Windows
Analysis Report
Dr. Lindsay Chropractic Corporation Spine Fit Rehab & Wellness (24-10-2024 - Submission).pdf
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 2108 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\D r. Lindsay Chropract ic Corpora tion Spine Fit Rehab & Wellnes s (24-10-2 024 - Subm ission).pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 3288 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6788 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 88 --field -trial-han dle=1648,i ,142600872 2444374593 6,13656865 5625645895 86,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Classification label: |
Source: | Initial sample: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 1 Spearphishing Link | 1 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Non-Application Layer Protocol | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
x1.i.lencr.org | unknown | unknown | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | unknown | |||
false | unknown |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1542219 |
Start date and time: | 2024-10-25 17:02:12 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 15s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Dr. Lindsay Chropractic Corporation Spine Fit Rehab & Wellness (24-10-2024 - Submission).pdf |
Detection: | CLEAN |
Classification: | clean0.winPDF@14/43@3/0 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 23.43.60.134, 2.19.126.143, 2.19.126.149, 34.193.227.236, 18.207.85.246, 107.22.247.231, 54.144.73.197, 162.159.61.3, 172.64.41.3, 2.23.197.184, 88.221.168.141, 2.22.242.123, 2.22.242.11
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, e4578.dscb.akamaiedge.net, ctldl.windowsupdate.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ssl.adobe.com.edgekey.net, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: Dr. Lindsay Chropractic Corporation Spine Fit Rehab & Wellness (24-10-2024 - Submission).pdf
Time | Type | Description |
---|---|---|
11:03:31 | API Interceptor |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.199773928373682 |
Encrypted: | false |
SSDEEP: | 6:rnAmq2Pwkn2nKuAl9OmbnIFUt8GpsZmw+GpMkwOwkn2nKuAl9OmbjLJ:lvYfHAahFUt8es/+eM5JfHAaSJ |
MD5: | 5C9D5C4052760A951960D34240370E6C |
SHA1: | D3C39CD77D8C57798221E4B42881F99C982A75DE |
SHA-256: | E258BA28040D5EA9B4DF5E04D2DA7B161BA6609524CDA2B77C0B8B6C50FA36E7 |
SHA-512: | 72D43A708A318EF1A407AB7F38CC7A863A5C80AF07B9E28E000EBAEAD4420F91E8DE0D03ECC85EDAE63076A4B90E39C1A75B2D3685E66CB81B73316064C6E071 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.199773928373682 |
Encrypted: | false |
SSDEEP: | 6:rnAmq2Pwkn2nKuAl9OmbnIFUt8GpsZmw+GpMkwOwkn2nKuAl9OmbjLJ:lvYfHAahFUt8es/+eM5JfHAaSJ |
MD5: | 5C9D5C4052760A951960D34240370E6C |
SHA1: | D3C39CD77D8C57798221E4B42881F99C982A75DE |
SHA-256: | E258BA28040D5EA9B4DF5E04D2DA7B161BA6609524CDA2B77C0B8B6C50FA36E7 |
SHA-512: | 72D43A708A318EF1A407AB7F38CC7A863A5C80AF07B9E28E000EBAEAD4420F91E8DE0D03ECC85EDAE63076A4B90E39C1A75B2D3685E66CB81B73316064C6E071 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.101926414620962 |
