| File name: | Reader_Install_Setup.exe |
| Full analysis: | https://app.any.run/tasks/c550a0ab-7767-47f6-8797-6b5feafb0846 |
| Verdict: | Malicious activity |
| Analysis date: | October 18, 2023, 15:21:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | DE3A5611EF7E1D852EEC6710922FB439 |
| SHA1: | C27FABACD332AE18E55E52300F136ED755C99D63 |
| SHA256: | EEB363DA3C8A04C8D9AC767A98795499EFB5F72D4D907AC8A990990BF16FA526 |
| SSDEEP: | 49152:ByPHx+zd+TbTEqHFBqIGWEN3CxSyoYqLq2GMPjqGoeBxG3VhCKuuMXolNP8S6CYa:ByPHxYAnQqHFBGFNyLtqFG0x4p9MXoPv |
| .exe | | | Win64 Executable (generic) (43.7) |
|---|---|---|
| .exe | | | UPX compressed Win32 Executable (42.8) |
| .exe | | | Win32 Executable (generic) (7.1) |
| .exe | | | Generic Win/DOS Executable (3.1) |
| .exe | | | DOS Executable Generic (3.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:10:04 13:37:49+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.35 |
| CodeSize: | 1421312 |
| InitializedDataSize: | 20480 |
| UninitializedDataSize: | 3031040 |
| EntryPoint: | 0x43f0a0 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.707 |
| ProductVersionNumber: | 2.0.0.707 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Adobe Inc |
| FileDescription: | Adobe Download Manager |
| FileVersion: | 2.0.0.707s |
| InternalName: | Adobe Download Manager |
| LegalCopyright: | Copyright 2019 Adobe Inc. All rights reserved. |
| OriginalFileName: | Adobe Download Manager |
| ProductName: | Adobe Download Manager |
| ProductVersion: | 2.0.0.707s |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2392 | "C:\Users\admin\AppData\Local\Temp\Reader_Install_Setup.exe" --pipename={67596D3C-4070-45F2-98F6-9A54D67BEC0D} --pid=3820 | C:\Users\admin\AppData\Local\Temp\Reader_Install_Setup.exe | Reader_Install_Setup.exe | ||||||||||||
User: admin Company: Adobe Inc Integrity Level: HIGH Description: Adobe Download Manager Exit code: 0 Version: 2.0.0.707s Modules
| |||||||||||||||
| 2424 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3820 | "C:\Users\admin\AppData\Local\Temp\Reader_Install_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Reader_Install_Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Adobe Inc Integrity Level: MEDIUM Description: Adobe Download Manager Exit code: 0 Version: 2.0.0.707s Modules
| |||||||||||||||
| 4068 | "C:\Users\admin\AppData\Local\Adobe\FE35D6F0-1D38-4E4C-BC12-AC0243BE9D48\5A42BE38-1582-44C2-9CA0-63973D1C6BE3\C3BDEAA6-936D-4B2F-B721-EC932D25D7A7" /sAll /re /sMutexTimeout "300" /msi PRODUCT_SOURCE=ACDC OWNERSHIP_STATE=1 UPDATE_MODE=3 EULA_ACCEPT=YES ENABLE_CHROMEEXT=1 | C:\Users\admin\AppData\Local\Adobe\FE35D6F0-1D38-4E4C-BC12-AC0243BE9D48\5A42BE38-1582-44C2-9CA0-63973D1C6BE3\C3BDEAA6-936D-4B2F-B721-EC932D25D7A7 | — | Reader_Install_Setup.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: HIGH Description: Adobe Self Extractor Exit code: 150410 Version: 23.6.20360.0 Modules
| |||||||||||||||
| (PID) Process: | (3820) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3820) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3820) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3820) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2392) Reader_Install_Setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3820) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3820) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3820) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3820) Reader_Install_Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000056010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3820) Reader_Install_Setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3820 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Temp\Adobe_ADMLogs\Adobe_ADM.log | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 3820 | Reader_Install_Setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | binary | |
MD5:724A7B35257D20E3E2C556A433B959A4 | SHA256:FA63817A8CC002567847E4F0C668FFE3F50CACCED8F22DFCA37B321D8BAE9DA8 | |||
| 3820 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\d[1] | binary | |
MD5:83E5380B9DC2077B664E383CF6FCF47E | SHA256:741A4BC7D04FC8385F9A1DB0CCC586A224F14233B08D764D37EA165163A247A0 | |||
| 3820 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\d[2] | binary | |
MD5:EE10AE517D40542F597A9E0E2852B52B | SHA256:ED1815F9829E1F6A710FCDC182613F614F4887E39281E095360BEEC1CCC72348 | |||
| 3820 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\d[1] | binary | |
MD5:A870EE6A735514C321010F19CE3644D7 | SHA256:79E3A4E2C2274ACD602155924DC8C0B7C3AFDCD40450B2DFEDA302AD8E140649 | |||
| 3820 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\bxf0ivf[1].js | text | |
MD5:32294DAC4A42454945B628842529D064 | SHA256:BA47541514A1077E41059F3BAC6BEC055417971C461FA83BA747D928A5CCC08C | |||
| 3820 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Adobe\FE35D6F0-1D38-4E4C-BC12-AC0243BE9D48\status_icon_caution_100.png | image | |
MD5:784ABEA138D9F1E5A1026162AF5BF2CD | SHA256:5C7B6B5456CAABC9D5A928AC892D9903836693960517C4E534A5DE1ACD6AE428 | |||
| 3820 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\d[1] | binary | |
MD5:DF0CD5EDE266E9EA694C3D28209FCE9F | SHA256:5ECD3C64E4C0D1A51D13E2762BECB9E7DA2ACD30D670058A6B16761BE3E017DB | |||
| 3820 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\d[1] | binary | |
MD5:590A9EEBC0AC0BA776529CBA1D5B718A | SHA256:28195F698F74D701F5B253495756F7ECD70C50047C1F795952587E6F3E742B19 | |||
| 3820 | Reader_Install_Setup.exe | C:\Users\admin\AppData\Local\Adobe\FE35D6F0-1D38-4E4C-BC12-AC0243BE9D48\status_icon_caution_200.png | image | |
MD5:3683A511B9DBA974CD9F36A6B023E423 | SHA256:210F1B214ECCDE9E148072A10FC0E263FE6A443341BE4DC9630C47BC84796101 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3820 | Reader_Install_Setup.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1a5936d8398c4a57 | unknown | compressed | 4.66 Kb | unknown |
3820 | Reader_Install_Setup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3820 | Reader_Install_Setup.exe | 184.24.77.156:443 | use.typekit.net | Akamai International B.V. | DE | unknown |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3820 | Reader_Install_Setup.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | STACKPATH-CDN | US | whitelisted |
3820 | Reader_Install_Setup.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3820 | Reader_Install_Setup.exe | 184.30.16.138:443 | geo-dc.adobe.com | AKAMAI-AS | DE | unknown |
3820 | Reader_Install_Setup.exe | 184.24.77.154:443 | p.typekit.net | Akamai International B.V. | DE | unknown |
3820 | Reader_Install_Setup.exe | 34.252.184.159:443 | rdc.adobe.io | AMAZON-02 | IE | unknown |
3820 | Reader_Install_Setup.exe | 2.18.160.138:443 | platformdl.adobe.com | AKAMAI-AS | DE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
use.typekit.net |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
geo-dc.adobe.com |
| whitelisted |
p.typekit.net |
| shared |
rdc.adobe.io |
| unknown |
dlmping2.adobe.com |
| whitelisted |
platformdl.adobe.com |
| whitelisted |
ardownload2.adobe.com |
| whitelisted |