| File name: | After_Effects_Set-Up (1).exe |
| Full analysis: | https://app.any.run/tasks/f6092ddb-b183-4fa9-b938-e6b7c317b255 |
| Verdict: | Malicious activity |
| Analysis date: | May 17, 2025, 06:00:23 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections |
| MD5: | FA1BEBA48EF8C786B2A4F38ADC3B4483 |
| SHA1: | 19745869810CD99CAC44709BD42C2B0E25FEC622 |
| SHA256: | DDAF989461BAA7EEB0D9787A2A072722ABC3F51E53B1B607AB1BA7B16F49F378 |
| SSDEEP: | 98304:ehrrrAZbJJcNChltm1kO0U2qcJtWYhcU91jTJ7bWu7Cw28/H/EDOjdmRFva3opuq:7Qn3xQj3s |
| .exe | | | UPX compressed Win32 Executable (76) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.6) |
| .exe | | | Generic Win/DOS Executable (5.6) |
| .exe | | | DOS Executable Generic (5.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:10:30 03:14:41+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.23 |
| CodeSize: | 2072576 |
| InitializedDataSize: | 45056 |
| UninitializedDataSize: | 3284992 |
| EntryPoint: | 0x51cb70 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.3.5.13 |
| ProductVersionNumber: | 5.3.5.13 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Adobe Inc. |
| FileDescription: | Adobe Installer |
| FileVersion: | 5.3.5.13 |
| InternalName: | Adobe Installer |
| LegalCopyright: | © 2015-2020 Adobe. All rights reserved. |
| OriginalFileName: | Adobe Installer |
| ProductName: | Adobe Installer |
| ProductVersion: | 5.3.5.13 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 536 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4936 -childID 3 -isForBrowser -prefsHandle 4972 -prefMapHandle 4836 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1452 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {75eda7c4-bc30-4688-bbeb-8150bd87f547} 7252 "\\.\pipe\gecko-crash-server-pipe.7252" 1fb3c46b150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 736 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4276 -childID 2 -isForBrowser -prefsHandle 4216 -prefMapHandle 4224 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1452 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d9ae6a9c-5c66-4e26-8b13-b923693898b2} 7252 "\\.\pipe\gecko-crash-server-pipe.7252" 1fb3b199a10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4152 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5820 -childID 6 -isForBrowser -prefsHandle 2652 -prefMapHandle 5704 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1452 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {43ae5951-196f-4165-acf2-9d4c4fddfae2} 7252 "\\.\pipe\gecko-crash-server-pipe.7252" 1fb3b982850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 4448 | "C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\admin\Desktop\pointrental.rtf" /o "" | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 16.0.16026.20146 Modules
| |||||||||||||||
| 4452 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2660 -childID 1 -isForBrowser -prefsHandle 2808 -prefMapHandle 2804 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1452 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c8a7d38e-ce2d-4c32-bf3c-671a4979c0f9} 7252 "\\.\pipe\gecko-crash-server-pipe.7252" 1fb38c44f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 6268 | "C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Desktop\stringshare.png" | C:\Windows\System32\mspaint.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Paint Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6436 | "C:\Users\admin\AppData\Local\Temp\After_Effects_Set-Up (1).exe" | C:\Users\admin\AppData\Local\Temp\After_Effects_Set-Up (1).exe | explorer.exe | ||||||||||||
User: admin Company: Adobe Inc. Integrity Level: MEDIUM Description: Adobe Installer Version: 5.3.5.13 Modules
| |||||||||||||||
| 6480 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4988 -childID 4 -isForBrowser -prefsHandle 4984 -prefMapHandle 4980 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1452 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {96a6da61-97ec-4845-bb15-b8918e76ca29} 7252 "\\.\pipe\gecko-crash-server-pipe.7252" 1fb3c46b690 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 6560 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1908 -parentBuildID 20240213221259 -prefsHandle 1848 -prefMapHandle 1840 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b7a62c04-c1b1-4518-8ec1-975e157c4b79} 7252 "\\.\pipe\gecko-crash-server-pipe.7252" 1fb33eeee10 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (6436) After_Effects_Set-Up (1).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6436) After_Effects_Set-Up (1).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6436) After_Effects_Set-Up (1).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7252) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (4448) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\WINWORD\4448 |
| Operation: | write | Name: | 0 |
Value: 0B0E105C4D9C8ABD82D641A01766B421999CDB230046D7C1F5A391DEF1ED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC906022222CA0DC2190000C91003783634C511E022D2120B770069006E0077006F00720064002E00650078006500C51620C517808004C91808323231322D44656300 | |||
| (PID) Process: | (4448) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | en-US |
Value: 2 | |||
| (PID) Process: | (4448) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | de-de |
Value: 2 | |||
| (PID) Process: | (4448) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | fr-fr |
Value: 2 | |||
| (PID) Process: | (4448) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | es-es |
Value: 2 | |||
| (PID) Process: | (4448) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | it-it |
Value: 2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6436 | After_Effects_Set-Up (1).exe | C:\Users\admin\AppData\Local\Temp\CreativeCloud\ACC\WAM.log | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 6436 | After_Effects_Set-Up (1).exe | C:\Users\admin\AppData\Local\Adobe\OOBE\temp_ins_lbs_wid | text | |
MD5:652CE08E86D65DD0518DB56EF23ABAAE | SHA256:467568BA3DCC144D1FC8359B40516595A71932BC77EC0C5128520339749F8FFF | |||
| 6436 | After_Effects_Set-Up (1).exe | C:\Users\admin\AppData\Local\Temp\{90187CB1-7C50-4D91-8303-13087255FF1B}\lib\jquery.placeholder.min.js | binary | |
MD5:E13F16E89FFF39422BBB2CB08A015D30 | SHA256:24320ADD10244D1834052C7E75B853AA2D164601C9D09220A9F9AC1F0AE44AFE | |||
| 6436 | After_Effects_Set-Up (1).exe | C:\Users\admin\AppData\Local\Temp\{90187CB1-7C50-4D91-8303-13087255FF1B}\js\mainController.js | binary | |
MD5:51BDCC0E7D53C59FF20FF2F6E276E321 | SHA256:EC5B0CEDE51F5FD48C341CD27D42433BB9A2ADB04836433FEE5A90B101E4B1B2 | |||
| 6436 | After_Effects_Set-Up (1).exe | C:\Users\admin\AppData\Local\Adobe\OOBE\temp_lbs_wid | text | |
MD5:D9EE9054908F73F3323C3AD231493033 | SHA256:D74F918416F9BD6563779A2222A8970F7974B24E55FF468FDF0D0A23BA00DC56 | |||
| 6436 | After_Effects_Set-Up (1).exe | C:\Users\admin\AppData\Local\Temp\{90187CB1-7C50-4D91-8303-13087255FF1B}\js\main.js | binary | |
MD5:A2ECC3BBA3A5033720DD046CC6CF64D3 | SHA256:FC1BBA3A598AF6605A402AD2552CD8D7605E51A019AF119F25F30DFBD67E63C0 | |||
| 6436 | After_Effects_Set-Up (1).exe | C:\Users\admin\AppData\Local\Temp\{90187CB1-7C50-4D91-8303-13087255FF1B}\main.html | html | |
MD5:A501355E23582CBC6C8C2835FE076F52 | SHA256:4BE92DEE71936C52319D441434992895818586ACAB859000341AF74D0175AB54 | |||
| 6436 | After_Effects_Set-Up (1).exe | C:\Users\admin\AppData\Local\Temp\{90187CB1-7C50-4D91-8303-13087255FF1B}\js\overlayController.js | binary | |
MD5:B610650C4D826B14C225CFBECA89B8C1 | SHA256:79D00458B49A02ACEE141B53DCF026AA1302AB6B48A745B57E1215BD3B20501C | |||
| 6436 | After_Effects_Set-Up (1).exe | C:\Users\admin\AppData\Local\Temp\{90187CB1-7C50-4D91-8303-13087255FF1B}\lib\angular.min.js | binary | |
MD5:3BE66F7F7B86956BC5E5ABD64CADF924 | SHA256:B1A45F28AED77E38FB5FF62393F6C6573C6BEA7F6089E83ED5E2E1FA025A6B2E | |||
| 6436 | After_Effects_Set-Up (1).exe | C:\Users\admin\AppData\Local\Temp\{90187CB1-7C50-4D91-8303-13087255FF1B}\lib\jquery.min.js | binary | |
MD5:9AC39DC31635A363E377EDA0F6FBE03F | SHA256:9A2723C21FB1B7DFF0E2AA5DC6BE24A9670220A17AE21F70FDBC602D1F8ACD38 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7252 | firefox.exe | POST | 200 | 142.250.186.35:80 | http://o.pki.goog/s/wr3/3H4 | unknown | — | — | whitelisted |
7252 | firefox.exe | POST | 200 | 184.24.77.46:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
7252 | firefox.exe | POST | 200 | 184.24.77.46:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
7252 | firefox.exe | POST | 200 | 142.250.186.35:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6436 | After_Effects_Set-Up (1).exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D | unknown | — | — | whitelisted |
6436 | After_Effects_Set-Up (1).exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | unknown | — | — | whitelisted |
7252 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
6436 | After_Effects_Set-Up (1).exe | 34.213.253.53:443 | na1e-acc.services.adobe.com | AMAZON-02 | US | whitelisted |
6436 | After_Effects_Set-Up (1).exe | 34.250.67.152:443 | cc-api-data.adobe.io | AMAZON-02 | IE | whitelisted |
— | — | 34.250.67.152:443 | cc-api-data.adobe.io | AMAZON-02 | IE | whitelisted |
3216 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6436 | After_Effects_Set-Up (1).exe | 172.66.0.163:443 | ims-prod07.adobelogin.com | — | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
na1e-acc.services.adobe.com |
| whitelisted |
cc-api-data.adobe.io |
| whitelisted |
client.wns.windows.com |
| whitelisted |
ims-prod07.adobelogin.com |
| whitelisted |
cdn-ffc.oobesaas.adobe.com |
| whitelisted |
login.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |