Windows
Analysis Report
Seminole Casino - 2023 DJI Invoice.pdf
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
Acrobat.exe (PID: 2836 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\S eminole Ca sino - 202 3 DJI Invo ice.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) AcroCEF.exe (PID: 5272 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) AcroCEF.exe (PID: 4904 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 80 --field -trial-han dle=1732,i ,175987753 6477150877 9,35602894 5760665101 6,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 12 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
23.47.168.24 | unknown | United States | 16625 | AKAMAI-ASUS | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1447358 |
Start date and time: | 2024-05-24 21:41:58 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 8s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 12 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Seminole Casino - 2023 DJI Invoice.pdf |
Detection: | CLEAN |
Classification: | clean2.winPDF@14/47@0/1 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 23.22.254.206, 52.5.13.197, 52.202.204.11, 54.227.187.23, 172.64.41.3, 162.159.61.3, 88.221.110.120, 88.221.110.59, 2.16.100.176, 2.16.202.123, 95.101.54.195, 199.232.214.172
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, identrust.edgesuite.net, slscr.update.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, a1952.dscq.akamai.net, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, apps.identrust.com, wu-b-net.trafficmanager.net
- VT rate limit hit for: Seminole Casino - 2023 DJI Invoice.pdf
Time | Type | Description |
---|---|---|
15:43:01 | API Interceptor |
Input | Output |
---|---|
URL: PDF Model: gpt-4o | ```json { "riskscore": 2, "reasons": "The PDF appears to be a legitimate invoice from a known foundation. The email address provided (Events@turn2foundation.org) seems to be consistent with the organization's domain. However, there is always a minimal risk of phishing, especially if the email address is spoofed or if the PDF was received unexpectedly. Users should verify the authenticity of the invoice by contacting the foundation directly using known contact information." } |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
23.47.168.24 | Get hash | malicious | Captcha Phish, HTMLPhisher | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HtmlDropper, HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
bg.microsoft.map.fastly.net | Get hash | malicious | VMdetect | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, RisePro Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AKAMAI-ASUS | Get hash | malicious | Vidar | Browse |
| |
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Captcha Phish, HTMLPhisher | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer, Vidar | Browse |
| ||
Get hash | malicious | CryptOne, Djvu, LummaC Stealer, Mars Stealer, PureLog Stealer, RedLine, RisePro Stealer | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.185331383199297 |
Encrypted: | false |
SSDEEP: | 6:DXq6mN4q2PN72nKuAl9OmbnIFUt86XqnJZmw+6XqnDkwON72nKuAl9OmbjLJ:D66mOvVaHAahFUt866J/+66D5OaHAaSJ |
MD5: | 7B99B0F37361CBE5CF18621509560619 |
SHA1: | 87A9CA9C464CB104DFE766FD57F01036CE41A560 |
SHA-256: | A55E011C488846794759D673A9BAD06763C9CC088E2D66CB1EDEA9EC2438A5E4 |
SHA-512: | C87EDFE2FCFD10AD8ED1D0B14DE1FE4BE05E1BF7AB892F5070D2FBADAB8B781EE5C6319768FB19FB747C0039514097BD3B5D514378E787613DA513C960E6F76E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.185331383199297 |
Encrypted: | false |
SSDEEP: | 6:DXq6mN4q2PN72nKuAl9OmbnIFUt86XqnJZmw+6XqnDkwON72nKuAl9OmbjLJ:D66mOvVaHAahFUt866J/+66D5OaHAaSJ |
MD5: | 7B99B0F37361CBE5CF18621509560619 |
SHA1: | 87A9CA9C464CB104DFE766FD57F01036CE41A560 |
SHA-256: | A55E011C488846794759D673A9BAD06763C9CC088E2D66CB1EDEA9EC2438A5E4 |
