Windows
Analysis Report
document.pdf
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 7312 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\d ocument.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7496 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7780 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 52 --field -trial-han dle=1508,i ,596439204 1809778140 ,460735840 4255903214 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 3 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 13 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | high | |
x1.i.lencr.org | unknown | unknown | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
50.16.47.176 | unknown | United States | 14618 | AMAZON-AESUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1564534 |
Start date and time: | 2024-11-28 13:57:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 30s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | document.pdf |
Detection: | CLEAN |
Classification: | clean2.winPDF@15/54@3/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 2.23.160.135, 88.221.134.32, 88.221.134.42, 172.64.41.3, 162.159.61.3, 52.6.155.20, 3.233.129.217, 52.22.41.97, 3.219.243.226, 199.232.214.172, 88.221.134.64, 88.221.134.50, 88.221.134.17, 88.221.135.211, 88.221.135.90, 23.195.39.65, 2.20.40.170, 88.221.134.33, 88.221.135.218, 88.221.134.56, 88.221.135.72, 88.221.134.41, 88.221.134.75, 88.221.134.51, 88.221.134.27, 88.221.134.57
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, e4578.dscb.akamaiedge.net, ctldl.windowsupdate.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ssl.adobe.com.edgekey.net, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtCreateFile calls found.
- VT rate limit hit for: document.pdf
Time | Type | Description |
---|---|---|
07:58:25 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
50.16.47.176 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
bg.microsoft.map.fastly.net | Get hash | malicious | Lokibot, PureLog Stealer | Browse |
| |
Get hash | malicious | AteraAgent | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | RedLine, SectopRAT | Browse |
| ||
Get hash | malicious | RedLine, SectopRAT | Browse |
| ||
Get hash | malicious | RedLine, SectopRAT | Browse |
| ||
Get hash | malicious | RHADAMANTHYS | Browse |
| ||
Get hash | malicious | RHADAMANTHYS | Browse |
| ||
Get hash | malicious | CredentialStealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-AESUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Clipboard Hijacker, Cryptbot | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Clipboard Hijacker, Cryptbot | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.251349803170146 |
Encrypted: | false |
SSDEEP: | 6:Ht5N+q2Pwkn2nKuAl9OmbnIFUt8YtOmZmw+YtOiVkwOwkn2nKuAl9OmbjLJ:Nz+vYfHAahFUt8SOm/+SOiV5JfHAaSJ |
MD5: | 9EBFFA0A3706191F1CF081E389D5D246 |
SHA1: | 729570EB1B54A4FCB3F79210DA0CC216FDBA1027 |
SHA-256: | 2539FCF2D7672D48A1356A8B17186D53780315FEE867E923766283A6FDE0D539 |
SHA-512: | FA23A11F3B64C51E1A7307FADE8052A491196055F1440DB716DFA8687A4D7A95C9418C2C1DF31D0EC6A254FACF5864AB0A2020F992C427114BDCB89CE5486150 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.251349803170146 |
Encrypted: | false |
SSDEEP: | 6:Ht5N+q2Pwkn2nKuAl9OmbnIFUt8YtOmZmw+YtOiVkwOwkn2nKuAl9OmbjLJ:Nz+vYfHAahFUt8SOm/+SOiV5JfHAaSJ |
MD5: | 9EBFFA0A3706191F1CF081E389D5D246 |
SHA1: | 729570EB1B54A4FCB3F79210DA0CC216FDBA1027 |
SHA-256: | 2539FCF2D7672D48A1356A8B17186D53780315FEE867E923766283A6FDE0D539 |
SHA-512: | FA23A11F3B64C51E1A7307FADE8052A491196055F1440DB716DFA8687A4D7A95C9418C2C1DF31D0EC6A254FACF5864AB0A2020F992C427114BDCB89CE5486150 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.215412552011719 |
Encrypted: | false |
SSDEEP: | 6:Htil4pM+q2Pwkn2nKuAl9Ombzo2jMGIFUt8YtiXubZmw+YtiXu2MVkwOwkn2nKuA:Ne2M+vYfHAa8uFUt8S0I/+S0rMV5JfHA |
MD5: | E6F32D53A532B419FFAF1F19C44517B7 |
SHA1: | A9DA22C90B6B28A12CDB1D0BC20362AE4959D32F |
SHA-256: | EEDFFF201485255187C18B8CAF0B65033198AEACFCBF57354231E47655A505E7 |
SHA-512: | 47F787BC9D7EC32D6A30FDAC907B0F5B3EC7461F0A6EE5B07F5DD216E410974016EFECAA6848064F5E3E9869166A75AD1B86A546C9F7AC77A2A2D0E426BC3E33 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.215412552011719 |
Encrypted: | false |
SSDEEP: | 6:Htil4pM+q2Pwkn2nKuAl9Ombzo2jMGIFUt8YtiXubZmw+YtiXu2MVkwOwkn2nKuA:Ne2M+vYfHAa8uFUt8S0I/+S0rMV5JfHA |
MD5: | E6F32D53A532B419FFAF1F19C44517B7 |
SHA1: | A9DA22C90B6B28A12CDB1D0BC20362AE4959D32F |
SHA-256: | EEDFFF201485255187C18B8CAF0B65033198AEACFCBF57354231E47655A505E7 |
SHA-512: | 47F787BC9D7EC32D6A30FDAC907B0F5B3EC7461F0A6EE5B07F5DD216E410974016EFECAA6848064F5E3E9869166A75AD1B86A546C9F7AC77A2A2D0E426BC3E33 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqLsBdOg2HHfcaq3QYiubInP7E4TX:Y2sRdsVdMHO3QYhbG7n7 |
MD5: | B7761633048D74E3C02F61AD04E00147 |
SHA1: | 72A2D446DF757BAEA2C7A58C050925976E4C9372 |
SHA-256: | 1A468796D744FCA806D1F828C07E0064AB6A1FA0E31DA3A403F12B9B89868B67 |
SHA-512: | 397A10C510FAA048E4AAB08A11B2AE14A09EE47EC4F5A2B47CE1A9580C2874ADE0F9F8FC287B9358C0FFEA4C89F8AB9270B9CA00064EA90CD2EF0EAD0A59369F |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF6b7fa7.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqLsBdOg2HHfcaq3QYiubInP7E4TX:Y2sRdsVdMHO3QYhbG7n7 |
MD5: | B7761633048D74E3C02F61AD04E00147 |
SHA1: | 72A2D446DF757BAEA2C7A58C050925976E4C9372 |
SHA-256: | 1A468796D744FCA806D1F828C07E0064AB6A1FA0E31DA3A403F12B9B89868B67 |
SHA-512: | 397A10C510FAA048E4AAB08A11B2AE14A09EE47EC4F5A2B47CE1A9580C2874ADE0F9F8FC287B9358C0FFEA4C89F8AB9270B9CA00064EA90CD2EF0EAD0A59369F |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\a9c8cd2f-1842-4dc5-90cc-f84e45eb5b7e.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 546 |
Entropy (8bit): | 4.946098305903923 |
Encrypted: | false |
SSDEEP: | 12:YHgLdvZTAoqBWsB6um3RA8sq2Y2sBd2caq3QH7E4TX:YALtIB7JsRdsFYbdJ3QH7n7 |
MD5: | CB38933B6973D05F1C38C713C06060CE |
SHA1: | 58B98D5CC42131C2855A943F9965F59CC5BEE93F |
SHA-256: | 7CA82E34C0610B9ADFD6376228DD51DF7D4C7E72684F9FB1CDF9AEDBFEA019D3 |
SHA-512: | 85DE054EE568B48F335A5E7157C031F01050B27A1D91665ED38D611EB28A337DE074DD11C7FE9073D3302AB300500C5022ADF0FE46E24CCD42B26DB89BA0EE84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\f4b2bd58-bb10-434f-a4fe-092b773219dd.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqLsBdOg2HHfcaq3QYiubInP7E4TX:Y2sRdsVdMHO3QYhbG7n7 |
MD5: | B7761633048D74E3C02F61AD04E00147 |
SHA1: | 72A2D446DF757BAEA2C7A58C050925976E4C9372 |
SHA-256: | 1A468796D744FCA806D1F828C07E0064AB6A1FA0E31DA3A403F12B9B89868B67 |
SHA-512: | 397A10C510FAA048E4AAB08A11B2AE14A09EE47EC4F5A2B47CE1A9580C2874ADE0F9F8FC287B9358C0FFEA4C89F8AB9270B9CA00064EA90CD2EF0EAD0A59369F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4730 |
Entropy (8bit): | 5.255143539082138 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7tgRGZ:etJCV4FiN/jTN/2r8Mta02fEhgO73goF |
MD5: | 5A479FE2CFDCB8F33B6DE8AAEE5283AC |
SHA1: | 06ACA57ADD33B1F6D8E143EC000302BAF9EA8D25 |
SHA-256: | 41836DB09C4A2B9EE64158A1B40478540A8F438473291ACEA79AADEA9E487746 |
SHA-512: | F934B1EC5AA1BAFB1A41B901F9C5D364A5D9BDC4E5C394F8F4350C81E5A40F62173253E205F060164D1C8744BC0F5F60E128E53401A804732331E473F1B622D3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.232082111207414 |
Encrypted: | false |
SSDEEP: | 6:H5lpM+q2Pwkn2nKuAl9OmbzNMxIFUt8YelZmw+YaMVkwOwkn2nKuAl9OmbzNMFLJ:ZlpM+vYfHAa8jFUt81l/+bMV5JfHAa8E |
MD5: | 24978DA7F4C78D9A83B624FA709F6B47 |
SHA1: | 7517FD9492773A9EB13AA877C19C113EF32A98AE |
SHA-256: | E1EE61E6284A19CEB42983C9CE253F3A18B3007624003255202C9911499BC8A9 |
SHA-512: | F28ADA710373FCED0D4C6E5668D685D16B9FEBA7C91BF257B6F3D0BD961F294940DFCF706EC7B7CCF4B634A12C65A78326BEFE5FA1BAE05FDE831BAD796CA461 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.232082111207414 |
Encrypted: | false |
SSDEEP: | 6:H5lpM+q2Pwkn2nKuAl9OmbzNMxIFUt8YelZmw+YaMVkwOwkn2nKuAl9OmbzNMFLJ:ZlpM+vYfHAa8jFUt81l/+bMV5JfHAa8E |
MD5: | 24978DA7F4C78D9A83B624FA709F6B47 |
SHA1: | 7517FD9492773A9EB13AA877C19C113EF32A98AE |
SHA-256: | E1EE61E6284A19CEB42983C9CE253F3A18B3007624003255202C9911499BC8A9 |
SHA-512: | F28ADA710373FCED0D4C6E5668D685D16B9FEBA7C91BF257B6F3D0BD961F294940DFCF706EC7B7CCF4B634A12C65A78326BEFE5FA1BAE05FDE831BAD796CA461 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241128125817Z-216.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60406 |
Entropy (8bit): | 5.923054204088395 |
Encrypted: | false |
SSDEEP: | 768:2FzdUeYqjZ+OoPzX2JsoqYpQEgOB77YIA1Jv8/aQTxTvJUCYQ7VzoG:CYqjZ+FPjoqYSEgORJM8/r0CYQ7loG |
MD5: | 294332998F9C786C03FBFD7251133561 |
SHA1: | A1F101017FCAF7E07E203FFE2DADE17D1DA66222 |
SHA-256: | 0CBDE5518CEDD0665C8613482012071A40F636FBC625EA0C468C9CB067DFBAC3 |
SHA-512: | D58598F6881709AC7D16E22229F99E7F459E78F22A4D55F6A69F0057868CC22447099E5F4F977AACA1FDC89489B3EE407031885E8B75ADD87226754F3155BF1C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.445252990873196 |
Encrypted: | false |
SSDEEP: | 384:yezci5tAiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:rXs3OazzU89UTTgUL |
MD5: | A3DC3124F9A3C6233345774C4EE87358 |
SHA1: | A890C68102588843EE62201578EA975A3E5044E3 |
SHA-256: | 06414117D4C9329ED7E686BB5F49979BD6051FAA288A0DCB0125E64BBCF6D27A |
SHA-512: | E660DDABDABA29BA1EBA53E09941A177364DE2964D18B0E7A334B8B74D6A5A75EF5A4606B9CEBBA8635DC88E8371DD596B08C3CDF9BE29481CB25CF0E68E7E2C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.777675351262244 |
Encrypted: | false |
SSDEEP: | 48:7Mjp/E2ioyVaioy9oWoy1Cwoy1SKOioy1noy1AYoy1Wioy1hioybioyooy1noy1d:7UpjuaFpXKQV5b9IVXEBodRBkL |
MD5: | F2527C41998B55E7479C61D78679FD7C |
SHA1: | 95B50B703028199C810AAC06DCEF267184744F62 |
SHA-256: | 93AD8CD53B5DE440738720C1E6E6798CA0F6680C44539ED1A6537B474CDC6B9F |
SHA-512: | AF37ADCDB124B04A62A181652906C6B251F75B5FF6BCDDF8214F94A7D76D67BAF5A7043BFC5DDAA058393949F0D35678E5EB89616E96642FF38CB77D48DA3277 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7381013623686155 |
Encrypted: | false |
SSDEEP: | 3:kkFklV5G3M/tfllXlE/HT8kpdll7vNNX8RolJuRdxLlGB9lQRYwpDdt:kKXceT8gd/7VNMa8RdWBwRd |
MD5: | 319DCB3481847766767FF92F8BF648B8 |
SHA1: | 294150D333F371C92AC78A750CD7C3DC4DAFC216 |
SHA-256: | F38B3339216AE36217E0509330AD93DED5B48BE89F98A758671E2ED4A4357C6B |
SHA-512: | 601561ACB2AA36B39E43E0AA82B77AB17D53CF107A0558416C7BD5E70F74BDC6C58268AF673C406166DE057B1C390CC57C4F7253EF1B75FC107656923DB503E7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.2539954282295116 |
Encrypted: | false |
SSDEEP: | 6:kKIeL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:niDImsLNkPlE99SNxAhUe/3 |
MD5: | 90B75910134D7FFCD64ABDEE1B227A99 |
SHA1: | E43392AEAA16C0198DF8B64E64D46A672C483F19 |
SHA-256: | 3317A9DD6C58D1986D88D9E762F3BC5F00852E56A6F4230AD8DC7BBA8D70504E |
SHA-512: | 7ED509F9B68B60782E2F258212977B3CCF1338885DA2A9EBA1D503E3009B680994C1C994891B7EAD6A8DE11D6F227FB6F782EFB0F4ECE4D23E965E0850D9506D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 244540 |
Entropy (8bit): | 3.3415042960460593 |
Encrypted: | false |
SSDEEP: | 1536:vKPCPiyzDtrh1cK3XEivK7VK/3AYvYwggErRo+RQn:yPClJ/3AYvYwgrFo+RQn |
MD5: | 758B42992DDFC41CB5E57069C621B54A |
SHA1: | D0C28AF6CF1BD2208DA97DEDE57F6C78CEC98DCD |
SHA-256: | 55DF75758DD6CA825ED2DC9380EDC8469351191308C34CACFC44205197ABD25D |
SHA-512: | 437918372167A402005A728DCBBEF7B3A9580B794AD6A948A435C9D57C1672ACC1B7376E2A09113B66600EF5049D23625174256565BC639125A2F2BD07928926 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.34968546447327 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJM3g98kUwPeUkwRe9:YvXKXKVxkZc0vCSGMbLUkee9 |
MD5: | 70D8BCBE74CB58575BFB26EE4A70127E |
SHA1: | 99DBFA441A8A8110BEE60556AC6FD7661DA1BD90 |
SHA-256: | DAE6658BD62B3762EB0D32E6B4FEE3E362AF87AF4A179BA56444E8CAC1E3857C |
SHA-512: | A2F97CDB0FCFB6799FD56455350CBD3D1C247AE5D0A76A47108C8F652AF9B12EF80B30F8002A19BB222A5F21C0ACEB55ACA9EFED367BD037E6A45204F9BBC1D8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.300657857883515 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJfBoTfXpnrPeUkwRe9:YvXKXKVxkZc0vCSGWTfXcUkee9 |
MD5: | DD8FC134E974CBE997D96C28620513E9 |
SHA1: | 2236A0608F5049552EA94411AC3A5448BAA0557F |
SHA-256: | 7085245ECA42F81A6DF32073527E03386E52F9699209D738AAB89DE248F1D85D |
SHA-512: | 01B37329958E6C08580F0A8091ECFA7B6BB039DCABDCEC86D0A17B7800723C14F7019B86F08F30A686AEE5CD22092871656FD6D0FB74F6061FBAD75BAD04FA1C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.278130107087143 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJfBD2G6UpnrPeUkwRe9:YvXKXKVxkZc0vCSGR22cUkee9 |
MD5: | 3A3B6A33FBBEC446278757182449D431 |
SHA1: | D111201DE2D6E01976369D7289B77DD4F8497DFC |
SHA-256: | 388D09358444580B1FC8B43F60085A715BE1D47CE682D241B5D5150EA264BAD7 |
SHA-512: | 2A42DD799F2C89C56569A34183CFCDAE047A04F4D5928CDE8CF170A487FDCEEEB20C59021E53FD01C0E49B55EC00C626E18274804307A6D716E2F741DEA3652A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.336216043586186 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJfPmwrPeUkwRe9:YvXKXKVxkZc0vCSGH56Ukee9 |
MD5: | CA63254CCD780ACE9293359B6EE84EC9 |
SHA1: | E20215D3E457F146E0B330870F44F40646136847 |
SHA-256: | D45C6ECF2A52B7078299F5B1EBB05BEF02BAA310B04915C1567722031DA5DCCA |
SHA-512: | DAAA30775DB79C49AF24E2BDDEC619C5041E0926DBDF080763032FB879CA595781F535A5C34F2589C8D8187B2B67E423A095EA05ACCEFB75F554D027218621D6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.691071233766813 |
Encrypted: | false |
SSDEEP: | 24:Yv6XokzvCvpLgE9cQx8LennAvzBvkn0RCmK8czOCCSz1:YviKvhgy6SAFv5Ah8cv/z1 |
MD5: | 0E2A8ABC47E05F24A0578B559A21452E |
SHA1: | E4A4EF2DF24AA5E32F8775DCD0A311DFB1ECBC24 |
SHA-256: | BA00A46A9C02D0CC4F4D14130F177CD6E15C4BE07AC920B79CB99A50C4831A3E |
SHA-512: | 5CE9912A0ACA9D10541FA5A9DCA1104B280ED123878AEF680D3C1D600729A77987AE90E2B3E8EDF5BC9B9A32BD33C65AF41689B3096824F45EBF60A0893EEE72 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1122 |
Entropy (8bit): | 5.6824520500872 |
Encrypted: | false |
SSDEEP: | 24:Yv6XokzvCzVLgEwcp06ybnAvz7xHn0RCmK8czOCYHfl8zdBe1:YviKzFgSNycJUAh8cvYHB1 |
MD5: | C79D9BB7361240D07FA2D98F2C415055 |
SHA1: | FDA5CFFDE86495283987B8AD8E79F26CD06DE75F |
SHA-256: | C8E8853F115D9C5A47A0700E787082D9E81AD216AE28225046B0925403EEF342 |
SHA-512: | 62CC86FABB6039010F5DEA245D49DC6B94FEA19CC0BB31345CBEBDF558C1B4389B9F3E1D2F6947BDD50479B5CEA1432ABD8E64A9FA713EAE9F3FA9FCC2623674 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.2892821920304804 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJfQ1rPeUkwRe9:YvXKXKVxkZc0vCSGY16Ukee9 |
MD5: | FAB64CAE574831701041F961B9EC8C07 |
SHA1: | 4EE3D93E709CD74F7547B93770445B0CD7ECDFB9 |
SHA-256: | EFB98B8527D12925DB6A93A042D7834D9F308542A1E2E09583D2A1ACAE3BF273 |
SHA-512: | 19FC528D8851AA6D5B0FFE421D7695C607A66A2C4D18ECDEB4079D3140E8365391BEDCDE49BF1777EECB698DA1AB6430C0EAC9A8899683BD0DF27F5BEF655AE5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1102 |
Entropy (8bit): | 5.672448007187651 |
Encrypted: | false |
SSDEEP: | 24:Yv6XokzvCC2LgErcXWl7y0nAvzIBcSJCBViVe1:YviKCogH47yfkB5kVz1 |
MD5: | 372CEB355CFDB4EBE379998593EC0947 |
SHA1: | 31CA42A8F3D05D43B491852221F43F509C342EC5 |
SHA-256: | 7E203096550DFA7E9601C8EB15847D509C59E8CDE168DA04B1E7CE8F0D4AE8F4 |
SHA-512: | 3212FEAA7CEB558A8E9D141967FB80CF981C317F05EF4AA2D7C14EBA1C7F86BDAD1857EC89022E6E02B2E4BEB99E9DA75300200F1ECD28F6468D16689FDD736F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1164 |
Entropy (8bit): | 5.697942204697821 |
Encrypted: | false |
SSDEEP: | 24:Yv6XokzvC+KLgEfIcZVSkpsn264rS514ZjBrwloJTmcVIsrSK5e1:YviK+EgqprtrS5OZjSlwTmAfSKE1 |
MD5: | 69D9FA0C5AFD821A51EB2434FF18B3B0 |
SHA1: | 1FF8571CBB712AFF00EE0DB875A1B881B1F50FED |
SHA-256: | 54F8EDFEB5CD73EB2E843CF7349C0CF6FAB9C2D064F721F607DBCA3CF8F76FBD |
SHA-512: | F12AB625A9472FD6BC9878667DC5DCC1AD0486CCCFD08051CE6E89E474575892AFE45C0F89EDA2CD3064B26BB0B3FE0799B85CBA4FF1FDF88FD0E56446279A47 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.292097603082132 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJfYdPeUkwRe9:YvXKXKVxkZc0vCSGg8Ukee9 |
MD5: | 0877C7AEF8892A91EBB2E1B2EF60DB34 |
SHA1: | 791DCF388A60D2398D43303D85E421C2F8EA8881 |
SHA-256: | B7849CD6995AB26D5FB13BAAEE3B36940EC94FDFF5F3AD198FC9C6A59AF77CFE |
SHA-512: | 3EE8C0A864AB839CAC35559EAD56DF9E0196D5B973671E34205250331FF81687E0126235BB78EC13B9CA836A435DB4FC52306CDB4B590C5AD6D4E0C070B806D9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.278008849198705 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJf+dPeUkwRe9:YvXKXKVxkZc0vCSG28Ukee9 |
MD5: | 1B6A7C4A64357E96FA49DA8FCCBF9AD8 |
SHA1: | 15EA1AEAAC29E5A207160E94C9F8BDB473B859BC |
SHA-256: | 94A81CDDF3F8D4290F828EA0955165D96CA624C5B27B325385EBB4C26A33F6C0 |
SHA-512: | 90F66143D8F85FD63F9B94C1AB44EC54523FE5DB8B8EAAFEC5BDDE8AB0FABAB6962F98D4548524093AE03AA0FDD02E8EA406C2C8B3CE5638FF1DFAA8F7D8C9A6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.275699012762304 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJfbPtdPeUkwRe9:YvXKXKVxkZc0vCSGDV8Ukee9 |
MD5: | 70EB2944BDD5D9474F10FA1EEC4316D0 |
SHA1: | 5B263184577C50D1EB9AD8D3985620C262952A99 |
SHA-256: | 631E13443812E8CB02430BC5B53B7FD520EC20DC603BD2067E70DF9D8C1F28CA |
SHA-512: | 9F2AF29DA3BA645BABED4A6ACB67438B3B114572F8E5BB1E53921AF3EBBB4F51C92A83BFDE232DF5F63275409815C49CBBF0F0357FE3AB227B2C14FC27F7C3B6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2805369500110855 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJf21rPeUkwRe9:YvXKXKVxkZc0vCSG+16Ukee9 |
MD5: | FD8E366A94EADEA7779A484E920097DC |
SHA1: | AC97F1033A1D17575068799C6862E955F73C0FDB |
SHA-256: | B90BC34432244223CAE58F5BF4B6C64A93F8D8873A5EB37E4B903D1EFBFDBF49 |
SHA-512: | D7919277AB4FB7D836979F70C6F8CF08CB5A4DD6CC0EF40E78470579AFDCE9308AC207F77A377D9C397172139081B6D09FC2C4732DB43A6BDC1B974C659404EF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.668281924948179 |
Encrypted: | false |
SSDEEP: | 24:Yv6XokzvC3amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSz1:YviKPBgkDMUJUAh8cvMz1 |
MD5: | E0313A352311679056470AA838F85817 |
SHA1: | 8EA09B6CFD649181E681CB8ECB1C125A1C926F23 |
SHA-256: | 7B31E1A44B7B9186EDE92ADCBC74B61BE9E3391AE6D86087AA50D169FAF9FF02 |
SHA-512: | D018F1F59846D68FE99C8705D9554D5303F899D41BC50148655BDF347BA0CA574FD7C6CA207C6396476DFDAE76AB084D5594D0444AE8B11901E00BB60273DA9E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.257847993840752 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJfshHHrPeUkwRe9:YvXKXKVxkZc0vCSGUUUkee9 |
MD5: | 6BA70009FA76489505F6EC27B9AFDE88 |
SHA1: | A4EEAF9E12B78DBBA2D12DF55A1161A297716582 |
SHA-256: | AEA206F489F03BBB8F47CCC389A565CD71769CC6AD5583E2E2C7200BC4C6CF6D |
SHA-512: | 342B92207381D4703A3102BB043410705C2B21119E92938AFAC9F47DC0228A33DDCCCE9C213B79D7399D8C7937A37210476C7FCD050111C23AD27D3C0DAE8549 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.262374840833551 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXKyG1WwzJNHVoZcg1vRcR0YAuueoAvJTqgFCrPeUkwRe9:YvXKXKVxkZc0vCSGTq16Ukee9 |
MD5: | 8D36940B775577319FA5BBD738BAE4FA |
SHA1: | 27A6DA55B04D1D28D17BFA201FB33555131DEA77 |
SHA-256: | 5DBF782109208A5A3E662F71F7DA1693055687B79CAF19A987E0576E8353AC9B |
SHA-512: | A22104429A7B21EEF752355259DA314DB375F1FABB3C9772992B1EC224BACE74565AB6926E4667557BCC00D3D10383FDC442B816D3A5C7C22059C685BA2CE269 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2817 |
Entropy (8bit): | 5.123782473021255 |
Encrypted: | false |
SSDEEP: | 48:YKhp2jylOcMKpgsnmYMfYxqPcF67t9MPp:tiBcMKpgsnmY+o63MPp |
MD5: | 725800ECF060C099E6D29EA79BB1438A |
SHA1: | 717542EBABFF7B8FB7984D7DC5081ECC8869BB88 |
SHA-256: | FFFD049C65C7D0427239DAB9B03F82F87D2857959E43C74F6DBC6C9F652861A1 |
SHA-512: | 2A32555CB21D965688DC9A35B00D6267227D8F6825DA2D776730690F183827D8D231FD884AB309A2DD1E6908D647ED2CC0EE2FA4094D4742826D4537EBC5B6EB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1884084521940013 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUf7SvR9H9vxFGiDIAEkGVvpjz:lNVmswUUUUUUUUT+FGSItL |
MD5: | C665E3093ED341D8E496CC61E0922A5A |
SHA1: | 0D55F8C496147D7D207A71865557193E83F858C6 |
SHA-256: | 730D89CF22B965457C99C001E88E3A77570389FC89D4517DA6C7D0BBE15C7719 |
SHA-512: | 8A61578FAC21A8E45C4CA39DF77331843A58FEE5D0E6E0D787B39209EE4F6DEF75B1268BC554C4C589B2CEAC70E8553198235EB60C99D9CB58FA6681E25E24FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6072253423897112 |
Encrypted: | false |
SSDEEP: | 48:7MKCKUUUUUUUUUUfvvR9H9vxFGiDIAEkGVvTqFl2GL7msH:7BUUUUUUUUUUvFGSItRKVmsH |
MD5: | A7ED218394C5CB3C3C3DA7FB6C0E491D |
SHA1: | 7219ED243D2ECD84B446379C0024D549D0092FD2 |
SHA-256: | D3700A33E2C1615ED4A3587DA026FBA017773F6511E1E7694B5C7087B48BFC7D |
SHA-512: | 72FEA634B677E52FF03FA190897DBEB4249479F463F060E86AE58883433E2C21E93B55C68B1B6575570023FECF221E427757DF6CB3F68674214680A80807AE62 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg7TX7OSo05tWd6+JIcBM/ycKjTeYyu:6a6TZ44ADE777OSo05tI96KjqK |
MD5: | DC74D5E53170682C91D9B573CBDA6958 |
SHA1: | EE89B33158734C0E8FD12B81003041C1ADFA992D |
SHA-256: | 26EECF94E3254A0AC55E74628D503A7314CDA0EA0679B11F7DFB073BA2050B83 |
SHA-512: | B26ADF1E18A71CC535F8934E87C4B18BDADCB6F0E62CEBE3F6E26463FCA535E9C6B001E8C6776E461C7183267C96CE5F3DC6084FCFB877F3437351B8E37764AC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5162684137903053 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8QpVlYH:Qw946cPbiOxDlbYnuRKtPYH |
MD5: | EFC98D1352863E45C8C298E4AC32A781 |
SHA1: | ECAF49A383D28E85AE779C93A73A7E1ACB65074A |
SHA-256: | 5AE173DA946402121B5C250B86BA0DD1D4F341328D062697EA8F7992185A76F9 |
SHA-512: | EA24AD9DB69A7EA58FCCC912A78E857CA84E9F5B742181AD418AD7DAE1D3FACF8B18429172268B2B9FF44FAC56A3354052D74AA42BB6E9F4DAE16D38FC05BBB8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-11-28 07-58-14-235.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.3653177911927825 |
Encrypted: | false |
SSDEEP: | 384:I4UxcQc6843//iGvcwmtvEOfnEDquKGOmdmCIUoJ4Tg83898l8gHgH+H5HmyHGH4:ElV |
MD5: | FC2D7D001C9DB8D886503946E4A52EAA |
SHA1: | 5DF74E65FE1E1B12B12F0D6B6CDB983267F1EC4C |
SHA-256: | 30FF51A302C5233BFC8EAAB2F785E51623387D6435B9E2827D507151A433F6E0 |
SHA-512: | F52C6563B4362CD18855E765AA9704AA5958349DB6D376E32180B17E0E873BE0E6B1BA38BAC03D180EC724019087F80C4887FD9B071F8039044295E354E9F294 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.394562798083788 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rn:r |
MD5: | 1D91B68387CC92AD6667C88B9984F63F |
SHA1: | 2AB119C25949C5F4738AE60515CC24A919E86423 |
SHA-256: | 3639430605EA71844B8E8466CA56A7ADA8263560D2D00BE697464BB89F8DF01D |
SHA-512: | 560151174AC99E586EE8074725BD89216DFCD1402B30765BF193F29623980E1F3F6ADF309D8C13B6FF5077BEBD509A05A1CEA7FF90139E2A979E7EBAAE4E5F05 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121D1ybxrr/IxkB1mabFhOXZ/fEa+fDERXTJJJJv+9UZwY0SWB4:O3Pjegf121DMNB1DofjEiJJJJm94GS84 |
MD5: | FA6978A9EA472E8ACFF72AFE8CC7CC81 |
SHA1: | D58155446B67ACF4DA331A977B8EC7BA105C2C4F |
SHA-256: | 3D0DF2B14FC632520705424D2DA394922D3EDD8C977950656B736352CD5A37E2 |
SHA-512: | 6B16382E6A4B9EECB8E8FB82189C2741511E8CF99C83B3FA52B062165B3B366EE0C11A7F60CE4B08D881B2418234097FA13CCAA9C90B1D7D37BD4D9A56EBA96C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/yowYIGNP4bdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07WWL07oBGZd:twZG6b3mlind9i4ufFXpAXkrfUs0qWLa |
MD5: | 8D04FDC5022E491B91EC6B32F003430B |
SHA1: | 6619D46E06076B5669D4CC677D6D8F638189E46A |
SHA-256: | 7682C53053D66EF0B1A89335C88C4420226B10AFAC87A286E6E1A6BC795FEE61 |
SHA-512: | AA96FA56D3C5C4200BAA917D3091ADB1A5FAE7D534DD9C909D8B60AE13E902D6B71D42C2823319483414987E4B41079FA241B3D0A384EE4B281B63F834917E7D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:rBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOFjNOX1Lj3vfE4JvWTlP:r+Tegs661ybxrr/IxkB1mabFhOXZ/fEh |
MD5: | C14EBC9A03804BAB863F67F539F142C6 |
SHA1: | FD44F63771819778149B24DD4B073940F5D95BFA |
SHA-256: | A495629FA5E71EE50BB96F9C4CAEAC46E8B44BFC3F910A073348258F63DFAFCE |
SHA-512: | 8ED832A54A3925914E3BCFC96A3ABFF63A511ADAC79A869AD1569BB175CC1AF84E6C2BD20FA2187A5C3B733625EDE5D95C2172B24ED2F252835689F6D4A0F5A2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/VRaWL07oYGZlYIGNPJKdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07c:tRaWLxYGZlZGu3mlind9i4ufFXpAXkrj |
MD5: | 80810A6BBD1140B4448CC39EE2349290 |
SHA1: | 3BAB3900903546D160F952AE78050C6A9FFA87B0 |
SHA-256: | BEA84A96782F94822B51A08753E155847A92DFE416A320103BF641AD9132CB49 |
SHA-512: | C6C2BFCCC5E6EF9B06732488E07839A3048582177C2DB7B17013A372AA613A1620320D9F63F2A6EBBC3AF8BDA9F56EE74F8705E168560B222EFEAD2C325425DB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 24 |
Entropy (8bit): | 3.66829583405449 |
Encrypted: | false |
SSDEEP: | 3:So6FwHn:So6FwHn |
MD5: | DD4A3BD8B9FF61628346391EA9987E1D |
SHA1: | 474076C122CACAAF112469FC62976BB69187AA2B |
SHA-256: | 7C22C759CA704106556BBC4FC10B7F53404CA1F8B40F01038D3F7C4B8183F486 |
SHA-512: | FDAF3D9F8072ED7DE9B2528376C10E3C3FDBEA74347710A4795BECF23C6577B3582B2E89D3C04EF0523C98FE0A46F2AF3629490701A20B848C63BA7B26579491 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.414047851487961 |
TrID: |
|
File name: | document.pdf |
File size: | 3'000'337 bytes |
MD5: | 1564debc205330db6ec59839837de047 |
SHA1: | 07fe560f2f5b66bab01b3847aa26196ae8905a02 |
SHA256: | ac1d3a7d60e52c4b49fb2ab1cba0257e763bd2c26a971ce1161e3ae118dbc5cd |
SHA512: | 04224f5e0131978298aba57e1fe91b3326839b59a4af34b4d217390b9ce5221ac521cf2c66fde0a1b18c91193bad5c564a5388fcc1b39bda25ac0df02b771ea8 |
SSDEEP: | 49152:y9LAsFco7FQZhA/YRIIRK0dM5TTijxd7yOr4/nBzLHkYN:CLAmcaenA/YOWZKTy75ABTN |
TLSH: | FBD5CF91B28D1D44C28943FC11BBB6142B6DF0E19BD3E2DB2A68A371B677FA1EF45101 |
File Content Preview: | %PDF-1.7.%......1039 0 obj.<</Linearized 1/L 2948780/O 1043/E 296086/N 14/T 2927878/H [ 878 1158]>>.endobj. ..xref..1039 28..0000000016 00000 n..0000002240 00000 n..0000002474 00000 n..0000002512 00000 n..0000002549 00000 n..0000004525 00000 n..0000 |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.7 |
Total Entropy: | 7.414048 |
Total Bytes: | 3000337 |
Stream Entropy: | 7.406400 |
Stream Bytes: | 2835302 |
Entropy outside Streams: | 4.917050 |
Bytes outside Streams: | 165035 |
Number of EOF found: | 3 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 349 |
endobj | 349 |
stream | 143 |
endstream | 143 |
xref | 3 |
trailer | 3 |
startxref | 3 |
/Page | 28 |
/Encrypt | 0 |
/ObjStm | 8 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 1 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
1058 | 0000000000000000 | 9bb57bb3adc8f26f88132ea9352d89f9 | |
1059 | 000000008080c0e0 | 7115c92e2337a485f0302d950dc04e1d | |
1061 | 9918496d7ced793f | ec871ddca4128b3c5e92d18dff01f765 | |
1062 | b26972102a9258f0 | 1af62b073fa4387eb06ca83bd47f5879 | |
1063 | b26872102a9258f0 | 7c90c7582d27bbd2ae29e054107457ba |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 28, 2024 13:58:22.860780954 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:22.860829115 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:22.860958099 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:22.861136913 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:22.861150026 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:24.274570942 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:24.274857998 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:24.274876118 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:24.275960922 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:24.276036978 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:24.276046038 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:24.276135921 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:24.276398897 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:24.276460886 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:24.276647091 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:24.276659966 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:24.325932980 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:24.775367975 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:24.775389910 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:24.775449038 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Nov 28, 2024 13:58:24.775480986 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:24.775598049 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:24.776715994 CET | 49744 | 443 | 192.168.2.4 | 50.16.47.176 |
Nov 28, 2024 13:58:24.776735067 CET | 443 | 49744 | 50.16.47.176 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 28, 2024 13:58:23.263371944 CET | 53958 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 28, 2024 13:58:36.404736042 CET | 49817 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 28, 2024 13:58:54.233349085 CET | 61759 | 53 | 192.168.2.4 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 28, 2024 13:58:23.263371944 CET | 192.168.2.4 | 1.1.1.1 | 0xd7cd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 28, 2024 13:58:36.404736042 CET | 192.168.2.4 | 1.1.1.1 | 0xf855 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 28, 2024 13:58:54.233349085 CET | 192.168.2.4 | 1.1.1.1 | 0x3e70 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 28, 2024 13:58:21.079267025 CET | 1.1.1.1 | 192.168.2.4 | 0xc74b | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Nov 28, 2024 13:58:21.079267025 CET | 1.1.1.1 | 192.168.2.4 | 0xc74b | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Nov 28, 2024 13:58:23.495650053 CET | 1.1.1.1 | 192.168.2.4 | 0xd7cd | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 28, 2024 13:58:36.543066025 CET | 1.1.1.1 | 192.168.2.4 | 0xf855 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 28, 2024 13:58:54.468641996 CET | 1.1.1.1 | 192.168.2.4 | 0x3e70 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49744 | 50.16.47.176 | 443 | 7780 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-28 12:58:24 UTC | 1473 | OUT | |
2024-11-28 12:58:24 UTC | 608 | IN | |
2024-11-28 12:58:24 UTC | 4762 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 07:58:09 |
Start date: | 28/11/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 07:58:11 |
Start date: | 28/11/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 07:58:13 |
Start date: | 28/11/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |