Windows
Analysis Report
REGISTERED NY LIEN JUDGMENT 3 FILED.pdf
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
- Acrobat.exe (PID: 3636 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\R EGISTERED NY LIEN JU DGMENT 3 F ILED.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 6228 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6444 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 44 --field -trial-han dle=1580,i ,131780853 9668722907 4,42433653 1378799458 8,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Static file information: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 3 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 13 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.210.172 | true | false | unknown | |
171.39.242.20.in-addr.arpa | unknown | unknown | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
23.47.168.24 | unknown | United States | 16625 | AKAMAI-ASUS | false | |
52.6.155.20 | unknown | United States | 14618 | AMAZON-AESUS | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1467207 |
Start date and time: | 2024-07-03 21:08:06 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 33s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 22 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | REGISTERED NY LIEN JUDGMENT 3 FILED.pdf |
Detection: | CLEAN |
Classification: | clean2.winPDF@16/57@1/2 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe, TextInputHost.exe
- Excluded IPs from analysis (whitelisted): 172.64.41.3, 162.159.61.3, 184.28.88.176, 199.232.210.172, 2.16.241.13, 2.16.241.15, 2.19.126.143, 2.19.126.149, 104.124.11.43, 104.124.11.64, 88.221.110.81, 88.221.110.120, 88.221.110.64, 88.221.110.91, 88.221.110.115, 88.221.110.99, 88.221.110.59, 2.16.100.176, 2.16.100.162, 2.22.242.11, 2.22.242.123
- Excluded domains from analysis (whitelisted): www.bing.com, chrome.cloudflare-dns.com, e4578.dscg.akamaiedge.net, fs.microsoft.com, identrust.edgesuite.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, acroipm2.adobe.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com, a1952.dscq.akamai.net, ocsp.digicert.com, login.live.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, evoke-windowsservices-tas.msedge.net, geo2.adobe.com, wu-b-net.trafficmanager.net, apps.identrust.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- VT rate limit hit for: REGISTERED NY LIEN JUDGMENT 3 FILED.pdf
Time | Type | Description |
---|---|---|
15:08:49 | API Interceptor |
Input | Output |
---|---|
URL: PDF Model: gpt-4o | ```json{ "riskscore": 1, "reasons": "The document appears to be an official filing acknowledgment from the State of New York Department of State. There are no visually prominent buttons or links in the screenshot. The text does not create a sense of urgency or interest that typically characterizes phishing attempts. It is a formal acknowledgment of a filing with no immediate call to action. The document does not impersonate any well-known brands beyond the legitimate government entity it claims to represent. The sense of urgency is not connected to any prominent button or link, as there are none present."} |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
23.47.168.24 | Get hash | malicious | HTMLPhisher | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | ScreenConnect Tool | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Arc Stealer | Browse | |||
Get hash | malicious | Unknown | Browse | |||
52.6.155.20 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HtmlDropper, HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
bg.microsoft.map.fastly.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | BlackMoon | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | AteraAgent | Browse |
| ||
Get hash | malicious | FormBook | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-AESUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AKAMAI-ASUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | CryptOne, Vidar | Browse |
| ||
Get hash | malicious | CryptOne, Vidar | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.212368316484212 |
Encrypted: | false |
SSDEEP: | 6:BOWIvU7L+q2PsHO2nKuAl9OmbnIFUt84OWIvU5z1Zmw+4OWIvU5lLVkwOsHO2nKZ:EPvK+vkHVHAahFUt81Pvmz1/+1PvmNVM |
MD5: | F1214095391F59B07302F03FFB91E867 |
SHA1: | C0F5372F46A92CF8704A155039F3DB7A7A1A5E1E |
SHA-256: | C55555C73D6A86AE08527CABE945B1DD8B4CD92D14659C0C32184B71CEF4CFB0 |
SHA-512: | 9D2E548F640D91785BED34E5F5C0A9F91BA6E089F97DD8AF579A3B7EF17BE1313A04D5F8A642428632BE5AB6279D8686CB71EB9A5FC2BD04E1C688AE1FD71DBA |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.212368316484212 |
Encrypted: | false |
SSDEEP: | 6:BOWIvU7L+q2PsHO2nKuAl9OmbnIFUt84OWIvU5z1Zmw+4OWIvU5lLVkwOsHO2nKZ:EPvK+vkHVHAahFUt81Pvmz1/+1PvmNVM |
