File name:

ADB AppControl 1.7.4 Extended Multilingual [FileCR].zip

Full analysis: https://app.any.run/tasks/571614cb-609b-453b-93f9-91314f773c5c
Verdict: Malicious activity
Analysis date: August 07, 2023, 12:12:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

4BE0D7F95460EBC1660B8858A0661BC6

SHA1:

9C8428244A16F3C7FF23FF9BF3ED914F5F4D117C

SHA256:

E5074AA2E38D9208B787AE8AE306FDF06F4EB72A3BC72266A9E4B999F5F82BBD

SSDEEP:

98304:9pEtuMZPrm2gFdnmhRZjoB3wdnqprN46TTx6ZYSU85Bbky8igyVPTbAevvl7gMk9:9guMZgKoBwn8TVNSUUBbkbigyGevNsb9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ADBAppControl-1.7.4-setup.exe (PID: 2960)
      • ADBAppControl-1.7.4-setup.exe (PID: 2720)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ADBAppControl-1.7.4-setup.exe (PID: 2960)
      • ADBAppControl-1.7.4-setup.exe (PID: 2720)
    • Reads the Windows owner or organization settings

      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
    • Reads the Internet Settings

      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1948)
    • Checks supported languages

      • ADBAppControl-1.7.4-setup.tmp (PID: 1816)
      • ADBAppControl-1.7.4-setup.exe (PID: 2960)
      • ADBAppControl-1.7.4-setup.exe (PID: 2720)
      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
    • Reads the computer name

      • ADBAppControl-1.7.4-setup.tmp (PID: 1816)
      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
    • The process checks LSA protection

      • ADBAppControl-1.7.4-setup.tmp (PID: 1816)
      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
    • Create files in a temporary directory

      • ADBAppControl-1.7.4-setup.exe (PID: 2960)
      • ADBAppControl-1.7.4-setup.exe (PID: 2720)
    • Application was dropped or rewritten from another process

      • ADBAppControl-1.7.4-setup.tmp (PID: 1816)
      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
    • Application launched itself

      • msedge.exe (PID: 644)
      • msedge.exe (PID: 3656)
    • Manual execution by a user

      • msedge.exe (PID: 3656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: ADB AppControl 1.7.4 Extended Multilingual/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2022:05:09 02:58:00
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
19
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start winrar.exe adbappcontrol-1.7.4-setup.exe adbappcontrol-1.7.4-setup.tmp no specs adbappcontrol-1.7.4-setup.exe adbappcontrol-1.7.4-setup.tmp no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
564"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1200 --field-trial-handle=1272,i,14367362013106558163,5658702200047048582,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
644"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://dotnet.microsoft.com/download/dotnet-framework/net48C:\Program Files\Microsoft\Edge\Application\msedge.exeADBAppControl-1.7.4-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
996"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=1396 --field-trial-handle=1272,i,14367362013106558163,5658702200047048582,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1164"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1464 --field-trial-handle=1320,i,10536785455067983337,5185692879293066604,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1584"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1532 --field-trial-handle=1272,i,14367362013106558163,5658702200047048582,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1640"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6dc4f598,0x6dc4f5a8,0x6dc4f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
1816"C:\Users\admin\AppData\Local\Temp\is-J3NT2.tmp\ADBAppControl-1.7.4-setup.tmp" /SL5="$10021C,4597415,848384,C:\Users\admin\AppData\Local\Temp\Rar$EXb1948.39361\ADB AppControl 1.7.4 Extended Multilingual\ADBAppControl-1.7.4-setup.exe" C:\Users\admin\AppData\Local\Temp\is-J3NT2.tmp\ADBAppControl-1.7.4-setup.tmpADBAppControl-1.7.4-setup.exe
User:
admin
Company:
Cyber.Cat
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mpr.dll
c:\users\admin\appdata\local\temp\is-j3nt2.tmp\adbappcontrol-1.7.4-setup.tmp
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1868"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3636 --field-trial-handle=1272,i,14367362013106558163,5658702200047048582,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1948"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ADB AppControl 1.7.4 Extended Multilingual [FileCR].zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2116"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1616 --field-trial-handle=1272,i,14367362013106558163,5658702200047048582,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\rpcrt4.dll
Total events
3 749
Read events
3 699
Write events
45
Delete events
5

Modification events

(PID) Process:(1948) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
4
Suspicious files
17
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
3188msedge.exe
MD5:
SHA256:
644msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local Statetext
MD5:6D53262F642A7D7B87DB29A0F5DFAC1E
SHA256:BC46E9C313221548825902CD6A7463DE36A8F86E47B17E61C56448E9C72488F7
1948WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1948.39361\ADB AppControl 1.7.4 Extended Multilingual\ADBac_1.7.4_crk\Read.txttext
MD5:DEDC1B4926E28C15E15A35DB06F202D1
SHA256:C6114C0DE9F97F35D2E01CD66F12B6D649CBD6539A41E9FD4F317220D2744483
3656msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF472f34.TMP
MD5:
SHA256:
3656msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
644msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF472d31.TMPtext
MD5:A6062B2E34D70CEC633311D4155B0DED
SHA256:DDD1E3B78566D4A6DE26DAAD628F106512B0FA83ECC603D2F004085C5FBE31A8
644msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\e79e0d38-0025-41a9-9b27-64bc1cdca138.tmptext
MD5:BAF6539E52436377C42219CA408DDDB6
SHA256:4F5D81183C04F8CABB6083ACDFAA52E49E9CF6E909A821550C2983CDD410ABF5
3656msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF472f44.TMP
MD5:
SHA256:
3656msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
644msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\9749d441-010c-4cda-a46d-a5e313cef1ef.tmptext
MD5:C1E7A372BC01628A289A4C0BA754691E
SHA256:45DB823EA3F428E5403537CEC60649C744B7FB7DDB93840B986F1B51347CB7C0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
19
DNS requests
18
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2912
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3656
msedge.exe
239.255.255.250:1900
whitelisted
2912
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2912
msedge.exe
20.31.42.83:443
sploit-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2912
msedge.exe
13.107.246.44:443
dotnet.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
suspicious
2912
msedge.exe
20.105.73.143:443
data-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2912
msedge.exe
184.86.251.19:443
www.bing.com
Akamai International B.V.
DE
suspicious
2912
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3656
msedge.exe
224.0.0.251:5353
unknown

DNS requests

Domain
IP
Reputation
dotnet.microsoft.com
  • 13.107.246.44
  • 13.107.213.44
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
sploit-edge.smartscreen.microsoft.com
  • 20.31.42.83
whitelisted
config.edge.skype.com
  • 13.107.42.16
malicious
nav-edge.smartscreen.microsoft.com
  • 20.67.143.122
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.105.73.143
whitelisted
www.bing.com
  • 184.86.251.19
  • 184.86.251.24
  • 184.86.251.14
  • 184.86.251.9
  • 184.86.251.22
  • 184.86.251.7
  • 184.86.251.4
  • 184.86.251.27
  • 184.86.251.30
whitelisted
self.events.data.microsoft.com
  • 20.189.173.12
whitelisted

Threats

No threats detected
No debug info