adobe online.com

The file adobe online.com has been detected as malware by 13 anti-virus scanners.
MD5:
93e1184862254dd8321a2143c703e07e

SHA-1:
9c616a2221b7c571db68df733e9891c377e2ab84

SHA-256:
91a87ec80c17364094b3cb650c1e5e4ab7a4c6410474664219cfa8fedab4115c

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/23/2024 3:08:19 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

AVG
Worm/VB.10.AC
2015.0.4568

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
16.05.20

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.96

Kaspersky
Worm.Win32.AutoRun
15.0.0.562

McAfee
Virus.W32/Pitin.worm
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.219.2198.0

Norman
Win32.Sality.3
19.05.2016 05:17:13

Sophos
Virus 'Mal/Sality-D'
5.23

VIPRE Antivirus
Threat.4721115
48908

File size:
112 KB (114,688 bytes)

Common path:
C:\users\{user}\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe online.com

File PE Metadata
Compilation timestamp:
1/28/2007 12:00:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:zFFXgb4ES704Vzxs4AeYgDTJSrlxyDu3E/QcM0IAoZqckVly654zj/3s0Fvdo8N:zXg+zs4AeYghSZED/JRvlv5mfsMvh

Entry address:
0x110C

Entry point:
60, 8D, 15, D0, CF, 63, 8E, 2A, F8, 89, DA, EB, 07, 89, CD, 89, FE, 0F, AF, C7, EB, 01, 49, F7, C0, B2, 83, 78, FE, 18, D5, 0F, AF, EF, EB, 07, 87, CA, 3D, D6, 8F, 47, BA, 53, 68, 75, 38, 32, 00, EB, 04, FE, C8, 88, C9, E8, 25, 00, 00, 00, C7, C3, 92, 24, 8F, E0, F7, C5, 55, 26, 68, 14, 46, 84, D0, 49, 81, FA, A3, E2, 00, 00, 73, 08, 8D, 2D, E7, 1F, F8, 90, 1A, F1, 3D, 94, E6, 00, 00, 8D, 35, 81, B0, 33, DD, 8A, C5, 0C, 94, FF, C7, 81, FA, 54, 7C, 00, 00, 89, CB, 08, E2, F2, 8A, CC, 30, F6, 8D, 2D, 1E, 08...
 
[+]

Entropy:
7.0217

Code size:
24 KB (24,576 bytes)

User Start Menu Item
Name:
Adobe Online.com


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.4.120:80)

TCP (HTTP):
Connects to mail.accu17.denver.wehostwebsites.com  (173.248.137.197:80)

TCP (HTTP):
Connects to ekiaiooqqo.c06.mtsvc.net  (205.186.187.148:80)

TCP (HTTP):
Connects to ec2-54-85-149-135.compute-1.amazonaws.com  (54.85.149.135:80)

TCP (HTTP):
Connects to ec2-52-204-129-22.compute-1.amazonaws.com  (52.204.129.22:80)

TCP (HTTP):
Connects to ec2-54-165-22-2.compute-1.amazonaws.com  (54.165.22.2:80)

TCP (HTTP):
Connects to ec2-52-55-207-183.compute-1.amazonaws.com  (52.55.207.183:80)

TCP (HTTP):
Connects to ec2-52-1-32-25.compute-1.amazonaws.com  (52.1.32.25:80)

Remove adobe online.com - Powered by Reason Core Security