Windows
Analysis Report
Specification Sample.........pdf
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 7320 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\S pecificati on Sample. ........pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7508 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7716 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 12 --field -trial-han dle=1596,i ,127157734 1298501162 8,19191905 0831672604 0,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1544425 |
Start date and time: | 2024-10-29 12:08:19 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 14s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Specification Sample.........pdf |
Detection: | CLEAN |
Classification: | clean0.winPDF@14/50@0/0 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 2.19.126.143, 2.19.126.149, 54.144.73.197, 34.193.227.236, 107.22.247.231, 18.207.85.246, 172.64.41.3, 162.159.61.3, 192.168.2.4, 93.184.221.240, 2.23.197.184, 88.221.168.141, 23.47.194.80
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, e4578.dscb.akamaiedge.net, acroipm2.adobe.com, wu.azureedge.net, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, fs.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, ssl.adobe.com.edgekey.net, armmf.adobe.com, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: Specification Sample.........pdf
Time | Type | Description |
---|---|---|
07:09:34 | API Interceptor |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.181978853752956 |
Encrypted: | false |
SSDEEP: | 6:c0cfEOV+q2Pwkn2nKuAl9OmbnIFUt8H0cfGuPZmw+H0cf4kiVkwOwkn2nKuAl9Oe:plQ+vYfHAahFUt8UuP/+UyiV5JfHAaSJ |
MD5: | 7A69F6B54B9A07CF16B8F91FFBB4D181 |
SHA1: | 9F0CE850C4C602F9CF496AAA6557DD1FE23AF841 |
SHA-256: | B68607D7B8C86FDE1E747C9A1E6E19E7DA5039A6DE2525F3B2AD8353E205EB39 |
SHA-512: | 232208D2805BD76CEEDC6082099131B641B86AC237227D1C0A53E9596125B6EFF64305E2F323EB7428696B6E3426CE8A0ABE46BF993C58787720C0C6B540FC74 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.181978853752956 |
Encrypted: | false |
SSDEEP: | 6:c0cfEOV+q2Pwkn2nKuAl9OmbnIFUt8H0cfGuPZmw+H0cf4kiVkwOwkn2nKuAl9Oe:plQ+vYfHAahFUt8UuP/+UyiV5JfHAaSJ |
MD5: | 7A69F6B54B9A07CF16B8F91FFBB4D181 |
SHA1: | 9F0CE850C4C602F9CF496AAA6557DD1FE23AF841 |
SHA-256: | B68607D7B8C86FDE1E747C9A1E6E19E7DA5039A6DE2525F3B2AD8353E205EB39 |
SHA-512: | 232208D2805BD76CEEDC6082099131B641B86AC237227D1C0A53E9596125B6EFF64305E2F323EB7428696B6E3426CE8A0ABE46BF993C58787720C0C6B540FC74 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.2001652243572885 |
Encrypted: | false |
SSDEEP: | 6:c0cf+bIq2Pwkn2nKuAl9Ombzo2jMGIFUt8H0cf+4Zmw+H0cf+/JkwOwkn2nKuAlx:pLIvYfHAa8uFUt8Uo/+Ux5JfHAa8RJ |
MD5: | 82577FBD712531BD861AF06617CB312B |
SHA1: | D15A81C32095042D40CE3A9E02514EEC1747378C |
SHA-256: | 4543AD58B82695C0D2C145953FFCC0AE8CE0E91D7F557C54316B18172BA26AC1 |
SHA-512: | C9AA7530750956C3237E60FBE81C5C3F1503949E399195CA0E4CD7D16099CC4DB7E2917B5183A6ADE4E384B5F595467C00DE4C10959B9492F51405D1A64C8E54 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.2001652243572885 |
Encrypted: | false |
SSDEEP: | 6:c0cf+bIq2Pwkn2nKuAl9Ombzo2jMGIFUt8H0cf+4Zmw+H0cf+/JkwOwkn2nKuAlx:pLIvYfHAa8uFUt8Uo/+Ux5JfHAa8RJ |
MD5: | 82577FBD712531BD861AF06617CB312B |
SHA1: | D15A81C32095042D40CE3A9E02514EEC1747378C |
SHA-256: | 4543AD58B82695C0D2C145953FFCC0AE8CE0E91D7F557C54316B18172BA26AC1 |
SHA-512: | C9AA7530750956C3237E60FBE81C5C3F1503949E399195CA0E4CD7D16099CC4DB7E2917B5183A6ADE4E384B5F595467C00DE4C10959B9492F51405D1A64C8E54 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\9525c6db-19cd-450e-99f1-c1cd200b8d0d.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.970895562327589 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPxsBdOg2Hpwcaq3QYiubInP7E4T3y:Y2sRdsLdMHp73QYhbG7nby |
MD5: | FBD32379A5B7D1EA6DF6E136013608C7 |
SHA1: | CBB2AAABAD7C0E1C0794B6B00DD1F65A7D525371 |
SHA-256: | 330058D8656F80F762E675ACC13B64383F17703C38F1CEAA5BA0BAADB6FBD171 |
SHA-512: | E9329E0415152B9BCB9025754A4091BE1B44A307F035F0AD1BFADE7EE13D957EABA730871CDA1440E60D714F8AB2699BFF72F294BA9050DCB7C84C273A55FFE8 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.970895562327589 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPxsBdOg2Hpwcaq3QYiubInP7E4T3y:Y2sRdsLdMHp73QYhbG7nby |
MD5: | FBD32379A5B7D1EA6DF6E136013608C7 |
SHA1: | CBB2AAABAD7C0E1C0794B6B00DD1F65A7D525371 |
SHA-256: | 330058D8656F80F762E675ACC13B64383F17703C38F1CEAA5BA0BAADB6FBD171 |
SHA-512: | E9329E0415152B9BCB9025754A4091BE1B44A307F035F0AD1BFADE7EE13D957EABA730871CDA1440E60D714F8AB2699BFF72F294BA9050DCB7C84C273A55FFE8 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4730 |
Entropy (8bit): | 5.252763607082367 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7diLRFZ:etJCV4FiN/jTN/2r8Mta02fEhgO73gow |
MD5: | A2169AF7130CE8A49B7C22D878932FB8 |
SHA1: | B8D7CA02B9AB955C69D877437FC98ED67098E43A |
SHA-256: | CE29D2E8DD2C372192C3124FE3A106F77DDF83017F379B658A25DEE5AFB2FD5D |
SHA-512: | 15202DBF6A89C98749950AF7AAE245A48DB8A56697A0B5C7344A59C3513E41F0FE3002517B65C20DBCA21145255353C51528AE56A7CD66D26900874757A65E21 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.142809910283548 |
Encrypted: | false |
SSDEEP: | 6:c0cfHhWyaq2Pwkn2nKuAl9OmbzNMxIFUt8H0cfHhJ9Zmw+H0cfHhJPkwOwkn2nKA:pQOvYfHAa8jFUt8UQ//+UQt5JfHAa84J |
MD5: | AF57335213699B607755C93952ABE9C1 |
SHA1: | 538E5331957556EDEACDE81A8DA46083FD02D849 |
SHA-256: | 02F431F5DBEFCA1CFFB0FF9FF2C58BC9806A7D9A4ED73000BC0216D9A4D08082 |
SHA-512: | 3A7CDF30309ABD08C2CC22CB1BD9FA543065BF89F810D12F641FD4E5D7BA232C11B58E0F784924D8920AB7C29EDB978D7BEB0F10DB36A62819F09F868C9A1B76 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.142809910283548 |
Encrypted: | false |
SSDEEP: | 6:c0cfHhWyaq2Pwkn2nKuAl9OmbzNMxIFUt8H0cfHhJ9Zmw+H0cfHhJPkwOwkn2nKA:pQOvYfHAa8jFUt8UQ//+UQt5JfHAa84J |
MD5: | AF57335213699B607755C93952ABE9C1 |
SHA1: | 538E5331957556EDEACDE81A8DA46083FD02D849 |
SHA-256: | 02F431F5DBEFCA1CFFB0FF9FF2C58BC9806A7D9A4ED73000BC0216D9A4D08082 |
SHA-512: | 3A7CDF30309ABD08C2CC22CB1BD9FA543065BF89F810D12F641FD4E5D7BA232C11B58E0F784924D8920AB7C29EDB978D7BEB0F10DB36A62819F09F868C9A1B76 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241029110925Z-160.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71190 |
Entropy (8bit): | 1.2422095750571964 |
Encrypted: | false |
SSDEEP: | 96:MJ4HMWY6b9B/R/Q9Nhfqu6LxxAYmrlBKD7QDGiNRt2IdtpSd/AMM74L1MMOMCpHF:9ZpY9N9qTmrrKDsDGid2vW4FSX0Vja |
MD5: | 9837849FB2060D183D66EF85E3B3D671 |
SHA1: | C2F6FD7BE80BE2B054F95F143CCF41D48270F2D6 |
SHA-256: | 5499B33BEEFE768026421315BD4BBEA094B9E1D52C1EC29C1FA290B53DC99454 |
SHA-512: | F253D9FCF780D5F7D644DD299D15635EA45FD418587E3BD1317A2C3C5A6334867CE926186B4EDB1888919AF7ECAAF25BFAEEEDD64ECAA13F11C88357F1307E29 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.445000786873078 |
Encrypted: | false |
SSDEEP: | 384:Se9ci5tAiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:hXs3OazzU89UTTgUL |
MD5: | 4EA5CB1C33562FC7DF6EB55DE2E5BB22 |
SHA1: | AA8722D2ACAC080E1DB13EFFD610A29D3BA17CB6 |
SHA-256: | 65DAE4133956455E75EBF5AD3D159E5D3ABC62766404FB56223D5A5478EC0C21 |
SHA-512: | C66E6799F82F5AB04DF10B15E797D7A77309D5857AD2D364C557D35BBD3535CFB7999E7732DFA351B8176E179D97C95AE29223B6455BED7E0216C4ABC8441AEA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2147259398789383 |
Encrypted: | false |
SSDEEP: | 48:7MfVHnClqvmFTIF3XmHjBoGGR+jMz+LhA:7w1nY79IVXEBodRBkC |
MD5: | 8DC4DA98EB78BC9F2C2B941D18730A77 |
SHA1: | 277B3BD95E71FF6CDF205A085E2EF5180AF99CDE |
SHA-256: | 8FB349B45D3447AF677193854AC7C64C1F5575C613885B518EF4981256C40862 |
SHA-512: | 667296F8DD7755E5AEBAFA818928AD9C23C6ED6A93DB562A9B0E6F97C9ACF8128E67D79B9B29243F5F08767CD525BF2D78B31B96E12A58EFFB80794D9E64809B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7386214950254373 |
Encrypted: | false |
SSDEEP: | 3:kkFkl57K/kNttfllXlE/HT8kE/ltNNX8RolJuRdxLlGB9lQRYwpDdt:kKBEteT89VNMa8RdWBwRd |
MD5: | CEBF630D81AE85A6687873BA6B74F48A |
SHA1: | 7C4F1F10CCEBCE1B40EEAF4DE0925C3EB7D29E0C |
SHA-256: | A9FD5C43484CF501B440DEC4846D8D68E924E28E8864173B07DFC24138A231AD |
SHA-512: | 91E90C423CE4C6F2888027D69799540C407B9A9BC0AB34241E7DE69E07902BAD0A1B94C0E06248F51F848B4E82732C1FAA2889008A1E87F121762F321BB35D9C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.150184159866504 |
Encrypted: | false |
SSDEEP: | 6:kKZlPL9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:ziDnLNkPlE99SNxAhUe/3 |
MD5: | 6120B9A1333277F623AF0F88B93C1444 |
SHA1: | 6FBBEB531FC6B13295A9F8E626BA92FFB302BC15 |
SHA-256: | 15B0FE99D1710D8BA54EBB61D7137BAF225779356E0B69C9A86ACEEC94A4E7DE |
SHA-512: | CE97149F4E18803A17B4EE1740104CEBFE412651F64A2127F8A6116926FDEAE57CFD11DDB96161B9952C77F54C2942A0D3DC8821F2F245CD9530C7DCA16755A7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 243196 |
Entropy (8bit): | 3.3450692389394283 |
Encrypted: | false |
SSDEEP: | 1536:vKPCPiyzDtrh1cK3XEivK7VK/3AYvYwgqErRo+RQn:yPClJ/3AYvYwghFo+RQn |
MD5: | F5567C4FF4AB049B696D3BE0DD72A793 |
SHA1: | EBEADDE9FF0AF2C201A5F7CC747C9EA61CFA6916 |
SHA-256: | D8DBFE71873929825A420F73821F3FF0254D51984FAAA82E1B89D31188F77C04 |
SHA-512: | E769735991E5B1331E259608854D00CDA4F3E92285FDC500158CBD09CBCCEAD8A387F78256A43919B13EBE70C995D19242377C315B0CCBBD4F813251608C1D56 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.356587010574356 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBDVVvOi+HoQqIH9VoZcg1vRcR0YMSUoAvJM3g98kUwPeUkwRe9:YvXKXBDVxF+HoqkZc0v1SnGMbLUkee9 |
MD5: | D044C6A2BD484EBB53FDEF2B6010624A |
SHA1: | D6DF9D40243443428DBA5DC479F83FC85D90C081 |
SHA-256: | 398AB1377E98B689D11AA28B998A579F0752D54ECB2D6CF93067656A9A3EF114 |
SHA-512: | A4E3F0FFCFCC8ED2FC51835E16117F146D4E3309F20CD93BEEEA86B6F422ACC31842F0852CBB20BBFDD5E6E340C315707B2914102021DD9221F0A69147543DEC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.305478480655702 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBDVVvOi+HoQqIH9VoZcg1vRcR0YMSUoAvJfBoTfXpnrPeUkwRe9:YvXKXBDVxF+HoqkZc0v1SnGWTfXcUke6 |
MD5: | 9D7D76BA9CE52FB4F8344D6135D13E88 |
SHA1: | 3137B61583C0AA61DA5659B4C1C1EC04B75DEA6E |
SHA-256: | BCDAEF8D520CFC5E36380FA53EE9E81891622243FB59F1CEC7EF0714033FECF6 |
SHA-512: | 938407BA4DB73582B13F5D9A332F5CC6C0F90137585FEDD2B53905FEC5869B1486EC1D711650AE836A8BD0A5A1420B0C117A99DF0AC5424BB8D7CD68E5F43084 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.283617395400969 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBDVVvOi+HoQqIH9VoZcg1vRcR0YMSUoAvJfBD2G6UpnrPeUkwRe9:YvXKXBDVxF+HoqkZc0v1SnGR22cUkee9 |
MD5: | 1F9237F2DDC74CD218D026F2494782B7 |
SHA1: | 7C15A3E7823040AA398BB6A1C917184722E3AE9F |
SHA-256: | E0DB836DAD35974A1C6F2774B805747C6B3401F1CAB0E2726B41D2C49A73C8F9 |
SHA-512: | 207AF001DFAE528649FF50BCBF00B658C163593E36F6572FE6B771B82820F8DB39502C52C9C0BFD7E70535450F03C937095561F9D9D4BDF2D5244D0E4691746A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.343359749199591 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBDVVvOi+HoQqIH9VoZcg1vRcR0YMSUoAvJfPmwrPeUkwRe9:YvXKXBDVxF+HoqkZc0v1SnGH56Ukee9 |
MD5: | CA1EE81654403842E8FFA7A8AA397559 |
SHA1: | F99D0D3788C64DD56688F2EC792B41F33DE92092 |
SHA-256: | 1AB89FED7EF62E33CBA9F1B9A0A2200690BB904FA709FCA6E7221A4A9885E035 |
SHA-512: | 1101508E3CB9EACBA873BB81CAC0C097230B109F03725E2764FF57D0CB7B4CC4938B8CD58639BCCE382EA4ED736F33CA3191D85B49687C0F44E6A63C52D82197 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1055 |
Entropy (8bit): | 5.660699481952072 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBlqkzv1SspLgEscLf7nnl0RCmK8czOCCSVG:YvElqsdSshgGzaAh8cv/VG |
MD5: | F1BDAB1AA080E8C3D53F3A3DB6E08F76 |
SHA1: | 259897ADBF49FE21BA937F8D98528F373CE7D13B |
SHA-256: | 2656EEC0278A54D52EF721575956FD4DCD559DAADB972823F359C43C513AEA51 |
SHA-512: | 0DF32D0D4AAAD136807FC2E93934F3B739A1E22BB8825EA92603A0210ED2A7BDDD0C843E03DD537AB2E694D6FA3378282CE96FF839275F6F1277838E5144BD35 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1050 |
Entropy (8bit): | 5.651705359537221 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBlqkzv1SGVLgEF0c7sbnl0RCmK8czOCYHflEpwiVoG:YvElqsdSGFg6sGAh8cvYHWpwVG |
MD5: | 67BD011C495549B24EB2F11354FF0C34 |
SHA1: | 9EEE64A16A750E75994ED9F6102E635E9FE6237C |
SHA-256: | 829F7DD2BC132F06DD20BC947DEA2CCE30AEC22463A3722D36AFFB25BFB6B2D0 |
SHA-512: | 7C4CC6F26FF47CAAE72A2193E58D4D4A75E31005338B181E2430887ED3DF8D111EF9FCA480997E5278A243CC7C2F1E99CCCD1767056FB6A26680BA66D436DFDE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.292456980041953 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBDVVvOi+HoQqIH9VoZcg1vRcR0YMSUoAvJfQ1rPeUkwRe9:YvXKXBDVxF+HoqkZc0v1SnGY16Ukee9 |
MD5: | 02D6DBCDAAE16944C5AF3D8B4F411E58 |
SHA1: | 71D0E8FC9DF4D5E5176A4DF025223D0FA54DAACD |
SHA-256: | A2AD21A0CD235132607092B7D6B071906D77025C398283825EA246904B673702 |
SHA-512: | 499E03EFBDB3CFF575234CBB966873EA526C5A5AC38D2BC1844BF15AC4BFBBBBA47E17B30FBD14CE650345F875D4B43251E66AA89774E89BFF0BF428C43F3866 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1038 |
Entropy (8bit): | 5.644748032961689 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBlqkzv1Sz2LgEF7cciAXs0nl0RCmK8czOCAPtciBoG:YvElqsdSzogc8hAh8cvA2G |
MD5: | 612D39EE9F11F6C9DF884EB62022885A |
SHA1: | DDA6DD1A078385EDBB5AD86DB9BCD14D125522F8 |
SHA-256: | CC6081A20B9E7070CCC51170F47322BE3369C134A52EA8919F059A7F5A7E39BB |
SHA-512: | 38B1680AA7C103FBCA5EC31E358FB10487ABFE7BD14994FD3C17D93F22DECBAE08A811A6A5CD7244735B4A77E762687545811C037A8925AA7FE936482B56A172 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1164 |
Entropy (8bit): | 5.695478020172621 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBlqkzv1S/KLgEfIcZVSkpsn264rS514ZjBrwloJTmcVIsrSK5oG:YvElqsdS/EgqprtrS5OZjSlwTmAfSKSG |
MD5: | F2195E5DA731D5CBC1B6632AD64ACC08 |
SHA1: | 7C8E08E054C402BE0ED7C5C9571007650AC9BC87 |
SHA-256: | 2C06C99D018D484971D5FBD02FC4812A25F00A1F8DA28F6207FFC3FCA0E44BAB |
SHA-512: | C1BB78DD09E1FFB9A7235520919A6710E78114187C54A0CB20F99E009B860429845AAC1A682910B4B6CD27304AB87759B74D835CDC1B116A48AFE552054E756D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2948888625140125 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBDVVvOi+HoQqIH9VoZcg1vRcR0YMSUoAvJfYdPeUkwRe9:YvXKXBDVxF+HoqkZc0v1SnGg8Ukee9 |
MD5: | D96563A9C8AFB64F8026E91392A7702B |
SHA1: | D26A99E61163C7F2710FE335E0D6EC24DDA5F635 |
SHA-256: | 501EB9D621AFF5A7EDB37A1FB03A31DB305E694493A421F67D0378C4C5B1331E |
SHA-512: | 380DCAF265D47CA8910A8B47DA896039CF842248EE76F26734A3271046C0B6E4B791194410D093A42C06C2DB2204B4A8AB1ACFD2AF7A2A5448037B597BEF01B8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1395 |
Entropy (8bit): | 5.774439062085861 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBlqkzv1SCrLgEGOc93W2JeFmaR7CQzttgBcu141CjrWpHfRzVCV9FJNQG:YvElqsdSCHgDv3W2aYQfgB5OUupHrQ9b |
MD5: | 48947BB8F05D54AC0A94BEF38B7D4B29 |
SHA1: | 8783602AC788841E8D111588F4543821B6FFA8DE |
SHA-256: | 7C67502F583A3449E5A6751EBF3A10B7748841BE67E325BEDC47428951C9A2CD |
SHA-512: | 59BD923A32B6EA529641F9296DD47F50AEFDB12AEC35FA5C3C0267C73E246EBEF27551A4A4EC8CAB0941E4CE0FD5C03D1104BF69EC9294C81C460AC1CDD7BBF7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.278471088280563 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBDVVvOi+HoQqIH9VoZcg1vRcR0YMSUoAvJfbPtdPeUkwRe9:YvXKXBDVxF+HoqkZc0v1SnGDV8Ukee9 |
MD5: | 548E5236E26D766D3ACB9520E9262847 |
SHA1: | 9D6EB6B7C57B65904FF1CF7E17C41B19A69E0248 |
SHA-256: | 3CED53AECD9BFD31803E5A971F99B47D67316F803F81AC7FD61A8C4677A2C20C |
SHA-512: | 133B1B67A782C09CA5D9402D64062F893961F0190F48C8CA031D7AAF77AAA0ADBBF88DE538BF210ED88A69EBC81DBC6692BFA04330F88972F8D68B757E21C899 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2833476607282055 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBDVVvOi+HoQqIH9VoZcg1vRcR0YMSUoAvJf21rPeUkwRe9:YvXKXBDVxF+HoqkZc0v1SnG+16Ukee9 |
MD5: | 0C84F1D7265F89D2356EE2BB07C35CA8 |
SHA1: | F691EF85AB24D559DA6EB1003C1F09E95D75434F |
SHA-256: | 48ACFF18A9C1FD6E90E25FB8AE88A261D7086EBB8FD26CF3E5B4A758B95A6273 |
SHA-512: | AFE27D8664658D028E5A94222DC2280799F3BCA9A7A77B6BD1A1F6880B8C6DEF0EF407D164E8D6BA9B81E2F6777B79A05FD7CDE5C22721510FA3A165EEF8CBE1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1026 |
Entropy (8bit): | 5.630514957921036 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBlqkzv1SYamXayLgE7cMCBNaqnl0RCmK8czOC/BSVG:YvElqsdSeBgACBOAh8cvMVG |
MD5: | 0FD0C4465CA7590AFFC26CB8B3E14601 |
SHA1: | 432144135F73D23F89FBBD2151D983B61ED716EF |
SHA-256: | 9BCDB67F812279A8856DD1109B69B1F9940E7A3AFF3A353858075C067F5AD696 |
SHA-512: | 5459D11B66E432D8C6BA3814903AB63FFCB04610142232DE40BD33DCCCC3745DA5C556B15E6CE601122114A9DAB76A553EF0BE05C43B497037223B3995DF61ED |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.258675145474354 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBDVVvOi+HoQqIH9VoZcg1vRcR0YMSUoAvJfshHHrPeUkwRe9:YvXKXBDVxF+HoqkZc0v1SnGUUUkee9 |
MD5: | FDEB5918ADC5EBB3E5ED1A26DBD61473 |
SHA1: | 6878E43C15891730EE8CB86E15E948CCC1F3E3FF |
SHA-256: | 93AA6C52501D6E177EFB4B2713CE00EC49421A19D59F8536B0325E68ABC8E72B |
SHA-512: | 28A9CED9C620F9D9080DBC1E7C2247C6615B0D3B4923881E4B676755017D266B4A7C51CB38422A01DE057E6DF598ECF644DF3AF47149C4FFD629D78627C9A71B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 782 |
Entropy (8bit): | 5.364489080398874 |
Encrypted: | false |
SSDEEP: | 12:YvXKXBDVxF+HoqkZc0v1SnGTq16Ukee1+3CEJ1KXd15kcyKMQo7P70c0WM6ZB/uK:Yv6XBlqkzv1Sn168CgEXX5kcIfANhVG |
MD5: | EF49DC24664EE70CEA3B1A4D6593DF38 |
SHA1: | AE6344E301D772FAE7BF97B52FA8FBE6AF8787A5 |
SHA-256: | 1FBEDC2F5B74C6C21C7A676E8B8505FAEF35110BA656E2FA0573E6632BFF9822 |
SHA-512: | 07F4DE3168A69B7C59F8F0AE4A8E721A192C862DCD4BFBB8EE5B05615DB9994F3A41A71687C5F4EDB700E5F81CBBF530C3E19472D94E8E77F85A086833A410AA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2818 |
Entropy (8bit): | 5.1278480568866645 |
Encrypted: | false |
SSDEEP: | 48:YzGmikAKMVzYZFwVF6ONTdHXEONWPPaVQ8g4PB9YzN+t:MGNiwP6MVXUCbpB |
MD5: | 2047D425F296CC07247AE44D172F8B34 |
SHA1: | 4CA41B22F98290346C285D6181032F3406AA48D7 |
SHA-256: | C6932AAF087EB563335DEEDC9720532F1F07F18A721A23FCAAE9E198CCEB765A |
SHA-512: | 439E5C0CE7A1C15E6E5BAEE4B2C333860AF8340DA6EE520D4493DF8CB0265D8EF32F839F777F801706346A79EAE9329AE6ED9A8F566620ACC0C2925C7E9C136C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.187150180838201 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUyT2SvR9H9vxFGiDIAEkGVvplw:lNVmswUUUUUUUUyC+FGSItG |
MD5: | 88E77966D625B2D69C42D92CF338AD35 |
SHA1: | 8ACEDCD87E31C236E255CC580146139D86CB39F9 |
SHA-256: | BA332BDC4D7E2E026073023CE8206527DE2BBBE4ED6E290C1676F600B620DD94 |
SHA-512: | 74D978933373B33AE2584336C9C49F5EEE73A1B6133BD6165D54DE4E53494B031A311376BFD5A320DAF0B9FD1FABDCD4E6D48E4720D07D0491E96F109C58B1A4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6058101615468856 |
Encrypted: | false |
SSDEEP: | 48:7MqKUUUUUUUUUUyTUvR9H9vxFGiDIAEkGVv5qFl2GL7ms8:7aUUUUUUUUUUyoFGSIt7KVms8 |
MD5: | E51CD0676CEBE900F261BE0143C1B04F |
SHA1: | 1D7212942818A939A3520399BEAB8F7E66AEF5BF |
SHA-256: | B5EA3627AC52A64698D1A93B7AD7796BDB2BA8B200EE46927055746ECA633FC7 |
SHA-512: | 0B1C5285D402FB1FB2B4558D048DEBAD46DB7AF05636E1F4E0631462D475813990D30A41EB198D627500ECA0E6BA29FFAD9806704306BE847422A0AB0BB9480E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.505069684106714 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8xOlQU00Kw:Qw946cPbiOxDlbYnuRK5L9H |
MD5: | A93950AA0FBF0E3562ACFAED9213DFAB |
SHA1: | EAE4E89D1C5C7A164E6AFCA6A921C8EB188B4F5E |
SHA-256: | 1920F74269849DD8DC706EE257BB16A6721120BB740B1D2A69D00A1517D127C3 |
SHA-512: | 98865F07E7F187183FB6BAFF2A5BD61E6AF762D823DFF6BBA2EB8CE84E9A64C0DDD9B3001F357C86238FF0F8D9D768A4DFBA7D54ED911F28C65C661751BD4501 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-10-29 07-09-23-911.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.3364313551355425 |
Encrypted: | false |
SSDEEP: | 384:pgcJkAVOppWmwATht6M3J30hB6FmE6qsrEa4GuYIpC2SsBwjxoaxJMJMhbZScXPc:iF5 |
MD5: | 1828AA985EA2DE33B3B00DDEB6C79A04 |
SHA1: | F6D2578FACC46BEBC948BE304945235607BF616E |
SHA-256: | 409667434AC5C3C9BE19CB7540AA59F6D3C3B2C0F03953D95AA6CD3215559F01 |
SHA-512: | 07B2679216C2D1ECB810B3E976A08694DFF8F386AFF99CF82AB89BF6BF919A9BE6ECFFE4276B78C6B7D3B01EF2DC384474632BAF395A24CE523E6DAF00E23E24 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.391337926021868 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rq:gjTz |
MD5: | 791ABC758BA7F86D4650AB3887E8A591 |
SHA1: | 570AC96CCCA35351611DB28ED05DB86F761EFF0A |
SHA-256: | 2D71F359A6C23E33E5D20EA76D11AA5A59B84777CFA9DC64646B49450543BD2B |
SHA-512: | CCAEB60B6DD45527C80765E9ADD7251301D883BE43D674B8CDB63CCB567B3CE256F02E2657EC9537D726749E3B9EFFB02327F70CD85BEF9F962402ECEAE1F993 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/x0WLGwYIGNPe7oYGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:J0WLGwZGtYGZn3mlind9i4ufFXpAXkru |
MD5: | 8D0363CB6E658F9FB75DDF89015A7BE9 |
SHA1: | DFCD52F83EB0B2771B4AB26AEC58CD3EE33CDA98 |
SHA-256: | EC6C6ED5878F0E123E39886C673B97FFC93C42166202F31A6ED41EF39F205999 |
SHA-512: | 00EBC9F665E26390994396803A0DE99A152AB3CF505C1610F22E093F3985E04E3FA394EDE1CF50B989E981B1CF30BD3F528564F55488B7480692B983EBD21F61 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 24 |
Entropy (8bit): | 3.66829583405449 |
Encrypted: | false |
SSDEEP: | 3:So6FwHn:So6FwHn |
MD5: | DD4A3BD8B9FF61628346391EA9987E1D |
SHA1: | 474076C122CACAAF112469FC62976BB69187AA2B |
SHA-256: | 7C22C759CA704106556BBC4FC10B7F53404CA1F8B40F01038D3F7C4B8183F486 |
SHA-512: | FDAF3D9F8072ED7DE9B2528376C10E3C3FDBEA74347710A4795BECF23C6577B3582B2E89D3C04EF0523C98FE0A46F2AF3629490701A20B848C63BA7B26579491 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.983526362427687 |
TrID: |
|
File name: | Specification Sample.........pdf |
File size: | 689'620 bytes |
MD5: | aeba7f17c41f5649d00cc2d728e8d41b |
SHA1: | f481d17c0ea06eb8740f4034e77ac21c9e66f08d |
SHA256: | c0c081d9deec15050d9b50fa0f648729e87d6b393694db94ad40b20f89997429 |
SHA512: | 798bf387b9c02ac5e11c334f0973bfc1083fb025d69525cf388fe82a835ef32e01f8159f67a7cf787817e408bdebce209ee129bc8e85299dd117a323b3bf13c4 |
SSDEEP: | 12288:9EJhqICGoeL+jPz7jaSFEaWcak80ktC3brl5k0RlK9VNb2yT6t32IRWBzVqDD/Tl:OHbCGoNnXYkUC3brtsVNb2yT6cIMODe6 |
TLSH: | 09E4E153CC089B87A46887E9BE574EAC2F19771DE8923BFF21620ED73D501524D9E02E |
File Content Preview: | %PDF-1.7..4 0 obj.(Identity).endobj.5 0 obj.(Adobe).endobj.8 0 obj.<<./Filter /FlateDecode./Length 87905./Length1 368228./Type /Stream.>>.stream.x..}.`.E.........+3..L.r...@ .....AL.H....\^...x.z........D1 (.z.+....kv.[V.E.U3..U....~.|d....S...]]..U..>... |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.7 |
Total Entropy: | 7.983526 |
Total Bytes: | 689620 |
Stream Entropy: | 7.984034 |
Stream Bytes: | 682595 |
Entropy outside Streams: | 5.062642 |
Bytes outside Streams: | 7025 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 47 |
endobj | 47 |
stream | 12 |
endstream | 12 |
xref | 1 |
trailer | 1 |
startxref | 1 |
/Page | 1 |
/Encrypt | 0 |
/ObjStm | 0 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
44 | 20032b3b2d0d2e6d | 091abe46d4b59be12e338df1bd320bff |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 07:09:20 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 07:09:21 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 07:09:21 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |