Windows
Analysis Report
Adfast Canada Request For Proposal (RFP) ID#9009.pdf
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- Acrobat.exe (PID: 1556 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\A dfast Cana da Request For Propo sal (RFP) ID#9009.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 6400 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6628 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=22 60 --field -trial-han dle=1568,i ,147377177 6366709533 7,13717673 3711641712 74,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - chrome.exe (PID: 7728 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// adfast5663 7.castillo delvalle.c om//@ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7964 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2008 --fi eld-trial- handle=197 6,i,285984 1652507592 07,5809077 7417214708 23,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction /pre fetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7876 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// adfast5663 7.castillo delvalle.c om//@ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7524 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2024 --fi eld-trial- handle=198 4,i,154437 5806932491 156,300430 3556114073 429,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
Phishing |
---|
Source: | LLM: |
Source: | HTTP Parser: |
Source: | Matcher: | ||
Source: | Matcher: |
Source: | Matcher: |
Source: | OCR Text: | ||
Source: | OCR Text: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Memory has grown: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: |
Source: | File created: |
Source: | Key opened: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Persistence and Installation Behavior |
---|
Source: | LLM: | ||
Source: | LLM: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: |
Source: | Process information queried: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 Extra Window Memory Injection | 1 Extra Window Memory Injection | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | Document-PDF.Phishing.Generic |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
a.nel.cloudflare.com | 35.190.80.1 | true | false | unknown | |
clblnc.com | 172.67.211.189 | true | true | unknown | |
code.jquery.com | 151.101.194.137 | true | false | unknown | |
abzturistico.com | 199.223.210.198 | true | false | unknown | |
challenges.cloudflare.com | 104.18.94.41 | true | false | unknown | |
www.google.com | 172.217.16.196 | true | false | unknown | |
x1.i.lencr.org | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
true | unknown | ||
true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.185.78 | unknown | United States | 15169 | GOOGLEUS | false | |
184.28.88.176 | unknown | United States | 16625 | AKAMAI-ASUS | false | |
144.217.123.236 | unknown | Canada | 16276 | OVHFR | false | |
104.18.94.41 | challenges.cloudflare.com | United States | 13335 | CLOUDFLARENETUS | false | |
142.250.185.106 | unknown | United States | 15169 | GOOGLEUS | false | |
162.159.61.3 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
54.144.73.197 | unknown | United States | 14618 | AMAZON-AESUS | false | |
142.250.185.163 | unknown | United States | 15169 | GOOGLEUS | false | |
151.101.194.137 | code.jquery.com | United States | 54113 | FASTLYUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false | |
172.217.16.142 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.186.35 | unknown | United States | 15169 | GOOGLEUS | false | |
172.67.211.189 | clblnc.com | United States | 13335 | CLOUDFLARENETUS | true | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
142.250.185.234 | unknown | United States | 15169 | GOOGLEUS | false | |
104.18.95.41 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
142.250.185.138 | unknown | United States | 15169 | GOOGLEUS | false | |
151.101.2.137 | unknown | United States | 54113 | FASTLYUS | false | |
2.23.197.184 | unknown | European Union | 1273 | CWVodafoneGroupPLCEU | false | |
93.184.221.240 | unknown | European Union | 15133 | EDGECASTUS | false | |
64.233.167.84 | unknown | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
199.223.210.198 | abzturistico.com | United States | 7203 | LEASEWEB-USA-SFO-12US | false | |
172.217.16.196 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1529326 |
Start date and time: | 2024-10-08 21:10:07 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Sample name: | Adfast Canada Request For Proposal (RFP) ID#9009.pdf |
Detection: | MAL |
Classification: | mal68.phis.winPDF@43/67@23/186 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, SgrmBroker.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.90.27, 184.28.88.176
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, fs.microsoft.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: Adfast Canada Request For Proposal (RFP) ID#9009.pdf
Input | Output |
---|---|
URL: PDF document Model: jbxai | { "brand":["Microsoft 365", "ADFAST"], "contains_trigger_text":true, "trigger_text":"This pdf document has been encrypted by Adfast.", "prominent_button_name":"View PDF", "text_input_field_labels":"unknown", "pdf_icon_visible":true, "has_visible_captcha":false, "has_urgent_text":false, "text":"PDF FILE This pdf document has been encrypted by Adfast. View PDF", "has_visible_qrcode":false} |
URL: https://abzturistico.com/yyhu.html Model: jbxai | { "brand":[], "contains_trigger_text":false, "trigger_text":"", "prominent_button_name":"VIEW PDF", "text_input_field_labels":"unknown", "pdf_icon_visible":false, "has_visible_captcha":false, "has_urgent_text":false, "text":"PDF Document Type in rfp to access on Microsoft OneDrive. Enter 'rfp' VIEW PDF", "has_visible_qrcode":false} |
URL: https://abzturistico.com/yyhu.html Model: jbxai | { "phishing_score":5, "brands":"unknown", "legit_domain":"unknown", "classification":"unknown", "reasons":["The brand is marked as 'unknown', and there is no clear indication of a well-known brand associated with the URL.", "The domain 'abzturistico.com' does not immediately suggest any well-known brand or service.", "Without a specific brand association, it is difficult to determine the legitimacy of the domain.", "The URL does not contain any obvious misspellings or suspicious elements, but the lack of brand association is a concern."], "brand_matches":[], "url_match":true, "brand_input":"unknown", "input_fields":"unknown"} |
URL: https://abzturistico.com/yyhu.html Model: jbxai | { "brand":[], "contains_trigger_text":false, "trigger_text":"", "prominent_button_name":"VIEW PDF", "text_input_field_labels":"unknown", "pdf_icon_visible":true, "has_visible_captcha":false, "has_urgent_text":false, "text":"PDF Document Type in rfp to access on Microsoft OneDrive. VIEW PDF", "has_visible_qrcode":false} |
URL: https://clblnc.com/ Model: jbxai | { "brand":["Microsoft", "Cloudflare"], "contains_trigger_text":true, "trigger_text":"Verifying...", "prominent_button_name":"unknown", "text_input_field_labels":"unknown", "pdf_icon_visible":false, "has_visible_captcha":false, "has_urgent_text":false, "text":"Verifying... CLOUDFLARE Privacy Terms Microsoft", "has_visible_qrcode":false} |
URL: https://clblnc.com/ Model: jbxai | { "brand":["Microsoft", "Cloudflare"], "contains_trigger_text":true, "trigger_text":"Verifying...", "prominent_button_name":"unknown", "text_input_field_labels":"unknown", "pdf_icon_visible":false, "has_visible_captcha":false, "has_urgent_text":false, "text":"Verifying... CLOUDFLARE Privacy Terms Microsoft", "has_visible_qrcode":false} |
URL: https://clblnc.com/&redirect=59355266bd7290abadf8b20fd6cb87207c540f21main&uid=f253efe302d32ab264a76e0ce65be769670583eee7b77 Model: jbxai | { "brand":["Microsoft"], "contains_trigger_text":true, "trigger_text":"Email or phone", "prominent_button_name":"Next", "text_input_field_labels":["Email or phone"], "pdf_icon_visible":false, "has_visible_captcha":false, "has_urgent_text":false, "text":"Sign in Email or phone No account? Create one! Can't access your account? Next", "has_visible_qrcode":false} |
URL: https://clblnc.com/&redirect=59355266bd7290abadf8b20fd6cb87207c540f21main&uid=f253efe302d32ab264a76e0ce65be769670583eee7b77 Model: jbxai | { "phishing_score":9, "brands":"Microsoft", "legit_domain":"microsoft.com", "classification":"wellknown", "reasons":["The brand 'Microsoft' is a well-known global technology company.", "The legitimate domain for Microsoft is 'microsoft.com'.", "The provided URL 'clblnc.com' does not match the legitimate domain for Microsoft.", "The URL 'clblnc.com' does not contain any recognizable association with Microsoft.", "The presence of input fields for 'Email or phone' is common in phishing attempts targeting Microsoft accounts.", "The URL 'clblnc.com' is suspicious due to its lack of association with the brand and its unusual structure."], "brand_matches":[false], "url_match":false, "brand_input":"Microsoft", "input_fields":"Email or phone"} |
URL: https://abzturistico.com/yyhu.html Model: jbxai | |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.191720879678061 |
Encrypted: | false |
SSDEEP: | |
MD5: | AC668EB8F72B205D7979F3B33C3CAFE7 |
SHA1: | 8F2BAD34DADB2BB02E24AAB04DAEA5D79CB9B58F |
SHA-256: | FCD2DADB3034622F5158C2C0918E7368D679E34FC186BAEAD8A247C6334053E5 |
SHA-512: | 61E189F393958AA41134AF5BF313AA174DF6A4E4C8E87D9D11BE98CC87E58DE85607727C9684C846E7FC8AF072A82DDE39B7EE726833E259B858BED08747DD6B |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.14886077805209 |
Encrypted: | false |
SSDEEP: | |
MD5: | E584B683D282DD0F15018C2B188D9D27 |
SHA1: | 002FD0531B05B2253763C529BBDE1FCF483D0392 |
SHA-256: | 31D34ABF8B5224F4A64DCD84F2144AEC53D6508E0A7B81C8B11E994D9F7CF56B |
SHA-512: | 64652E80DBC02BFD4B31E44760B0154132E72125E85F7753D52BE90516AB84FE517162634C21C47F0263CDF0FACA12A5FF1151BC60C48A0D1807B3DA5507201B |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\1b210411-0b24-4355-9bf0-8da077454e44.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 403 |
Entropy (8bit): | 4.953858338552356 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4C313FE514B5F4E7E89329630909F8DC |
SHA1: | 916EED77EC8C9DC90C64FF1E5CC9D04D4674EE56 |
SHA-256: | 1EE7C151EF264F91FCDCCB6644F62DC33E27A4E829DAAB748DA1DE4426400873 |
SHA-512: | 1726CAFCBA0121691DFA87A7298E6610BC4C7FD900867FD1B1710811E764918585E56788E08B7CA2CEE001F5DFD110E1BE6F6BBD7C2A7B7E2FC87D3DED210205 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\8eb4e0a6-67dd-4d9e-abc1-30318c185e19.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 403 |
Entropy (8bit): | 4.98490874198158 |
Encrypted: | false |
SSDEEP: | |
MD5: | A5038F0168AFE4583F2F2460434A7B47 |
SHA1: | C5A45E68B7ED724F9590784E2FBF7DED7D972A67 |
SHA-256: | 012820C28E81ADD3EFEBCA2E400B23BD447B41F48CD5AE92372096D2D0FC7501 |
SHA-512: | 32A8FDADBB3B909C37DF5CE061FAAC07C40C8D8E707644C30E0ADC3C6E561F1C2D26A280577F3576D013D777638C95121A3C3FF99C52AA6F5740D9A758FBC7B1 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4C313FE514B5F4E7E89329630909F8DC |
SHA1: | 916EED77EC8C9DC90C64FF1E5CC9D04D4674EE56 |
SHA-256: | 1EE7C151EF264F91FCDCCB6644F62DC33E27A4E829DAAB748DA1DE4426400873 |
SHA-512: | 1726CAFCBA0121691DFA87A7298E6610BC4C7FD900867FD1B1710811E764918585E56788E08B7CA2CEE001F5DFD110E1BE6F6BBD7C2A7B7E2FC87D3DED210205 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF62b672.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4C313FE514B5F4E7E89329630909F8DC |
SHA1: | 916EED77EC8C9DC90C64FF1E5CC9D04D4674EE56 |
SHA-256: | 1EE7C151EF264F91FCDCCB6644F62DC33E27A4E829DAAB748DA1DE4426400873 |
SHA-512: | 1726CAFCBA0121691DFA87A7298E6610BC4C7FD900867FD1B1710811E764918585E56788E08B7CA2CEE001F5DFD110E1BE6F6BBD7C2A7B7E2FC87D3DED210205 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.236860877576163 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9F5F482B88A15F691674668ADD58CF54 |
SHA1: | 8D2C000184C49F6B780F314D5CDCE53D33A627DD |
SHA-256: | 4DFC403D60FCE25CCCF7C62BA1721EB5B2A4D7B4488EF68B1EA14CD3098608A5 |
SHA-512: | A04F4CFEC8DC2D194AC7E5DFC24280C863A41C5EC5CFAB4D3C1C61D752487FFC72B155CB858F745B18A3C151851EA21A96AC3F89AC81FF1CDE9AD68184044C80 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.195626003299622 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5E704F741761919CE323BC42F31DD348 |
SHA1: | 07A6C888C1037056858BCCC9D7D12A56EF25B534 |
SHA-256: | 9F22A9B3FF766422D7C853C9440EF23C4CB40DD91BCBC28D35ED1D089ABC4922 |
SHA-512: | 1DD827D3665315E1DA948D417F89FD74AA3058B32A4E2221358F3285C9268A64DDC0D2102910BA9630E25F451A6BFA5371E70A8ABC90E3A318006DC71122088E |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241008191047Z-165.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71190 |
Entropy (8bit): | 0.3289138993814831 |
Encrypted: | false |
SSDEEP: | |
MD5: | 41A821D9B78B80F051067D6FA19894F7 |
SHA1: | B7365CBA4F6EBFE2C8024415A9C609E49FA340BD |
SHA-256: | 5CD030CF29FC0BDD3FA0D4A9D47DAAB0B0E11532E48EC9FB6D0E5D662F3FBEB2 |
SHA-512: | 1AF9040CBF476EF9CE17509123F2052D552AC6EE06C627FA6754EE4D46CBBECC0A0D4144FF3B3B7E9B7AB376E380ABEDBAAED7599998A017BEC7F80BAA83F8D4 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.291927920232006 |
Encrypted: | false |
SSDEEP: | |
MD5: | A4D5FECEFE05F21D6F81ACF4D9A788CF |
SHA1: | 1A9AC236C80F2A2809F7DE374072E2FCCA5A775C |
SHA-256: | 83BE4623D80FFB402FBDEC4125671DF532845A3828A1B378D99BD243A4FD8FF2 |
SHA-512: | FF106C6B9E1EA4B1F3E3AB01FAEA21BA24A885E63DDF0C36EB0A8C3C89A9430FE676039C076C50D7C46DC4E809F6A7E35A4BFED64D9033FEBD6121AC547AA5E9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16928 |
Entropy (8bit): | 1.2160291275063093 |
Encrypted: | false |
SSDEEP: | |
MD5: | D466C013B0047846848CBC3E944D290A |
SHA1: | C881CE24153581EFC965A7663EA28A67604B8B52 |
SHA-256: | 5D8C8EFFBD09D89FE882604D77DEC61F6EB736EA6DF5BB824CCD75C14AEF11BE |
SHA-512: | D0CCD5E66498875A0F7900DCFC43C2AFA290204ADE42F2117303E90B68A094B0BB33AFBA52D5F6B2152E3598C0641A1F0CD2C7EF1E18F7AAC51F929A54207904 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7895108629891827 |
Encrypted: | false |
SSDEEP: | |
MD5: | 65892CDDDFB362976FE7C27D3B2CB36B |
SHA1: | 712203872A6303A372239B7CE3FA72AD6836F6C3 |
SHA-256: | FB399126ADB108C1DFE866518F63BCDD5DFB7989D370A117454520CEE377F884 |
SHA-512: | 7527973FF5872A7D6E7B98FA0F7914CD6852102291488531D4826036069769407D633A713DE3542650822169CD66F16AF821AABCE41B0D3DB102B5FD18C3D060 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.1440865988908953 |
Encrypted: | false |
SSDEEP: | |
MD5: | 360017D7A24C235A6F4C0136C6C88C89 |
SHA1: | 20CE381DD1606B559DC93F0B35D74605C027AA12 |
SHA-256: | BE344A13F3ABD6DB947DA519D72E99C774ADB3F27F0ADC2567392565C7F6AA90 |
SHA-512: | BC54D3263CF8D027D7B077FD9EBBB6F56BA6DC13AA8E41AD94F3CED66C95F6FCE5328716877EDF351A3AD7DE5FD60C1752C6CA2945BF37A83381E7D90BB99B71 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3789269853519075 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6C2B27F977BE3003A02972B8929A5CF2 |
SHA1: | 758FBB64C74CE73FA5A9D5AB5AECD30D10E1EB1B |
SHA-256: | CBD2F4D21AE408B93849422655D15EBEE7B6AB489E114EA4AA45A1FFC2A3B25E |
SHA-512: | 4731F935374972067370410B6CDD3FE6B6AC2F273C7A096E583562A45817A2EE4BE57315E057ACE124391E5E6D31D5D3C5ACC0378AD30A935BC9F05B769B436F |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.3259909645607975 |
Encrypted: | false |
SSDEEP: | |
MD5: | 71DC59A28FEAD9D1A984C3CEAD559C5B |
SHA1: | C262F46264D74826926028B6ED463B625A02F47B |
SHA-256: | 578AC40334F3F108F35076236EB0E944B5B52CF67082DD66EAC8A8CF3FE160AA |
SHA-512: | 910CE63815314CCCDF3EA74CE657ADC8D759AEA9A8D5E2771430EFC28753B37B35D504CC4C59EF95A2D01507C432D030D928BA3FB9A8F01611351BB3CC04DF55 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.3034632137644255 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5A8069EDC4C2F767F570E9E766A7FEF3 |
SHA1: | 5E95F3D41D92E568E8B2CEFD98A09465BDC5689F |
SHA-256: | 03AE45D636795026D1655836F9DF51BD34874A697095D0B075E71A9A5AFF6971 |
SHA-512: | D52A6F281D8D3C39798E23275073BB51A48A8492D1A4F0A00CA8284A1EEC2BE226F5567B73FAC109A90EAA8BEE0EB971E0CBF823CA63328A3293DF0CC3C47B5C |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.367853265287104 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5E6574C92F63E36194B7A3D5C41F6248 |
SHA1: | 580FFA252DDC9887CAF9E85739059B81225BA7C5 |
SHA-256: | 2D22547AF587D952AB818A22212B4BC4432AFAA6B6A919D3030D2B672C4EBA56 |
SHA-512: | 01F44071BDB1EB375E03E2B99B4D6051A27BEB5E0BD798A5A4548AD0F02DC9F4A712CCEF118DE65561EA305E6718A8221195F8AD06A1E01E3C78CE9990F93D9E |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1083 |
Entropy (8bit): | 5.686627990048107 |
Encrypted: | false |
SSDEEP: | |
MD5: | 1C0C821704195B71D94AF69DB557ECB1 |
SHA1: | D6E6476B7C5280BAF1DD8F0D80C1643CAE805B4F |
SHA-256: | EEA947625B75DF92DD474B5211F93376D94E9E69DFA55802B1934DC8B07B0E89 |
SHA-512: | 8F0F121BF533FDB054E16987D85E931ED884E56109AC1E18EB78C63545A58F55F328EDF2F5A8C68411AA3381DF6974EBD94A7ED1D9F91E47E28F22B157C4D4A1 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1050 |
Entropy (8bit): | 5.659664142776138 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4B54DA8107B2F522AB02AE455F440324 |
SHA1: | 43F454CB27F1857C7F88B626A2A9B999FB73A0E0 |
SHA-256: | 350220B7394996B5429E802FF5CE0E1A5563CDC81ABC12AF1908B301AEEA4896 |
SHA-512: | 57F1B90F9CCB51899366BDB47335248E39C7AF7331E5477F1F240ED158959AB5E6A8B17F1D20766A46295F9DB155D86106601308CC9ACB297838F119B1233D14 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.319473969144768 |
Encrypted: | false |
SSDEEP: | |
MD5: | FE9DEAD51E8BF338477C852FF72B6AC0 |
SHA1: | 86658CDAF580CA25FEDCF28825A1479F95C73EA2 |
SHA-256: | 08D3A035FCB27711DE9BD0C90F09A1CB31D1B623EB1132DB5DD24596FCE4F67B |
SHA-512: | 2A0810C295AC74189AB7BBA3EF5624CF1185F6086F1355970B5F4D4F8ABB56181C0A7CB5B6384304D5449EA4DF54B1E6B5E42C1C39A8AB48C2BF80D6A1C2D4A0 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1062 |
Entropy (8bit): | 5.694942911861403 |
Encrypted: | false |
SSDEEP: | |
MD5: | 67160B4AF43851E216181355D7028D08 |
SHA1: | A839BB554C1E9FBE4D8BBE27B6B7547BA9D7ED4D |
SHA-256: | 3C6E57089F9D087A5AECAEE74C6786AB63B5642321C14E437547C5BC9C899114 |
SHA-512: | 94D890B6E063443247760E5F4B5ADFE6E477C8CB1F03AFF6ACC9C61804ADE0B2650BBDED067ABFAE74E3CEF5B7389059E6C38F93340F9EAB0096B3696B4468BA |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1164 |
Entropy (8bit): | 5.704505938964451 |
Encrypted: | false |
SSDEEP: | |
MD5: | 30312A2F249330E8A3C38A19DBB776DC |
SHA1: | 38D5033A2C9F3A264EE869BF11F1027838ED48A3 |
SHA-256: | DECF483218EDA9695EA846C3EE8885F2BA0C3FB525D448FDB53780466BF31226 |
SHA-512: | A0585CF72206544EAE3DD6AAE9B53B5E5877E1CFFF95C9720B488D50131C3CD20748F8286F27A85671F01472D39FA46BA052F033A6C8E3DE89C9D7F82C59AE9C |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.324803203751188 |
Encrypted: | false |
SSDEEP: | |
MD5: | 78EE815068DCCE091742CD09C6F6CC62 |
SHA1: | 5A907CD5753459AF7AE5AAE364EC1C83825375AC |
SHA-256: | DEB159CB72DC84D389A917DB00239A3C7B0B37D8FFA0F4FFCB7B6CE062FD3B7B |
SHA-512: | E64049B04E9F6EB2C36085A2BE57F5B82C7CD977DCB4E92FFB6F38A50E62F15388C82FB4B86B42CE174740AB5D994E64C65FF8D49DCB58D9ACF8E99BE5D1419E |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1395 |
Entropy (8bit): | 5.778306824598848 |
Encrypted: | false |
SSDEEP: | |
MD5: | D1494AB893EDF3BE23C6C3865AEE2DF5 |
SHA1: | C51DC33B7FBDACC05E06DEB9E62BBE68883B8EC0 |
SHA-256: | 8AF7D9FFABB9B4877D58E326174654A9C2E13D404C53727A3AD82B3B4CD4ED2C |
SHA-512: | 27BDD2C95F6280E2240F14F01D355E805A0FA3777B0409288D3F1DE8A8E2A25AC36137D5EDE526B25E3FD034BD88989A93E5F0E6F28AB9671FE9E55F4C99E350 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.308179832670747 |
Encrypted: | false |
SSDEEP: | |
MD5: | EC430CF953A2348C29E739B9C364831C |
SHA1: | 58CEF076E7D3B4853CEEFDF017FFC397E5AC1FCC |
SHA-256: | 885583B62375534E66DEE362405440746F44FE94CFBEFEBDDDC5D37F6537B40D |
SHA-512: | FCD1D5A2AC7075BBAC62B896116908E132FFEEA3D66EA88231D4CFA08B87FB38E755B1A95E5E0B874D69375C60BF37A2DEC0AAB46C0E1351E24A7A1620D5A28B |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.311254716273707 |
Encrypted: | false |
SSDEEP: | |
MD5: | AB961D61993DC7D1810CDC2CDE26F124 |
SHA1: | 2E18698C95D951761D9062A29A543133CC9C6BB5 |
SHA-256: | F64F099D40966334AE43D31E61AB603F3B502F6A1C2299CC5FECF8EDF52FD494 |
SHA-512: | DC01CDE2255A25E94BDB89494353CF9410EEDD949E630EDFFFB7F11E9874985B61A770C0CB3BE37FA1928361523487BDA98F18BE8C44A6A12B8B80240DD3FA99 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1082 |
Entropy (8bit): | 5.69118165241927 |
Encrypted: | false |
SSDEEP: | |
MD5: | 81E8C8F896E9B7FA6A951044F2140F3C |
SHA1: | F34E2CA86E3700F1D836F7F1EE2EEB1CFAEFC975 |
SHA-256: | E56A0B95203A7853A8407BCAF7A988008EC95F88E4C7FA0C3AE654D4CBE7C74D |
SHA-512: | 72473B2EC9F3CF96A2372B9BD532FDE920FC1C74609D53B8A3F9413CFC63D1C670355287B15B2F08932330A5EEEA1FA0EE12019411EE6523E4287E3F98D76D8B |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.288347513561579 |
Encrypted: | false |
SSDEEP: | |
MD5: | 886FF5B832D9C3093FB014CAD2782EF5 |
SHA1: | 2E1CC40EDF49B43D8CBD6B9E3E3B2EC7B6B332DD |
SHA-256: | 6D7F7285159F24A61A4726ED4EE570BBB7772CEC709504F920734B4FEDF55E74 |
SHA-512: | 53E6C67C8B707F95BE7FBC5B61AA168C32BABEA453AF79FE28726823EA54DDDA6C9B9F7AD23D3D879E41813D2C77D06EAF5F121F0A7AAD343AE3CD9D5EA3B48C |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 782 |
Entropy (8bit): | 5.3735618738769695 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5CC1980371CAAACAFFDD7BC83817B769 |
SHA1: | 405C01B9578BDF4950FAEE666A8C768AC5FC7AD6 |
SHA-256: | EB482DA361B6FA2DFE99A118C8B96DFAF910CFDC15F42487D442A3E65B8DE5D0 |
SHA-512: | 9DB9BAF35F9BCB458620269567E8057B8DD6F39FDFF6F8819F7FB44CDB3127DD1A78B6D83ED273E4E674C3735D83E1CA0C7092962A7E83AF2EC66B6257687443 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2818 |
Entropy (8bit): | 5.1342926113928735 |
Encrypted: | false |
SSDEEP: | |
MD5: | 84950F80D9129F3D5BF43A7C9FC6F7F4 |
SHA1: | 6634F5A7AED67FFE63A40E8A238D737D08DDEB5C |
SHA-256: | 049B3F1A46986375AE9D31A81774AEB1BFA788332BAF61F68354D0212A9A3E62 |
SHA-512: | 08E2893523DCC2B1F3F2A99B3567FD004F6CA155DD08D2835FC338ADD2BA3C8ED793B46EF40B7DD567B51FF2111EDB190C76F053DE391CDD7E01CE7B995CE4A8 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 0.9882775623608001 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9420D493D3FD5E39A6CFACE75F025B7E |
SHA1: | 654EF11B0D9F507C768229756891132FB827B277 |
SHA-256: | ABAB89535DE7806EB7A34C234B461CAA72D9EC1F88B335D91E4455CEDC6863EA |
SHA-512: | 2C37A0A7B9DB10B6B91DE292B06C3D8F85EF7372E8263CF7B88D97440DDCEE26F537EF23BF14E7ED27C55954C8B6F97EC11031082991B90A8618A8A070C4F856 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.3434285702082789 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3A2B4CA817E48612E96748FAD57243B5 |
SHA1: | 8324FE5F06C01574A68E3C5EFB5CCE2370F97DE1 |
SHA-256: | C000116C86F404D0A63A7ADF365D84D6928B258AD4AF85C50A62A313E3F429A6 |
SHA-512: | 7C1D2E758D0224F8AC07239C14DC1672CF250B88D0FDB05E354538490E3553F7A7412ECEA82B1BC6C267CE69781AF996AF376FC1C021F4DA85AB7A3496D19A0B |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5097251598291805 |
Encrypted: | false |
SSDEEP: | |
MD5: | 877FAB3FAF6CFF4211A6C207D8966E41 |
SHA1: | 2C2A63FA69A493B59DF06163EA2CD0EED9E57694 |
SHA-256: | E5FB61F8BF5D17EBA0E1888ABD199E345324DB6B992630606CE4E4139E4E2460 |
SHA-512: | 744F68D3BCF76648FC445FB34BC3605457F9DD51D07B33E9DB00CB389A80704D3373E684D7C2B62E1EC5EB2A23D52E96C9D5E7DEBD4D5F9CB946B5A869E55F4A |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-10-08 15-10-45-167.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.353642815103214 |
Encrypted: | false |
SSDEEP: | |
MD5: | 91F06491552FC977E9E8AF47786EE7C1 |
SHA1: | 8FEB27904897FFCC2BE1A985D479D7F75F11CEFC |
SHA-256: | 06582F9F48220653B0CB355A53A9B145DA049C536D00095C57FCB3E941BA90BB |
SHA-512: | A63E6E0D25B88EBB6602885AB8E91167D37267B24516A11F7492F48876D3DDCAE44FFC386E146F3CF6EB4FA6AF251602143F254687B17FCFE6F00783095C5082 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.4157777367596305 |
Encrypted: | false |
SSDEEP: | |
MD5: | 65707D39B5D914FE82EE1AEC72D5F293 |
SHA1: | 4239B660CB421C1AC8FBA5A7A284828C55042BA0 |
SHA-256: | 419D78A2BBE83E6B9A9DD153018C2D5A309D05B917B16DEDDD266548A89E86AC |
SHA-512: | 566B676B201E63F4E2F9E0757CA06ED0B8649176483FC1BC57EC806E933A5E03B9A4C6BF31CC1A68B5EA10F83A4226B2B0F695022E43A15DE89577F235C0D9FE |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8B9FA2EC5118087D19CFDB20DA7C4C26 |
SHA1: | E32D6A1829B18717EF1455B73E88D36E0410EF93 |
SHA-256: | 4782624EA3A4B3C6EB782689208148B636365AA8E5DAF00814FA9AB722259CBD |
SHA-512: | 662F8664CC3F4E8356D5F5794074642DB65565D40AC9FEA323E16E84EBD4F961701460A1310CC863D1AB38849E84E2142382F5DB88A0E53F97FF66248230F7B9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | |
MD5: | A8E5C37206C98D1B655FF994A420FFB6 |
SHA1: | 827237782AB5971EC205C3BCECCC7950BE9F84C3 |
SHA-256: | F1F755059AF7C2CBC36920337941AEFB18FBDB3CD14D3239CBBBCF0CB8F208EA |
SHA-512: | 12DE33EB7624458AEC44D83D4E2C09E626F8E54E177FC0C26EEBA232935F34FAAAEB71FBB025EB7C53BEA9933C46ADCE759C32516D1B80C03B6734C61D61CEB2 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9874483631810795 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4EF97E145CD670F4943F057A76195BCB |
SHA1: | C48978B5D212CC2DBE6C167709D8A9EB014ABF6A |
SHA-256: | DC1ED15CFCBEE3FBA62D2E3D49A39061AB44711E1976461A3A1D4855D9032364 |
SHA-512: | 0B53249A480C8CF564B328DD6F2BDD336A5BF582687CA409B39DF83998497FA55A901AC8BB68EB9D6454714350B4CFDFC406F9BFF51F73191A4F10FA4CF33EA4 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.004610022977072 |
Encrypted: | false |
SSDEEP: | |
MD5: | FC9D470D3968745DD4D15B3152269C45 |
SHA1: | 7AB996242EF1CDC5E9A2443DFBDA192F3DD8EA1D |
SHA-256: | 5E99D5E76DB56E8C54C88BB2B0B676A2247154409018506D7604FE05A3D77F83 |
SHA-512: | E7C5349CDFC5DE333A2B4D355CE7886743047143886D998921AC0EF1505FE7775A01F53AADB9F801C779876911FA1965F1B295FADC069E194622C47FDCE659ED |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.01159632050234 |
Encrypted: | false |
SSDEEP: | |
MD5: | B3C62F0F0ACD54BD1C69F1168FFAFEF2 |
SHA1: | 278CF1A90DFD3F97128D55727457D12BF5837E3A |
SHA-256: | 28260F5892922F41880145BA16397B07A85F3CE85B48550F84D02B8B2CB43AC8 |
SHA-512: | B04DF95137C579C5670981E853B3CCA17E9EAD2562D20804084C6D0E007B1B66D0A75C9CDFECBAC6EF60C0ADEABA918837E340BB6DDD9A04ED4549E192B37375 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.0003891094361155 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4FA3714910EA23E1C00C2B017391510B |
SHA1: | 4FC5E93CEE709A70EF3CA65C2105504C88D1445C |
SHA-256: | 39EF7F87C9F201EE32B0959D73C2861FCCEB6D4C7594A847DAFDDCDE5EE48A2F |
SHA-512: | 7910974F2044882DD633612999B5DFFFB7FA6713BE74325E95EB6C75649439D2F4EC3729478B4FDABD549ACE8E427725F9A7C9963BD7B37079FC3E9DD67464A9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9930190349044943 |
Encrypted: | false |
SSDEEP: | |
MD5: | FB63CD17DC240663488095EDDD2B2259 |
SHA1: | D4862AD0940A00DCADB3B45FB18070B07CDE549E |
SHA-256: | D7A29ECA7C9D4DAE887711D303DDD4410D4E0801E6AD0AF96CB7FC6686C8D377 |
SHA-512: | 75EEF16738E5E50B709A06FBFAE149A86943FCE804BE9321036778F47A9B3D074FB2C6827BFDE13D3E3CC3A0E3CB3F26DF5EA014B40F6EE5616068CE925F58EB |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.001719982361553 |
Encrypted: | false |
SSDEEP: | |
MD5: | A88E70324219D728DFAEC951034412A6 |
SHA1: | 7B52F39BF67F356F5DCCBBC649FCA182AFE19804 |
SHA-256: | A7B690025F35CB0AD4949F6C001CBB8BD39417D10DEE200DD47BFF50565CC180 |
SHA-512: | BA39D9F433697AE049A330E0B4BC39AF7ECDA477F40F6AD6C57A9243B9C22DA627E6C8361E9B79FACCB65F27A2F1735A5CF3F367D5F4BF7D10BB0DB0E0987313 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4210 |
Entropy (8bit): | 5.364580472613482 |
Encrypted: | false |
SSDEEP: | |
MD5: | 59087D72EEDCB7650C9D5D6088440DD3 |
SHA1: | 97B607FCE11F640E5764699038E50A76EB98944B |
SHA-256: | E0E3FB0FE5CA541950CF8DD213FBE9E8957A3DB0010B515AD01ADFF6CA908A3E |
SHA-512: | 4F213391C01CFB017AB290007F3C7E66DB9B2A7A1EA4B4843DD52B0D7E5B1A5C04896BF1856806964F5A49C38A66403A8CDFE2C8C3EAF82C8318012F444DCD3F |
Malicious: | false |
Reputation: | unknown |
URL: | https://clblnc.com/captcha/style.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5342 |
Entropy (8bit): | 5.443168458526043 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6EEB5219917F8E272ACA4C7B16793524 |
SHA1: | AE3D417DF559755CC91D7E6D471D31403B69505E |
SHA-256: | 8B4ED31D3D0E61FF3FDE86672A42788F89F354EDB841F320C5A58EF46886166D |
SHA-512: | EC8ACE3604C92FAB20AEF011CCCB2BB26E4F810CE07EC7C903A3549A4B9C5F1F076B654C14DD5B00F55E0B6727C1ED660C90F5F95303764DA18F1A2E6C516531 |
Malicious: | false |
Reputation: | unknown |
URL: | https://clblnc.com/&redirect=59355266bd7290abadf8b20fd6cb87207c540f21main&uid=f253efe302d32ab264a76e0ce65be769670583eee7b77 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 105456 |
Entropy (8bit): | 5.227044897009775 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4C674D8D4294C4A6B763AA1FC836827C |
SHA1: | 88DEC91B36CAD6555FB73B9ED28D6FDC7A944467 |
SHA-256: | 99855F2433E80A925CE4CABD975E2DD7A9FE01FAB8E164B26F67010FF5769EC0 |
SHA-512: | 80B73385D21512B2FD10690F08EE99B6FD2D1123920ABACF7A864841F07F817EE1BCC5C466ACC27209A094E31D334E4532AE7EFE7F2F7D7427E67CC567F20733 |
Malicious: | false |
Reputation: | unknown |
URL: | https://clblnc.com/css_/yyCmFY0CoOT1Qmc |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 89501 |
Entropy (8bit): | 5.289893677458563 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8FB8FEE4FCC3CC86FF6C724154C49C42 |
SHA1: | B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4 |
SHA-256: | FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E |
SHA-512: | F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 47460 |
Entropy (8bit): | 5.397735966179774 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5D332FD1AE9FEB79A10425DFC3F84FE4 |
SHA1: | C7D7F9D2BF5EE08E242765803CDD3A223FE1CBFC |
SHA-256: | 2EA786910282DF7AE154A0011375CD1254ADBD8EF0E75EB62177ADA67DAF9611 |
SHA-512: | 01CDAC8103290B0FC1BF9BE8EE3923BFA6B8AD7778FF6B4716E421D6BBB3382240D9316B9994D6F4EA87E67DA9791EB8E3E2A1AAF81DBD749B3C8D7778E15F20 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.875 |
Encrypted: | false |
SSDEEP: | |
MD5: | 344EB8D19F5C0A3435EF32FD9601F1FB |
SHA1: | E082EB1D89D91CC1A25A1D510268E576109DA07E |
SHA-256: | B44289B54959639FCA6A742F7CC2E2A5AF9C6E7B73C1B3E25227CA9790F3A587 |
SHA-512: | EB9F1CD4A566192160371F4B182EE00180F6912333FFB79C537BD80635A6AFE6379FBE7BB74043D635BA65C9F4F956D9E97E516E24E516F2591192A36F866EAE |
Malicious: | false |
Reputation: | unknown |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAkMdlBwJnQ3HxIFDc5BTHo=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1864 |
Entropy (8bit): | 5.222032823730197 |
Encrypted: | false |
SSDEEP: | |
MD5: | BC3D32A696895F78C19DF6C717586A5D |
SHA1: | 9191CB156A30A3ED79C44C0A16C95159E8FF689D |
SHA-256: | 0E88B6FCBB8591EDFD28184FA70A04B6DD3AF8A14367C628EDD7CABA32E58C68 |
SHA-512: | 8D4F38907F3423A86D90575772B292680F7970527D2090FC005F9B096CC81D3F279D59AD76EAFCA30C3D4BBAF2276BBAA753E2A46A149424CF6F1C319DED5A64 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3651 |
Entropy (8bit): | 4.094801914706141 |
Encrypted: | false |
SSDEEP: | |
MD5: | EE5C8D9FB6248C938FD0DC19370E90BD |
SHA1: | D01A22720918B781338B5BBF9202B241A5F99EE4 |
SHA-256: | 04D29248EE3A13A074518C93A18D6EFC491BF1F298F9B87FC989A6AE4B9FAD7A |
SHA-512: | C77215B729D0E60C97F075998E88775CD0F813B4D094DC2FDD13E5711D16F4E5993D4521D0FBD5BF7150B0DBE253D88B1B1FF60901F053113C5D7C1919852D58 |
Malicious: | false |
Reputation: | unknown |
URL: | https://clblnc.com/logo_/ca2698095ba60d59decb3693fe745c92670583f3175cf |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 61 |
Entropy (8bit): | 4.035372245524404 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7EA46794981D2C0910AB95D919CAD764 |
SHA1: | 33ACA0554324D6955E8F591DC21965D388026860 |
SHA-256: | F2F8CA5D9ABC7499284D35D050FCC29E9AF92565F50C2F4ED589A9EDE9C49900 |
SHA-512: | 3899CB5E55CBAE18D4BCACA52A11E5FAB4EF8C83AD9D2607D82F6A71FDBF18681B6637DCC8D69E5742F4A44A8A875031C24CB0785206487F2E95B1D282F6C0D6 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 85578 |
Entropy (8bit): | 5.366055229017455 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2F6B11A7E914718E0290410E85366FE9 |
SHA1: | 69BB69E25CA7D5EF0935317584E6153F3FD9A88C |
SHA-256: | 05B85D96F41FFF14D8F608DAD03AB71E2C1017C2DA0914D7C59291BAD7A54F8E |
SHA-512: | 0D40BCCAA59FEDECF7243D63B33C42592541D0330FEFC78EC81A4C6B9689922D5B211011CA4BE23AE22621CCE4C658F52A1552C92D7AC3615241EB640F8514DB |
Malicious: | false |
Reputation: | unknown |
URL: | https://clblnc.com/js___/670583ef4a63d-ba2bb57d59945e9b24269d32f81e5b5b |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 17174 |
Entropy (8bit): | 2.9129715116732746 |
Encrypted: | false |
SSDEEP: | |
MD5: | 12E3DAC858061D088023B2BD48E2FA96 |
SHA1: | E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5 |
SHA-256: | 90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21 |
SHA-512: | C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1592 |
Entropy (8bit): | 4.205005284721148 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4E48046CE74F4B89D45037C90576BFAC |
SHA1: | 4A41B3B51ED787F7B33294202DA72220C7CD2C32 |
SHA-256: | 8E6DB1634F1812D42516778FC890010AA57F3E39914FB4803DF2C38ABBF56D93 |
SHA-512: | B2BBA2A68EDAA1A08CFA31ED058AFB5E6A3150AABB9A78DB9F5CCC2364186D44A015986A57707B57E2CC855FA7DA57861AD19FC4E7006C2C239C98063FE903CF |
Malicious: | false |
Reputation: | unknown |
URL: | https://clblnc.com/sig/ca2698095ba60d59decb3693fe745c92670583f317701 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 61 |
Entropy (8bit): | 3.990210155325004 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9246CCA8FC3C00F50035F28E9F6B7F7D |
SHA1: | 3AA538440F70873B574F40CD793060F53EC17A5D |
SHA-256: | C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84 |
SHA-512: | A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6829 |
Entropy (8bit): | 5.314145616554395 |
Encrypted: | false |
SSDEEP: | |
MD5: | CE202E987F73676DDC8E7042790EE414 |
SHA1: | 66F59F67CDFCB3C4F6883C6176163489E450CA44 |
SHA-256: | C081039D9377505091C01E7A83D1D565DFF013E703B66A60AD4E41F9D678F0F3 |
SHA-512: | 456A5B065880D2EF5A92C49F5C52AE2830E8EDC367AA590CF1756B0BB32BE201EA25A754231D9089DDA9A5944A4FBC6796FF57AD98A4EDC981E59C83DB41D043 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 315 |
Entropy (8bit): | 5.0572271090563765 |
Encrypted: | false |
SSDEEP: | |
MD5: | A34AC19F4AFAE63ADC5D2F7BC970C07F |
SHA1: | A82190FC530C265AA40A045C21770D967F4767B8 |
SHA-256: | D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3 |
SHA-512: | 42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765 |
Malicious: | false |
Reputation: | unknown |
URL: | https://abzturistico.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 51039 |
Entropy (8bit): | 5.247253437401007 |
Encrypted: | false |
SSDEEP: | |
MD5: | 67176C242E1BDC20603C878DEE836DF3 |
SHA1: | 27A71B00383D61EF3C489326B3564D698FC1227C |
SHA-256: | 56C12A125B021D21A69E61D7190CEFA168D6C28CE715265CEA1B3B0112D169C4 |
SHA-512: | 9FA75814E1B9F7DB38FE61A503A13E60B82D83DB8F4CE30351BD08A6B48C0D854BAF472D891AF23C443C8293380C2325C7B3361B708AF9971AA0EA09A25CDD0A |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 37250 |
Entropy (8bit): | 5.061887240240996 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4E012FC5E7C86EED50BEB75EE8394A1D |
SHA1: | E3FC3728D52A192BB7977709566A468E26E94406 |
SHA-256: | 67A65D1424664E7ADF273810D3CE3D772D169AEB8F096B586DC52386CF8379C6 |
SHA-512: | FC30B39C129112A8597D5523A2224736129B60AC13676F46B6E0AE5CE0323898CBA65DC845CD8BC58D2FAFE3D12D87C8C5932DA339AEC6A518A06B6CF3AC939A |
Malicious: | false |
Reputation: | unknown |
URL: | https://abzturistico.com/yyhu.html |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.875 |
Encrypted: | false |
SSDEEP: | |
MD5: | 011B17B116126E6E0C4A9B0DE9145805 |
SHA1: | DF63A6EB731FFCE96F79802EFF6D53D00CDA42BC |
SHA-256: | 3418E6E704387A99F1611EB7BB883328A438BA600971E6D692E8BEA60F10B179 |
SHA-512: | BB432E96AF588E0B19CBD8BC228C87989FE578167FD1F3831C7E50D2D86DE11016FB93679FEF189B39085E9151EB9A6EB2986155C65DD0FE95EC85454D32AE7D |
Malicious: | false |
Reputation: | unknown |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAlV0WNb5jCtfRIFDdFbUVI=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3202 |
Entropy (8bit): | 4.236796532981122 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7D2B8F25545A2894E2721E9FE528E34C |
SHA1: | D0DAE76F4BF5C04ACD5FCDF1BCB12908099E328C |
SHA-256: | 797BDA35D13E5130FE5A14E0069C31B46EC1AF6EA47F2D300309803BB4D2608C |
SHA-512: | FE1F84AF0BA1100B2A90EE6FBFBD3763EF34D1A3BF045345538302ECE7D37EAADC9A9CD0E09C2030E62B13A55E118A2417B27F14336C271758BFB3E256906385 |
Malicious: | false |
Reputation: | unknown |
URL: | https://clblnc.com/captcha/logo.svg |
Preview: |
File type: | |
Entropy (8bit): | 6.967505611885174 |
TrID: |
|
File name: | Adfast Canada Request For Proposal (RFP) ID#9009.pdf |
File size: | 14'248 bytes |
MD5: | 62956b2d378f56db703e6ebe07d96548 |
SHA1: | 82f9f6536856bc834d35038174c408b5ad527347 |
SHA256: | aa86d5b516c6c2e27f93503f96ed499a598bbeb89864eec92e1461bdc46fb8e4 |
SHA512: | c0872a70dbf030e342663747f4a5acb9b79614f29cf8df733bb7a9b566360bad6a45efa4f7b8594bf99a043de3bd1a38040cd31d5f6e2c2496a0b0db64541e65 |
SSDEEP: | 384:11FzLRJHaPcfoZ5R43/kl26v4OjUTshUR:/FzN4UfoZ5RU/EgOjUQh8 |
TLSH: | 73526B580D0ED67BCD8E4D375C29721D619380D19A4B09753D1DCAFE2F0CA096D89EF6 |
File Content Preview: | %PDF-2.0.%.....6 0 obj<</Linearized 1/L 14248/O 11/E 10899/N 1/T 13955/H [ 923 300]>>.endobj. .7 0 obj<</Root 8 0 R/Info 4 0 R/ID[<D566 |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-2.0 |
Total Entropy: | 6.967506 |
Total Bytes: | 14248 |
Stream Entropy: | 7.116576 |
Stream Bytes: | 11913 |
Entropy outside Streams: | 4.776044 |
Bytes outside Streams: | 2335 |
Number of EOF found: | 2 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 14 |
endobj | 14 |
stream | 11 |
endstream | 11 |
xref | 0 |
trailer | 0 |
startxref | 2 |
/Page | 1 |
/Encrypt | 0 |
/ObjStm | 3 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 1 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
12 | c004c0f1c5c02040 | 04ee78a00855611ef296e28d75c5cb8d | |
13 | 0045006d2b0a2000 | 2e57a745b0a86fbcfcf5cbcdf5ad6769 |