Encrypted: | false |
SSDEEP: | 6:RtDM+q2Pwkn2nKuAl9Ombzo2jMGIFUt8kCgZmw+lSDMVkwOwkn2nKuAl9Ombzo23:s+vYfHAa8uFUt8g/+l3V5JfHAa8RJ |
MD5: | 8E349486F934DA2FA0E609016E0B3EF4 |
SHA1: | 3D7FBB6C32DB0D918785F7EC325DCA4A174F1B86 |
SHA-256: | DA6C72BEE8C4FE90C220EB604ACD460752E117284358FB2F305D38635E55D09B |
SHA-512: | 5A0D02B9E1E47E02B8499B0A3070EC0F0E1F9A0B1A0145FA35E1B387E5FE193824E322ED839393F8C7B7D42323E6BB103B14FED7769D551C65B240E013F88FB8 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.101926414620962 |
Encrypted: | false |
SSDEEP: | 6:RtDM+q2Pwkn2nKuAl9Ombzo2jMGIFUt8kCgZmw+lSDMVkwOwkn2nKuAl9Ombzo23:s+vYfHAa8uFUt8g/+l3V5JfHAa8RJ |
MD5: | 8E349486F934DA2FA0E609016E0B3EF4 |
SHA1: | 3D7FBB6C32DB0D918785F7EC325DCA4A174F1B86 |
SHA-256: | DA6C72BEE8C4FE90C220EB604ACD460752E117284358FB2F305D38635E55D09B |
SHA-512: | 5A0D02B9E1E47E02B8499B0A3070EC0F0E1F9A0B1A0145FA35E1B387E5FE193824E322ED839393F8C7B7D42323E6BB103B14FED7769D551C65B240E013F88FB8 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\8c98ff50-e130-474d-bea7-ca56fea0e52e.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.971316048517525 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqAOxsBdOg2H8gcaq3QYiubInP7E4T3y:Y2sRds/bdMH8L3QYhbG7nby |
MD5: | 24AB171235194FB7386480CEF1E2977E |
SHA1: | 0F671571733CBD55F66D1D422BAC7190B84DAB46 |
SHA-256: | D9B456F058F5627BC7A5B61FF905898A8F79C34F80BDB6A53D9C83DA61C8B497 |
SHA-512: | BDBF1ABA02E54FE12C0184C6C90C206967276543FDC98AB2483A611C7B8AD3B5706DAD697E63A09125A2FB69F56BB3ED38A3F1CD33F7E04A4E73197DC8E8505E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971316048517525 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqAOxsBdOg2H8gcaq3QYiubInP7E4T3y:Y2sRds/bdMH8L3QYhbG7nby |
MD5: | 24AB171235194FB7386480CEF1E2977E |
SHA1: | 0F671571733CBD55F66D1D422BAC7190B84DAB46 |
SHA-256: | D9B456F058F5627BC7A5B61FF905898A8F79C34F80BDB6A53D9C83DA61C8B497 |
SHA-512: | BDBF1ABA02E54FE12C0184C6C90C206967276543FDC98AB2483A611C7B8AD3B5706DAD697E63A09125A2FB69F56BB3ED38A3F1CD33F7E04A4E73197DC8E8505E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4730 |
Entropy (8bit): | 5.2495865691478265 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo72q6fP3F6Z:etJCV4FiN/jTN/2r8Mta02fEhgO73go9 |
MD5: | 0D2563BBE6D26A686F3B085F449DF24C |
SHA1: | B1871B40A31276595A89675CAC8082E1557951CA |
SHA-256: | 2C464B8B0FCD966B3698AE2C6A34F3D162DA980BC062A6296692D4CB0B62A11A |
SHA-512: | FFB7CB33EE48BEC04726E5258C185D4980C55274CADA6522D06FFA511F810E8C0DEBD16094B917DF54A49CEFDB67F4B00C012018E398C1FBBC1EE1E69591CE17 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.113460948199404 |
Encrypted: | false |
SSDEEP: | 6:lxXSDM+q2Pwkn2nKuAl9OmbzNMxIFUt8IS6gZmw+IstDMVkwOwkn2nKuAl9OmbzE:lxX3+vYfHAa8jFUt8IS//+I/V5JfHAab |
MD5: | 9D54593A6F5730116C74E85752326EDA |
SHA1: | 9D695AE0D7D3ECCCE026BE23734B07FA8156CEDB |
SHA-256: | 5C8E8C7CF0F2F8CF19CE1EEF01AE406B0CFA0A018D34C6F3638C470ECD482581 |
SHA-512: | B3B5AE38A9C332617C3E6CC54695B42C43996A89209736915FDEEB86C57E5170B05E90FADDC6F27BDD11B50537E6BD68DEE9D0AEEC83331A22FC7C22F98BC8C4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.113460948199404 |
Encrypted: | false |
SSDEEP: | 6:lxXSDM+q2Pwkn2nKuAl9OmbzNMxIFUt8IS6gZmw+IstDMVkwOwkn2nKuAl9OmbzE:lxX3+vYfHAa8jFUt8IS//+I/V5JfHAab |
MD5: | 9D54593A6F5730116C74E85752326EDA |
SHA1: | 9D695AE0D7D3ECCCE026BE23734B07FA8156CEDB |
SHA-256: | 5C8E8C7CF0F2F8CF19CE1EEF01AE406B0CFA0A018D34C6F3638C470ECD482581 |
SHA-512: | B3B5AE38A9C332617C3E6CC54695B42C43996A89209736915FDEEB86C57E5170B05E90FADDC6F27BDD11B50537E6BD68DEE9D0AEEC83331A22FC7C22F98BC8C4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241025150322Z-171.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71190 |
Entropy (8bit): | 1.025755477162734 |
Encrypted: | false |
SSDEEP: | 96:vkkCyz6jMnpnv6YNwMMPMMMMSUnMM9vEB5xxFsp3EHmflAMMUMMMyMMEUM4MEMM9:vrPE8HKge |
MD5: | EE4187A8B79383624360F42AD45559BC |
SHA1: | 6761DF105612BC66A05DD941E034BB0F654984DD |
SHA-256: | EB8443C289D299FF764B3A29F538C696686DB62E331F5B6B7A36E52D0FEC83ED |
SHA-512: | C7028829C83D4C1D4FCA9D3A845E3DA66CE5D17AE5BC69CB009E35DBAB6E28961375DB7E0ED93D5478BB17CE9A1A0B01CCC124A3AC819E6167B16C3E9D9A4B95 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444921300683469 |
Encrypted: | false |
SSDEEP: | 384:yezci5tkiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:rTs3OazzU89UTTgUL |
MD5: | EB60BECA4639BA27A08E6E80A6C3FBA5 |
SHA1: | 23053F1F0DE699F7C1DD0FE72F931CDA3E167A04 |
SHA-256: | ED160B7309036A4555B4DEB6ED3B95A3884E7E631E8DCBB7BED7F4138C77F016 |
SHA-512: | 050B948A5671846CC9E1CC595294F0CED76AEC955AA461799792D9C4B370C66F668721EF3081719315F3A1C44B8B926FE58BB24584170EB1460F84AC8F61BE54 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.772109723282363 |
Encrypted: | false |
SSDEEP: | 48:7MDp/E2ioyVaioy9oWoy1Cwoy1OKOioy1noy1AYoy1Wioy1hioybioywoy1noy1c:70pjuaF1XKQNRb9IVXEBodRBke |
MD5: | 754073D00B94C907A8D5CB92D33ADA4F |
SHA1: | F215924B7F944E04882FEB72F154F6D55BBB38E9 |
SHA-256: | ED526B5054CF078204DC19604152BA9BA6D2A1FE2DB6FA76294CA49B8DE27556 |
SHA-512: | 41B546FD18C1F17858559FD2C839BD8BF494E5FDB8D599ADCFE95585D4B8BD77D89D4225014438DAB2CF9F79E34EB4188F87BB3EB7E8B7567C5B8D57BD71EA7D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.779094196322516 |
Encrypted: | false |
SSDEEP: | 3:kkFklMMkNttfllXlE/HT8kkXzXNNX8RolJuRdxLlGB9lQRYwpDdt:kKVMEteT8ZzdNMa8RdWBwRd |
MD5: | E69D5BD918BE9665278B99FD07431F99 |
SHA1: | 904D8E6E05EA01CC75DE63BC1F4039CFEE741556 |
SHA-256: | 6FB32FB14A1508A6C3391DD5E77FC85C95A71D8055603879805EEEA5E8207341 |
SHA-512: | FD31120AE6590E18940A84DC65904A858F515CDFC8DD3E43AF81CC8C7B840FB928A6257BE7101B6BEAC96DBE1FDE266CCEC95FCF42A6C1704AD445F094A023B4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 243196 |
Entropy (8bit): | 3.3450692389394283 |
Encrypted: | false |
SSDEEP: | 1536:vKPCPiyzDtrh1cK3XEivK7VK/3AYvYwgqErRo+RQn:yPClJ/3AYvYwghFo+RQn |
MD5: | F5567C4FF4AB049B696D3BE0DD72A793 |
SHA1: | EBEADDE9FF0AF2C201A5F7CC747C9EA61CFA6916 |
SHA-256: | D8DBFE71873929825A420F73821F3FF0254D51984FAAA82E1B89D31188F77C04 |
SHA-512: | E769735991E5B1331E259608854D00CDA4F3E92285FDC500158CBD09CBCCEAD8A387F78256A43919B13EBE70C995D19242377C315B0CCBBD4F813251608C1D56 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.351131161776853 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXo3rGPHJ9VoZcg1vRcR0YmoAvJM3g98kUwPeUkwRe9:YvXKXobEHJEZc0vmGMbLUkee9 |
MD5: | 84A078F5353A48539AA0EA0C08699D03 |
SHA1: | F2F8DD2963647A4225A8FABFA867A544A0CE30F8 |
SHA-256: | FB7907C9E4D818D4677A30EF55A337DC5A28668F5FC2EFBDB3F517023F0AE9BA |
SHA-512: | E4B00DA2D5FA97E2E22ABD11F35500A1D4789D3D6B9A19BBF0842209D99A5399C50E6F02934B2B726F5946A13C9AC3914662839C1AB47C8CCA80547B848F932D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.299650279380933 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXo3rGPHJ9VoZcg1vRcR0YmoAvJfBoTfXpnrPeUkwRe9:YvXKXobEHJEZc0vmGWTfXcUkee9 |
MD5: | B06653893102187B84792CE2DDF131B5 |
SHA1: | D4A543AA4F39C2F0E79AB8321A31AAED4D60F1ED |
SHA-256: | 2FFD7E11561949D0AF1B1AFDCF7AFC46852879657513623EFA3EDF0874A41F4C |
SHA-512: | 977FC11E2FFFA8AD5A6F4B6D0333A71A509939B134A7787899146640727A6B2FFF63099BACC8C9DFB566C2F6AE2882628F5E4F1B51124DB7E778A4110C2BE036 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.277789194126201 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXo3rGPHJ9VoZcg1vRcR0YmoAvJfBD2G6UpnrPeUkwRe9:YvXKXobEHJEZc0vmGR22cUkee9 |
MD5: | 9695C41C92D91F755F42E35DBB859162 |
SHA1: | B3A87DBE2DD2348FA058085979E65491157D8FC2 |
SHA-256: | C4CD3B4F22A95220970AC5F2586F736752B8B31A78C22A63D5BEDF3E88782BBF |
SHA-512: | C6A124CA0D22C22F1F8A0C1848CDEA02689FB3220721A8A97396B66F68B12C6E5EE9A6397FEBA2106EAED526FF59C57F12C11F3C931AECECBCE66D8BFCBEEB87 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.337712467110947 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXo3rGPHJ9VoZcg1vRcR0YmoAvJfPmwrPeUkwRe9:YvXKXobEHJEZc0vmGH56Ukee9 |
MD5: | 3001BE137858FC693D1D70A8F2474E4B |
SHA1: | 8D7F79210412E75E8838A3687BE7341723DF1868 |
SHA-256: | 4CF06146E7048B7DD9730729624F116EC6737CF3C29F57E11985BE96B2ABBB37 |
SHA-512: | 928C4627BB95F4B7B20F5A03F4E39B6F790D9AB0DAC5B2AEB9A2716CCB2959B8D2879DBBE8163FE4726A7678FCBBC073014B8DCDE268C4C68305931BD437DF37 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1055 |
Entropy (8bit): | 5.6599410185233525 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xob02zvzpLgEscLf7nnl0RCmK8czOCCSBaY:Yv5b0ubhgGzaAh8cv/h |
MD5: | F1D325F078E2530A95C89DCDD4CC2BF8 |
SHA1: | 97A224AECB9DB66CD1E49ED48BD7FB60799C2A5F |
SHA-256: | 23EB4590EE118946BD81162DE055FB7A9116D05FE1B05695242FC595970E4D82 |
SHA-512: | E65E5E8C0C9878DA80DBC50025E1F22AF7D39B991846AA52E0E365F0350E67EA840CBFB97E027D825E67D7495D02D744AA964C26EF4B1AD07EC4BB67A2222ACB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1050 |
Entropy (8bit): | 5.6510371818167195 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xob02zvvVLgEF0c7sbnl0RCmK8czOCYHflEpwiVIaY:Yv5b0uXFg6sGAh8cvYHWpwh |
MD5: | C29552D441EE8260448E16A125C99E8E |
SHA1: | 4EADD8EEDB435D1F6D33598932D08FF918EB1825 |
SHA-256: | 18C1925DCA5B55708FF812D2152555274F63FEB7DB0502269EE4909A61A3431F |
SHA-512: | E183F8CAAC55AB62527EE92753D1D34E2E45BB39C111721EE27CAC54EC719140DB7F55734A9F777CB3E3CFA038D5D2957114AB95E263B321DAE0C5B8E02B4F9B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.287583702236033 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXo3rGPHJ9VoZcg1vRcR0YmoAvJfQ1rPeUkwRe9:YvXKXobEHJEZc0vmGY16Ukee9 |
MD5: | D938EFE1D6012DEFF28F9995B032D017 |
SHA1: | 726BC6A2942C7B8AC8F3B49226A3B3682989D3A2 |
SHA-256: | 286FFD71D7E35E4FCF7C981148403B2D09F107ABB169D4F47D99A834D7D86010 |
SHA-512: | FA25F95A490305CD098AE0083CA5A7E5B50259AA54C5EDF1C8E24516690BBA131AB838947BBCFF9EEAD2938F7BC44E9D0CFD763F57B49FE4A4A34B2575AA3089 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1038 |
Entropy (8bit): | 5.644359601671782 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xob02zv+2LgEF7cciAXs0nl0RCmK8czOCAPtciBIaY:Yv5b0uGogc8hAh8cvAy |
MD5: | 4D350DFF04EE98B4FCADFDBAD6CC3183 |
SHA1: | 8A9C21FD310960D78B509AA2BF181DD5966A8054 |
SHA-256: | B8C72FC986E860E55776C96296D48D31D075489B790A678434A4738D6C8F6DF6 |
SHA-512: | BA51CC1232BBB138D18782FA4B04CE70F2325019B69A22AA41D05D21A1F0725392BF7FCBE8DB86C924B78773F6920FE8C115D6EB3B903E8B44645D537AA34C38 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1164 |
Entropy (8bit): | 5.699049584728699 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xob02zvyKLgEfIcZVSkpsn264rS514ZjBrwloJTmcVIsrSK5IaY:Yv5b0uqEgqprtrS5OZjSlwTmAfSKO |
MD5: | ADAB80C76A5A12E3E380974F31FD64A7 |
SHA1: | A2C52C1FB030F085EF546D3E1F53B7224CA3E0A2 |
SHA-256: | 938CFCD9FB6058F4B7F523B6FDDA7FB9BE9532E5971F909D7E58EA512A4BAC8F |
SHA-512: | A2E89F81487C0B4C7D90B91BCC9195FC1E1197AD4E638BB2D101418CF115B1E25C0EADE1AA50729A3FEF53A04D62F7CC475ECDE0C465E89CB55FFC476C6041FB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2905710200901535 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXo3rGPHJ9VoZcg1vRcR0YmoAvJfYdPeUkwRe9:YvXKXobEHJEZc0vmGg8Ukee9 |
MD5: | 2FBCE431A3AED56EF24B46E9DEC3F95A |
SHA1: | 5012BB380B159C5191BA08C837F1D4E77D0C7132 |
SHA-256: | 90FD0FF0E8E084C824AE07AFFB501890F0829A4A561508C3E5D80BBCFF310762 |
SHA-512: | EEAA46950D1509BD1816C28AE165301FE08007E9E13C568CE003A212E54EE9BE91DF50A47280EBAFEADAAE01BC6608615C05899BAEC08502A93CC601AC9096C2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1395 |
Entropy (8bit): | 5.775427116945337 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xob02zvxrLgEGOc93W2JeFmaR7CQzttgBcu141CjrWpHfRzVCV9FJNgaY:Yv5b0uZHgDv3W2aYQfgB5OUupHrQ9FJO |
MD5: | 37C27D1FB13F89C9BA979A75BAB6EBAA |
SHA1: | BBD31EBF59C869BD04E62CFD14BA9697E7A78011 |
SHA-256: | EF72CB2375D9411ABD174EA764DA8F08D8F50DB8F0E6F1FBF0293133A5D2BEE7 |
SHA-512: | 9BD8B543943E1DCD2309A2BDAE7DD9DFE3397A1AF56E863241966BF9ADFC739EA467D7704A90748C96DB2D72D5248BC04C75506B893E65D5025538CCD6800185 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.274182921749652 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXo3rGPHJ9VoZcg1vRcR0YmoAvJfbPtdPeUkwRe9:YvXKXobEHJEZc0vmGDV8Ukee9 |
MD5: | 3A61F291393DCEA84C5313824A4A8901 |
SHA1: | A0007A670C6F8A2D4BC7D8DE284DC230E3C0683F |
SHA-256: | A142D830908594D4FBEEA895A23ACBE881DEF03263FC55F265B1B47BE1ECA8C3 |
SHA-512: | D1F7F02435B9A31F39BC903E9D3FAD02CB6D33CB9ECBCC6617EE12A5AE2EBAC3053B6D496FE3D98DB7BAD5A9BD5AD87B1D65CBEE0B59E8C5E04F65AB6E65DC44 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.278389482612077 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXo3rGPHJ9VoZcg1vRcR0YmoAvJf21rPeUkwRe9:YvXKXobEHJEZc0vmG+16Ukee9 |
MD5: | 8ACD7DEDDB1DA7C1E396EAE8A34D0951 |
SHA1: | E20D5E46D807489E7398323CD77B34883B896B96 |
SHA-256: | 8FFE59B1CE79DDCFBB48160317752A7B49E4C7856FF3134A3A5C8BBF29B61FAB |
SHA-512: | 2991F26C9CBAFA5F4B311C9A36DE34CC381A9AE21605D32BFBF0EF7DE77F4EBBD661E8486334C7A3114E74D10213836101CB1817CD8F3E4E5C1CCA9D6F914570 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1026 |
Entropy (8bit): | 5.630197490687464 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xob02zvDamXayLgE7cMCBNaqnl0RCmK8czOC/BSBaY:Yv5b0urBgACBOAh8cvMh |
MD5: | 188A80ECCF9B60B7A843EA970BC26EF0 |
SHA1: | 1F0BE27AAC1AB0B8F2C132E9E50E52634A0DB436 |
SHA-256: | A702671B6963A58BC4758A728748800DF74B64685A7B3CE746F910C06859A064 |
SHA-512: | 833A59CB01483C4EAD4708CC49F8758DC0C7E75797F1CCAF29986137628A2207A6FE488AE084ADA17CAF2157473C8C7F5519004FD36D9D2241DCF4C545EE8AFE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.254312010997097 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXo3rGPHJ9VoZcg1vRcR0YmoAvJfshHHrPeUkwRe9:YvXKXobEHJEZc0vmGUUUkee9 |
MD5: | 9B0D035A04629A9847C0C62160FEC7AA |
SHA1: | 51967C83EC10526E744BBC982B0A96DD0C6E3440 |
SHA-256: | B3993C7A7F025F7D88E0C652233BDA38ABCECC955F3209E5F5DD6ACA795E761A |
SHA-512: | C7510A6152470D86791D5E3300149B7440C6D0B2E8BDE01A55ACE94F4FA36E651E042A5B574465D19AAA511AD1F8FF825949F07FA280CFD73FDE345785C9DADB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 782 |
Entropy (8bit): | 5.365030889014941 |
Encrypted: | false |
SSDEEP: | 12:YvXKXobEHJEZc0vmGTq16Ukee1+3CEJ1KXd15kcyKMQo7P70c0WM6ZB/uhWkQJY:Yv6Xob02zvA168CgEXX5kcIfANhBaY |
MD5: | 6C1C28C06EB909CBC063D1D63B34F971 |
SHA1: | 57C108FA520083F887B7C8215A5C698606F4D922 |
SHA-256: | A792820A0A24D52642D9360CEA6F6EA644AFB23D4645FEFCCA06140EA3A93AA4 |
SHA-512: | 869BA8D9EC15BF90217C6D5CFEE905EC6FC6F1061F8B95F3CC0B2BCE9B6EE757909553C7FA772F6B5F72AD9553E7F0E7F640F663988EFE819A6AFCC9382A2660 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2818 |
Entropy (8bit): | 5.136195882869241 |
Encrypted: | false |
SSDEEP: | 24:YvxsaUjq6a2mKqayfoShbNkINC94DTw91rab0kv72B9izj5IdHWvj0SYDL//e2W2:YvOJVU/qSe1r9k685v7PWR6gRg9wPi8 |
MD5: | A2F655BA3FD646D7D9819ADDAAD2220C |
SHA1: | D3FA4F476E0C2935019527A0556CA892D3B71825 |
SHA-256: | 3C050FA6AB12F5A00A611D32FDD469DBB5838B288A581A520EAA813A85B17714 |
SHA-512: | CE926370766A9981E7B3EE26A9C53DE1944EBEE043D3273DB65607C1FB72F04F73B613AF6206DAD9E8CDB8F37A866D18CBF256D25E7545A39DBE3CB1D6A0F01B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1887957016612944 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUsjSvR9H9vxFGiDIAEkGVvpI7:lNVmswUUUUUUUUsj+FGSIts7 |
MD5: | 27E88F037228345D47A80E4CFFDE1F84 |
SHA1: | EE552FAB21E80A53582876D28B14877DE6B24149 |
SHA-256: | 044D53EC99E7155A3B677814A4A11222AA77B8B8018B22FC569E4197D188787C |
SHA-512: | 4A08AEB43DE3EE9E0C51757E8BCC53239E5059AC52ABFAA189152873A26EA8F37B46F89CF453D24A9AB2838DEF5FFCF0202BA21D012F1182E955BC554AACB6C1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6048009149843492 |
Encrypted: | false |
SSDEEP: | 48:7MQKUUUUUUUUUUsHvR9H9vxFGiDIAEkGVvcqFl2GL7ms5:7wUUUUUUUUUUs/FGSItmKVms5 |
MD5: | C15F3420EEA50D9F0A7665AFBD1A8734 |
SHA1: | AE33B9C854A12753BEFD6F2BE75A5CB930D9D342 |
SHA-256: | C861435701883D599FCA409F7134B58B8FD487FA58F4D7B120AB1DFA6F3488B0 |
SHA-512: | B4C40AEBD5042C3448765B8229C1EFAAE4A87F9FE7331D36A18FE679A191126D19B3B8177908C530DD62AAB04A1ECCA935D58E8F76C7DBD4655FCA154E9ADF83 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5097251598291805 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8jqHl2:Qw946cPbiOxDlbYnuRKt2 |
MD5: | B3CF025B7520DE3BBCE43561F9C3B406 |
SHA1: | FC33C8771172CE4170B330B9310A560DA9A87D2A |
SHA-256: | ECC68E77E4A0EFDB8EE20CFCA1F1BBD0FF8DDDD5293C6DD7B94329D14B30FF5A |
SHA-512: | 7D82973F4658FBF315A921A3B9C76576AC7D3DE266901B280CB27040B3C3AEDF006847470F5FF1AF59E7D24050672F6653EBD007243966FC6F16139D1CF6A346 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-10-25 11-03-20-192.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.328003842783904 |
Encrypted: | false |
SSDEEP: | 384:euHzGzjyAYhYkhG8L2kfIIuwMM3UY2EsunQLXRZJnOm/NjUfycJ0GclcxoN7Wk5+:wLs |
MD5: | 2C44B87894D137DB5C68FEF10ED3052E |
SHA1: | 0693EDA52371EE2E6265D56F81291384DA69E700 |
SHA-256: | AE3FAB0A4F78CC7BE531611D37F8ECF32A54F888E79D79A7DFB067D8DDC389E2 |
SHA-512: | 3A5543CDBFBA89BAC46676B7FC0F9B9D93706A633E17AEE0D9FD5B7C55F47A9F07789F891F5E1DE026CF1931E1037E3633D8370338EA04A38DBBDE7BF2AAAC5F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.381650761495515 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rQ:U |
MD5: | 5A7653393923657B59EA59BFE87371BB |
SHA1: | B9933773184A692D5800B85F80362EA1F93FEDC7 |
SHA-256: | 03BAACD61B8E742CD81012CB21A38F362D8F879F2A70816E1E29C8C992DD39E6 |
SHA-512: | 06634605FC6297CC5C1AE06E2F4A76E794D72928F1A0A1D96B68150F7DF07551D0BEE7CAD2D147B833724F0D45936FCFCD6E4E41BEF590FBE95883B2B373C529 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZjZwYIGNPJe:RB3mlind9i4ufFXpAXkrfUs03WLaGZje |
MD5: | 716C2C392DCD15C95BBD760EEBABFCD0 |
SHA1: | 4B4CE9C6AED6A7F809236B2DAFA9987CA886E603 |
SHA-256: | DD3E6CFC38DA1B30D5250B132388EF73536D00628267E7F9C7E21603388724D8 |
SHA-512: | E164702386F24FF72111A53DA48DC57866D10DAE50A21D4737B5687E149FF9D673729C5D2F2B8DA9EB76A2E5727A2AFCFA5DE6CC0EEEF7D6EBADE784385460AF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/nZwYIGNPgeWL07oYGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:fZwZG/WLxYGZN3mlind9i4ufFXpAXkru |
MD5: | 1F3D69524A9D7E17BD2363C81D130F1A |
SHA1: | C2A4A08839CBA47BEE2B601975F7C4F0CC191091 |
SHA-256: | D0FFBEC8502A0BE88A99F6708987658FEBE4CF3B6B79AF219C53EFF6458F9D9D |
SHA-512: | A4CBE7073A7CB4C5E33E1CD903CCD7F24B78A04C037BFA1D90D9A5BBD12AF60E3DFFD6546277D1B765CA1DAC1CDA28D24D3454C81952B72D97CAF84DF395E99A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.21105379295891 |
TrID: |
|
File name: | Dr. Lindsay Chropractic Corporation Spine Fit Rehab & Wellness (24-10-2024 - Submission).pdf |
File size: | 889'637 bytes |
MD5: | 3eeac61ae9da7c2d2084d0faba3be42e |
SHA1: | e44d7bc5cb1440d56a55d34336b951ac0043d52d |
SHA256: | ba8a07ae916344599fda196821b2521ac936e3e7ff3195061bbfb5706c25b2a7 |
SHA512: | 23b14dc91fd58f0340d7362df8c2131b2858dbd065272faf2420b5b0ac999f63d70bf524dd7a235cb45bf91f2e76b2c4d910267bde98d61d8161f6ca713c898d |
SSDEEP: | 24576:Jly0O1702RfPTTy0QLJKrc3f30F5HsfrGehZHP54Ao76s9Tl:JEhNXTu4P |
TLSH: | 1315010B956A0FDDDB7397B2191A4AC89BADB380D4F6A55CF01C4C43EF94B3D84C6826 |
File Content Preview: | %PDF-1.4..%......1 0 obj..<</Type /Font /Subtype /Type1../Encoding /WinAnsiEncoding /BaseFont /Helvetica >>..endobj..2 0 obj..<< /Filter /FlateDecode /Length 49 >>..stream..x.s.....0...r..5...Q.P.I.2P.)V..E ".D.s..p.. `.....endstream..endobj..3 0 obj..<< |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.4 |
Total Entropy: | 7.211054 |
Total Bytes: | 889637 |
Stream Entropy: | 7.215120 |
Stream Bytes: | 868963 |
Entropy outside Streams: | 5.140080 |
Bytes outside Streams: | 20674 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 123 |
endobj | 123 |
stream | 61 |
endstream | 61 |
xref | 1 |
trailer | 1 |
startxref | 1 |
/Page | 16 |
/Encrypt | 0 |
/ObjStm | 0 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
44 | 00044d0c5b552480 | 68eb01dac4e91d95a35c7052a6eb8ac8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 25, 2024 17:03:31.231611967 CEST | 64799 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 25, 2024 17:03:43.625544071 CEST | 61659 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 25, 2024 17:03:59.469923973 CEST | 63851 | 53 | 192.168.2.4 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 25, 2024 17:03:31.231611967 CEST | 192.168.2.4 | 1.1.1.1 | 0x3fe9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 25, 2024 17:03:43.625544071 CEST | 192.168.2.4 | 1.1.1.1 | 0x918c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 25, 2024 17:03:59.469923973 CEST | 192.168.2.4 | 1.1.1.1 | 0xfbd8 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 25, 2024 17:03:31.239871025 CEST | 1.1.1.1 | 192.168.2.4 | 0x3fe9 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 25, 2024 17:03:43.632983923 CEST | 1.1.1.1 | 192.168.2.4 | 0x918c | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 25, 2024 17:03:59.477533102 CEST | 1.1.1.1 | 192.168.2.4 | 0xfbd8 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:03:16 |
Start date: | 25/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 11:03:17 |
Start date: | 25/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 11:03:18 |
Start date: | 25/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |