Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
AlisonMarshall.pdf

Overview

General Information

Sample name:AlisonMarshall.pdf
Analysis ID:1541311
MD5:0daf716d2a8903b2d4ea1d979fd8b496
SHA1:cd700bc3ee2c28c20ec178db9c6fa49d6083175d
SHA256:8938dbda5acf5d8870d745181731a016fe8fbafa881ea572f3a2b44ec3fd3992
Infos:

Detection

Score:2
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

IP address seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Uses a known web browser user agent for HTTP communication

Classification

  • System is w10x64
  • Acrobat.exe (PID: 2520 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\AlisonMarshall.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C)
    • AcroCEF.exe (PID: 5764 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
      • AcroCEF.exe (PID: 2256 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2076 --field-trial-handle=1364,i,7330972416840462097,15245140379851579721,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: global trafficDNS query: name: x1.i.lencr.org
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 96.7.168.138:443 -> 192.168.2.7:49734
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 96.7.168.138:443 -> 192.168.2.7:49734
Source: global trafficTCP traffic: 96.7.168.138:443 -> 192.168.2.7:49734
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 96.7.168.138:443 -> 192.168.2.7:49734
Source: global trafficTCP traffic: 96.7.168.138:443 -> 192.168.2.7:49734
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 96.7.168.138:443 -> 192.168.2.7:49734
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 96.7.168.138:443 -> 192.168.2.7:49734
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 96.7.168.138:443 -> 192.168.2.7:49734
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 96.7.168.138:443 -> 192.168.2.7:49734
Source: global trafficTCP traffic: 96.7.168.138:443 -> 192.168.2.7:49734
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: global trafficTCP traffic: 192.168.2.7:49734 -> 96.7.168.138:443
Source: Joe Sandbox ViewIP Address: 96.7.168.138 96.7.168.138
Source: global trafficHTTP traffic detected: GET /onboarding/smskillreader.txt HTTP/1.1Host: armmf.adobe.comConnection: keep-aliveAccept-Language: en-US,en;q=0.9User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brIf-None-Match: "78-5faa31cce96da"If-Modified-Since: Mon, 01 May 2023 15:02:33 GMT
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownTCP traffic detected without corresponding DNS query: 96.7.168.138
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /onboarding/smskillreader.txt HTTP/1.1Host: armmf.adobe.comConnection: keep-aliveAccept-Language: en-US,en;q=0.9User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brIf-None-Match: "78-5faa31cce96da"If-Modified-Since: Mon, 01 May 2023 15:02:33 GMT
Source: global trafficDNS traffic detected: DNS query: x1.i.lencr.org
Source: 77EC63BDA74BD0D0E0426DC8F80085060.4.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: 2D85F72862B55C4EADD9E66E06947F3D0.4.drString found in binary or memory: http://x1.i.lencr.org/
Source: ReaderMessages.0.drString found in binary or memory: https://www.adobe.co
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: classification engineClassification label: clean2.winPDF@14/46@1/1
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journalJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-10-24 11-23-48-356.logJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CAJump to behavior
Source: unknownProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\AlisonMarshall.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2076 --field-trial-handle=1364,i,7330972416840462097,15245140379851579721,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2076 --field-trial-handle=1364,i,7330972416840462097,15245140379851579721,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: AlisonMarshall.pdfInitial sample: PDF keyword /JS count = 0
Source: AlisonMarshall.pdfInitial sample: PDF keyword /JavaScript count = 0
Source: A913k6tiu_19unl2h_2xo.tmp.0.drInitial sample: PDF keyword /JS count = 0
Source: A913k6tiu_19unl2h_2xo.tmp.0.drInitial sample: PDF keyword /JavaScript count = 0
Source: AlisonMarshall.pdfInitial sample: PDF keyword /EmbeddedFile count = 0
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts3
Exploitation for Client Execution
Path Interception1
Process Injection
1
Masquerading
OS Credential Dumping1
System Information Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive13
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1541311 Sample: AlisonMarshall.pdf Startdate: 24/10/2024 Architecture: WINDOWS Score: 2 14 x1.i.lencr.org 2->14 16 bg.microsoft.map.fastly.net 2->16 7 Acrobat.exe 20 69 2->7         started        process3 process4 9 AcroCEF.exe 109 7->9         started        process5 11 AcroCEF.exe 4 9->11         started        dnsIp6 18 96.7.168.138, 443, 49734 INTERNEXABRASILOPERADORADETELECOMUNICACOESSABR United States 11->18

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://x1.i.lencr.org/0%URL Reputationsafe
https://www.adobe.co0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    x1.i.lencr.org
    unknown
    unknownfalse
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      http://x1.i.lencr.org/2D85F72862B55C4EADD9E66E06947F3D0.4.drfalse
      • URL Reputation: safe
      unknown
      https://www.adobe.coReaderMessages.0.drfalse
      • URL Reputation: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      96.7.168.138
      unknownUnited States
      262589INTERNEXABRASILOPERADORADETELECOMUNICACOESSABRfalse
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1541311
      Start date and time:2024-10-24 17:22:49 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 4m 12s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:defaultwindowspdfcookbook.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:21
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:AlisonMarshall.pdf
      Detection:CLEAN
      Classification:clean2.winPDF@14/46@1/1
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • Found application associated with file extension: .pdf
      • Found PDF document
      • Close Viewer
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 184.28.88.176, 52.5.13.197, 54.227.187.23, 23.22.254.206, 52.202.204.11, 162.159.61.3, 172.64.41.3, 2.23.197.184, 199.232.210.172, 2.19.126.143, 2.19.126.149
      • Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, time.windows.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
      • Not all processes where analyzed, report is missing behavior information
      • VT rate limit hit for: AlisonMarshall.pdf
      TimeTypeDescription
      11:23:54API Interceptor2x Sleep call for process: AcroCEF.exe modified
      InputOutput
      URL: PDF document Model: claude-3-haiku-20240307
      ```json
      {
        "contains_trigger_text": true,
        "trigger_text": "Your video will get sent to all your contacts. The video is straight fire, and I can't even fathom the humiliation you'll face when your colleagues, friends, and fam see it. But hey, that's life, ain't it Don't be playing the victim here.",
        "prominent_button_name": "unknown",
        "text_input_field_labels": [
          "Transfer Amount:",
          "My Bitcoin Address:"
        ],
        "pdf_icon_visible": false,
        "has_visible_captcha": false,
        "has_urgent_text": true,
        "has_visible_qrcode": false
      }
      URL: PDF document Model: claude-3-haiku-20240307
      ```json
      {
        "brands": []
      }
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      96.7.168.138Demande de proposition du CPE Les Coquins.pdfGet hashmaliciousUnknownBrowse
        Airbornemx Benefits Enrollment.pdfGet hashmaliciousHTMLPhisherBrowse
          Scan_8346203.pdfGet hashmaliciousUnknownBrowse
            Jwhite Pay Increase EFile997843.pdfGet hashmaliciousUnknownBrowse
              roba.txtGet hashmaliciousMeterpreter, ReflectiveLoaderBrowse
                Inv No.248730.xlsGet hashmaliciousUnknownBrowse
                  ddsfsfsa.pdfGet hashmaliciousUnknownBrowse
                    v2.0.pdfGet hashmaliciousUnknownBrowse
                      Xfab BENEFIT ENROLLMENT GUIDE 2024.pdfGet hashmaliciousHTMLPhisher, Mamba2FABrowse
                        Project_Proposal_Review_and_Approval13617.pdfGet hashmaliciousUnknownBrowse
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          bg.microsoft.map.fastly.nethttps://www.canva.com/design/DAGUUU-VdiI/DdL4Z-_loK4X7NMMbGGnJg/view?utm_content=DAGUUU-VdiI&utm_campaign=designshare&utm_medium=link&utm_source=editorGet hashmaliciousUnknownBrowse
                          • 199.232.214.172
                          Windows-StandardCollector-x64.exeGet hashmaliciousCodoso GhostBrowse
                          • 199.232.210.172
                          Payment for outstanding statements.pdfGet hashmaliciousHTMLPhisherBrowse
                          • 199.232.214.172
                          ATT25322.htmlGet hashmaliciousUnknownBrowse
                          • 199.232.210.172
                          https://app.pandadoc.com/document/v2?token=69b8ae0059c2551a9a27ed1b65653c1a0b5ee1ffGet hashmaliciousUnknownBrowse
                          • 199.232.214.172
                          file.exeGet hashmaliciousUnknownBrowse
                          • 199.232.214.172
                          https://1drv.ms/o/c/3e563d3fb2a98d1c/Emlo5KUbYYNEvKtIF-7SS0EBYSeT3hOOGuv_MbeT-n2y4g?e=HPjqUnGet hashmaliciousHtmlDropperBrowse
                          • 199.232.214.172
                          praxisbackup.exeGet hashmaliciousUnknownBrowse
                          • 199.232.210.172
                          http://74.248.121.8/d/msdownload/update/software/defu/2024/10/updateplatform.amd64fre_d3f6f8300855e56b8ed00da6dac55a3c4cbf8c20.exe?cacheHostOrigin=au.download.windowsupdate.comGet hashmaliciousUnknownBrowse
                          • 199.232.214.172
                          1863415243647.exeGet hashmaliciousAgentTeslaBrowse
                          • 199.232.214.172
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          INTERNEXABRASILOPERADORADETELECOMUNICACOESSABRDemande de proposition du CPE Les Coquins.pdfGet hashmaliciousUnknownBrowse
                          • 96.7.168.138
                          Airbornemx Benefits Enrollment.pdfGet hashmaliciousHTMLPhisherBrowse
                          • 96.7.168.138
                          Scan_8346203.pdfGet hashmaliciousUnknownBrowse
                          • 96.7.168.138
                          Jwhite Pay Increase EFile997843.pdfGet hashmaliciousUnknownBrowse
                          • 96.7.168.138
                          roba.txtGet hashmaliciousMeterpreter, ReflectiveLoaderBrowse
                          • 96.7.168.138
                          Inv No.248730.xlsGet hashmaliciousUnknownBrowse
                          • 96.7.168.138
                          MDE_File_Sample_1a8e4ebbcc2e3f76efb2a55bb6179417263ebf3d.zipGet hashmaliciousUnknownBrowse
                          • 96.7.169.183
                          bin.armv7l.elfGet hashmaliciousMiraiBrowse
                          • 201.33.178.44
                          ddsfsfsa.pdfGet hashmaliciousUnknownBrowse
                          • 96.7.168.138
                          armv4l.elfGet hashmaliciousUnknownBrowse
                          • 200.220.215.193
                          No context
                          No context
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:ASCII text
                          Category:dropped
                          Size (bytes):300
                          Entropy (8bit):5.238521045619185
                          Encrypted:false
                          SSDEEP:6:+6/WeLq2PcNwi2nKuAl9OmbnIFUt8t6/WVXZmw+t6/WNazkwOcNwi2nKuAl9Omb5:d/PvLZHAahFUt8c/sX/+c/8az54ZHAae
                          MD5:FAE9ABB8D6AE1676EEA4CB092AA32D8A
                          SHA1:464C4BEA152D44969E677159D2583BB7DC2B1148
                          SHA-256:4DEB6C0B4C5ECEEDA6CA1AED2E631F3E79D0C6947510E93A3D677AD768484A8F
                          SHA-512:2417BECE5C457979759235A27D79F641A91F75648E12FCE554FE3278E1D8711F42D122C680CE1BDD373B5BBA78478355422681D6C61C340E5768163126E4181B
                          Malicious:false
                          Reputation:low
                          Preview:2024/10/24-11:23:46.548 1914 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2024/10/24-11:23:46.551 1914 Recovering log #3.2024/10/24-11:23:46.552 1914 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:ASCII text
                          Category:dropped
                          Size (bytes):300
                          Entropy (8bit):5.238521045619185
                          Encrypted:false
                          SSDEEP:6:+6/WeLq2PcNwi2nKuAl9OmbnIFUt8t6/WVXZmw+t6/WNazkwOcNwi2nKuAl9Omb5:d/PvLZHAahFUt8c/sX/+c/8az54ZHAae
                          MD5:FAE9ABB8D6AE1676EEA4CB092AA32D8A
                          SHA1:464C4BEA152D44969E677159D2583BB7DC2B1148
                          SHA-256:4DEB6C0B4C5ECEEDA6CA1AED2E631F3E79D0C6947510E93A3D677AD768484A8F
                          SHA-512:2417BECE5C457979759235A27D79F641A91F75648E12FCE554FE3278E1D8711F42D122C680CE1BDD373B5BBA78478355422681D6C61C340E5768163126E4181B
                          Malicious:false
                          Reputation:low
                          Preview:2024/10/24-11:23:46.548 1914 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2024/10/24-11:23:46.551 1914 Recovering log #3.2024/10/24-11:23:46.552 1914 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:ASCII text
                          Category:dropped
                          Size (bytes):344
                          Entropy (8bit):5.211563690056017
                          Encrypted:false
                          SSDEEP:6:+6/WzFL/Iq2PcNwi2nKuAl9Ombzo2jMGIFUt8t6/WxFpFZZmw+t6/WxFpFzkwOc1:d/4FL/IvLZHAa8uFUt8c/AZ/+c/Az54y
                          MD5:4134F243302513DB27EEFA95BCB8536F
                          SHA1:23E4A0696EF3E0B43E3C5B85585E3989766C664F
                          SHA-256:3CC66E38FD750C987EAEE600AFEA5D0543B1076BF73906682A54B49D50354DA0
                          SHA-512:2CB951E1ADAB808507E68E57CB2620A0D46A1278891B59C48BD8808BD3A7245211A43AFE064B163D002C0CF1EF2E085C938A0AA426B111F68BED90DD939CED38
                          Malicious:false
                          Reputation:low
                          Preview:2024/10/24-11:23:46.794 1720 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2024/10/24-11:23:46.796 1720 Recovering log #3.2024/10/24-11:23:46.796 1720 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:ASCII text
                          Category:dropped
                          Size (bytes):344
                          Entropy (8bit):5.211563690056017
                          Encrypted:false
                          SSDEEP:6:+6/WzFL/Iq2PcNwi2nKuAl9Ombzo2jMGIFUt8t6/WxFpFZZmw+t6/WxFpFzkwOc1:d/4FL/IvLZHAa8uFUt8c/AZ/+c/Az54y
                          MD5:4134F243302513DB27EEFA95BCB8536F
                          SHA1:23E4A0696EF3E0B43E3C5B85585E3989766C664F
                          SHA-256:3CC66E38FD750C987EAEE600AFEA5D0543B1076BF73906682A54B49D50354DA0
                          SHA-512:2CB951E1ADAB808507E68E57CB2620A0D46A1278891B59C48BD8808BD3A7245211A43AFE064B163D002C0CF1EF2E085C938A0AA426B111F68BED90DD939CED38
                          Malicious:false
                          Reputation:low
                          Preview:2024/10/24-11:23:46.794 1720 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2024/10/24-11:23:46.796 1720 Recovering log #3.2024/10/24-11:23:46.796 1720 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):475
                          Entropy (8bit):4.967056916756884
                          Encrypted:false
                          SSDEEP:12:YH/um3RA8sqUjuksBdOg2Hvcaq3QYiubSpDyP7E4TX:Y2sRdskJdMHe3QYhbSpDa7n7
                          MD5:16FF9A5F20D1B5B99587E5027B043DBA
                          SHA1:EC9F335AE38264CBD609C11498A59B3E91C159F9
                          SHA-256:400A7C1E950AE99B4ECCF43BBDF0616E93EAE3D14B0B06D84E0CB70F704AA653
                          SHA-512:58A746B7DC4E4D41E9EF3949365D317E41AD6186726F89A614A9467C9C0F74652C3D753EE8463D6A865F3D38A6F445A670E97773BB814B51E801EDBB86D6299C
                          Malicious:false
                          Reputation:low
                          Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://armmf.adobe.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13374343437962542","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":308895},"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.7","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:JSON data
                          Category:modified
                          Size (bytes):475
                          Entropy (8bit):4.967056916756884
                          Encrypted:false
                          SSDEEP:12:YH/um3RA8sqUjuksBdOg2Hvcaq3QYiubSpDyP7E4TX:Y2sRdskJdMHe3QYhbSpDa7n7
                          MD5:16FF9A5F20D1B5B99587E5027B043DBA
                          SHA1:EC9F335AE38264CBD609C11498A59B3E91C159F9
                          SHA-256:400A7C1E950AE99B4ECCF43BBDF0616E93EAE3D14B0B06D84E0CB70F704AA653
                          SHA-512:58A746B7DC4E4D41E9EF3949365D317E41AD6186726F89A614A9467C9C0F74652C3D753EE8463D6A865F3D38A6F445A670E97773BB814B51E801EDBB86D6299C
                          Malicious:false
                          Reputation:low
                          Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://armmf.adobe.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13374343437962542","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":308895},"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.7","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):4509
                          Entropy (8bit):5.239429679480636
                          Encrypted:false
                          SSDEEP:96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtPRy/PCACQ2/8Z:CwNw1GHqPySfkcigoO3h28ytP0/PCAzt
                          MD5:2780C3602BAB264A824D078D3D8B043A
                          SHA1:9BF3978E2053BDC47C61D5D407A3BAAB33EC35DE
                          SHA-256:51CB5D5B0E9B96E3F9EC078931E26BADF01C9BB71620E37202EA49F33E9D12D8
                          SHA-512:E1DB738331D2DC731F2D43BF9F0A69179E8BF04DC08838AC85176C5544F62204DC5E043F4DA5B8DC4F99654F10BF56D320612DFFF7D60C8E4ED2D6C40C0C9B5B
                          Malicious:false
                          Reputation:low
                          Preview:*...#................version.1..namespace-.aw.o................next-map-id.1.Pnamespace-aa11265e_f35e_4e5d_85db_f163e1c0f691-https://rna-resource.acrobat.com/.0I.$.r................next-map-id.2.Snamespace-9a9aa6d6_c307_4dda_b6c0_dc91084c8e68-https://rna-v2-resource.acrobat.com/.1!...r................next-map-id.3.Snamespace-1fbd9dc5_70a3_4975_91b4_966e0915c27a-https://rna-v2-resource.acrobat.com/.2..N.o................next-map-id.4.Pnamespace-0e0aed8d_6d6f_4be0_b28f_8e02158bc792-https://rna-resource.acrobat.com/.3*.z.o................next-map-id.5.Pnamespace-52652c26_09c2_43f2_adf7_da56a1f00d32-https://rna-resource.acrobat.com/.4.{.^...............Pnamespace-aa11265e_f35e_4e5d_85db_f163e1c0f691-https://rna-resource.acrobat.com/.C..r................next-map-id.6.Snamespace-3a89c6b0_72b9_411a_9e44_fa247f34ac91-https://rna-v2-resource.acrobat.com/.5.q._r................next-map-id.7.Snamespace-02b23955_9103_42e0_ba64_3f8683969652-https://rna-v2-resource.acrobat.com/.6..d.o..............
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:ASCII text
                          Category:dropped
                          Size (bytes):332
                          Entropy (8bit):5.1568968062515195
                          Encrypted:false
                          SSDEEP:6:+6/WsRNIq2PcNwi2nKuAl9OmbzNMxIFUt8t6/WsyZZmw+t6/WI3kwOcNwi2nKuAo:d/9RNIvLZHAa8jFUt8c/9G/+c/h354Zv
                          MD5:D2B0CBBA31BFD00E86A5E45725DB796C
                          SHA1:1EBCA0B6C2947DE5D8BC486DF8DDC6E9D0A2468F
                          SHA-256:3E3729F6B66723B764DCFBA2E8D940CEACFB2580386E055DB1D60B929B5B0B8E
                          SHA-512:630F452A496F32F369B9A607BD53A2F67B760273E305122D8248B047766D44D4B6CF83F8EE4442B7431677A3CA641A9FA4D4DC7243C5000DFA00414467EF285C
                          Malicious:false
                          Preview:2024/10/24-11:23:47.114 1720 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2024/10/24-11:23:47.119 1720 Recovering log #3.2024/10/24-11:23:47.143 1720 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:ASCII text
                          Category:dropped
                          Size (bytes):332
                          Entropy (8bit):5.1568968062515195
                          Encrypted:false
                          SSDEEP:6:+6/WsRNIq2PcNwi2nKuAl9OmbzNMxIFUt8t6/WsyZZmw+t6/WI3kwOcNwi2nKuAo:d/9RNIvLZHAa8jFUt8c/9G/+c/h354Zv
                          MD5:D2B0CBBA31BFD00E86A5E45725DB796C
                          SHA1:1EBCA0B6C2947DE5D8BC486DF8DDC6E9D0A2468F
                          SHA-256:3E3729F6B66723B764DCFBA2E8D940CEACFB2580386E055DB1D60B929B5B0B8E
                          SHA-512:630F452A496F32F369B9A607BD53A2F67B760273E305122D8248B047766D44D4B6CF83F8EE4442B7431677A3CA641A9FA4D4DC7243C5000DFA00414467EF285C
                          Malicious:false
                          Preview:2024/10/24-11:23:47.114 1720 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2024/10/24-11:23:47.119 1720 Recovering log #3.2024/10/24-11:23:47.143 1720 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:PC bitmap, Windows 3.x format, 107 x -152 x 32, cbSize 65110, bits offset 54
                          Category:dropped
                          Size (bytes):65110
                          Entropy (8bit):2.4850375426072993
                          Encrypted:false
                          SSDEEP:768:zhEF9aKkwCk3foucStyY3QKRUwhRbl8Y6OvcVP934RI:yfaxsPyECw7lz6Ovc5933
                          MD5:D4976C0357F1C2BF3BFC45214D63064A
                          SHA1:730C46DB4F21E8F0B0BBFFC95BA99F3609A71794
                          SHA-256:7016B238B8674A556189E86762C0FF4942A824E61B025238B77E7C727209B118
                          SHA-512:A963258D6FE882201D3F1A51952F82E24C6EC8221180E6B86F8B41ECF5E745D2441BC056E0E8C18DC504FC1B4B9A4D52D9CC376006438EAF82590DB96E5786D6
                          Malicious:false
                          Preview:BMV.......6...(...k...h..... ...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 15, database pages 21, cookie 0x5, schema 4, UTF-8, version-valid-for 15
                          Category:dropped
                          Size (bytes):86016
                          Entropy (8bit):4.439114984227952
                          Encrypted:false
                          SSDEEP:384:yeaci5GsiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:1AurVgazUpUTTGt
                          MD5:22541FA9610CBB97CF17B97199B6B762
                          SHA1:865A8C42B6C6894718F4A5BB7EAD7C100C3F1312
                          SHA-256:B6135CC264FEF86A2FFA8D4066655CC6A1D310289E28C15AF102E91320C463CD
                          SHA-512:13D53443881A75BE0CB9EA68088AE7C3F6E260EC853470C8790A764CAF4EF01922859F14DC7D626D552A86945DEFCA6CAECD4C3034474EEF9F773F51C9EAA22C
                          Malicious:false
                          Preview:SQLite format 3......@ ..........................................................................c.......1........T...U.1.D............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:SQLite Rollback Journal
                          Category:dropped
                          Size (bytes):8720
                          Entropy (8bit):3.773673864478678
                          Encrypted:false
                          SSDEEP:48:7MIp/E2ioyV/ioy3DoWoy1CABoy1PKOioy1noy1AYoy1Wioy1hioybioyfoy1noD:77pju/0iAhXKQGYb9IVXEBodRBkN
                          MD5:621101D427C973ED8B648DF1BF16E6CF
                          SHA1:370AA791847333E38D6DAB061F9D870C90C76C9E
                          SHA-256:7FA18462A8A9F79017124F93C1C5BAC2E02EEA08737D31EDBF655CDEFE71E552
                          SHA-512:0CBAD4CB4738370FFD4DB384B4354235C3D85A85A5BBFCD0D16D48BB1AF324FEFD5311A448B61745F8237B546E6544ED7F4A958B36A17594047758EE7FD41D14
                          Malicious:false
                          Preview:.... .c.....G.l................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................T...[...b...r...t...}.....L..............................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:Certificate, Version=3
                          Category:dropped
                          Size (bytes):1391
                          Entropy (8bit):7.705940075877404
                          Encrypted:false
                          SSDEEP:24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1
                          MD5:0CD2F9E0DA1773E9ED864DA5E370E74E
                          SHA1:CABD2A79A1076A31F21D253635CB039D4329A5E8
                          SHA-256:96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6
                          SHA-512:3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910
                          Malicious:false
                          Preview:0..k0..S............@.YDc.c...0...*.H........0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X10...150604110438Z..350604110438Z0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X10.."0...*.H.............0..........$s..7.+W(.....8..n<.W.x.u...jn..O(..h.lD...c...k....1.!~.3<.H..y.....!.K...qiJffl.~<p..)"......K...~....G.|.H#S.8.O.o...IW..t../.8.{.p!.u.0<.....c...O..K~.....w...{J.L.%.p..)..S$........J.?..aQ.....cq...o[...\4ylv.;.by.../&.....................6....7..6u...r......I.....*.A..v........5/(.l....dwnG7..Y^h..r...A)>Y>.&.$...Z.L@.F....:Qn.;.}r...xY.>Qx....../..>{J.Ks......P.|C.t..t.....0.[q6....00\H..;..}`...).........A.......|.;F.H*..v.v..j.=...8.d..+..(.....B.".'].y...p..N..:..'Qn..d.3CO......B0@0...U...........0...U.......0....0...U......y.Y.{....s.....X..n0...*.H.............U.X....P.....i ')..au\.n...i/..VK..s.Y.!.~.Lq...`.9....!V..P.Y...Y.............b.E.f..|o..;.....'...}~.."......
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
                          Category:dropped
                          Size (bytes):71954
                          Entropy (8bit):7.996617769952133
                          Encrypted:true
                          SSDEEP:1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ
                          MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
                          SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
                          SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
                          SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
                          Malicious:false
                          Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):192
                          Entropy (8bit):2.756901573172974
                          Encrypted:false
                          SSDEEP:3:kkFklpFvtfllXlE/HT8ksllXNNX8RolJuRdxLlGB9lQRYwpDdt:kKqveT8ZdNMa8RdWBwRd
                          MD5:951BB10F85381854DE302C5F45EF25C8
                          SHA1:68C9E1B25DCACAE19CDDEAF22487E3ACF4C71FE1
                          SHA-256:D347F2DC62EB43B81E75D5C83215AC959E5D7634A0992ED01EBCBCC21DD74741
                          SHA-512:F1A3611E20DC59FF60660875B0A611905B01116B6869CBC6AB2821D30F85195E30DA3397230FB36353AAF017A43657D8FA06DC6F81C6B9B65303CA2EA25A5867
                          Malicious:false
                          Preview:p...... .........M..(&..(....................................................... ..........W.....a..............o...h.t.t.p.:././.x.1...i...l.e.n.c.r...o.r.g./...".6.4.c.d.6.6.5.4.-.5.6.f."...
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:data
                          Category:modified
                          Size (bytes):328
                          Entropy (8bit):3.2418003062782916
                          Encrypted:false
                          SSDEEP:6:kK8L9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:FDImsLNkPlE99SNxAhUe/3
                          MD5:DD87C410168A190D29C0925F10E6F524
                          SHA1:5A44199042BE403BA688557387A1C188911B3EF8
                          SHA-256:13313A0B0FDBFC4B53AF1D56CE931649EDBC384B9A459195167EFA8697D752C0
                          SHA-512:0795FCCDFE1F926CF5989D76603441285163EF0BA544159D817EAF29809C4EA8E6E433738D026133BE63A4F80D2C3DE9ECFA637CFC5BF379022C38B488307EC8
                          Malicious:false
                          Preview:p...... ............(&..(....................................................... ........G..@.......&......X........h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".a.7.2.8.2.e.b.4.0.b.1.d.a.1.:.0."...
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):227002
                          Entropy (8bit):3.392780893644728
                          Encrypted:false
                          SSDEEP:1536:qMKP+iyzDtrh1cK3XEivK7VK/3AYvYwgF/rRoL+sn:FKPoJ/3AYvYwglFoL+sn
                          MD5:C11248DE3EDEB5F39EE8D1E2C1FFE7D8
                          SHA1:7EC6B85BDB7C99BA691BB08A051EF7C4D4A43231
                          SHA-256:57612AEEE8F8E8471B730963F8E111C9890F83D8120380A6FF0676A3814A4B41
                          SHA-512:E13FD658A42EE8BA3CDE3DE5912C3BF3F1A5D720D6C47C3FBCB9C529208DC2860A64B3C41F08660A76CAF5482CF8FDA5EEB62ACC719860AE05EE5C8369C24D9F
                          Malicious:false
                          Preview:Adobe Acrobat Reader (64-bit) 23.6.20320....?A12_AV2_Search_18px.............................................................................................................KKK KKK.KKK.KKK.KKK.KKK.KKK@........................................KKK`KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK.............................KKKPKKK.KKK.KKK.KKK.........KKKPKKK.KKK.KKK.........................KKK.KKK.KKK.KKK0....................KKK.KKK.KKK.KKK`....................KKK`KKK.KKK.............................KKK@KKK.KKK.....................KKK.KKK.KKK0................................KKK.KKK.....................KKK.KKK.....................................KKK.KKK.....................KKK.KKK.KKK0................................KKK.KKK.....................KKK`KKK.KKK.............................KKK@KKK.KKK.....................KKK.KKK.KKK.KKK@....................KKK.KKK.KKK.KKK`........................KKKPKKK.KKK.KKK.KKK.........KKKPKKK.KKK.KKK.KKK.............................KKK`KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):295
                          Entropy (8bit):5.3623323422113085
                          Encrypted:false
                          SSDEEP:6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJM3g98kUwPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGMbLUkee9
                          MD5:FF98DFECE8DC4DE0CBA3CD075F15AA01
                          SHA1:77C9F7EAEAE8CCC50F2DBE7C746F0C60A1D987EC
                          SHA-256:AD366ED845D6D18E43ECD6D18CAF93F02B029AD02A051643F301305ACB204F87
                          SHA-512:EDB3A411C83D33FB26356303A3C748898AE324081491B7BF1BDC1B71F8E73FAE482AA8D31425AE11FAD7D5AF39206268698BD0ABF0830A94277F4716F64EAF5C
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"ACROBAT_READER_MASTER_SURFACEID","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):294
                          Entropy (8bit):5.293386530726487
                          Encrypted:false
                          SSDEEP:6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfBoTfXpnrPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGWTfXcUkee9
                          MD5:9FA58BEF05E8E426B66DBB213328EC2E
                          SHA1:553513A7ADEB9835BEB5071654D34D6801AF047E
                          SHA-256:053CA2ED1E9D5454DFECB3A0680B5554C1BE5E4A93B4CFC8FDFA3AD574AE6BBF
                          SHA-512:2E8CF418C30A2FC09C276C3D63DEE0B0E71C6309B3BBB70580844ECAD897E94BE3E54BD103189AD5FCD09BE31D31B6403912F130FA064756BA5116A0A906D357
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_FirstMile_Home_View_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):294
                          Entropy (8bit):5.271420359617906
                          Encrypted:false
                          SSDEEP:6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfBD2G6UpnrPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGR22cUkee9
                          MD5:C67B71D2C7748C3BE611E9312293F612
                          SHA1:489D81D63167CCCC374E2F9241915632BA876B6F
                          SHA-256:F012CD57E310A1354725EFC7627CBC5CBC97E1046432936492BAED0376BECB1B
                          SHA-512:01E3F7A8BE6508B323CB8209791DE1BE9E11869AF2983DF5E120BDF9A47940DF4EF6090075AA1F0E55158A21EB67B196939B2D3A47E4ABC081FD1A664B21D5DC
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_FirstMile_Right_Sec_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):285
                          Entropy (8bit):5.349174468379952
                          Encrypted:false
                          SSDEEP:6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfPmwrPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGH56Ukee9
                          MD5:1598184E269F2D41244B32F5C234197E
                          SHA1:10FF1A90603055C53A3DAA3D7ADD9BFC847E1936
                          SHA-256:6938CF65F4FCD55B7E3B5424C5B8FA72B8DB9F0440392782A871A5D24D2955FF
                          SHA-512:69309F200618CE1595C0E0724E43FE9B5FC8739BD51ED273DA1B0A7D7659CE07D3232B5C64C9E623295980DFA0EFC442458B095FD6D9C5D193650B33C6066F22
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_READER_LAUNCH_CARD","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):1055
                          Entropy (8bit):5.663298780968814
                          Encrypted:false
                          SSDEEP:24:Yv6XSVbmeOvpLgEscLf7nnl0RCmK8czOCCSV:Yv4eshgGzaAh8cv/V
                          MD5:421DB58F3BD9D122D699C1F06E3EDB98
                          SHA1:864BFF4F80DE4FFB5DBC837234A6699D1A5EF773
                          SHA-256:0EFE9BD17742972F934EA55BF0109C729195C942D7EE1F358EA6AA5AF6549256
                          SHA-512:9B15F1DD6A188E89C78F89BD8CDD0A9A03622B3758C1F37127F552B8B35041D2595D7E7136342221FFEA57AC72D8B5D98C69E5CC2BF5ABE97F8A5875E6FF3522
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_Convert_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Convert_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"92038_285529ActionBlock_1","campaignId":92038,"containerId":"1","controlGroupId":"","treatmentId":"eb1a4bce-8215-46f1-b44c-154b21a85d60","variationId":"285529"},"containerId":1,"containerLabel":"JSON for DC_Reader_Convert_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkV4cG9ydCBQREZzIHRvIE1pY3Jvc29mdCBXb3JkIGFuZCBFeGNlbC4ifSwidGNhdElkIjpudWxsfQ==","dataType":"application\/json","encodingScheme":tr
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):1050
                          Entropy (8bit):5.654781561566843
                          Encrypted:false
                          SSDEEP:24:Yv6XSVbmeOzVLgEF0c7sbnl0RCmK8czOCYHflEpwiVk:Yv4eGFg6sGAh8cvYHWpwV
                          MD5:61DB5720A61D1A20BE5C0A5CAFEA7005
                          SHA1:85ACE28539F5F9312E5B3527B1A9CAEDB80BEF19
                          SHA-256:30CDFA4B3730419F61136E4411258469E05D6A3A581DA0B4762D605B64C19385
                          SHA-512:AB4F6FEAF95E79CECFD750CDFF758B53949CF8B01BE5F3574D56B0D95F225570D0122D7192D024F048184AE13DC5463E710AF2868D62F08D27D34F0FAF019979
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Disc_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"85534_264855ActionBlock_0","campaignId":85534,"containerId":"1","controlGroupId":"","treatmentId":"0924134e-3c59-4f53-b731-add558c56fec","variationId":"264855"},"containerId":1,"containerLabel":"JSON for DC_Reader_Disc_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkNvbnZlcnQsIGVkaXQgYW5kIGUtc2lnblxuZm9ybXMgJiBhZ3JlZW1lbnRzLiJ9LCJ0Y2F0SWQiOm51bGx9","dataType":"application\/json","encodingScheme":true},"
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):292
                          Entropy (8bit):5.290003922720311
                          Encrypted:false
                          SSDEEP:6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfQ1rPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGY16Ukee9
                          MD5:459A3B162BD7A9FCC66EB591A1B1BD2C
                          SHA1:C52E0FC15B5B6C4FDB86FF2DB388BAC16BD5548F
                          SHA-256:C4365A1FC2BB5037E93F05E4A2550D0667E5F0E0B5B54C215565A48331CFDB16
                          SHA-512:EDA8DFBCBA81D1220BE3F53D011123AA4007786166F36352E5BB1EEF43C91D7E652C4F139FBAB16D52548B2A17FBB471BBFB6C23D206CDF3FDD3720A1E383A4F
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):1038
                          Entropy (8bit):5.655570213210326
                          Encrypted:false
                          SSDEEP:24:Yv6XSVbmeOC2LgEF7cciAXs0nl0RCmK8czOCAPtciBk:Yv4ezogc8hAh8cvAm
                          MD5:69B1A15F46B154F7B639E7B7138AC46F
                          SHA1:4D47C293482EE34F396DEB1B924BFAFF7AC5FB76
                          SHA-256:568D9D72067ECCE0B9BB49C0E0631C02D7747E0C5FFC958CFA5B97354BA255F6
                          SHA-512:D9E8D845329A526BF2EC5C5EC04EE2BA111B9B56EE66C066E97645CEB517A3C9F43141800B92A32AB315C9A0DDA5386FC842A773D900EAF2C7D87673EBA562FE
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_Edit_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Edit_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"85534_264855ActionBlock_1","campaignId":85534,"containerId":"1","controlGroupId":"","treatmentId":"49d2f713-7aa9-44db-aa50-0a7a22add459","variationId":"264855"},"containerId":1,"containerLabel":"JSON for DC_Reader_Edit_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkVkaXQgdGV4dCwgaW1hZ2VzLCBwYWdlcywgYW5kIG1vcmUuIn0sInRjYXRJZCI6bnVsbH0=","dataType":"application\/json","encodingScheme":true},"endDTS":1744
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):1164
                          Entropy (8bit):5.703615438882712
                          Encrypted:false
                          SSDEEP:24:Yv6XSVbmeO+KLgEfIcZVSkpsn264rS514ZjBrwloJTmcVIsrSK5k:Yv4e/EgqprtrS5OZjSlwTmAfSKi
                          MD5:575906F8FC888973211A451F365BFC10
                          SHA1:1F64CF750F761BB5C12DDA079B7B6D48DB0B3BE4
                          SHA-256:257ECADAFEFEB86E414F8CF6172B9731CC7513BADCE72E81E958D78D5B2072A3
                          SHA-512:23896A892019D5AE66A3405FE9481B7FE179331935F96C5DF7D5CEEEFF70578BAFBF6A4E358368EA2F1295FC07C60A91B67F4C1905365F6457F0C6D2470C9CA6
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_Home_LHP_Trial_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Home_LHP_Trial_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"85531_264848ActionBlock_0","campaignId":85531,"containerId":"1","controlGroupId":"","treatmentId":"ee1a7497-76e7-43c2-bb63-9a0551e11d73","variationId":"264848"},"containerId":1,"containerLabel":"JSON for DC_Reader_Home_LHP_Trial_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IlRyeSBBY3JvYmF0IFBybyJ9LCJ1aSI6eyJ0aXRsZV9zdHlsaW5nIjp7ImZvbnRfc2l6ZSI6IjE1cHgiLCJmb250X3N0eWxlIjoiMCJ9LCJkZXNjcmlwdGlvbl9zdHlsaW5nIjp7ImZvbnRfc2l6ZSI6IjEzcHgiLCJmb250X3N0eWxlIjoiLTEifSwidGl0bGUiOiJGcmVlIHRyaWFsIiwiZGVzY3JpcHRpb24iOiJHZXQgdW5saW1pdGVkIGFjY2VzcyB0b1xucHJlbWl1bSBQREYgYW5kIGUtc2lnbmluZ1xudG9vbHMuIn0sImJhbm5lcl9zdHlsaW5nIjo
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):289
                          Entropy (8bit):5.294058487122437
                          Encrypted:false
                          SSDEEP:6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfYdPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGg8Ukee9
                          MD5:C16692BBF685AFD8BE4DA2202F1706DE
                          SHA1:21BA7BA8A50D340641BA34451191F36EF375E05D
                          SHA-256:C8B8D8B68B94A6D7ACE375E1DCDE7ECAC0E623E2C5CB4E2F8578A3091E2B1B91
                          SHA-512:C046E39E655733EC405C46C6223EEF5EE8F604A238A0E6A4912172D8DAD86C21019E1FA14AF057B965BA50E7CBEB70090F164EC77FE7E28B27B7CC2DBFA295BF
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_More_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):1395
                          Entropy (8bit):5.776154003064308
                          Encrypted:false
                          SSDEEP:24:Yv6XSVbmeO1rLgEGOc93W2JeFmaR7CQzttgBcu141CjrWpHfRzVCV9FJNc:Yv4eCHgDv3W2aYQfgB5OUupHrQ9FJi
                          MD5:8CBE050568F8294C7CC9B1711169947B
                          SHA1:EF91543FA594998471E886209B1EB88C697FD496
                          SHA-256:2965EB07D68186FA7FEDFE7C8132598AA5C12D59D6831F1E9A44B8F51F10EA2A
                          SHA-512:89198394266EC0920015C51AB110030D2503E513D048CE48D0ADF3FB850FDDB956213F0D7F73B04570285BD53702F677C815963FE73735D9715158962862AE36
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_RHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_RHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"57802_176003ActionBlock_0","campaignId":57802,"containerId":"1","controlGroupId":"","treatmentId":"d0374f2d-08b2-49b9-9500-3392758c9e2e","variationId":"176003"},"containerId":1,"containerLabel":"JSON for Reader DC RHP Banner","content":{"data":"eyJjdGEiOnsidHlwZSI6ImJ1dHRvbiIsInRleHQiOiJGcmVlIDctRGF5IFRyaWFsIiwiZ29fdXJsIjoiaHR0cHM6Ly9hY3JvYmF0LmFkb2JlLmNvbS9wcm94eS9wcmljaW5nL3VzL2VuL3NpZ24tZnJlZS10cmlhbC5odG1sP3RyYWNraW5naWQ9UEMxUFFMUVQmbXY9aW4tcHJvZHVjdCZtdjI9cmVhZGVyIn0sInVpIjp7InRpdGxlX3N0eWxpbmciOnsiZm9udF9zaXplIjoiMTQiLCJmb250X3N0eWxlIjoiMyJ9LCJkZXNjcmlwdGlvbl9zdHlsaW5nIjp7ImZvbnRfc2l6ZSI6IjEyIiwiZm9udF9zdHlsZSI6IjMifSwidGl0
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):291
                          Entropy (8bit):5.277646419936353
                          Encrypted:false
                          SSDEEP:6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfbPtdPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGDV8Ukee9
                          MD5:0B9BEE36BDA5375FA685FF87777E8BB8
                          SHA1:96EA5270E47035B96782AE2352B708073A0C30EF
                          SHA-256:5FD64C31E1CE82556B133C004DFA3601E6DDE7306CF2605F197007168D7C1492
                          SHA-512:AC5A271A6AE109053CCF2C2F70D260EAAC30DBCE891B5FA5B3475B9290A0196E2F1FDFC70FF96DE06768F7C97391C5608838767AAA7360328E29A97457C5A34C
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_RHP_Intent_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):287
                          Entropy (8bit):5.28190125255051
                          Encrypted:false
                          SSDEEP:6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJf21rPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VG+16Ukee9
                          MD5:C4E9F284850A38E032BBDF0A9BC4D75B
                          SHA1:307F242CD0A1901008E883D426065F606F2DFCA6
                          SHA-256:D74881663FB02938263892BAFB9169776844C49EBB807D515A81998B781E65B4
                          SHA-512:5942ED6B259FC70A8839D7CE4F7CE24DDDA8A11D856B5EA5D23C08FAEE70E82E6E077CD931E351116DCF49519B83F72052A1656E069B7AA5C14557E28833A7AA
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_RHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):1026
                          Entropy (8bit):5.633839858453574
                          Encrypted:false
                          SSDEEP:24:Yv6XSVbmeO3amXayLgE7cMCBNaqnl0RCmK8czOC/BSV:Yv4eeBgACBOAh8cvMV
                          MD5:2285F28F03A46E3BE17ADFDA640D4672
                          SHA1:71D9088E95D739D90CE70F4EA79BCBAB6B93A5A2
                          SHA-256:A6A4FF5E8968783C35425915101F2D0C9D43636F4C6074EAF99062D6E70B9BF6
                          SHA-512:1C94C7731F759A3E936C1FA1BC1409104721B52C24AF71A682D0E9804A754489F53B127F25AAF7EC15A49D9A22105B69FCA8962517C87630CE9373C06D5C0D0B
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_Sign_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Sign_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"92038_285529ActionBlock_0","campaignId":92038,"containerId":"1","controlGroupId":"","treatmentId":"6291f52b-6cb0-4d31-bc46-37ce85e9eb25","variationId":"285529"},"containerId":1,"containerLabel":"JSON for DC_Reader_Sign_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkVhc2lseSBmaWxsIGFuZCBzaWduIFBERnMuIn0sInRjYXRJZCI6bnVsbH0=","dataType":"application\/json","encodingScheme":true},"endDTS":1751323379000,"s
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):286
                          Entropy (8bit):5.260406734805295
                          Encrypted:false
                          SSDEEP:6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfshHHrPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGUUUkee9
                          MD5:CCB764E209C612732B94DF4A08B6348C
                          SHA1:264ACDC3CFD24C9B6807B6E6B8F908FC81598A1B
                          SHA-256:C6A4AC2BDC1B41CDEB54910A8BD0A8E7025CA6BAA715C3E619009D5A59AFC003
                          SHA-512:CB69EF72FB629D6A8B5E0F3BEEB23DE5791A66D8909AA5114CD126186AD4D7E3418B49C15A930CC43549F8DCFB4076421DF15DADDFAC1DD2282818015ACDA442
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"DC_Reader_Upsell_Cards","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):782
                          Entropy (8bit):5.37690854290155
                          Encrypted:false
                          SSDEEP:12:YvXKX6ygbTHVbsdTeOm7VGTq16Ukee1+3CEJ1KXd15kcyKMQo7P70c0WM6ZB/uhV:Yv6XSVbmeOc168CgEXX5kcIfANhV
                          MD5:FDD7928DF2C14FFAC4AA0E75468A78EB
                          SHA1:B4EED54A44A8501EDA29431FC02EB6879903EE2E
                          SHA-256:B1DE9BE2B042D8EA228BA9158019031991909DCF83A7333012253C7ACADD3470
                          SHA-512:FF47892FFB7CDF00A881EB14DAD1982D4EEA691F959971BEBE7DB362D519D060F828B814DF8443DDABA75CC056A37978E631A24EBE2F97F7C4B3B33A0B21D998
                          Malicious:false
                          Preview:{"analyticsData":{"responseGUID":"b98f574f-4fce-4a9f-86c1-b791bcef1ec6","sophiaUUID":"83ABFDB2-FC78-4BD3-A96C-A13541192F3B"},"encodingScheme":true,"expirationDTS":1729958995758,"statusCode":200,"surfaceID":"Edit_InApp_Aug2020","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"Edit_InApp_Aug2020"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"20360_57769ActionBlock_0","campaignId":20360,"containerId":"1","controlGroupId":"","treatmentId":"3c07988a-9c54-409d-9d06-53885c9f21ec","variationId":"57769"},"containerId":1,"containerLabel":"JSON for switching in-app test","content":{"data":"eyJ1cHNlbGxleHBlcmltZW50Ijp7InRlc3RpZCI6IjEiLCJjb2hvcnQiOiJicm93c2VyIn19","dataType":"application\/json","encodingScheme":true},"endDTS":1735804679000,"startDTS":1729783435790}}}}
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):4
                          Entropy (8bit):0.8112781244591328
                          Encrypted:false
                          SSDEEP:3:e:e
                          MD5:DC84B0D741E5BEAE8070013ADDCC8C28
                          SHA1:802F4A6A20CBF157AAF6C4E07E4301578D5936A2
                          SHA-256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
                          SHA-512:65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71
                          Malicious:false
                          Preview:....
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:JSON data
                          Category:dropped
                          Size (bytes):2818
                          Entropy (8bit):5.137994629973526
                          Encrypted:false
                          SSDEEP:24:YTF9aAazOumaykWJMkpCtSv75RKG5ZxdDdC5Fj8LGj0SnFgT2FIm2LShNgk5r9oy:YgWnOwFwIXDUD8cEmrqkd99X
                          MD5:4E9B4A74B7E3B05C180BC959974D2B42
                          SHA1:877ADA5F03A1E7C6C8FCAD79854AA0725D4D5710
                          SHA-256:920F3F04AE67660C07ACD4F2A1A863D33AB54D341C891C5C1C151CF1279549F3
                          SHA-512:3CDB86D31A78BFC241E9322D6604E0042ECF64D325847D238E2472A042BF3EE2A8AC5074B9C99FDC4B5E7C4AD7A3A613FA766E5FB826DA93745E113FCD04D581
                          Malicious:false
                          Preview:{"all":[{"id":"DC_Reader_Disc_LHP_Banner","info":{"dg":"48cd77f400ce3a079215761a2431ec9d","sid":"DC_Reader_Disc_LHP_Banner"},"mimeType":"file","size":1050,"ts":1729783434000},{"id":"DC_Reader_Home_LHP_Trial_Banner","info":{"dg":"5f60ff00ce142e47f58b9a2723fa7ba7","sid":"DC_Reader_Home_LHP_Trial_Banner"},"mimeType":"file","size":1164,"ts":1729783434000},{"id":"DC_Reader_Sign_LHP_Banner","info":{"dg":"d8791e196ee5e007abeb267ef8cc596b","sid":"DC_Reader_Sign_LHP_Banner"},"mimeType":"file","size":1026,"ts":1729783434000},{"id":"DC_Reader_Convert_LHP_Banner","info":{"dg":"dfc5e9c94bdeb4c8b03d14ad41e9ecde","sid":"DC_Reader_Convert_LHP_Banner"},"mimeType":"file","size":1055,"ts":1729783434000},{"id":"DC_Reader_Edit_LHP_Banner","info":{"dg":"3023ada9d8bc279c4f67092e633ff6cb","sid":"DC_Reader_Edit_LHP_Banner"},"mimeType":"file","size":1038,"ts":1729783434000},{"id":"Edit_InApp_Aug2020","info":{"dg":"ce80b2b732473f19b5a03c0fa9604431","sid":"Edit_InApp_Aug2020"},"mimeType":"file","size":782,"ts":17
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 25, database pages 3, cookie 0x2, schema 4, UTF-8, version-valid-for 25
                          Category:dropped
                          Size (bytes):12288
                          Entropy (8bit):1.453972295270802
                          Encrypted:false
                          SSDEEP:48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsLFllZ:lNVmsw3SHtbDbPe0K3+fDZdM
                          MD5:D2945AA9F2D815AD22386A4A84297C5F
                          SHA1:5B45180A92D7844E3D2DFE0ED3188C4EDB0F7148
                          SHA-256:4AD7CF8309F074E53BCDA1F6B4E7FC7B8BC71141186F4124927653CA134D90ED
                          SHA-512:F8378B10F39081C420077DC3243904A1B26244483E63FDD0EB5DF73D6CB6E6733E9BC0B61CCEDF2CAD45AB80D7291ED4F3F026633A53F183B7369A6B68125558
                          Malicious:false
                          Preview:SQLite format 3......@ ..........................................................................c.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:SQLite Rollback Journal
                          Category:dropped
                          Size (bytes):8720
                          Entropy (8bit):1.9596167064158574
                          Encrypted:false
                          SSDEEP:48:7M/rvrBd6dHtbGIbPe0K3+fDy2dsLQrqFl2GL7ms1:7y3SHtbDbPe0K3+fDZddKVms1
                          MD5:FF20E3D4517F124397A488D76D8EF6AD
                          SHA1:DD3EAA80295E2606F9D8CF3B3F8E82D2C2201D50
                          SHA-256:60A31A159A30CEC7374D2410B6ED75E2DD9E058970E7A18255BEC41E305C8F38
                          SHA-512:2D28631FCF1978230A49EE4E2048F255EE1B2AB50E976621605774DC152195DC4E961C18A0A1752D50DCF72614517E06D4EF8406653A6792885C0728CC44DAFE
                          Malicious:false
                          Preview:.... .c..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................v.../.././././....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                          Category:dropped
                          Size (bytes):246
                          Entropy (8bit):3.512793808211959
                          Encrypted:false
                          SSDEEP:6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8cjqZH:Qw946cPbiOxDlbYnuRKHe
                          MD5:F4CCB36665CB272AF29B57CBF8253DCF
                          SHA1:C96B7A33414167A1837AB5BD5D8163ADAF5A42E6
                          SHA-256:67EC8061E31DB575BBFE6BB68CE8470DBA0B161FBF94B9228274D07ECEB9A972
                          SHA-512:3AF7E95F78B0F8D7EC9080AF471EC0515A613DB9CE29DF63D423572EEAC16FC9A1AEC51F238A47379D35EC7EB6FEEDA3861C7E838A8AD643D553728347270EF9
                          Malicious:false
                          Preview:..E.r.r.o.r. .2.7.1.1...T.h.e. .s.p.e.c.i.f.i.e.d. .F.e.a.t.u.r.e. .n.a.m.e. .(.'.A.R.M.'.). .n.o.t. .f.o.u.n.d. .i.n. .F.e.a.t.u.r.e. .t.a.b.l.e.......=.=.=. .L.o.g.g.i.n.g. .s.t.o.p.p.e.d.:. .2.4./.1.0./.2.0.2.4. . .1.1.:.2.3.:.5.3. .=.=.=.....
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:PDF document, version 1.6, 0 pages
                          Category:dropped
                          Size (bytes):358
                          Entropy (8bit):5.074341916757025
                          Encrypted:false
                          SSDEEP:6:IngVMrexJzJT0y9VEQIFVmb/eu2g/86S1kxROOsVos+kmVos+VLCSyAAO:IngVMre9T0HQIDmy9g06JXEoFkmVoFBR
                          MD5:0802A8C752F694D540F21CD8135BF352
                          SHA1:3856FDE80102A4D6F897788E34A5BBB40B41D540
                          SHA-256:6600CFFC66A61B416DA44218A1D04EEE2473A0F64611FFA422A508422F097616
                          SHA-512:B04A83ED59B578A32A0EAA65C069264A6F6B4BBA33681A0BB615A126ED0D1408A964392E1742E89ED5CC44C8D08984FBCF601A4E03C4A8B298175C7192585B89
                          Malicious:false
                          Preview:%PDF-1.6.%......1 0 obj.<</Pages 2 0 R/Type/Catalog>>.endobj.2 0 obj.<</Count 0/Kids[]/Type/Pages>>.endobj.3 0 obj.<<>>.endobj.xref..0 4..0000000000 65535 f..0000000016 00000 n..0000000061 00000 n..0000000107 00000 n..trailer..<</Size 4/Root 1 0 R/Info 3 0 R/ID[<D079205CFE881D44AB75EF6AC4AE8A88><D079205CFE881D44AB75EF6AC4AE8A88>]>>..startxref..127..%%EOF..
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:ASCII text, with very long lines (393)
                          Category:dropped
                          Size (bytes):16525
                          Entropy (8bit):5.386483451061953
                          Encrypted:false
                          SSDEEP:384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID
                          MD5:F49CA270724D610D1589E217EA78D6D1
                          SHA1:22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3
                          SHA-256:D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D
                          SHA-512:181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29
                          Malicious:false
                          Preview:SessionID=f1c78126-6a87-4f56-987d-4547733fd5ac.1696492435808 Timestamp=2023-10-05T09:53:55:808+0200 ThreadID=6044 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------".SessionID=f1c78126-6a87-4f56-987d-4547733fd5ac.1696492435808 Timestamp=2023-10-05T09:53:55:809+0200 ThreadID=6044 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found".SessionID=f1c78126-6a87-4f56-987d-4547733fd5ac.1696492435808 Timestamp=2023-10-05T09:53:55:809+0200 ThreadID=6044 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!".SessionID=f1c78126-6a87-4f56-987d-4547733fd5ac.1696492435808 Timestamp=2023-10-05T09:53:55:809+0200 ThreadID=6044 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1".SessionID=f1c78126-6a87-4f56-987d-4547733fd5ac.1696492435808 Timestamp=2023-10-05T09:53:55:809+0200 ThreadID=6044 Component=ngl-lib_NglAppLib Description="SetConfig:
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:ASCII text, with very long lines (393), with CRLF line terminators
                          Category:dropped
                          Size (bytes):15114
                          Entropy (8bit):5.3236914664707715
                          Encrypted:false
                          SSDEEP:384:sCA3oCxRc5drxgkdWs4+i4eXrk1NrU0OTIKmYwAZc3Loa2G+WBvl8D8dkVvdKX/Q:2Ke
                          MD5:4938BDD679A486714BCA64EA051ECCE1
                          SHA1:9D10A7D186ED32E92858A4958F8880E3D546E45B
                          SHA-256:01E5775323F8766EADFCC8D8B1A584C10AA1C185EDD8219789F258C560DD893F
                          SHA-512:4744605B6408C5D0DB1F74CD9F127DE2F2D93DF00C573BE165311EE680415A805D5D7A352F065A97E72FE0B8BB35F1C5F256766FAD06302FD292576941857150
                          Malicious:false
                          Preview:SessionID=e94120e1-d11a-4511-bacc-8e99e7bf0e28.1729783428375 Timestamp=2024-10-24T11:23:48:375-0400 ThreadID=6880 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------"..SessionID=e94120e1-d11a-4511-bacc-8e99e7bf0e28.1729783428375 Timestamp=2024-10-24T11:23:48:381-0400 ThreadID=6880 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found"..SessionID=e94120e1-d11a-4511-bacc-8e99e7bf0e28.1729783428375 Timestamp=2024-10-24T11:23:48:381-0400 ThreadID=6880 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!"..SessionID=e94120e1-d11a-4511-bacc-8e99e7bf0e28.1729783428375 Timestamp=2024-10-24T11:23:48:381-0400 ThreadID=6880 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1"..SessionID=e94120e1-d11a-4511-bacc-8e99e7bf0e28.1729783428375 Timestamp=2024-10-24T11:23:48:381-0400 ThreadID=6880 Component=ngl-lib_NglAppLib Description="SetConf
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          File Type:ASCII text, with CRLF line terminators
                          Category:dropped
                          Size (bytes):35721
                          Entropy (8bit):5.410056486704181
                          Encrypted:false
                          SSDEEP:768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRm/llxWlgtMsD+/b:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gR7
                          MD5:ACBCF8555277DAC27D172FA05B01B42B
                          SHA1:78CED2504D4CF06B1E7D2B7FD667F1E22CB98280
                          SHA-256:302958792912F831FB4228BFA86F750CB1E9DF919320D58C0CBCC8337389A858
                          SHA-512:E7B902325BD12A649D62EF6AE5CED4D43C76486657E472A27FC5F7FF861B9E4DD1D5C540249D5C83AF783CCAFA25F6F653AA1589BD3AE1882BE8FF9AFC65638F
                          Malicious:false
                          Preview:05-10-2023 08:41:17:.---2---..05-10-2023 08:41:17:.AcroNGL Integ ADC-4240758 : ***************************************..05-10-2023 08:41:17:.AcroNGL Integ ADC-4240758 : ***************************************..05-10-2023 08:41:17:.AcroNGL Integ ADC-4240758 : ******** Starting new session ********..05-10-2023 08:41:17:.AcroNGL Integ ADC-4240758 : Starting NGL..05-10-2023 08:41:17:.AcroNGL Integ ADC-4240758 : Setting synchronous launch...05-10-2023 08:41:17:.AcroNGL Integ ADC-4240758 ::::: Configuring as AcrobatReader1..05-10-2023 08:41:17:.AcroNGL Integ ADC-4240758 : NGLAppVersion 23.6.20320.6..05-10-2023 08:41:17:.AcroNGL Integ ADC-4240758 : NGLAppMode NGL_INIT..05-10-2023 08:41:17:.AcroNGL Integ ADC-4240758 : AcroCEFPath, NGLCEFWorkflowModulePath - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1 C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow..05-10-2023 08:41:17:.AcroNGL Integ ADC-4240758 : isNGLExternalBrowserDisabled - No..05-10-2023 08:41:17:.Closing File..05-10-
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 299538
                          Category:dropped
                          Size (bytes):758601
                          Entropy (8bit):7.98639316555857
                          Encrypted:false
                          SSDEEP:12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg
                          MD5:3A49135134665364308390AC398006F1
                          SHA1:28EF4CE5690BF8A9E048AF7D30688120DAC6F126
                          SHA-256:D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B
                          SHA-512:BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5
                          Malicious:false
                          Preview:...........kWT..0...W`.........b..@..nn........5.._..I.R3I..9g.x....s.\+.J......F...P......V]u......t....jK...C.fD..]..K....;......y._.U..}......S.........7...Q.............W.D..S.....y......%..=.....e..^.RG......L..].T.9.y.zqm.Q]..y..(......Q]..~~..}..q...@.T..xI.B.L.a.6...{..W..}.mK?u...5.#.{...n...........z....m^.6!.`.....u...eFa........N....o..hA-..s.N..B.q..{..z.{=..va4_`5Z........3.uG.n...+...t...z.M."2..x.-...DF..VtK.....o]b.Fp.>........c....,..t..an[............5.1.(}..q.q......K3.....[>..;e..f.Y.........mV.cL...]eF..7.e.<.._.o\.S..Z...`..}......>@......|.......ox.........h.......o....-Yj=.s.g.Cc\.i..\..A.B>.X..8`...P......[..O...-.g...r..u\...k..7..#E....N}...8.....(..0....w....j.......>.L....H.....y.x3...[>..t......0..z.qw..]X..i8..w.b..?0.wp..XH.A.[.....S..g.g..I.A.15.0?._n.Q.]..r8.....l..18...(.].m...!|G.1...... .3.`./....`~......G.............|..pS.e.C....:o.u_..oi.:..|....joi...eM.m.K...2%...Z..j...VUh..9.}.....
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 33081
                          Category:dropped
                          Size (bytes):1407294
                          Entropy (8bit):7.97605879016224
                          Encrypted:false
                          SSDEEP:24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo
                          MD5:A0CFC77914D9BFBDD8BC1B1154A7B364
                          SHA1:54962BFDF3797C95DC2A4C8B29E873743811AD30
                          SHA-256:81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685
                          SHA-512:74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE
                          Malicious:false
                          Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 5111142
                          Category:dropped
                          Size (bytes):1419751
                          Entropy (8bit):7.976496077007677
                          Encrypted:false
                          SSDEEP:24576:/xaWL07oSwYIGNPUGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JaWLxSwZG6GZn3mlind9i4ufFXpAXkru
                          MD5:C267C8C3D4A0DBACC06F3737E1784EB3
                          SHA1:D798A10176D979377257977E896C8D332B785F23
                          SHA-256:B5B5EF233AADF8F9C3509CDE98C7A9885D0E1B4938CD2A0676170BC8B30855F4
                          SHA-512:3C9CC6700F7827321C0DEADA8F8517F8BAAB6056AF3D7FDAA71BF258C58399EDFDA8601AEBAEEBAB36EF0B1F59BA3E9690EEC2ACD2B8E3A94C8A328261D55D16
                          Malicious:false
                          Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                          Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1311022
                          Category:dropped
                          Size (bytes):386528
                          Entropy (8bit):7.9736851559892425
                          Encrypted:false
                          SSDEEP:6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m
                          MD5:5C48B0AD2FEF800949466AE872E1F1E2
                          SHA1:337D617AE142815EDDACB48484628C1F16692A2F
                          SHA-256:F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE
                          SHA-512:44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324
                          Malicious:false
                          Preview:...........]s[G. Z...{....;...J$%K&..%.[..k...S....$,.`. )Z..m........a.......o..7.VfV...S..HY}Ba.<.NUVVV~W.].;qG4..b,N..#1.=1.#1..o.Fb.........IC.....Z...g_~.OO.l..g.uO...bY.,[..o.s.D<..W....w....?$4..+..%.[.?..h.w<.T.9.vM.!..h0......}..H..$[...lq,....>..K.)=..s.{.g.O...S9".....Q...#...+..)>=.....|6......<4W.'.U.j$....+..=9...l.....S..<.\.k.'....{.1<.?..<..uk.v;.7n.!...g....."P..4.U........c.KC..w._G..u..g./.g....{'^.-|..h#.g.\.PO.|...]x..Kf4..s..............+.Y.....@.K....zI..X......6e?[..u.g"{..h.vKbM<.?i6{%.q)i...v..<P8P3.......CW.fwd...{:@h...;........5..@.C.j.....a.. U.5...].$.L..wW....z...v.......".M.?c.......o..}.a.9..A..%V..o.d....'..|m.WC.....|.....e.[W.p.8...rm....^..x'......5!...|......z..#......X_..Gl..c..R..`...*.s-1f..]x......f...g...k........g....... ).3.B..{"4...!r....v+As...Zn.]K{.8[..M.r.Y..........+%...]...J}f]~}_..K....;.Z.[..V.&..g...>...{F..{I..@~.^.|P..G.R>....U..../HY...(.z.<.~.9OW.Sxo.Y
                          File type:PDF document, version 1.4, 2 pages
                          Entropy (8bit):7.831334950352108
                          TrID:
                          • Adobe Portable Document Format (5005/1) 100.00%
                          File name:AlisonMarshall.pdf
                          File size:29'799 bytes
                          MD5:0daf716d2a8903b2d4ea1d979fd8b496
                          SHA1:cd700bc3ee2c28c20ec178db9c6fa49d6083175d
                          SHA256:8938dbda5acf5d8870d745181731a016fe8fbafa881ea572f3a2b44ec3fd3992
                          SHA512:7ee342e1b2ecca616e1cc1f87e8e0619ff8695c6190b1fecd35c4bffacc40586ab63214b6a3237c0ec69ad86e8ec9b7f679a1213a043155d5345420bf4b8621b
                          SSDEEP:768:S/Lm47wiGE2k7tjpKHWUivL9SI/H5bVkSz2F/CpR5:U602k7tjpKH+wW5qWA6pf
                          TLSH:22D2BF36DDD51C9CF4E79F9B80AABC9F5C3CB2470BC46EDA70B80B148E05C816646A5B
                          File Content Preview:%PDF-1.4.1 0 obj.<<./Title (..)./Creator (..)./Producer (...Q.t. .5...5...1)./CreationDate (D:20241023204931).>>.endobj.2 0 obj.<<./Type /Catalog./Pages 3 0 R.>>.endobj.4 0 obj.<<./Type /ExtGState./SA true./SM 0.02./ca 1.0./CA 1.0./AIS false./SMask /None>
                          Icon Hash:62cc8caeb29e8ae0

                          General

                          Header:%PDF-1.4
                          Total Entropy:7.831335
                          Total Bytes:29799
                          Stream Entropy:7.946303
                          Stream Bytes:26482
                          Entropy outside Streams:5.074480
                          Bytes outside Streams:3317
                          Number of EOF found:1
                          Bytes after EOF:
                          NameCount
                          obj27
                          endobj27
                          stream6
                          endstream5
                          xref1
                          trailer1
                          startxref1
                          /Page2
                          /Encrypt0
                          /ObjStm0
                          /URI0
                          /JS0
                          /JavaScript0
                          /AA0
                          /OpenAction0
                          /AcroForm0
                          /JBIG2Decode0
                          /RichMedia0
                          /Launch0
                          /EmbeddedFile0
                          TimestampSource PortDest PortSource IPDest IP
                          Oct 24, 2024 17:23:59.216614962 CEST49734443192.168.2.796.7.168.138
                          Oct 24, 2024 17:23:59.216629982 CEST4434973496.7.168.138192.168.2.7
                          Oct 24, 2024 17:23:59.216811895 CEST49734443192.168.2.796.7.168.138
                          Oct 24, 2024 17:23:59.217027903 CEST49734443192.168.2.796.7.168.138
                          Oct 24, 2024 17:23:59.217035055 CEST4434973496.7.168.138192.168.2.7
                          Oct 24, 2024 17:23:59.934432983 CEST4434973496.7.168.138192.168.2.7
                          Oct 24, 2024 17:23:59.934813023 CEST49734443192.168.2.796.7.168.138
                          Oct 24, 2024 17:23:59.934823036 CEST4434973496.7.168.138192.168.2.7
                          Oct 24, 2024 17:23:59.935831070 CEST4434973496.7.168.138192.168.2.7
                          Oct 24, 2024 17:23:59.936024904 CEST49734443192.168.2.796.7.168.138
                          Oct 24, 2024 17:23:59.983603954 CEST49734443192.168.2.796.7.168.138
                          Oct 24, 2024 17:23:59.983774900 CEST4434973496.7.168.138192.168.2.7
                          Oct 24, 2024 17:23:59.983887911 CEST49734443192.168.2.796.7.168.138
                          Oct 24, 2024 17:23:59.983906984 CEST4434973496.7.168.138192.168.2.7
                          Oct 24, 2024 17:24:00.038863897 CEST49734443192.168.2.796.7.168.138
                          Oct 24, 2024 17:24:00.107778072 CEST4434973496.7.168.138192.168.2.7
                          Oct 24, 2024 17:24:00.108459949 CEST49734443192.168.2.796.7.168.138
                          Oct 24, 2024 17:24:00.108513117 CEST4434973496.7.168.138192.168.2.7
                          Oct 24, 2024 17:24:00.108659983 CEST4434973496.7.168.138192.168.2.7
                          Oct 24, 2024 17:24:00.108668089 CEST49734443192.168.2.796.7.168.138
                          Oct 24, 2024 17:24:00.108835936 CEST49734443192.168.2.796.7.168.138
                          TimestampSource PortDest PortSource IPDest IP
                          Oct 24, 2024 17:23:54.733517885 CEST5994453192.168.2.71.1.1.1
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Oct 24, 2024 17:23:54.733517885 CEST192.168.2.71.1.1.10xbb8Standard query (0)x1.i.lencr.orgA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Oct 24, 2024 17:23:54.741306067 CEST1.1.1.1192.168.2.70xbb8No error (0)x1.i.lencr.orgcrl.root-x1.letsencrypt.org.edgekey.netCNAME (Canonical name)IN (0x0001)false
                          Oct 24, 2024 17:23:55.648147106 CEST1.1.1.1192.168.2.70x1bc1No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                          Oct 24, 2024 17:23:55.648147106 CEST1.1.1.1192.168.2.70x1bc1No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                          • armmf.adobe.com
                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          0192.168.2.74973496.7.168.1384432256C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          TimestampBytes transferredDirectionData
                          2024-10-24 15:23:59 UTC475OUTGET /onboarding/smskillreader.txt HTTP/1.1
                          Host: armmf.adobe.com
                          Connection: keep-alive
                          Accept-Language: en-US,en;q=0.9
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36
                          Sec-Fetch-Site: same-origin
                          Sec-Fetch-Mode: no-cors
                          Sec-Fetch-Dest: empty
                          Accept-Encoding: gzip, deflate, br
                          If-None-Match: "78-5faa31cce96da"
                          If-Modified-Since: Mon, 01 May 2023 15:02:33 GMT
                          2024-10-24 15:24:00 UTC198INHTTP/1.1 304 Not Modified
                          Content-Type: text/plain; charset=UTF-8
                          Last-Modified: Mon, 01 May 2023 15:02:33 GMT
                          ETag: "78-5faa31cce96da"
                          Date: Thu, 24 Oct 2024 15:24:00 GMT
                          Connection: close


                          Click to jump to process

                          Click to jump to process

                          Click to dive into process behavior distribution

                          Click to jump to process

                          Target ID:0
                          Start time:11:23:44
                          Start date:24/10/2024
                          Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\AlisonMarshall.pdf"
                          Imagebase:0x7ff702560000
                          File size:5'641'176 bytes
                          MD5 hash:24EAD1C46A47022347DC0F05F6EFBB8C
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Target ID:4
                          Start time:11:23:45
                          Start date:24/10/2024
                          Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
                          Imagebase:0x7ff6c3ff0000
                          File size:3'581'912 bytes
                          MD5 hash:9B38E8E8B6DD9622D24B53E095C5D9BE
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Target ID:8
                          Start time:11:23:46
                          Start date:24/10/2024
                          Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2076 --field-trial-handle=1364,i,7330972416840462097,15245140379851579721,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
                          Imagebase:0x7ff6c3ff0000
                          File size:3'581'912 bytes
                          MD5 hash:9B38E8E8B6DD9622D24B53E095C5D9BE
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          No disassembly