Windows
Analysis Report
Inbreukalert 108853.pdf
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 4268 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\I nbreukaler t 108853.p df" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 6764 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 1396 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 00 --field -trial-han dle=1680,i ,141885856 1264769308 4,44686608 6260869322 6,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 3 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 13 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
x1.i.lencr.org | unknown | unknown | false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
23.47.168.24 | unknown | United States | 16625 | AKAMAI-ASUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1531474 |
Start date and time: | 2024-10-11 09:34:46 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 32s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Inbreukalert 108853.pdf |
Detection: | CLEAN |
Classification: | clean2.winPDF@14/25@2/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 95.100.50.221, 18.207.85.246, 54.144.73.197, 34.193.227.236, 107.22.247.231, 172.64.41.3, 162.159.61.3, 23.3.109.48, 2.19.126.149, 2.19.126.142, 104.76.201.34
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, crl.root-x1.letsencrypt.org.edgekey.net
Time | Type | Description |
---|---|---|
03:36:10 | API Interceptor |
Input | Output |
---|---|
URL: PDF document Model: jbxai | { "brands":["KNIJFF"], "text":"Stichting Envida T.a.v. mevrouw S. Houtappel Postbus 241 6200 AE MAASTRICHT Weesp, 8 oktober 2024 Onze ref. : ERS/W34469BX00/I08853 Geachte mevrouw Houtappel, Jullie ontvangen dit bericht omdat jullie een bewakingsabonnement bij ons hebben. Wij signaleerden het onderstaande merk. Willen jullie alstublieft contact met ons opnemen over deze mogelijkke merkinbreuk? INBREUKALERT Gegevens van uw merk Gevonden merk EVIDA Bewaking type Klasse(n) Woord Benelux 35, 37, 39, 43, 44, 45 Register Klasse(n) Internationaal 42, 44 Depot nr. 1813144 Depotdatum 28 maart 2024 Publicatiedatum 3 oktober 2024 Hoogstwaarschijnlijk inbreuk Mogelijk inbreuk Ter kennisgeving Merkenbureau Knijff & Partners B.V. Leeuwenveldseweg 12 1382 LX Weesp | The Netherlands +31 (0)294 490 900 info@knijff.com www.knijff.com btw/vat NL007 033 199 B01 kvk 320 485 61 iban NL58 ABNA 0564 530 786 bic ABNA AN L2A", "contains_trigger_text":false, "trigger_text":"", "prominent_button_name":"unknown", "text_input_field_labels":"unknown", "pdf_icon_visible":false, "has_visible_captcha":false, "has_urgent_text":false, "has_visible_qrcode":false} |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
23.47.168.24 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | PureLog Stealer, XWorm | Browse | |||
Get hash | malicious | Metasploit | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AKAMAI-ASUS | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.18237584095907 |
Encrypted: | false |
SSDEEP: | 6:gMFIq2P92nKuAl9OmbnIFUt818BZZmw+18BzkwO92nKuAl9OmbjLJ:g9v4HAahFUt818r/+18h5LHAaSJ |
MD5: | DF815D450617DAF3927EA6BCF459C66A |
SHA1: | C355B0FED0ABF2C72BBBA9DBFE8A810A8AE623B2 |
SHA-256: | B7F5A80CE9D88DC245850FE48E1B2B2D0DA825BF07C26D8EB3D2E5D97BBE690A |
SHA-512: | B81905120C041EEE7F90B23E76B7F7AE141E7595EC11ECCF74E578D7FC593404601D9FDE56EB2277C60D57883CA3A9686DEB71049D652633A7CA05AEC2D23A8D |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.18237584095907 |
Encrypted: | false |
SSDEEP: | 6:gMFIq2P92nKuAl9OmbnIFUt818BZZmw+18BzkwO92nKuAl9OmbjLJ:g9v4HAahFUt818r/+18h5LHAaSJ |
MD5: | DF815D450617DAF3927EA6BCF459C66A |
SHA1: | C355B0FED0ABF2C72BBBA9DBFE8A810A8AE623B2 |
SHA-256: | B7F5A80CE9D88DC245850FE48E1B2B2D0DA825BF07C26D8EB3D2E5D97BBE690A |
SHA-512: | B81905120C041EEE7F90B23E76B7F7AE141E7595EC11ECCF74E578D7FC593404601D9FDE56EB2277C60D57883CA3A9686DEB71049D652633A7CA05AEC2D23A8D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.252019854221623 |
Encrypted: | false |
SSDEEP: | 6:g9MujL+q2P92nKuAl9Ombzo2jMGIFUt819JK1Zmw+19zTlLVkwO92nKuAl9Ombzz:gmGyv4HAa8uFUt81Q/+1PR5LHAa8RJ |
MD5: | 4951DB94357D3503E2F36BD5F1067B70 |
SHA1: | 7217F3A1876700E9B27681E143A8297E9F34D59C |
SHA-256: | 91C37C740DC6B75699C925B2A16807A55AB9EB807123BC598F982EF88A51B275 |
SHA-512: | 35EAC14F95FF20B84850802674863BF96BB9580FD0D6C2DA58DD49B973F3AC00AF026CE602AD6E9DAF1A8492F6DB8539B9D89D0F411DE00B200AD9DB9F3FCFE8 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.252019854221623 |
Encrypted: | false |
SSDEEP: | 6:g9MujL+q2P92nKuAl9Ombzo2jMGIFUt819JK1Zmw+19zTlLVkwO92nKuAl9Ombzz:gmGyv4HAa8uFUt81Q/+1PR5LHAa8RJ |
MD5: | 4951DB94357D3503E2F36BD5F1067B70 |
SHA1: | 7217F3A1876700E9B27681E143A8297E9F34D59C |
SHA-256: | 91C37C740DC6B75699C925B2A16807A55AB9EB807123BC598F982EF88A51B275 |
SHA-512: | 35EAC14F95FF20B84850802674863BF96BB9580FD0D6C2DA58DD49B973F3AC00AF026CE602AD6E9DAF1A8492F6DB8539B9D89D0F411DE00B200AD9DB9F3FCFE8 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 508 |
Entropy (8bit): | 5.052567248163298 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqyssBdOg2HHJgcaq3QYiubxnP7E4T3OF+:Y2sRdsDdMHp3QYhbxP7nbI+ |
MD5: | 8846EAFEEC0A14768711C3A6B7661524 |
SHA1: | 0376538DD9A00E3414066943ECB8B97A6EAC15A9 |
SHA-256: | 48A6FF91C90D0DC58534103A50FB729BB75FB4547D99E1DA6B4F308D63D6BFB1 |
SHA-512: | F6C44E0F15CFDE5418FC4E9F343B5FFAE27E95094F31E0A61ADEAEA8A6E69152E442189F6080EDD09AA98839176001D08D6F1115B5DABF9D6A6F227DA78D7198 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\a1acbc5c-db7a-4188-b3e0-c533993ce49a.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 508 |
Entropy (8bit): | 5.052567248163298 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqyssBdOg2HHJgcaq3QYiubxnP7E4T3OF+:Y2sRdsDdMHp3QYhbxP7nbI+ |
MD5: | 8846EAFEEC0A14768711C3A6B7661524 |
SHA1: | 0376538DD9A00E3414066943ECB8B97A6EAC15A9 |
SHA-256: | 48A6FF91C90D0DC58534103A50FB729BB75FB4547D99E1DA6B4F308D63D6BFB1 |
SHA-512: | F6C44E0F15CFDE5418FC4E9F343B5FFAE27E95094F31E0A61ADEAEA8A6E69152E442189F6080EDD09AA98839176001D08D6F1115B5DABF9D6A6F227DA78D7198 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4509 |
Entropy (8bit): | 5.237114327912973 |
Encrypted: | false |
SSDEEP: | 96:QqBpCqGp3Al+NehBmkID2w6bNMhugoKTNY+No/KTNcygLPGLLUruWdjEIW7Z:rBpJGp3AoqBmki25ZEVoKTNY+NoCTNLv |
MD5: | 71B9497D5D595E60A70F1E4E94A1A486 |
SHA1: | 1B5A9D6AB37B5F44606B12EA5739A65D625882E6 |
SHA-256: | 3F22BB6DDB5C481FD093E961F87504F02EC7FAE4C7ADD9FD1478CFCB156613F3 |
SHA-512: | C2DEA5DCB4CC36091B511082CD05A5C8B22D4D1A1EB4E5ED12817DC57A4DFC2BB6D773669E925D92806B0FCD9982AC8E1C00808540320E0A67ED2E3250921ECC |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.248744715022967 |
Encrypted: | false |
SSDEEP: | 6:gqL+q2P92nKuAl9OmbzNMxIFUt81mFgz1Zmw+1NGLVkwO92nKuAl9OmbzNMFLJ:gqyv4HAa8jFUt81mi/+10R5LHAa84J |
MD5: | 4197B0C50B41B1EB7CB383FD222728D0 |
SHA1: | B6FE0CBC8DD0B0300D3F7326CDB5F635983A35C4 |
SHA-256: | 0B8EEE5C4F3A9C4682BE33A7C67A1E6B9D72DB308388E4AA52F5A5B7E371C62D |
SHA-512: | 2230DD4608A05B455D4942A1F0AFE8E972448CF0A46515711CCAEB4DB7C8ADDA8F49699F5567FB465FA5E29BE5DC270DA1ECBC1B5DB5BC70731D9081636E7C65 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.248744715022967 |
Encrypted: | false |
SSDEEP: | 6:gqL+q2P92nKuAl9OmbzNMxIFUt81mFgz1Zmw+1NGLVkwO92nKuAl9OmbzNMFLJ:gqyv4HAa8jFUt81mi/+10R5LHAa84J |
MD5: | 4197B0C50B41B1EB7CB383FD222728D0 |
SHA1: | B6FE0CBC8DD0B0300D3F7326CDB5F635983A35C4 |
SHA-256: | 0B8EEE5C4F3A9C4682BE33A7C67A1E6B9D72DB308388E4AA52F5A5B7E371C62D |
SHA-512: | 2230DD4608A05B455D4942A1F0AFE8E972448CF0A46515711CCAEB4DB7C8ADDA8F49699F5567FB465FA5E29BE5DC270DA1ECBC1B5DB5BC70731D9081636E7C65 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241011073602Z-186.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65110 |
Entropy (8bit): | 1.000876578769695 |
Encrypted: | false |
SSDEEP: | 96:x998qDMXMLJrvMMRB4KfQ3s+MKFMl4MjMhVKTTGavpIfqJto5hkPs2Pm/eS8QE18:n98sB49KTGaRIfvrt2npQE1f8KTA |
MD5: | D283228F68BEB826E6402B3E2AFEC7AE |
SHA1: | 9C3CCFE4918DEE2B3DCFB76C4035F5ABED2D882C |
SHA-256: | EFE9EF8DBB8B555FD54FB884D77E38721D6D22C3CBA3D2F5DD1AE94830C9A6EE |
SHA-512: | 6E49B245820B894737D36093C635035C170E354819203AC36BC17DE9051D8674D846F572FCB3D507BE739DC8E2664D3A14A9F71EC61C6AF27503DFCC47C17B8F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.779094196322516 |
Encrypted: | false |
SSDEEP: | 3:kkFkl26M/tfllXlE/HT8kglzltNNX8RolJuRdxLlGB9lQRYwpDdt:kKv6M/eT8HzlTNMa8RdWBwRd |
MD5: | EE11D9C30A37E3F56175F3EE0543FAC5 |
SHA1: | E365E611D28E48163A03387A01DA4514D511EFEC |
SHA-256: | 06C77E7A32BF02CF515275133B442345621FE04B2F37FCC0197DE0FDA6D35C0F |
SHA-512: | 1AD60E2C7477F17C40FEF90FB25883726B9AC6BB3D1391EA336ADD49BD63EED1AF6FFD3086737343DE82DCAD8BB339112722BE5473A9C87CDA2AD677A02215F0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 227002 |
Entropy (8bit): | 3.392780893644728 |
Encrypted: | false |
SSDEEP: | 1536:WKPC4iyzDtrh1cK3XEivK7VK/3AYvYwgF/rRoL+sn:DPCaJ/3AYvYwglFoL+sn |
MD5: | 87EDBEE38F56C20298F25D5D3D4D1B5C |
SHA1: | 7F904E9615AC3186A87472EF366DD8202855B0B7 |
SHA-256: | A46B56D3ABCC137D1872DDF20EED4BCD7D04518282282ADB32DDCCF70D7FFBA6 |
SHA-512: | BBEBC1FCD5BC9AE042DD5782425BA8C47BF3EAC283B2487FC4E3FF6BF8101306DAB081E5135594165D4DC1AC120FF125AADBC5B3FFE7C646183C04DF77865E0D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2145 |
Entropy (8bit): | 5.068522786432734 |
Encrypted: | false |
SSDEEP: | 24:YFuQ3QJGm27XHZ2LSCt7aZna0TNpnayGZmmuBJvbZW4xCZqu20Z+nZO8ZMCCDxiW:Y7AwmWXZYEtoitbRCwu20wD+JliWxao |
MD5: | 792B4777E5D2ADFD12829915B5B2BDC9 |
SHA1: | 86FBFF6786718A6878F6337DE67F4A479CC6E5BB |
SHA-256: | C7B205E4A7C8C308422164FFE1FDEB123AC0F71A5A0CF0C4873C7D4F550DAC7F |
SHA-512: | 096DEBE4550C81256C4DAFFE322A71A6546637890C47C849ED0AFA21BD00DE4DEB831C0C22BBFD1E0AEDCA63815A9A083F71D6FEAD46447B661EF7F0ABA0F3CF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 0.9840130996586833 |
Encrypted: | false |
SSDEEP: | 24:TLHRx/XYKQvGJF7urs6I1RZKHs/Ds/SpqZ4zJwtNBwtNbRZ6bRZ4vZF:TVl2GL7ms6ggOVpq6zutYtp6Pw7 |
MD5: | 756BF7CCFC3A898373BEF00E8F330608 |
SHA1: | 9201A2DA4180537E72756CDE0874F98DA5FAF747 |
SHA-256: | F01A77269CD8C06D22FFD3A15F9E9A1B45BB54ECF1E31928E377B56E95900CE4 |
SHA-512: | E3740FDBE151DE6A518110E28A2472FDE31F990FE8E3BE69089425825E9C08EB76D61D77DA68489FE46881166CA4F23E50E770070FBC082AFA44CD11C6989557 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.3370517210411974 |
Encrypted: | false |
SSDEEP: | 24:7+tgEAD1RZKHs/Ds/SpqZPzJwtNBwtNbRZ6bRZWf1RZK5qLBx/XYKQvGJF7urs9l:7MFGgOVpqhzutYtp6PMUqll2GL7ms9l |
MD5: | 87CA819294C6A2D44C4DEC859C839E2F |
SHA1: | 522EAF2D5A0FF5E89B6B2F70340B71C7F2915A82 |
SHA-256: | C194A952E412AF750299D575D73FA30DB66D647971BC7B1B550E925F8A4D93A9 |
SHA-512: | 26A1B89EAEE5FA647ADA519BD903ABF16BFC047141880C8E802AC608E13CD2AA20F9B440CFB72246BACBDE4F5F9B5576DC105946C96AB3AEF696E75812C12A04 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5162684137903053 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8SQID:Qw946cPbiOxDlbYnuRKiID |
MD5: | 69BA06AC54862ABC1EB9341CD785DDFE |
SHA1: | 5D746EAEDF2737DB6D075D4A433CA8F836E75232 |
SHA-256: | C2A4A27A5874AC62106E21A5ED9C207BDC1B8CF1C5C4E2B3EF99342D1C58C3F3 |
SHA-512: | 5E657201068DA846BEA3B91C2CAC2500CB82087C9E28AA861F69F6779DF7F6618ECF499A4AD4280DAC590791C9F0FFB87E0C599EAC3DCFF83FC83D9F6325BF80 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-10-11 03-35-59-594.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.376360055978702 |
Encrypted: | false |
SSDEEP: | 384:6b1sdmfenwop+WP21h2RPjRNg7JjO2on6oU6CyuJw1oaNIIu9EMuJuF6MKK9g9JQ:vIn |
MD5: | 1336667A75083BF81E2632FABAA88B67 |
SHA1: | 46E40800B27D95DAED0DBB830E0D0BA85C031D40 |
SHA-256: | F81B7C83E0B979F04D3763B4F88CD05BC8FBB2F441EBFAB75826793B869F75D1 |
SHA-512: | D039D8650CF7B149799D42C7415CBF94D4A0A4BF389B615EF7D1B427BC51727D3441AA37D8C178E7E7E89D69C95666EB14C31B56CDFBD3937E4581A31A69081A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.3782113984848365 |
Encrypted: | false |
SSDEEP: | 384:1MqByEffAXqIf9M7ypHzHoAJdmnLdNRbal8GAsWXCaVkse7V1Oh9GlGTikt6OZZD:FXb |
MD5: | 511A480A5656B8F4C10B562419DF5691 |
SHA1: | 6E9A1067A897D09064EE625465D7ED8350A9576B |
SHA-256: | 535797EA7E132F0DB02D0E987237E8F12E8FFBCAFCEA182A0427B75C715321B2 |
SHA-512: | D3C7FD115212B8EA97E4AD1B5A5D2AAFBD911814832B49FD0233CA4F74419D9D8B432183C57C3D54209438E97C55CA068F6B13BC819DC1397875BF4A04204B1C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.400638284431066 |
Encrypted: | false |
SSDEEP: | 768:GLxxlyVUFcAzWL8VWL1ANSFld5YjMWLvJ8Uy++NSXl3WLd5WLrbhhVClkVMwDGbk:w |
MD5: | 5EA9AB16B7DB8A3A40DEDF21596C5888 |
SHA1: | D6140FC99F713590A14C2D6303C8627277A03B9F |
SHA-256: | CFC8CFE75239F9D084FCC06A178A4BCA9DCE9CC77BA414EC8A4144B8F40F838F |
SHA-512: | 728E31725883A156119F1229998FFE1F81FEC8B90A059C5271CE78B833CDF93182B89E2D177712653210F59098177A89B8947AA3C035AA6A5B7E569D54FD6E05 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLaGZDwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLaGZDwZGk3mlind9i4ufFXpAXkru |
MD5: | 18E3D04537AF72FDBEB3760B2D10C80E |
SHA1: | B313CD0B25E41E5CF0DFB83B33AB3E3C7678D5CC |
SHA-256: | BBEF113A2057EE7EAC911DC960D36D4A62C262DAE5B1379257908228243BD6F4 |
SHA-512: | 2A5B9B0A5DC98151AD2346055DF2F7BFDE62F6069A4A6A9AB3377B644D61AE31609B9FC73BEE4A0E929F84BF30DA4C1CDE628915AC37C7542FD170D12DE41298 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.030700484907539 |
TrID: |
|
File name: | Inbreukalert 108853.pdf |
File size: | 1'736'018 bytes |
MD5: | 8502fcad5d4442b2b5d7a45d4b077674 |
SHA1: | 8a8fd3d77f0d765ce72ff3405fb6ed51c000f8e0 |
SHA256: | 75a5dbf11322e80312741c8b0ba8a5a4f0787d86103e09f45f6aaae379057ced |
SHA512: | 71542bc0be23fca03ecaa30fe783438fcb621e3b633c515bcb33eb10095fa784149d772a87b1fe3a457309243c60bad00f3cea536e4c7acd300f15f3ac1d590a |
SSDEEP: | 24576:hSNOPeT+99KHMkt1dFaBiSNzjB6cSbt1dFaBiPO8tz+Qp1n4:hCT+94skxe9zlSbxeWOoz+Qp14 |
TLSH: | 75859E03CD194B97A51C43FCAE070EB82F0D1A5CE9C62BEB01726E977A656360C5F16E |
File Content Preview: | %PDF-1.4..%......4 0 obj..<</Type /XObject /Subtype /Image /Width 4960 /Height 7015 /ColorSpace /DeviceGray /BitsPerComponent 8 /Decode [0 1] /Interpolate false /Filter /FlateDecode /DecodeParms <</Predictor 12 /Columns 4960 >>.. /Length 68386 >>..stream. |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.4 |
Total Entropy: | 7.030700 |
Total Bytes: | 1736018 |
Stream Entropy: | 7.020694 |
Stream Bytes: | 1726009 |
Entropy outside Streams: | 5.222343 |
Bytes outside Streams: | 10009 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 50 |
endobj | 50 |
stream | 26 |
endstream | 26 |
xref | 1 |
trailer | 1 |
startxref | 1 |
/Page | 2 |
/Encrypt | 0 |
/ObjStm | 0 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
4 | 0000000000000020 | 7c062b4be63880ba14df21e74e5c0fa4 | |
3 | 7070000000000159 | 6756c77997a9aaad7dab8e75b8a9fa11 | |
8 | 6073b1d828262588 | 5e6d0b79039b73c03571ddedaff5441e | |
7 | 1f0f07232b164d33 | cc1a155a2b48796d3fbd404e107699c4 | |
12 | 7072e12028282588 | 4352ebef33df4849a462ee179270edb8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 11, 2024 09:36:10.464848042 CEST | 49814 | 443 | 192.168.2.5 | 23.47.168.24 |
Oct 11, 2024 09:36:10.464878082 CEST | 443 | 49814 | 23.47.168.24 | 192.168.2.5 |
Oct 11, 2024 09:36:10.464941025 CEST | 49814 | 443 | 192.168.2.5 | 23.47.168.24 |
Oct 11, 2024 09:36:10.465478897 CEST | 49814 | 443 | 192.168.2.5 | 23.47.168.24 |
Oct 11, 2024 09:36:10.465495110 CEST | 443 | 49814 | 23.47.168.24 | 192.168.2.5 |
Oct 11, 2024 09:36:11.017419100 CEST | 443 | 49814 | 23.47.168.24 | 192.168.2.5 |
Oct 11, 2024 09:36:11.017710924 CEST | 49814 | 443 | 192.168.2.5 | 23.47.168.24 |
Oct 11, 2024 09:36:11.017745018 CEST | 443 | 49814 | 23.47.168.24 | 192.168.2.5 |
Oct 11, 2024 09:36:11.019195080 CEST | 443 | 49814 | 23.47.168.24 | 192.168.2.5 |
Oct 11, 2024 09:36:11.019260883 CEST | 49814 | 443 | 192.168.2.5 | 23.47.168.24 |
Oct 11, 2024 09:36:11.027120113 CEST | 49814 | 443 | 192.168.2.5 | 23.47.168.24 |
Oct 11, 2024 09:36:11.027203083 CEST | 443 | 49814 | 23.47.168.24 | 192.168.2.5 |
Oct 11, 2024 09:36:11.027316093 CEST | 49814 | 443 | 192.168.2.5 | 23.47.168.24 |
Oct 11, 2024 09:36:11.027329922 CEST | 443 | 49814 | 23.47.168.24 | 192.168.2.5 |
Oct 11, 2024 09:36:11.075011969 CEST | 49814 | 443 | 192.168.2.5 | 23.47.168.24 |
Oct 11, 2024 09:36:11.123310089 CEST | 443 | 49814 | 23.47.168.24 | 192.168.2.5 |
Oct 11, 2024 09:36:11.123415947 CEST | 443 | 49814 | 23.47.168.24 | 192.168.2.5 |
Oct 11, 2024 09:36:11.123490095 CEST | 49814 | 443 | 192.168.2.5 | 23.47.168.24 |
Oct 11, 2024 09:36:11.124054909 CEST | 49814 | 443 | 192.168.2.5 | 23.47.168.24 |
Oct 11, 2024 09:36:11.124073029 CEST | 443 | 49814 | 23.47.168.24 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 11, 2024 09:36:10.032247066 CEST | 53772 | 53 | 192.168.2.5 | 1.1.1.1 |
Oct 11, 2024 09:36:23.591558933 CEST | 61882 | 53 | 192.168.2.5 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 11, 2024 09:36:10.032247066 CEST | 192.168.2.5 | 1.1.1.1 | 0x9eaf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 11, 2024 09:36:23.591558933 CEST | 192.168.2.5 | 1.1.1.1 | 0x37ec | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 11, 2024 09:36:10.042380095 CEST | 1.1.1.1 | 192.168.2.5 | 0x9eaf | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 11, 2024 09:36:24.084239006 CEST | 1.1.1.1 | 192.168.2.5 | 0x37ec | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49814 | 23.47.168.24 | 443 | 1396 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-11 07:36:11 UTC | 475 | OUT | |
2024-10-11 07:36:11 UTC | 198 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 03:35:55 |
Start date: | 11/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff686a00000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 03:35:57 |
Start date: | 11/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6413e0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 03:35:57 |
Start date: | 11/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6413e0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |