File name:

ADB AppControl 1.7.4 Extended Multilingual [FileCR].zip

Full analysis: https://app.any.run/tasks/571614cb-609b-453b-93f9-91314f773c5c
Verdict: Malicious activity
Analysis date: August 07, 2023, 12:12:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

4BE0D7F95460EBC1660B8858A0661BC6

SHA1:

9C8428244A16F3C7FF23FF9BF3ED914F5F4D117C

SHA256:

E5074AA2E38D9208B787AE8AE306FDF06F4EB72A3BC72266A9E4B999F5F82BBD

SSDEEP:

98304:9pEtuMZPrm2gFdnmhRZjoB3wdnqprN46TTx6ZYSU85Bbky8igyVPTbAevvl7gMk9:9guMZgKoBwn8TVNSUUBbkbigyGevNsb9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ADBAppControl-1.7.4-setup.exe (PID: 2960)
      • ADBAppControl-1.7.4-setup.exe (PID: 2720)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ADBAppControl-1.7.4-setup.exe (PID: 2960)
      • ADBAppControl-1.7.4-setup.exe (PID: 2720)
    • Reads the Windows owner or organization settings

      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
    • Reads the Internet Settings

      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1948)
    • Checks supported languages

      • ADBAppControl-1.7.4-setup.exe (PID: 2960)
      • ADBAppControl-1.7.4-setup.tmp (PID: 1816)
      • ADBAppControl-1.7.4-setup.exe (PID: 2720)
      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
    • Application was dropped or rewritten from another process

      • ADBAppControl-1.7.4-setup.tmp (PID: 1816)
      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
    • Reads the computer name

      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
      • ADBAppControl-1.7.4-setup.tmp (PID: 1816)
    • Create files in a temporary directory

      • ADBAppControl-1.7.4-setup.exe (PID: 2960)
      • ADBAppControl-1.7.4-setup.exe (PID: 2720)
    • Application launched itself

      • msedge.exe (PID: 644)
      • msedge.exe (PID: 3656)
    • The process checks LSA protection

      • ADBAppControl-1.7.4-setup.tmp (PID: 3644)
      • ADBAppControl-1.7.4-setup.tmp (PID: 1816)
    • Manual execution by a user

      • msedge.exe (PID: 3656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: ADB AppControl 1.7.4 Extended Multilingual/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2022:05:09 02:58:00
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
19
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start winrar.exe adbappcontrol-1.7.4-setup.exe adbappcontrol-1.7.4-setup.tmp no specs adbappcontrol-1.7.4-setup.exe adbappcontrol-1.7.4-setup.tmp no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
564"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1200 --field-trial-handle=1272,i,14367362013106558163,5658702200047048582,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
644"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://dotnet.microsoft.com/download/dotnet-framework/net48C:\Program Files\Microsoft\Edge\Application\msedge.exeADBAppControl-1.7.4-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
996"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=1396 --field-trial-handle=1272,i,14367362013106558163,5658702200047048582,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1164"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1464 --field-trial-handle=1320,i,10536785455067983337,5185692879293066604,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1584"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1532 --field-trial-handle=1272,i,14367362013106558163,5658702200047048582,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1640"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6dc4f598,0x6dc4f5a8,0x6dc4f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
1816"C:\Users\admin\AppData\Local\Temp\is-J3NT2.tmp\ADBAppControl-1.7.4-setup.tmp" /SL5="$10021C,4597415,848384,C:\Users\admin\AppData\Local\Temp\Rar$EXb1948.39361\ADB AppControl 1.7.4 Extended Multilingual\ADBAppControl-1.7.4-setup.exe" C:\Users\admin\AppData\Local\Temp\is-J3NT2.tmp\ADBAppControl-1.7.4-setup.tmpADBAppControl-1.7.4-setup.exe
User:
admin
Company:
Cyber.Cat
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mpr.dll
c:\users\admin\appdata\local\temp\is-j3nt2.tmp\adbappcontrol-1.7.4-setup.tmp
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1868"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3636 --field-trial-handle=1272,i,14367362013106558163,5658702200047048582,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1948"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ADB AppControl 1.7.4 Extended Multilingual [FileCR].zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2116"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1616 --field-trial-handle=1272,i,14367362013106558163,5658702200047048582,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\rpcrt4.dll
Total events
3 749
Read events
3 699
Write events
45
Delete events
5

Modification events

(PID) Process:(1948) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
4
Suspicious files
17
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
3188msedge.exe
MD5:
SHA256:
1948WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1948.39361\ADB AppControl 1.7.4 Extended Multilingual\ADBac_1.7.4_crk\ADBAppControl_key.regtext
MD5:CD95DABA61D524DCFCDA95FAE12B7091
SHA256:142DCC62C0194F883A8EDF09BBB96F457D39FFBBAE48E3259AF23B881392DA60
2960ADBAppControl-1.7.4-setup.exeC:\Users\admin\AppData\Local\Temp\is-J3NT2.tmp\ADBAppControl-1.7.4-setup.tmpexecutable
MD5:5D0A3ED2FE92BAE04274509ED0C2DE41
SHA256:3F95C9D25DF0525733D2AEFB12BA9053C9ABC3350E2F46F87C420CD2307FEA36
3656msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF472f34.TMP
MD5:
SHA256:
3656msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
1948WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1948.39361\ADB AppControl 1.7.4 Extended Multilingual\ADBAppControl-1.7.4-setup.exeexecutable
MD5:D09179BB9C0B8FC1BE3E63FE29D82AC6
SHA256:B81D02F6104D6538FFBC3C770BC0801B3FB560B29BB207D140B5CD99A0A87C0A
1948WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1948.39361\ADB AppControl 1.7.4 Extended Multilingual\ADBac_1.7.4_crk\Read.txttext
MD5:DEDC1B4926E28C15E15A35DB06F202D1
SHA256:C6114C0DE9F97F35D2E01CD66F12B6D649CBD6539A41E9FD4F317220D2744483
3656msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF472f44.TMP
MD5:
SHA256:
3656msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
1948WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1948.39361\ADB AppControl 1.7.4 Extended Multilingual\ADBac_1.7.4_crk\ADBAppControl.exeexecutable
MD5:2D7CAE8F9DF2B06E02BCD349937F4451
SHA256:0BE9AE9C80E17DBE158CEE079012FADFACF93B11681EEC4ECC0C7F61948B8D14
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
19
DNS requests
18
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3656
msedge.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
2912
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2912
msedge.exe
20.31.42.83:443
sploit-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
suspicious
2912
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2912
msedge.exe
20.67.143.122:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2912
msedge.exe
184.86.251.19:443
www.bing.com
Akamai International B.V.
DE
suspicious
2912
msedge.exe
20.105.73.143:443
data-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
suspicious
2912
msedge.exe
20.189.173.12:443
self.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3656
msedge.exe
224.0.0.251:5353
unknown

DNS requests

Domain
IP
Reputation
dotnet.microsoft.com
  • 13.107.246.44
  • 13.107.213.44
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
sploit-edge.smartscreen.microsoft.com
  • 20.31.42.83
whitelisted
config.edge.skype.com
  • 13.107.42.16
malicious
nav-edge.smartscreen.microsoft.com
  • 20.67.143.122
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.105.73.143
whitelisted
www.bing.com
  • 184.86.251.19
  • 184.86.251.24
  • 184.86.251.14
  • 184.86.251.9
  • 184.86.251.22
  • 184.86.251.7
  • 184.86.251.4
  • 184.86.251.27
  • 184.86.251.30
whitelisted
self.events.data.microsoft.com
  • 20.189.173.12
whitelisted

Threats

No threats detected
No debug info