SHA-512: | C87EDFE2FCFD10AD8ED1D0B14DE1FE4BE05E1BF7AB892F5070D2FBADAB8B781EE5C6319768FB19FB747C0039514097BD3B5D514378E787613DA513C960E6F76E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 339 |
Entropy (8bit): | 5.142195377537517 |
Encrypted: | false |
SSDEEP: | 6:DXqC1yq2PN72nKuAl9Ombzo2jMGIFUt86Xq8j1Zmw+6XqIMlRkwON72nKuAl9OmT:D6C1yvVaHAa8uFUt8668J/+66IQR5Oag |
MD5: | 3C9846DFC18E8371806424AECF20245E |
SHA1: | 63F0D0D0A774707F45C290B91DC173388D696964 |
SHA-256: | 08563C2FD32B004C9BB8D4A67638E9328223E187C9D40502C843E4766482E929 |
SHA-512: | B51AA9841104ED34EA09A77F6FAB6D616BE66695B51AFEAD3CA9FE388830EA53B45DF356FAECFCF19CBBDD5F557234BEC1F1B83CDA8583CEDF814ABB537FD1C3 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 339 |
Entropy (8bit): | 5.142195377537517 |
Encrypted: | false |
SSDEEP: | 6:DXqC1yq2PN72nKuAl9Ombzo2jMGIFUt86Xq8j1Zmw+6XqIMlRkwON72nKuAl9OmT:D6C1yvVaHAa8uFUt8668J/+66IQR5Oag |
MD5: | 3C9846DFC18E8371806424AECF20245E |
SHA1: | 63F0D0D0A774707F45C290B91DC173388D696964 |
SHA-256: | 08563C2FD32B004C9BB8D4A67638E9328223E187C9D40502C843E4766482E929 |
SHA-512: | B51AA9841104ED34EA09A77F6FAB6D616BE66695B51AFEAD3CA9FE388830EA53B45DF356FAECFCF19CBBDD5F557234BEC1F1B83CDA8583CEDF814ABB537FD1C3 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\8ad11e5a-0ee4-4f63-be33-647c357b6ad1.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.9538772718856245 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqRHWsBdOg2Hxfcaq3QYiubcP7E4T3y:Y2sRdss7dMHxu3QYhbA7nby |
MD5: | C840C9AC51828AF4CC4A922E3D809E46 |
SHA1: | C476655287B7B3E1C6395A4FA7C7D9E04404A672 |
SHA-256: | 460C4452D8380E9B0A94D4DE851CC1D728132BE32064340E6D556EE2525AA39E |
SHA-512: | 26296F3F738197A2709C899B6F55F5A464E2A641ABD69B484D367F91E0AB409596B06453E8FB586C7EB8C31818A181677F83D46420708C2C5D7D8926987C27D5 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.9538772718856245 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqRHWsBdOg2Hxfcaq3QYiubcP7E4T3y:Y2sRdss7dMHxu3QYhbA7nby |
MD5: | C840C9AC51828AF4CC4A922E3D809E46 |
SHA1: | C476655287B7B3E1C6395A4FA7C7D9E04404A672 |
SHA-256: | 460C4452D8380E9B0A94D4DE851CC1D728132BE32064340E6D556EE2525AA39E |
SHA-512: | 26296F3F738197A2709C899B6F55F5A464E2A641ABD69B484D367F91E0AB409596B06453E8FB586C7EB8C31818A181677F83D46420708C2C5D7D8926987C27D5 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5859 |
Entropy (8bit): | 5.2486060233948395 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7zA/2v:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhv |
MD5: | 1EDE1B07BF01DFC6DFD408FC1464E997 |
SHA1: | DB9672EB041715EA037FF05BA6A059909D203783 |
SHA-256: | C05FF6E55162B50BD127324776E0898FAFCC0E6C37715BD8ADEFCAE4CA174951 |
SHA-512: | BD25DB92E4852FCC53937B822C5D47C2B492B6F587FCD2F1F067234B2C77BF82238E98018885C51B0F9FDB64D5E42939FAE770BCBA85F1582103ADCC05CA582D |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 327 |
Entropy (8bit): | 5.192799582809804 |
Encrypted: | false |
SSDEEP: | 6:DXq21yq2PN72nKuAl9OmbzNMxIFUt86Xqg1Zmw+6Xq9jRkwON72nKuAl9OmbzNMT:D621yvVaHAa8jFUt866O/+669jR5OaHP |
MD5: | 5309D8A37C7B1CD234A3C1B23593F764 |
SHA1: | 65A501C78CFE603D6F025BB84BBF6B32604267DD |
SHA-256: | 69EF2795D7B8D65773805F3C52D7E379CB6B7F7F61F3D60CDDA8E627D85B9873 |
SHA-512: | A16C4C786471B0A3B88AB38573B140E320AA0BFA91BD92DCC8F1EEB0073A8676A8EAA961DA4B4FAD4AE561706F360D55E6537CBEB447B2579D4C41CEDC687B10 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 327 |
Entropy (8bit): | 5.192799582809804 |
Encrypted: | false |
SSDEEP: | 6:DXq21yq2PN72nKuAl9OmbzNMxIFUt86Xqg1Zmw+6Xq9jRkwON72nKuAl9OmbzNMT:D621yvVaHAa8jFUt866O/+669jR5OaHP |
MD5: | 5309D8A37C7B1CD234A3C1B23593F764 |
SHA1: | 65A501C78CFE603D6F025BB84BBF6B32604267DD |
SHA-256: | 69EF2795D7B8D65773805F3C52D7E379CB6B7F7F61F3D60CDDA8E627D85B9873 |
SHA-512: | A16C4C786471B0A3B88AB38573B140E320AA0BFA91BD92DCC8F1EEB0073A8676A8EAA961DA4B4FAD4AE561706F360D55E6537CBEB447B2579D4C41CEDC687B10 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-240524194253Z-155.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71190 |
Entropy (8bit): | 1.6404651398837147 |
Encrypted: | false |
SSDEEP: | 192:+DewsWzzFem+oGXkFtGx0bZLPJ96TTTHq0j3y3AXjUvs3RTnm63Mq:Q3z/dGXkvGx0bZjJ96TTTHqwy3AXjGsz |
MD5: | C3B16464E1EBB1F3A68C59E385F536D0 |
SHA1: | 6980576D63EEAC8CA72AAA79E440E5A9C9314692 |
SHA-256: | C8A4E57C6736CACE1A9C5BACDAB977A2BC47CCB11D2E71F707D47867D03F66F1 |
SHA-512: | CC84C31E9292FAF327C1D130468C25AECA6FADD4130CDF5E440ECDA2D800FAC6C93CBEECEF15313B7F08B8E339354D63B0D78BFDE0AF88F28F56EFAC576FC843 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.44491292466675 |
Encrypted: | false |
SSDEEP: | 384:ye6ci5tliBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:mOs3OazzU89UTTgUL |
MD5: | 7544B72F9A468EDFBC1FE7C3B2481E7D |
SHA1: | 7A5CF95E1A4750E9DE40C7116D855AE383A41344 |
SHA-256: | 0B176AB52397DD68CC9304C266BD263857AFC5A75465823D606737120B56E4B8 |
SHA-512: | B1D5CC3CEA7F44978B97D2587B1D56EBE6E2F0BB61299BF4CC21B1C1E55D7FACC2BB094E3B828D70D14207C716F539F2795E4FB795360A199E9416CAEA6C69C2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.7678828004670346 |
Encrypted: | false |
SSDEEP: | 48:7MbJioyVEtioyJWoy1C7oy16oy1XsKOioy1noy1AYoy1Wioy1oioykioyBoy1no3:7QJuEtgP2AXjBikb9IVXEBodRBkV |
MD5: | 5087260674364661117AEEA8D7CD0FD3 |
SHA1: | FEFBC8D8ADA0A78B467D23435D5D7D17C12C0AC6 |
SHA-256: | 7C355D8E0C72406A6ACF820C4223C552390604090196DA11F6075643C6D38017 |
SHA-512: | ED9D4526575C243E95BA33D2A9B54460234218FD87C14C00D6038557C2FC55F6CF37019743807D39CF239DFFE68FDF1EB16F4BDADEF818E286FFBBB8650303D1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 ![encrypted](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABgAAAAXCAYAAAARIY8tAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyFpVFh0WE1MOmNvbS5hZG9iZS54bXAAAAAAADw/eHBhY2tldCBiZWdpbj0i77u/IiBpZD0iVzVNME1wQ2VoaUh6cmVTek5UY3prYzlkIj8+IDx4OnhtcG1ldGEgeG1sbnM6eD0iYWRvYmU6bnM6bWV0YS8iIHg6eG1wdGs9IkFkb2JlIFhNUCBDb3JlIDUuNi1jMTQyIDc5LjE2MDkyNCwgMjAxNy8wNy8xMy0wMTowNjozOSAgICAgICAgIj4gPHJkZjpSREYgeG1sbnM6cmRmPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj4gPHJkZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIgeG1sbnM6eG1wTU09Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC9tbS8iIHhtbG5zOnN0UmVmPSJodHRwOi8vbnMuYWRvYmUuY29tL3hhcC8xLjAvc1R5cGUvUmVzb3VyY2VSZWYjIiB4bWxuczp4bXA9Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC8iIHhtcE1NOkRvY3VtZW50SUQ9InhtcC5kaWQ6NkY0N0QxMkZFMDExMTFFNzlEQjNEM0NBNTA2NjRBOEEiIHhtcE1NOkluc3RhbmNlSUQ9InhtcC5paWQ6NkY0N0QxMkVFMDExMTFFNzlEQjNEM0NBNTA2NjRBOEEiIHhtcDpDcmVhdG9yVG9vbD0iQWRvYmUgUGhvdG9zaG9wIENDIChXaW5kb3dzKSI+IDx4bXBNTTpEZXJpdmVkRnJvbSBzdFJlZjppbnN0YW5jZUlEPSJ4bXAuaWlkOjUxREYxNzEwRTAxMTExRTc4NzA2RDNFQTNEMTNCRTY1IiBzdFJlZjpkb2N1bWVudElEPSJ4bXAuZGlkOjUxREYxNzExRTAxMTExRTc4NzA2RDNFQTNEMTNCRTY1Ii8+IDwvcmRmOkRlc2NyaXB0aW9uPiA8L3JkZjpSREY+IDwveDp4bXBtZXRhPiA8P3hwYWNrZXQgZW5kPSJyIj8+MtWoxQAAAcJJREFUeNpi/P//PwMyYGRkhLOrauvZuDg5izk5OZPff/ig9O/fP0YGVADSfBOI5wLxpLbmxl9wCai5jLgsABkuJiq6j5ub2/rBw4cM6OqwgD1A7A2zBKaeBZdqoMFNwsLC1tdv3ABxXwPxJiD+gqaMB4j9gFgUiF2AuBaKEQ7G5gOg61nk5eXev3v7jufzly93gcKWQJe9xuYQoFqQ4ceBWBmIP4AsA6r9AzOXCYcHVIDhDjIcxJ6My3AQgMpNhnIFQHqR5XFZwMHECJd6yEAYIKvhIMYCqoFRCwgCjGSanZPzhpeXVwiYXBn///vH8PPXr/8MaGpu3Ljx+e/fv/+RkjYrExMTF4gNzO1fgGYe27VrlzvWjCYsJCT8/ccPkEKIF5mYGLE4jA+lvAA6AGghcuZzwxlE/4CKYYbTPQ5AuVxTU5PBzMwMpVDEB1hIscDB3p7Bx8cHzJ49ezbD6tWrqesDGRkZOFtNTY36QXT02DFw/IAidNOmTdQPonv37jFcv36d4fPnzwyXL1+mTUb7j1SZDIqcjBFEhFx34sQJhkcPH5Jvwa9fv/BqAMXBtatXyQ+iHz9+/KRCyFyDMQACDADO2LiJuitcAQAAAABJRU5ErkJggg==)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 69993 |
Entropy (8bit): | 7.99584879649948 |
Encrypted: | true |
SSDEEP: | 1536:iMveRG6BWC7T2g1wGUa5QUoaIB9ttiFJG+AOQOXl0Usvwr:feRG6BX6gUaHo9tkBHiUewr |
MD5: | 29F65BA8E88C063813CC50A4EA544E93 |
SHA1: | 05A7040D5C127E68C25D81CC51271FFB8BEF3568 |
SHA-256: | 1ED81FA8DFB6999A9FEDC6E779138FFD99568992E22D300ACD181A6D2C8DE184 |
SHA-512: | E29B2E92C496245BED3372578074407E8EF8882906CE10C35B3C8DEEBFEFE01B5FD7F3030ACAA693E175F4B7ACA6CD7D8D10AE1C731B09C5FA19035E005DE3AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 893 |
Entropy (8bit): | 7.366016576663508 |
Encrypted: | false |
SSDEEP: | 24:hBntmDvKUQQDvKUr7C5fpqp8gPvXHmXvponXux:3ntmD5QQD5XC5RqHHXmXvp++x |
MD5: | D4AE187B4574036C2D76B6DF8A8C1A30 |
SHA1: | B06F409FA14BAB33CBAF4A37811B8740B624D9E5 |
SHA-256: | A2CE3A0FA7D2A833D1801E01EC48E35B70D84F3467CC9F8FAB370386E13879C7 |
SHA-512: | 1F44A360E8BB8ADA22BC5BFE001F1BABB4E72005A46BC2A94C33C4BD149FF256CCE6F35D65CA4F7FC2A5B9E15494155449830D2809C8CF218D0B9196EC646B0C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 330 |
Entropy (8bit): | 3.2300565441917586 |
Encrypted: | false |
SSDEEP: | 6:kK07kVlEN+SkQlPlEGYRMY9z+4KlDA3RUeVlWI/Vt:uSlbkPlE99SNxAhUeVLVt |
MD5: | A7CA1465C6F24FDA9CB2125F200E01EA |
SHA1: | 5E8EE5C0F0CEAE52044FC3B877C9DA7287379AAD |
SHA-256: | DF3A3F3646A93159EA59E09E824C89367EAB124A95DC386D235855885F1979C7 |
SHA-512: | 093F1D8CAEC7FB2ED8ACB0B971CB2C78C4A08998A12C4213786CD37C998DCB3497330E643C2B3852EF04FBB4B515563D18ADFD8377E6F0D31FECAB324EA9DE92 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 252 |
Entropy (8bit): | 3.034404395079139 |
Encrypted: | false |
SSDEEP: | 3:kkFklSttfllXlE/E/KRkzllPlzRkwWBARLNDU+ZMlKlBkvclcMlVHblB8V7lnklc:kKLzxliBAIdQZV7I7kc3 |
MD5: | 8FDF21CF3461C6C41356C7204EFB2E61 |
SHA1: | 2C064E2C8C9C5C0A6EF2B3387369BBB37EDD9B5D |
SHA-256: | 91CE075A5EC178D7B51260920D78D056D11544CB6C2A9B3224FF4D267493C604 |
SHA-512: | 1AEF05C99B9B5BFCD564D88DD0436A7E3D1AA11815FD2DCD8E63D9868121B304AE2978132C8C76664BF8C5ED409518D1E2773CD2BFBF01939275E29B15B4ECEA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | 1536:JsVoWFMWQNk1KUQII5J5lZRT95tFiQibVJDS+Stu/3IVQBrp3Mv9df0CXLhNHqTM:bViyFXE07ZmandGCyN2mM7IgOP0gC |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | 1536:JsVoWFMWQNk1KUQII5J5lZRT95tFiQibVJDS+Stu/3IVQBrp3Mv9df0CXLhNHqTM:bViyFXE07ZmandGCyN2mM7IgOP0gC |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 227002 |
Entropy (8bit): | 3.392780893644728 |
Encrypted: | false |
SSDEEP: | 1536:qKPC4iyzDtrh1cK3XEivK7VK/3AYvYwgF/rRoL+sn:XPCaJ/3AYvYwglFoL+sn |
MD5: | 265E3E1166312A864FB63291EA661C6A |
SHA1: | 80DFF3187FF929596EB22E1DB9021BAD6F97178C |
SHA-256: | C13E08B1887A4E44DC39609D7234E8D732A6BC11313B55D6F4ECFB060CD87728 |
SHA-512: | 48776A2BFE8F25E5601DCC0137F7AB103D5684517334B806E3ACF61683DD9B283828475FC85CE0CBE4E8AF88E6F8B25EED0A77640E2CFFF2CC73708726519AFA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.362053405593646 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJM3g98kUwPeUkwRe9:YvXKXFosWni0ccGMbLUkee9 |
MD5: | 7B38614BAD062B07DE4F676A983F3A43 |
SHA1: | BADACC60431BD94DCCDF8606207D10124086295C |
SHA-256: | D8501868B4F959A4D7B1BCA3AF94A3710088CA4DD6F1017716DE23323F395B61 |
SHA-512: | C4953E59B2B6D7559DD73979A9F5908398C70042BC3198A48D05F12C6A62F144ED1003CDFEE8B50DC021C384FEA1A4704620308D324093D4986A59A78289E1C2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.314874637743992 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJfBoTfXpnrPeUkwRe9:YvXKXFosWni0ccGWTfXcUkee9 |
MD5: | E214DAC54009FD01BBB26D9D5B839FCA |
SHA1: | 51EF3D4E763170DA8F3686914ACF4EEB88ACE968 |
SHA-256: | 94D615EC68B1EADFD6FF0D5BBD1DABE09667D6F0FF2FCFBD17CE7F75AE0CD3AE |
SHA-512: | 7E4975808D11C22D7F0ABEA9F9D8E3061760683DB7B4F602F9076F631E558E278672C32541A17D1D78BE7186A00083BA503BC638572A3D1C115AB6F879F41AB0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.2923468869476205 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJfBD2G6UpnrPeUkwRe9:YvXKXFosWni0ccGR22cUkee9 |
MD5: | C3C560A7668C20EB16D4B9F21B118410 |
SHA1: | DE2736607B24B4F8E1E48C48DAAE4EBD126B877D |