MD5: | F1214095391F59B07302F03FFB91E867 |
SHA1: | C0F5372F46A92CF8704A155039F3DB7A7A1A5E1E |
SHA-256: | C55555C73D6A86AE08527CABE945B1DD8B4CD92D14659C0C32184B71CEF4CFB0 |
SHA-512: | 9D2E548F640D91785BED34E5F5C0A9F91BA6E089F97DD8AF579A3B7EF17BE1313A04D5F8A642428632BE5AB6279D8686CB71EB9A5FC2BD04E1C688AE1FD71DBA |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.184847357092801 |
Encrypted: | false |
SSDEEP: | 6:BOWIvU5qjyq2PsHO2nKuAl9Ombzo2jMGIFUt84OWIvUdyz1Zmw+4OWIvUdFjRkwM:EPvZOvkHVHAa8uFUt81Pvoyz1/+1PvoG |
MD5: | 345B0A9BE02FC75AC99AE1881BE9870A |
SHA1: | 9BF9DA67E31F19C767B048389DB0DE8EABBAC092 |
SHA-256: | EA4901FEFF6B701D0716DED1CC73204E443730D09C7C6660D99AD15333D1EC53 |
SHA-512: | 1926697C32AEC3C215EC1A1B366D5D5A8F043A3756728C85C37A25149CF5814255FB440DC63F66A2A7404469EC4C28E54F8990B764E512BF10993ECCE8F6C4F1 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.184847357092801 |
Encrypted: | false |
SSDEEP: | 6:BOWIvU5qjyq2PsHO2nKuAl9Ombzo2jMGIFUt84OWIvUdyz1Zmw+4OWIvUdFjRkwM:EPvZOvkHVHAa8uFUt81Pvoyz1/+1PvoG |
MD5: | 345B0A9BE02FC75AC99AE1881BE9870A |
SHA1: | 9BF9DA67E31F19C767B048389DB0DE8EABBAC092 |
SHA-256: | EA4901FEFF6B701D0716DED1CC73204E443730D09C7C6660D99AD15333D1EC53 |
SHA-512: | 1926697C32AEC3C215EC1A1B366D5D5A8F043A3756728C85C37A25149CF5814255FB440DC63F66A2A7404469EC4C28E54F8990B764E512BF10993ECCE8F6C4F1 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 476 |
Entropy (8bit): | 4.977564621483501 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqbl7SsBdOg2HNcaq3QYiubEP7E4T3y:Y2sRdsWlbdMH83QYhbY7nby |
MD5: | BBFFABCBFCCF8D0768D314FB28B0F8D6 |
SHA1: | FC35B6B48C9997E42A7F094B765A37A3AC031C72 |
SHA-256: | CD378BE71FE74AC3344F2CE976F1B8BBF80FA9C1E4FFF28EA80FC60069A32E9B |
SHA-512: | 779EBB50C677050116D8A59A0E21C92638139C5964BF7F808C4181BF73339FAC33926D5CE4789638BE02D06CD5AB4038C2131FF8328F9C0001171CBCA8214C61 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\fbe6c672-8240-4893-981a-414a27204b52.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 476 |
Entropy (8bit): | 4.977564621483501 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqbl7SsBdOg2HNcaq3QYiubEP7E4T3y:Y2sRdsWlbdMH83QYhbY7nby |
MD5: | BBFFABCBFCCF8D0768D314FB28B0F8D6 |
SHA1: | FC35B6B48C9997E42A7F094B765A37A3AC031C72 |
SHA-256: | CD378BE71FE74AC3344F2CE976F1B8BBF80FA9C1E4FFF28EA80FC60069A32E9B |
SHA-512: | 779EBB50C677050116D8A59A0E21C92638139C5964BF7F808C4181BF73339FAC33926D5CE4789638BE02D06CD5AB4038C2131FF8328F9C0001171CBCA8214C61 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6495 |
Entropy (8bit): | 5.243880731815611 |
Encrypted: | false |
SSDEEP: | 192:TUi8h+F8Aj8DRCGwtqzmsLnNreR2ZpjRe4I8qr9jnNI92D3jC+3ETKEAE8jQe3KZ:jX8eQM0 |
MD5: | 3DA7368D01140B7B9A1EB9AE0D422AA1 |
SHA1: | 367642A9AEF29F8FAA6841121D4F9DAD00DF9C3F |
SHA-256: | DF2930C53A0EE5566B678CD9D9B14A908440B94714F6382E946782573AB047F1 |
SHA-512: | 1741A6A49FB28D323085884AD0C56704BD5733BB669586D0FEEFB52283AE0A6FC6CC56E911835A541AF965D339C8086431DAA5F1942222E3CED743B4EF109670 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.228271608271069 |
Encrypted: | false |
SSDEEP: | 6:BOWIvU6yq2PsHO2nKuAl9OmbzNMxIFUt84OWIvUTQR11Zmw+4OWIvUORkwOsHO2v:EPvKvkHVHAa8jFUt81PvT1/+1Pv951Hp |
MD5: | CE63CA5BD54D051480CDABA127ACFAAB |
SHA1: | F6BCFF0F9B071447243B2FE51419F15493C302EB |
SHA-256: | C71FB171B3650FF2FC949BE25B488E5A182E7B736A8551BEC3B4DE80E01E1DA9 |
SHA-512: | 2FE9C7E1A91DFB31810B4CAD4EDB72A0B79A5BA0474DC0F1CAE727F4D0BBBABB2E453653839FBB087D83B47B507EF2FFC60E3FAD20BEC1CF1CF0D2CB222FD132 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.228271608271069 |
Encrypted: | false |
SSDEEP: | 6:BOWIvU6yq2PsHO2nKuAl9OmbzNMxIFUt84OWIvUTQR11Zmw+4OWIvUORkwOsHO2v:EPvKvkHVHAa8jFUt81PvT1/+1Pv951Hp |
MD5: | CE63CA5BD54D051480CDABA127ACFAAB |
SHA1: | F6BCFF0F9B071447243B2FE51419F15493C302EB |
SHA-256: | C71FB171B3650FF2FC949BE25B488E5A182E7B736A8551BEC3B4DE80E01E1DA9 |
SHA-512: | 2FE9C7E1A91DFB31810B4CAD4EDB72A0B79A5BA0474DC0F1CAE727F4D0BBBABB2E453653839FBB087D83B47B507EF2FFC60E3FAD20BEC1CF1CF0D2CB222FD132 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\000001.dbtmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16 |
Entropy (8bit): | 3.2743974703476995 |
Encrypted: | false |
SSDEEP: | 3:1sjgWIV//Uv:1qIFUv |
MD5: | 46295CAC801E5D4857D09837238A6394 |
SHA1: | 44E0FA1B517DBF802B18FAF0785EEEA6AC51594B |
SHA-256: | 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443 |
SHA-512: | 8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 107 |
Entropy (8bit): | 4.562663554774739 |
Encrypted: | false |
SSDEEP: | 3:x9K+k1t1HcZUV/TSq8qaOlknlll11HcZUV/TgllkW:ItVnVmq83OIlPVnV8OW |
MD5: | 500A7231DF678BE00BF7BD9E19759B22 |
SHA1: | 065BAEFD0C8832A87821DC7B95C778706754806E |
SHA-256: | 54BC9ABDAC791BB99323175D9B45787A1B076E8A7F64E4797272A485C1F9E4B9 |
SHA-512: | 3BD8FE5ED8EF86B152091517D0921D7E8CC21F153A50928418B8AE2B7AFDA9B38D5D0194A9D7F8D8ACDC8A0C56C4F7ED96995654DA4E5CA763968692182D6F7A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\CURRENT (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16 |
Entropy (8bit): | 3.2743974703476995 |
Encrypted: | false |
SSDEEP: | 3:1sjgWIV//Uv:1qIFUv |
MD5: | 46295CAC801E5D4857D09837238A6394 |
SHA1: | 44E0FA1B517DBF802B18FAF0785EEEA6AC51594B |
SHA-256: | 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443 |
SHA-512: | 8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.20734629366535 |
Encrypted: | false |
SSDEEP: | 6:BOWIIDEFD1sHO2nKuAl9OmbzfXkrl2KLlrOWIID+4q2PsHO2nKuAl9OmbzfXkrKQ:EPIwwHVHAa8/uLcPIK4vkHVHAa8/F3F2 |
MD5: | E0773E8EFDA4D54CE495A6481553843D |
SHA1: | D0447FD3E5ABDBC59E172FD2D535437A153828C6 |
SHA-256: | 2AD5A044C74DFE56AA85A410E99268CEAE7C2A8670C28F0FAF7D1311C321CDDF |
SHA-512: | 4F14246681BD652CC31D7EA297226F5B96D488BE5015F9CF5A9BC861F664589CFEC14FB899B3A947A9FC640D8202623083352ECB0B8494FA35205BBBB58AAE97 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\MANIFEST-000001
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 41 |
Entropy (8bit): | 4.704993772857998 |
Encrypted: | false |
SSDEEP: | 3:scoBAIxQRDKIVjn:scoBY7jn |
MD5: | 5AF87DFD673BA2115E2FCF5CFDB727AB |
SHA1: | D5B5BBF396DC291274584EF71F444F420B6056F1 |
SHA-256: | F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4 |
SHA-512: | DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\metadata\000001.dbtmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16 |
Entropy (8bit): | 3.2743974703476995 |
Encrypted: | false |
SSDEEP: | 3:1sjgWIV//Uv:1qIFUv |
MD5: | 46295CAC801E5D4857D09837238A6394 |
SHA1: | 44E0FA1B517DBF802B18FAF0785EEEA6AC51594B |
SHA-256: | 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443 |
SHA-512: | 8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\metadata\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 126 |
Entropy (8bit): | 3.6123534208443075 |
Encrypted: | false |
SSDEEP: | 3:G0XttkJcsRwI9tkJcsSaJkG3mH2lztzlkzXlfmH2lG:G0XtqcsqczaJf3mH2lztzl4mH2lG |
MD5: | A05963DD9E2C7C3F13C18A9245AD5934 |
SHA1: | 15A87493591860C6C22499DF3A705ACB3CB466BD |
SHA-256: | F40B7EF0FE0B676871403B8DD21CE42AF8E482DC8B81F09D93CB2C48CCD112B4 |
SHA-512: | E67833950A3DB8D4C27FC851C7DF9AEBB85699024F805E98A2951E9E9FC3B606F10EAD23CE0A3B97484A18A9A52520540FB29787178BFEB9FBD8D46D0AA492A2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\metadata\CURRENT (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16 |
Entropy (8bit): | 3.2743974703476995 |
Encrypted: | false |
SSDEEP: | 3:1sjgWIV//Uv:1qIFUv |
MD5: | 46295CAC801E5D4857D09837238A6394 |
SHA1: | 44E0FA1B517DBF802B18FAF0785EEEA6AC51594B |
SHA-256: | 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443 |
SHA-512: | 8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\metadata\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 303 |
Entropy (8bit): | 5.178802974173485 |
Encrypted: | false |
SSDEEP: | 6:BOWIIDcR1sHO2nKuAl9OmbzfXkrzs52KLlrOWIIDPN4q2PsHO2nKuAl9OmbzfXkO:EPIDHVHAa8/N9LcPIzN4vkHVHAa8/iF2 |
MD5: | ADF409835A8F2F72C3F997215D333DD0 |
SHA1: | EEF3CC6E07971194C12C0D9580694578A228F297 |
SHA-256: | 187D695E8E9A818B6FF48709D3273376A6FD7E4194C63354B114A89F8DF0A7CA |
SHA-512: | 6EB805AA5481D1D5068FC70B7FDE47A8356DA33EAA2903E015E6034118A16C42403B6186EF95EED80FFE8219779151434B353ED1E99A5A6DB4D9D0EC884DC6AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\metadata\MANIFEST-000001
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 41 |
Entropy (8bit): | 4.704993772857998 |
Encrypted: | false |
SSDEEP: | 3:scoBAIxQRDKIVjn:scoBY7jn |
MD5: | 5AF87DFD673BA2115E2FCF5CFDB727AB |
SHA1: | D5B5BBF396DC291274584EF71F444F420B6056F1 |
SHA-256: | F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4 |
SHA-512: | DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-240703190847Z-246.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71190 |
Entropy (8bit): | 1.9038836417609133 |
Encrypted: | false |
SSDEEP: | 192:JBdIuxWqftGSmlcZdjJRJzpE0Oe/2KjqR6OiwMseNxtIV3xds5N0mc3W9KAFlqiW:WABmUjv1OlKO6OHAtIFsH0/3WYAFFW |
MD5: | D41CC13956E189B0381DF3E3E595F550 |
SHA1: | 6909372332C0C779A274BF29E43F358448D9C5E8 |
SHA-256: | 23529DEFE1A7DA911FC013195CFF8A0B8BDECCF602B8255D3F6254F91ACCD0FF |
SHA-512: | 924616A8785CD28F041B52C8785CA4594ED316446D70D7DE2E9088400477AE928E43B9F881D9F7DEC8DB249D0DA33B5EA68A4D7A882957D22D455CA53B62929C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.4448400659258755 |
Encrypted: | false |
SSDEEP: | 384:yeZci5tRiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:Fis3OazzU89UTTgUL |
MD5: | ED8E9CAA6C322C94A2058BBAEFFAC344 |
SHA1: | 0F939BF3932DA5C2AC223F34651FF089D0E7AD31 |
SHA-256: | 2919BEEC467C57F525655F3AA0DBD0ADA48687A406686B9B7E65000FEBC78E63 |
SHA-512: | 15720B18BA5A8DF103E6802442388461771CD7E33C487563BD01CE33302F7B195B915FD89422C2154525025F92C441C80F413A95916AB728ADB0926503644463 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.7665941734906774 |
Encrypted: | false |
SSDEEP: | 48:7MfJioyVPioyDoy1C7oy16oy1ZKOioy1noy1AYoy1Wioy1oioykioyBoy1noy1Oa:7IJuPd0XjBikb9IVXEBodRBkE |
MD5: | D95F960DB18BD637FC7EAD10E26D8361 |
SHA1: | 810A1700262CC719E5236B0AC1C7EFEE1212EA0E |
SHA-256: | 7C85CC24D7B68267835F5F44CE0DF8246EE228CDD6D870B35CEFD2F70BF04763 |
SHA-512: | 776488738B1235F56635FCB3EDA55268A5CF71CB2725A709B405A25E1F1FD18A933CFC79BB3B3E35DC7BF86DCA815F22D80946522986D55C9982797F0EB830A8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 893 |
Entropy (8bit): | 7.366016576663508 |
Encrypted: | false |
SSDEEP: | 24:hBntmDvKUQQDvKUr7C5fpqp8gPvXHmXvponXux:3ntmD5QQD5XC5RqHHXmXvp++x |
MD5: | D4AE187B4574036C2D76B6DF8A8C1A30 |
SHA1: | B06F409FA14BAB33CBAF4A37811B8740B624D9E5 |
SHA-256: | A2CE3A0FA7D2A833D1801E01EC48E35B70D84F3467CC9F8FAB370386E13879C7 |
SHA-512: | 1F44A360E8BB8ADA22BC5BFE001F1BABB4E72005A46BC2A94C33C4BD149FF256CCE6F35D65CA4F7FC2A5B9E15494155449830D2809C8CF218D0B9196EC646B0C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.241800306278292 |
Encrypted: | false |
SSDEEP: | 6:kKo9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:LDImsLNkPlE99SNxAhUe/3 |
MD5: | 97366CFA55357B4AA6A18A20B7CA05CE |
SHA1: | 8C93F4EDD4198CCE78AE2984A033606D3C316654 |
SHA-256: | C90084E0CA19B12B6B39DCEC5F506AE9C1ECBA81C790046EF648D2C585400A42 |
SHA-512: | BE7751104C292D00D125FFE83BB5EBFC5150299834E9412D4ED0D3E89E47C9D381BD666077EF014DDB2C0EF78CE7C2FCA19517DF2B011B98EF870CF990CEF588 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 252 |
Entropy (8bit): | 3.018927670754178 |
Encrypted: | false |
SSDEEP: | 3:kkFkl0w31fllXlE/E/KRkzllPlzRkwWBARLNDU+ZMlKlBkvclcMlVHblB8V7lnka:kKuxliBAIdQZV7I7kc3 |
MD5: | 6ED2E4851B4C10EED664F9006ADD0903 |
SHA1: | 39D311F1AF043599D5B4305181CC111A3E4155D2 |
SHA-256: | AF5C789DC37F48895E61B8CAE0649E5F80BBF6FCCF707F5069BDB4926E16480D |
SHA-512: | 72779B6E0CDAB250D0D5196A9628B7DB0624C8450DCCDBB0BBBB24EE973232B2A724AD9F69E708D55A106ADE217E364C77BC6EE36BA7E0CA31292068B0EAF5EC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | 1536:JsVoWFMWQNk1KUQII5J5lZRT95tFiQibVJDS+Stu/3IVQBrp3Mv9df0CXLhNHqTM:bViyFXE07ZmandGCyN2mM7IgOP0gC |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | 1536:JsVoWFMWQNk1KUQII5J5lZRT95tFiQibVJDS+Stu/3IVQBrp3Mv9df0CXLhNHqTM:bViyFXE07ZmandGCyN2mM7IgOP0gC |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.341249681261484 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJM3g98kUwPeUkwRe9:YvXKXFoxxjx6mk3kGMbLUkee9 |
MD5: | 95EEE892BD13E1ADFA2FC407D3908201 |
SHA1: | 2B4AFE1EA904ED29C84C7674BD955C552CF3677A |
SHA-256: | B7F1407B686948163630324A0E9C0FA763EC92717963379941ED03C98C39A790 |
SHA-512: | 406442929A30A3F93EFD323236F96BD6DE5DE9495C1684847198A01AA375DBD1B9D137B0298CDE534EF1244B52647E929531BAFADA2B1B90F9567B64F7364DE0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.286636331732146 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJfBoTfXpnrPeUkwRe9:YvXKXFoxxjx6mk3kGWTfXcUkee9 |
MD5: | 6B07FA7F1F5ED38CBC9847D364974A68 |
SHA1: | AE667EA874AA83699E672911B28336E0F441164D |
SHA-256: | 1494B0DC2A658ADC659A7DFAF6A9390FF60980D34734335FF38708768210176F |
SHA-512: | 3CB3C7A215579FA6A7904CB9B10CFBA8138D7F39401C443C5E28A23BDB149D5D86CC28DC3AE2A16BF8D3C2A1A7BEA428EBDE946590183421F502644EB22F08C2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.265631367127222 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJfBD2G6UpnrPeUkwRe9:YvXKXFoxxjx6mk3kGR22cUkee9 |
MD5: | F1C92082A5E44E10D726979C069CF824 |
SHA1: | 5822C79601A3AC32DDF918E8D84C7F3FE2F65C19 |
SHA-256: | 8D719982DFBA8994851612245F0DCBF938B531F06FDA734F65417FF7C7B33A15 |
SHA-512: | 481951C3E2CE655C72DCE42F5D6E9858D66D473F76B835992E812D18CC36A68965014DD0F7369575F615149F816936455370842BDA7ED50A034A10B0EB16C4B4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.326570245549348 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJfPmwrPeUkwRe9:YvXKXFoxxjx6mk3kGH56Ukee9 |
MD5: | 7F7C971C7516B330C68E543E2831F1A3 |
SHA1: | C3F22D21E6B35BF6EDCE8FD1AFAB3B13CF68E1E8 |
SHA-256: | 3316881B222B60B1FB43A716AD8E410762D90A34CC445592F011254E18DF40FA |
SHA-512: | F344CEF0B1B54E6C97DB4D35B5483E97B1881A1D4781CE4606EC4C8E0896C928D81E464CEBAF4CF64A574D0D5CB047E316BD51FA34C2FFC8D808E0B07D31AC9B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.287118867437206 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJfJWCtMdPeUkwRe9:YvXKXFoxxjx6mk3kGBS8Ukee9 |
MD5: | D68F243708AB9D263D3CF15A0F63A0C7 |
SHA1: | A304386BDED772679033A7CF1BADD0F3892205DC |
SHA-256: | A6323BF5C59EBA52472A4EACCC7A73E92D185A25818C86D6D181C8794B1FE48D |
SHA-512: | 9837483216A34F980F98D424C7E5F79B71FFE5D9F1AE6910A8AB53646C6E5952A1B9F952EBD00456EB89F52B9A8098C6227874CEF214FAA5DB31B7FD77496C0E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.273642170814053 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJf8dPeUkwRe9:YvXKXFoxxjx6mk3kGU8Ukee9 |
MD5: | 2C5EBD3C873B4614B1FD208C9C5D752E |
SHA1: | 4FF631EBD240DC15DB1495C9A327060D4CCA4DC8 |
SHA-256: | 9DE18D0113FC817706EEC9F3FEC6902C561451ACCEE78AB1D722F88094C7493B |
SHA-512: | 9655BAE6E3222065DCD2ED8A459A69FF2DCCB8C2BB634BD4881F6D387CB7710B3043250EEB9F35563D7C2E77657246834DB8CE4A9E77CE96CDDDDF26A0FF1EBA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.2754517959709055 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJfQ1rPeUkwRe9:YvXKXFoxxjx6mk3kGY16Ukee9 |
MD5: | 01A9D2E9474FEAEE530CE0B5B5458E64 |
SHA1: | 61FE1635192E23E479A01F8CF450B5115DEE9AA1 |
SHA-256: | 9BCB64FD83DDF8DE172C8239CD674DAD1F8D0A0CA8912A458F1110A4FA280904 |
SHA-512: | 0F89A9DEE42C345D1B9C2728C93CFD5FE07484E26B7CD2E5E52C38BDD205E7FED98B09CE8D1175D2B5F0894830CF3E721C746DBF417F7FCB28B2EA2045EC67C5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.28151936397677 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJfFldPeUkwRe9:YvXKXFoxxjx6mk3kGz8Ukee9 |
MD5: | 82D52CDC3A9140D255D9CCA26E36B305 |
SHA1: | 5EF71F638DBF0448A97BCF93B47B324D9642A009 |
SHA-256: | AB9571AB94DFE4B1189F07353E8F93895C3C76888DD7C7777B801BBB3E2EAB63 |
SHA-512: | 3B8D3D910D8FB7CB8632C55AF8B634FEA50AC638A863DA4ADB2338BCB1C5243F0EE8412B911148D691059A22B874A4071AB095F7792FD5C9C93A4B6A1F4AB444 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1372 |
Entropy (8bit): | 5.735050671946279 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xwxd6HMKLgENRcbrZbq00iCCBrwJo++ns8ct4mFJN9r:Yv9x8sEgigrNt0wSJn+ns8cvFJvr |
MD5: | 36D1CF4831AD5AC7B25FF4C331B878FF |
SHA1: | 00706E7E3E559A420E157A30C9630A12AA8F40E2 |
SHA-256: | B751DE6AE66B096D92D612313542D8EC533409FEFD42CB7A2FDACD1C271F512B |
SHA-512: | 07401C3F5DFD18BA961B7CCEB9A6616C8DE5605D5863E65B179EFBF3C972C45F353B2EAA309FBB4CC810669C167CB9556AF751DBDA369E77FF19B6AEEA168147 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.280058452197058 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJfYdPeUkwRe9:YvXKXFoxxjx6mk3kGg8Ukee9 |
MD5: | 4574C665E56ED3554D5211C0972CC6C5 |
SHA1: | 32C04D0EDA695E1C2911469B950A4E8D7D56960D |
SHA-256: | 5C9CA4185C1172FB4140317B122CB1CB07C3F886BC8369C450070D5E405FFC90 |
SHA-512: | D3C926C6AA65FB5238D03AB86B1837A7F12C1F51DD69EF12C7E429AA213A3F90BEDE5FD06E8F78DAD4B487208382C41A456D452025A45D4764E2B9D86E8716CC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1395 |
Entropy (8bit): | 5.77215330255997 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xwxd6HDrLgEGOc93W2JeFmaR7CQzttgBcu141CjrWpHfRzVCV9FJNlr:Yv9x8jHgDv3W2aYQfgB5OUupHrQ9FJ7r |
MD5: | DE392F682A0980741B8FA51145FFEB63 |
SHA1: | 0B1878FAD601B244B4B80AE39CAC52B1C6D266D7 |
SHA-256: | 815581352BD4137E09A91725C1BEA477FBF59458730E439585E655A206A3B676 |
SHA-512: | E464F0901BE5F34C1E4A260A81EA62D5BC41A241038CAD28C337AD562C9916465DB121CECCD3EC178774AD1EB24C0E04DE98E60EB7636E06B66D506208E1E76F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.263742605182283 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJfbPtdPeUkwRe9:YvXKXFoxxjx6mk3kGDV8Ukee9 |
MD5: | D0BC260DE4A3FD407E57D9826A05E188 |
SHA1: | D1F3C84607F0CFD15ADA5E59498000F897F91DF1 |
SHA-256: | 22B532C8051A2DE93F566FDFB94FA13BCEFDAB168E206802A34EC0ABF5DBDF67 |
SHA-512: | BC14FE3DA890AA198EE568299C452C572A2C7F8ED8A18BAB6176B3F579F718D21B13258971797AF38D56ADB93066B335D15D27398DD21FBFC30705CBC1B63B75 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.265715080417709 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJf21rPeUkwRe9:YvXKXFoxxjx6mk3kG+16Ukee9 |
MD5: | 12706DF1F5A5CFE7F621356448877A22 |
SHA1: | 57986D531D91A3E559CFFF4B4110759A54B5ADBE |
SHA-256: | D95F2956CB7ACFA320286057BB160790542F87F3AE2E29E123FDA128721DFF35 |
SHA-512: | E63E200C8E384117B3BC1CBC1C0990AE7CD54CFAFC88FD07BEA61A42FB103EEDC1BA285F126C429AB59AC78C0C21EEDA204DB9E4E9E2E7FDEB9068F667615C7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.286893580955206 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJfbpatdPeUkwRe9:YvXKXFoxxjx6mk3kGVat8Ukee9 |
MD5: | 7F292E053BE8310480CB5397CAE4569A |
SHA1: | 40B23612058CBF676BE9273EE362C0861B6B61E8 |
SHA-256: | 6768679424A8C87C4C5393FC20A1EAFC1DF8624AF312BE9091FE7A98031FC369 |
SHA-512: | AB3E198164D2445D446FC9087BA0FF914F327BAD636BDB31B10B283A4BB8C7BE91FB13E51B9F133F25C4651ED29BF6CF513C89C6AB0921608EA704B103669CDD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.239132758867432 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXFWf+sV/jx6mJ0YOX3ceoAvJfshHHrPeUkwRe9:YvXKXFoxxjx6mk3kGUUUkee9 |
MD5: | 066DDBE25BEA0D568258100FBBBAC6C1 |
SHA1: | 6B917AE432D1357347570142842CB20D47AEA18F |
SHA-256: | 8EB27C88AAB61BA7F02B427334284567AC20BB927CFB3B08DE65BB059C8FC887 |
SHA-512: | FEC748C5B3333809C8E01E630FCC49CC045B689D309839DAEDC6042282ED7788266CFF38E0B8D4A4CE03EA013949A1711D2AA5A3AE6637102D76DF1AA529B78F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 782 |
Entropy (8bit): | 5.362060573982161 |
Encrypted: | false |
SSDEEP: | 12:YvXKXFoxxjx6mk3kGTq16Ukee1+3CEJ1KXd15kcyKMQo7P70c0WM6ZB/uhWpYS:Yv6Xwxd6Ha168CgEXX5kcIfANhAr |
MD5: | 4BB92359A91BFAA648DF3AC39B09BB0B |
SHA1: | 9542838BB304E6A14DAD2501CDB601674D8DA5FB |
SHA-256: | C8EC322A7528C5E0C6C98AB0E006CDF44488C0B5F94715C4B594459A15F506E2 |
SHA-512: | 06B46D346A6710FEABAA50C15EE5F3138CA7C5CFBB36288546A011C18F40AB31765F3A5DCEFAAA3F21F169A4D6DA64D4C48E182216191564DA157E2305E2627C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.11171229560097 |
Encrypted: | false |
SSDEEP: | 48:Y5irPp5ActRgcbv3lGqdwabB5Zx6Ajw/jnz12X9taG/:tAAg8v1X5Lfgz+x |
MD5: | 34524995DEBF37DF3E67B8BA73E79EAE |
SHA1: | 6C2B1DCE221BFF30407D4E65F95971AEAF61A316 |
SHA-256: | 6300A68F3A45ACB4EC9892F15C6ABCF66BF5A71D8701894265A60C2F9B2E51AE |
SHA-512: | 62DCAF805BC7184C5F3085FDCAEEAAB855AAE8F3CE1A515E6B7A90CD1B96E417AE1CD2D7E582907E663FCE665AED9109F0A2F33A38EA059480789E27D40243D5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3570997345394584 |
Encrypted: | false |
SSDEEP: | 48:TVl2GL7msncRVbjVpOV6cV6+VZeVZvVZCVZW/Vk/Vhjv2ubCs22Lb5BvPX:vVmssZnrF4tf |
MD5: | 557EDFF9D71C8A931984CBC9D772417A |
SHA1: | F1E65069DF4544A13E4DD5110145543A2C55A57D |
SHA-256: | B662C59C1BB6D0ECCAC6BB0381F631B993B1087E955E425435AAAF195A259EC5 |
SHA-512: | FDACDA1E415437E7098759BAA94AD8EDAE29A1F2F791DFFE584D451C238066D74311E602E98A7E3959C9470273A771E9D58785048D7F20C85374FDB51FB8D48A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.8298028706964506 |
Encrypted: | false |
SSDEEP: | 48:7MgWcRVbjVpOV6cV6+VZeVZvVZCVZW/Vk/Vhjv2ubCs22LaBvPxcTqll2GL7msY:7VZnrFrtaqVmsY |
MD5: | 9C39704FAAE976E1CCE31B1A15DDDA3C |
SHA1: | FE850A584F176034B79887F142CAB9443B97F52F |
SHA-256: | 5C7321EAFC526DEF28CE6AA561E0F4EFB8D7D4994AC5ECFD1B9DDDB664450AC5 |
SHA-512: | 051504F4D57E9C3EA4AD91DCAEFFD478741747C2504DE5CB688F1FC0392C10FF93C7A9171768BB070EC3F2278EC7B8FE29656FFB9587888AD45181DE735BE0DC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5309417490522437 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K82AawClUnH:Qw946cPbiOxDlbYnuRKXArH |
MD5: | 7309030769A0A67AEF849986666511A5 |
SHA1: | 35C6E2C5BE5DF1F221F1AE2ABAC3FA90D3FFFE8F |
SHA-256: | 3AAB1800FA5B7BE43331B302E23C6C8D7F85C9E32716A393C8C2608A6C07D468 |
SHA-512: | 0DA2AF6D28497A004A3DEF4336C2C61C8E81227E7E526566EE5B1F6CD7D73ADD033A0D2AAA69E30796C7505C8AE9D6700AEFCD440264365EBC8C950E1B7BC013 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-07-03 15-08-46-785.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.359827924713262 |
Encrypted: | false |
SSDEEP: | 384:yNDmLJAZYTtvEcrd/GVMimVRMTzpCeb9sJVPbvHktuFKr4Bnk2DfNSNq8iwyhZ9u:bAPaRH9E3/ |
MD5: | 06DEAEDB81D09FD8FB5FF668D8E09CB2 |
SHA1: | 28A02BCBD5975117B97A08AFB049F2C94F334726 |
SHA-256: | D98DE785425112A2D7A41B16073812FA4FA4955F2D5139AE87C9A5FBC4717D64 |
SHA-512: | 948E3B56E5A8D818A5FE9D74B82A898F7264909ADF2C49E5D096CB90F4D28ED95990545A4857933F0E06D493AA0F6D41F6109C74B44BC0E4B84346B519681936 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15090 |
Entropy (8bit): | 5.363305827815339 |
Encrypted: | false |
SSDEEP: | 384:ZWULsy9/tm31rSGTOkmr0yba+RQrm99/rcie4a5/H3eHJjmj7E/ApmpIRpnkP2eF:t6m |
MD5: | 6E4741F5D96DD1EDA6BD3E0AFCB7FEB7 |
SHA1: | 562D3F9870896167B4D67EBD731B73C95636B2AE |
SHA-256: | 938C1BE056E378AEB3F5DF0CD2819FE54DCE92ABE26968F09DAE68E475E3E577 |
SHA-512: | 3777C13E592721A73E9DDC38FCB0E7300E361AFD5495E445A3BD8F957DDFB7BF5BF6743EC407F0C7EDF117EEE9E4C11556C60B669F0AF0A39F68EADCBA6AB712 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.424573981635283 |
Encrypted: | false |
SSDEEP: | 192:fcbmI6ccb9cb+IqccbdcbIIl3cbXcbWIS+cb4cbIIJzcbWcbAIXRcbh:g6sqGlVS/JgXu |
MD5: | 18E40BB8288BF3E4F7FAAED5938A4F6D |
SHA1: | E3704378D91C4D703D3684C6F0EB92AE8586533D |
SHA-256: | C9627A20D4056565B87065706A1D75A88A21E178A81EE14F0AF366BC87B420B7 |
SHA-512: | C2E81F391996426BA276E1FBF7B7013B8C10DFED43EE8EBA0FD45460953F9F943F2AC503C3C1DB8FDADB00F732895EFD1A2AE2827F149DE384DCD2DD77FABFBD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7ouWLGwYIGNPMGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVuWLGwZGuGZn3mlind9i4ufFXpAXkru |
MD5: | 0E1580362291AD21A1D725FA761C79B6 |
SHA1: | C7F4D713FE4C54F61F1A49E50157466B02540C19 |
SHA-256: | 76239186C62B735AC3954CE66A2A216AA2D703A4AAF29F2C50CE1C2A8679E647 |
SHA-512: | 52BECFE8086D70C8F1B2F52551E43BE17F3238BB771D91C2B267EC7DDE1DB830FC612A021E0C491C283D61E05C4B5EF191B23D41EBAF2AC36712F6B0C4D15785 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZ7wYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs03WLaGZw |
MD5: | 8B9FA2EC5118087D19CFDB20DA7C4C26 |
SHA1: | E32D6A1829B18717EF1455B73E88D36E0410EF93 |
SHA-256: | 4782624EA3A4B3C6EB782689208148B636365AA8E5DAF00814FA9AB722259CBD |
SHA-512: | 662F8664CC3F4E8356D5F5794074642DB65565D40AC9FEA323E16E84EBD4F961701460A1310CC863D1AB38849E84E2142382F5DB88A0E53F97FF66248230F7B9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 543911 |
Entropy (8bit): | 7.977303608379539 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121STJJJJv+9UZ+bvH01ybxrr/IxkB1mabFhOXZ/fEa+Q:O3Pjegf1210JJJJm94+oMNB1DofjR |
MD5: | 956BEC2EB32005025184F904D9622D32 |
SHA1: | C6A9A8B3F7A7AB8122FB00457C0F83D4A77F21AF |
SHA-256: | DEFD4ADB96BA87467278B6B06980FDAB1EE460D971B62ED05A89FF32983784EF |
SHA-512: | 3A32B169312E5886D8C3029BF15AD291C41AF9FB03AE7D9B1A3CAB74E95C7AAAF3E384F2432BDB8F815075B11F30D4FF083271802B41616C9060E268EB3B5D3D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121D1ybxrr/IxkB1mabFhOXZ/fEa+bSWBlkipdjuGTJJJJv+9U0:O3Pjegf121DMNB1Dofj0S8lkipdj/JJg |
MD5: | 410BB1A54ECCE470696636D4C2000E33 |
SHA1: | 53A6AC06832DAA17D7C006C0A9B8B30597701926 |
SHA-256: | 8B6D42D70862D6623F66B09F6819A35E1AF4ACC409461E140DA020F386877F92 |
SHA-512: | 1A46EDB52F5785C7B9D1FF702CC62764BFDD3EDA5848740B00751E7F4C3AE7C691E88A26B1AE7F5213242887846BEC92C02C744B43046E7414F4D6B85E0E5913 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.755217322942899 |
TrID: |
|
File name: | REGISTERED NY LIEN JUDGMENT 3 FILED.pdf |
File size: | 83'103'267 bytes |
MD5: | 3d1421e74c45d30d1861983288f509d6 |
SHA1: | ae031b7c4a69f2b338b70df155c31133f48e1272 |
SHA256: | f7ae91286f594920119d821e62cfae146e942f8a22495ee18777ce945d0af8c0 |
SHA512: | c1cf6c531477bdfcc8f28f14c02ab7a5c973cdca2a498a363c2e9c613b6b7b68a0ab2f1909b552ae88db786d44a66dccece93d8f57233d1de89452e082f4aa7a |
SSDEEP: | 1572864:7N1l6LERn7hiHarRfYDE8rHRp0uRphGc1elAjM4/Zb6YKC0GY5eriwHm:7NeEZhiGRsE8DXhnh5dp6MfY5+rG |
TLSH: | E508ABEF9FCD40BA4D868370FD11458E9BBD49589AF85790007B503FA88695CB2EE87C |
File Content Preview: | %PDF-2.0.%.....1124 0 obj<</Linearized 1/L 83103267/O 1127/E 485011/N 138/T 83099941/H [ 691 570]>>.endobj. .1125 0 obj<</ID[<0943564B84B30E0B9DECDEA |
Icon Hash: | 62cc8caeb29e8ae0 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 3, 2024 21:08:49.637758970 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:49.637798071 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:49.637870073 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:49.638106108 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:49.638118982 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.261478901 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.261871099 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.261897087 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.262773037 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.262840033 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.262847900 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.262886047 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.291712046 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.291821957 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.291975975 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.291986942 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.345827103 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.623157024 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.623274088 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.623343945 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.624980927 CEST | 49707 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.624998093 CEST | 443 | 49707 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.626562119 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.626580954 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:50.626646042 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.626847982 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:50.626864910 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.223222017 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.223777056 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:51.223808050 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.227152109 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.227250099 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:51.227261066 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.229536057 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:51.229690075 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:51.229747057 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.229967117 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:51.229983091 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.282849073 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:51.472475052 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.472560883 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.472635031 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:51.472665071 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.472702980 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:51.472737074 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:51.472805023 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:51.474390984 CEST | 49709 | 443 | 192.168.2.17 | 52.6.155.20 |
Jul 3, 2024 21:08:51.474406958 CEST | 443 | 49709 | 52.6.155.20 | 192.168.2.17 |
Jul 3, 2024 21:08:53.491899967 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:53.491954088 CEST | 443 | 49713 | 23.47.168.24 | 192.168.2.17 |
Jul 3, 2024 21:08:53.492145061 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:53.492301941 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:53.492317915 CEST | 443 | 49713 | 23.47.168.24 | 192.168.2.17 |
Jul 3, 2024 21:08:54.141747952 CEST | 443 | 49713 | 23.47.168.24 | 192.168.2.17 |
Jul 3, 2024 21:08:54.142085075 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:54.142118931 CEST | 443 | 49713 | 23.47.168.24 | 192.168.2.17 |
Jul 3, 2024 21:08:54.143603086 CEST | 443 | 49713 | 23.47.168.24 | 192.168.2.17 |
Jul 3, 2024 21:08:54.143683910 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:54.202785015 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:54.202985048 CEST | 443 | 49713 | 23.47.168.24 | 192.168.2.17 |
Jul 3, 2024 21:08:54.203027010 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:54.244081974 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:54.244096041 CEST | 443 | 49713 | 23.47.168.24 | 192.168.2.17 |
Jul 3, 2024 21:08:54.291918039 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:54.309082031 CEST | 443 | 49713 | 23.47.168.24 | 192.168.2.17 |
Jul 3, 2024 21:08:54.309236050 CEST | 443 | 49713 | 23.47.168.24 | 192.168.2.17 |
Jul 3, 2024 21:08:54.309381008 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:54.309726954 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:54.309726954 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Jul 3, 2024 21:08:54.309755087 CEST | 443 | 49713 | 23.47.168.24 | 192.168.2.17 |
Jul 3, 2024 21:08:54.310702085 CEST | 49713 | 443 | 192.168.2.17 | 23.47.168.24 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 3, 2024 21:09:02.912003994 CEST | 53 | 55227 | 162.159.36.2 | 192.168.2.17 |
Jul 3, 2024 21:09:03.479067087 CEST | 65462 | 53 | 192.168.2.17 | 1.1.1.1 |
Jul 3, 2024 21:09:03.486974001 CEST | 53 | 65462 | 1.1.1.1 | 192.168.2.17 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jul 3, 2024 21:09:03.479067087 CEST | 192.168.2.17 | 1.1.1.1 | 0xbc9b | Standard query (0) | PTR (Pointer record) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jul 3, 2024 21:08:48.366347075 CEST | 1.1.1.1 | 192.168.2.17 | 0x308d | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 21:08:48.366347075 CEST | 1.1.1.1 | 192.168.2.17 | 0x308d | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 21:09:03.486974001 CEST | 1.1.1.1 | 192.168.2.17 | 0xbc9b | Name error (3) | none | none | PTR (Pointer record) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.17 | 49707 | 52.6.155.20 | 443 | 6444 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 19:08:50 UTC | 1353 | OUT | |
2024-07-03 19:08:50 UTC | 569 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.17 | 49709 | 52.6.155.20 | 443 | 6444 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 19:08:51 UTC | 1473 | OUT | |
2024-07-03 19:08:51 UTC | 605 | IN | |
2024-07-03 19:08:51 UTC | 3120 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.17 | 49713 | 23.47.168.24 | 443 | 6444 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 19:08:54 UTC | 475 | OUT | |
2024-07-03 19:08:54 UTC | 198 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 15:08:39 |
Start date: | 03/07/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75d550000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | false |
Target ID: | 2 |
Start time: | 15:08:40 |
Start date: | 03/07/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7678d0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | false |
Target ID: | 3 |
Start time: | 15:08:41 |
Start date: | 03/07/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7678d0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | false |