Windows
Analysis Report
CJ-241115826_CJ_430448_OE_BMSCAD.pdf
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 1856 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\C J-24111582 6_CJ_43044 8_OE_BMSCA D.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 5424 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7248 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 08 --field -trial-han dle=1676,i ,174530976 9064675600 ,302820572 5165205519 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 3 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 13 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
windowsupdatebg.s.llnwi.net | 87.248.205.0 | true | false | high | |
x1.i.lencr.org | unknown | unknown | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
23.203.104.175 | unknown | United States | 16625 | AKAMAI-ASUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1558820 |
Start date and time: | 2024-11-19 20:38:01 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 9s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | CJ-241115826_CJ_430448_OE_BMSCAD.pdf |
Detection: | CLEAN |
Classification: | clean2.winPDF@14/49@2/1 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 23.22.254.206, 52.5.13.197, 52.202.204.11, 54.227.187.23, 162.159.61.3, 172.64.41.3, 87.248.205.0, 2.23.197.184, 2.19.126.143, 2.19.126.149
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- VT rate limit hit for: CJ-241115826_CJ_430448_OE_BMSCAD.pdf
Time | Type | Description |
---|---|---|
14:39:12 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
23.203.104.175 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HtmlDropper | Browse | |||
Get hash | malicious | HtmlDropper | Browse | |||
Get hash | malicious | HtmlDropper | Browse | |||
Get hash | malicious | HtmlDropper | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
windowsupdatebg.s.llnwi.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | ScreenConnect Tool | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Captcha Phish | Browse |
| ||
Get hash | malicious | BruteRatel, Latrodectus | Browse |
| ||
Get hash | malicious | KnowBe4 | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AKAMAI-ASUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Stealc, Vidar | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.190398426321159 |
Encrypted: | false |
SSDEEP: | 6:HU/VMtDM+q2P92nKuAl9OmbnIFUt8YU/VdSgZmw+YU/VdSDMVkwO92nKuAl9Omb5:IGG+v4HAahFUt8BXX/+BX3V5LHAaSJ |
MD5: | BF827A3BA4C43B9221B0384DDDB7B4D6 |
SHA1: | ADE2C7653FA5C5BFDB5EFF494E4611571ECC3712 |
SHA-256: | 8D4EFABC399FA1C34D15E72767D47DE2BE9BE0C1238ECDB060790FC2741C1DD2 |
SHA-512: | C502B1E3E5F2B3619415B1B653B27E14DD8C902972D21609BDFDC9204DEEC2765C0CF5D742A7AA976EB81D0E06A8FF07A36A6BE644FAF038C98112363AF5AFA5 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.190398426321159 |
Encrypted: | false |
SSDEEP: | 6:HU/VMtDM+q2P92nKuAl9OmbnIFUt8YU/VdSgZmw+YU/VdSDMVkwO92nKuAl9Omb5:IGG+v4HAahFUt8BXX/+BX3V5LHAaSJ |
MD5: | BF827A3BA4C43B9221B0384DDDB7B4D6 |
SHA1: | ADE2C7653FA5C5BFDB5EFF494E4611571ECC3712 |
SHA-256: | 8D4EFABC399FA1C34D15E72767D47DE2BE9BE0C1238ECDB060790FC2741C1DD2 |
SHA-512: | C502B1E3E5F2B3619415B1B653B27E14DD8C902972D21609BDFDC9204DEEC2765C0CF5D742A7AA976EB81D0E06A8FF07A36A6BE644FAF038C98112363AF5AFA5 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.2052659690077965 |
Encrypted: | false |
SSDEEP: | 6:HU/TGM+q2P92nKuAl9Ombzo2jMGIFUt8YU/TxXZmw+YU/TVpMVkwO92nKuAl9OmT:ITGM+v4HAa8uFUt8BTxX/+BTVpMV5LHA |
MD5: | E1ED166E46B3BDE52106D28B80D05DEA |
SHA1: | E75B94DB27F87784D7C71A4CE65F1FEA208764B6 |
SHA-256: | D1584D76DC524150B1EF566CEA06C56F3A9CA61BF181DB7396EDABF847F2A589 |
SHA-512: | B1C5A83AF0D1B8F07B50D73F5709FC8843DA402A847A244A17F8E755E2446F93B5D30775B7EDD9370935D23285DBC773545AA0DDBF3C589C80EF28F09C885F38 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.2052659690077965 |
Encrypted: | false |
SSDEEP: | 6:HU/TGM+q2P92nKuAl9Ombzo2jMGIFUt8YU/TxXZmw+YU/TVpMVkwO92nKuAl9OmT:ITGM+v4HAa8uFUt8BTxX/+BTVpMV5LHA |
MD5: | E1ED166E46B3BDE52106D28B80D05DEA |
SHA1: | E75B94DB27F87784D7C71A4CE65F1FEA208764B6 |
SHA-256: | D1584D76DC524150B1EF566CEA06C56F3A9CA61BF181DB7396EDABF847F2A589 |
SHA-512: | B1C5A83AF0D1B8F07B50D73F5709FC8843DA402A847A244A17F8E755E2446F93B5D30775B7EDD9370935D23285DBC773545AA0DDBF3C589C80EF28F09C885F38 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 508 |
Entropy (8bit): | 5.061602859316414 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqK7ksBdOg2HpB2caq3QYiubxnP7E4T3OF+:Y2sRds/7JdMHF3QYhbxP7nbI+ |
MD5: | 6E09B6D7F813CFFBFFFB5B603CF094C6 |
SHA1: | E368D6F49165F700A1CAC673020B3B648672EA8B |
SHA-256: | EFE94457A80BD9F7FD629EBE0F73BF2C82E66FC1A1992B5AEE887FD77B13466F |
SHA-512: | 723F287C801264A5B6861377C1FF91594B7157641B44AF14ADFF53C307D20046A44E49DADB79A86BFBC3D43EDA5844BD6FE18B38E14405863ECAD578163521B4 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\ad5e8410-3024-42a8-ad15-45f37d047dae.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 508 |
Entropy (8bit): | 5.061602859316414 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqK7ksBdOg2HpB2caq3QYiubxnP7E4T3OF+:Y2sRds/7JdMHF3QYhbxP7nbI+ |
MD5: | 6E09B6D7F813CFFBFFFB5B603CF094C6 |
SHA1: | E368D6F49165F700A1CAC673020B3B648672EA8B |
SHA-256: | EFE94457A80BD9F7FD629EBE0F73BF2C82E66FC1A1992B5AEE887FD77B13466F |
SHA-512: | 723F287C801264A5B6861377C1FF91594B7157641B44AF14ADFF53C307D20046A44E49DADB79A86BFBC3D43EDA5844BD6FE18B38E14405863ECAD578163521B4 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4509 |
Entropy (8bit): | 5.236418664495832 |
Encrypted: | false |
SSDEEP: | 96:QqBpCqGp3Al+NehBmkID2w6bNMhugoKTNY+No/KTNcygLPGLLUPHiA/ZFZ3CAZ:rBpJGp3AoqBmki25ZEVoKTNY+NoCTNLa |
MD5: | 29346C772949E3150AFFFBABC7409CA9 |
SHA1: | 8E406254D5D5BF0D29D7C470D9DAF554656E953C |
SHA-256: | 905F6F2DE93E12E938C84CC1D598B138167D758E1FE37118145BB3E5CE57BAB2 |
SHA-512: | 3DB811CF1F38DDF3C9C0F2E716353B9C2D97E30704636E048DB856D73910846E20F39113788D70D9BD1A1033C7929BFA6E5BFDDDB5641D9D7BD5917FC42F4E74 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.252271465124272 |
Encrypted: | false |
SSDEEP: | 6:HU/kqM+q2P92nKuAl9OmbzNMxIFUt8YU/+5Zmw+YU/+sMVkwO92nKuAl9OmbzNMT:IDM+v4HAa8jFUt8Bq/+B1MV5LHAa84J |
MD5: | FB414F494CCCC298C1FB253F4A626F1E |
SHA1: | 5E969A232C5F15BECA212EA5E951A1503ACBDDD0 |
SHA-256: | 3DCA9445753163E022A3759E52AC6C1FF8DE7B5E6462986244BF4CF1FCD34BDD |
SHA-512: | A63CFE1790E3B8D083BEF1E2580EF91183F28D4541A8E8407B50E7C0F9A5DFE297D300432821232652A91719C84D132C05B088FFCE5BAB985331ED32B28F3DE7 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.252271465124272 |
Encrypted: | false |
SSDEEP: | 6:HU/kqM+q2P92nKuAl9OmbzNMxIFUt8YU/+5Zmw+YU/+sMVkwO92nKuAl9OmbzNMT:IDM+v4HAa8jFUt8Bq/+B1MV5LHAa84J |
MD5: | FB414F494CCCC298C1FB253F4A626F1E |
SHA1: | 5E969A232C5F15BECA212EA5E951A1503ACBDDD0 |
SHA-256: | 3DCA9445753163E022A3759E52AC6C1FF8DE7B5E6462986244BF4CF1FCD34BDD |
SHA-512: | A63CFE1790E3B8D083BEF1E2580EF91183F28D4541A8E8407B50E7C0F9A5DFE297D300432821232652A91719C84D132C05B088FFCE5BAB985331ED32B28F3DE7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241119193904Z-171.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65110 |
Entropy (8bit): | 1.3184543741795909 |
Encrypted: | false |
SSDEEP: | 96:I6MA9IXSNW3KR4J5fM3Sc2MqgYKyg1F4AlPQH:Np99NWrwSSYKffo |
MD5: | 893651C6D9EB1B14514A6BC2BCE2C295 |
SHA1: | 4EE5D3CF2D101E88D062B7D60EAA780A2C618FFC |
SHA-256: | 1DE8D9832BDDF537AA017AAECF7A30E635DB307449C33166E94C8D0C984C4E1A |
SHA-512: | BF41016A14C93C4A665008C140B297B813DC49C980B6099285D47D4529FAD86063945F2A1DB97DC076DA158D600CF22B47B4C769A11BBC5A5D9C84054515F2CA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.739999945580075 |
Encrypted: | false |
SSDEEP: | 3:kkFklcwjNvfllXlE/HT8kvrlXNNX8RolJuRdxLlGB9lQRYwpDdt:kKFemT8m/NMa8RdWBwRd |
MD5: | 990E5005C4580D5077177EF453F8F55B |
SHA1: | A8C3B8EAA3B6C1CE1A5F4F6022E334CEDD0A7908 |
SHA-256: | B8893FE25503DBC2937B9233350ADCC999DB93E68834A0CD1F81BA714CE0B633 |
SHA-512: | F7B6EEFF24D9D5E0660BE527C3B3EC362DCF5049F2068F092962BCC35693281ED0C95DFB2652C1919EF0CC7B534A704F173F1543C5B6AB8D45B939549DA9B322 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 290 |
Entropy (8bit): | 2.9775254079344555 |
Encrypted: | false |
SSDEEP: | 6:kKDD9Usw9L+N+SkQlPlEGYRMY9z+4KlDA3RUe/:mD9LNkPlE99SNxAhUe/ |
MD5: | 544994C380F12CCFCDB1896751345AA8 |
SHA1: | FDC16BBC55507600E9D763A6CA3B839C0994F19B |
SHA-256: | A4435FF1DC2E42AAB72F3B4CA4186DE21F00411714BC1DA5D89C6616E47C52C2 |
SHA-512: | ADF6BAE113D4140E6A0D7EE3AE1CD583E205D9E0C95A0CF6E3859B5129BC6A2AC12F4BCB9FC358BA26A44A4FE0C28600FD5E0293A3917E6011BB3E9C6855B081 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 227002 |
Entropy (8bit): | 3.392780893644728 |
Encrypted: | false |
SSDEEP: | 1536:WKPC4iyzDtrh1cK3XEivK7VK/3AYvYwgF/rRoL+sn:DPCaJ/3AYvYwglFoL+sn |
MD5: | 87EDBEE38F56C20298F25D5D3D4D1B5C |
SHA1: | 7F904E9615AC3186A87472EF366DD8202855B0B7 |
SHA-256: | A46B56D3ABCC137D1872DDF20EED4BCD7D04518282282ADB32DDCCF70D7FFBA6 |
SHA-512: | BBEBC1FCD5BC9AE042DD5782425BA8C47BF3EAC283B2487FC4E3FF6BF8101306DAB081E5135594165D4DC1AC120FF125AADBC5B3FFE7C646183C04DF77865E0D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.281598521702584 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB6aCnx+FIbRI6XVW7+0YzJHKoAvJM3g98kUwPeUkwRe9:YvXKXBonUYpW7KJZGMbLUkee9 |
MD5: | 8D3B7C8C8486548628DD92CD54023EEC |
SHA1: | 1EFFD9CB39D0194635707EE6F7D1C9A8AA18ACD0 |
SHA-256: | 335624B0A5B97F9A8C2FA2AD131C5E3E2A353F332405CBE94F22ACB1DB4CE031 |
SHA-512: | B7F953351D7B0428CCBCF067E1025D9EB3164728E96127488E2F63F1432F2298CEF7B86CA81FAD90D26805E5185547DE76E4D4312C4B17804C11B662354CF561 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.217898803517534 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB6aCnx+FIbRI6XVW7+0YzJHKoAvJfBoTfXpnrPeUkwRe9:YvXKXBonUYpW7KJZGWTfXcUkee9 |
MD5: | BB5526E2CCEAA690D01716FFB46F79C4 |
SHA1: | BBFC3FFF6A616F46C00EDC2E274C9D199A3787F8 |
SHA-256: | E5A31B61AC7A44246FB3B026164EEE98E4CFCF6A412F5BC7C382A8CA640DAB1C |
SHA-512: | FF1AEA21B100365B5A5E89E509F3E21B2C59B1B90C2457AE82A9C52B73D8EC14F7691EEF5B6130A19CD3816F27B05E902B8B800C8A3EEFFFCD08FAE3C6E8331A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.196568865941758 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB6aCnx+FIbRI6XVW7+0YzJHKoAvJfBD2G6UpnrPeUkwRe9:YvXKXBonUYpW7KJZGR22cUkee9 |
MD5: | 3864B6619C1ABA494D61C405A7289009 |
SHA1: | 6630AE5CE6B306D3E6EA1867D684CF5A1E6197EB |
SHA-256: | 41841CC57A75245A9EC74ED1ED7F7F7DC15158727E4976EEC61A8392FED7A1B9 |
SHA-512: | D3F0DF1BE665F3314282CBB0036910C99DA26BFF4DB4E6CD96D725CCA09DD016707CB9DF141B3A11EF3B3796B78013CF47DA0A7FB3A88445CE08876B8BDDE3C8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.2576224567384635 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB6aCnx+FIbRI6XVW7+0YzJHKoAvJfPmwrPeUkwRe9:YvXKXBonUYpW7KJZGH56Ukee9 |
MD5: | 3F0D8471F993776B75A59F61BFF1386F |
SHA1: | 6050E67001DFD973DA05DAB26CBBF45851B2E36B |
SHA-256: | 4DCB4DA6184A430CEFAEDBFC968C2597A187D814C6C1078E5FD7F590F5F9D237 |
SHA-512: | 6B3F534749F8F28D49AE1BD63B116A9E2833511513BAA47510D21533325D4DD632F3E68C5B6577CCF4A42D5EE818EEE58ECE8A071689707443EC9AD4B3267DAA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.669560705194153 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBQijpLgE9cQx8LennAvzBvkn0RCmK8czOCCS9K1:YvEHjhgy6SAFv5Ah8cv/G |
MD5: | 58C973DD3B389AF73B6DD7B71E453495 |
SHA1: | 292130558A0A58E6B7089B1138D4CCF8CE275556 |
SHA-256: | 2C96B7FCA399B1DFBAFA2C3C7079C602E88276B7F6A3DCFE02C1549952F894B5 |
SHA-512: | 17EB815E9C65238A4468A4B28BD2D169DF88A8F5B71FCE393471805726F52935E6746ECB4C513B05297E334B761B81A94CF6DF99A543869AE6E64F4D71A3466D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1122 |
Entropy (8bit): | 5.660993760986116 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBQi/VLgEwcp06ybnAvz7xHn0RCmK8czOCYHfl8zdBqK1:YvEH/FgSNycJUAh8cvYHM |
MD5: | 9E9F558A15732350453CC01C0318877B |
SHA1: | FEC0E4DE75BA8A35F3DC656F851FAAA68B9A0813 |
SHA-256: | 52C7023E4DF3A868412374943E193FAB587A90A7AE995A9A2CF60E1F55F4DD37 |
SHA-512: | BF9C52F24C5623FF709EBEFBEB2642303F1A84280214BB593E7AC5D0ADCF242CE4DED3B04C4EF3991AFBF4D39E13CAFA37A6E440BF8CAEC3F8373AA04835C71C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.1982152372189905 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB6aCnx+FIbRI6XVW7+0YzJHKoAvJfQ1rPeUkwRe9:YvXKXBonUYpW7KJZGY16Ukee9 |
MD5: | E3904C71D204B388F18DCDB18762CDF4 |
SHA1: | B4212B4BF18F24CB99649ABDEA15C9C595A0370F |
SHA-256: | 5169BFFB5FE3D513157386D56A9597AEB554F14716C2F515E23AD1FADEEF4564 |
SHA-512: | 565F96D53519DDA449AF1CE47DB7082260B4C1785863469AA6737B7D84CE2DF53093C7D0E66ABFFD3DB26B5902C4CE42B241839806F09F649EE9775758F5226D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1102 |
Entropy (8bit): | 5.6575420945717925 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBQiO2LgErcXWl7y0nAvzIBcSJCBViVqK1:YvEHOogH47yfkB5kVG |
MD5: | 6572A686C43A0AAEB06BBA3A47F871C1 |
SHA1: | 75127EFC16175ED1C09EED7737FA89DA6751C000 |
SHA-256: | 565FACD8BEDF31220BC72357C70650ED8368B6EF16A57986AE0272E9D8F9E7CF |
SHA-512: | F3760BBC44E04E58EE15A5A162DDABDC20E86CC882B150AB4347E180AF1CD064C19EE34FE1581B4A1E3ED59177A88E06882E3CBF05A367629FEE8B7674BA811B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1164 |
Entropy (8bit): | 5.6808166104706235 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBQiCKLgEfIcZVSkpsn264rS514ZjBrwloJTmcVIsrSK5qK1:YvEHCEgqprtrS5OZjSlwTmAfSKV |
MD5: | 742D73A0513F623D9D621A1F990B6D79 |
SHA1: | 0D7856E826CC18D96A50CA1265E54D12FE8F1C10 |
SHA-256: | E6122B80D5B58C1A169A5D134FD14E974CFAE50D018517B49BFCC9B27EC635BA |
SHA-512: | 6B789A7D3FFBAAC6C0AA57D3B06038FE24AE5026EA41ECCE2D33FB4E4866C8472E50868A62F2C32782C3C0DBE0110256B416DE049348EFF8938D0A83C2ECE20C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.204030469343586 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB6aCnx+FIbRI6XVW7+0YzJHKoAvJfYdPeUkwRe9:YvXKXBonUYpW7KJZGg8Ukee9 |
MD5: | 21660A2CC148D59C52E9B3FDA0ACB47B |
SHA1: | D612FB69F84F3D4ABD49845A3707F8D1531E8AFC |
SHA-256: | FD8EA0DBBDE4A42460A37CAC9FC28D4559B5593893B89240E5DC87DDB4E8EB65 |
SHA-512: | DCCD6C3A84CCB974D744647E66C83A69AAE79E512BF6A7BE93E1C5838BB3ED52B390BF32434307560C42C47FA5B68E127D5241A457CC11E938F281D0E6B9E44B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.189240078743155 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB6aCnx+FIbRI6XVW7+0YzJHKoAvJf+dPeUkwRe9:YvXKXBonUYpW7KJZG28Ukee9 |
MD5: | 1C9703372F384EB90EC52BAC1CE4D4D3 |
SHA1: | 6AA7D1CB577A501F38E329E4F1DCB5045536F8FC |
SHA-256: | 0F9A5DFA89A1FDF36AFD956C323550935009335ED60C4B5FCE8842EFC09AF2E0 |
SHA-512: | BE0405063DBC525177E9DB04A02875570EF34FBD9B170463434B960D866D18087AB439C08BD0346701AC92DAE6D11DDB63EE1382161AA32AFE2FE33EE7B6D4D4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.188237151420587 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB6aCnx+FIbRI6XVW7+0YzJHKoAvJfbPtdPeUkwRe9:YvXKXBonUYpW7KJZGDV8Ukee9 |
MD5: | 02D3F6CCE329A50B86C24AFE1AE65586 |
SHA1: | CC9F64BA9749B713D3EC2ECD973D36497DB5A5F6 |
SHA-256: | AFB947FBD796CD2CB7692D75ED9496E9689331D2403CD115BCC8C7B8F2C6DCBC |
SHA-512: | 6CD7DA7324B8EA9D705B10758EA42D29970041C31D894E28FF6A9AE3FD653BD8F9FA1441D3B3AFA3E163E8BC0E7EDA4E7191994300D60C65DB396755B565F363 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.1891572858370365 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB6aCnx+FIbRI6XVW7+0YzJHKoAvJf21rPeUkwRe9:YvXKXBonUYpW7KJZG+16Ukee9 |
MD5: | C72A963E6C2F93D51A92DA7C4E39E219 |
SHA1: | 81EE533BB06B89AEFBE0333DB369EDF0E96FF8C6 |
SHA-256: | 2C6A81BEE27887A5E45BAAA03421C6E3219DF5526C3BA9C8B6A4625D0164CE9C |
SHA-512: | 99852133644E6FDED82039CD47C162A42B8090BBD1FADF7E1F55094FB8BAB366A3B4832FDA314549E886281866195F37CFBFA3D272CA05B43CC537BE8344E685 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.637268095164837 |
Encrypted: | false |
SSDEEP: | 24:Yv6XBQiTamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BS9K1:YvEHDBgkDMUJUAh8cvMG |
MD5: | B689C8DCFA0BBEEE0B42EEDC3EC889CB |
SHA1: | BC2EBC9545BB673CD9D2BF8E3F7A26F18E432744 |
SHA-256: | DB28D3C4BFBB0BF030FD6A8EA9876E5A2B97E291B43099B54EC2BBFC6EEFAFCE |
SHA-512: | B72B3A67FB1D5B33B70275CE652B97077E6F578697190C13905C4F1DFBA29544B59B12BC008FC4246DCF213074FC204B9267A795FCD458B352ECEF258C93F5F7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.160643723647889 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXB6aCnx+FIbRI6XVW7+0YzJHKoAvJfshHHrPeUkwRe9:YvXKXBonUYpW7KJZGUUUkee9 |
MD5: | 0968337BBAD44E2C5114B4234D66C1B4 |
SHA1: | 2A9C9602DA5E0972DC655ED8860920BEC8D102CD |
SHA-256: | C82D5587F4B396AB4711DFABACEFCCCACA20F81312C9ADBFB55972FDD2CAA506 |
SHA-512: | 8B13C9C873BC6DF0AAB4897ABBF86A1256BB42D577C38787FDA56302408DDFBFC7A3B612CC425500DF7BAC1A8E7C2AB50EA08769E6E5B8A6F6F0DAD01C7FE742 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 782 |
Entropy (8bit): | 5.342526650439071 |
Encrypted: | false |
SSDEEP: | 12:YvXKXBonUYpW7KJZGTq16Ukee1+3CEJ1KXd15kcyKMQo7P70c0WM6ZB/uhWmK1:Yv6XBQiQ168CgEXX5kcIfANh9K1 |
MD5: | 298E67B69E54DF9F9F77F56D35CB2F6D |
SHA1: | A0FF6986ED9A97619A3C9FE32C263BBB6EB55120 |
SHA-256: | 8CD29BA7BC1EA1923EC231E7364B2D48C4316793E2820664CC96A6DFFC3541EC |
SHA-512: | 24F7F85394DDC303A3E37624F25C9C1473157FA5A5748079802A296A950E4E727AA18CA20F792F16FF257D69D32EC4A0807F9235E7FDFBE1CDB04F809EAFD26A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2817 |
Entropy (8bit): | 5.13230050074588 |
Encrypted: | false |
SSDEEP: | 24:Yv/lv6+e6c9aGUayoSnaxaOCP6Vm6AgS3MGrRiDikujU4j0Sa8ob7PFPp2jvf2Ld:Y3FeHrXCkmjg2SaU6ab7zOXpe/Q+h9f |
MD5: | 094B8C79DE0D064E820756C0DAF4DFD2 |
SHA1: | 3966F34B3D208E9203CBE6C4FE60C88EEB2862EC |
SHA-256: | 516956E9353BEF034ADDC2FC76D2019A2CFB3EDEFFF337617E509C3F69BD487D |
SHA-512: | AB905D99A3938D97F68C585E9D5888E710CB349A15B09404412A31068EC4306F4EC3D4AE5E3AA15D53C6A9DDFA626975256EECE80562F12B55AA99979044E17F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 0.9861900034211576 |
Encrypted: | false |
SSDEEP: | 24:TLHRx/XYKQvGJF7urs6I1RZKHs/Ds/Spxmn4zJwtNBwtNbRZ6bRZ4CmnF:TVl2GL7ms6ggOVpxDzutYtp6PP8 |
MD5: | 98A644EC9E26E16D67CA57B03B2D6648 |
SHA1: | 1652D6C825FF853C31C9F14D85AFFD7285200827 |
SHA-256: | F201B1EC08E1957AD6F89623925E0F4B9D051A237B087E804B28AE8406BAF184 |
SHA-512: | ED20FB2EF6230AB52C33477F615A1B3B9BC184FB322DC3A622C110BDCF458B254254CE9F37267AEF533A67F191F4C284E6D9291B708A6EC2A6E6ABB77D853418 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.3412258338058918 |
Encrypted: | false |
SSDEEP: | 24:7+tnAD1RZKHs/Ds/SpxmnPzJwtNBwtNbRZ6bRZWf1RZKRqLBx/XYKQvGJF7ursk:7MnGgOVpx8zutYtp6PMoqll2GL7msk |
MD5: | 4DA0DA02C80AAAEB570D4D7B6FE79034 |
SHA1: | 3955EFC646E9567CFE5E2F655D7BF67FEA38722C |
SHA-256: | EBBFB1515BFB1FD939E6DDCD0D79A6B1AFF3BC458085E3A8BD02F70A6911BD61 |
SHA-512: | 1E8D1145646DB128E83D5CEC3D285D23319B913AE5E6E30046FF29DEC61915965D4A06AB184F65FA4AD2153C0542B02883C0E0EA8CFE711EFF6E4E90B9E594D7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgFyxvwr06ufZTcblrAZbSaXI17QotYyu:6a6TZ44ADEFyxJ6ufObi5IrK |
MD5: | C61434893A0D16238A6D7C3565C5C3BC |
SHA1: | 44248939A3452930FA3D233EC6487B49CE3304E8 |
SHA-256: | DEFB55E28D6303ABF4E05F0FB8BEFD04B970963397BAB077B8AE075512973942 |
SHA-512: | 19E741621FFA1110F35D90D9B51147BA68FFDA95B8618A8E7EF60C29BD3F00423BEECFCD9693F39AAE576CAD15CEECF6D583446756F77D336F4EC3F15D59AC05 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.516674370985874 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8mUl8vR4l:Qw946cPbiOxDlbYnuRK4l |
MD5: | B3828CA8D3B8709BCB817113BF2EA9F5 |
SHA1: | 034C5DCB01CC6D1CF4CAFEF571278B7AEAEE2BD6 |
SHA-256: | FFB547A60AF14E423731AF8428138C94A8A320E1F3243F1456FA850CB319F6F0 |
SHA-512: | 4179A47762EB770998CFE55398E5756268B13B5F6D0A2C5FF3DE73790F7871F62AD767A54C9A1A8BF18703BCC2F04BDD745EAC4071E6B01A97DC4461CAC31C89 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-11-19 14-39-01-679.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.376360055978702 |
Encrypted: | false |
SSDEEP: | 384:6b1sdmfenwop+WP21h2RPjRNg7JjO2on6oU6CyuJw1oaNIIu9EMuJuF6MKK9g9JQ:vIn |
MD5: | 1336667A75083BF81E2632FABAA88B67 |
SHA1: | 46E40800B27D95DAED0DBB830E0D0BA85C031D40 |
SHA-256: | F81B7C83E0B979F04D3763B4F88CD05BC8FBB2F441EBFAB75826793B869F75D1 |
SHA-512: | D039D8650CF7B149799D42C7415CBF94D4A0A4BF389B615EF7D1B427BC51727D3441AA37D8C178E7E7E89D69C95666EB14C31B56CDFBD3937E4581A31A69081A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.358872844758653 |
Encrypted: | false |
SSDEEP: | 384:me4Twehx8ZZHIG5U4mY5FINt3I+muS2W3EYsCmyz6sSXtBOSINq4wJwo5bBhrKqG:E+P |
MD5: | 3D86DC3B148C4E3F525FA7C963AAFEB3 |
SHA1: | 60EEA6144A4785891D159A34409D31E89CD7882C |
SHA-256: | D559DFC5B269681CD8F6E63D77AD0D2CA0F28EC1167D994D8A225523DE0ACE4D |
SHA-512: | BE27763C07E6F6A37A988E2C11941D17544DAF40DAB72723B4C6155E594DB4EF2E4D9C6E8BE44BEB77B06ED659D8284CFF791C7D58FFCF1F47E5EAB663C57EA9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.400405556758583 |
Encrypted: | false |
SSDEEP: | 768:GLxxlyVUFcAzWL8VWL1ANSFld5YjMWLvJ8Uy++NSXl3WLd5WLrbhhVClkVMwDGbV:4z0 |
MD5: | F1E46BB897C2B33A092DC4AB9C7E6EC7 |
SHA1: | FA816433A059FF5412B395231E39BBE1DFC390A2 |
SHA-256: | 11F6495FEBD11D98D9A6EFACCAC41C8FAE6F91537F1C5000354288EE3C84C26E |
SHA-512: | 53D51715541D032A5F360492B8D68E1FD06ECAF606071EC5AEDE303A68BF37DA6C139E468F674744B07F71C54EB305D12FD2D6B076DBEBC6889C7BD88FF0A314 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLkwYIGNPMGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLkwZGuGZn3mlind9i4ufFXpAXkru |
MD5: | CA6B0D9F8DDC295DACE8157B69CA7CF6 |
SHA1: | 6299B4A49AB28786E7BF75E1481D8011E6022AF4 |
SHA-256: | A933C727CE6547310A0D7DAD8704B0F16DB90E024218ACE2C39E46B8329409C7 |
SHA-512: | 9F150CDA866D433BD595F23124E369D2B797A0CA76A69BA98D30DF462F0A95D13E3B0834887B5CD2A032A55161A0DC8BB30C16AA89663939D6DCF83FAC056D34 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.940902653829558 |
TrID: |
|
File name: | CJ-241115826_CJ_430448_OE_BMSCAD.pdf |
File size: | 20'159 bytes |
MD5: | 8b7dcee56b4a8a1c85180efd916f4057 |
SHA1: | 2a11fc0fec727b5293a87e7e47550178a748ce7a |
SHA256: | c3c590c7beb7883610edc82c7fa47d09e1ba7b9251d9745da14582ca440ccefb |
SHA512: | df0fb99380783c4a86065e9854142b8169a538b9a6d93eb85e0ddad08430ccb2b798fd6d06ccdb4d45ae782cf310e0451a1171d0417ef7d8f8fff871ab932438 |
SSDEEP: | 384:D84gyhZz9WYWVxQxIe7Ox4YYe9CplRd925TilLVpHrYrUtnq:9gyv9XAVe7Y4fuCp7dYsVJMz |
TLSH: | C792DF4FEEE74828D225753939003555193E395CD6EA36824A1B0F98B0E0FC82B83BF7 |
File Content Preview: | %PDF-1.5.%.....4 0 obj.<</ColorSpace[/Indexed/DeviceRGB 15(.........fff333.................................)]/Subtype/Image/Height 284/Filter/FlateDecode/Type/XObject/Width 734/Length 5512/BitsPerComponent 4>>stream.x...M{.....N.NR.....q....'6...r,..f.... |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.5 |
Total Entropy: | 7.940903 |
Total Bytes: | 20159 |
Stream Entropy: | 7.984447 |
Stream Bytes: | 18080 |
Entropy outside Streams: | 5.373938 |
Bytes outside Streams: | 2079 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 14 |
endobj | 14 |
stream | 3 |
endstream | 3 |
xref | 1 |
trailer | 1 |
startxref | 1 |
/Page | 2 |
/Encrypt | 0 |
/ObjStm | 0 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 19, 2024 20:39:13.132625103 CET | 49733 | 443 | 192.168.2.5 | 23.203.104.175 |
Nov 19, 2024 20:39:13.132725954 CET | 443 | 49733 | 23.203.104.175 | 192.168.2.5 |
Nov 19, 2024 20:39:13.132814884 CET | 49733 | 443 | 192.168.2.5 | 23.203.104.175 |
Nov 19, 2024 20:39:13.132975101 CET | 49733 | 443 | 192.168.2.5 | 23.203.104.175 |
Nov 19, 2024 20:39:13.133008003 CET | 443 | 49733 | 23.203.104.175 | 192.168.2.5 |
Nov 19, 2024 20:39:13.690857887 CET | 443 | 49733 | 23.203.104.175 | 192.168.2.5 |
Nov 19, 2024 20:39:13.691144943 CET | 49733 | 443 | 192.168.2.5 | 23.203.104.175 |
Nov 19, 2024 20:39:13.691190004 CET | 443 | 49733 | 23.203.104.175 | 192.168.2.5 |
Nov 19, 2024 20:39:13.692399979 CET | 443 | 49733 | 23.203.104.175 | 192.168.2.5 |
Nov 19, 2024 20:39:13.692482948 CET | 49733 | 443 | 192.168.2.5 | 23.203.104.175 |
Nov 19, 2024 20:39:13.719398022 CET | 49733 | 443 | 192.168.2.5 | 23.203.104.175 |
Nov 19, 2024 20:39:13.719552040 CET | 443 | 49733 | 23.203.104.175 | 192.168.2.5 |
Nov 19, 2024 20:39:13.719594002 CET | 49733 | 443 | 192.168.2.5 | 23.203.104.175 |
Nov 19, 2024 20:39:13.767333984 CET | 443 | 49733 | 23.203.104.175 | 192.168.2.5 |
Nov 19, 2024 20:39:13.771526098 CET | 49733 | 443 | 192.168.2.5 | 23.203.104.175 |
Nov 19, 2024 20:39:13.771550894 CET | 443 | 49733 | 23.203.104.175 | 192.168.2.5 |
Nov 19, 2024 20:39:13.817651987 CET | 443 | 49733 | 23.203.104.175 | 192.168.2.5 |
Nov 19, 2024 20:39:13.817754030 CET | 49733 | 443 | 192.168.2.5 | 23.203.104.175 |
Nov 19, 2024 20:39:13.818217993 CET | 49733 | 443 | 192.168.2.5 | 23.203.104.175 |
Nov 19, 2024 20:39:13.818238974 CET | 443 | 49733 | 23.203.104.175 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 19, 2024 20:39:12.671195984 CET | 55374 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 19, 2024 20:39:26.649657965 CET | 63725 | 53 | 192.168.2.5 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 19, 2024 20:39:12.671195984 CET | 192.168.2.5 | 1.1.1.1 | 0x6cc9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 20:39:26.649657965 CET | 192.168.2.5 | 1.1.1.1 | 0xb06f | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 19, 2024 20:39:10.488892078 CET | 1.1.1.1 | 192.168.2.5 | 0x218e | No error (0) | 87.248.205.0 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 20:39:12.679743052 CET | 1.1.1.1 | 192.168.2.5 | 0x6cc9 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 19, 2024 20:39:26.657202959 CET | 1.1.1.1 | 192.168.2.5 | 0xb06f | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49733 | 23.203.104.175 | 443 | 7248 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-19 19:39:13 UTC | 475 | OUT | |
2024-11-19 19:39:13 UTC | 198 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 14:38:58 |
Start date: | 19/11/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff686a00000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 14:38:59 |
Start date: | 19/11/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6413e0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 14:38:59 |
Start date: | 19/11/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6413e0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |