Windows
Analysis Report
GWKBOHZU0T6TSY8WB9DBB.pdf
Overview
General Information
Detection
Score: | 20 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
Acrobat.exe (PID: 7580 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\G WKBOHZU0T6 TSY8WB9DBB .pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) AcroCEF.exe (PID: 7784 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) AcroCEF.exe (PID: 8000 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 60 --field -trial-han dle=1728,i ,111059282 0136462837 6,14060171 1696907953 00,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Persistence and Installation Behavior |
---|
Source: | LLM: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1469340 |
Start date and time: | 2024-07-08 19:40:48 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 21s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | GWKBOHZU0T6TSY8WB9DBB.pdf |
Detection: | SUS |
Classification: | sus20.winPDF@14/47@0/0 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 3.233.129.217, 52.22.41.97, 3.219.243.226, 52.6.155.20, 172.64.41.3, 162.159.61.3, 2.19.126.143, 2.19.126.149, 2.16.202.123, 95.101.54.195, 88.221.168.141, 2.16.100.168, 88.221.110.91
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, identrust.edgesuite.net, slscr.update.microsoft.com, acroipm2.adobe.com.edgesuite.net, e4578.dscb.akamaiedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, a767.dspw65.akamai.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, a1952.dscq.akamai.net, ssl.adobe.com.edgekey.net, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, apps.identrust.com, wu-b-net.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: GWKBOHZU0T6TSY8WB9DBB.pdf
Time | Type | Description |
---|---|---|
13:42:02 | API Interceptor |
Input | Output |
---|---|
URL: PDF Model: gpt-4o | ```json{ "riskscore": 8, "reasons": "The PDF document contains several elements that are indicative of a phishing attempt. Firstly, there is a visually prominent phone number (+1 (818) 627-0063) highlighted in red, which could mislead the user into calling a potentially harmful number. The text in the document creates a sense of urgency by stating that the user's subscription is set to renew today and that $498.98 will be debited from their account within the next 24 hours. It further urges the user to contact the billing department immediately if they believe the transaction is unauthorized. This sense of urgency is directly connected to the prominent phone number. Additionally, the document impersonates a well-known brand, Geek Squad, which adds to its credibility and potential to deceive the user. The combination of these factors significantly increases the risk of phishing."} |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
bg.microsoft.map.fastly.net | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, Tycoon2FA | Browse |
| ||
Get hash | malicious | HTMLPhisher, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PXRECVOWEIWOEI Stealer | Browse |
| ||
Get hash | malicious | Tycoon2FA | Browse |
| ||
Get hash | malicious | Tycoon2FA | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.227989257031783 |
Encrypted: | false |
SSDEEP: | 6:BOuJ+q2PFi2nKuAl9OmbnIFUt84OuxsXZmw+4Ouxs3VkwOFi2nKuAl9OmbjLJ:EuEvdZHAahFUt81uu/+1uC5wZHAaSJ |
MD5: | EFBB26C747A0A51922DE638F63182EC3 |
SHA1: | EE148D480BD0CDFC54FCBFF3B7DDE12D025DCBF4 |
SHA-256: | E568DD568F8E833C21D37974E7261193C93BE15B0F782CD9746AA295E5A8121E |
SHA-512: | 98ED77EB6FC000434C6FFF577729AC07F86342382FEEF65C70BBF496703D2CD483970CF9619C5B58128A5249C491EDD0449B23A237659F3D37EA5F1909C24432 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.227989257031783 |
Encrypted: | false |
SSDEEP: | 6:BOuJ+q2PFi2nKuAl9OmbnIFUt84OuxsXZmw+4Ouxs3VkwOFi2nKuAl9OmbjLJ:EuEvdZHAahFUt81uu/+1uC5wZHAaSJ |
MD5: | EFBB26C747A0A51922DE638F63182EC3 |
SHA1: | EE148D480BD0CDFC54FCBFF3B7DDE12D025DCBF4 |
SHA-256: | E568DD568F8E833C21D37974E7261193C93BE15B0F782CD9746AA295E5A8121E |
SHA-512: | 98ED77EB6FC000434C6FFF577729AC07F86342382FEEF65C70BBF496703D2CD483970CF9619C5B58128A5249C491EDD0449B23A237659F3D37EA5F1909C24432 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.230406663714335 |
Encrypted: | false |
SSDEEP: | 6:BOuq4q2PFi2nKuAl9Ombzo2jMGIFUt84OuB0JZmw+4OuvLDkwOFi2nKuAl9Ombzz:EuJvdZHAa8uFUt81uo/+1uX5wZHAa8RJ |
MD5: | 822771068A9E907655F284FC83DDE8A1 |
SHA1: | DC119054D24DB8C3E44B900D9F2D426525E33DAC |
SHA-256: | B5A90F1508B74E7A4657FA168CB020CCEAEB41253C103F801433026F22E16982 |
SHA-512: | 3D2FE5B023AC6C3B5C12A9AB6431611D1007CE51F02C51858406A36B29EE38707B0F9CA9A8BCAF90104FB92DDA7E29CB1077CA6B51E66E9F387348655254EE4E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.230406663714335 |
Encrypted: | false |
SSDEEP: | 6:BOuq4q2PFi2nKuAl9Ombzo2jMGIFUt84OuB0JZmw+4OuvLDkwOFi2nKuAl9Ombzz:EuJvdZHAa8uFUt81uo/+1uX5wZHAa8RJ |
MD5: | 822771068A9E907655F284FC83DDE8A1 |
SHA1: | DC119054D24DB8C3E44B900D9F2D426525E33DAC |
SHA-256: | B5A90F1508B74E7A4657FA168CB020CCEAEB41253C103F801433026F22E16982 |
SHA-512: | 3D2FE5B023AC6C3B5C12A9AB6431611D1007CE51F02C51858406A36B29EE38707B0F9CA9A8BCAF90104FB92DDA7E29CB1077CA6B51E66E9F387348655254EE4E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 476 |
Entropy (8bit): | 4.969303435619907 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqEhsBdOg2HZTQWgcaq3QYiubpP7E4T3y:Y2sRdsvydMHiWL3QYhbd7nby |
MD5: | AC8CA8D81B4814952B0E386E15715ED0 |
SHA1: | 41EF927AC6CAA61A6DAFD0B902379D7339DF999C |
SHA-256: | 1582C5AEAC4EBA594CCDBAFCA6029A995AA97523B414D0B88C4AF75753794E07 |
SHA-512: | 513A83AA3CA61CB2ABF4FF6004D02E4F67D32A28647E3B33A17555FAB0FF04258099B9574C119BF157FEF3B28C9AB4DCE03ECB801259B322DD0D6CF2B0AEAF39 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\f9bc1b37-e01c-41d1-8083-e5209c5ce876.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 476 |
Entropy (8bit): | 4.969303435619907 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqEhsBdOg2HZTQWgcaq3QYiubpP7E4T3y:Y2sRdsvydMHiWL3QYhbd7nby |
MD5: | AC8CA8D81B4814952B0E386E15715ED0 |
SHA1: | 41EF927AC6CAA61A6DAFD0B902379D7339DF999C |
SHA-256: | 1582C5AEAC4EBA594CCDBAFCA6029A995AA97523B414D0B88C4AF75753794E07 |
SHA-512: | 513A83AA3CA61CB2ABF4FF6004D02E4F67D32A28647E3B33A17555FAB0FF04258099B9574C119BF157FEF3B28C9AB4DCE03ECB801259B322DD0D6CF2B0AEAF39 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4288 |
Entropy (8bit): | 5.224599149936381 |
Encrypted: | false |
SSDEEP: | 96:wshFT0h7cA4YC2EVPCqY35NEmNOYcGPtqKYSEVlYdBGsZ:wshFT0h7cZb2EVKZPEANcGIK5EVlYdB/ |
MD5: | D6432F4E709507BEAFFE5F34B8DE9693 |
SHA1: | 04BDB3E531C090008B5DA5D5A058FA8745301B7E |
SHA-256: | E0D09D1BF240D09890B30E3C9CAF14BCF70FF3B76B98E8B26E015C48C8C014F4 |
SHA-512: | 59BB114D7D115245E8B6AD7D61915DC4C3A85D29A762888CDADF2CE3F83F74D9956F4AE7817AE616A7ECD34401D8DBF683CED8EBE5947B333F0E38AFEB10F22C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.231185294338081 |
Encrypted: | false |
SSDEEP: | 6:BOubdRN4q2PFi2nKuAl9OmbzNMxIFUt84OuPcLJZmw+4OurDkwOFi2nKuAl9Ombg:EubavdZHAa8jFUt81uk/+1uv5wZHAa8E |
MD5: | FCC5BFC91840359C4C0F5DD003B6AB40 |
SHA1: | 4787D6352BC60DD33333960D80A745DA4BC6B71C |
SHA-256: | F1991C8193F5B301F014FBDAD01BEA9BE70B92531437A78A2B7F17398D0D038F |
SHA-512: | EF9EC40047502857EA353AFD100B2F1E17C7DFC289A28AEDAC157174FCE0197504D7391BC52CF15640CCD8AD220F406B48B456D6F31929ABDB4C93438C52222B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.231185294338081 |
Encrypted: | false |
SSDEEP: | 6:BOubdRN4q2PFi2nKuAl9OmbzNMxIFUt84OuPcLJZmw+4OurDkwOFi2nKuAl9Ombg:EubavdZHAa8jFUt81uk/+1uv5wZHAa8E |
MD5: | FCC5BFC91840359C4C0F5DD003B6AB40 |
SHA1: | 4787D6352BC60DD33333960D80A745DA4BC6B71C |
SHA-256: | F1991C8193F5B301F014FBDAD01BEA9BE70B92531437A78A2B7F17398D0D038F |
SHA-512: | EF9EC40047502857EA353AFD100B2F1E17C7DFC289A28AEDAC157174FCE0197504D7391BC52CF15640CCD8AD220F406B48B456D6F31929ABDB4C93438C52222B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-240708174155Z-192.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 56598 |
Entropy (8bit): | 3.0932168438645236 |
Encrypted: | false |
SSDEEP: | 384:XwrQQdyE3HDbGIc8T2dD6oyGyj+5A2e7C:XgDdBpCjyjh2 |
MD5: | A8630ABA338BCDD576DEE1594580BA91 |
SHA1: | C45F4B43A6016162C2C113BAA3BB373C0A2EC259 |
SHA-256: | 6E92D902FB0284528EE7F9061FD743E82A43B042C4E1F83D432D27294A43CB89 |
SHA-512: | BBBF7A7EC2AB978F55070720F2BF718C5B627BD97BEFA5332D024B9C2E3B7FC184DE00D69A474261E9ECB2B8BA0296B045F3062B56E535A4B91D811947DA910F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438775537553053 |
Encrypted: | false |
SSDEEP: | 384:yejci5GZiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:01urVgazUpUTTGt |
MD5: | 93A42F49927B51CE0772C95064100866 |
SHA1: | 86E0C9AC4F69E88D0B2322ADA04190E49AA6BDF6 |
SHA-256: | 4F4093453FCFE515B028ADC1BEB4BE938E812ED8067BEC9A3EDC5FF33C19E1BA |
SHA-512: | D3D87F2E633FC03AE54FFC172F0D243877537DFFC769E8906B31CFA8E30BCB17CCD40D6703EBFD59158A0D981C4B9E93E50A102280672BBA510FA4D58291A7A6 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.7740870296832996 |
Encrypted: | false |
SSDEEP: | 48:7MVp/E2ioyVQAioy5oWoy1CUoy1jjKOioy1noy1AYoy1Wioy1hioybioyZEoy1n/:7upju3JqXKQvob9IVXEBodRBkE |
MD5: | 35E6424DE3B539D79C3D15633B32D6B2 |
SHA1: | FCEDAAFB273626D35820A97BFDC75C4CFE5D5EFB |
SHA-256: | 8CACDEF06B5A7ED3D359A17C1807280A3FB81DCC75883A573299E4C22743FC22 |
SHA-512: | 31FC55586BBBA8E80F560D85ABA0DC6F9EE8C0F1B5AAAE75E6F4E017CCE84AE610F13F3D1186F77103288E1815762F0FF83DAB1BF40E36003AB742192689666B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 ![encrypted](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABgAAAAXCAYAAAARIY8tAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyFpVFh0WE1MOmNvbS5hZG9iZS54bXAAAAAAADw/eHBhY2tldCBiZWdpbj0i77u/IiBpZD0iVzVNME1wQ2VoaUh6cmVTek5UY3prYzlkIj8+IDx4OnhtcG1ldGEgeG1sbnM6eD0iYWRvYmU6bnM6bWV0YS8iIHg6eG1wdGs9IkFkb2JlIFhNUCBDb3JlIDUuNi1jMTQyIDc5LjE2MDkyNCwgMjAxNy8wNy8xMy0wMTowNjozOSAgICAgICAgIj4gPHJkZjpSREYgeG1sbnM6cmRmPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj4gPHJkZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIgeG1sbnM6eG1wTU09Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC9tbS8iIHhtbG5zOnN0UmVmPSJodHRwOi8vbnMuYWRvYmUuY29tL3hhcC8xLjAvc1R5cGUvUmVzb3VyY2VSZWYjIiB4bWxuczp4bXA9Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC8iIHhtcE1NOkRvY3VtZW50SUQ9InhtcC5kaWQ6NkY0N0QxMkZFMDExMTFFNzlEQjNEM0NBNTA2NjRBOEEiIHhtcE1NOkluc3RhbmNlSUQ9InhtcC5paWQ6NkY0N0QxMkVFMDExMTFFNzlEQjNEM0NBNTA2NjRBOEEiIHhtcDpDcmVhdG9yVG9vbD0iQWRvYmUgUGhvdG9zaG9wIENDIChXaW5kb3dzKSI+IDx4bXBNTTpEZXJpdmVkRnJvbSBzdFJlZjppbnN0YW5jZUlEPSJ4bXAuaWlkOjUxREYxNzEwRTAxMTExRTc4NzA2RDNFQTNEMTNCRTY1IiBzdFJlZjpkb2N1bWVudElEPSJ4bXAuZGlkOjUxREYxNzExRTAxMTExRTc4NzA2RDNFQTNEMTNCRTY1Ii8+IDwvcmRmOkRlc2NyaXB0aW9uPiA8L3JkZjpSREY+IDwveDp4bXBtZXRhPiA8P3hwYWNrZXQgZW5kPSJyIj8+MtWoxQAAAcJJREFUeNpi/P//PwMyYGRkhLOrauvZuDg5izk5OZPff/ig9O/fP0YGVADSfBOI5wLxpLbmxl9wCai5jLgsABkuJiq6j5ub2/rBw4cM6OqwgD1A7A2zBKaeBZdqoMFNwsLC1tdv3ABxXwPxJiD+gqaMB4j9gFgUiF2AuBaKEQ7G5gOg61nk5eXev3v7jufzly93gcKWQJe9xuYQoFqQ4ceBWBmIP4AsA6r9AzOXCYcHVIDhDjIcxJ6My3AQgMpNhnIFQHqR5XFZwMHECJd6yEAYIKvhIMYCqoFRCwgCjGSanZPzhpeXVwiYXBn///vH8PPXr/8MaGpu3Ljx+e/fv/+RkjYrExMTF4gNzO1fgGYe27VrlzvWjCYsJCT8/ccPkEKIF5mYGLE4jA+lvAA6AGghcuZzwxlE/4CKYYbTPQ5AuVxTU5PBzMwMpVDEB1hIscDB3p7Bx8cHzJ49ezbD6tWrqesDGRkZOFtNTY36QXT02DFw/IAidNOmTdQPonv37jFcv36d4fPnzwyXL1+mTUb7j1SZDIqcjBFEhFx34sQJhkcPH5Jvwa9fv/BqAMXBtatXyQ+iHz9+/KRCyFyDMQACDADO2LiJuitcAQAAAABJRU5ErkJggg==)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 893 |
Entropy (8bit): | 7.366016576663508 |
Encrypted: | false |
SSDEEP: | 24:hBntmDvKUQQDvKUr7C5fpqp8gPvXHmXvponXux:3ntmD5QQD5XC5RqHHXmXvp++x |
MD5: | D4AE187B4574036C2D76B6DF8A8C1A30 |
SHA1: | B06F409FA14BAB33CBAF4A37811B8740B624D9E5 |
SHA-256: | A2CE3A0FA7D2A833D1801E01EC48E35B70D84F3467CC9F8FAB370386E13879C7 |
SHA-512: | 1F44A360E8BB8ADA22BC5BFE001F1BABB4E72005A46BC2A94C33C4BD149FF256CCE6F35D65CA4F7FC2A5B9E15494155449830D2809C8CF218D0B9196EC646B0C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.144086598890895 |
Encrypted: | false |
SSDEEP: | 6:kKI9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:bDnLNkPlE99SNxAhUe/3 |
MD5: | EFCBD68E0966BBD40AAF508B03F8E716 |
SHA1: | FA0BBB2915E8A96CBCA297AD85B9764B73202C41 |
SHA-256: | 478F7CF85955A585099046234162F00E5C2BAF774A251B288372BC9D8C873E50 |
SHA-512: | 4B0F4450C25081F2EDC03C6ECB124826D432F1DBDD8FF16A67E62753B9C67D1BC313024AD47AABC5C02E2B095805B099468FF5251A97F1B427948CCC8BAC1224 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 252 |
Entropy (8bit): | 3.018531379206123 |
Encrypted: | false |
SSDEEP: | 3:kkFklCjKkXfllXlE/E/KRkzllPlzRkwWBARLNDU+ZMlKlBkvclcMlVHblB8V7ln3:kKZjKAxliBAIdQZV7I7kc3 |
MD5: | 4CB9FA4B7656262B0C2FD27225EE5E23 |
SHA1: | 86EDF4763F7696FC5A82CB1B1B49E116C7BB4D0A |
SHA-256: | AD3262509BCC479732D55E593A66F316220E65716C123D178395DBB13208F8A7 |
SHA-512: | E4344D3B89F889F7ED8AEAF50E4EF3AEE2691FA711951E461A3DF017DDB2ED52A64028FF62A0B5B5EB567A26B1A6264CDC52C1890361D9D1EF9165BEBA4298CB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | 1536:JsVoWFMWQNk1KUQII5J5lZRT95tFiQibVJDS+Stu/3IVQBrp3Mv9df0CXLhNHqTM:bViyFXE07ZmandGCyN2mM7IgOP0gC |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | 1536:JsVoWFMWQNk1KUQII5J5lZRT95tFiQibVJDS+Stu/3IVQBrp3Mv9df0CXLhNHqTM:bViyFXE07ZmandGCyN2mM7IgOP0gC |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 228351 |
Entropy (8bit): | 3.3898188882857125 |
Encrypted: | false |
SSDEEP: | 1536:qKPC4iyzDtrh1cK3XEivQ7VK/3AYvYwgF/rRoL+sn:XPCaH/3AYvYwglFoL+sn |
MD5: | 20A7B5B58ED072AE08A03BC126638854 |
SHA1: | E6F3576C1BF518BFEB2E3117C7B06D9567BDA927 |
SHA-256: | 68FB83644BDF0195E6D962C1F7D0B84820E78B61E08558D12E7669615AAC02AA |
SHA-512: | 624B8D689D50CC2960E85018035D1CECE498361FD31740AABC7AF56EF0F9623B20F2E1266ACC788A7320DDAB5FF6296175600F561D38437897E3F419B8A981CC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.352577460328389 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJM3g98kUwPeUkwRe9:YvXKXkPV4UTbdLXJ5GMbLUkee9 |
MD5: | 5B730A82179C6C349330A9E897CC3961 |
SHA1: | 7F3FC40817784D40F9F5B814261005AB83349247 |
SHA-256: | DFD269A252ECF7362293895ADC044C55584C3BA3E8C64660316398C98E78A766 |
SHA-512: | AD3E64BE3EB947796611D79E987F6A8EF930A22816660528AEC1AAF1EFDFB1F96E4F27FAD000BB968568584832A2794F6680647AFE9E497C5B15E973F76FF40C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.291583693991449 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJfBoTfXpnrPeUkwRe9:YvXKXkPV4UTbdLXJ5GWTfXcUkee9 |
MD5: | CAAD964DE2B4D7FDEF37CA0F9197122C |
SHA1: | A35404CC5496B36DADB2D9E1E1A47EA023C1BD71 |
SHA-256: | 303CE205A232CBF85F813B52AFF837B4A4C0746CC9DE8BC0D73624ED09257101 |
SHA-512: | 42D8D25F65EC287B58177ACFCB5199A4BAC1AB8669DA151EF918954107D874D91F47516782B9C3C0B5FEE9CE742EB99633E364826DA3A905C6E55361F4FA7DDE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.269126892210071 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJfBD2G6UpnrPeUkwRe9:YvXKXkPV4UTbdLXJ5GR22cUkee9 |
MD5: | AB8EADB11D91B1A50BC8CB337829EC40 |
SHA1: | 1B68F69F089A775EFE697DCAD33AFCDA6C0B4569 |
SHA-256: | 07DA76274EF3415FDB185719C8B8D115910255A96357A3DF6E71FB7907DABE54 |
SHA-512: | 015F54D07B1C912C5335921175CB478AD58AC8B3639F3108ABB9F7E0FC6FFCCA33DD462E4C94E83AF9B035857381658DF1FC1277DF1CACBA1E72C00BBFCCE3A6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.326477716673863 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJfPmwrPeUkwRe9:YvXKXkPV4UTbdLXJ5GH56Ukee9 |
MD5: | F1571C507FFEC59BD0B83C8061570013 |
SHA1: | 650B82DAA44B87FBE5B0012296F2A46F03DFE08D |
SHA-256: | 7D945506DF39B3391AB1FAE9F038F83E604B8F509ED334F4C28D6178AC9DD176 |
SHA-512: | 3DBAC90CA0EBBC97DA1BBF5517CD47ABCFF517536FD3D4535F40F425A6CBC7AF00F85DCFAB5B3469A1FE761D5B1F5ACFE74792A3539EA2DF7DF54394F2E4621A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.281211179846304 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJfJWCtMdPeUkwRe9:YvXKXkPV4UTbdLXJ5GBS8Ukee9 |
MD5: | 6201612BF78ADF1879B8D5402F1E4774 |
SHA1: | 76F6208453F2E321D054ABFE50572876B5586F39 |
SHA-256: | A9ABEA4AB4DFBCD0F7D820AB2C8AF51094B3BA91171A33F988719BB9CD39599C |
SHA-512: | 07467E5E2EE296E71F9E2A568B685318B5C6C4EDDC1D3E43D3F0E9AF2E857EE6C2A8EE6F776C52B8F1C956188FF17B7BDBA2962852BDB2C049F5BE64E46D512B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2661126493499415 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJf8dPeUkwRe9:YvXKXkPV4UTbdLXJ5GU8Ukee9 |
MD5: | 3B8FA1E7948E29239E3DF5A372B83210 |
SHA1: | 6B93193DE1235ED0AEA93FFD2EDF1BF9DA378014 |
SHA-256: | 8F642286833D8F57CA52CD690A17AC8676C698EC3BBFE01F1DF7BD4C2BFBDF3C |
SHA-512: | 2D90E2E7E85677D3E4336356D73FBD877183E1BFE50EF21125EBF5F4A2A0601B4E3E6BD91AB2D09D642F39F3067403B104548AB35B0980EEA37E1D296483C771 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.270003655377131 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJfQ1rPeUkwRe9:YvXKXkPV4UTbdLXJ5GY16Ukee9 |
MD5: | BA2AD4ABAE5E5478E6AF06103CF00F4F |
SHA1: | F1AC2F689D3967587BFD773A38E8EF8501FEFF8B |
SHA-256: | CB679108581FBFC450ACC6AF487D33C326222314926F293FD914C69101B0C74C |
SHA-512: | D5D14A483EB96573DE79B8B3C225AD11EF62818EBEAA91469DD308205A75F673611A91C39B75BF10E86733C5C97D877F3A767C774A77E2B4BD149A869C8BD7EB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.278271987375755 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJfFldPeUkwRe9:YvXKXkPV4UTbdLXJ5Gz8Ukee9 |
MD5: | 61BC1C18C592BA5BD2DFE93FCA766045 |
SHA1: | C20322E935EEFF2CF0A301F5E8225A2DE6FB1F2D |
SHA-256: | B81B8D1522ED3CB2C3690FB0B2F1930050A919F14D935DE92257D1AA08BCAAD7 |
SHA-512: | 4C4B525A72F232D920C564015BE677158A559514505230B7A6AB6FC7481EBD8F01D7FCD2941870DD4D3E8A898A6346E1B28D36A88D654982E5557D89E34089AB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1372 |
Entropy (8bit): | 5.731442881121904 |
Encrypted: | false |
SSDEEP: | 24:Yv6XsV4UXHlKLgENRcbrZbq00iCCBrwJo++ns8ct4mFJNP1:Yv74wHlEgigrNt0wSJn+ns8cvFJV1 |
MD5: | 409A93948FC9AF63142CAE053265C7B4 |
SHA1: | 262D7E5628650DE8DA258AC9F789721BBC249BF7 |
SHA-256: | C0B30D40E184C04AF1B59E38DF973338E8F11A1C1281A526B0A54A70F1EF5A24 |
SHA-512: | 407E0740A0D2E06133F770FC96179CFEE8ADB30426E6116DFD349B10258A5F9D772DC905FF3202E1770CE8C62E583A0EFC04A3564428CAE882567CEF919D1610 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.274089439129432 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJfYdPeUkwRe9:YvXKXkPV4UTbdLXJ5Gg8Ukee9 |
MD5: | 28281D543621441382A182A29F4D1D82 |
SHA1: | 89520F1C39D9E70ACC9414C01DCD0F3591C43701 |
SHA-256: | 8D7A6B0FF14BDDC6B2B4BC0518A6DD40F687E91EC525F47999F0F1D4209C02A3 |
SHA-512: | BC594B280CCB3663BE9BC1905AB7AE0D9D0E5BFE9E16F621415DDDC8A8162B30FA1D799520B26F6D2A1AD9888203F7A25319D1B0A4E9EC60C455302FF7BB33BC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1395 |
Entropy (8bit): | 5.768848380003362 |
Encrypted: | false |
SSDEEP: | 24:Yv6XsV4UXHYrLgEGOc93W2JeFmaR7CQzttgBcu141CjrWpHfRzVCV9FJN31:Yv74wHYHgDv3W2aYQfgB5OUupHrQ9FJ3 |
MD5: | D9272C854D45DDBC55B7310A808DFC3A |
SHA1: | FE08332B133E360CC787A6EEE6799D8A28A18362 |
SHA-256: | F5DE7431731C6FEF2636D349A4E5CE7FCD9B289C606BFA2A18C63BF8C673AB64 |
SHA-512: | E6F04009B996C2A70BD98A4403F750836D7DB738F93F954FB31B0C7AF1940302424681A26A19FDE2B9C1281A549D83A6681CE3C3C37F88CF9E03FA919549AFA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.257814616259451 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJfbPtdPeUkwRe9:YvXKXkPV4UTbdLXJ5GDV8Ukee9 |
MD5: | ABE4B46EE73B0264A61887AB5E4EDF7B |
SHA1: | 8BA0E8D46664A9A940B11421FF4DCA53CFCF98AE |
SHA-256: | 5895537587204F54B64E72F324578DEA0A889C99348E34223AB116A5E2256534 |
SHA-512: | 95E7BDBA13BBD9F672D4C3013E09E937B502E6A0240E2DF33E558AA7FB3B4E4D4A423BCBB035C0CD93FA752FB73F591FE67BEC7BB89D20709D7D84B6FC580347 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.261133161304012 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJf21rPeUkwRe9:YvXKXkPV4UTbdLXJ5G+16Ukee9 |
MD5: | 7570936A21E9C170C59BF5E92D10F1B5 |
SHA1: | EA40983AC916C91EB0DFA0EA010758B06A417A69 |
SHA-256: | D26A62EE8995A5405EC3369BAF805735785F654A71F2B9B4FB3C0979FE2711FC |
SHA-512: | 170D0E9FBF0E122A24410A59C5F5F06F679D05EF2D553E496CF8F3C7E260CE98C23CC10E4C159E4A6125164394B0FCE61DF2853D1FF23F5B3A980DA5A73DBF85 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.280318544846634 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJfbpatdPeUkwRe9:YvXKXkPV4UTbdLXJ5GVat8Ukee9 |
MD5: | 117C5BDBD53791C72682DF105FE79BF8 |
SHA1: | 62740C7805165C7182C9C35CE1DD6D86AE4D3998 |
SHA-256: | 80A9417DDE9536BA8F8BC1445DBB64E150015E264A716B7D8C2071DDFEE873B4 |
SHA-512: | FABDD8401D8B3B219C83976E24539038C273D5C0380DB2CF5763EF9FB24D763341F16419CA75F999B5C8D07418FEFDC3447ABC7DE6F91B050D27256D33B7EC72 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.234925925496159 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHEq8V4UXjb24kF0YOTL7JKoAvJfshHHrPeUkwRe9:YvXKXkPV4UTbdLXJ5GUUUkee9 |
MD5: | 19250C59BD9EDA3473C48A329361BB11 |
SHA1: | EF4379867BC7D917F3700E5959FF15E4471E30DF |
SHA-256: | 14A1BBC947BD19A55A6886D607BC364C17F605BB6D5E5677F1C480C5234A8725 |
SHA-512: | 5C75AE42CC3FEFBFFA646882E1C035E77E7C8309A133E664FADA7BCCADD6C5B36A2211DC1CF92C85599A0579812A2D10C239483C1E3386FF11F20533A91DFC7E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 782 |
Entropy (8bit): | 5.352634146135738 |
Encrypted: | false |
SSDEEP: | 12:YvXKXkPV4UTbdLXJ5GTq16Ukee1+3CEJ1KXd15kcyKMQo7P70c0WM6ZB/uhWL1:Yv6XsV4UXHV168CgEXX5kcIfANh+1 |
MD5: | EDB960A1784AF5645F07B42242967D46 |
SHA1: | BBBAB9BF3FF5A802706D89F507EE54A0D0788AA3 |
SHA-256: | C7C6E349D2682FA62EE66616D9F87C7254EB9CC4A021ADCDCE66E2814C2D0727 |
SHA-512: | BF659CC5CEF6A9E6B06CAF7180A43C943DBE396C1F1E827749869D6995A282B93B35903B497025608497C9E00CA1C9EB2C76D3F0EA58CEE6F249AD7727507FFF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.128409780521033 |
Encrypted: | false |
SSDEEP: | 24:YB1bkU/Ck0Whp18MjeTEav8aeyP1ayVBONh+/jrj0SNwsYt2H4x2LSfNYQFW5dYD:YvkuP0Wfm4eTxOWHa9YONCeWjY99bvf |
MD5: | 89425842F4189B8F49713641E41F9B08 |
SHA1: | 0CFA02396251D0B6D96535802B45637DE926839E |
SHA-256: | 28D8C4653A6EDF388E39193D458AE350419594B6E4EE7E6D2FA850EE5F2FC370 |
SHA-512: | 96A31BFCE4495C29234EB01C9E36CCBCEEA76E77C5776D1F3E96CAC75BD83ADF294455872D89078D0887AE4F5B8E65EC5E59E37181B3FE30B27EA6C4D651429E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3202617834998835 |
Encrypted: | false |
SSDEEP: | 24:TLKufx/XYKQvGJF7urs9O3KaiZ3FL63FLesb+sZobF16R6FdpqpQ6YWUQ+EXSqXv:TGufl2GL7msUKB0M0+Tb608YWqrep |
MD5: | A47CABB36C6229C875F875824A935833 |
SHA1: | D0E7D7F87BF9D253246C94471A94E82B7E853F0D |
SHA-256: | AB66C8023D71B52E00D190D00104E7AABD65D4B4FCCEE247A229C2145F096E28 |
SHA-512: | 9655CC4EA904532A09C0A6A815D71D7230413BB839C445831F1E0E666B3A988A333F2D62AB3DBCBBA6DD040C92F2ECE64AE9AA68BCC932429F62C1EADAEED68F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.780784207125804 |
Encrypted: | false |
SSDEEP: | 24:7+t8l3KaiZ3FL63FLesb+sZobF16R6FdpqpQ6YWUQ/EXSqXlyGKaiTqLhx/XYKQZ:7MSKB0M0+Tb608YWzrGKfqFl2GL7mse |
MD5: | 7AEBBB857D5E273EF7B9D5A17A5BE24C |
SHA1: | FA9C152DF6D0234D4F49EF50CD6D00EE7733CF3C |
SHA-256: | 46ED2C209E9560527DCC9AA2A0E8893AF108F3A70987AAF5670F65AAA69C66E9 |
SHA-512: | 806ED5D8455CB2AC73C8C6125E2CECDB9C38042F4F93E1EE88156CD9FB81FC61074626B3BF19B5F654521EE84BF9D848E25D769C4024FCB08695C1956AE8DFE5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5329345335875004 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8eqQaMG:Qw946cPbiOxDlbYnuRKEQM |
MD5: | 21C35AD0F297E770E634EFCA439DCBBC |
SHA1: | EF1F9239D15FE604CFB6DE78AD55ACB137E2B453 |
SHA-256: | EBC8573FB03DF32148E18DC9529F6CC97556A2550C6031AF10494AB890973C1B |
SHA-512: | ED08AFC8ACCE63BA7DD2D4E43C30AB86E52162C18AC5BB336CC9B91D5D3D2107FC6F481F7E40CC7E422D0E703FEF8C47BBB03D8571C5DBD536A0E0C4C410360A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-07-08 13-41-51-987.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.361022727805069 |
Encrypted: | false |
SSDEEP: | 384:cBD67lQV4j1MOuD/btX+wknz+fzTqyorqz3tVFr84AbAYpfFWbWt+Fjwn0z5O+Wf:4M5 |
MD5: | 70A2D078BEFD5E910EE035832171B399 |
SHA1: | 1AB91914ECD7852E512C73437D30013594A16FB0 |
SHA-256: | 2B55DE84E5446FD295128DAD5827122E98AC784F96A1F422B711B14E8F7DB1ED |
SHA-512: | 9FF36D4E320A8791AB0B87F24CAB4CBE777D9E8A3A64D26AF419132CDFDFCCD9A253EE9854032C4C87C546187951077F869CBCBDC9513278C557FC4895C7DBBC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.33150155723823 |
Encrypted: | false |
SSDEEP: | 384:MUSp6k7J2DC3gOT3QeFIXNEd5+HlJmORMD1Br2GdZ4BACIMSyhRn0v0Jw7d1E4oQ:WS4 |
MD5: | D0DD6A541D4B99D9A27ECD72C4CC11AA |
SHA1: | 753E0DBCE6F22F54ACE694EEDC047172DD5E679E |
SHA-256: | 8C6683051BE06858CFBB0114DD7C41FB55905E90073E426E1939F3CBD8AE3BA6 |
SHA-512: | BE6EBE0736BAE2E0153C12567AE3F22ED6EC4E3F240CFBA83F5BB1B1BE5D3D824118AB2EE0C58DB38C255E1D4D74FACFF71E81E05F644CD497EE5BC77E70592F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.402233919056698 |
Encrypted: | false |
SSDEEP: | 192:zcbaIGkcbIcbiIICcbBOQQ0fQNCHPaPOhWPOA3mbSAcbsGC9GZPOdIzZMJzV3Zm7:EGvIcNYddeH |
MD5: | 631F2BC86D0E3CF3DD6696AA4804D0EA |
SHA1: | 8FF0F2A9D24C7AF038693D78853DAA2072995B66 |
SHA-256: | 37CA8FF2AAE995CD069263FFCA826F9D6E3C273DEA74D78E33A39DAA82A3DAC5 |
SHA-512: | 4E66CA0B736AEE8BCAF8C8900FE6931D0195C8D7D547FABE0FE2F2FAD25DEB7216AE297F9F24200C43FA75410ADA30B0FBEDD750EFB379B71076DD906389783B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZL4YIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | 9F39E726C0EA0FB425C69A21F30C0EED |
SHA1: | 9B2B079D2F9A4F53A981F1518F11D4BEB50FABC4 |
SHA-256: | 52F1F422A8A01FD89E8EB051F2EED7015C66DD3EBAB64F72C3A0AAD781E95748 |
SHA-512: | 5BAF313AE82677BA101CE70092B1CDDBD679C9A04614087E5CE091246A30A7AD235E20F3809E4B7FB1BC608DC2C42781BB9BD03D5837D9DC16EBBC5CD6D725D8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7ouWLgGZtwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVuWLgGZtwZGk3mlind9i4ufFXpAXkru |
MD5: | A8E5C37206C98D1B655FF994A420FFB6 |
SHA1: | 827237782AB5971EC205C3BCECCC7950BE9F84C3 |
SHA-256: | F1F755059AF7C2CBC36920337941AEFB18FBDB3CD14D3239CBBBCF0CB8F208EA |
SHA-512: | 12DE33EB7624458AEC44D83D4E2C09E626F8E54E177FC0C26EEBA232935F34FAAAEB71FBB025EB7C53BEA9933C46ADCE759C32516D1B80C03B6734C61D61CEB2 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.827199989866602 |
TrID: |
|
File name: | GWKBOHZU0T6TSY8WB9DBB.pdf |
File size: | 62'491 bytes |
MD5: | 95750558568ee0e0bf7e5064e1d8ebf4 |
SHA1: | 452709033a70a0fda4a03aba92b3e5441b877ed3 |
SHA256: | 99fdcdc5d2dd5705192f30a40a3515159eba7cd9c3464f8fba6802d5e2331451 |
SHA512: | 59979fdce8e828bdc4b637477345fe8691b1d069dda1f3b0e231105b42b7401670e1d50389d108198759c43c6232060a3c56eee5c224f0c1e9eed742d75aa9a6 |
SSDEEP: | 1536:q3WO79UVsx4yGGGGGGGGGGGGGfP56BJVNCkyCfOAyuQQN:BQ9UVByGGGGGGGGGGGGGfP5eJVNCkyUp |
TLSH: | 2C53BEC48DF28302FE71813814AF7B789A94D34F296D7E9F9857152C79ED20F8E462A4 |
File Content Preview: | %PDF-1.5.%.....1 0 obj.<</Type/XObject/Subtype/Image/Width 888/Height 1440/Length 61484/ColorSpace/DeviceRGB/BitsPerComponent 8/Filter/FlateDecode>>stream.x....t.U..{Og....o........E.a.(..@PYB DH:..mt.m.G}8.u..e.EeD.......d.-a.N.....[].....N...:...=}:..n. |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.5 |
Total Entropy: | 7.827200 |
Total Bytes: | 62491 |
Stream Entropy: | 7.823729 |
Stream Bytes: | 61721 |
Entropy outside Streams: | 5.496491 |
Bytes outside Streams: | 770 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 6 |
endobj | 6 |
stream | 4 |
endstream | 4 |
xref | 0 |
trailer | 0 |
startxref | 1 |
/Page | 0 |
/Encrypt | 0 |
/ObjStm | 1 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
1 | 633b2f33e523735c | 840367aa709ee36dfee50b08239d0b46 |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jul 8, 2024 19:42:06.580598116 CEST | 1.1.1.1 | 192.168.2.10 | 0xa89d | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Jul 8, 2024 19:42:06.580598116 CEST | 1.1.1.1 | 192.168.2.10 | 0xa89d | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 13:41:48 |
Start date: | 08/07/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff64eb90000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 13:41:49 |
Start date: | 08/07/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63ec50000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 4 |
Start time: | 13:41:50 |
Start date: | 08/07/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63ec50000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |