Windows
Analysis Report
Invoice Number INV132146-1.pdf
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
Acrobat.exe (PID: 7944 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\I nvoice Num ber INV132 146-1.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) AcroCEF.exe (PID: 8140 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) AcroCEF.exe (PID: 7544 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=17 16 --field -trial-han dle=1548,i ,181078742 2946126097 6,17683304 7346087958 74,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
chrome.exe (PID: 5684 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 9064 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1968,i ,893187728 8581135740 ,143673552 5690537163 ,262144 -- disable-fe atures=Opt imizationG uideModelD ownloading ,Optimizat ionHints,O ptimizatio nHintsFetc hing,Optim izationTar getPredict ion --vari ations-see d-version= 20250306-1 83004.4290 00 --mojo- platform-c hannel-han dle=2040 / prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7972 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://thera pyforhappi ness.co.uk /ra3.pdf" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • AV Detection
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Hooking and other Techniques for Hiding and Protection
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Phishing |
---|
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 11 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
11% | Virustotal | Browse | ||
18% | ReversingLabs | Document-PDF.Trojan.ScamX |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | high | |
google.com | 142.251.40.142 | true | false | high | |
e8652.dscx.akamaiedge.net | 23.48.144.248 | true | false | high | |
edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | 208.89.73.17 | true | false | high | |
www.google.com | 142.251.40.228 | true | false | high | |
x1.i.lencr.org | unknown | unknown | false | high | |
therapyforhappiness.co.uk | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.251.40.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
23.48.144.248 | e8652.dscx.akamaiedge.net | United States | 20940 | AKAMAI-ASN1EU | false |
IP |
---|
192.168.2.4 |
192.168.2.23 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1646479 |
Start date and time: | 2025-03-24 03:35:33 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 36s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 25 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Invoice Number INV132146-1.pdf |
Detection: | MAL |
Classification: | mal52.winPDF@43/48@46/4 |
Cookbook Comments: |
|
- Corrupt sample or wrongly sele
cted analyzer.
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, WMIA DAP.exe, SIHClient.exe, SgrmBr oker.exe, backgroundTaskHost.e xe, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 23.51.56.185, 23.2 00.0.173, 23.200.0.196, 34.237 .241.83, 18.213.11.84, 50.16.4 7.176, 54.224.241.105, 162.159 .61.3, 172.64.41.3, 208.89.73. 17, 142.251.32.99, 142.250.80. 46, 142.251.40.206, 172.253.12 2.84, 142.250.80.99, 142.251.3 2.110, 142.250.65.174, 142.250 .64.110, 142.250.80.78, 142.25 0.176.206, 142.250.65.206, 142 .251.35.163, 142.251.40.110, 1 42.250.80.110, 184.31.69.3, 20 4.79.197.222, 20.109.210.53, 2 3.56.162.204 - Excluded domains from analysis
(whitelisted): clients1.googl e.com, fp.msedge.net, e4578.ds cg.akamaiedge.net, chrome.clou dflare-dns.com, fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, acroipm 2.adobe.com.edgesuite.net, ctl dl.windowsupdate.com.delivery. microsoft.com, ctldl.windowsup date.com, clientservices.googl eapis.com, p13n.adobe.io, acro ipm2.adobe.com, fe3cr.delivery .mp.microsoft.com, clients2.go ogle.com, edgedl.me.gvt1.com, redirector.gvt1.com, armmf.ado be.com, ssl-delivery.adobe.com .edgekey.net, a122.dscd.akamai .net, update.googleapis.com, c lients.l.google.com, geo2.adob e.com, wu-b-net.trafficmanager .net - Not all processes where analyz
ed, report is missing behavior information - Report size exceeded maximum c
apacity and may have missing b ehavior information. - Report size getting too big, t
oo many NtOpenFile calls found .
Time | Type | Description |
---|---|---|
22:36:47 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
23.48.144.248 | Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | Get hash | malicious | PureCrypter, AsyncRAT | Browse |
| |
Get hash | malicious | SheetRat | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | SheetRat, XWorm | Browse |
| ||
Get hash | malicious | Amadey | Browse |
| ||
Get hash | malicious | DarkTortilla, LummaC Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
google.com | Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XRed, XWorm | Browse |
| ||
Get hash | malicious | XRed, XWorm | Browse |
| ||
Get hash | malicious | XRed, XWorm | Browse |
| ||
e8652.dscx.akamaiedge.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DanaBot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
bg.microsoft.map.fastly.net | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | DanaBot | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | PureCrypter, AsyncRAT | Browse |
| ||
Get hash | malicious | SheetRat | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AKAMAI-ASN1EU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.217087845694844 |
Encrypted: | false |
SSDEEP: | 6:iOsI/RWMR+q2Pwkn2nKuAl9OmbnIFUtCI/ROOZmwgI/RKMRVkwOwkn2nKuAl9Omt:7pMrvYfHAahFUtLUO/NQM/5JfHAaSJ |
MD5: | BCF306EC86715340B19172889997B786 |
SHA1: | EFB3B4E68A612C109DD26409D0F50E7DD9494F30 |
SHA-256: | 56BBFEA8B4847735F18739262070CD8DFB6BDF4835A41DBE79EEA578760FD01E |
SHA-512: | 1513E6B7972FF6DE204706927F5E7112AD7567EAB903AB65B74BD39B1B5943652FF2C2E02BC1A1527B604A9DC56EFE6F4A19697EE35B670065354FD60D2D4382 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.217087845694844 |
Encrypted: | false |
SSDEEP: | 6:iOsI/RWMR+q2Pwkn2nKuAl9OmbnIFUtCI/ROOZmwgI/RKMRVkwOwkn2nKuAl9Omt:7pMrvYfHAahFUtLUO/NQM/5JfHAaSJ |
MD5: | BCF306EC86715340B19172889997B786 |
SHA1: | EFB3B4E68A612C109DD26409D0F50E7DD9494F30 |
SHA-256: | 56BBFEA8B4847735F18739262070CD8DFB6BDF4835A41DBE79EEA578760FD01E |
SHA-512: | 1513E6B7972FF6DE204706927F5E7112AD7567EAB903AB65B74BD39B1B5943652FF2C2E02BC1A1527B604A9DC56EFE6F4A19697EE35B670065354FD60D2D4382 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.1643022056632315 |
Encrypted: | false |
SSDEEP: | 6:iOsI/RWjyq2Pwkn2nKuAl9Ombzo2jMGIFUtCI/RVG1ZmwgI/RVQRkwOwkn2nKuAv:7pMyvYfHAa8uFUtLfg/NfQR5JfHAa8RJ |
MD5: | 596CC9A34B8913678D090A2697F2B207 |
SHA1: | A5B2180D14BAC056576918CC92633580AB2807A8 |
SHA-256: | 3367A9005F37584EB2CA1F8064F35704F8925F47AEEFE891115217529EB1B117 |
SHA-512: | 3E04D2B8E7C4FE33598F26E7D2CF3B581FB0782D811914DFC44E90DBDA79F72AE87ED59E7C4E2FA54A4C44D1E105E5DD6FE51AF53F4F676317DE3C0917DAE4A2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.1643022056632315 |
Encrypted: | false |
SSDEEP: | 6:iOsI/RWjyq2Pwkn2nKuAl9Ombzo2jMGIFUtCI/RVG1ZmwgI/RVQRkwOwkn2nKuAv:7pMyvYfHAa8uFUtLfg/NfQR5JfHAa8RJ |
