Windows
Analysis Report
F-000687.pdf
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 5448 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\F -000687.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 4544 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6792 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 92 --field -trial-han dle=1628,i ,752481347 3393860247 ,172359380 8790930730 2,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | DNS query: | ||
Source: | DNS query: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Non-Application Layer Protocol | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.210.172 | true | false | unknown | |
x1.i.lencr.org | unknown | unknown | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1542139 |
Start date and time: | 2024-10-25 15:34:54 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 21s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | F-000687.pdf |
Detection: | CLEAN |
Classification: | clean0.winPDF@14/30@2/0 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 54.144.73.197, 34.193.227.236, 18.207.85.246, 107.22.247.231, 172.64.41.3, 162.159.61.3, 199.232.210.172, 2.16.164.91, 2.16.164.50, 2.23.197.184, 88.221.168.141
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, e4578.dscb.akamaiedge.net, ctldl.windowsupdate.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ssl.adobe.com.edgekey.net, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: F-000687.pdf
Time | Type | Description |
---|---|---|
09:36:27 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
bg.microsoft.map.fastly.net | Get hash | malicious | AsyncRAT | Browse |
| |
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher, Microsoft Phishing | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.2828693526091035 |
Encrypted: | false |
SSDEEP: | 6:/eVFUQt+q2PcNwi2nKuAl9OmbnIFUt8ieDsXZmw+ieDs3VkwOcNwi2nKuAl9Omb5:WvIvLZHAahFUt8FD4/+FDg54ZHAaSJ |
MD5: | 627CEB0BAEC0883C2965D418658E0CF7 |
SHA1: | 040214C0793A54EC7C47D6DF3F9A98151F90A898 |
SHA-256: | 6E047EEFCF6620623B28F800D3279E7371BD68F9369ABBD8ABD94AB7712AD8C0 |
SHA-512: | 1D995F15EA94FE68D17DD5B9953BD4B57FECBA8CDE8143BFC242ED744B5F6B28392744C2C0D628C183092D6173AE26609C0518343CD083C8C852E7D81EC615CA |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.2828693526091035 |
Encrypted: | false |
SSDEEP: | 6:/eVFUQt+q2PcNwi2nKuAl9OmbnIFUt8ieDsXZmw+ieDs3VkwOcNwi2nKuAl9Omb5:WvIvLZHAahFUt8FD4/+FDg54ZHAaSJ |
MD5: | 627CEB0BAEC0883C2965D418658E0CF7 |
SHA1: | 040214C0793A54EC7C47D6DF3F9A98151F90A898 |
SHA-256: | 6E047EEFCF6620623B28F800D3279E7371BD68F9369ABBD8ABD94AB7712AD8C0 |
SHA-512: | 1D995F15EA94FE68D17DD5B9953BD4B57FECBA8CDE8143BFC242ED744B5F6B28392744C2C0D628C183092D6173AE26609C0518343CD083C8C852E7D81EC615CA |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.207249530475916 |
Encrypted: | false |
SSDEEP: | 6://rSQ+q2PcNwi2nKuAl9Ombzo2jMGIFUt8iipdWZmw+iiXDQVkwOcNwi2nKuAl97:r3+vLZHAa8uFUt8tXW/+tsV54ZHAa8RJ |
MD5: | 087B3E5071B06D4FBF888BC3A06FE6CA |
SHA1: | F120E1BC4FE81E79E665932D3A324816CDA503BC |
SHA-256: | 8A33B2E2A1C6EA615B3DD362D7110D86F56D3995DECA6A4E9C4220FEA7CD764E |
SHA-512: | 57083AB725896911F1324D63B39344A59B0129B940D9A41D7CD0F4CC74C69416BB7706A706DD3421FE3ADCF9658637FE5F7CE083B92E1575B2765E3901F0D83E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.207249530475916 |
Encrypted: | false |
SSDEEP: | 6://rSQ+q2PcNwi2nKuAl9Ombzo2jMGIFUt8iipdWZmw+iiXDQVkwOcNwi2nKuAl97:r3+vLZHAa8uFUt8tXW/+tsV54ZHAa8RJ |
MD5: | 087B3E5071B06D4FBF888BC3A06FE6CA |
SHA1: | F120E1BC4FE81E79E665932D3A324816CDA503BC |
SHA-256: | 8A33B2E2A1C6EA615B3DD362D7110D86F56D3995DECA6A4E9C4220FEA7CD764E |
SHA-512: | 57083AB725896911F1324D63B39344A59B0129B940D9A41D7CD0F4CC74C69416BB7706A706DD3421FE3ADCF9658637FE5F7CE083B92E1575B2765E3901F0D83E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF57627b.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\a6d64c38-7a05-4e90-aa84-cd6c6114a73a.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.9602737064168165 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqRdhsBdOg2HU2caq3QYiubSpDyP7E4T3y:Y2sRdsA0dMHUJ3QYhbSpDa7nby |
MD5: | 5BE94EF8A877A93630ECEBA8213BBA2D |
SHA1: | 8B24919CAEFB720FB463088FE116587494F08D9B |
SHA-256: | D7747A3E5638734FC7F5FB9EE8C25FF4EB631A5264F3EA56113F97B12A418417 |
SHA-512: | 0F80C411D1F8D231C89D7892E0A45FA5DB5B86A44A6A02B447CA91319DA98EB163E4CE7736E550EED1BCF5CAB32739A44A89E563B8E3F4896BB179E256E78D37 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\ca77f2d1-e7f5-4313-a334-e32b7aff2bfa.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4509 |
Entropy (8bit): | 5.237061812911161 |
Encrypted: | false |
SSDEEP: | 96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtPxN2mUmBZ:CwNw1GHqPySfkcigoO3h28ytPxN2mUmr |
MD5: | 79765EDFA7CFC62AB73C418CC04AA684 |
SHA1: | 65DBE461887C41F7544BA86B1B344F70A740A3D7 |
SHA-256: | 3FCEC7A8794627652DDDB6CD3BC9A9639954D38AD6C16D3D4C4F7FFA04B07E65 |
SHA-512: | 738BD17643005999F46ED51C79C26D4A23A398A4BE59BB698CD0731FB468C2A0A4B33CF52B704B8CB1627395E4B9365E807694F62D0834F9863FA0E2E4FD1CC8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.205789036900478 |
Encrypted: | false |
SSDEEP: | 6:b5SQ+q2PcNwi2nKuAl9OmbzNMxIFUt80pdWZmw+FMQVkwOcNwi2nKuAl9OmbzNMT:b5+vLZHAa8jFUt8YW/+F5V54ZHAa84J |
MD5: | D4FDA2023B2974410DC84CE1A0EE002F |
SHA1: | B32427FB5F7409F96ACD719D201733DA2090CFB4 |
SHA-256: | 3AE363040EA865B74F2D910ABEF3498586756A0B1261D3F2B641CD9E06962BF2 |
SHA-512: | 1F41C34CA8C825DB9F7A25120D6D02153DF8B3CB71C79BE1A2C94EF1C40B52DD375FDE3AC23094AE5E2EF268366FC39C5F9BAD8EF07D0CC0D4476AE9BF8454B1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.205789036900478 |
Encrypted: | false |
SSDEEP: | 6:b5SQ+q2PcNwi2nKuAl9OmbzNMxIFUt80pdWZmw+FMQVkwOcNwi2nKuAl9OmbzNMT:b5+vLZHAa8jFUt8YW/+F5V54ZHAa84J |
MD5: | D4FDA2023B2974410DC84CE1A0EE002F |
SHA1: | B32427FB5F7409F96ACD719D201733DA2090CFB4 |
SHA-256: | 3AE363040EA865B74F2D910ABEF3498586756A0B1261D3F2B641CD9E06962BF2 |
SHA-512: | 1F41C34CA8C825DB9F7A25120D6D02153DF8B3CB71C79BE1A2C94EF1C40B52DD375FDE3AC23094AE5E2EF268366FC39C5F9BAD8EF07D0CC0D4476AE9BF8454B1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241025133618Z-165.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65110 |
Entropy (8bit): | 1.4195099593798866 |
Encrypted: | false |
SSDEEP: | 96:ThDvoeMVXugc7kzaJXuYsGfkKXKAiOqxxZal6BmAlMhN2rRp4pKVlTGG2ykhki9a:ThDvodwkyl28kAKfEVY |
MD5: | B7DB2E4E736B6B81BB7A8355510457AA |
SHA1: | A84B723449B0ECF5DEFD64C8DDAC8D0EE22BB5E7 |
SHA-256: | 33B51E07703BCF6B59D7F6D54295C4B032A11FC4F299EF012536B43ACAE1A7A9 |
SHA-512: | 6528CD17D0768C7B719E740220206C6628DD29FF6AE95B5917A4A8A7FE31EB173E283C7261792A2C96BC83237AD45D333DE913708468841248A003A93782E8EF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.439071984416051 |
Encrypted: | false |
SSDEEP: | 384:yeaci5GciBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:1wurVgazUpUTTGt |
MD5: | 0F4AD3A853A22843B08CD98462EEA660 |
SHA1: | B4EB6B5C29971FC7EB0D647B3D30A70DF7C2FDDD |
SHA-256: | 43AD6409FB0A8F6343234F252870BF39039D9513D302A334782396DB592476A7 |
SHA-512: | 62C9A35EE357199E05AE566DF8D5B25030086087633E142E6257D6058E37F0A83754A1084F973111B1037FE2B5150D67FA82A3C25EAC97EB170B9108F4A49408 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.7751931001788948 |
Encrypted: | false |
SSDEEP: | 48:7Mfcp/E2ioyVNioy3DoWoy1CABoy1JKOioy1noy1AYoy1Wioy1hioybioy9oy1np:77pjuN0iAPXKQcEb9IVXEBodRBki |
MD5: | C9933E1536D6838D74F71882E321CC15 |
SHA1: | 9404C346D3311A2EC541B30508E5547834D857DC |
SHA-256: | A8C24B270760F08CCB6627ABA03107E5F59B9EAA17829610196B4F947E5BB490 |
SHA-512: | AD756038AFF7560C3F04E913473795B291FAD7109312FEC6D239C5B7A69973DBEC5C5C9ECC96746BE3D6EE6BAF23AA29401BBCA2972CD58BC2F80825495AF068 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7569015731729736 |
Encrypted: | false |
SSDEEP: | 3:kkFklBNFDtfllXlE/HT8knGz1NNX8RolJuRdxLlGB9lQRYwpDdt:kKCDeT8uG3NMa8RdWBwRd |
MD5: | FA59CC5E4888DBB5FD470E76B3FD0234 |
SHA1: | BB98C445FBC87195AD87D06F91C203B33673F49B |
SHA-256: | 110156FC30FCBC0228C53E5A3603E95A55E339934AD6576EE5AD69C8D63392B8 |
SHA-512: | E8B67CCB1F15E21E2B68FADF9AB5F98C75A5919EFCC00831BE61D0EBE6075DB009507B0E7A23321754C8C642F16F6740C1792CF76EBA8238E678AF16998C0E37 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.247897867253902 |
Encrypted: | false |
SSDEEP: | 6:kK1b3/L9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:13aDImsLNkPlE99SNxAhUe/3 |
MD5: | F19E9E4F260CE3A5292CCC2CE7474B5C |
SHA1: | 21748658E656EFD4A3729C88EA8795610381CC44 |
SHA-256: | 00DF81DD8196973E5847F2655FE0177644A224F5F3C5321CD815718FEE9DD3D9 |
SHA-512: | 49F3C743C4F4C24FB20491070378412955FB0FA23C73DC8D00FFAD27EF8864CCE78111EDAC713426A1C5A94E65CE7FD1FBACB16ACDFD99D9AD516EDCC60D0EC5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2145 |
Entropy (8bit): | 5.082398570258171 |
Encrypted: | false |
SSDEEP: | 48:YL8YvXvwvfb7ACHaECU6akn2ZqijwiIE0O:mfif4oh612ZdXrz |
MD5: | A80C712E5423E54263ED296CF86EF95C |
SHA1: | 31B123AE629278BCC967D93E9210C29995541CB6 |
SHA-256: | EB4491F44EE1AA12DE072D03FE90BBA0EB44B496C47267A221E4C39EAE3ACAFA |
SHA-512: | DE581F33E091B27CA68DB6B1149F319B24CCB66D36C41F19BB8F7F49A656BC69D54B188799C65CB18E23CC5B82354EA4F32CF1BB72410FB5A6F676D3AB418096 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.4550694654155512 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsTlx:lNVmsw3SHtbDbPe0K3+fDZdk |
MD5: | E2AEA269B876E280303F2C2300F59D61 |
SHA1: | A72DFD0C623E3C7A2B325E5C3C2BE998C82E162B |
SHA-256: | 7C764A6C48EB00D499C53E6780F79476217D0618AD9ED804DB4BA431C75A6DD9 |
SHA-512: | FDFC12814EED1EE16BF1D1791ABA69704C91F3E1B639CF8C2F7DFAE1265255E3DD36ED4480ADE2748004773074335A5304BB5B50980C6EF484F9B27B7486D8C0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.9582836900032294 |
Encrypted: | false |
SSDEEP: | 48:7MHrvrBd6dHtbGIbPe0K3+fDy2dsS4WqFl2GL7mst:723SHtbDbPe0K3+fDZdnKVmst |
MD5: | DF28BDE9775E9AC22C85641590165207 |
SHA1: | 991006C60D43259915E87AEED80663C7EFA983B0 |
SHA-256: | 8C07DBEB8CA1C91C762699E67C9AB08B048D3EF9BD57DB8726A3D6B7D2D796E4 |
SHA-512: | E5A9924B88FF0EC4FCD6CAE2EEB91420A3A09D893D86C94C6D8618BCF694787B443C64AF816CC952844A16CE35DBA005B2DF29AA364C30B99FFB65D8B18715BB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5325285763919316 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8jaI0lH:Qw946cPbiOxDlbYnuRKo09 |
MD5: | C6E71BF674630C3760DB158122E26942 |
SHA1: | 41A51211CA37344D14BC2B0181885A738CA6F96B |
SHA-256: | B0AAC388203658343F6AA69A6EF03047D81245397EBB2C55A2EAFD4CEDCC1791 |
SHA-512: | 295C19F9148D4988A1A6F7CB2392C4B8D200316773498FB141AA81B1F1858A4CC9285DEE929DF17B4574FCDC6ADD8CABDC13A9B354B7F8DC77CDEEDADD4C0B91 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-10-25 09-36-16-220.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.386483451061953 |
Encrypted: | false |
SSDEEP: | 384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID |
MD5: | F49CA270724D610D1589E217EA78D6D1 |
SHA1: | 22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3 |
SHA-256: | D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D |
SHA-512: | 181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.324200672561885 |
Encrypted: | false |
SSDEEP: | 384:T3rTcHTcwTcfTczTc8di0dIdRdJdqdwdD76747y7otbtTtitPtyeAgxAWHWrwroT:zcLk2S+g |
MD5: | 258B77982D4BB11A091E735DA6432C4D |
SHA1: | 26D5EC7D75F4EA1B6578A9BEF0F5E434BD16A6B7 |
SHA-256: | F918BA531B6764ED2D9C51F43AC55E3CEE2D0D1537FD06B1A22EA6D239BFEEB1 |
SHA-512: | 35B5AC1D95CD54E80888F6066043AC6535A79AD1766FE3ADE41512A2FC1F426BCD666C375D832C97C52B9936FFDD5A56C55BCD59D4E7B0BA19D39CD611024FE6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.421043883944 |
Encrypted: | false |
SSDEEP: | 768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRC:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRM |
MD5: | A7773D7A2602E71779C53BB78924B803 |
SHA1: | 576F6D211674FC5D6395D5CAEA3B51FED773135B |
SHA-256: | B5DDE128CA30E989C8DC448C520537318965EA109D5960CBF2E95F6BFFA2FF40 |
SHA-512: | 891E7F17B02E1B93C804C0CFC042CA5097D47660AF6D064E0429D8A65AB4BBA26685B57E1440A0AA60D71594F6336755E9C62D2FEDEF5E7D73D9992CA3064BE3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLkwYIGNPMGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLkwZGuGZn3mlind9i4ufFXpAXkru |
MD5: | CA6B0D9F8DDC295DACE8157B69CA7CF6 |
SHA1: | 6299B4A49AB28786E7BF75E1481D8011E6022AF4 |
SHA-256: | A933C727CE6547310A0D7DAD8704B0F16DB90E024218ACE2C39E46B8329409C7 |
SHA-512: | 9F150CDA866D433BD595F23124E369D2B797A0CA76A69BA98D30DF462F0A95D13E3B0834887B5CD2A032A55161A0DC8BB30C16AA89663939D6DCF83FAC056D34 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.957961970427303 |
TrID: |
|
File name: | F-000687.pdf |
File size: | 35'897 bytes |
MD5: | 7db0bb6e4f26570e3fde6768673d95aa |
SHA1: | 28f2e11a4487d7a175c2e8a9fa9fb8da56e73f94 |
SHA256: | fd72bba6429d89498a6bb6983637de088568092b7352f2af7cbe8797448efb4a |
SHA512: | e19c97654f5fdfc853b2c1dad9667d05f5c40b3bdda0d5b1833afd5bd837bcad8d7e0345a70cc6b2904cd1d265d7929573188430b41bba024b7d50057484c76f |
SSDEEP: | 768:XSKkSAsM67J66OJ3XuzxAfcFuNspn0hu0vfR6tUC3IATdLhWLj:X8SAV+UJUuhA0vfErIATdLMj |
TLSH: | 23F2E150EBFAF9CBE8810446B608386FE57DF1478ED4B8E0555C084AA254E167EE0AE7 |
File Content Preview: | %PDF-1.5.%.....4 0 obj.<</ColorSpace/DeviceGray/Subtype/Image/Height 122/Filter/FlateDecode/Type/XObject/Width 340/Length 9304/BitsPerComponent 8>>stream.x....X.Gw...7E.P.Tl.."....5F..Qc7..%vc.^.Q.F.].Qc..;..V. E8.......-.'.._.....7.f.......@..P..P..P..P. |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.5 |
Total Entropy: | 7.957962 |
Total Bytes: | 35897 |
Stream Entropy: | 7.992064 |
Stream Bytes: | 32707 |
Entropy outside Streams: | 5.325527 |
Bytes outside Streams: | 3190 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 17 |
endobj | 17 |
stream | 7 |
endstream | 7 |
xref | 1 |
trailer | 1 |
startxref | 1 |
/Page | 1 |
/Encrypt | 0 |
/ObjStm | 0 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
4 | a3b3b65458b6b682 | 0d58081264c75c25f0d45aadfe598ea1 | |
5 | a3b3b65458b6b682 | 9088f33c3e1b42f41126fbd9abd31ec8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 25, 2024 15:36:26.976470947 CEST | 55999 | 53 | 192.168.2.7 | 1.1.1.1 |
Oct 25, 2024 15:36:39.742666960 CEST | 49646 | 53 | 192.168.2.7 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 25, 2024 15:36:26.976470947 CEST | 192.168.2.7 | 1.1.1.1 | 0x15a5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 25, 2024 15:36:39.742666960 CEST | 192.168.2.7 | 1.1.1.1 | 0x69f3 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 25, 2024 15:36:25.892210960 CEST | 1.1.1.1 | 192.168.2.7 | 0x9557 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Oct 25, 2024 15:36:25.892210960 CEST | 1.1.1.1 | 192.168.2.7 | 0x9557 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Oct 25, 2024 15:36:26.984910965 CEST | 1.1.1.1 | 192.168.2.7 | 0x15a5 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 25, 2024 15:36:39.751379013 CEST | 1.1.1.1 | 192.168.2.7 | 0x69f3 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:36:12 |
Start date: | 25/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702560000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 09:36:13 |
Start date: | 25/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 09:36:14 |
Start date: | 25/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |