Edit tour

Windows Analysis Report
JGJRA8m29G.pdf

Overview

General Information

Sample name:JGJRA8m29G.pdf
renamed because original name is a hash value
Original sample name:8b40155d682d653dde378e398c4953d3cc68875fd609e936dfd5411ab8383d30.pdf
Analysis ID:1657404
MD5:aa4fdc2f462ca150cd7aea3c77c1bf8d
SHA1:b3ccd9a009def98c94a011168073ee3297074a0d
SHA256:8b40155d682d653dde378e398c4953d3cc68875fd609e936dfd5411ab8383d30
Infos:

Detection

Score:64
Range:0 - 100
Confidence:100%

Signatures

AI detected phishing page
Suricata IDS alerts for network traffic
AI detected landing page (webpage, office document or email)
AI detected suspicious URL
HTML body contains low number of good links
HTML title does not match URL
Suricata IDS alerts with low severity for network traffic
Suspicious form URL found

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • Acrobat.exe (PID: 6964 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\JGJRA8m29G.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C)
    • AcroCEF.exe (PID: 7164 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
      • AcroCEF.exe (PID: 4732 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2260 --field-trial-handle=1588,i,11110562663448513532,4123534873551076654,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
    • chrome.exe (PID: 1308 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://kobadropinv.live/en/az/tz/drop/ MD5: E81F54E6C1129887AEA47E7D092680BF)
      • chrome.exe (PID: 7208 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1780,i,13061439328805714332,12215359193444047693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2196 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-04-05T18:43:25.912671+020020296571Successful Credential Theft Detected23.95.132.226443192.168.2.1649754TCP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-04-05T18:42:59.266434+020020256592Possible Social Engineering Attempted23.95.132.226443192.168.2.1649718TCP
2025-04-05T18:43:27.022426+020020256592Possible Social Engineering Attempted23.95.132.226443192.168.2.1649752TCP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-04-05T18:43:25.912283+020028122371Successful Credential Theft Detected192.168.2.164975423.95.132.226443TCP

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://kobadropinv.live/en/az/tz/drop/Joe Sandbox AI: Score: 9 Reasons: The brand 'Dropbox' is a well-known cloud storage service., The legitimate domain for Dropbox is 'dropbox.com'., The provided URL 'kobadropinv.live' does not match the legitimate domain., The URL contains suspicious elements such as an unusual domain extension '.live' and does not include 'dropbox' in a recognizable form., The presence of input fields for email and password on a non-legitimate domain is a common phishing tactic. DOM: 0.0.pages.csv
Source: https://kobadropinv.live/en/az/tz/drop/confirm.phpJoe Sandbox AI: Score: 9 Reasons: The brand 'Dropbox' is well-known and is associated with the domain 'dropbox.com'., The URL 'kobadropinv.live' does not match the legitimate domain 'dropbox.com'., The domain 'kobadropinv.live' contains suspicious elements such as an unusual domain extension '.live' and does not include 'dropbox' in a recognizable form., The presence of input fields asking for email and password is typical for phishing attempts, especially when the domain is not legitimate. DOM: 1.1.pages.csv
Source: PDF documentJoe Sandbox AI: Page contains button: 'VIEW SECURED FILE' Source: 'PDF document'
Source: PDF documentJoe Sandbox AI: PDF document contains prominent button: 'view secured file'
Source: https://kobadropinv.liveJoe Sandbox AI: The URL 'kobadropinv.live' appears to be attempting to mimic 'Dropbox', a well-known cloud storage service. The use of 'drop' within the domain name is a strong indicator of an attempt to visually and contextually associate with Dropbox. The addition of 'inv' could be an attempt to suggest an invitation or involvement, which is a common tactic in phishing attempts. The top-level domain '.live' is not typically associated with Dropbox, which uses '.com'. The similarity score is high due to the inclusion of 'drop', which is a key part of the legitimate brand name. The likelihood of typosquatting is also high, as the domain structure and name could easily confuse users into thinking it is related to Dropbox, especially if used in a context that suggests file sharing or cloud storage.
Source: https://kobadropinv.live/en/az/tz/drop/HTTP Parser: Number of links: 0
Source: https://kobadropinv.live/en/az/tz/drop/confirm.phpHTTP Parser: Number of links: 0
Source: https://kobadropinv.live/en/az/tz/drop/HTTP Parser: Title: Dropbox Download does not match URL
Source: https://kobadropinv.live/en/az/tz/drop/confirm.phpHTTP Parser: Title: Dropbox Download does not match URL
Source: https://kobadropinv.live/en/az/tz/drop/HTTP Parser: Form action: d1.php
Source: https://kobadropinv.live/en/az/tz/drop/confirm.phpHTTP Parser: Form action: d2.php
Source: https://kobadropinv.live/en/az/tz/drop/HTTP Parser: <input type="password" .../> found
Source: https://kobadropinv.live/en/az/tz/drop/confirm.phpHTTP Parser: <input type="password" .../> found
Source: https://kobadropinv.live/en/az/tz/drop/HTTP Parser: No favicon
Source: https://kobadropinv.live/en/az/tz/drop/confirm.phpHTTP Parser: No favicon
Source: https://kobadropinv.live/en/az/tz/drop/HTTP Parser: No <meta name="author".. found
Source: https://kobadropinv.live/en/az/tz/drop/confirm.phpHTTP Parser: No <meta name="author".. found
Source: https://kobadropinv.live/en/az/tz/drop/HTTP Parser: No <meta name="copyright".. found
Source: https://kobadropinv.live/en/az/tz/drop/confirm.phpHTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49732 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49735 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49737 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.132:443 -> 192.168.2.16:49751 version: TLS 1.2

Networking

barindex
Source: Network trafficSuricata IDS: 2029657 - Severity 1 - ET PHISHING Successful Generic Phish (302) 2016-12-16 : 23.95.132.226:443 -> 192.168.2.16:49754
Source: Network trafficSuricata IDS: 2025659 - Severity 2 - ET PHISHING Suspicious Dropbox Page - Possible Phishing Landing : 23.95.132.226:443 -> 192.168.2.16:49718
Source: Network trafficSuricata IDS: 2025659 - Severity 2 - ET PHISHING Suspicious Dropbox Page - Possible Phishing Landing : 23.95.132.226:443 -> 192.168.2.16:49752
Source: Network trafficSuricata IDS: 2812237 - Severity 1 - ETPRO PHISHING Possible Successful Generic Phish July 28 : 192.168.2.16:49754 -> 23.95.132.226:443
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.95.132.226
Source: global trafficHTTP traffic detected: GET /en/az/tz/drop/ HTTP/1.1Host: kobadropinv.liveConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /npm/bootstrap@5.2.3/dist/css/bootstrap.min.css HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://kobadropinv.live/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /npm/bootstrap-icons@1.10.5/font/bootstrap-icons.css HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://kobadropinv.live/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /npm/bootstrap@5.2.3/dist/js/bootstrap.bundle.min.js HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://kobadropinv.live/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en/az/tz/drop/drop.png HTTP/1.1Host: kobadropinv.liveConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://kobadropinv.live/en/az/tz/drop/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en/az/tz/drop/laptop.png HTTP/1.1Host: kobadropinv.liveConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://kobadropinv.live/en/az/tz/drop/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en/az/tz/drop/avast.png HTTP/1.1Host: kobadropinv.liveConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://kobadropinv.live/en/az/tz/drop/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en/az/tz/drop/avast.png HTTP/1.1Host: kobadropinv.liveConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en/az/tz/drop/laptop.png HTTP/1.1Host: kobadropinv.liveConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en/az/tz/drop/drop.png HTTP/1.1Host: kobadropinv.liveConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /npm/bootstrap-icons@1.10.5/font/fonts/bootstrap-icons.woff2?1fa40e8900654d2863d011707b9fb6f2 HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-aliveOrigin: https://kobadropinv.livesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/bootstrap-icons.cssAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: kobadropinv.liveConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://kobadropinv.live/en/az/tz/drop/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Microsoft-CryptoAPI/10.0Host: x1.i.lencr.org
Source: global trafficHTTP traffic detected: GET /en/az/tz/drop/confirm.php HTTP/1.1Host: kobadropinv.liveConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://kobadropinv.live/en/az/tz/drop/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=2125a9f4c8751891a90935f2b3ec170f
Source: global trafficDNS traffic detected: DNS query: x1.i.lencr.org
Source: global trafficDNS traffic detected: DNS query: cdn.jsdelivr.net
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownHTTP traffic detected: POST /en/az/tz/drop/d1.php HTTP/1.1Host: kobadropinv.liveConnection: keep-aliveContent-Length: 187Cache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Origin: https://kobadropinv.liveContent-Type: application/x-www-form-urlencodedUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://kobadropinv.live/en/az/tz/drop/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundConnection: closecache-control: private, no-cache, no-store, must-revalidate, max-age=0pragma: no-cachecontent-type: text/htmlcontent-length: 1251date: Sat, 05 Apr 2025 16:43:02 GMTserver: LiteSpeedx-content-type-options: nosniffx-xss-protection: 1; mode=blockalt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49673
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49732 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49735 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49737 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.95.132.226:443 -> 192.168.2.16:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.229:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.132:443 -> 192.168.2.16:49751 version: TLS 1.2
Source: classification engineClassification label: mal64.phis.winPDF@37/48@5/68
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-04-05 12-42-38-764.log
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
Source: unknownProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\JGJRA8m29G.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2260 --field-trial-handle=1588,i,11110562663448513532,4123534873551076654,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 26F6AE21C2B0ED071E4EBBE8F6A1720C
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://kobadropinv.live/en/az/tz/drop/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1780,i,13061439328805714332,12215359193444047693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2196 /prefetch:3
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2260 --field-trial-handle=1588,i,11110562663448513532,4123534873551076654,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://kobadropinv.live/en/az/tz/drop/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1780,i,13061439328805714332,12215359193444047693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2196 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: JGJRA8m29G.pdfInitial sample: PDF keyword /JS count = 0
Source: JGJRA8m29G.pdfInitial sample: PDF keyword /JavaScript count = 0
Source: JGJRA8m29G.pdfInitial sample: PDF keyword /EmbeddedFile count = 0
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information queried: ProcessInformation
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation2
Browser Extensions
1
Process Injection
3
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS Memory1
System Information Discovery
Remote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Obfuscated Files or Information
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://kobadropinv.live/en/az/tz/drop/avast.png0%Avira URL Cloudsafe
https://kobadropinv.live/en/az/tz/drop/drop.png0%Avira URL Cloudsafe
https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/js/bootstrap.bundle.min.js0%Avira URL Cloudsafe
https://kobadropinv.live/en/az/tz/drop/laptop.png0%Avira URL Cloudsafe
https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/bootstrap-icons.css0%Avira URL Cloudsafe
https://kobadropinv.live/favicon.ico0%Avira URL Cloudsafe
https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/fonts/bootstrap-icons.woff2?1fa40e8900654d2863d011707b9fb6f20%Avira URL Cloudsafe
https://kobadropinv.live/en/az/tz/drop/d1.php0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
jsdelivr.map.fastly.net
151.101.129.229
truefalse
    high
    bg.microsoft.map.fastly.net
    199.232.210.172
    truefalse
      high
      e8652.dscx.akamaiedge.net
      23.39.37.95
      truefalse
        high
        www.google.com
        142.251.40.132
        truefalse
          high
          x1.i.lencr.org
          unknown
          unknownfalse
            high
            cdn.jsdelivr.net
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://kobadropinv.live/en/az/tz/drop/d1.phptrue
              • Avira URL Cloud: safe
              unknown
              https://kobadropinv.live/en/az/tz/drop/confirm.phptrue
                unknown
                https://kobadropinv.live/en/az/tz/drop/true
                  unknown
                  https://kobadropinv.live/en/az/tz/drop/drop.pngtrue
                  • Avira URL Cloud: safe
                  unknown
                  http://x1.i.lencr.org/false
                    high
                    https://kobadropinv.live/favicon.icotrue
                    • Avira URL Cloud: safe
                    unknown
                    https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/css/bootstrap.min.cssfalse
                      high
                      https://kobadropinv.live/en/az/tz/drop/laptop.pngtrue
                      • Avira URL Cloud: safe
                      unknown
                      https://kobadropinv.live/en/az/tz/drop/avast.pngtrue
                      • Avira URL Cloud: safe
                      unknown
                      https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/bootstrap-icons.cssfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/js/bootstrap.bundle.min.jsfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/fonts/bootstrap-icons.woff2?1fa40e8900654d2863d011707b9fb6f2false
                      • Avira URL Cloud: safe
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      142.250.80.14
                      unknownUnited States
                      15169GOOGLEUSfalse
                      1.1.1.1
                      unknownAustralia
                      13335CLOUDFLARENETUSfalse
                      151.101.129.229
                      jsdelivr.map.fastly.netUnited States
                      54113FASTLYUSfalse
                      23.95.132.226
                      unknownUnited States
                      36352AS-COLOCROSSINGUStrue
                      23.56.162.204
                      unknownUnited States
                      16625AKAMAI-ASUSfalse
                      23.51.56.185
                      unknownUnited States
                      4788TMNET-AS-APTMNetInternetServiceProviderMYfalse
                      142.251.40.132
                      www.google.comUnited States
                      15169GOOGLEUSfalse
                      162.159.61.3
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      142.251.41.14
                      unknownUnited States
                      15169GOOGLEUSfalse
                      23.39.37.95
                      e8652.dscx.akamaiedge.netUnited States
                      16625AKAMAI-ASUSfalse
                      192.178.155.84
                      unknownUnited States
                      15169GOOGLEUSfalse
                      199.232.210.172
                      bg.microsoft.map.fastly.netUnited States
                      54113FASTLYUSfalse
                      142.251.41.3
                      unknownUnited States
                      15169GOOGLEUSfalse
                      18.213.11.84
                      unknownUnited States
                      14618AMAZON-AESUSfalse
                      142.250.80.106
                      unknownUnited States
                      15169GOOGLEUSfalse
                      IP
                      192.168.2.16
                      Joe Sandbox version:42.0.0 Malachite
                      Analysis ID:1657404
                      Start date and time:2025-04-05 18:42:05 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:18
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • EGA enabled
                      Analysis Mode:stream
                      Analysis stop reason:Timeout
                      Sample name:JGJRA8m29G.pdf
                      renamed because original name is a hash value
                      Original Sample Name:8b40155d682d653dde378e398c4953d3cc68875fd609e936dfd5411ab8383d30.pdf
                      Detection:MAL
                      Classification:mal64.phis.winPDF@37/48@5/68
                      Cookbook Comments:
                      • Found application associated with file extension: .pdf
                      • Exclude process from analysis (whitelisted): SIHClient.exe
                      • Excluded IPs from analysis (whitelisted): 23.51.56.185, 18.213.11.84, 50.16.47.176, 54.224.241.105, 34.237.241.83, 162.159.61.3, 172.64.41.3, 52.149.20.212
                      • Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, slscr.update.microsoft.com, ssl-delivery.adobe.com.edgekey.net, p13n.adobe.io, geo2.adobe.com
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size getting too big, too many NtOpenFile calls found.
                      • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                      • VT rate limit hit for: https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/bootstrap-icons.css
                      • VT rate limit hit for: https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/fonts/bootstrap-icons.woff2?1fa40e8900654d2863d011707b9fb6f2
                      • VT rate limit hit for: https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/js/bootstrap.bundle.min.js
                      • VT rate limit hit for: https://kobadropinv.live/en/az/tz/drop/avast.png
                      • VT rate limit hit for: https://kobadropinv.live/en/az/tz/drop/drop.png
                      • VT rate limit hit for: https://kobadropinv.live/en/az/tz/drop/laptop.png
                      • VT rate limit hit for: https://kobadropinv.live/favicon.ico
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):290
                      Entropy (8bit):5.187897770022783
                      Encrypted:false
                      SSDEEP:
                      MD5:EFEEEA4CAAD32BEB7932783AAF7AB9A6
                      SHA1:8098F691F6FF5E3DC46662F9C00E53980119C224
                      SHA-256:350B14BE2F19EDCC3AACAD890366AA8CBBBE6EA7038B4A3F90751D72BBCD20C3
                      SHA-512:9A415D8DBB5A76B982492D6572E57AE49102804D105268BD3E467126CF479DFA912B51F1243BD0A419A2231575276E2FC155B61D04D62FA6E0EA3ACAABF43C64
                      Malicious:false
                      Reputation:unknown
                      Preview:2025/04/05-12:42:37.203 182c Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2025/04/05-12:42:37.206 182c Recovering log #3.2025/04/05-12:42:37.206 182c Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):331
                      Entropy (8bit):5.151093466197255
                      Encrypted:false
                      SSDEEP:
                      MD5:BF06CE4651F4B9755672147FE9A1BB78
                      SHA1:81C5A5052EF2D492E4706E2A7CE5CABF1AC3FABF
                      SHA-256:FAB072580D546CD355323E6FECE0418B16612DBCA614B2F1C153A11D7BD8B206
                      SHA-512:C0E8C0DC6E5B8ACEDFDF2AEAA2594F4385AF817BE8DED6D77C9DE0BA4E28B99A58B9928D4B3CBEF307B5D2303E70131B89696EECDEED31DDA1347618B4763083
                      Malicious:false
                      Reputation:unknown
                      Preview:2025/04/05-12:42:37.070 bf4 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2025/04/05-12:42:37.074 bf4 Recovering log #3.2025/04/05-12:42:37.074 bf4 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):4099
                      Entropy (8bit):5.2266214005466045
                      Encrypted:false
                      SSDEEP:
                      MD5:4C8148DB9E41C6D24821CC402DB8266C
                      SHA1:E934E07F00C0B6F1188755E9D125D53248036F36
                      SHA-256:237B6E4483939F6BE0D2918ADAA681A07DA286A83D91D3097258B755D47FB23E
                      SHA-512:0B9A5E4FAAA594415DBFADF292B860624FF199A8E52681F0A21134AF99CD05274F99815E9EA1C2B0AF3B083F643B11A27FAB0BF1D862B1DDB469DFBFEAC5D2B7
                      Malicious:false
                      Reputation:unknown
                      Preview:*...#................version.1..namespace-e...o................next-map-id.1.Pnamespace-1d95df23_a38f_44a8_b732_4e62dd896a16-https://rna-resource.acrobat.com/.0y.S_r................next-map-id.2.Snamespace-2a884c18_b39c_4e3d_942f_252e530ca4bd-https://rna-v2-resource.acrobat.com/.16.X:r................next-map-id.3.Snamespace-2e78bfda_7188_4688_a4aa_1ff81b6e5eaa-https://rna-v2-resource.acrobat.com/.2.P.@o................next-map-id.4.Pnamespace-09c119c2_97bc_4467_8f67_f92472c9e5dc-https://rna-resource.acrobat.com/.346.+^...............Pnamespace-1d95df23_a38f_44a8_b732_4e62dd896a16-https://rna-resource.acrobat.com/....^...............Pnamespace-09c119c2_97bc_4467_8f67_f92472c9e5dc-https://rna-resource.acrobat.com/..?&a...............Snamespace-2a884c18_b39c_4e3d_942f_252e530ca4bd-https://rna-v2-resource.acrobat.com/_...a...............Snamespace-2e78bfda_7188_4688_a4aa_1ff81b6e5eaa-https://rna-v2-resource.acrobat.com/...o................next-map-id.5.Pnamespace-07af9ee9_2076_4f12_94b5_
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):319
                      Entropy (8bit):5.199126727158231
                      Encrypted:false
                      SSDEEP:
                      MD5:2C1382D00558CD4BB48D5E8EBF9D84DC
                      SHA1:2E72B58B639C0EBDE51548DF0C9A1B905BB900C8
                      SHA-256:00A211094FF42EAF6500085F80FF6AEF857C39B1B7F2C7C4C120215CF13F55D5
                      SHA-512:00AAFF9E5FFC26809655339E81C17AE61BEF707583E07442E26A485A7ED9D06578DAAEFF9B98AF3C7371C8DDAEC859F97847F9EBA6C5C433BE333655DBA10A4B
                      Malicious:false
                      Reputation:unknown
                      Preview:2025/04/05-12:42:37.246 bf4 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2025/04/05-12:42:37.247 bf4 Recovering log #3.2025/04/05-12:42:37.249 bf4 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:PC bitmap, Windows 3.x format, 107 x -152 x 32, cbSize 65110, bits offset 54
                      Category:dropped
                      Size (bytes):65110
                      Entropy (8bit):1.6669235728719018
                      Encrypted:false
                      SSDEEP:
                      MD5:86EC4A021136157A715B87B154026A67
                      SHA1:156B486ADCA3406D870B8B8BF800B3ABBCA378BA
                      SHA-256:B1DA6208633602E82A10BE05984EC0C9DECB2C604B9D7C928A0658ADF5881CE4
                      SHA-512:AA59823210DAE7EE71C24FA528C6784C4322E8712297C018BE00F241D01F004F99D0C58564FD7BBA3000299A188B805F176C42A3EA956975656499D00D8574AB
                      Malicious:false
                      Reputation:unknown
                      Preview:BMV.......6...(...k...h..... ...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 2, database pages 14, cookie 0x5, schema 4, UTF-8, version-valid-for 2
                      Category:dropped
                      Size (bytes):57344
                      Entropy (8bit):3.291927920232006
                      Encrypted:false
                      SSDEEP:
                      MD5:A4D5FECEFE05F21D6F81ACF4D9A788CF
                      SHA1:1A9AC236C80F2A2809F7DE374072E2FCCA5A775C
                      SHA-256:83BE4623D80FFB402FBDEC4125671DF532845A3828A1B378D99BD243A4FD8FF2
                      SHA-512:FF106C6B9E1EA4B1F3E3AB01FAEA21BA24A885E63DDF0C36EB0A8C3C89A9430FE676039C076C50D7C46DC4E809F6A7E35A4BFED64D9033FEBD6121AC547AA5E9
                      Malicious:false
                      Reputation:unknown
                      Preview:SQLite format 3......@ ..........................................................................c.......1........T...U.1.D............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:SQLite Rollback Journal
                      Category:dropped
                      Size (bytes):16928
                      Entropy (8bit):1.215554065834525
                      Encrypted:false
                      SSDEEP:
                      MD5:BDDD0E48B92B35BE2957AD7616E52D6B
                      SHA1:985E8E1C0B7555B9FEFAA1C87BE2128BAAB0DF7F
                      SHA-256:7B20783B3E0866F3E1E948D588B8D358DA43A99D1B818F3D21CE92C3B70AFE98
                      SHA-512:CDA3C5648871E733C6BB426CF062756ABA1E2644F71B6DEF5D869891016AD72F106E085A26B59903F29D070743F58A14878D500A534402ADA7232DFDAC21F9F3
                      Malicious:false
                      Reputation:unknown
                      Preview:.... .c......Z..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:Certificate, Version=3
                      Category:dropped
                      Size (bytes):1391
                      Entropy (8bit):7.705940075877404
                      Encrypted:false
                      SSDEEP:
                      MD5:0CD2F9E0DA1773E9ED864DA5E370E74E
                      SHA1:CABD2A79A1076A31F21D253635CB039D4329A5E8
                      SHA-256:96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6
                      SHA-512:3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910
                      Malicious:false
                      Reputation:unknown
                      Preview:0..k0..S............@.YDc.c...0...*.H........0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X10...150604110438Z..350604110438Z0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X10.."0...*.H.............0..........$s..7.+W(.....8..n<.W.x.u...jn..O(..h.lD...c...k....1.!~.3<.H..y.....!.K...qiJffl.~<p..)"......K...~....G.|.H#S.8.O.o...IW..t../.8.{.p!.u.0<.....c...O..K~.....w...{J.L.%.p..)..S$........J.?..aQ.....cq...o[...\4ylv.;.by.../&.....................6....7..6u...r......I.....*.A..v........5/(.l....dwnG7..Y^h..r...A)>Y>.&.$...Z.L@.F....:Qn.;.}r...xY.>Qx....../..>{J.Ks......P.|C.t..t.....0.[q6....00\H..;..}`...).........A.......|.;F.H*..v.v..j.=...8.d..+..(.....B.".'].y...p..N..:..'Qn..d.3CO......B0@0...U...........0...U.......0....0...U......y.Y.{....s.....X..n0...*.H.............U.X....P.....i ')..au\.n...i/..VK..s.Y.!.~.Lq...`.9....!V..P.Y...Y.............b.E.f..|o..;.....'...}~.."......
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 73305 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
                      Category:dropped
                      Size (bytes):73305
                      Entropy (8bit):7.996028107841645
                      Encrypted:true
                      SSDEEP:
                      MD5:83142242E97B8953C386F988AA694E4A
                      SHA1:833ED12FC15B356136DCDD27C61A50F59C5C7D50
                      SHA-256:D72761E1A334A754CE8250E3AF7EA4BF25301040929FD88CF9E50B4A9197D755
                      SHA-512:BB6DA177BD16D163F377D9B4C63F6D535804137887684C113CC2F643CEAB4F34338C06B5A29213C23D375E95D22EF417EAC928822DFB3688CE9E2DE9D5242D10
                      Malicious:false
                      Reputation:unknown
                      Preview:MSCF....Y.......,...................I.................;Za. .authroot.stl.98.?.6..CK..<Tk......4..c... .Ec...U.d.d.E&I.DH*..M.KB."..rK.RQ*..}f..f...}..1....9...........$.8q..fa...7.o.1.0...bfsM4.........u..l..0..4.a.t....0.....6#....n. :... ....%.,CQ5uU..(.3.<7#.0..JN.$...=j|w..*.#.oU..Eq[..P..^..~.V...;..m...I|...l..@-W..=.QQ.._./.M.nZ..(.........`.$Z.9wW:W.]..8*E.......I.D{..n...K:.m..^.(.S.......c..s.y..<...2.%o.o.....H.B.R.....11.|!.(...........h.SZ........<...^....Z>.Pp?... .pT@p.#.&..........#VEV=.....p........y..."T=l.n..egf.w..X.Y..-G...........KQ.]...pM..[m..-6.wd:........T...:.P5Zs....c.oT`..F1#......EuD.......7....V ..-....!.N..%S...k...S. ...@.J..../..b!B.(=\../.l......`.\...q9..>4!b..8EH.....zdy.....#...X>%0w...i.,>c.z.g"p.S..2W.+mMs.....5Def.....#._D.4....>}...i...\.&`D.......z;..ZY.3.+t.`....z_.q'w.z.)..j3.+.co.s..:.........qK...{...E....uPO...#vs.XxH.B!..(t. 8k+.....G\..?..GF8....'..w.>.ms..\ve.nFN..W)....xi..u..5.f.l....
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):192
                      Entropy (8bit):2.7673182398396405
                      Encrypted:false
                      SSDEEP:
                      MD5:33918C5FAEEBD03E46B2D447F0E57560
                      SHA1:7A1ED8B3DA6E2344E190D9D4EFF826FD5D9D67E1
                      SHA-256:35177853C210ADEC48E6303D88C9F83CD8906409359ADF2D38CA2B3116C2A090
                      SHA-512:B2486F80E508B05515E0B342F37F8CE7326F9E89DC95E3B3D67A41EA19294B30215CE719A1F7E720844856F8F936F5F30F55A5498EC8B126B917FDA388E07448
                      Malicious:false
                      Reputation:unknown
                      Preview:p...... ........+...I...(....................................................... ..........W....................o...h.t.t.p.:././.x.1...i...l.e.n.c.r...o.r.g./...".6.4.c.d.6.6.5.4.-.5.6.f."...
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:data
                      Category:modified
                      Size (bytes):330
                      Entropy (8bit):3.287136292755414
                      Encrypted:false
                      SSDEEP:
                      MD5:86560E5FD8CDA8B5A40A048974BDB43A
                      SHA1:C9D76E7266B5F71BFCBE51626D3C41D8651FF19A
                      SHA-256:A9CEEE3B6EE352BD9D3044515DA2B21231B6B72A077F971F59FA2A3FBEF992FF
                      SHA-512:6F7DEAB9E42822B3307BCD958AB789871F70D5BF3A1E0468619D19F2DEE731FCA734D677C29819265C419AD6140B51F7BD1257F55BDCAD14E82276347BE9F137
                      Malicious:false
                      Reputation:unknown
                      Preview:p...... ........k...I...(....................................................... ..................(....c*.....Y...h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".6.4.2.7.f.6.c.2.b.7.8.7.d.b.1.:.0."...
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):295
                      Entropy (8bit):5.362941139591646
                      Encrypted:false
                      SSDEEP:
                      MD5:D42AB26867968ACFBFA6378FF4903F2C
                      SHA1:D2A27324B4F631CFC71CB9A058A7DF2131102F8F
                      SHA-256:5549C11B240413D944899310D45B8C6CD31EB50862BD22F9736961F255937174
                      SHA-512:98D2310F82ED17CCFE091E41649A97279BEF20485E2A23709037FBD560E612EA915C4527BFDD66494208EB74047FDE4830E060E8E8284AD96BC83F81F84F026E
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"ACROBAT_READER_MASTER_SURFACEID","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):294
                      Entropy (8bit):5.3094388527094285
                      Encrypted:false
                      SSDEEP:
                      MD5:3FD1AFC49081969A72DBD1EBAE0CCFC5
                      SHA1:E72362259C3E3FE96D39551E215C0AAF42DC4086
                      SHA-256:5CA711468C1FFC5E056B3587A33BF5E99EF9CFC509063E6F3DFF090274598847
                      SHA-512:4878021E094EAAA5E4C5557F1E4D7D7744312BED710EA8215F0D2594038706B3C955ADA83DAEE522BC3691C18CF936A9B066AE824B54E90E31FDED60FE2F880E
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_FirstMile_Home_View_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):294
                      Entropy (8bit):5.287577767454696
                      Encrypted:false
                      SSDEEP:
                      MD5:F50E1D1748EA37AB87EDA0DB69A5F493
                      SHA1:61F129078EEAF9A2E4AA26E054BB70220DCFD811
                      SHA-256:D945FEB50E6A6DA89FAA27EEEBB806F3AF70954902D6F0019E9B4DEE9BC59DDF
                      SHA-512:41C720A91E6DA5586DBC3833BC5DDF15D98213F095980024F9069FA0376BAAA182272F9FE02E9803C11CB587FFD64E569767C58216C2159EC4DC163F7CE56511
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_FirstMile_Right_Sec_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):285
                      Entropy (8bit):5.35130651265806
                      Encrypted:false
                      SSDEEP:
                      MD5:65C8D8985615C76FB69E86718147ADEE
                      SHA1:3D6C871732579A8E3BA005D2FCCC8F1F3D7A3982
                      SHA-256:E3C049BAB037CCB511DE51D2AEE73D660839881F17087ACA08FF8C46A5DD2D99
                      SHA-512:750DA682C29793DAF018BBFF280C81B346996D4825FB7098ADFA26A74E9F8590284C7FE756A475AF370688D317FB19E315569914AFBCFC27EED71F36854C2367
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_READER_LAUNCH_CARD","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):2129
                      Entropy (8bit):5.839521410538603
                      Encrypted:false
                      SSDEEP:
                      MD5:CF559C37A60AAA2067F351974571DF3F
                      SHA1:10FAC70EB4EAF045D10CE1497A6545137E5DB07D
                      SHA-256:DD1CF042203F7FFFF7C8D55EA70ABD96C7101BAE80C28C7653046AFA9C637309
                      SHA-512:3574ACC3E012F404955151C6FB1C81B84DD1D08896AD100C449B930AFDED710321D2F7F072B85A6C7BF93743E6E0930B15B00F97CFB955C262C86B5073A6C3C5
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_Convert_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Convert_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"102656_316349ActionBlock_1","campaignId":102656,"containerId":"1","controlGroupId":"","treatmentId":"5a9d1955-ab74-4b89-837a-074b702313c0","variationId":"316349"},"containerId":1,"containerLabel":"JSON for DC_Reader_Convert_LHP_Banner","content":{"data":"eyJkYXRhIjp7ImxocFYyQnlQYXRoIjp7Iml0ZW0iOnsiX3BhdGgiOiIvY29udGVudC9kYW0vYWNyb2JhdGRlc2t0b3AvZ3Jvd3RoL3JlYWRlci9lbi11cy9saHAtYmFubmVyL3YyL2NvbnZlcnQiLCJfdmFyaWF0aW9uIjoicmdzMDM2MS0wIiwidGl0bGUiOm51bGwsImRlc2NyaXB0aW9uIjoiRXhwb3J0IFBERnMgdG8gTWljcm9zb2Z0IFdvcmQgYW5kIEV4Y2VsLiIsImN0YUxhYmVsIjpudWxsLCJjdGFCZWhhdmlvciI6bnVsbCwiY3RhVXJsIjpudWxsLCJjdGFVcmxUeXBlIjpudWxsLC
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):289
                      Entropy (8bit):5.29849312679421
                      Encrypted:false
                      SSDEEP:
                      MD5:8A710C881EDE03011B830B5321305AA1
                      SHA1:0DC792BCFA84F50B8DAEDC6C91940831D115A5F0
                      SHA-256:061E1B500143A0EB485BBAB043DBFCB060863E5EF09BE94FA8A53626BD7145E3
                      SHA-512:B28D0E321CE498A914D667EEC61BA621C017BC7500ED579913AFA7EB500AEEB818390D6E549AA3FF64463862F788FD9E5F08134FC867256E3812820CA0A07A5A
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):292
                      Entropy (8bit):5.300851863129619
                      Encrypted:false
                      SSDEEP:
                      MD5:97011A01D1ACC518FB1757DEE2170CB6
                      SHA1:6779E028024291E94F2A4D178D2333F8454CE8EB
                      SHA-256:100DC703CA55701F8E9202516B318094EA193A41F83686852C44B8173F29B4A8
                      SHA-512:B45E6BA5CC79DE929900E76EB8CA2C8581EB928463EE97278F3087F2E1E2AE47BBE504281520D684DD965090B446F603595962DDB15ACA05CE0D18453A45ADB4
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):2080
                      Entropy (8bit):5.824133844878202
                      Encrypted:false
                      SSDEEP:
                      MD5:189C5C337280362B08CAA8552C1E1EA8
                      SHA1:5C2F8F22DBCB2E82EED55908EE985D20550249D4
                      SHA-256:4CA211B5605784F55E3ECACD338B8578745BA0F72F80300FB64F3F4739B0F947
                      SHA-512:D14B84C15281C0C1EF5B5283AC2837FFFB563CA1F1F1772F984366DAA8B2FDC33700D435FA11E28F760AD847336CB5EEA63F744B1657A813AFF843A986F8FA71
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_Edit_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Edit_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"102656_316349ActionBlock_2","campaignId":102656,"containerId":"1","controlGroupId":"","treatmentId":"164bf29d-ee04-491c-adf2-c0bfeedb2d1b","variationId":"316349"},"containerId":1,"containerLabel":"JSON for DC_Reader_Edit_LHP_Banner","content":{"data":"eyJkYXRhIjp7ImxocFYyQnlQYXRoIjp7Iml0ZW0iOnsiX3BhdGgiOiIvY29udGVudC9kYW0vYWNyb2JhdGRlc2t0b3AvZ3Jvd3RoL3JlYWRlci9lbi11cy9saHAtYmFubmVyL3YyL2VkaXQiLCJfdmFyaWF0aW9uIjoicmdzMDM2MS0wIiwidGl0bGUiOm51bGwsImRlc2NyaXB0aW9uIjpudWxsLCJjdGFMYWJlbCI6bnVsbCwiY3RhQmVoYXZpb3IiOm51bGwsImN0YVVybCI6bnVsbCwiY3RhVXJsVHlwZSI6bnVsbCwidHJhY2tpbmdJZCI6bnVsbCwiX21ldGFkYXRhIjp7InN0cmluZ01ldGFkYXRhIjp
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):295
                      Entropy (8bit):5.324775963562535
                      Encrypted:false
                      SSDEEP:
                      MD5:7F84C829BA09EF09021C87073314D55F
                      SHA1:AC684F0E20B036CF7DDBED92463E5723A7798CD7
                      SHA-256:90AF604E8BE63597C476A2F424A9573A0B60C27A02DCA5BDB6D3F9D30B10F48B
                      SHA-512:4CF39900A70BDF1646DE3B21C4BB4BED556DDA97BC2B33CAB2F12AB11C977B2AAB9DB943C821A5D2DF50526335C3EFCBF2EC5CC81B6BECB8039D837372E76059
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_Home_LHP_Trial_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):289
                      Entropy (8bit):5.305238255237308
                      Encrypted:false
                      SSDEEP:
                      MD5:11BA0B911F2F2EE0724F843F31EE5591
                      SHA1:9083E77C5C9565EFB3BF88F31555BEB110DE9E2E
                      SHA-256:5D255B824467709B1E073A68021305B145D7765A776A7DA102B0675F1BA22541
                      SHA-512:4CDDD42E69FD36E8141473A649E6AB1C4D4517B1EA15664574E15FFC9DEA26DE4347BB117BB63D0452FF3CAEA3BAC62FA6DA20EBF4F4F8C2A6E8C9FB46094994
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_More_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):284
                      Entropy (8bit):5.2916798417912965
                      Encrypted:false
                      SSDEEP:
                      MD5:05E004143389BDEE283851D9F551706D
                      SHA1:2B7C1F7C4A992F76161AB06762BDC51BF846A558
                      SHA-256:5132E8705F9AED65DE1662312CCCF41DC4BC79265BE0538B33CC873F3590B5C2
                      SHA-512:92D12654A212BA18E0A88C3F80CDBC12059CCACC6E8EBE0A1ED13F7C3E48D18C293F4E560D0E5E8C12B91562BB2FBA428D10D31DDB66DE6AD7E0B9D0D838E434
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_RHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):291
                      Entropy (8bit):5.288749351156963
                      Encrypted:false
                      SSDEEP:
                      MD5:A088E95127EB2046F16CD85ABA073740
                      SHA1:3D5B756BC36AA6CB796E115400352B308C610ECB
                      SHA-256:F9A8736AF75C11B4FC3B2BE893D29EA34C507804549B5786F43EA834F41DBC16
                      SHA-512:2FCB222D12015162606F3946125EAC94A387FCE30C22770732C722EFD96F799B1DBC8EA7A86329152641CD461764921F576E2DF7E6061342FDA23A867FD8E36D
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_RHP_Intent_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):287
                      Entropy (8bit):5.291888796134471
                      Encrypted:false
                      SSDEEP:
                      MD5:0290F215DCC4BCE8C32279B6BF4B17DE
                      SHA1:56F96FCA1739B536DD69784A3A1213DE8BBB94C1
                      SHA-256:40901733D2CC93F515E146C9B79A142FDACE7DC3F1B4FE5C3F34E293A0057A02
                      SHA-512:2AEF0433BF11257182F636C0C1A019AB0F5AB5DA4995DCDBF0A3E955920232EBF311429553B788097A0EF3BB089CDA67AA266758CBE38372B4DB493CBE3DC646
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_RHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):2028
                      Entropy (8bit):5.838868326043943
                      Encrypted:false
                      SSDEEP:
                      MD5:86BF89BED93DFA7C7F9982946B38E533
                      SHA1:BF63837726B12E4191592004423AE35FDA9BB07D
                      SHA-256:F1FD6A83817495BA33B01C92E830407798C29430F8EE59BDA5C8394EFFA12BE6
                      SHA-512:7CE1B59349A46508A7020316A3ACCE5F3D6F6B98448041EDFF5766B8742F940E0936F6B72A4BD6EDF8BF0EC62FB6C6A9BEF1BA9EF755CEF71E94510014653941
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_Sign_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Sign_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"102656_316349ActionBlock_0","campaignId":102656,"containerId":"1","controlGroupId":"","treatmentId":"339c0ba6-2e61-4622-82f6-f07787d206b8","variationId":"316349"},"containerId":1,"containerLabel":"JSON for DC_Reader_Sign_LHP_Banner","content":{"data":"eyJkYXRhIjp7ImxocFYyQnlQYXRoIjp7Iml0ZW0iOnsiX3BhdGgiOiIvY29udGVudC9kYW0vYWNyb2JhdGRlc2t0b3AvZ3Jvd3RoL3JlYWRlci9lbi11cy9saHAtYmFubmVyL3YyL3NpZ24iLCJfdmFyaWF0aW9uIjoicmdzMDM2MS0wIiwidGl0bGUiOm51bGwsImRlc2NyaXB0aW9uIjoiRWFzaWx5IGZpbGwgYW5kIHNpZ24gUERGcy4iLCJjdGFMYWJlbCI6bnVsbCwiY3RhQmVoYXZpb3IiOm51bGwsImN0YVVybCI6bnVsbCwiY3RhVXJsVHlwZSI6bnVsbCwidHJhY2tpbmdJZCI6bnVsbCwiX21ldGF
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):286
                      Entropy (8bit):5.267858524916424
                      Encrypted:false
                      SSDEEP:
                      MD5:5FEC6DD80ECB4CC9F94E94097ED4003C
                      SHA1:0F5605A958A66ED8C2203F1DC053D359B7F50267
                      SHA-256:A2ED3F857E501FA097356539A884431AE70BC872EE0E9588736FDAE23B5DAA10
                      SHA-512:6057F67B714A27DF73F5F5A5BD741ECDFAF8A39C3F1254BFDC8A4515745201BC01B6DF73F91080B2CF2F1954F56B5E7440F78030C82CABAA4350FB64CBE1EAEA
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"DC_Reader_Upsell_Cards","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):282
                      Entropy (8bit):5.273210554264925
                      Encrypted:false
                      SSDEEP:
                      MD5:2527AE72E0436DDFE21724B1B2E8997B
                      SHA1:6D5C895586238CBB6C021A74AEE1DC7FCA358B8D
                      SHA-256:A0B1E13CD9AE26D20A03839047417E2212CBCF9C9BC9C8B90FE8276A05468A76
                      SHA-512:28B217A3D977E2B931F270591B258843EA11F0DAFBD35A1F38A9B1BD7C9A094A28B6AC6D4F26AAA3CFB8D8A43F52531BE652E6FBCFF8F8AE6F067EBCF02706C2
                      Malicious:false
                      Reputation:unknown
                      Preview:{"analyticsData":{"responseGUID":"e0308082-1cf6-4e92-9d15-f2ccad59661f","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1744047566031,"statusCode":200,"surfaceID":"Edit_InApp_Aug2020","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):4
                      Entropy (8bit):0.8112781244591328
                      Encrypted:false
                      SSDEEP:
                      MD5:DC84B0D741E5BEAE8070013ADDCC8C28
                      SHA1:802F4A6A20CBF157AAF6C4E07E4301578D5936A2
                      SHA-256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
                      SHA-512:65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71
                      Malicious:false
                      Reputation:unknown
                      Preview:....
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:JSON data
                      Category:dropped
                      Size (bytes):2815
                      Entropy (8bit):5.145380432389783
                      Encrypted:false
                      SSDEEP:
                      MD5:EF315027BB524C857F4F58F958E24975
                      SHA1:F68F429D8C9DCC70F8E3604DDCFF8E522A9E52D4
                      SHA-256:38AEA410604B8BD2684C6155CCF665FB0798A1B1907153BFBE83F86D3C71F917
                      SHA-512:DF0FA998A1E70B352BF5609345221EB0B304DF61BC4813D5EA912341896FFB1FC5C644156CFDDD1CD94B7EEE5B4F38F7AC8FDC405C58A69959617AA794C9A612
                      Malicious:false
                      Reputation:unknown
                      Preview:{"all":[{"id":"DC_Reader_Disc_LHP_Banner","info":{"dg":"f3ddab0029704078dd04ca88eb2568d8","sid":"DC_Reader_Disc_LHP_Banner"},"mimeType":"file","size":289,"ts":1743871361000},{"id":"DC_Reader_Sign_LHP_Banner","info":{"dg":"aa00c542965320d967951c5fef105bb8","sid":"DC_Reader_Sign_LHP_Banner"},"mimeType":"file","size":2028,"ts":1743871360000},{"id":"DC_Reader_Convert_LHP_Banner","info":{"dg":"85c8eff1520a54975f52f039039c3b28","sid":"DC_Reader_Convert_LHP_Banner"},"mimeType":"file","size":2129,"ts":1743871360000},{"id":"DC_Reader_Edit_LHP_Banner","info":{"dg":"f5df14497cb423bd8fc1d325b472a0af","sid":"DC_Reader_Edit_LHP_Banner"},"mimeType":"file","size":2080,"ts":1743871360000},{"id":"DC_Reader_Home_LHP_Trial_Banner","info":{"dg":"5535063fe0bfa4509c46c116c4ac3885","sid":"DC_Reader_Home_LHP_Trial_Banner"},"mimeType":"file","size":295,"ts":1743871360000},{"id":"DC_Reader_Disc_LHP_Retention","info":{"dg":"052bbaa9281d8e7f7db9e0cff5ca079a","sid":"DC_Reader_Disc_LHP_Retention"},"mimeType":"file",
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 19, database pages 3, cookie 0x2, schema 4, UTF-8, version-valid-for 19
                      Category:dropped
                      Size (bytes):12288
                      Entropy (8bit):0.988874296940828
                      Encrypted:false
                      SSDEEP:
                      MD5:3AAAA04B014140E307A72B2E0C089934
                      SHA1:D3D78DEAA9F7C6D77BADC8EC4CC498B09C4B5B3A
                      SHA-256:484B3A72C63AD63CE887687827787B3E5384CEBCE787C7E909C0EAEE10FC5856
                      SHA-512:FC1B4820963F11C97E1741B16FC54B16C5263032554B4CF1086823626DCB54F5BF6A24F50C7A47F5372EE707425685ACB3F64A9C2DCC74CC86D0B5388A002942
                      Malicious:false
                      Reputation:unknown
                      Preview:SQLite format 3......@ ..........................................................................c.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:SQLite Rollback Journal
                      Category:dropped
                      Size (bytes):8720
                      Entropy (8bit):1.3430720078952825
                      Encrypted:false
                      SSDEEP:
                      MD5:834C7557B7B1C3284E66A9C614D3DF13
                      SHA1:3545E875BA226047349E6F69279C526C0EDBF087
                      SHA-256:494DDC590DC9F134646C9C23B9A3E1BD1CEEC56A1BD09C815BCB7B6D14D9F985
                      SHA-512:C3FE0AA083A55DF31233C43941F930CF10045B990A2CD2E2CA37D5EDC41108EEC54EEF2F6E46D330481A55F0BF15F6C80350995DC3A4748DEFCFD1BCCADC6A35
                      Malicious:false
                      Reputation:unknown
                      Preview:.... .c......K3.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................j...#..#.#.#.#.#.#.#.#.7.7........................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):246
                      Entropy (8bit):3.518261198325562
                      Encrypted:false
                      SSDEEP:
                      MD5:F57386B6419BB607B96DB4B8D98E51EB
                      SHA1:62A9D0596729818A9BB008FFD238F7A0875726F9
                      SHA-256:071C98343294F8E27890CE6C7B7C06464F1C30DA3AC0972E35324F98B8D8B56D
                      SHA-512:95FAACC227FBD3D0B44D1F9737508FABE631C94CE0DE9FF89A81468B6B317585EF37FF6AEE14D49637DC02BAC66BCC1D151EEC7CB005F6201D82D53524F0D551
                      Malicious:false
                      Reputation:unknown
                      Preview:..E.r.r.o.r. .2.7.1.1...T.h.e. .s.p.e.c.i.f.i.e.d. .F.e.a.t.u.r.e. .n.a.m.e. .(.'.A.R.M.'.). .n.o.t. .f.o.u.n.d. .i.n. .F.e.a.t.u.r.e. .t.a.b.l.e.......=.=.=. .L.o.g.g.i.n.g. .s.t.o.p.p.e.d.:. .0.5./.0.4./.2.0.2.5. . .1.2.:.4.2.:.4.3. .=.=.=.....
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:ASCII text, with very long lines (393)
                      Category:dropped
                      Size (bytes):16525
                      Entropy (8bit):5.353642815103214
                      Encrypted:false
                      SSDEEP:
                      MD5:91F06491552FC977E9E8AF47786EE7C1
                      SHA1:8FEB27904897FFCC2BE1A985D479D7F75F11CEFC
                      SHA-256:06582F9F48220653B0CB355A53A9B145DA049C536D00095C57FCB3E941BA90BB
                      SHA-512:A63E6E0D25B88EBB6602885AB8E91167D37267B24516A11F7492F48876D3DDCAE44FFC386E146F3CF6EB4FA6AF251602143F254687B17FCFE6F00783095C5082
                      Malicious:false
                      Reputation:unknown
                      Preview:SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:073+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:073+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="SetConfig:
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:ASCII text, with very long lines (393), with CRLF line terminators
                      Category:dropped
                      Size (bytes):15114
                      Entropy (8bit):5.386571417813363
                      Encrypted:false
                      SSDEEP:
                      MD5:C7CEC48D8F950DFD564579D7C3635A8E
                      SHA1:F68585198F925779F0CE9710E8A5EA6E5D284695
                      SHA-256:3D5E73D9DD97EBD3D450AC64E3C2F41500C7783A061E3F555476A5746813D7B6
                      SHA-512:8E3BB400CADB60AD32F966BB4C6C9F6E82DCB3312D37B02A76ABAF4F1C071F32AF486FA9706EC6A35F8BB321FD8CB5DD719D576BF8F45ABE29FF1314BB01E17B
                      Malicious:false
                      Reputation:unknown
                      Preview:SessionID=7d52f352-56fa-42d6-b1c8-66937957acb0.1743871358778 Timestamp=2025-04-05T12:42:38:778-0400 ThreadID=7156 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------"..SessionID=7d52f352-56fa-42d6-b1c8-66937957acb0.1743871358778 Timestamp=2025-04-05T12:42:38:779-0400 ThreadID=7156 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found"..SessionID=7d52f352-56fa-42d6-b1c8-66937957acb0.1743871358778 Timestamp=2025-04-05T12:42:38:779-0400 ThreadID=7156 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!"..SessionID=7d52f352-56fa-42d6-b1c8-66937957acb0.1743871358778 Timestamp=2025-04-05T12:42:38:779-0400 ThreadID=7156 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1"..SessionID=7d52f352-56fa-42d6-b1c8-66937957acb0.1743871358778 Timestamp=2025-04-05T12:42:38:780-0400 ThreadID=7156 Component=ngl-lib_NglAppLib Description="SetConf
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                      File Type:ASCII text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):29752
                      Entropy (8bit):5.420498163956304
                      Encrypted:false
                      SSDEEP:
                      MD5:F6DF17391414E81BF8779C8C7E7C8AF4
                      SHA1:BAAEAB8D9B60BF7D16476433BFECAE8D049A2E86
                      SHA-256:A21E1C83099F29B28587F29F436ACCB3F9B4CA677580C2996D8966019D85F51B
                      SHA-512:0C41DD74C8956AB5A34BCF3004B8E63968EE5443BB8C8A7095BA3B20E31745A3A8CE6DD89807295CA983DFEDABE2C5D21C9EFB49C5EF0360F8A647A6BCDCD66C
                      Malicious:false
                      Reputation:unknown
                      Preview:06-10-2023 10:08:42:.---2---..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ***************************************..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ***************************************..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ******** Starting new session ********..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : Starting NGL..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : Setting synchronous launch...06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 ::::: Configuring as AcrobatReader1..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : NGLAppVersion 23.6.20320.6..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : NGLAppMode NGL_INIT..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : AcroCEFPath, NGLCEFWorkflowModulePath - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1 C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : isNGLExternalBrowserDisabled - No..06-10-2023 10:08:42:.Closing File..06-10-
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1311022
                      Category:dropped
                      Size (bytes):386528
                      Entropy (8bit):7.9736851559892425
                      Encrypted:false
                      SSDEEP:
                      MD5:5C48B0AD2FEF800949466AE872E1F1E2
                      SHA1:337D617AE142815EDDACB48484628C1F16692A2F
                      SHA-256:F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE
                      SHA-512:44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324
                      Malicious:false
                      Reputation:unknown
                      Preview:...........]s[G. Z...{....;...J$%K&..%.[..k...S....$,.`. )Z..m........a.......o..7.VfV...S..HY}Ba.<.NUVVV~W.].;qG4..b,N..#1.=1.#1..o.Fb.........IC.....Z...g_~.OO.l..g.uO...bY.,[..o.s.D<..W....w....?$4..+..%.[.?..h.w<.T.9.vM.!..h0......}..H..$[...lq,....>..K.)=..s.{.g.O...S9".....Q...#...+..)>=.....|6......<4W.'.U.j$....+..=9...l.....S..<.\.k.'....{.1<.?..<..uk.v;.7n.!...g....."P..4.U........c.KC..w._G..u..g./.g....{'^.-|..h#.g.\.PO.|...]x..Kf4..s..............+.Y.....@.K....zI..X......6e?[..u.g"{..h.vKbM<.?i6{%.q)i...v..<P8P3.......CW.fwd...{:@h...;........5..@.C.j.....a.. U.5...].$.L..wW....z...v.......".M.?c.......o..}.a.9..A..%V..o.d....'..|m.WC.....|.....e.[W.p.8...rm....^..x'......5!...|......z..#......X_..Gl..c..R..`...*.s-1f..]x......f...g...k........g....... ).3.B..{"4...!r....v+As...Zn.]K{.8[..M.r.Y..........+%...]...J}f]~}_..K....;.Z.[..V.&..g...>...{F..{I..@~.^.|P..G.R>....U..../HY...(.z.<.~.9OW.Sxo.Y
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 5111142
                      Category:dropped
                      Size (bytes):1419751
                      Entropy (8bit):7.976496077007677
                      Encrypted:false
                      SSDEEP:
                      MD5:1A39CAAE4C5F8AD2A98F0756FFCBA562
                      SHA1:279F2B503A0B10E257674D31532B01EA7DE0473F
                      SHA-256:57D198C7BDB9B002B8C9C1E1CCFABFE81C00FE0A1E30A237196A7C133237AA95
                      SHA-512:73D083E92FB59C92049AF8DC31A0AA2F38755453FFB161D18A1C4244747EE88B7A850F7951FC10F842AE65F6CC8F6164231DB6261777EC5379B337CB379BEF99
                      Malicious:false
                      Reputation:unknown
                      Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 33081
                      Category:dropped
                      Size (bytes):1407294
                      Entropy (8bit):7.97605879016224
                      Encrypted:false
                      SSDEEP:
                      MD5:716C2C392DCD15C95BBD760EEBABFCD0
                      SHA1:4B4CE9C6AED6A7F809236B2DAFA9987CA886E603
                      SHA-256:DD3E6CFC38DA1B30D5250B132388EF73536D00628267E7F9C7E21603388724D8
                      SHA-512:E164702386F24FF72111A53DA48DC57866D10DAE50A21D4737B5687E149FF9D673729C5D2F2B8DA9EB76A2E5727A2AFCFA5DE6CC0EEEF7D6EBADE784385460AF
                      Malicious:false
                      Reputation:unknown
                      Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                      File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 299538
                      Category:dropped
                      Size (bytes):758601
                      Entropy (8bit):7.98639316555857
                      Encrypted:false
                      SSDEEP:
                      MD5:3A49135134665364308390AC398006F1
                      SHA1:28EF4CE5690BF8A9E048AF7D30688120DAC6F126
                      SHA-256:D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B
                      SHA-512:BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5
                      Malicious:false
                      Reputation:unknown
                      Preview:...........kWT..0...W`.........b..@..nn........5.._..I.R3I..9g.x....s.\+.J......F...P......V]u......t....jK...C.fD..]..K....;......y._.U..}......S.........7...Q.............W.D..S.....y......%..=.....e..^.RG......L..].T.9.y.zqm.Q]..y..(......Q]..~~..}..q...@.T..xI.B.L.a.6...{..W..}.mK?u...5.#.{...n...........z....m^.6!.`.....u...eFa........N....o..hA-..s.N..B.q..{..z.{=..va4_`5Z........3.uG.n...+...t...z.M."2..x.-...DF..VtK.....o]b.Fp.>........c....,..t..an[............5.1.(}..q.q......K3.....[>..;e..f.Y.........mV.cL...]eF..7.e.<.._.o\.S..Z...`..}......>@......|.......ox.........h.......o....-Yj=.s.g.Cc\.i..\..A.B>.X..8`...P......[..O...-.g...r..u\...k..7..#E....N}...8.....(..0....w....j.......>.L....H.....y.x3...[>..t......0..z.qw..]X..i8..w.b..?0.wp..XH.A.[.....S..g.g..I.A.15.0?._n.Q.]..r8.....l..18...(.].m...!|G.1...... .3.`./....`~......G.............|..pS.e.C....:o.u_..oi.:..|....joi...eM.m.K...2%...Z..j...VUh..9.}.....
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:Unicode text, UTF-8 text, with very long lines (65305)
                      Category:downloaded
                      Size (bytes):194901
                      Entropy (8bit):5.014294143940012
                      Encrypted:false
                      SSDEEP:
                      MD5:3F30C2C47D7D23C7A994DB0C862D45A5
                      SHA1:7791DD1F3173A0D62CC39C21D2AD71FC8DAD0E72
                      SHA-256:C0BCF7898FDC3B87BABCA678CD19A8E3EF570E931C80A3AFBFFCC453738C951A
                      SHA-512:49B891FDEBACA612A8315557CAC4CA1BFED5B1E5A28BE63715D1EBB741292A0A53A1979E9A1A8779978B58B849BADCFFDAEB76570D6E4048F631B445F9354150
                      Malicious:false
                      Reputation:unknown
                      URL:https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/css/bootstrap.min.css
                      Preview:@charset "UTF-8";/*!. * Bootstrap v5.2.3 (https://getbootstrap.com/). * Copyright 2011-2022 The Bootstrap Authors. * Copyright 2011-2022 Twitter, Inc.. * Licensed under MIT (https://github.com/twbs/bootstrap/blob/main/LICENSE). */:root{--bs-blue:#0d6efd;--bs-indigo:#6610f2;--bs-purple:#6f42c1;--bs-pink:#d63384;--bs-red:#dc3545;--bs-orange:#fd7e14;--bs-yellow:#ffc107;--bs-green:#198754;--bs-teal:#20c997;--bs-cyan:#0dcaf0;--bs-black:#000;--bs-white:#fff;--bs-gray:#6c757d;--bs-gray-dark:#343a40;--bs-gray-100:#f8f9fa;--bs-gray-200:#e9ecef;--bs-gray-300:#dee2e6;--bs-gray-400:#ced4da;--bs-gray-500:#adb5bd;--bs-gray-600:#6c757d;--bs-gray-700:#495057;--bs-gray-800:#343a40;--bs-gray-900:#212529;--bs-primary:#0d6efd;--bs-secondary:#6c757d;--bs-success:#198754;--bs-info:#0dcaf0;--bs-warning:#ffc107;--bs-danger:#dc3545;--bs-light:#f8f9fa;--bs-dark:#212529;--bs-primary-rgb:13,110,253;--bs-secondary-rgb:108,117,125;--bs-success-rgb:25,135,84;--bs-info-rgb:13,202,240;--bs-warning-rgb:255,193,7;--bs-
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text
                      Category:downloaded
                      Size (bytes):93734
                      Entropy (8bit):4.7854569434333385
                      Encrypted:false
                      SSDEEP:
                      MD5:8F4B242830EC54686815617E7B5A5B1B
                      SHA1:A7838D8A20DBDA0EE9E4C1CB7F1F832CE9AF1C11
                      SHA-256:D8824F7067CDFEA38AFEC7E9FFAF072125266824206D69EF1F112D72153A505E
                      SHA-512:D326210B288C07EE973A2B38AAF580E3690F90A6F9E3EB8C68E85BB2D6BA9BE690EDC64E9B98731113EB4649249E5A44768C550B062E8BEC8CD2345ACE90C5B8
                      Malicious:false
                      Reputation:unknown
                      URL:https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/bootstrap-icons.css
                      Preview:/*!. * Bootstrap Icons v1.10.5 (https://icons.getbootstrap.com/). * Copyright 2019-2023 The Bootstrap Authors. * Licensed under MIT (https://github.com/twbs/icons/blob/main/LICENSE). */..@font-face {. font-display: block;. font-family: "bootstrap-icons";. src: url("./fonts/bootstrap-icons.woff2?1fa40e8900654d2863d011707b9fb6f2") format("woff2"),.url("./fonts/bootstrap-icons.woff?1fa40e8900654d2863d011707b9fb6f2") format("woff");.}...bi::before,.[class^="bi-"]::before,.[class*=" bi-"]::before {. display: inline-block;. font-family: bootstrap-icons !important;. font-style: normal;. font-weight: normal !important;. font-variant: normal;. text-transform: none;. line-height: 1;. vertical-align: -.125em;. -webkit-font-smoothing: antialiased;. -moz-osx-font-smoothing: grayscale;.}...bi-123::before { content: "\f67f"; }..bi-alarm-fill::before { content: "\f101"; }..bi-alarm::before { content: "\f102"; }..bi-align-bottom::before { content: "\f103"; }..bi-align-center::before { cont
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:PNG image data, 2000 x 629, 8-bit colormap, non-interlaced
                      Category:downloaded
                      Size (bytes):28216
                      Entropy (8bit):7.947578719695897
                      Encrypted:false
                      SSDEEP:
                      MD5:B8468E2D5BEB7B35C9950670ED026B19
                      SHA1:736A0ECF6A82BCE41C90374EEEF4155501DDCF80
                      SHA-256:4175C73ED64CF30C2BBA49AFA8DFC6A44E23020F505D73EA7D46A70EE69D0141
                      SHA-512:02B4CD5DA10F6EFF2AE06CC67FA18A7267C81365351FD9FA8E694A3BE2E9E167B27A79528DA0D540505FEA8E0D3FA39EE436165D0674A0EDEA083E0079BF89C2
                      Malicious:false
                      Reputation:unknown
                      URL:https://kobadropinv.live/en/az/tz/drop/avast.png
                      Preview:.PNG........IHDR.......u.............gAMA......a.....sRGB.........PLTEGpL..9..0..9..9..9..K..8..8..9.....9..8..7..:..8..3..9.....8..8..9..9..8..8..8..9..8..8..;..8..8..6..7..8..8..9..8..8..:..8..8.V...9..8..9..8..8..8..9..8..9..8..8..8..9..8..8..8..8..7..9..8..8..;..8..8..8..8.`...8.`...8.e...8..?..9..8..8..8..8..:..8.a...8..8..8..8.a...8.....8..9..8..8.`...8.]..`..a..`..`..`...9.`..d..`...8..7..9.`...8..8..8.b...8..9.`.._..`..`..b..`...8..8.b..`...8..9.`...8.`..`..`..a..`..`..a..`..a..`..U.._..`..`..a..`..`..`..a...6.`..`..`..`..`..`..a..`.._..a..a..`...9.`..`..`..`..a..a..a..a..a..Z..`.._..a..`..`..`..a..`..a..a..`..c..`..a..`..`..b...9.a..a..`..a..`..a...9.......b......:.......u+.g.....i..c...D.l........o".r&..~..g.|6.....y...z2.....S.......O.........a..>........n........W....e...\....r..I.............................?......tRNS.......2.Y..^.......N.8.v.d.."...D..J......a.'....U.../.....3..<*j..R.s.|.o...y...,.![.5G...g.....@...~$B.pl....$Qw..>5....W.....8i..3-.(....
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:Web Open Font Format (Version 2), TrueType, length 121340, version 1.0
                      Category:downloaded
                      Size (bytes):121340
                      Entropy (8bit):7.998013315456264
                      Encrypted:true
                      SSDEEP:
                      MD5:A30FB81BD52143BCD4DE2898422AC8B9
                      SHA1:4C0EFCF1DCCC7295EFC26FABE81FFE8F28D594A3
                      SHA-256:CFE45B981D1B91B173361A34CFCE5F60893DBD1AC4AF2C3AC11FC17552C5401F
                      SHA-512:C3EE9BD353A1E7DE0C247651215B4B34F69C0027B987F7779271D61CD5122A6C72A38D52C2D91275D9E76EED0B08C4E6CDA61341E077005C70AB790295EB858E
                      Malicious:false
                      Reputation:unknown
                      URL:https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/fonts/bootstrap-icons.woff2?1fa40e8900654d2863d011707b9fb6f2
                      Preview:wOF2............................................T.`..........z.6.$........ ..j...}[.....?..]....E ._.......9...h.....9..,.....B...V...&.QI.Rg............G.#.Mg....p..... ..bH.4&M.4..B.L<..b...T...V./....x.t=lrRYS.n..g...b6.i.K8.......<.\*.*.....X..Z..Wn..$h......RhW&Y.g|g......!...=<CI..E..q.X..1=......I..Y3<m.m.... .i./w......i.^3j...Au.L.9.....7...n:RM.9.j.n...u]..h3F.......m.[..U.dx....i..J...w......'?....:.$.........Zy.....N.TO..f.#.3...\~..?...O.........F,.!..7.Z.\.e-.._.K<..).... ;.!3...4!...6...h.v....e....._..U.....'h9....o.."..=1.o.|n.....kWv.......2..,...,.*...[..e..Z.op..g......!.[a&..... ...n.S4'N._^..Z[....6.%.w..?...I.[..._..U..$.z.P..'y.J.S&.{6.,K.I(o.F..L.z.{.C..b@......F...$.&...."...W....+.....7}_....'M....a+.u..k....g<......^...[A..D..{.6..5..P.Ns..S.^>f........s#jUH[A.h..^..R.Z../..y....?...,..!LQ1..0.Y..-...Q..l.BT...@.5A;...9fO.X.V[..zj[.Z..n.....=..<.h.. a...6..!...V.q..cw..F.X.....;....M..5(..v...E.s~8.=g..)'..-
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:PNG image data, 2560 x 802, 8-bit/color RGBA, non-interlaced
                      Category:dropped
                      Size (bytes):129221
                      Entropy (8bit):7.678670032134684
                      Encrypted:false
                      SSDEEP:
                      MD5:2197F0A96C2D467BEAA395C2B9496580
                      SHA1:02238CA189C552BB939368D1A3929401E3B75E85
                      SHA-256:9B298CDCB83459F58F73000BC5C644BFB209F0D7583759DB2098EF3183DB33DC
                      SHA-512:721561DB32612205BB9F6E7DF134073DD89101446168E908849C1F159C6F19A65D6CEA31C6A74CBC0F53B07FF75E84859145C4D98407EC45180FC064888A5CE0
                      Malicious:false
                      Reputation:unknown
                      Preview:.PNG........IHDR......."........6....sRGB....... .IDATx^..y..ey'..s....#.]U...,.]3N.d../...$D..EhD.Q.....A...,&1j.....M...hb.I\@...P......36&F...]g{...W..}..{..."\...)....... @....... @....... @....... @....... .:..... @....... @....... @....... @....... @.......% @....... @....... @....... @....... @....-.....K........ @....... @....... @....... @......X.... @....... @....... @....... @....... @.....X.l.L....... @....... @....... @....... @.....,.z... @....... @....... @....... @....... @.@..,....D&@....... @....... @....... @....... @........... @....... @....... @....... @....... @.....[xi". @....... @....... @....... @....... @........... @....... @....... @....... @....... .B...-.4... @....... @....... @....... @....... @...@....... @....... @....... @....... @.......h.....^..... @....... @....... @....... @....... @...w....... @....... @....... @....... @.......P..`./Md.... @....... @....... @....... @....... `..;@....... @....... @....... @....... @.....Z(`....&2..... @..
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with very long lines (65299)
                      Category:downloaded
                      Size (bytes):80420
                      Entropy (8bit):5.182949713414269
                      Encrypted:false
                      SSDEEP:
                      MD5:B75AE000439862B6A97D2129C85680E8
                      SHA1:90D15036EF48FCB336A135BAE812B45669F19044
                      SHA-256:9520018FA5D81F4E4DC9D06AFB576F90CBBABA209CFCC6CB60E1464647F7890B
                      SHA-512:8BD7047C9C14C158843C529D0B57A7CF86511818FC610A3A401C854C5F766171E2EF0682AB27B1BD10FBE52E4D553B12893BFBACA5AA1BD639785C6646C3A7D0
                      Malicious:false
                      Reputation:unknown
                      URL:https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/js/bootstrap.bundle.min.js
                      Preview:/*!. * Bootstrap v5.2.3 (https://getbootstrap.com/). * Copyright 2011-2022 The Bootstrap Authors (https://github.com/twbs/bootstrap/graphs/contributors). * Licensed under MIT (https://github.com/twbs/bootstrap/blob/main/LICENSE). */.!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?module.exports=e():"function"==typeof define&&define.amd?define(e):(t="undefined"!=typeof globalThis?globalThis:t||self).bootstrap=e()}(this,(function(){"use strict";const t="transitionend",e=t=>{let e=t.getAttribute("data-bs-target");if(!e||"#"===e){let i=t.getAttribute("href");if(!i||!i.includes("#")&&!i.startsWith("."))return null;i.includes("#")&&!i.startsWith("#")&&(i=`#${i.split("#")[1]}`),e=i&&"#"!==i?i.trim():null}return e},i=t=>{const i=e(t);return i&&document.querySelector(i)?i:null},n=t=>{const i=e(t);return i?document.querySelector(i):null},s=e=>{e.dispatchEvent(new Event(t))},o=t=>!(!t||"object"!=typeof t)&&(void 0!==t.jquery&&(t=t[0]),void 0!==t.nodeType),r=t=>o(t)?t.jquer
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:HTML document, ASCII text, with CRLF line terminators
                      Category:downloaded
                      Size (bytes):6427
                      Entropy (8bit):4.583944991094644
                      Encrypted:false
                      SSDEEP:
                      MD5:3274093A4431EAF6754993983B5639E0
                      SHA1:C1C261F8C0BE1021F86A0E8FFA91601326000954
                      SHA-256:F6DA76A305AF8E3885437DB9EA68B81BD2472D01CBBE1EE22A0B6852FF74327B
                      SHA-512:D742E7A062621F2D6D215DCB126DCF077B24ABCD03E1ACB1546AA89427A9F0362F885A980B5C74CB145C289B99779695BDB34E24C5F87B7D569634967A6FB949
                      Malicious:false
                      Reputation:unknown
                      URL:https://kobadropinv.live/en/az/tz/drop/
                      Preview:<!DOCTYPE html>..<html lang="en">..<head>.. <meta charset="UTF-8" />.. <meta name="viewport" content="width=device-width, initial-scale=1" />.. <title>Dropbox Download</title>.. Bootstrap CSS -->.. <link.. rel="stylesheet".. href="https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/css/bootstrap.min.css".. />.. Bootstrap Icons (for PDF icon) -->.. <link.. rel="stylesheet".. href="https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/bootstrap-icons.css".. />.. <style>.. body {.. margin: 0;.. padding: 0;.. background-color: #f7f9fa;.. font-family: Arial, sans-serif;.. }.... /* Top bar container */.. .top-bar {.. background-color: #ffffff;.. border-bottom: 1px solid #e2e2e2;.. height: 70px;.. margin-top: 15px;.. }.... .top-bar a {.. color: #007ee5;.. font-weight: 500;.. text-decoration: none;.. }.. .top-bar a:hover {.. text-decoration: underline;.. }.... .dropbox-log
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:PNG image data, 646 x 293, 8-bit/color RGBA, non-interlaced
                      Category:downloaded
                      Size (bytes):36392
                      Entropy (8bit):7.965372593916268
                      Encrypted:false
                      SSDEEP:
                      MD5:95774F8F0351A8A7B79965A024A2E66D
                      SHA1:449A184F8716311FBF9FE853E1AB2248318966D7
                      SHA-256:C4E13BDED364B910462285FF5F5C2694F548A06CB7E85C654E1BE94A76227F15
                      SHA-512:D0DF73F3CD76A8EC093966425728823EE67C226A1E079D9916747C12C230FA97497B592E20B8018B0EDCDBA1925A3A1A1BA17678C19F2CC4BBF160954E2EFD76
                      Malicious:false
                      Reputation:unknown
                      URL:https://kobadropinv.live/en/az/tz/drop/laptop.png
                      Preview:.PNG........IHDR.......%.....y.#.....sRGB....... .IDATx^.]..MU..sgwt.3I../E.M.PJ...?.C.JD.T.@E2..)_..J.).h..O..y.....?.u.:...9w.}..w.}..<.....w......].}O....&.Q.@.....G9.y..W(.(,*....0.s0.........Q..c..qq1.....1.N9nyc.h.. .7.eILJ..,...?..&O(....~.._.....(,,......_W7N........3....|....0.Z~.'.[B..=..z...S).....R.\OJ<y.....&.z.".R../Q.......`]...d...V..C9.P..Z~...v...U.y...{v.>..[=Vqq......*......N~...T..g..y...8.1.F..V'5.2eVI...d..TI...G.8...G5.aZ;v.E.|.....+....t...C.R%%.2..&....@\\.%...d..'...X....".\d.x?a...|.>..}........>-6...9..Iy.}I....%.xRn5.r.....s..p.0.\........|.S..9Q.......a.|..T.T...O.....D...p.x.[Cj<.o0...S.Z...l.Z+.n.`sP.[....}...0.I0,..A.Lo&.)..g6;..<.:^..d..>&w......GW.I........]{...y..T.Nu.U#..f...Z-..*.N8.[l.~.v+-..u.&.....,$.HK.......XZ4p.uo.zL.P.;.U......v..\.c....Q.'.\W.1.<_.s.f..2G.eT)...i8.O.@.^...E..1.#Gsh.........w.A......%.^-...w.|...:_G.I.......m....VT.nM.....F..`......u_.D.....vnO...*...Fw.lY.`.01..u....i...!.y.e...
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with no line terminators
                      Category:downloaded
                      Size (bytes):28
                      Entropy (8bit):4.378783493486175
                      Encrypted:false
                      SSDEEP:
                      MD5:4C42AB4890733A2B01B1B3269C4855E7
                      SHA1:5B68BFE664DCBC629042EA45C23954EEF1A9F698
                      SHA-256:F69E8FC1414A82F108CFA0725E5211AF1865A9CEA342A5F01E6B2B5ABE47E010
                      SHA-512:0631C6EFD555699CB2273107FE5AF565FEC2234344E2D412C23E4EE43C6D721CB2B058764622E44FD544D840FF64D7C866565E280127C701CAAB0A48C35D4F5C
                      Malicious:false
                      Reputation:unknown
                      URL:https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIgCbyLX8x6oPpSEgUNg6hbPRIFDc5BTHohE45WMhZRyxI=?alt=proto
                      Preview:ChIKBw2DqFs9GgAKBw3OQUx6GgA=
                      File type:PDF document, version 1.5
                      Entropy (8bit):7.992858310792901
                      TrID:
                      • Adobe Portable Document Format (5005/1) 100.00%
                      File name:JGJRA8m29G.pdf
                      File size:477'378 bytes
                      MD5:aa4fdc2f462ca150cd7aea3c77c1bf8d
                      SHA1:b3ccd9a009def98c94a011168073ee3297074a0d
                      SHA256:8b40155d682d653dde378e398c4953d3cc68875fd609e936dfd5411ab8383d30
                      SHA512:c8b4c5f8c23c828135f04e3d77f953a204c18772f555e9f9990c0f9ef88dfbd8e48e97dab13e5372bfdba6bb7f0e68daa28b6f906c166dbc622609950a7f2a47
                      SSDEEP:12288:V6ZJKSELl4ncMYQ6vLdvpe0aPNIVDlAWjpq7G:VDN4ncjvLVpDxVJAWyG
                      TLSH:7CA422D1852F89759989C49ADF201C12EE2D801E4067BD0681524137CABB7EEDBFC9FB
                      File Content Preview:%PDF-1.5.%.....2 0 obj.<<./Type /Catalog./Pages 4 0 R./Lang (en-US)./AcroForm 5 0 R.>>.endobj.9 0 obj.<<./Filter /FlateDecode./Length 8395.>>.stream..x..|].^.q.....u.wP.Y.&..@.$nz...Z@/.^(.......[.'..y8.<3.k['H.......g........,...............8o....3...r.G
                      Icon Hash:62cc8caeb29e8ae0

                      General

                      Header:%PDF-1.5
                      Total Entropy:7.992858
                      Total Bytes:477378
                      Stream Entropy:7.992785
                      Stream Bytes:475137
                      Entropy outside Streams:5.171960
                      Bytes outside Streams:2241
                      Number of EOF found:1
                      Bytes after EOF:
                      NameCount
                      obj16
                      endobj16
                      stream14
                      endstream14
                      xref0
                      trailer0
                      startxref1
                      /Page0
                      /Encrypt0
                      /ObjStm1
                      /URI0
                      /JS0
                      /JavaScript0
                      /AA0
                      /OpenAction0
                      /AcroForm1
                      /JBIG2Decode0
                      /RichMedia0
                      /Launch0
                      /EmbeddedFile0
                      IDDHASHMD5Preview
                      204653590517456515b019ae2ab892a6d07dc26db82228a5a6
                      210a480b1b13316043c5ecebfb35dfa082870ee0f4f2322a7f
                      228484848484000000584ab649fc5e7abfcf371cf024e18681
                      23a9a919a9aa1ab1ad1a8c402bba5cbae8b3d7726e481bd75a
                      2426330b0f0f333333de7f4a5958c30ca10ffcf1d076d935e2