Windows
Analysis Report
Marriott Departmenty.pdf
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 5660 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\M arriott De partmenty. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7096 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7384 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 76 --field -trial-han dle=1512,i ,110526198 0047717622 3,80241734 6636676585 4,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 3 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 13 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
x1.i.lencr.org | unknown | unknown | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
107.22.247.231 | unknown | United States | 14618 | AMAZON-AESUS | false | |
23.195.92.153 | unknown | United States | 16625 | AKAMAI-ASUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1560414 |
Start date and time: | 2024-11-21 19:30:31 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 9s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Marriott Departmenty.pdf |
Detection: | CLEAN |
Classification: | clean2.winPDF@14/50@1/2 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 2.18.64.223, 2.18.64.220, 23.218.208.137, 52.202.204.11, 54.227.187.23, 23.22.254.206, 52.5.13.197, 162.159.61.3, 172.64.41.3, 23.195.39.65, 2.20.68.210, 2.20.68.201, 23.193.114.8, 23.193.114.34, 2.19.126.149, 2.19.126.143
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, a767.dspw65.akamai.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: Marriott Departmenty.pdf
Time | Type | Description |
---|---|---|
13:31:37 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
107.22.247.231 | Get hash | malicious | HTMLPhisher | Browse | ||
Get hash | malicious | Braodo | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HtmlDropper, HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | GRQ Scam | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
23.195.92.153 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Phisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AKAMAI-ASUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-AESUS | Get hash | malicious | KnowBe4 | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.186896569067684 |
Encrypted: | false |
SSDEEP: | 6:HE71FIq2Pwkn2nKuAl9OmbnIFUt8YE5PZZmw+YE5PzkwOwkn2nKuAl9OmbjLJ:k7PIvYfHAahFUt8/9Z/+/9z5JfHAaSJ |
MD5: | 855CBA35D44EB898D349F81989813D41 |
SHA1: | 1256D824FC0AE3DABBD3B7B3BB3DD090BEE83713 |
SHA-256: | 00A8181E5C65CEF453908AC696D722D3AA0C00CDDBAD6D84E001043D5DBE5968 |
SHA-512: | 8541F8883A95413EC72A1183F80666BEE54A0B997964751C7A14DA39A5D66E8370EFB97B9B792091A462C7AA8EA668C3ABC4B904C8BC5E2E7A0843EA167A2C7D |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.186896569067684 |
Encrypted: | false |
SSDEEP: | 6:HE71FIq2Pwkn2nKuAl9OmbnIFUt8YE5PZZmw+YE5PzkwOwkn2nKuAl9OmbjLJ:k7PIvYfHAahFUt8/9Z/+/9z5JfHAaSJ |
MD5: | 855CBA35D44EB898D349F81989813D41 |
SHA1: | 1256D824FC0AE3DABBD3B7B3BB3DD090BEE83713 |
SHA-256: | 00A8181E5C65CEF453908AC696D722D3AA0C00CDDBAD6D84E001043D5DBE5968 |
SHA-512: | 8541F8883A95413EC72A1183F80666BEE54A0B997964751C7A14DA39A5D66E8370EFB97B9B792091A462C7AA8EA668C3ABC4B904C8BC5E2E7A0843EA167A2C7D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.170140369750763 |
Encrypted: | false |
SSDEEP: | 6:HEBMX9+q2Pwkn2nKuAl9Ombzo2jMGIFUt8YEBQOnJZmw+YEBI9VkwOwkn2nKuAlx:kI4vYfHAa8uFUt8/SOnJ/+/OD5JfHAaU |
MD5: | 87A916DF7620AEA13B5324041213FCF3 |
SHA1: | 572061B24A7B30B39D054C94CFF2FAF158DF5B31 |
SHA-256: | 7F671653580B9B886C0E358C43E94FC9698E15233E179DD3DF5A2F820B0B341E |
SHA-512: | 19DF87E8830B1079F84DF7B8624949BA35C182F8CB823E5B735C91327E7C8A6E2190D145129840175E738292689BC6E74443F42B828D0B313ABDBF846BF930C0 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.170140369750763 |
Encrypted: | false |
SSDEEP: | 6:HEBMX9+q2Pwkn2nKuAl9Ombzo2jMGIFUt8YEBQOnJZmw+YEBI9VkwOwkn2nKuAlx:kI4vYfHAa8uFUt8/SOnJ/+/OD5JfHAaU |
MD5: | 87A916DF7620AEA13B5324041213FCF3 |
SHA1: | 572061B24A7B30B39D054C94CFF2FAF158DF5B31 |
SHA-256: | 7F671653580B9B886C0E358C43E94FC9698E15233E179DD3DF5A2F820B0B341E |
SHA-512: | 19DF87E8830B1079F84DF7B8624949BA35C182F8CB823E5B735C91327E7C8A6E2190D145129840175E738292689BC6E74443F42B828D0B313ABDBF846BF930C0 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\276fd2f9-332a-4c0a-bcb5-bf3d09a83ae6.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqLsBdOg2HHfcaq3QYiubInP7E4TX:Y2sRdsVdMHO3QYhbG7n7 |
MD5: | B7761633048D74E3C02F61AD04E00147 |
SHA1: | 72A2D446DF757BAEA2C7A58C050925976E4C9372 |
SHA-256: | 1A468796D744FCA806D1F828C07E0064AB6A1FA0E31DA3A403F12B9B89868B67 |
SHA-512: | 397A10C510FAA048E4AAB08A11B2AE14A09EE47EC4F5A2B47CE1A9580C2874ADE0F9F8FC287B9358C0FFEA4C89F8AB9270B9CA00064EA90CD2EF0EAD0A59369F |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\55fce0d1-aacd-4f11-8d70-e69063920b25.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.972484799174249 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqCsBdOg2H52caq3QYiubInP7E4TX:Y2sRds2dMH5J3QYhbG7n7 |
MD5: | 5D10464C88940DE9AC2355A300341BB6 |
SHA1: | EEEF7B9487B2559D1268522799D6A7C5B4989008 |
SHA-256: | 99A58F53870D7F03C3508082CF8CD72A393085513A3DB372798D35A5B6150FEF |
SHA-512: | AD276DE73D8CA88814B38445931E68B008FF4D938F68E0DCC41D874BFD7173769813F870BD821D1F3A847925489C23F0F7D864FEB2BF23B7717EC3E116952040 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqLsBdOg2HHfcaq3QYiubInP7E4TX:Y2sRdsVdMHO3QYhbG7n7 |
MD5: | B7761633048D74E3C02F61AD04E00147 |
SHA1: | 72A2D446DF757BAEA2C7A58C050925976E4C9372 |
SHA-256: | 1A468796D744FCA806D1F828C07E0064AB6A1FA0E31DA3A403F12B9B89868B67 |
SHA-512: | 397A10C510FAA048E4AAB08A11B2AE14A09EE47EC4F5A2B47CE1A9580C2874ADE0F9F8FC287B9358C0FFEA4C89F8AB9270B9CA00064EA90CD2EF0EAD0A59369F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF58d19c.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqLsBdOg2HHfcaq3QYiubInP7E4TX:Y2sRdsVdMHO3QYhbG7n7 |
MD5: | B7761633048D74E3C02F61AD04E00147 |
SHA1: | 72A2D446DF757BAEA2C7A58C050925976E4C9372 |
SHA-256: | 1A468796D744FCA806D1F828C07E0064AB6A1FA0E31DA3A403F12B9B89868B67 |
SHA-512: | 397A10C510FAA048E4AAB08A11B2AE14A09EE47EC4F5A2B47CE1A9580C2874ADE0F9F8FC287B9358C0FFEA4C89F8AB9270B9CA00064EA90CD2EF0EAD0A59369F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4730 |
Entropy (8bit): | 5.257035450470382 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7IO4WpLOrZ:etJCV4FiN/jTN/2r8Mta02fEhgO73goi |
MD5: | F8E034276982F3ADD879F24E786CA704 |
SHA1: | 5D99A1FBA745110BBCB0FC10D95EE77B580F9C53 |
SHA-256: | 05FF4D43FB722ADCACFCE588F0167D29A7F236D9D88B07625EE1C9BC5A203F67 |
SHA-512: | 6D51BE11F6DF83F7C8E141CF67E19BCA288717EF511D3D6C57D400F5310F498DA9F67799AA44EE77D28F607B45EDC982F6A39167B315CCEA658D00EE124B047A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.199502901057916 |
Encrypted: | false |
SSDEEP: | 6:HEPRcux9+q2Pwkn2nKuAl9OmbzNMxIFUt8YEPgYXdNJZmw+YEPWX9VkwOwkn2nKA:kPRtx4vYfHAa8jFUt8/PgYXXJ/+/PWXf |
MD5: | F39A7DBF66152232642FE54EF3DB8F17 |
SHA1: | 14DB64B81D23451C050F65ED5A6B9D16C5E82037 |
SHA-256: | 81CF72977653D03A1B0BE1917C08F619FC7EDEE80B5CF41D6157BDF72F307290 |
SHA-512: | 9EB0D5FEF88DEBA7F743896D7F9EE6FD46B7F7AAE110ED303B4AE47A0C28B009FCB674F57F92ABF69045F2161495E99EE86339A692275649D5B36C992F345D48 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.199502901057916 |
Encrypted: | false |
SSDEEP: | 6:HEPRcux9+q2Pwkn2nKuAl9OmbzNMxIFUt8YEPgYXdNJZmw+YEPWX9VkwOwkn2nKA:kPRtx4vYfHAa8jFUt8/PgYXXJ/+/PWXf |
MD5: | F39A7DBF66152232642FE54EF3DB8F17 |
SHA1: | 14DB64B81D23451C050F65ED5A6B9D16C5E82037 |
SHA-256: | 81CF72977653D03A1B0BE1917C08F619FC7EDEE80B5CF41D6157BDF72F307290 |
SHA-512: | 9EB0D5FEF88DEBA7F743896D7F9EE6FD46B7F7AAE110ED303B4AE47A0C28B009FCB674F57F92ABF69045F2161495E99EE86339A692275649D5B36C992F345D48 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444830747262843 |
Encrypted: | false |
SSDEEP: | 384:yezci5tOaJGeiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:rcs3OazzU89UTTgUL |
MD5: | 0709E9F97CF5D48029B00B9BF2CCD611 |
SHA1: | 60A2635DA31912A5157C8660AAD5835FADBA2E2E |
SHA-256: | 4F77E77C43F76744820526CB791BCA4DE3F0B0C5C090489677350989A9E1B0C7 |
SHA-512: | CD3CD2A5928AD854EB1AAF20CD435DE1D4CC058373E07693B4C99561886D151DDE4295CF9ABE1FE3041065B9D078A149FA1F94327A08005129723C9F0AB8CC36 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.774573419652916 |
Encrypted: | false |
SSDEEP: | 48:7MRpA2ioyVd3ioyZloWoy1Cwoy1E0KOioy1noy1AYoy1Wioy11ioyeioyBoy1nom:7Spfud3q4T4X2jiQb9IVXEBodRBk8 |
MD5: | 0D14FBF11CCC6E784E7B65364B2F1B92 |
SHA1: | C0178287DD81E7ED9519245B839EC2CDBC280CE3 |
SHA-256: | 03AC97EFFE1C4D54F71FC29314FC8C36BD6EAF668D73C7C6D8107EA2ADF16033 |
SHA-512: | F1C4586B8F5D54AD8C9FDEF36E6586409C7992698F2A6C8FAE167C4BC7F3B9F257FECA679ED62E4751C4DCE8424CB6DCD7C983786F4F986A7946C1AB768272B9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.746484906506307 |
Encrypted: | false |
SSDEEP: | 3:kkFkltKLmAM1fllXlE/HT8k+cll7l/tNNX8RolJuRdxLlGB9lQRYwpDdt:kKzSA9T8slz7NMa8RdWBwRd |
MD5: | D552D1CE1B2171D0FA4EFC6A9CCFFE61 |
SHA1: | 5809DFDC8E389DE7DBAB1372F1C21214DB21441B |
SHA-256: | 3888EDE3BC03F6D61CD79E15B4BAA9BC347EBC2D4EF866139A8B31F17CB82F43 |
SHA-512: | 1A55926F41E9A2A653ABAFB171B08C12ABC7A01E3BBC20EBBA7351B1EFF80437E9E95B8BF8B726DFAD57104C992E2E1FC2047454EAE9AC3BEC121FDC6ED91516 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.1292855227559153 |
Encrypted: | false |
SSDEEP: | 6:kK6Ai9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:SAdDnLNkPlE99SNxAhUe/3 |
MD5: | 76D213136FB588FA618CBF96DCF58751 |
SHA1: | B0928CE2B17A92DC1A3484E6E4372332B39F16B8 |
SHA-256: | B01120A7E3F1924B3EA87FB2A651C4CFE6CDBCDF321BE0F42D7F1C8FC8AE41F0 |
SHA-512: | 8A7C73A532B701CF045C40C08232F4626CBA871C557D4F622A69399E866AE56F617EABAF3449411715B3981211F0CB04AFA0116357BF76993EF4697C6750ADC1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.387524072020306 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXqBwDzvRY9VoZcg1vRcR0Ym8RDoAvJM3g98kUwPeUkwRe9:YvXKXKKprZc0v38OGMbLUkee9 |
MD5: | 642BD5B341DA2279EEFFD39DDBD1EB12 |
SHA1: | 05BD377F1A3F7F9938BFADB56A1E0CDE38599A97 |
SHA-256: | B1E0BF425EA1012C9E320C2BCDD37A0B896AFC9ECB12713825715EAE37AE7F5C |
SHA-512: | 5CE0A508AE179A787000F809D4CD03366B2545B53F3F6A16661FC37917294B9343261E26336D6E785CE4661097850247834B055C2EB155D826A4396AB5F24D84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.3410317816927755 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXqBwDzvRY9VoZcg1vRcR0Ym8RDoAvJfBoTfXpnrPeUkwRe9:YvXKXKKprZc0v38OGWTfXcUkee9 |
MD5: | 0D2133C1D8C902AD6646C306EE18A3EC |
SHA1: | 6AD5EF478FB35408CAF299DABA5C544821D922C1 |
SHA-256: | 6CA5CBB08A0E99E252805CF667ADFCE3FDF04D02D40727B01676FF71ACA7859A |
SHA-512: | 057DE9E8717C4218CCE2D1D635CDED810CD5E98F95B3E2163797082882E6A804382485280AEE88E7162245001C19C3BDCD3FB79A04751672C79571FB70F71240 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.318574979911398 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXqBwDzvRY9VoZcg1vRcR0Ym8RDoAvJfBD2G6UpnrPeUkwRe9:YvXKXKKprZc0v38OGR22cUkee9 |
MD5: | 71538CCE5E9ACCAE7D179ED8AEAC54D4 |
SHA1: | 5EB68FF7FFB1216AAC2AD7F9E66CB48AF9C8343C |
SHA-256: | 1882C68DC0D74A56E9C22B623D6B3218EB5DB600A5ECE55E07DA482053B662B5 |
SHA-512: | 10351BA640A673187200FC68CDD012756A0397FE0B31A30189E57C1FA2237AEAF387FD05331DFE14E5125B65B7BBF8B9261991A03707D14ED93D3D5E3526AF66 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.37538232157347 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXqBwDzvRY9VoZcg1vRcR0Ym8RDoAvJfPmwrPeUkwRe9:YvXKXKKprZc0v38OGH56Ukee9 |
MD5: | 0EC32611DFBB02EE546511AFA75D3297 |
SHA1: | ACBD611C8A253BC56FAE410CA962F657D4D6D3ED |
SHA-256: | 86867B55559DA01941E0D7567D0641D54FEF922C993E09EAE0E2B85E251A417C |
SHA-512: | 394202C8AE36C57C3F3556154A59CB0B78953E70654DA81142F5CFD6182596FA0FE68AA498B0DCCEB9D68B5B1AA67FADB64FF7436E66C5C20FE0CE6C179C2F29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.692744141505158 |
Encrypted: | false |
SSDEEP: | 24:Yv6XKKprzvgpLgE9cQx8LennAvzBvkn0RCmK8czOCCSj:YvDwohgy6SAFv5Ah8cv/j |
MD5: | 9310EE8B9E0C073E9C520A2552EC3402 |
SHA1: | 584AB58C1E578E807F8BF9F28E9B410575B96AF7 |
SHA-256: | 932BB7D649BA0A8854FF09F0E1F345753C9C1963E6BF07489DC2355B90D44C86 |
SHA-512: | 50536D9595AAC7817218C27146E878EA3898BCBD0C2AA8261067FA754ECF67CBECC7963C7F068C57AB8C97A16996B732E7D72C875BDC7A18758ADF7CA67E5166 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1122 |
Entropy (8bit): | 5.685759020275 |
Encrypted: | false |
SSDEEP: | 24:Yv6XKKprzvyVLgEwcp06ybnAvz7xHn0RCmK8czOCYHfl8zdBq:YvDw6FgSNycJUAh8cvYH5 |
MD5: | 5FB78CF391C748CB8EA30E95FF6EBDDE |
SHA1: | 4467BBBDC5327BB8C5BB6D2E66A322E42FBF42E6 |
SHA-256: | 1034BAE177D0A1ABE954BE1505717F9B78088E725511AA8A6DC500D33F6314E2 |
SHA-512: | BE825293D3C092189C7DED272BB987E281C31233467A7EC386B0B5294915713DD90ED40F51EF9A11F28FC904439E6BCB4C0C23242F7D3F0D671EDB2CBBC2FD38 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.327005413358046 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXqBwDzvRY9VoZcg1vRcR0Ym8RDoAvJfQ1rPeUkwRe9:YvXKXKKprZc0v38OGY16Ukee9 |
MD5: | 242771AEF9251140A957B7A6240D3DC6 |
SHA1: | DDBA2207970EF2B9B7A0CE35E6D877EB6A5C7A62 |
SHA-256: | 791EEAA1EF6DE9B91444F5F4CF4CE5C128E4886E5DEF93B4049AA78C135D7ED3 |
SHA-512: | 4FB79D93CFB02D996FC3B9304385EF45217B8E4FCDB4B2AEE62F7E6BEF32DE76425034FE72E6D565C457EB4338B7A92C731FA2FDF31F72D1842D28263EDB29FA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1102 |
Entropy (8bit): | 5.675258522301197 |
Encrypted: | false |
SSDEEP: | 24:Yv6XKKprzvf2LgErcXWl7y0nAvzIBcSJCBViVq:YvDwnogH47yfkB5kVj |
MD5: | C594D63F629FE42F26A8733D0933C98A |
SHA1: | F5A7EBBC48740F01D17D61207B9BBB1229A28CB6 |
SHA-256: | DD7C02DBB5F0FF8D1192893424FDC45B93AAF2958FB954BD5B606A492D9B8FF3 |
SHA-512: | 1CFA1736623D6CC1693FAD64AD4FDA732B12DF03F3812E1564FD6DD69E458F733350B36D1A048B64D219B01FA645BC024F2FBC351980B6AC1AFFF2D3D45DBD3E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1164 |
Entropy (8bit): | 5.702446594697423 |
Encrypted: | false |
SSDEEP: | 24:Yv6XKKprzvzKLgEfIcZVSkpsn264rS514ZjBrwloJTmcVIsrSK5q:YvDwLEgqprtrS5OZjSlwTmAfSKA |
MD5: | 9A3F01E7AAD4340140406942E90FF55A |
SHA1: | F6F890279E3DBD0891A032A4572741D9810665D2 |
SHA-256: | 8A18B06E9B7DD3C1CCC2AE92981DB47274A38E9E7892BE833D9FDD0BD8FF578F |
SHA-512: | 2746C81AB32C00D176BBE53FD29712F717B7CB53A6DAD7ECB94FAFD811EC14EAC72CA990C8F98824E9FEE716341A0DD04232A4341E5C15B3E375DBA4FDABC573 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.330401953126928 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXqBwDzvRY9VoZcg1vRcR0Ym8RDoAvJfYdPeUkwRe9:YvXKXKKprZc0v38OGg8Ukee9 |
MD5: | E4E0276F373B00BC5A5AE34CFB099910 |
SHA1: | 0DAAA511E99375F36147245B4D670DC3C7064A01 |
SHA-256: | B27D2ED32472DBF94543A5F1A8C5B8C9359878ED3D563D2C6206875E448BC30C |
SHA-512: | 69BE3D93FEDF34336B268CEBF51DCDCB23EF7292C5B31CE9B95C387F21CE06D874E92AAFAEFBF09EB377F1F1E65B9E053327EEB347D124A21D1720117AF139F6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.316669870070405 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXqBwDzvRY9VoZcg1vRcR0Ym8RDoAvJf+dPeUkwRe9:YvXKXKKprZc0v38OG28Ukee9 |
MD5: | 7F04A18735C8C1131541FE9F4C25F34E |
SHA1: | 2F6C8612072936951F8765E81E1FCF674F178F47 |
SHA-256: | F739B5485E1FFA7A55D963A8CBF1BC72CB3CB4CE0D63122E9A2F557D04E98FD9 |
SHA-512: | 90777C22B96F1D6328A9B4A442CB97227BC7785B4D66CA05280B8E788826F70C0CCFA5250CBA6CCE5B4F3E09FFAE461E3D9B24ED57151F9E5260E176DA4B187B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.313740102669335 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXqBwDzvRY9VoZcg1vRcR0Ym8RDoAvJfbPtdPeUkwRe9:YvXKXKKprZc0v38OGDV8Ukee9 |
MD5: | 9F4BD91031F4C60870CCC6EA309ACE37 |
SHA1: | 3959BEAC46A4F3F6718B55966D913EA4FF7C36FF |
SHA-256: | 4418C4F853824AA4C395AC1AC1D92718AF3EFDD2C41A16B27DDA270C7547E2FC |
SHA-512: | 52F227F9D4BD95A2E962CB1ABD1E1E2CFEE2975DEC6B5D527FCE29015BB30A139C6F780056DBF35D5DF51D17A9ADDBBBA545678E1C593E846935CC68DDB544B9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.318497983126461 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXqBwDzvRY9VoZcg1vRcR0Ym8RDoAvJf21rPeUkwRe9:YvXKXKKprZc0v38OG+16Ukee9 |
MD5: | 520F3F1A20ACCB290D0D83A87234503F |
SHA1: | E94F5404F68C0E2A0150B5CAE629DE31D4B17627 |
SHA-256: | 37022900ACBD68B13EB2C126B25ACCAB5AAA002C0469C65E3A222A0B0362747E |
SHA-512: | 071275F10D41A96A35DE732AB4200B9BD10DF64D698CBEE668A9EFF53C78052F4C74E38C6529EA66EEB2F2C17EB2CF664194C329767F9465F8E0E7A62AADBF58 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.670288686551265 |
Encrypted: | false |
SSDEEP: | 24:Yv6XKKprzvEamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSj:YvDw6BgkDMUJUAh8cvMj |
MD5: | 2278DB8C4299F56CC5516C29140DD813 |
SHA1: | 307EAB0FD3C46C08B7B575D30757D7DF532CA52A |
SHA-256: | AD11F71256758B0F82FED8466558A34FF4CD777001FB41E356B0855F6970345E |
SHA-512: | 6C05FAB7671E935D7B58F389774AEC4AE564B3014D6CC49F6DA40003F7F471C2E59030158449A9108C4221359C262F49CD2ED2F6DD7D6952DAB4365A092D9242 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.293948371097778 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXqBwDzvRY9VoZcg1vRcR0Ym8RDoAvJfshHHrPeUkwRe9:YvXKXKKprZc0v38OGUUUkee9 |
MD5: | 2BF8C4CE13ACEFC56291F916F2156380 |
SHA1: | 3A6413BEDAFE6984EB21BE1162DBF4FF8043EE9D |
SHA-256: | 22E6D2E39BE731A45EBB12E4D2D0A9561EE919D3CC451AF1AE514C004F2BB975 |
SHA-512: | 8384693B161656E2B8DE8DBC52A38E5FFE9FCBCCDFED6FE66C8D79C6D6229D2AE56BFAD6850651050A1D7298379178B82C5823941D9409A5FAC44F5541871E7F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2817 |
Entropy (8bit): | 5.133181031683164 |
Encrypted: | false |
SSDEEP: | 24:YCq3aW0ayQZcZxEvUb6+Jg7B4kjVfvj0SQCZo26L2LSK0qwtUj54yw9veuTCOiMY:YCl2Ub6D1VDtqJAdwWun9fpiMY |
MD5: | 1CBC3ED4679D1C97A9E928ACF8EF404C |
SHA1: | EF073329A61BB51D8C401A93A05913D477263B8B |
SHA-256: | 243F874861AD14A7D0206B5AB5A41254ABB51D270405A4F3FA4A0352CAA5B519 |
SHA-512: | CA9EC26E15E06A99CEC51D2C74CF7E45D4F0DEE5AC1DDA322BE7632AC79BEE673FBDC0F8FC36C9D92FD02B36F282A94F5F21835434D8F748BB3D5C106DE5814C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1886147458818768 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUHqSvR9H9vxFGiDIAEkGVvpzM:lNVmswUUUUUUUUHq+FGSItHM |
MD5: | F8C2AF40CC3AA6731924AF9F5BA9DFA0 |
SHA1: | 4B444A5A296080ECC6D41A0E14870D0239A1F99B |
SHA-256: | C72A2E8645BD25F53C4CE0EAAACF23EEA4C90622FCC06B5B52532916CA3B037C |
SHA-512: | 5444E9443E25BE61856A718FBAED98707BEFA2812537329FF47C477F87B68E9D0AB03DDEBBD23A582940CECB5E8374094DFFF1841F0B9BFC8ACD248158185B63 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6070433525143046 |
Encrypted: | false |
SSDEEP: | 48:7M14KUUUUUUUUUUHIvR9H9vxFGiDIAEkGVvqnqFl2GL7msM:7OUUUUUUUUUUHgFGSIt8KVmsM |
MD5: | F12A54790B3D76575B5A6BF90957134A |
SHA1: | 4B56919DF8B8BD6877EE91457506AFB0C493D063 |
SHA-256: | 3546C3ECD7AAA841A60EB23A96D824DB171C098656ABA99F7A12955B980BE354 |
SHA-512: | F07D4612EA6290AE176342E6DC732B6057FBA9AE1DD3CE3D68361599565A80EABE7A24A16BF0DE73B7F5341D43A2013738BE40DF2BD00E8396956D8F4BE40993 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgNbs3y9bFRr+1GYKWGBRXqfYfpYyu:6a6TZ44ADEBs3y9bHr+fAxK |
MD5: | 0DD22398654FF56A0451A7E0FB5DEDCE |
SHA1: | D81D933B75AF9AA0904E4DAD0EA473321F639234 |
SHA-256: | 1257A09FFBE9A02A6F52389A538CF60D07A39DE24A7F1F2102E79993BDA45D6C |
SHA-512: | A4D9C2E1E5C52CF5545C7577E0367C9D1606C11E591194361BAA1B75EBFF1A04B2321406B9A3A59AC8FE5BB1BCB30C18B72CDFEC5CCEBE9CF6BA310EAD443C3F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4851648184472035 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8hlvMUflH:Qw946cPbiOxDlbYnuRKeflH |
MD5: | 82A208E16F8AA92CDE759A156ADD4275 |
SHA1: | F05C0DD54840290DCA2FF6062EC4895D8FC279B4 |
SHA-256: | 7C496AAC73951B96C901CBE3567A07F145A64B0CF67F3B1B4945BE6D7FD2B0AF |
SHA-512: | 74FB1D11241E5D4491CAA6E24CD837532A74D4F1B8A0408C068A8D790BDF838587D0309B1821D221F35257E225749993C9621267746868E72BAE1AEC688D904F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-11-21 13-31-27-302.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.358709717177118 |
Encrypted: | false |
SSDEEP: | 384:QguuVfc3rENqpCq7kRUFxKjDZVkydi69+N/FDbl+nLGEeLdsMfhRyJynmnRLJGWS:g+c |
MD5: | 666361070A78385D9A0D3B97F03A09B4 |
SHA1: | 2FC5D512CE27699404C0D2BE62D506D5642F4590 |
SHA-256: | 7EC20D5F073E7E8FB2F6ED0D7875959CEB0214297EEE60C3FADD34AA80C81810 |
SHA-512: | C5E3F3CEF757406B15630B0807DD2159BB7F832031FF62947AB69FAE78355D11D952BF1EAFCA45D726D57F6D4F2E3CB3744E911997E3F8A15B565A43B5BC9FBA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.386742636987878 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rg:E |
MD5: | 8C5D1A407091721CF6444A67627BDEAB |
SHA1: | 73323CB955D6813176A40B00B1624F3C1E8028F0 |
SHA-256: | 1CCB6BAFF352E1F2B1E4ED2543A242C286AFF86199D423871DE102716FED9CFB |
SHA-512: | 65929B4A27F0450DCCD9A9567F300F7AC189AD70A16B0052C378E8FC833C0DD9B00DAF40B425BDFCB067A35F921AD69E0840C5747AAC2F76908B8E966A375414 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLaGZDwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLaGZDwZGk3mlind9i4ufFXpAXkru |
MD5: | 18E3D04537AF72FDBEB3760B2D10C80E |
SHA1: | B313CD0B25E41E5CF0DFB83B33AB3E3C7678D5CC |
SHA-256: | BBEF113A2057EE7EAC911DC960D36D4A62C262DAE5B1379257908228243BD6F4 |
SHA-512: | 2A5B9B0A5DC98151AD2346055DF2F7BFDE62F6069A4A6A9AB3377B644D61AE31609B9FC73BEE4A0E929F84BF30DA4C1CDE628915AC37C7542FD170D12DE41298 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.934439149697017 |
TrID: |
|
File name: | Marriott Departmenty.pdf |
File size: | 94'848 bytes |
MD5: | 9a311255ac82fd1928be703c8c7ceb5d |
SHA1: | e0b27de62ebd34f8f3a7d68ded0d5059bb16f587 |
SHA256: | 9c0afeb203d3dcbcf738504ce4ca767e6684104a47b2769b6e23104eff7e4ced |
SHA512: | 5a338426c41a787ce74bd5ad3c4aedb891903d44f9031cffdf965c55e89f3ea226f72a81f36569e66bceaffe5f3fd2acb253fc2b0edd98932e5b2cf429f6ee10 |
SSDEEP: | 1536:TEZDX0ZHsq8rNaA4Slq9WCWTVKiP44L235QoiL2FOJXVJbqeqQ:ohXPyAUWCWTb4+oqnRfNqeqQ |
TLSH: | 7793F170C6C1F98DDA8A867CAB3D3C749A07B2F7C4C9289711384F065528F964DB3696 |
File Content Preview: | %PDF-1.4.%......22 0 obj.<</Linearized 1/L 2373336/O 26/E 2366377/N 1/T 2372776/H [ 1116 261]>>.endobj. ..xref..22 41..0000000016 00000 n..0000001377 00000 n..0000001511 00000 n..0000001559 00000 n..0000001624 00000 n..0000002057 00000 n..000000 |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.4 |
Total Entropy: | 7.934439 |
Total Bytes: | 94848 |
Stream Entropy: | 7.945380 |
Stream Bytes: | 88836 |
Entropy outside Streams: | 5.272005 |
Bytes outside Streams: | 6012 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 39 |
endobj | 38 |
stream | 19 |
endstream | 18 |
xref | 1 |
trailer | 1 |
startxref | 1 |
/Page | 1 |
/Encrypt | 0 |
/ObjStm | 0 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
57 | a00010d42a347480 | 92f591f15e36f30e81bb26722c57bdb8 | |
58 | 0000000000000000 | 54f12d06e2faf54a415381a8b2fc2279 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 21, 2024 19:31:36.399060965 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:36.399110079 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:36.399177074 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:36.399471045 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:36.399502993 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:37.827334881 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:37.827718019 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:37.827769995 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:37.831353903 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:37.831440926 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:37.831463099 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:37.831521034 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:37.831851006 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:37.831938028 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:37.832181931 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:37.832214117 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:37.879379034 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:38.196625948 CET | 49744 | 443 | 192.168.2.4 | 23.195.92.153 |
Nov 21, 2024 19:31:38.196645021 CET | 443 | 49744 | 23.195.92.153 | 192.168.2.4 |
Nov 21, 2024 19:31:38.196717024 CET | 49744 | 443 | 192.168.2.4 | 23.195.92.153 |
Nov 21, 2024 19:31:38.196929932 CET | 49744 | 443 | 192.168.2.4 | 23.195.92.153 |
Nov 21, 2024 19:31:38.196940899 CET | 443 | 49744 | 23.195.92.153 | 192.168.2.4 |
Nov 21, 2024 19:31:38.367887020 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:38.367939949 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:38.368184090 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:38.368222952 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:38.371154070 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:38.371800900 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:38.371820927 CET | 443 | 49741 | 107.22.247.231 | 192.168.2.4 |
Nov 21, 2024 19:31:38.371857882 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:38.371891975 CET | 49741 | 443 | 192.168.2.4 | 107.22.247.231 |
Nov 21, 2024 19:31:39.787703037 CET | 443 | 49744 | 23.195.92.153 | 192.168.2.4 |
Nov 21, 2024 19:31:39.790677071 CET | 49744 | 443 | 192.168.2.4 | 23.195.92.153 |
Nov 21, 2024 19:31:39.790714979 CET | 443 | 49744 | 23.195.92.153 | 192.168.2.4 |
Nov 21, 2024 19:31:39.793431997 CET | 443 | 49744 | 23.195.92.153 | 192.168.2.4 |
Nov 21, 2024 19:31:39.793513060 CET | 49744 | 443 | 192.168.2.4 | 23.195.92.153 |
Nov 21, 2024 19:31:39.799902916 CET | 49744 | 443 | 192.168.2.4 | 23.195.92.153 |
Nov 21, 2024 19:31:39.800077915 CET | 443 | 49744 | 23.195.92.153 | 192.168.2.4 |
Nov 21, 2024 19:31:39.800592899 CET | 49744 | 443 | 192.168.2.4 | 23.195.92.153 |
Nov 21, 2024 19:31:39.800607920 CET | 443 | 49744 | 23.195.92.153 | 192.168.2.4 |
Nov 21, 2024 19:31:39.848134041 CET | 49744 | 443 | 192.168.2.4 | 23.195.92.153 |
Nov 21, 2024 19:31:40.126971006 CET | 443 | 49744 | 23.195.92.153 | 192.168.2.4 |
Nov 21, 2024 19:31:40.127154112 CET | 443 | 49744 | 23.195.92.153 | 192.168.2.4 |
Nov 21, 2024 19:31:40.127342939 CET | 49744 | 443 | 192.168.2.4 | 23.195.92.153 |
Nov 21, 2024 19:31:40.280332088 CET | 49744 | 443 | 192.168.2.4 | 23.195.92.153 |
Nov 21, 2024 19:31:40.280365944 CET | 443 | 49744 | 23.195.92.153 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 21, 2024 19:31:36.674428940 CET | 61060 | 53 | 192.168.2.4 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 21, 2024 19:31:36.674428940 CET | 192.168.2.4 | 1.1.1.1 | 0xf157 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 21, 2024 19:31:36.907875061 CET | 1.1.1.1 | 192.168.2.4 | 0xf157 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49741 | 107.22.247.231 | 443 | 7384 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-21 18:31:37 UTC | 1473 | OUT | |
2024-11-21 18:31:38 UTC | 608 | IN | |
2024-11-21 18:31:38 UTC | 5227 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49744 | 23.195.92.153 | 443 | 7384 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-21 18:31:39 UTC | 475 | OUT | |
2024-11-21 18:31:40 UTC | 198 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 13:31:23 |
Start date: | 21/11/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 13:31:27 |
Start date: | 21/11/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 13:31:27 |
Start date: | 21/11/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |