Skip to main content
August 3, 2016
Question

Adobe Application Manager - aamcustomhook.exe - connection to TOR exit node

  • August 3, 2016
  • 1 reply
  • 1844 views

Recently in our environment, we deployed several packages of Adobe Captivate.    Suspicious registry key events started to appear in our systems for the aamcustomhook.exe file.   Analysis of the file showed it connecting to a known TOR exit node in the Netherlands.  It also connected to a known blacklisted malware site.

I pasted the details below on the file, and was wondering if anyone can confirm the MD5 of the file version below, or if you have a different MD5 of the same file version.   Basically, I need to know if this was from a legitimate Adobe package or if someone obtained it somewhere else.

If you want more details on what the file was doing, there were several submissions done to different sandboxes on 8-1-2016 and 8-2-2016.   Just search for the md5 in your favorite search engine.

Thanks

File path: C:\PROGRAM FILES\COMMON
FILES\ADOBE\OOBE\PDAPP\CORE\AAMCUSTOMHOOK.EXE

Product version: 9.0.0.267

Language: English (India)

MD5:  d75afed1aba06565da940d9fc98c0167

SHA256:  fb8f9633618ced962fa6a5d7412eb66247d13bf94cf2170be99dfd7d29474e89

This topic has been closed for replies.

1 reply

August 3, 2016

Additional info:

Contacted Hosts : 192.42.116.41

inetnum:         192.42.116.0 - 192.42.116.255

netname: TOR-EXIT-HVIV

descr:           https://www.hartvoorinternetvrijheid.nl/eng.html

descr:           Amsterdam

country:         NL

org:             ORG-NSN4-RIPE

admin-c:         WB311-RIPE

tech-c:          WB311-RIPE

status:          LEGACY

mnt-by:          AS1101-MNT

created:         2007-07-03T16:54:09Z

last-modified:   2015-03-05T14:07:33Z

source:          RIPE

The other site is under the virustotal results for the MD5.   Idk if links are allowed on here, so I'll leave it to you to run a search of the md5.  It should only return a few results.

Thanks again