
SHA256:BA4612DB8CE37B8E64D163A4C8E236B0AD2DDC223B91383F270924846394BF95
996msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF0A8D673A727BEC26.TMPbinary
MD5:73F93B40FC83EE4B48CA4360B4F6C55E
SHA256:EBCD2BEBED286D7C035FA9C09435194AEAC8E1F5E1E590821C580E4310F024B1
996msiexec.exeC:\Windows\Installer\SourceHash{C9BC840A-0E96-4595-AE16-15CAE1E4F236}binary
MD5:2344593C2F5CC699CDE9D55721D4B6FB
SHA256:FCFDD4A4F514CA7CFECD2418A49A5A0DA06C7B15D19A453FF8758731D6900D1B
2800Adobe Acrobat Pro.exeC:\ProgramData\Vso\font.cachebinary
MD5:7238B02DC1DB1407720A4E19A52BCF56
SHA256:11D6E83773A1AE77D8F2E95D560EDD3E6E366C24489EE3C09DA5AE890EB9D598
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
0
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2800
Adobe Acrobat Pro.exe
POST
200
185.228.72.212:80
http://185.228.72.212/contador/serv.php
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2800
Adobe Acrobat Pro.exe
185.228.72.212:80
Bursabil Teknoloji A.S.
ES
unknown

DNS requests

No data

Threats

Found threats are available for the paid subscriptions
2 ETPRO signatures available at the full report
No debug info