SHA-256: | 5F11B1D6D3AD379334DCC73C4F3E79D5B89F1A1B67652122C6F73B7BA35B05BF |
SHA-512: | DC48AA9858FDB105B28E021B02E8B562368DD660C90D3CF96A78DC0D7E03DA08A2815FF18F2A9F746360FCC8C9F9EF79DCD6FF5E4FD753EF3912A789AB367BEC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.342030017021669 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJfPmwrPeUkwRe9:YvXKXFosWni0ccGH56Ukee9 |
MD5: | 79722DE41AB6F5DE527B39D6556C4D59 |
SHA1: | 7AA9087D6A0F0F8268925DD3D67669E302045B36 |
SHA-256: | 9F94C2186900F391692C8A58B3CE38C05A5819E1012BE4C8E90C991EB7093F0A |
SHA-512: | A1904E3F151E5D53AC61F5951B302BD06AF9B52F95A00C6D234EA92276CE682EAE2632F3047AC2C2856D09E81372BDFFB648C26B39DAD1AF86EF3DDCDDD707D7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.3092413489342345 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJfJWCtMdPeUkwRe9:YvXKXFosWni0ccGBS8Ukee9 |
MD5: | 839F5FD319BC3AE83C858DA3FD56CCCA |
SHA1: | 07B09CBB1DEEC8DFDECB96FB1E95966154EA234B |
SHA-256: | C0B013298F44DCFEB5F3BC8FE77C390E87EB94FB6775693334A0C9C4420F83C2 |
SHA-512: | 435170CAEC7D5B5E52EE0D0AB0E8DDB80651EC6906B0CD3B893F1A0EE39494DBF06C29C34FD9D91DF512BB59F1F43C735177CDB3824E5BCCE2A166EDE3A475C9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2925123503395985 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJf8dPeUkwRe9:YvXKXFosWni0ccGU8Ukee9 |
MD5: | 3B29E831CDB9E21EDD22CAC524EAD343 |
SHA1: | 0905F954DE170D9F58D9098D31C7D58180DDD921 |
SHA-256: | 008DEE51D54DA55CE521994D9475FEB6F5FEB7DEEA4DF7C873D80E10E3A1B310 |
SHA-512: | 66DE46BF8F64D8AB7946BF3C8A1690CDC334893D90B5ED7D18E67EFCF5656E4BD5A6BCDA7EA92C432B455D64B37778AB631A30B29E60DDE81BD219E839DB9E6F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.294893705552621 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJfQ1rPeUkwRe9:YvXKXFosWni0ccGY16Ukee9 |
MD5: | F40AB42DD3F6E1422BE9E980BAB8A712 |
SHA1: | 7FE2030707BCE0EAEC3D1ECF0688404A3F700D64 |
SHA-256: | F2F95A95C4D6FE53B6BEB2EBD1008412ABED02B5C5E466F7E6D1AACD6E4623CA |
SHA-512: | F8E4018D807446812A1FE116812B7ED03D892D45A1F9234C397660B470DA508CAE438FC026961BBF342058C5F3F09C89C7D9387EBB5DF47CDFF3C43C6C81A530 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.303867821460468 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJfFldPeUkwRe9:YvXKXFosWni0ccGz8Ukee9 |
MD5: | 76BA4F1ABE796D1A2AAD24CF2E419FEF |
SHA1: | A93E49FA8E3BA70ECBCE53093E80E58BC6E6EDF4 |
SHA-256: | F66B9DC03395C80F0BF5496F08519C922F21B5274D8934F2BFBAD96C5F850CD8 |
SHA-512: | 764BA28EBC57112372CB53E192BE3B671E0AB78A70DD1B97DDE5021D3F10379B8B4CFFAE1944A72802472F7C1A2D7D8249318F1A04F25FF8A989441C96619643 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1372 |
Entropy (8bit): | 5.741936794928705 |
Encrypted: | false |
SSDEEP: | 24:Yv6XrZEKLgENRcbrZbq00iCCBrwJo++ns8ct4mFJNF:YvtEgigrNt0wSJn+ns8cvFJX |
MD5: | 74AA6D78D178FE433092F7991748D74D |
SHA1: | E13B7EB90A332C326EC6D05E1EDD7F01BAB71B34 |
SHA-256: | 79876FAAE7651394D953E69708DD4E8CECFF75B5C85EEFB4941B79FEBFF176B4 |
SHA-512: | F7A4B5EBD8FE24C3484C42416069F1C81A52B8888E773E195C15C7C120F4911B29464B1051AD92588BB089184E8D714445B555295F4BB666796798F4247869C3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.301149236351149 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJfYdPeUkwRe9:YvXKXFosWni0ccGg8Ukee9 |
MD5: | 19DE1A029D24381045B668E0C1C2B6C1 |
SHA1: | 81F0EA85AF095CABD1A082C4196D060E144F2625 |
SHA-256: | 28326A5A3136024783786D41A8FCE57C2B2030FF58A9C5F40D2D8466227570B4 |
SHA-512: | 97784B6FE97CF73F59BE2E0DC71E71921F159336C9102B64768CC36DFC092D5F6E9545055FD31AB222DDF8F507F313858CCA4ED64F450A5576AA59CE38325F0B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1395 |
Entropy (8bit): | 5.778202785224074 |
Encrypted: | false |
SSDEEP: | 24:Yv6XrZrrLgEGOc93W2JeFmaR7CQzttgBcu141CjrWpHfRzVCV9FJNN:YvwHgDv3W2aYQfgB5OUupHrQ9FJz |
MD5: | 4F0BDC6E2E0A77D65CB2E7B00F7B764F |
SHA1: | 12DF6BB436C81D8ADE7348FD6546FBD04AB88508 |
SHA-256: | 9BACC105FCE9EB26353655283DA9390621968913C9D4566120FD171D7182D713 |
SHA-512: | C97BDED7B2D2B540C16FDA355643E573F8EE75C3EEC5A35E43768F3C765F68EB784BF778397383B08FAC24A160AA51A77CB2FB8E0989DBE3635210351FBA217F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.284688435493388 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJfbPtdPeUkwRe9:YvXKXFosWni0ccGDV8Ukee9 |
MD5: | 29901E6475FCD3AA0E9584413F464988 |
SHA1: | 919EB382C330FA1E6C5D174973A21D6EDC9C00FD |
SHA-256: | E8EE10057C3CE0FE268D1FA12047BB4C04D28549A16FC666634FE6B8B0E31A72 |
SHA-512: | FCE5C7C8BB0C105EDE94AC90E027E186E16C0674BD653D997C0A1B9651FCB39200BBD2F8D8DB83A2EFEADDC9CA9B270B6EF71DA26873324F9006295259EE2CD8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.287435912863912 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJf21rPeUkwRe9:YvXKXFosWni0ccG+16Ukee9 |
MD5: | A1330A9D884165C2A6F9989A6B9BF011 |
SHA1: | 28D146E2AFC5628F2B5A5DC2AB3A305CC2B963FB |
SHA-256: | 7DF8D2BDB7B164053C22253AD2A7B3DC1F284ED459F30C38A13E9C8F1ACAE6FA |
SHA-512: | 57BD380B830FB74B612016B0EA4BC51D24C6FBEBF6411F08115C6C4AA9D21458774FCE359FB040BC900FE024DFF2E206F7EB35466B156320BEB1F74392F35441 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.307690547035075 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJfbpatdPeUkwRe9:YvXKXFosWni0ccGVat8Ukee9 |
MD5: | 5E8A495C48423A104388CD1879BBA8C8 |
SHA1: | 91172FEC359F1D088578743B1217ABF89C12DDA4 |
SHA-256: | 2008E5EF0E06814E0ECEDBC768B3C0FCB83BC97ABE1D4E415089482A750EE68F |
SHA-512: | 983B8148C4FE1197E00B772FA4FC0EA262D2F0E2D900A6E57125A44BEAD502300FFDC101CBDD13C013CFA5A9806B6A322EB4C674DB7CB2FE9CC1FB68EBD4A706 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.26470428748653 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF0GgsWnWn0nZiQ0YtqoAvJfshHHrPeUkwRe9:YvXKXFosWni0ccGUUUkee9 |
MD5: | CB0DCC61F20530C706CE8C3428CDA562 |
SHA1: | 7C39DB31713911F649B431F4B667B1E5CD9B4CE5 |
SHA-256: | D5CBE6F48040FD75085C9D1EF474A091CA39C49F1ADDEDED4ED9B77B37CB5F7D |
SHA-512: | 0125892CD98045544B841FB51AE5C5E727A6EA91677EA1328D0A9AB94E28F686A002B234CB2CBC0056D0FE410A23E0A4D33A5B81BDFA911DE95FF91E15538C79 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 782 |
Entropy (8bit): | 5.361307903520206 |
Encrypted: | false |
SSDEEP: | 12:YvXKXFosWni0ccGTq16Ukee1+3CEJ1KXd15kcyKMQo7P70c0WM6ZB/uhWB:Yv6XrZy168CgEXX5kcIfANho |
MD5: | F1020179072334498F3F50E95BEFE4DD |
SHA1: | 0A6E3BDE0E26C6786A17C52F2D6285F3BF5CFD29 |
SHA-256: | D55972A941009075248AA9A490F9B7C340A52AB2A7DA660EF3532A47CBBAE14C |
SHA-512: | 00DDCB35C817514BB499E75DEAC66B1BFDD605E1A8F2A26AC725B5681FAE86C4DF229408930E63404ECF41A474B4C927E5DF54705BC5B469967773A2618FAE11 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.135341051187209 |
Encrypted: | false |
SSDEEP: | 24:Yf8WCe+cetroHgzRaHi11ayWMs55M0TWmh4Djv01j0SNcvh20KL2LSfL8eG5ZtoD:Yb3+ceBo/iLs5TTLM6wVKLx1Gto9aS |
MD5: | FE25A81C028EDF76E2DE249892B92D6A |
SHA1: | 868BEE070B5D91787AAE0A2742E4348121E8EDAE |
SHA-256: | EEB196109BFD69596FDE56C7B53329BB7BC1CE4DF62F5664E5C49C9E4C4648BF |
SHA-512: | F7712EB1B43773327E9ABED758AADC45FEA407D11CA31510C7F53BE8F5AA61EBE52202FF9D4BCE4A72E1446D531FBE6672E5B9103D3B2A8798E70F0C64EE98F3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.145739065392205 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursk1ZLRZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUuk:TFl2GL7msuPXc+XcGNFlRYIX2v3kDh |
MD5: | 7E3F4ACA142407AE6A78A7FBF5811CCD |
SHA1: | 9EF70BAA81849201E31901CFD76D1CCB04A80EB4 |
SHA-256: | E5357A234ADB53CC796A17A89CD9610174E4AD980D592888DE1BFE1AF22CC72C |
SHA-512: | C79535EE4A810CE30BE55ABF928A7658E868B789445CE839F1F34D7759A6C1FCA21D6ED22CB8DED2A43A0A659050A23A5BDDD5310A93FE4E11F039AF35C8098E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5498566290573073 |
Encrypted: | false |
SSDEEP: | 24:7+t51ZLUXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLuxApqLxx/h:7Mh4Xc+XcGNFlRYIX2v9qVl2GL7msv |
MD5: | 5CF87AD401F0EA2742454D321D267979 |
SHA1: | 4A820D48A3AFD667F1787C1CF2307C731D0D09D4 |
SHA-256: | 31EEE25952273AAA1F5A8C955A5F02CAF00884AC3AB2027704EFADADACF4270E |
SHA-512: | 12C444D868AB97984B7CC16378C3D55FBB75D625D9118F4E3F25086E62BDD5C668339CF367DF1E301F3BF2BD80D9F91728C1474529FD1F255934EFB1EFEE4740 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.518261198325562 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8c6846e:Qw946cPbiOxDlbYnuRKHsr |
MD5: | FCB35E300B617593C029F1C85FA9DC34 |
SHA1: | 789325F5F30246607F693FD455097F7D4A393F6F |
SHA-256: | 01DADD849A4FCD87B5B32AE631E884A4557A94F68F22DA34D9119ED0B4D9A47D |
SHA-512: | 53E58292FA1A117196C01994AF0BD10E7143CAA76878BBA367C93F3D21BFC7E9E76B7F752712E022F4CAB0B9E9AE25C93D455693F528575E690CE6E7C7ACE34A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-05-24 15-42-51-357.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16601 |
Entropy (8bit): | 5.343357521147715 |
Encrypted: | false |
SSDEEP: | 384:Rh3bYCRHeJAuhf8NhvmTf0JT3W2GRDP4Un4qkIq77SWgd/SDpQYzZsZAN0GCZmuc:5VrB |
MD5: | 5C6E5251DD98526BCDEAB68DF94D408D |
SHA1: | 4A648FB0DDF40AD29051E431D3CD341CEEF55378 |
SHA-256: | A7F373DC5C7BFB84AB37EF723A7C9397B3F3D810B573B9561D62BA76474075F6 |
SHA-512: | E07A67B068D58D70873F9C940D9A48A1C40A9304C7C81091C4E39EF6EF5783CBD461E4A081F17E1D6F0DF646121119BE5B57068E5338300C0172787102103DC5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29845 |
Entropy (8bit): | 5.39187426610857 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcbTqyqAqAqEq1qgqXqAqLqzq+qtS:V3fOCIdJDemCb |
MD5: | 0D653F2A869E3870BA7943B470390E7B |
SHA1: | 05D145BC590821B365F3B5A32010055D63A95F5D |
SHA-256: | C3466FCFDD256B120FAF730A0DC2C7A29AE795E6D2412331D76521C5334AA837 |
SHA-512: | 82063C7A2097E101C8DF429D0FE7C4E7AF392134BE1E2188C8C5B83CA976D0F4D8A9C9CC5473D3FA9F7B68160B1088C774FBFB8D92B64120B699BF8E313F88AD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLaGZDwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLaGZDwZGk3mlind9i4ufFXpAXkru |
MD5: | 18E3D04537AF72FDBEB3760B2D10C80E |
SHA1: | B313CD0B25E41E5CF0DFB83B33AB3E3C7678D5CC |
SHA-256: | BBEF113A2057EE7EAC911DC960D36D4A62C262DAE5B1379257908228243BD6F4 |
SHA-512: | 2A5B9B0A5DC98151AD2346055DF2F7BFDE62F6069A4A6A9AB3377B644D61AE31609B9FC73BEE4A0E929F84BF30DA4C1CDE628915AC37C7542FD170D12DE41298 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.955915791207243 |
TrID: |
|
File name: | Seminole Casino - 2023 DJI Invoice.pdf |
File size: | 80'972 bytes |
MD5: | 778252f7dedae0b7954cd30f24e22f20 |
SHA1: | d020f2a610f12d927b710ba17ebadc1b2538b417 |
SHA256: | 7453ff20e6036ede9dacaf3f77ebe51ba7665b5b5c520d59795d25c882886dc8 |
SHA512: | 3ce8c54bdc1cd50e7058663c754193ca4d9fe9078649a7e852986a09af493a213f9f7add3fa3f691303afcb3de4302004a42ee07e1fd9c006d41945013a6e5f2 |
SSDEEP: | 1536:R/LaECkion40gX+02WZ+gfig9wMGch8iYSw5uJa+:RTaECk40v02bgqMrh8XuJa+ |
TLSH: | 1B83CF5AD7C8CC8FD809E512465FEBB4C5EA73B1859C1BC13E24BECA2C91998633B354 |
File Content Preview: | %PDF-1.3.%............3 0 obj.<< /Filter /FlateDecode /Length 6355 >>.stream.x..].s.......,E..&.....t.m...?.3.]..p.r*w%%g...._...0c...)Ui...........w..Y...n.....]..u.1k.~.G...V....s.d..S...?e.p.i...._.kQ.....aW../?........?......~.~./.C..Y..EQ`...9.vh.... |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.3 |
Total Entropy: | 7.955916 |
Total Bytes: | 80972 |
Stream Entropy: | 7.978318 |
Stream Bytes: | 75978 |
Entropy outside Streams: | 5.115579 |
Bytes outside Streams: | 4994 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 27 |
endobj | 27 |
stream | 13 |
endstream | 13 |
xref | 1 |
trailer | 1 |
startxref | 1 |
/Page | 1 |
/Encrypt | 0 |
/ObjStm | 0 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
5 | 0000000000000000 | 2a51157a8f80a9d51d2fc080fc6b1664 | |
6 | 0000000000000000 | 965bff88bff4961eb2d1d715016f6864 | |
16 | 04102ea2e2ea0082 | ad038f8486aa3b1d500f511eae537f02 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 24, 2024 21:43:02.343172073 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:02.343260050 CEST | 443 | 49711 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:02.343355894 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:02.343826056 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:02.343858957 CEST | 443 | 49712 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:02.343945980 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:02.344182014 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:02.344223022 CEST | 443 | 49711 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:02.344439030 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:02.344465017 CEST | 443 | 49712 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.046226025 CEST | 443 | 49711 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.062251091 CEST | 443 | 49712 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.088432074 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.103987932 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.188163996 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.188179970 CEST | 443 | 49712 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.188179016 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.188234091 CEST | 443 | 49711 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.191869974 CEST | 443 | 49712 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.191936970 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.192260027 CEST | 443 | 49711 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.192346096 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.203069925 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.203167915 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.203259945 CEST | 443 | 49712 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.203385115 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.203396082 CEST | 443 | 49712 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.203440905 CEST | 443 | 49711 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.244672060 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.246109009 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.246170998 CEST | 443 | 49711 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.291534901 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.329572916 CEST | 443 | 49712 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.334628105 CEST | 443 | 49712 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:03.334702969 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.373114109 CEST | 49712 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:03.373140097 CEST | 443 | 49712 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:13.785764933 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
May 24, 2024 21:43:13.786015034 CEST | 443 | 49711 | 23.47.168.24 | 192.168.2.6 |
May 24, 2024 21:43:13.786087990 CEST | 49711 | 443 | 192.168.2.6 | 23.47.168.24 |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
May 24, 2024 21:43:02.588073969 CEST | 1.1.1.1 | 192.168.2.6 | 0x42b8 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
May 24, 2024 21:43:02.588073969 CEST | 1.1.1.1 | 192.168.2.6 | 0x42b8 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49712 | 23.47.168.24 | 443 | 4904 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-24 19:43:03 UTC | 475 | OUT | |
2024-05-24 19:43:03 UTC | 198 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 15:42:48 |
Start date: | 24/05/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 2 |
Start time: | 15:42:48 |
Start date: | 24/05/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 4 |
Start time: | 15:42:49 |
Start date: | 24/05/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |