adobe online.com

The file adobe online.com has been detected as malware by 1 anti-virus scanner. While running, it connects to the Internet address apache2-yak.zarniwoop.dreamhost.com on port 80 using the HTTP protocol.
MD5:
99bd3b55f7a493ce291cb1028eed04c2

SHA-1:
d508655300698a670475f80b11c4ef9f1e49fd8b

SHA-256:
99f5589fca442b5e2a21f7ee292366ee474f1d6fef4e958ab989db68de6d024b

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/27/2024 5:36:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Worm.VB.AO (H)
16.11.17.22

File size:
112 KB (114,688 bytes)

Common path:
C:\users\{user}\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe online.com

File PE Metadata
Compilation timestamp:
1/28/2007 12:00:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:DXgGOugx8FhejRi5f/5QNUBS7HmZFAa5gk:DQ6ggej85X5QNUk7HmZFA3k

Entry address:
0x110C

Entry point:
88, D5, 81, D0, 9D, 6F, 76, 1B, 88, DE, 88, EE, 21, F7, 87, D9, 87, F3, 8A, C0, 3B, D2, C7, C3, 8A, 27, 75, 8F, 78, 0B, 0F, AF, CD, FF, C6, 8D, 3D, 21, 16, 10, EE, 8A, FA, 8A, F2, 0F, BF, CB, 85, F5, E8, 00, 00, 00, 00, EB, 08, 43, 41, 8D, 1D, F9, 2B, 7A, A1, C7, C1, 1A, 2D, 75, 7A, F6, C4, E0, 01, F9, 87, FB, BA, 37, B0, 00, 00, B8, AD, 29, DB, AA, F2, 81, F2, 0D, BE, 00, 00, 0B, FF, 89, D5, FE, C9, 5B, 89, EF, 0D, 29, E4, 4F, 02, 53, 68, A6, 23, 3D, 00, 87, EA, 8A, F1, 8B, ED, 81, FD, 54, BB, 00, 00, 73...
 
[+]

Entropy:
7.0211

Code size:
24 KB (24,576 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to apache2-yak.zarniwoop.dreamhost.com  (173.236.154.78:80)

TCP (HTTP):
Connects to server123.managedns.org  (103.14.97.123:80)

TCP (HTTP):
Connects to win04-host-kb.turkticaret.net  (31.186.8.104:80)

TCP (HTTP):
Connects to server250.net217.intbildns.org  (185.126.217.250:80)

TCP (HTTP):
Connects to neptune.corpservers.net  (63.247.87.162:80)

TCP (HTTP):
Connects to 209-99-40-222.fwd.datafoundry.com  (209.99.40.222:80)

Remove adobe online.com - Powered by Reason Core Security