MD5: | 596CC9A34B8913678D090A2697F2B207 |
SHA1: | A5B2180D14BAC056576918CC92633580AB2807A8 |
SHA-256: | 3367A9005F37584EB2CA1F8064F35704F8925F47AEEFE891115217529EB1B117 |
SHA-512: | 3E04D2B8E7C4FE33598F26E7D2CF3B581FB0782D811914DFC44E90DBDA79F72AE87ED59E7C4E2FA54A4C44D1E105E5DD6FE51AF53F4F676317DE3C0917DAE4A2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.961305759039287 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqFX0tsBdOg2HP3fcaq3QYiubInP7E4T3y:Y2sRdsIpdMHvu3QYhbG7nby |
MD5: | 607D90F39127CBB9ACD5FDA349632DF5 |
SHA1: | 3FE20FE3C76CE0E54B27175086AD0B54B452D200 |
SHA-256: | 06CEFD5F8843B98B8FB66F4C328C965DDAB1EEF9669017B03A1598711A8139C7 |
SHA-512: | 2E89CB4F8895DA93968E727CB1B459FD504E855091234DE205140B280646CF166A177003798D1A87CBF62C65432AE732ED5B3516F865489BB2DA5B24FC242A73 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.961305759039287 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqFX0tsBdOg2HP3fcaq3QYiubInP7E4T3y:Y2sRdsIpdMHvu3QYhbG7nby |
MD5: | 607D90F39127CBB9ACD5FDA349632DF5 |
SHA1: | 3FE20FE3C76CE0E54B27175086AD0B54B452D200 |
SHA-256: | 06CEFD5F8843B98B8FB66F4C328C965DDAB1EEF9669017B03A1598711A8139C7 |
SHA-512: | 2E89CB4F8895DA93968E727CB1B459FD504E855091234DE205140B280646CF166A177003798D1A87CBF62C65432AE732ED5B3516F865489BB2DA5B24FC242A73 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4730 |
Entropy (8bit): | 5.2626451702734975 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7A7bi5cnbiZ:etJCV4FiN/jTN/2r8Mta02fEhgO73goP |
MD5: | 0AA697CFE4DD9B9D87B7EA24D05649DF |
SHA1: | E4F7D85BD736CC83AC93E1991F92F6A168393C52 |
SHA-256: | E9EED52272D7117B7A463C774CBB5A25A9E57D92FB7C86208E89B80D2AC04541 |
SHA-512: | E2C9B10F0C22823A014D861C8BF4FBC8607C2C43FECC4BCFA8DEE07140082B7C6C4229B8C00F5A6B6DBE893702CC63D34B8FFC140887E3AC4FB60F251291D9C6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.175954076925481 |
Encrypted: | false |
SSDEEP: | 6:iOsI/RgHyq2Pwkn2nKuAl9OmbzNMxIFUtCI/RgR1ZmwgI/RgXBcVjRkwOwkn2nKA:7piHyvYfHAa8jFUtLib/NiXBc9R5JfHP |
MD5: | AF91F0D644A485AE542D5B2287915C58 |
SHA1: | E5EE2871BA2EB42114F9E72AA3B4CFD5E0AFD0E6 |
SHA-256: | 2C306AB48CA41174788EB00418692D9B5D3C11EB0E2F9DFCE90ABAF731C86CF2 |
SHA-512: | CF67F2AE0D484A10FFD228829BFD75A5939406157A8D2E5E90B2F67E26E0C6AF3F29711214CA2069E0B52E48725071E5C88A7040312D6F9D9DC3F40B6FF8B048 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.175954076925481 |
Encrypted: | false |
SSDEEP: | 6:iOsI/RgHyq2Pwkn2nKuAl9OmbzNMxIFUtCI/RgR1ZmwgI/RgXBcVjRkwOwkn2nKA:7piHyvYfHAa8jFUtLib/NiXBc9R5JfHP |
MD5: | AF91F0D644A485AE542D5B2287915C58 |
SHA1: | E5EE2871BA2EB42114F9E72AA3B4CFD5E0AFD0E6 |
SHA-256: | 2C306AB48CA41174788EB00418692D9B5D3C11EB0E2F9DFCE90ABAF731C86CF2 |
SHA-512: | CF67F2AE0D484A10FFD228829BFD75A5939406157A8D2E5E90B2F67E26E0C6AF3F29711214CA2069E0B52E48725071E5C88A7040312D6F9D9DC3F40B6FF8B048 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 82710 |
Entropy (8bit): | 1.2272662388702138 |
Encrypted: | false |
SSDEEP: | 96:dxWKmN/c/uSE/M/zYzWKOG75+MPBofgv1vucmgeYymqAiGkkg:dxw1SuupHITGfW1vgge8+ |
MD5: | 98F06D06F95BE5918A05315393F18BDF |
SHA1: | 37E3683B0A201DB8E67E2341002E04152E145A9C |
SHA-256: | DEBA64094F095542C8C7D2FD63C311A724D644802201B8CF3660B531CFCAE3F2 |
SHA-512: | 80A45505F1B613B6172A32F52BC8C8AFE3DF8412499AD08116B356B8E081AA70F41A39144F4B91C10A5CD14F26943C34DF48E22A19AE1D0A6FEC63B42B255C01 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.445289152750366 |
Encrypted: | false |
SSDEEP: | 384:yezci5tOiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:rhs3OazzU89UTTgUL |
MD5: | 82C65B3FEAA10C0328396585825D4AB2 |
SHA1: | 2458A4E27BCB216FB2DFBD11F93CDAC592F7A01E |
SHA-256: | 7E636C680E2047F654B7871E45F62D8AA3042A8B6DCBEBD7A1FCD782DAB7CB73 |
SHA-512: | A85D89D821BA33EA18088F8F049CCA8A3C96FA3691CDA033F2C23F9659850DCB9C01F23147855F417B72F0A7161B21E5FF281AF03B7B3E058C0F8202B8E30462 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.774975781344303 |
Encrypted: | false |
SSDEEP: | 48:7Mxp/E2ioyVt5Fioy9oWoy1Cwoy1k5uKOioy1noy1AYoy1Wioy1hioybioye5qo0:72pjuJFAXKQwKb9IVXEBodRBk4 |
MD5: | 5BCBE8B894BB28D1EEB42BC551458068 |
SHA1: | 10D831169FA3973021FB3E70B85706BC4EB65762 |
SHA-256: | 26C198CAEC3BD24E137B1F2EE6BF018D686DE94B8E6FD35D4B9AF49BB4147966 |
SHA-512: | 60333D92BCFECD5208E8AEBE5805769A94FE7DCF298B669EABEF24D3D58EE3A8DB00A1D9D18A2EE152E73624CCF601E527C61B793DF9A74D644D9F0E6753AB6E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 73305 |
Entropy (8bit): | 7.996028107841645 |
Encrypted: | true |
SSDEEP: | 1536:krha8mqJ7v3CeFMz/akys7nSTK7QMuK+C/Oh5:kAOFq+Mba9Ok7C/O/ |
MD5: | 83142242E97B8953C386F988AA694E4A |
SHA1: | 833ED12FC15B356136DCDD27C61A50F59C5C7D50 |
SHA-256: | D72761E1A334A754CE8250E3AF7EA4BF25301040929FD88CF9E50B4A9197D755 |
SHA-512: | BB6DA177BD16D163F377D9B4C63F6D535804137887684C113CC2F643CEAB4F34338C06B5A29213C23D375E95D22EF417EAC928822DFB3688CE9E2DE9D5242D10 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7464849065063075 |
Encrypted: | false |
SSDEEP: | 3:kkFkl92B1fllXlE/HT8k33XNNX8RolJuRdxLlGB9lQRYwpDdt:kKVMT8+NNMa8RdWBwRd |
MD5: | 023430F4DCEDAB3FCF91ADC4E4476686 |
SHA1: | 5E953DF79509AB48FDACD7E7151655F654F20CBC |
SHA-256: | 4FFE9CEA7CC1B72B0FD03D7551B7AC7708B6B79E15ECFDC4D7EEB419661FE9A7 |
SHA-512: | 58D3FE44C8FE79ED999B935BE47A0E63E7E9F7B4E984454A886AE6F28E232EB9426ACDBE4FBF9EB40FC7EE89694A35B618CD7C3F9CCC7C1D06C280484EE051FB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 3.167835558082537 |
Encrypted: | false |
SSDEEP: | 6:kK0rmcvSN+SkQlPlEGYRMY9z+4KlDA3RUeqpGVuys1:srmCkPlE99SNxAhUeq8S |
MD5: | 8568FC2ACD1711B68882935CD1BDE58A |
SHA1: | 358514124B04E985BAAB33DEEBD34246AA0637CB |
SHA-256: | 774E4517E692014AA2D2F234C6E7E588A95343D417EB1423A33C084266D45144 |
SHA-512: | DCB55F99EDC964FBAF3556CCB6D6EFB3CD5AAFA4A68A3AD557783CF64ACF73091759BBDDBA9424CF9C5A67F8ECEC143C6B410E048E00442857D2A54B1CA56D33 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | 1536:JsVoWFMWQNk1KUQII5J5lZRT95tFiQibVJDS+Stu/3IVQBrp3Mv9df0CXLhNHqTM:bViyFXE07ZmandGCyN2mM7IgOP0gC |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | 1536:JsVoWFMWQNk1KUQII5J5lZRT95tFiQibVJDS+Stu/3IVQBrp3Mv9df0CXLhNHqTM:bViyFXE07ZmandGCyN2mM7IgOP0gC |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.342615574177554 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJM3g98kUwPeUkwRe9:YvXKXTlakZc0v6ssGMbLUkee9 |
MD5: | 16873879C84BD9D5E276CAFE29B39C15 |
SHA1: | 46BED835C597139B54CE1D220B8810673864EC8B |
SHA-256: | BBAA0654EFB6E0373628C259AFF8022CE31A0C28544067E913B38EA0EE7D0DBC |
SHA-512: | 4A287F1D714F85D78B57F1E3078CFC6C596B45522DE031E0AD3D7364A7E878A51308AECD9ED9919ABA70CE321118A35BCD972FB7E14204F7AA9967AB004E13AB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.29150881079833 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJfBoTfXpnrPeUkwRe9:YvXKXTlakZc0v6ssGWTfXcUkee9 |
MD5: | 07027C05DE711663D94F7492487285C2 |
SHA1: | 95CA9EA8DAA9C0CF82AACDE51AA5FFE412E78934 |
SHA-256: | 7753C37B5768964F55982D5421FDED4E2A00AD458FFCCEB2AFB9D2E6D73F37EB |
SHA-512: | 21BDDD57329F486212BB4B64AC6D009868E2FB845A7C8BDDE4FFD43CD89843253EF33A000E8E825B819664FC6D6F8134BD6A30108E74FB809467826E28148639 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.270776604713 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJfBD2G6UpnrPeUkwRe9:YvXKXTlakZc0v6ssGR22cUkee9 |
MD5: | E534014C3D6711F2059C991C92F5BFEE |
SHA1: | 9A7D5180D246EDB8A8958831CB13F46602B22ADE |
SHA-256: | 3AAC95D99E85C98FCBBBB6111377A634F9C0E25AE8C2C0DB9F6D3F74C64B36CC |
SHA-512: | C4582FAC594F0D64AE073FB3AE64EE6BC832A6894A2F7E7113DEE70083D82CC96455B8C49AE098C982A5682CF6D45C5252BDEEA5F73A48D188FF6C14319247BD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.328898086964306 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJfPmwrPeUkwRe9:YvXKXTlakZc0v6ssGH56Ukee9 |
MD5: | 7283FB20CD5F114E125744B2C89405E7 |
SHA1: | 464E26364BD6AE0E0FAC47B4B6D9A730E1B47FCD |
SHA-256: | D5147C653F10BB8EA552135EF6532068F7768AB1F982A067AD92BF3BE12BD3A9 |
SHA-512: | CC19D9DF1AE528AA9621F4B63C367B8EC626FA7C32D4AB3BBC66106BFD7B8BB39C6D5B735D83B8E70CEFEF74EC697D823B3E5EC0571696033AF7AE82181F4B8E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2129 |
Entropy (8bit): | 5.844375918141963 |
Encrypted: | false |
SSDEEP: | 24:Yv6XVzvNJpLgEGycjycR84bNerISIedJGWQxiE5iODneLKnlYMfNcX5bpEsrAr39:Yv21Jhgly48Y/TWCjiOumNcXwKOpkU5 |
MD5: | B975832F38DE751AD18EF590CCB1D2AD |
SHA1: | 811E28673692DA3F61569A9F3F3F4DCEB79D3C1D |
SHA-256: | 6B2508AFFD66DCE1D8FD25E5E52B2BE256858525D887D2A5AEC9A09CBC19B3A4 |
SHA-512: | 625A95301C0609E1CAEAAA46E81554545B32D157E1743519537306204D3DCF564667FD204A4B72DF1C575BF058DE51A28E3BD9E17685AEFB6CFDF0BCC1125C2E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.277461292764398 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJf8dPeUkwRe9:YvXKXTlakZc0v6ssGU8Ukee9 |
MD5: | FF2E4C0D2F85551128C854AC9A6966B5 |
SHA1: | CA209E3C2CE5325CCE9F4C21B5AA9F16ECA26390 |
SHA-256: | 363A01C829CC0F242AB1ADDC85BFDC683DA22E88FD25C60A200F5B4ADC8492B3 |
SHA-512: | AC6021A43E312412EBAE3B2A626CE75A2234C9CB6DACE9866049D2A5BCBCFC3E974B770BE7D07EB67264E1C9E4FFE4593A489837EC82B584577B2FC527018A9F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.281318863720742 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJfQ1rPeUkwRe9:YvXKXTlakZc0v6ssGY16Ukee9 |
MD5: | 9391C28DF3074A41023E1833CAE34875 |
SHA1: | 8CD21B82ACCBF6BB0F54270D935A77D9FEE4466A |
SHA-256: | 3218C99F8CEE66AAD84A09D312FA9A38C1AC6A460F30648B01FF031827446F3E |
SHA-512: | DAA7E64278B1F37729F094CC091389362D31B809903FC11EF83E87F8FBB87318637CDC8980D4B21F2CAC99CC53D3CAE7F1038A2DAA8F09C85AB3E266E36FEDB4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2080 |
Entropy (8bit): | 5.830749446419773 |
Encrypted: | false |
SSDEEP: | 48:Yv21EogbN48l/GiyLVzyODVHKOkQLcSmjWA5:Gkjg54Y/IVO48OkQASmB |
MD5: | D613D33608947E0737BC516648ECE425 |
SHA1: | 0766F8F1680508A357D614C70A1377212A8A98F1 |
SHA-256: | F818A9EA83CC4BBBB32F0581FA40B0B9EEEC10D3447AEE76CD8A982655658AEA |
SHA-512: | B32B3565D7DDFD4FDBBEBF537EAF09623B316F9D89FECF2A39D32625E469B5C87E797A589515479F723BD900FD1E35D66C44E5EFAAC35C8436AECC2F2A3581A4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.302677147526681 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJfzdPeUkwRe9:YvXKXTlakZc0v6ssGb8Ukee9 |
MD5: | 6E02363459FD7CC77A3AFB34619F6201 |
SHA1: | C0A8EFD443175C18FCA2871BE117D429D6ABA9A6 |
SHA-256: | 416013F4E72CC571222A1B9341B91A7DC94843D02D2712545DD91F1690307996 |
SHA-512: | D4E6D868C7695A69C08E157D31907DC1F28D4AA3391AC1FFCEC77862CAE942E22FB15D5847B01E0AD9C4C6633F8CEEFA28713802763EFF11BF265FAFE0874BC8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.282974458326834 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJfYdPeUkwRe9:YvXKXTlakZc0v6ssGg8Ukee9 |
MD5: | CCB16302478862981FA5F28193DC56EF |
SHA1: | 162B6DE883C7306075F9851FC3217B61C00038ED |
SHA-256: | 7915E28EC107B5A37415528B472DF04FE9BFC658A3BD72210F0FFE7841F70598 |
SHA-512: | 3062C22DFBB852BE9A9E557462539BE3AC92C0897BCC96D5BC59F25D1AF4A8CCB7407F068FC96E6BC9423CF8B51FB410FAE58E2E77A958EA0E388505EEB6F114 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.269306439318176 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJf+dPeUkwRe9:YvXKXTlakZc0v6ssG28Ukee9 |
MD5: | D55C04F88202E1AFE932F2115793BFF9 |
SHA1: | C631626D61F00051CE5910A4609D6091E8577E6F |
SHA-256: | 99C14B5E44A693D17CE2EF758BD89F91C9CB6CE68227EB20B441B741C5BB9646 |
SHA-512: | 7772178848D28AA23E828679EF2BEF74016893D4BFABA80CDB7837E9AC01D94E2487CBE958A649F060A8E58C47088B07EB38A90835AD30A1763E7A5BD7584FA6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.266638570032815 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJfbPtdPeUkwRe9:YvXKXTlakZc0v6ssGDV8Ukee9 |
MD5: | 1AA959161ED7626302FF4DBDBD67AE70 |
SHA1: | CA008884504D95BC3F01982E5A7B0327B776F893 |
SHA-256: | 60AB3DA3D46B5B796957B9499532A977CBA4BB595C240A997D43CD75803786EA |
SHA-512: | E96C4C086BC54CC5FBB1401D4E50C82497913152E6182B92A5CFF6F4714BB27C2CC6F6172F58C188866B4A21D09FC0A6FD06016E07464E81D8749D6F46ECDE89 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.271054363747213 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJf21rPeUkwRe9:YvXKXTlakZc0v6ssG+16Ukee9 |
MD5: | 11AFFD6B40022B78A58E205AD62D7714 |
SHA1: | 320C819E12B4D5DE3829DC3A7F3A65D3A7BE7B55 |
SHA-256: | 47CF52189B42B340FE7C2C585F3EF2DDB513AD87402EEF182E699E711ADBCF55 |
SHA-512: | ECD325649F9F97B08B963D73319B7D2D29DF45A706F1CAB96ECD652864D9518AFDC0C9B1CEA364F99B98A194411B51348AD9CCC1BC9C0F573DA501C3F20C2ED1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2028 |
Entropy (8bit): | 5.843945036249289 |
Encrypted: | false |
SSDEEP: | 24:Yv6XVzvN5amXayLgEdycgNaLcR84bqerISIQ1iyLPZYMWD8W3V1LFnU6QHlOBED+:Yv21FBgBG48j/SiyLVWOAlNkU5 |
MD5: | BA52AE78C7C0F69CFF07FD2A023026B3 |
SHA1: | 2B1F6403BD755C374DB6A40E95DF53B1D150DCC6 |
SHA-256: | 82462B7AE8E1A455AB545DF382370DB7D7F2F87ED5683079E48306C48452B513 |
SHA-512: | 376934FBB9A4073D29169A31EF4910C4B26F894E4B81EDD49F586ACB32719E3497E9A189385E6D9D50416D855EBE0D437A7C2DFB241E7DB66702CCC83FB1874F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.249206439973372 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJfshHHrPeUkwRe9:YvXKXTlakZc0v6ssGUUUkee9 |
MD5: | 4AABBEAF7194597407770F5BF5591012 |
SHA1: | 8548F1B0AB779FDCFBA3B80D2B77900675FF4E47 |
SHA-256: | 573C28FE4138B2FE38DF572C86E9FABD623B827D029793E46559E56671BD122C |
SHA-512: | 740A72DEBF31E24519599DD81CE619ADB4FCE4EDD551740E78772955FD862773E572F9659370A4B911B101BDC3722FFBBCC4805D9CE6034026F5F4A3A16768D3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.259830329900978 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/7lUtNHVoZcg1vRcR0YWasDoAvJTqgFCrPeUkwRe9:YvXKXTlakZc0v6ssGTq16Ukee9 |
MD5: | 0DCBCA8BF0785782431091BB46D44D39 |
SHA1: | E1A869EAC034C83EAD87F65880BB6FB943872A6A |
SHA-256: | C707E5BEC1E20A1F2369DE021E7B6E91C73B785B7A90C6907928EAC9C30A19B0 |
SHA-512: | 55028148B7BEF921B56692AE7D21FB5E47F2388ED73FF812B42FB4BD09D9F875A2EE503AF5BC053E8358170791FB4530296256E940131BEE0F3F473001B529E8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2815 |
Entropy (8bit): | 5.123695802477363 |
Encrypted: | false |
SSDEEP: | 24:Y9OxaaJEaye8CJsAm581fJZQ5mh6k4vj3Lj0SZsFAh26Ap/2LS7CY8CXT4Gy65Rw:Y9iJnDWMRZQkx83uFYSV9ECXsGrY9Jx |
MD5: | 87EA7D02C81F9B3ECF12F8B334630810 |
SHA1: | 5728E052BC9BD91E1618D6657F76DBAAFB547578 |
SHA-256: | 82954F49BAF8F0886A1359DBCAC731A28B9C88F6DF36CDDDC92E79093785325A |
SHA-512: | 57EF3ADE7A790EC0F559A04D65B5BAF91608C0F81E33DEBE9D309AB90DD6D0B44F01D89EF5D819E45E757BA31358C7CD90CAEEA05A9FA3174781B6C7E6B7EC87 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1884302967422076 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUqdSvR9H9vxFGiDIAEkGVvpOp:lNVmswUUUUUUUUqd+FGSItqp |
MD5: | E110C0064B0A502870A3428E6029E64A |
SHA1: | 5D1EE2CDEE99C8D49DD50D96200507786BD25694 |
SHA-256: | C5B2A33F47FF3DF14ED97E401DF931725BB121C79E2731D4A6C672E0C12C438A |
SHA-512: | 6E0AE865A7FAFFE4B73CA9FF94A248F52B63B682FDC4BCDDD702E465623027C85F0CD317FE77CB6DE4ED3FE5C65038F039D95AE4E34394C497D390CC57FB9452 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6093318053126184 |
Encrypted: | false |
SSDEEP: | 48:7MvKUUUUUUUUUUqlvR9H9vxFGiDIAEkGVv6qFl2GL7msj:7dUUUUUUUUUUqBFGSIt0KVmsj |
MD5: | ACBBE908E5D3D462CEC5FF45AC5BC66E |
SHA1: | 914D7D4002A20EAEDFFD9B8249F72E77009648A7 |
SHA-256: | EBD68CF2BDAE0EA649DE5E5AA6BCABD8878C417CBF78F467B6DAC282CC46C3F7 |
SHA-512: | FDF6C753F5676F64442432A9F2F9EF99261590332933E6A5356D139AC712216D6FEB1706C04A6B815845C7640FF81F36EE9DD0C6C28FF6A4708C28BE65DF74D9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5248044522866877 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8r+lUlpv:Qw946cPbiOxDlbYnuRKqrv |
MD5: | 57CAE26696790C61C5BCE8786B3DE291 |
SHA1: | DE660FC6C984AAA48AD8AC0504CDEF755D4FAA60 |
SHA-256: | 71397A796D09AA12ED3422C64837CC723CC534B97398CEDE37D5454450149B48 |
SHA-512: | 617D20D87B83D35A5705E694EF66A0EADB0935D2A1D71C540B920C482635C986B273C4D2A15D2565DF24FD4BC8C9B1D9181C33AE4080429B9C2F970026B323C5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15099 |
Entropy (8bit): | 5.367809281084369 |
Encrypted: | false |
SSDEEP: | 384:leEH8S53+hULceS4HAKfbpz2qlIDYxtxdxzMdqUqazRp5cYzK7VS8vCDEUCHPeDJ:B0O7XtYvV |
MD5: | 75AD920CA465532E3C49A79AA0661B07 |
SHA1: | B9ABACC04144DC7DEE38022FD5A976319E3694BC |
SHA-256: | EB7A57E71521A8A1D1B54AB4121B67D8D6F2A880F80A784D2BB675811D6D5126 |
SHA-512: | ED992C01850B8F0A2829A59612A55D88A2D86DE9DF2F717E9FF27202400FA136825AFAB578C5F5F11D9C32548E825E22C04A7B65B00300440C2691CE98417B56 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.395190956750472 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rp:9 |
MD5: | 7A1BE4D71E7C18C2D8B6166F1F44EF49 |
SHA1: | CB4CECE307536D8AD2D5E7F541E5F1C03A65671E |
SHA-256: | 54218B9B7CD4B376B8347C2B905E87E5A45FB3970B6D77581D4126B995F3EF4F |
SHA-512: | 4A90799C87DAF0E8B2BB1D338B563441209E13C888DBE5832ED8D8429A078D35A8A0553B4BE32B716AADC7CBB3FAE57EA95E5B890847802E4A9E7D9D6D15F9C5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/W5mOWL07oDGZQYIGNPZdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:u5bWLxDGZQZGH3mlind9i4ufFXpAXkru |
MD5: | BECE717AE3587486D42CB3BBE467D234 |
SHA1: | B325B496C80E62F99849F352F6A1A160755FFEF3 |
SHA-256: | CF9BF1923A49C62FC67A0F9B9B7ED593D11FD30D4C04D66499454485FA077F36 |
SHA-512: | C8692B9256BFEC55407AE88D965D7717983504BA61353041356EF5CD4DEBC4758407CBA1AB08C4883E5571293210C4085BAED9C54DC4E0494AF1DE2CADAEA3A1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3155 |
Entropy (8bit): | 5.863722775877795 |
Encrypted: | false |
SSDEEP: | 48:K3ABkBGbKlgJXwnF5PqRUJ4wEkIRDgJtiRuylcANuoZh1ppQKxBf2Rb//BX0vA0y:K3Kml7SRsCgF2pN3ZQgf2htddfffffX |
MD5: | F833B5B408EDE5233B964A38A4A9222F |
SHA1: | A926EC85F6DA4844E2C6FF0190B5827D8CA0D224 |
SHA-256: | B77C715DB37579EAE47F88D26ACB4C140C27AD99C8BB754C949B5647F742F6DA |
SHA-512: | 144ED018143C95B8663771904F0B03D80CF66D8B963B981B8F456A231A25B964862B820A786D714E67D0BAD9E4C6B09ADD10EFB36EFE0C0A547FD56477551580 |
Malicious: | false |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE |
Preview: |
File type: | |
Entropy (8bit): | 7.929661539673598 |
TrID: |
|
File name: | Invoice Number INV132146-1.pdf |
File size: | 52'893 bytes |
MD5: | 786bb21da0bc0a7a90278e99818d59a9 |
SHA1: | 1b63a43223fa7a5d275d0b3631bee54fe8ca181c |
SHA256: | 3f193b89c9274026c94b4da74272c7160f1c6f76d5a64594ebb66b103d1e38d2 |
SHA512: | 5a2eef7c1a61b777c644b15e38070b3ffe358e69785a235b9cfa440ddc403bd509c786c843eb0d60063d14d2a560badd8df12c9cd9c060891766a444d2a46649 |
SSDEEP: | 1536:oaZC54j2Aup+lgekiqCAltX3/MCgPnTn9d6:HZCSaAusSi+XvjETn9d6 |
TLSH: | DB3302BCA895CC9DDEA459F62440438E42DFAC379FD617312ECBE3419E8930AF584DA4 |
File Content Preview: | %PDF-1.6.%.....2 0 obj.<<./Lang <FEFF0045004E002D00550053>./MarkInfo 4 0 R./Metadata 5 0 R./PageLayout /OneColumn./Pages 6 0 R./StructTreeRoot 7 0 R./Type /Catalog./AcroForm 8 0 R.>>.endobj.5 0 obj.<<./Subtype /XML./Type /Metadata./Filter /FlateDecode./Le |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.6 |
Total Entropy: | 7.929662 |
Total Bytes: | 52893 |
Stream Entropy: | 7.929453 |
Stream Bytes: | 51803 |
Entropy outside Streams: | 5.201380 |
Bytes outside Streams: | 1090 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 9 |
endobj | 9 |
stream | 7 |
endstream | 7 |
xref | 0 |
trailer | 0 |
startxref | 1 |
/Page | 0 |
/Encrypt | 0 |
/ObjStm | 1 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 1 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
ID | DHASH | MD5 | Preview |
---|---|---|---|
32 | 11313038394f3736 | 99a66323ff5e1bcbb778db6bfb3b60cf |
Download Network PCAP: filtered – full
- Total Packets: 99
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 24, 2025 03:36:32.042768955 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 24, 2025 03:36:32.354337931 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 24, 2025 03:36:32.964032888 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 24, 2025 03:36:34.166856050 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 24, 2025 03:36:36.573153019 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 24, 2025 03:36:37.354334116 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 24, 2025 03:36:40.916009903 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 24, 2025 03:36:41.231460094 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 24, 2025 03:36:41.423492908 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 24, 2025 03:36:41.872241974 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 24, 2025 03:36:43.179383993 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 24, 2025 03:36:45.679688931 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 24, 2025 03:36:45.714788914 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:45.715109110 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:45.715141058 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:45.812911987 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Mar 24, 2025 03:36:45.812961102 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Mar 24, 2025 03:36:45.813916922 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Mar 24, 2025 03:36:45.813955069 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Mar 24, 2025 03:36:45.814007998 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:45.814008951 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:45.814497948 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:45.817015886 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Mar 24, 2025 03:36:45.817050934 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Mar 24, 2025 03:36:45.817086935 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:45.817142010 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:45.820010900 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:45.909887075 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Mar 24, 2025 03:36:45.916081905 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Mar 24, 2025 03:36:45.918323994 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Mar 24, 2025 03:36:45.918366909 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Mar 24, 2025 03:36:45.918525934 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:45.918525934 CET | 49712 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 24, 2025 03:36:48.512708902 CET | 49727 | 80 | 192.168.2.4 | 23.48.144.248 |
Mar 24, 2025 03:36:48.602277994 CET | 80 | 49727 | 23.48.144.248 | 192.168.2.4 |
Mar 24, 2025 03:36:48.602372885 CET | 49727 | 80 | 192.168.2.4 | 23.48.144.248 |
Mar 24, 2025 03:36:48.602482080 CET | 49727 | 80 | 192.168.2.4 | 23.48.144.248 |
Mar 24, 2025 03:36:48.696391106 CET | 80 | 49727 | 23.48.144.248 | 192.168.2.4 |
Mar 24, 2025 03:36:48.698709011 CET | 80 | 49727 | 23.48.144.248 | 192.168.2.4 |
Mar 24, 2025 03:36:48.698746920 CET | 80 | 49727 | 23.48.144.248 | 192.168.2.4 |
Mar 24, 2025 03:36:48.698796988 CET | 49727 | 80 | 192.168.2.4 | 23.48.144.248 |
Mar 24, 2025 03:36:50.481861115 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 24, 2025 03:36:51.026913881 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 24, 2025 03:37:00.072356939 CET | 49727 | 80 | 192.168.2.4 | 23.48.144.248 |
Mar 24, 2025 03:37:00.092705011 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 24, 2025 03:37:06.470688105 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:06.470732927 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:06.470933914 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:06.471239090 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:06.471250057 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:06.670526028 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:06.670612097 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:06.672399044 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:06.672410965 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:06.672801971 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:06.713326931 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:09.309895992 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:09.352358103 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:09.457356930 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:09.457428932 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:09.457465887 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:09.457535982 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:09.457576036 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:09.457725048 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:09.464087009 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:09.464199066 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:09.464219093 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:09.464238882 CET | 443 | 49739 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:37:09.464267015 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:09.464298964 CET | 49739 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:37:20.573803902 CET | 49711 | 80 | 192.168.2.4 | 199.232.210.172 |
Mar 24, 2025 03:37:20.573853970 CET | 49714 | 80 | 192.168.2.4 | 199.232.210.172 |
Mar 24, 2025 03:37:20.662532091 CET | 80 | 49711 | 199.232.210.172 | 192.168.2.4 |
Mar 24, 2025 03:37:20.662548065 CET | 80 | 49711 | 199.232.210.172 | 192.168.2.4 |
Mar 24, 2025 03:37:20.662595034 CET | 49711 | 80 | 192.168.2.4 | 199.232.210.172 |
Mar 24, 2025 03:37:20.662992954 CET | 80 | 49714 | 199.232.210.172 | 192.168.2.4 |
Mar 24, 2025 03:37:20.663088083 CET | 80 | 49714 | 199.232.210.172 | 192.168.2.4 |
Mar 24, 2025 03:37:20.663135052 CET | 49714 | 80 | 192.168.2.4 | 199.232.210.172 |
Mar 24, 2025 03:38:06.434104919 CET | 49749 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:38:06.434175014 CET | 443 | 49749 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:38:06.434305906 CET | 49749 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:38:06.434429884 CET | 49749 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:38:06.434449911 CET | 443 | 49749 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:38:06.631700039 CET | 443 | 49749 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:38:06.632097960 CET | 49749 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:38:06.632123947 CET | 443 | 49749 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:38:16.631319046 CET | 443 | 49749 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:38:16.631460905 CET | 443 | 49749 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:38:16.631517887 CET | 49749 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:38:18.028237104 CET | 49749 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 24, 2025 03:38:18.028264999 CET | 443 | 49749 | 142.251.40.228 | 192.168.2.4 |
Mar 24, 2025 03:38:27.031810999 CET | 443 | 49708 | 52.113.196.254 | 192.168.2.4 |
Mar 24, 2025 03:38:51.966001034 CET | 443 | 49712 | 131.253.33.254 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 24, 2025 03:36:48.409181118 CET | 64634 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:36:48.509421110 CET | 53 | 64634 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:01.908380032 CET | 53 | 52362 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:02.299776077 CET | 53 | 51561 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:02.523940086 CET | 53 | 53582 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:02.998908043 CET | 53 | 51612 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:06.371094942 CET | 50927 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:06.371315002 CET | 51069 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:06.468904018 CET | 53 | 50927 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:06.469681025 CET | 53 | 51069 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:07.976586103 CET | 50849 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:07.976952076 CET | 61340 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:08.218839884 CET | 53 | 50849 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:08.219458103 CET | 61172 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:08.223284006 CET | 53 | 61340 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:08.223721027 CET | 65363 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:08.464056015 CET | 53 | 61172 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:08.465192080 CET | 60303 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:08.475398064 CET | 53 | 65363 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:08.866962910 CET | 53 | 60303 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:08.904288054 CET | 63125 | 53 | 192.168.2.4 | 8.8.8.8 |
Mar 24, 2025 03:37:08.904536963 CET | 53340 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:09.000633001 CET | 53 | 63125 | 8.8.8.8 | 192.168.2.4 |
Mar 24, 2025 03:37:09.008220911 CET | 53 | 53340 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:09.930723906 CET | 54997 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:09.930969000 CET | 59771 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:10.183795929 CET | 53 | 59771 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:10.198205948 CET | 57549 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:10.443960905 CET | 53 | 57549 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:10.470149994 CET | 53 | 54997 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:10.471649885 CET | 49515 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:10.712990046 CET | 53 | 49515 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:15.748164892 CET | 59853 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:15.748342037 CET | 56382 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:15.993273973 CET | 53 | 59853 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:15.993956089 CET | 51119 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:16.294528008 CET | 53 | 56382 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:16.295010090 CET | 55268 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:16.371680975 CET | 53 | 51119 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:16.372700930 CET | 51408 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:16.470439911 CET | 53 | 51408 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:16.544313908 CET | 53 | 55268 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:20.007955074 CET | 53 | 57910 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:21.223382950 CET | 60423 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:21.223596096 CET | 49941 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:21.464824915 CET | 53 | 60423 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:21.465398073 CET | 49478 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:21.468008995 CET | 53 | 49941 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:21.468334913 CET | 63828 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:21.705928087 CET | 53 | 49478 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:21.706814051 CET | 64689 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:21.715599060 CET | 53 | 63828 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:21.955774069 CET | 53 | 64689 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:21.970413923 CET | 57930 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:21.970674992 CET | 53858 | 53 | 192.168.2.4 | 8.8.8.8 |
Mar 24, 2025 03:37:22.070350885 CET | 53 | 57930 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:22.072150946 CET | 53 | 53858 | 8.8.8.8 | 192.168.2.4 |
Mar 24, 2025 03:37:33.284197092 CET | 56526 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:33.284435987 CET | 60713 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:33.529012918 CET | 53 | 60713 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:33.530169964 CET | 50572 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:33.686580896 CET | 53 | 56526 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:33.687180042 CET | 59818 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:33.781601906 CET | 53 | 50572 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:33.934418917 CET | 53 | 59818 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:33.937289000 CET | 50526 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:34.034291983 CET | 53 | 50526 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:34.095621109 CET | 56473 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:34.095952034 CET | 51132 | 53 | 192.168.2.4 | 8.8.8.8 |
Mar 24, 2025 03:37:34.194122076 CET | 53 | 51132 | 8.8.8.8 | 192.168.2.4 |
Mar 24, 2025 03:37:34.194448948 CET | 53 | 56473 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:38.821316004 CET | 53 | 62120 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:37:40.301038980 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Mar 24, 2025 03:37:53.792416096 CET | 63333 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:37:54.043518066 CET | 53 | 63333 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:01.235635996 CET | 53 | 50776 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:01.695219994 CET | 53 | 62584 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:04.096879005 CET | 62982 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:04.097754955 CET | 54706 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:04.336072922 CET | 53 | 62982 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:04.336533070 CET | 60020 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:04.481085062 CET | 53 | 54706 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:04.481601000 CET | 55343 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:04.576935053 CET | 53 | 60020 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:04.577848911 CET | 50768 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:04.722002983 CET | 53 | 55343 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:04.812668085 CET | 53 | 53684 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:04.821302891 CET | 53 | 50768 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:07.092835903 CET | 52424 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:07.092936993 CET | 61165 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:07.351900101 CET | 53 | 61165 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:07.352503061 CET | 62813 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:07.491908073 CET | 53 | 52424 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:07.492432117 CET | 62545 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:07.599409103 CET | 53 | 62813 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:07.739090919 CET | 53 | 62545 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:07.754935980 CET | 64098 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:07.755007982 CET | 61635 | 53 | 192.168.2.4 | 8.8.8.8 |
Mar 24, 2025 03:38:07.854398966 CET | 53 | 61635 | 8.8.8.8 | 192.168.2.4 |
Mar 24, 2025 03:38:07.854964018 CET | 53 | 64098 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:31.480212927 CET | 53 | 49295 | 1.1.1.1 | 192.168.2.4 |
Mar 24, 2025 03:38:46.480788946 CET | 55126 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 24, 2025 03:38:46.717839003 CET | 53 | 55126 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Mar 24, 2025 03:37:08.475502014 CET | 192.168.2.4 | 1.1.1.1 | c1ef | (Port unreachable) | Destination Unreachable |
Mar 24, 2025 03:37:16.544420958 CET | 192.168.2.4 | 1.1.1.1 | c1ef | (Port unreachable) | Destination Unreachable |
Mar 24, 2025 03:37:21.715665102 CET | 192.168.2.4 | 1.1.1.1 | c1ef | (Port unreachable) | Destination Unreachable |
Mar 24, 2025 03:38:04.722094059 CET | 192.168.2.4 | 1.1.1.1 | c1ef | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 24, 2025 03:36:48.409181118 CET | 192.168.2.4 | 1.1.1.1 | 0x4d40 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:06.371094942 CET | 192.168.2.4 | 1.1.1.1 | 0xebc3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:06.371315002 CET | 192.168.2.4 | 1.1.1.1 | 0xc1cf | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:07.976586103 CET | 192.168.2.4 | 1.1.1.1 | 0xd9da | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:07.976952076 CET | 192.168.2.4 | 1.1.1.1 | 0xa25 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:08.219458103 CET | 192.168.2.4 | 1.1.1.1 | 0xf319 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:08.223721027 CET | 192.168.2.4 | 1.1.1.1 | 0x1def | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:08.465192080 CET | 192.168.2.4 | 1.1.1.1 | 0x587f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:08.904288054 CET | 192.168.2.4 | 8.8.8.8 | 0xff2a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:08.904536963 CET | 192.168.2.4 | 1.1.1.1 | 0x7d3f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:09.930723906 CET | 192.168.2.4 | 1.1.1.1 | 0x11e5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:09.930969000 CET | 192.168.2.4 | 1.1.1.1 | 0xc4c6 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:10.198205948 CET | 192.168.2.4 | 1.1.1.1 | 0xefb4 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:10.471649885 CET | 192.168.2.4 | 1.1.1.1 | 0x4f7f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:15.748164892 CET | 192.168.2.4 | 1.1.1.1 | 0x99ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:15.748342037 CET | 192.168.2.4 | 1.1.1.1 | 0xd5a0 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:15.993956089 CET | 192.168.2.4 | 1.1.1.1 | 0x6078 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:16.295010090 CET | 192.168.2.4 | 1.1.1.1 | 0x5c30 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:16.372700930 CET | 192.168.2.4 | 1.1.1.1 | 0x13c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.223382950 CET | 192.168.2.4 | 1.1.1.1 | 0x3e84 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.223596096 CET | 192.168.2.4 | 1.1.1.1 | 0xe2aa | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.465398073 CET | 192.168.2.4 | 1.1.1.1 | 0x33f2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.468334913 CET | 192.168.2.4 | 1.1.1.1 | 0x5331 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.706814051 CET | 192.168.2.4 | 1.1.1.1 | 0x12d2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.970413923 CET | 192.168.2.4 | 1.1.1.1 | 0x274a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.970674992 CET | 192.168.2.4 | 8.8.8.8 | 0xac7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:33.284197092 CET | 192.168.2.4 | 1.1.1.1 | 0x262e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:33.284435987 CET | 192.168.2.4 | 1.1.1.1 | 0x5a8e | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:33.530169964 CET | 192.168.2.4 | 1.1.1.1 | 0xd74b | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:33.687180042 CET | 192.168.2.4 | 1.1.1.1 | 0x8eaf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:33.937289000 CET | 192.168.2.4 | 1.1.1.1 | 0xfdb5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:34.095621109 CET | 192.168.2.4 | 1.1.1.1 | 0xbbb6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:34.095952034 CET | 192.168.2.4 | 8.8.8.8 | 0xe047 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:53.792416096 CET | 192.168.2.4 | 1.1.1.1 | 0xfc55 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:04.096879005 CET | 192.168.2.4 | 1.1.1.1 | 0x744f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:04.097754955 CET | 192.168.2.4 | 1.1.1.1 | 0xbc5f | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:38:04.336533070 CET | 192.168.2.4 | 1.1.1.1 | 0x64ea | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:04.481601000 CET | 192.168.2.4 | 1.1.1.1 | 0xa5b1 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:38:04.577848911 CET | 192.168.2.4 | 1.1.1.1 | 0x35ed | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.092835903 CET | 192.168.2.4 | 1.1.1.1 | 0xefc4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.092936993 CET | 192.168.2.4 | 1.1.1.1 | 0xd594 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.352503061 CET | 192.168.2.4 | 1.1.1.1 | 0x3ce5 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.492432117 CET | 192.168.2.4 | 1.1.1.1 | 0xa809 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.754935980 CET | 192.168.2.4 | 1.1.1.1 | 0x8572 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.755007982 CET | 192.168.2.4 | 8.8.8.8 | 0x6483 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:46.480788946 CET | 192.168.2.4 | 1.1.1.1 | 0x2aed | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 24, 2025 03:36:48.509421110 CET | 1.1.1.1 | 192.168.2.4 | 0x4d40 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 24, 2025 03:36:48.509421110 CET | 1.1.1.1 | 192.168.2.4 | 0x4d40 | No error (0) | e8652.dscx.akamaiedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 24, 2025 03:36:48.509421110 CET | 1.1.1.1 | 192.168.2.4 | 0x4d40 | No error (0) | 23.48.144.248 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:36:48.833138943 CET | 1.1.1.1 | 192.168.2.4 | 0x112e | No error (0) | 208.89.73.17 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:36:48.833138943 CET | 1.1.1.1 | 192.168.2.4 | 0x112e | No error (0) | 208.89.73.25 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:36:48.833138943 CET | 1.1.1.1 | 192.168.2.4 | 0x112e | No error (0) | 208.89.73.21 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:36:48.833138943 CET | 1.1.1.1 | 192.168.2.4 | 0x112e | No error (0) | 208.89.73.29 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:36:48.833138943 CET | 1.1.1.1 | 192.168.2.4 | 0x112e | No error (0) | 208.89.73.19 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:36:48.833138943 CET | 1.1.1.1 | 192.168.2.4 | 0x112e | No error (0) | 208.89.73.31 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:36:48.833138943 CET | 1.1.1.1 | 192.168.2.4 | 0x112e | No error (0) | 208.89.73.23 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:36:48.833138943 CET | 1.1.1.1 | 192.168.2.4 | 0x112e | No error (0) | 208.89.73.27 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:37:01.480660915 CET | 1.1.1.1 | 192.168.2.4 | 0xb603 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:37:01.480660915 CET | 1.1.1.1 | 192.168.2.4 | 0xb603 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:37:06.468904018 CET | 1.1.1.1 | 192.168.2.4 | 0xebc3 | No error (0) | 142.251.40.228 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:37:06.469681025 CET | 1.1.1.1 | 192.168.2.4 | 0xc1cf | No error (0) | 65 | IN (0x0001) | false | |||
Mar 24, 2025 03:37:08.218839884 CET | 1.1.1.1 | 192.168.2.4 | 0xd9da | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:08.223284006 CET | 1.1.1.1 | 192.168.2.4 | 0xa25 | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:08.464056015 CET | 1.1.1.1 | 192.168.2.4 | 0xf319 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:08.475398064 CET | 1.1.1.1 | 192.168.2.4 | 0x1def | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:08.866962910 CET | 1.1.1.1 | 192.168.2.4 | 0x587f | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:09.000633001 CET | 8.8.8.8 | 192.168.2.4 | 0xff2a | No error (0) | 142.251.40.142 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:37:09.008220911 CET | 1.1.1.1 | 192.168.2.4 | 0x7d3f | No error (0) | 142.250.176.206 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:37:10.183795929 CET | 1.1.1.1 | 192.168.2.4 | 0xc4c6 | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:10.443960905 CET | 1.1.1.1 | 192.168.2.4 | 0xefb4 | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:10.470149994 CET | 1.1.1.1 | 192.168.2.4 | 0x11e5 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:10.712990046 CET | 1.1.1.1 | 192.168.2.4 | 0x4f7f | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:15.993273973 CET | 1.1.1.1 | 192.168.2.4 | 0x99ae | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:16.294528008 CET | 1.1.1.1 | 192.168.2.4 | 0xd5a0 | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:16.371680975 CET | 1.1.1.1 | 192.168.2.4 | 0x6078 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:16.470439911 CET | 1.1.1.1 | 192.168.2.4 | 0x13c3 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:16.544313908 CET | 1.1.1.1 | 192.168.2.4 | 0x5c30 | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.464824915 CET | 1.1.1.1 | 192.168.2.4 | 0x3e84 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.468008995 CET | 1.1.1.1 | 192.168.2.4 | 0xe2aa | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.705928087 CET | 1.1.1.1 | 192.168.2.4 | 0x33f2 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.715599060 CET | 1.1.1.1 | 192.168.2.4 | 0x5331 | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:21.955774069 CET | 1.1.1.1 | 192.168.2.4 | 0x12d2 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:22.070350885 CET | 1.1.1.1 | 192.168.2.4 | 0x274a | No error (0) | 142.251.40.174 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:37:22.072150946 CET | 8.8.8.8 | 192.168.2.4 | 0xac7 | No error (0) | 142.251.40.142 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:37:33.529012918 CET | 1.1.1.1 | 192.168.2.4 | 0x5a8e | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:33.686580896 CET | 1.1.1.1 | 192.168.2.4 | 0x262e | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:33.781601906 CET | 1.1.1.1 | 192.168.2.4 | 0xd74b | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:37:33.934418917 CET | 1.1.1.1 | 192.168.2.4 | 0x8eaf | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:34.034291983 CET | 1.1.1.1 | 192.168.2.4 | 0xfdb5 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:37:34.194122076 CET | 8.8.8.8 | 192.168.2.4 | 0xe047 | No error (0) | 142.251.40.142 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:37:34.194448948 CET | 1.1.1.1 | 192.168.2.4 | 0xbbb6 | No error (0) | 142.250.80.110 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:37:54.043518066 CET | 1.1.1.1 | 192.168.2.4 | 0xfc55 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:04.336072922 CET | 1.1.1.1 | 192.168.2.4 | 0x744f | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:04.481085062 CET | 1.1.1.1 | 192.168.2.4 | 0xbc5f | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:38:04.576935053 CET | 1.1.1.1 | 192.168.2.4 | 0x64ea | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:04.722002983 CET | 1.1.1.1 | 192.168.2.4 | 0xa5b1 | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:38:04.821302891 CET | 1.1.1.1 | 192.168.2.4 | 0x35ed | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.351900101 CET | 1.1.1.1 | 192.168.2.4 | 0xd594 | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.491908073 CET | 1.1.1.1 | 192.168.2.4 | 0xefc4 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.599409103 CET | 1.1.1.1 | 192.168.2.4 | 0x3ce5 | Server failure (2) | none | none | 65 | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.739090919 CET | 1.1.1.1 | 192.168.2.4 | 0xa809 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 24, 2025 03:38:07.854398966 CET | 8.8.8.8 | 192.168.2.4 | 0x6483 | No error (0) | 142.251.40.142 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:38:07.854964018 CET | 1.1.1.1 | 192.168.2.4 | 0x8572 | No error (0) | 142.250.65.206 | A (IP address) | IN (0x0001) | false | ||
Mar 24, 2025 03:38:46.717839003 CET | 1.1.1.1 | 192.168.2.4 | 0x2aed | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49727 | 23.48.144.248 | 80 | 8140 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 24, 2025 03:36:48.602482080 CET | 115 | OUT | |
Mar 24, 2025 03:36:48.698709011 CET | 1254 | IN | |
Mar 24, 2025 03:36:48.698746920 CET | 491 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49739 | 142.251.40.228 | 443 | 9064 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-24 02:37:09 UTC | 587 | OUT | |
2025-03-24 02:37:09 UTC | 1303 | IN | |
2025-03-24 02:37:09 UTC | 1303 | IN | |
2025-03-24 02:37:09 UTC | 1303 | IN | |
2025-03-24 02:37:09 UTC | 556 | IN | |
2025-03-24 02:37:09 UTC | 5 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 22:36:34 |
Start date: | 23/03/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff762540000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 22:36:35 |
Start date: | 23/03/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff718ce0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 22:36:36 |
Start date: | 23/03/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff718ce0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 19 |
Start time: | 22:36:59 |
Start date: | 23/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ac620000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 20 |
Start time: | 22:37:00 |
Start date: | 23/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 21 |
Start time: | 22:37:06 |
Start date: | 23/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |