Windows
Analysis Report
Marriott Departmenty.pdf
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 60% |
Signatures
Classification
- System is w10x64_ra
- Acrobat.exe (PID: 6944 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\M arriott De partmenty. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 6276 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6556 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=22 56 --field -trial-han dle=1592,i ,177273875 2586763263 2,36246508 8593628862 6,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: |
Source: | File created: |
Source: | Key opened: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: |
Source: | Process information queried: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 3 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
x1.i.lencr.org | unknown | unknown | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
23.22.254.206 | unknown | United States | 14618 | AMAZON-AESUS | false | |
162.159.61.3 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
23.218.208.137 | unknown | United States | 6453 | AS6453US | false | |
2.20.68.210 | unknown | European Union | 37457 | Telkom-InternetZA | false | |
23.195.39.65 | unknown | United States | 20940 | AKAMAI-ASN1EU | false | |
23.203.104.175 | unknown | United States | 16625 | AKAMAI-ASUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1560413 |
Start date and time: | 2024-11-21 19:29:20 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Sample name: | Marriott Departmenty.pdf |
Detection: | CLEAN |
Classification: | clean1.winPDF@17/40@3/60 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 23.218.208.137
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, fs.microsoft.com, ssl-delivery.adobe.com.edgekey.net, ctldl.windowsupdate.com, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: Marriott Departmenty.pdf
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.158474105596572 |
Encrypted: | false |
SSDEEP: | |
MD5: | F1E7C877A8F20F002A2249918988857D |
SHA1: | 1810D3CD24237860E360CE9660DCC329BAC65795 |
SHA-256: | 791C355A32C1C47E797F04767026023B9BEE0FF3D768176B9C066E4565E5F0F5 |
SHA-512: | A9695DE7E96ECE6088CEA9DE5F20EAEF09E920B079BA255D8118FE5C70CF81C840F531C8CC1AE3A8D5D20A1F28CEE1339D3E9E0FCA9AB4847B0160DF6E0D9553 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.148978568595083 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9E7A0152F05DCFAC0894549034E08259 |
SHA1: | C526BF19BC553632424FF00B37AACB497E4D32E5 |
SHA-256: | 10E09BDE43E66F135E42BDC5412E610FD04FEAD1C71BEFD9D4D5997E435091F0 |
SHA-512: | 05CA73568FB6CB9612837D9928554FED0E7E0CA14E1A9883DCDEFC6F15CD5D83308E78CE752EAA83A247F0426284230457D857AE0F9E8D8F8F8D8111A5D31EC7 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\8afd5ef0-f327-4b7f-a50c-be801cb82eb3.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 403 |
Entropy (8bit): | 4.992656035880891 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7B23A862D80FE3523D8D30B5AA112F5A |
SHA1: | 13EAA90917A83B422971CA95B1236182AB10BD68 |
SHA-256: | 6C335DE73976DDA1AB6806E748A75B6E626987ABA04994CEAF032D105A685841 |
SHA-512: | 606DDCEC1B403F1FA876C50ABA7A5166602306020C73CA9258C98AA232A8E519FDE7FF625C691706FAEE5FB632981D58E22ACC705AC87E4C8EE853058E41D73E |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7B23A862D80FE3523D8D30B5AA112F5A |
SHA1: | 13EAA90917A83B422971CA95B1236182AB10BD68 |
SHA-256: | 6C335DE73976DDA1AB6806E748A75B6E626987ABA04994CEAF032D105A685841 |
SHA-512: | 606DDCEC1B403F1FA876C50ABA7A5166602306020C73CA9258C98AA232A8E519FDE7FF625C691706FAEE5FB632981D58E22ACC705AC87E4C8EE853058E41D73E |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.226372054010857 |
Encrypted: | false |
SSDEEP: | |
MD5: | 869AD6F6B73B7E32AF76E7718E1274F5 |
SHA1: | 66AB6A45CB80878B2B79A952B1EEAF59B7F0088E |
SHA-256: | D8A087F92D89DBC4F9454036FB66E80221F2B0146E75134AAB70AD3DFA06CFC2 |
SHA-512: | 11143BEB8C3E6ABC7DDC096593172D1A0D71CCDD6CFBDE18908111C9A032F2B2F7E19AF84AEF50A63AF3785D23419999D62A891C075E2C52F6899AFB2A0E5621 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.163215539062557 |
Encrypted: | false |
SSDEEP: | |
MD5: | 24B43679F7345A1749456CE391501FDC |
SHA1: | 7311269DEE2A7E3101AAF7BF675E5E0DF08A49BE |
SHA-256: | 54F1A2B003475893D872D609A7792644E3A4257B59117137D29A2F7A3A8B2A5F |
SHA-512: | 6F8E3FF26271337C359120C13BBF1C3CB5166E045BDF259DD6C86CACDF992BDBEE4BF521C80EA627DC5368D55347DA367C371E6DEA3A75ED43894C79348DD572 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.291927920232006 |
Encrypted: | false |
SSDEEP: | |
MD5: | A4D5FECEFE05F21D6F81ACF4D9A788CF |
SHA1: | 1A9AC236C80F2A2809F7DE374072E2FCCA5A775C |
SHA-256: | 83BE4623D80FFB402FBDEC4125671DF532845A3828A1B378D99BD243A4FD8FF2 |
SHA-512: | FF106C6B9E1EA4B1F3E3AB01FAEA21BA24A885E63DDF0C36EB0A8C3C89A9430FE676039C076C50D7C46DC4E809F6A7E35A4BFED64D9033FEBD6121AC547AA5E9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16928 |
Entropy (8bit): | 1.2142096795345294 |
Encrypted: | false |
SSDEEP: | |
MD5: | 59BB9C44A29BB5207181B6FF798FA639 |
SHA1: | FF5AE2B635721812BF402C6926CAA0C53CB643A3 |
SHA-256: | 2799ECB020727F2E1597E06AAABAE90730A0D8EA066DBB065D49E296011BDA72 |
SHA-512: | 8A4C945E471EE4DFCCEA6666F057F69710987E79363468493CBC3F4135AD3A22047E720DA61C059E71D1EDF031A9FCAB77FF8B6C6C3687BC6FC99F08C1A064F7 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.752969867432539 |
Encrypted: | false |
SSDEEP: | |
MD5: | E0D06B4A67D5507E35913A176229F9EE |
SHA1: | E754908E5F5B593BE748484759ABB3887D68FB27 |
SHA-256: | 8EC7327CDDC43912746FF5A1AB5DB915F88C8506B82596A1285588D6D20ED191 |
SHA-512: | 226CBA740AC86B4D52D50ADB585A90F10C3CE5D7656544E27F4914ED89306A18540A357B598A481327A2A7F08F27114A347BB490331C5B36FDF3986EFE08265C |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.1391791584200512 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9038949AD9198F0D5BE75BCCA4D8CF46 |
SHA1: | 354B0F565BC78AFCBD613FC7EF8CC08B68DE1100 |
SHA-256: | F0374ED3004125870BB52531716219F1AF8D7C8E418BCD4EF9E19C044E1FAC93 |
SHA-512: | 865D1053120C6561C3E75F83F70DC424A49A8F422EAE1FE5A81FBE55D4052DDE1EDA6665C07353BA5F2F616A62367193D2CD3391C6B51BB73F2111EFF8129D83 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.381623018654984 |
Encrypted: | false |
SSDEEP: | |
MD5: | E94AD26162D16EEDBCD93C037E13309F |
SHA1: | 20CF6F494876A72188AE36C409E8FF237028AE42 |
SHA-256: | 45ED84667D116FEB90A51206272C0B2D0127631AA4A30F49CC070B7FE7D09664 |
SHA-512: | F60A32ABFDF76F242FEAD66B38566981AC59A6D86578F80C8F7380D2E8CC02BD6322AD5C3B1C21BAE313EF24B935C2E9547DE8020F19F3D66DC1A11AC111DA69 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.330604902119373 |
Encrypted: | false |
SSDEEP: | |
MD5: | 12FD99306B11F3EE0CC0BA408950D0C7 |
SHA1: | 5A3253F3C450EAADC4C124B7A45B49863259CD25 |
SHA-256: | 4B8CEE91A3886EECEEDA870CB1634BF82343086F035BFE09C2EB30B70BF71E0F |
SHA-512: | B34557326002499270022B981C7198A04BD030C4E35E3C691CEDDA2A87478203D4227BCF168D7B289F4D574AE13CA9C4D055228E2E9BF12A72001EFDFE9EB749 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.30959993751445 |
Encrypted: | false |
SSDEEP: | |
MD5: | 30420CB3BABAF7A2D37456E4BAA83BE8 |
SHA1: | 628DAF626A3215C09E64AAE31EB7EB41BB47577A |
SHA-256: | 363E7815AE7C5438FEDF73C7424C0E66CC0EC4D1E22E7EAC41EDD6332F2DCCFE |
SHA-512: | 9A6D47F8B9F71462EB4DE76BDB61C6347EBD460674C161410298A08CE4B8D67BF4FC70233A414EA4E63C555B65DFF8C17B6917CB6F30A1D61E7E5B225C8FC9E4 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.370643896249936 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3C255DD93CBC56296F7EA10A5350BDE4 |
SHA1: | D9EC208D6E7C12B32FF9CB36E6CA7D272B2549D0 |
SHA-256: | C5C30EE810400D1470E4B36A108A9C78E9EDA9A06EDAD245EB5C56E218E0D961 |
SHA-512: | 8C890D8B51C49E5E2FDE869F5031DB480FBF04E9BDAEFA5CB4691710EA22177D58FF9DC26BE28280C5EC18B5797819EB0E8A5066E423243F739E97AEDFECEFAF |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.687899158329228 |
Encrypted: | false |
SSDEEP: | |
MD5: | 65EA4C2A45E42900D51E8D787CFA038D |
SHA1: | 1CB3210705F845DFD44B53FE9DAAF3EA26D3BEC7 |
SHA-256: | ABCEDD740BEAC17F7BEF851D644E86A02718300B5D3CCFC49857291B2B9C2D1F |
SHA-512: | E33AF6D114FF945B86D7198444BD48836B79FF8803A163EA565A146C9C811B335A4800448704BA006706D350DB29DB25792D2E8E628BD296A4473DFF60CB3E1F |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1122 |
Entropy (8bit): | 5.682617371139419 |
Encrypted: | false |
SSDEEP: | |
MD5: | A4F8FBCB16F9695464997197BD3A6DF9 |
SHA1: | C2E876B5C452C781FF899B8F0FFA74F6273C42EF |
SHA-256: | E39D7D124EE72A360BC761AA4796FD2D5B8FBC6666AAE747999CEBD908CF89B9 |
SHA-512: | C6F2E951E55F50F40A9FE2B089A5F8069C52FEAD5A4BD6596CDF3A2874003DBE04F084947C4A13F9E4FDE8123BD5F81C6FCAA0D38B3425F331F1287435716A48 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.321589114936074 |
Encrypted: | false |
SSDEEP: | |
MD5: | D8967C268A7D534C75682D028451E99B |
SHA1: | 6E1F70DFE8C783605E2BF0D1B55EE1D4B81E725E |
SHA-256: | 528108B106B5343116D1094B8852E584235DB7FD919A88FEDB764DB025340DED |
SHA-512: | 843169AB6728F8768411C25FB86C55FC336EA72EEFE47962AEE1DB1A5BAECBC332595CFCCFBF3DE6B930F958F75840E8F2F1BDE87CF31553117F79F2F925D3C1 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1102 |
Entropy (8bit): | 5.673446110425106 |
Encrypted: | false |
SSDEEP: | |
MD5: | D55304809A4696777D48E7B375675EC4 |
SHA1: | DC643118BF7C23C328792B3E94B91C6EFFBD2DD1 |
SHA-256: | CF3495EF8F1997DD0149A6E3253334B3C7D643250F342B0B777F19FD45B02B46 |
SHA-512: | 918E21BDB5FC6D67DA2E334F0F741A8E097EA33EDF69BA25EBB08CC47F7FFBDF7675F213FBF31120BFA255E23A3E374C1E8A88AE4856F7CB890C9BE8A4D45998 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1164 |
Entropy (8bit): | 5.700196848911882 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3E5756368119E4E8DF2E2D9CE7CC3535 |
SHA1: | E113E1EBCA04A6A2B17D765BF76D9E4FD85FAA0E |
SHA-256: | E597F1A5FB15A1EBE2BA4E573F2CB0514FF1F90DBEA1F72C3BF6217D3CB9143D |
SHA-512: | 94AE091ED082F7238F5BE207619D710FBB8E23D008D7765300B41C5DE5BC0D95AF47616912D07F7C42782C86C42518EB26298289F5E22235EEB2BDEF0EF67900 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.324924082311186 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6396143CD02024FA8DF8D938ECE8458F |
SHA1: | 32F1C800C1AEA8F18BE6FB6879ABE8EBC7D16E5C |
SHA-256: | 382A2DA703556FD3470B3BA61E2D64EA82B6F4530BDC971803C992A714C54464 |
SHA-512: | AF26F2F0EF717A0B53245F61F46AC3E7B57EE394BFA5151D67BC3CD4D9C10F05B8E1AA7562F58D42322091C3AFAAF837FD113251071C2F94F322B06A79486112 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.311712250327742 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9111AED88FB63F559C8906B405FA7BCE |
SHA1: | F6A59AFB360CB839A19D7BBCE7C8E633A5963418 |
SHA-256: | CE9912AC9D5A60EB664BE651F66BBEAA55BEFE2625C279E7973CB0F1BFE7EED8 |
SHA-512: | B5C4B51159F51423CF99A9786A448EBAC34215B5E52FC8FF15A40BFCF447C1F55298D730774532DA7655C428EC1AD5704E53F3030C61D27A4AC3A007F17916CE |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.308299880450264 |
Encrypted: | false |
SSDEEP: | |
MD5: | 358E3E86B00FC9E3E77A73D1DA3C2ABA |
SHA1: | 213C56524DB7D86969EF711CC232478CE2682106 |
SHA-256: | 822352CE49022EC9172C26EB83D7679FB30624BCBA5CDBCA4AD9997086A4612C |
SHA-512: | 2F9D39784BA1BF721D4952363B4E18DD91C170362CC4D6295993D82167400072D867AF86EDC4AB0039FB30EB12C4D15696E9633383708EA273B4C882507B2D0F |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.3120261872833705 |
Encrypted: | false |
SSDEEP: | |
MD5: | BDCBF205BAA205B68647608E9D2B1960 |
SHA1: | E986A4969887A20EFAF65CCA68815AA6DD6E38FC |
SHA-256: | 1C526B07FEFF35A2E9864A83364AB7B8C17D2AE06F640D5FA8D1E5E3D4E4642F |
SHA-512: | EBDF62B4361C4B9009B7DB63A392576CD71BF3E27E9178CAC068DE97F589E9CDE6F9A0E65EF163DB88E1F6751D7C3BAE5EA79663E21AEB26B7F93D60BD13839E |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.661494456361552 |
Encrypted: | false |
SSDEEP: | |
MD5: | D6F95D330310406CC2FB3694B470C10F |
SHA1: | CD8C3786C2BFC093633E8158635AB40D8797BEC3 |
SHA-256: | A190BD288FE2D11A638F5CD4AFBAE1BFDAFA3D76BC12AC54208A08E688D1E088 |
SHA-512: | 50F8789D23D208648C08DA9BD3461ADB6C643FA39A75A2BA8144929DD639B5BD83804F165C644736D46458DA51C6587CBB4338A69743CC5094EA08D52644C756 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.288766560160492 |
Encrypted: | false |
SSDEEP: | |
MD5: | AF1C00996902C1FCCE2CAC240F51489B |
SHA1: | 42FC02D85EFBC0BE92F029BD3F77844EA897FA3C |
SHA-256: | 4CE4C760291F29E6FD3D1753BBBBA03EE89577F9D39CCFE4DF87F346A955A0EA |
SHA-512: | ECD4E1AF91DDEC7F6181B3DF1505CAF01F5132683F9EBE6A22FE992B4D83F27A0FE76A320D29636F0B2C6ADC91E458A6B7B79BF6C353C00477E71F2F9D47FE88 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2817 |
Entropy (8bit): | 5.130789365361545 |
Encrypted: | false |
SSDEEP: | |
MD5: | 734C4B3E49DAC83D062BFC70BF400CA1 |
SHA1: | 058E5E95980973C1D5906CC726517C2A10A6EB09 |
SHA-256: | AB4576C5D2046620D3DB1671E7929940E1BB591738238BFA8127D089127CB85D |
SHA-512: | FE446537AB42E93A0A88B7EC1DCDD1276C6D18406BF23BAFD089C12193E56F455A837758D9B01B65D53BADAC5D6B130EC396D2B11E3E6DA47D6932A36BF0007B |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 0.9884928848503965 |
Encrypted: | false |
SSDEEP: | |
MD5: | A665D3D9268E9F871F426A6994EDE6DB |
SHA1: | 3DC6AF624486F7CF46A7DA6830FEA00861FB5C1D |
SHA-256: | A668B245B6D9189EFE172406D44DA3CE9FB0FB49BFE097D79AA3B74D31643237 |
SHA-512: | 949CC49F4CBA6FC95EB3D90E24722AA6183D15EAFA18DA2D4D51B60119EF09776673C06E27600611225D77B48C1FEDC59BC1E2A4B405ED2EDD3F701AFDA187FD |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.342640760998803 |
Encrypted: | false |
SSDEEP: | |
MD5: | A54232E17FAA6F2E16B040E0DC637698 |
SHA1: | DBF4BD2996086AA5B9918679BCB71DD49F527B85 |
SHA-256: | 07B3DA2DB43D38CDB5F8305E02FC49B45C9C5577A835CAAA4BBD1693507A0212 |
SHA-512: | 0B1A3EEA4FB2B4175999B0E59A2FBE046C73E1E68C896CDE0CC4586254689EF067E0AF384A31580BCC3C1C7EF197641A246D69F4D060E919C0EBA4B37E38124B |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | |
MD5: | 550D6D889E956B57E1A344D5878CC3F7 |
SHA1: | 5A7F1B8312226F8F87A689EB73DFA0931DE3C341 |
SHA-256: | 62236A0B2192859F82E97D4416CC1EE61C46AE1960C08B1AFA79969762FD31A5 |
SHA-512: | 9F149938C069B21C31C195248A6E170D00F714549423F957C4DAF48C8BE3971ACE0458CC2B2633785F79E8C286569715933225AC2BCAEBB19E2E065456FD28D1 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-11-21 13-29-52-692.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.353642815103214 |
Encrypted: | false |
SSDEEP: | |
MD5: | 91F06491552FC977E9E8AF47786EE7C1 |
SHA1: | 8FEB27904897FFCC2BE1A985D479D7F75F11CEFC |
SHA-256: | 06582F9F48220653B0CB355A53A9B145DA049C536D00095C57FCB3E941BA90BB |
SHA-512: | A63E6E0D25B88EBB6602885AB8E91167D37267B24516A11F7492F48876D3DDCAE44FFC386E146F3CF6EB4FA6AF251602143F254687B17FCFE6F00783095C5082 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.418494734660745 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7BB1E751EB3D760E6F44FAB65B0F4ABB |
SHA1: | 999291C19BF711631A2DAC5A850DD942D4845464 |
SHA-256: | 663722619EB5FDEE8661B3FDF65DC12C5733CBD340C7CF315253BAB1B621BF38 |
SHA-512: | 15F458297920B2E2E405C3770E465F58D44F939AF15246E464B70DD8517CEF55A77F341E5017759D3E3CEE1A2B467B3CD1ABD2DC38FA5A57AC362580B5BFD37C |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8B9FA2EC5118087D19CFDB20DA7C4C26 |
SHA1: | E32D6A1829B18717EF1455B73E88D36E0410EF93 |
SHA-256: | 4782624EA3A4B3C6EB782689208148B636365AA8E5DAF00814FA9AB722259CBD |
SHA-512: | 662F8664CC3F4E8356D5F5794074642DB65565D40AC9FEA323E16E84EBD4F961701460A1310CC863D1AB38849E84E2142382F5DB88A0E53F97FF66248230F7B9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | |
MD5: | ECFA20D7144E6C6EDB6129A2266A8080 |
SHA1: | FF0C474BFF1FA6E59B8346345CBF60210C562E38 |
SHA-256: | 6E890EA390AE240E67BE50068F415F83B90730601D7B9A57D981236F5EE3E853 |
SHA-512: | 533194CC330DD691473A5DA431A6C52817EFE116E570D3A5CE91322534FDC23F3D87EC5B7AC582FC2DEC4746E70B2B85DAA20D7A15308870E267C80975683B7D |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Reputation: | unknown |
Preview: |
File type: | |
Entropy (8bit): | 7.934439149697017 |
TrID: |
|
File name: | Marriott Departmenty.pdf |
File size: | 94'848 bytes |
MD5: | 9a311255ac82fd1928be703c8c7ceb5d |
SHA1: | e0b27de62ebd34f8f3a7d68ded0d5059bb16f587 |
SHA256: | 9c0afeb203d3dcbcf738504ce4ca767e6684104a47b2769b6e23104eff7e4ced |
SHA512: | 5a338426c41a787ce74bd5ad3c4aedb891903d44f9031cffdf965c55e89f3ea226f72a81f36569e66bceaffe5f3fd2acb253fc2b0edd98932e5b2cf429f6ee10 |
SSDEEP: | 1536:TEZDX0ZHsq8rNaA4Slq9WCWTVKiP44L235QoiL2FOJXVJbqeqQ:ohXPyAUWCWTb4+oqnRfNqeqQ |
TLSH: | 7793F170C6C1F98DDA8A867CAB3D3C749A07B2F7C4C9289711384F065528F964DB3696 |
File Content Preview: | %PDF-1.4.%......22 0 obj.<</Linearized 1/L 2373336/O 26/E 2366377/N 1/T 2372776/H [ 1116 261]>>.endobj. ..xref..22 41..0000000016 00000 n..0000001377 00000 n..0000001511 00000 n..0000001559 00000 n..0000001624 00000 n..0000002057 00000 n..000000 |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.4 |
Total Entropy: | 7.934439 |
Total Bytes: | 94848 |
Stream Entropy: | 7.945380 |
Stream Bytes: | 88836 |
Entropy outside Streams: | 5.272005 |
Bytes outside Streams: | 6012 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 39 |
endobj | 38 |
stream | 19 |
endstream | 18 |
xref | 1 |
trailer | 1 |
startxref | 1 |
/Page | 1 |
/Encrypt | 0 |
/ObjStm | 0 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
57 | a00010d42a347480 | 92f591f15e36f30e81bb26722c57bdb8 | |
58 | 0000000000000000 | 54f12d06e2faf54a415381a8b2fc2279 |