Windows
Analysis Report
AlisonMarshall.pdf
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 2520 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\A lisonMarsh all.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 5764 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 2256 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 76 --field -trial-han dle=1364,i ,733097241 6840462097 ,152451403 7985157972 1,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 3 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 13 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.210.172 | true | false | unknown | |
x1.i.lencr.org | unknown | unknown | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
96.7.168.138 | unknown | United States | 262589 | INTERNEXABRASILOPERADORADETELECOMUNICACOESSABR | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1541311 |
Start date and time: | 2024-10-24 17:22:49 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 21 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | AlisonMarshall.pdf |
Detection: | CLEAN |
Classification: | clean2.winPDF@14/46@1/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 52.5.13.197, 54.227.187.23, 23.22.254.206, 52.202.204.11, 162.159.61.3, 172.64.41.3, 2.23.197.184, 199.232.210.172, 2.19.126.143, 2.19.126.149
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, time.windows.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: AlisonMarshall.pdf
Time | Type | Description |
---|---|---|
11:23:54 | API Interceptor |
Input | Output |
---|---|
URL: PDF document Model: claude-3-haiku-20240307 | ```json { "contains_trigger_text": true, "trigger_text": "Your video will get sent to all your contacts. The video is straight fire, and I can't even fathom the humiliation you'll face when your colleagues, friends, and fam see it. But hey, that's life, ain't it Don't be playing the victim here.", "prominent_button_name": "unknown", "text_input_field_labels": [ "Transfer Amount:", "My Bitcoin Address:" ], "pdf_icon_visible": false, "has_visible_captcha": false, "has_urgent_text": true, "has_visible_qrcode": false } |
URL: PDF document Model: claude-3-haiku-20240307 | ```json { "brands": [] } |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
96.7.168.138 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Meterpreter, ReflectiveLoader | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
bg.microsoft.map.fastly.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Codoso Ghost | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HtmlDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
INTERNEXABRASILOPERADORADETELECOMUNICACOESSABR | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Meterpreter, ReflectiveLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.238521045619185 |
Encrypted: | false |
SSDEEP: | 6:+6/WeLq2PcNwi2nKuAl9OmbnIFUt8t6/WVXZmw+t6/WNazkwOcNwi2nKuAl9Omb5:d/PvLZHAahFUt8c/sX/+c/8az54ZHAae |
MD5: | FAE9ABB8D6AE1676EEA4CB092AA32D8A |
SHA1: | 464C4BEA152D44969E677159D2583BB7DC2B1148 |
SHA-256: | 4DEB6C0B4C5ECEEDA6CA1AED2E631F3E79D0C6947510E93A3D677AD768484A8F |
SHA-512: | 2417BECE5C457979759235A27D79F641A91F75648E12FCE554FE3278E1D8711F42D122C680CE1BDD373B5BBA78478355422681D6C61C340E5768163126E4181B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.238521045619185 |
Encrypted: | false |
SSDEEP: | 6:+6/WeLq2PcNwi2nKuAl9OmbnIFUt8t6/WVXZmw+t6/WNazkwOcNwi2nKuAl9Omb5:d/PvLZHAahFUt8c/sX/+c/8az54ZHAae |
MD5: | FAE9ABB8D6AE1676EEA4CB092AA32D8A |
SHA1: | 464C4BEA152D44969E677159D2583BB7DC2B1148 |
SHA-256: | 4DEB6C0B4C5ECEEDA6CA1AED2E631F3E79D0C6947510E93A3D677AD768484A8F |
SHA-512: | 2417BECE5C457979759235A27D79F641A91F75648E12FCE554FE3278E1D8711F42D122C680CE1BDD373B5BBA78478355422681D6C61C340E5768163126E4181B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.211563690056017 |
Encrypted: | false |
SSDEEP: | 6:+6/WzFL/Iq2PcNwi2nKuAl9Ombzo2jMGIFUt8t6/WxFpFZZmw+t6/WxFpFzkwOc1:d/4FL/IvLZHAa8uFUt8c/AZ/+c/Az54y |
MD5: | 4134F243302513DB27EEFA95BCB8536F |
SHA1: | 23E4A0696EF3E0B43E3C5B85585E3989766C664F |
SHA-256: | 3CC66E38FD750C987EAEE600AFEA5D0543B1076BF73906682A54B49D50354DA0 |
SHA-512: | 2CB951E1ADAB808507E68E57CB2620A0D46A1278891B59C48BD8808BD3A7245211A43AFE064B163D002C0CF1EF2E085C938A0AA426B111F68BED90DD939CED38 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.211563690056017 |
Encrypted: | false |
SSDEEP: | 6:+6/WzFL/Iq2PcNwi2nKuAl9Ombzo2jMGIFUt8t6/WxFpFZZmw+t6/WxFpFzkwOc1:d/4FL/IvLZHAa8uFUt8c/AZ/+c/Az54y |
MD5: | 4134F243302513DB27EEFA95BCB8536F |
SHA1: | 23E4A0696EF3E0B43E3C5B85585E3989766C664F |
SHA-256: | 3CC66E38FD750C987EAEE600AFEA5D0543B1076BF73906682A54B49D50354DA0 |
SHA-512: | 2CB951E1ADAB808507E68E57CB2620A0D46A1278891B59C48BD8808BD3A7245211A43AFE064B163D002C0CF1EF2E085C938A0AA426B111F68BED90DD939CED38 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967056916756884 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqUjuksBdOg2Hvcaq3QYiubSpDyP7E4TX:Y2sRdskJdMHe3QYhbSpDa7n7 |
MD5: | 16FF9A5F20D1B5B99587E5027B043DBA |
SHA1: | EC9F335AE38264CBD609C11498A59B3E91C159F9 |
SHA-256: | 400A7C1E950AE99B4ECCF43BBDF0616E93EAE3D14B0B06D84E0CB70F704AA653 |
SHA-512: | 58A746B7DC4E4D41E9EF3949365D317E41AD6186726F89A614A9467C9C0F74652C3D753EE8463D6A865F3D38A6F445A670E97773BB814B51E801EDBB86D6299C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\d6f999eb-de21-4289-ad87-f127ebdbd442.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.967056916756884 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqUjuksBdOg2Hvcaq3QYiubSpDyP7E4TX:Y2sRdskJdMHe3QYhbSpDa7n7 |
MD5: | 16FF9A5F20D1B5B99587E5027B043DBA |
SHA1: | EC9F335AE38264CBD609C11498A59B3E91C159F9 |
SHA-256: | 400A7C1E950AE99B4ECCF43BBDF0616E93EAE3D14B0B06D84E0CB70F704AA653 |
SHA-512: | 58A746B7DC4E4D41E9EF3949365D317E41AD6186726F89A614A9467C9C0F74652C3D753EE8463D6A865F3D38A6F445A670E97773BB814B51E801EDBB86D6299C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4509 |
Entropy (8bit): | 5.239429679480636 |
Encrypted: | false |
SSDEEP: | 96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtPRy/PCACQ2/8Z:CwNw1GHqPySfkcigoO3h28ytP0/PCAzt |
MD5: | 2780C3602BAB264A824D078D3D8B043A |
SHA1: | 9BF3978E2053BDC47C61D5D407A3BAAB33EC35DE |
SHA-256: | 51CB5D5B0E9B96E3F9EC078931E26BADF01C9BB71620E37202EA49F33E9D12D8 |
SHA-512: | E1DB738331D2DC731F2D43BF9F0A69179E8BF04DC08838AC85176C5544F62204DC5E043F4DA5B8DC4F99654F10BF56D320612DFFF7D60C8E4ED2D6C40C0C9B5B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.1568968062515195 |
Encrypted: | false |
SSDEEP: | 6:+6/WsRNIq2PcNwi2nKuAl9OmbzNMxIFUt8t6/WsyZZmw+t6/WI3kwOcNwi2nKuAo:d/9RNIvLZHAa8jFUt8c/9G/+c/h354Zv |
MD5: | D2B0CBBA31BFD00E86A5E45725DB796C |
SHA1: | 1EBCA0B6C2947DE5D8BC486DF8DDC6E9D0A2468F |
SHA-256: | 3E3729F6B66723B764DCFBA2E8D940CEACFB2580386E055DB1D60B929B5B0B8E |
SHA-512: | 630F452A496F32F369B9A607BD53A2F67B760273E305122D8248B047766D44D4B6CF83F8EE4442B7431677A3CA641A9FA4D4DC7243C5000DFA00414467EF285C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.1568968062515195 |
Encrypted: | false |
SSDEEP: | 6:+6/WsRNIq2PcNwi2nKuAl9OmbzNMxIFUt8t6/WsyZZmw+t6/WI3kwOcNwi2nKuAo:d/9RNIvLZHAa8jFUt8c/9G/+c/h354Zv |
MD5: | D2B0CBBA31BFD00E86A5E45725DB796C |
SHA1: | 1EBCA0B6C2947DE5D8BC486DF8DDC6E9D0A2468F |
SHA-256: | 3E3729F6B66723B764DCFBA2E8D940CEACFB2580386E055DB1D60B929B5B0B8E |
SHA-512: | 630F452A496F32F369B9A607BD53A2F67B760273E305122D8248B047766D44D4B6CF83F8EE4442B7431677A3CA641A9FA4D4DC7243C5000DFA00414467EF285C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241024152350Z-169.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65110 |
Entropy (8bit): | 2.4850375426072993 |
Encrypted: | false |
SSDEEP: | 768:zhEF9aKkwCk3foucStyY3QKRUwhRbl8Y6OvcVP934RI:yfaxsPyECw7lz6Ovc5933 |
MD5: | D4976C0357F1C2BF3BFC45214D63064A |
SHA1: | 730C46DB4F21E8F0B0BBFFC95BA99F3609A71794 |
SHA-256: | 7016B238B8674A556189E86762C0FF4942A824E61B025238B77E7C727209B118 |
SHA-512: | A963258D6FE882201D3F1A51952F82E24C6EC8221180E6B86F8B41ECF5E745D2441BC056E0E8C18DC504FC1B4B9A4D52D9CC376006438EAF82590DB96E5786D6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.439114984227952 |
Encrypted: | false |
SSDEEP: | 384:yeaci5GsiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:1AurVgazUpUTTGt |
MD5: | 22541FA9610CBB97CF17B97199B6B762 |
SHA1: | 865A8C42B6C6894718F4A5BB7EAD7C100C3F1312 |
SHA-256: | B6135CC264FEF86A2FFA8D4066655CC6A1D310289E28C15AF102E91320C463CD |
SHA-512: | 13D53443881A75BE0CB9EA68088AE7C3F6E260EC853470C8790A764CAF4EF01922859F14DC7D626D552A86945DEFCA6CAECD4C3034474EEF9F773F51C9EAA22C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.773673864478678 |
Encrypted: | false |
SSDEEP: | 48:7MIp/E2ioyV/ioy3DoWoy1CABoy1PKOioy1noy1AYoy1Wioy1hioybioyfoy1noD:77pju/0iAhXKQGYb9IVXEBodRBkN |
MD5: | 621101D427C973ED8B648DF1BF16E6CF |
SHA1: | 370AA791847333E38D6DAB061F9D870C90C76C9E |
SHA-256: | 7FA18462A8A9F79017124F93C1C5BAC2E02EEA08737D31EDBF655CDEFE71E552 |
SHA-512: | 0CBAD4CB4738370FFD4DB384B4354235C3D85A85A5BBFCD0D16D48BB1AF324FEFD5311A448B61745F8237B546E6544ED7F4A958B36A17594047758EE7FD41D14 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.756901573172974 |
Encrypted: | false |
SSDEEP: | 3:kkFklpFvtfllXlE/HT8ksllXNNX8RolJuRdxLlGB9lQRYwpDdt:kKqveT8ZdNMa8RdWBwRd |
MD5: | 951BB10F85381854DE302C5F45EF25C8 |
SHA1: | 68C9E1B25DCACAE19CDDEAF22487E3ACF4C71FE1 |
SHA-256: | D347F2DC62EB43B81E75D5C83215AC959E5D7634A0992ED01EBCBCC21DD74741 |
SHA-512: | F1A3611E20DC59FF60660875B0A611905B01116B6869CBC6AB2821D30F85195E30DA3397230FB36353AAF017A43657D8FA06DC6F81C6B9B65303CA2EA25A5867 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.2418003062782916 |
Encrypted: | false |
SSDEEP: | 6:kK8L9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:FDImsLNkPlE99SNxAhUe/3 |
MD5: | DD87C410168A190D29C0925F10E6F524 |
SHA1: | 5A44199042BE403BA688557387A1C188911B3EF8 |
SHA-256: | 13313A0B0FDBFC4B53AF1D56CE931649EDBC384B9A459195167EFA8697D752C0 |
SHA-512: | 0795FCCDFE1F926CF5989D76603441285163EF0BA544159D817EAF29809C4EA8E6E433738D026133BE63A4F80D2C3DE9ECFA637CFC5BF379022C38B488307EC8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 227002 |
Entropy (8bit): | 3.392780893644728 |
Encrypted: | false |
SSDEEP: | 1536:qMKP+iyzDtrh1cK3XEivK7VK/3AYvYwgF/rRoL+sn:FKPoJ/3AYvYwglFoL+sn |
MD5: | C11248DE3EDEB5F39EE8D1E2C1FFE7D8 |
SHA1: | 7EC6B85BDB7C99BA691BB08A051EF7C4D4A43231 |
SHA-256: | 57612AEEE8F8E8471B730963F8E111C9890F83D8120380A6FF0676A3814A4B41 |
SHA-512: | E13FD658A42EE8BA3CDE3DE5912C3BF3F1A5D720D6C47C3FBCB9C529208DC2860A64B3C41F08660A76CAF5482CF8FDA5EEB62ACC719860AE05EE5C8369C24D9F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3623323422113085 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJM3g98kUwPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGMbLUkee9 |
MD5: | FF98DFECE8DC4DE0CBA3CD075F15AA01 |
SHA1: | 77C9F7EAEAE8CCC50F2DBE7C746F0C60A1D987EC |
SHA-256: | AD366ED845D6D18E43ECD6D18CAF93F02B029AD02A051643F301305ACB204F87 |
SHA-512: | EDB3A411C83D33FB26356303A3C748898AE324081491B7BF1BDC1B71F8E73FAE482AA8D31425AE11FAD7D5AF39206268698BD0ABF0830A94277F4716F64EAF5C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.293386530726487 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfBoTfXpnrPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGWTfXcUkee9 |
MD5: | 9FA58BEF05E8E426B66DBB213328EC2E |
SHA1: | 553513A7ADEB9835BEB5071654D34D6801AF047E |
SHA-256: | 053CA2ED1E9D5454DFECB3A0680B5554C1BE5E4A93B4CFC8FDFA3AD574AE6BBF |
SHA-512: | 2E8CF418C30A2FC09C276C3D63DEE0B0E71C6309B3BBB70580844ECAD897E94BE3E54BD103189AD5FCD09BE31D31B6403912F130FA064756BA5116A0A906D357 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.271420359617906 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfBD2G6UpnrPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGR22cUkee9 |
MD5: | C67B71D2C7748C3BE611E9312293F612 |
SHA1: | 489D81D63167CCCC374E2F9241915632BA876B6F |
SHA-256: | F012CD57E310A1354725EFC7627CBC5CBC97E1046432936492BAED0376BECB1B |
SHA-512: | 01E3F7A8BE6508B323CB8209791DE1BE9E11869AF2983DF5E120BDF9A47940DF4EF6090075AA1F0E55158A21EB67B196939B2D3A47E4ABC081FD1A664B21D5DC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.349174468379952 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfPmwrPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGH56Ukee9 |
MD5: | 1598184E269F2D41244B32F5C234197E |
SHA1: | 10FF1A90603055C53A3DAA3D7ADD9BFC847E1936 |
SHA-256: | 6938CF65F4FCD55B7E3B5424C5B8FA72B8DB9F0440392782A871A5D24D2955FF |
SHA-512: | 69309F200618CE1595C0E0724E43FE9B5FC8739BD51ED273DA1B0A7D7659CE07D3232B5C64C9E623295980DFA0EFC442458B095FD6D9C5D193650B33C6066F22 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1055 |
Entropy (8bit): | 5.663298780968814 |
Encrypted: | false |
SSDEEP: | 24:Yv6XSVbmeOvpLgEscLf7nnl0RCmK8czOCCSV:Yv4eshgGzaAh8cv/V |
MD5: | 421DB58F3BD9D122D699C1F06E3EDB98 |
SHA1: | 864BFF4F80DE4FFB5DBC837234A6699D1A5EF773 |
SHA-256: | 0EFE9BD17742972F934EA55BF0109C729195C942D7EE1F358EA6AA5AF6549256 |
SHA-512: | 9B15F1DD6A188E89C78F89BD8CDD0A9A03622B3758C1F37127F552B8B35041D2595D7E7136342221FFEA57AC72D8B5D98C69E5CC2BF5ABE97F8A5875E6FF3522 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1050 |
Entropy (8bit): | 5.654781561566843 |
Encrypted: | false |
SSDEEP: | 24:Yv6XSVbmeOzVLgEF0c7sbnl0RCmK8czOCYHflEpwiVk:Yv4eGFg6sGAh8cvYHWpwV |
MD5: | 61DB5720A61D1A20BE5C0A5CAFEA7005 |
SHA1: | 85ACE28539F5F9312E5B3527B1A9CAEDB80BEF19 |
SHA-256: | 30CDFA4B3730419F61136E4411258469E05D6A3A581DA0B4762D605B64C19385 |
SHA-512: | AB4F6FEAF95E79CECFD750CDFF758B53949CF8B01BE5F3574D56B0D95F225570D0122D7192D024F048184AE13DC5463E710AF2868D62F08D27D34F0FAF019979 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.290003922720311 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfQ1rPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGY16Ukee9 |
MD5: | 459A3B162BD7A9FCC66EB591A1B1BD2C |
SHA1: | C52E0FC15B5B6C4FDB86FF2DB388BAC16BD5548F |
SHA-256: | C4365A1FC2BB5037E93F05E4A2550D0667E5F0E0B5B54C215565A48331CFDB16 |
SHA-512: | EDA8DFBCBA81D1220BE3F53D011123AA4007786166F36352E5BB1EEF43C91D7E652C4F139FBAB16D52548B2A17FBB471BBFB6C23D206CDF3FDD3720A1E383A4F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1038 |
Entropy (8bit): | 5.655570213210326 |
Encrypted: | false |
SSDEEP: | 24:Yv6XSVbmeOC2LgEF7cciAXs0nl0RCmK8czOCAPtciBk:Yv4ezogc8hAh8cvAm |
MD5: | 69B1A15F46B154F7B639E7B7138AC46F |
SHA1: | 4D47C293482EE34F396DEB1B924BFAFF7AC5FB76 |
SHA-256: | 568D9D72067ECCE0B9BB49C0E0631C02D7747E0C5FFC958CFA5B97354BA255F6 |
SHA-512: | D9E8D845329A526BF2EC5C5EC04EE2BA111B9B56EE66C066E97645CEB517A3C9F43141800B92A32AB315C9A0DDA5386FC842A773D900EAF2C7D87673EBA562FE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1164 |
Entropy (8bit): | 5.703615438882712 |
Encrypted: | false |
SSDEEP: | 24:Yv6XSVbmeO+KLgEfIcZVSkpsn264rS514ZjBrwloJTmcVIsrSK5k:Yv4e/EgqprtrS5OZjSlwTmAfSKi |
MD5: | 575906F8FC888973211A451F365BFC10 |
SHA1: | 1F64CF750F761BB5C12DDA079B7B6D48DB0B3BE4 |
SHA-256: | 257ECADAFEFEB86E414F8CF6172B9731CC7513BADCE72E81E958D78D5B2072A3 |
SHA-512: | 23896A892019D5AE66A3405FE9481B7FE179331935F96C5DF7D5CEEEFF70578BAFBF6A4E358368EA2F1295FC07C60A91B67F4C1905365F6457F0C6D2470C9CA6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.294058487122437 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfYdPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGg8Ukee9 |
MD5: | C16692BBF685AFD8BE4DA2202F1706DE |
SHA1: | 21BA7BA8A50D340641BA34451191F36EF375E05D |
SHA-256: | C8B8D8B68B94A6D7ACE375E1DCDE7ECAC0E623E2C5CB4E2F8578A3091E2B1B91 |
SHA-512: | C046E39E655733EC405C46C6223EEF5EE8F604A238A0E6A4912172D8DAD86C21019E1FA14AF057B965BA50E7CBEB70090F164EC77FE7E28B27B7CC2DBFA295BF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1395 |
Entropy (8bit): | 5.776154003064308 |
Encrypted: | false |
SSDEEP: | 24:Yv6XSVbmeO1rLgEGOc93W2JeFmaR7CQzttgBcu141CjrWpHfRzVCV9FJNc:Yv4eCHgDv3W2aYQfgB5OUupHrQ9FJi |
MD5: | 8CBE050568F8294C7CC9B1711169947B |
SHA1: | EF91543FA594998471E886209B1EB88C697FD496 |
SHA-256: | 2965EB07D68186FA7FEDFE7C8132598AA5C12D59D6831F1E9A44B8F51F10EA2A |
SHA-512: | 89198394266EC0920015C51AB110030D2503E513D048CE48D0ADF3FB850FDDB956213F0D7F73B04570285BD53702F677C815963FE73735D9715158962862AE36 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.277646419936353 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfbPtdPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGDV8Ukee9 |
MD5: | 0B9BEE36BDA5375FA685FF87777E8BB8 |
SHA1: | 96EA5270E47035B96782AE2352B708073A0C30EF |
SHA-256: | 5FD64C31E1CE82556B133C004DFA3601E6DDE7306CF2605F197007168D7C1492 |
SHA-512: | AC5A271A6AE109053CCF2C2F70D260EAAC30DBCE891B5FA5B3475B9290A0196E2F1FDFC70FF96DE06768F7C97391C5608838767AAA7360328E29A97457C5A34C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.28190125255051 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJf21rPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VG+16Ukee9 |
MD5: | C4E9F284850A38E032BBDF0A9BC4D75B |
SHA1: | 307F242CD0A1901008E883D426065F606F2DFCA6 |
SHA-256: | D74881663FB02938263892BAFB9169776844C49EBB807D515A81998B781E65B4 |
SHA-512: | 5942ED6B259FC70A8839D7CE4F7CE24DDDA8A11D856B5EA5D23C08FAEE70E82E6E077CD931E351116DCF49519B83F72052A1656E069B7AA5C14557E28833A7AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1026 |
Entropy (8bit): | 5.633839858453574 |
Encrypted: | false |
SSDEEP: | 24:Yv6XSVbmeO3amXayLgE7cMCBNaqnl0RCmK8czOC/BSV:Yv4eeBgACBOAh8cvMV |
MD5: | 2285F28F03A46E3BE17ADFDA640D4672 |
SHA1: | 71D9088E95D739D90CE70F4EA79BCBAB6B93A5A2 |
SHA-256: | A6A4FF5E8968783C35425915101F2D0C9D43636F4C6074EAF99062D6E70B9BF6 |
SHA-512: | 1C94C7731F759A3E936C1FA1BC1409104721B52C24AF71A682D0E9804A754489F53B127F25AAF7EC15A49D9A22105B69FCA8962517C87630CE9373C06D5C0D0B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.260406734805295 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX6yRGbTHV4WsGiIPEeOF0Yri7eoAvJfshHHrPeUkwRe9:YvXKX6ygbTHVbsdTeOm7VGUUUkee9 |
MD5: | CCB764E209C612732B94DF4A08B6348C |
SHA1: | 264ACDC3CFD24C9B6807B6E6B8F908FC81598A1B |
SHA-256: | C6A4AC2BDC1B41CDEB54910A8BD0A8E7025CA6BAA715C3E619009D5A59AFC003 |
SHA-512: | CB69EF72FB629D6A8B5E0F3BEEB23DE5791A66D8909AA5114CD126186AD4D7E3418B49C15A930CC43549F8DCFB4076421DF15DADDFAC1DD2282818015ACDA442 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 782 |
Entropy (8bit): | 5.37690854290155 |
Encrypted: | false |
SSDEEP: | 12:YvXKX6ygbTHVbsdTeOm7VGTq16Ukee1+3CEJ1KXd15kcyKMQo7P70c0WM6ZB/uhV:Yv6XSVbmeOc168CgEXX5kcIfANhV |
MD5: | FDD7928DF2C14FFAC4AA0E75468A78EB |
SHA1: | B4EED54A44A8501EDA29431FC02EB6879903EE2E |
SHA-256: | B1DE9BE2B042D8EA228BA9158019031991909DCF83A7333012253C7ACADD3470 |
SHA-512: | FF47892FFB7CDF00A881EB14DAD1982D4EEA691F959971BEBE7DB362D519D060F828B814DF8443DDABA75CC056A37978E631A24EBE2F97F7C4B3B33A0B21D998 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2818 |
Entropy (8bit): | 5.137994629973526 |
Encrypted: | false |
SSDEEP: | 24:YTF9aAazOumaykWJMkpCtSv75RKG5ZxdDdC5Fj8LGj0SnFgT2FIm2LShNgk5r9oy:YgWnOwFwIXDUD8cEmrqkd99X |
MD5: | 4E9B4A74B7E3B05C180BC959974D2B42 |
SHA1: | 877ADA5F03A1E7C6C8FCAD79854AA0725D4D5710 |
SHA-256: | 920F3F04AE67660C07ACD4F2A1A863D33AB54D341C891C5C1C151CF1279549F3 |
SHA-512: | 3CDB86D31A78BFC241E9322D6604E0042ECF64D325847D238E2472A042BF3EE2A8AC5074B9C99FDC4B5E7C4AD7A3A613FA766E5FB826DA93745E113FCD04D581 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.453972295270802 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsLFllZ:lNVmsw3SHtbDbPe0K3+fDZdM |
MD5: | D2945AA9F2D815AD22386A4A84297C5F |
SHA1: | 5B45180A92D7844E3D2DFE0ED3188C4EDB0F7148 |
SHA-256: | 4AD7CF8309F074E53BCDA1F6B4E7FC7B8BC71141186F4124927653CA134D90ED |
SHA-512: | F8378B10F39081C420077DC3243904A1B26244483E63FDD0EB5DF73D6CB6E6733E9BC0B61CCEDF2CAD45AB80D7291ED4F3F026633A53F183B7369A6B68125558 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.9596167064158574 |
Encrypted: | false |
SSDEEP: | 48:7M/rvrBd6dHtbGIbPe0K3+fDy2dsLQrqFl2GL7ms1:7y3SHtbDbPe0K3+fDZddKVms1 |
MD5: | FF20E3D4517F124397A488D76D8EF6AD |
SHA1: | DD3EAA80295E2606F9D8CF3B3F8E82D2C2201D50 |
SHA-256: | 60A31A159A30CEC7374D2410B6ED75E2DD9E058970E7A18255BEC41E305C8F38 |
SHA-512: | 2D28631FCF1978230A49EE4E2048F255EE1B2AB50E976621605774DC152195DC4E961C18A0A1752D50DCF72614517E06D4EF8406653A6792885C0728CC44DAFE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.512793808211959 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8cjqZH:Qw946cPbiOxDlbYnuRKHe |
MD5: | F4CCB36665CB272AF29B57CBF8253DCF |
SHA1: | C96B7A33414167A1837AB5BD5D8163ADAF5A42E6 |
SHA-256: | 67EC8061E31DB575BBFE6BB68CE8470DBA0B161FBF94B9228274D07ECEB9A972 |
SHA-512: | 3AF7E95F78B0F8D7EC9080AF471EC0515A613DB9CE29DF63D423572EEAC16FC9A1AEC51F238A47379D35EC7EB6FEEDA3861C7E838A8AD643D553728347270EF9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 358 |
Entropy (8bit): | 5.074341916757025 |
Encrypted: | false |
SSDEEP: | 6:IngVMrexJzJT0y9VEQIFVmb/eu2g/86S1kxROOsVos+kmVos+VLCSyAAO:IngVMre9T0HQIDmy9g06JXEoFkmVoFBR |
MD5: | 0802A8C752F694D540F21CD8135BF352 |
SHA1: | 3856FDE80102A4D6F897788E34A5BBB40B41D540 |
SHA-256: | 6600CFFC66A61B416DA44218A1D04EEE2473A0F64611FFA422A508422F097616 |
SHA-512: | B04A83ED59B578A32A0EAA65C069264A6F6B4BBA33681A0BB615A126ED0D1408A964392E1742E89ED5CC44C8D08984FBCF601A4E03C4A8B298175C7192585B89 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-10-24 11-23-48-356.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.386483451061953 |
Encrypted: | false |
SSDEEP: | 384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID |
MD5: | F49CA270724D610D1589E217EA78D6D1 |
SHA1: | 22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3 |
SHA-256: | D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D |
SHA-512: | 181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.3236914664707715 |
Encrypted: | false |
SSDEEP: | 384:sCA3oCxRc5drxgkdWs4+i4eXrk1NrU0OTIKmYwAZc3Loa2G+WBvl8D8dkVvdKX/Q:2Ke |
MD5: | 4938BDD679A486714BCA64EA051ECCE1 |
SHA1: | 9D10A7D186ED32E92858A4958F8880E3D546E45B |
SHA-256: | 01E5775323F8766EADFCC8D8B1A584C10AA1C185EDD8219789F258C560DD893F |
SHA-512: | 4744605B6408C5D0DB1F74CD9F127DE2F2D93DF00C573BE165311EE680415A805D5D7A352F065A97E72FE0B8BB35F1C5F256766FAD06302FD292576941857150 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.410056486704181 |
Encrypted: | false |
SSDEEP: | 768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRm/llxWlgtMsD+/b:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gR7 |
MD5: | ACBCF8555277DAC27D172FA05B01B42B |
SHA1: | 78CED2504D4CF06B1E7D2B7FD667F1E22CB98280 |
SHA-256: | 302958792912F831FB4228BFA86F750CB1E9DF919320D58C0CBCC8337389A858 |
SHA-512: | E7B902325BD12A649D62EF6AE5CED4D43C76486657E472A27FC5F7FF861B9E4DD1D5C540249D5C83AF783CCAFA25F6F653AA1589BD3AE1882BE8FF9AFC65638F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xaWL07oSwYIGNPUGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JaWLxSwZG6GZn3mlind9i4ufFXpAXkru |
MD5: | C267C8C3D4A0DBACC06F3737E1784EB3 |
SHA1: | D798A10176D979377257977E896C8D332B785F23 |
SHA-256: | B5B5EF233AADF8F9C3509CDE98C7A9885D0E1B4938CD2A0676170BC8B30855F4 |
SHA-512: | 3C9CC6700F7827321C0DEADA8F8517F8BAAB6056AF3D7FDAA71BF258C58399EDFDA8601AEBAEEBAB36EF0B1F59BA3E9690EEC2ACD2B8E3A94C8A328261D55D16 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.831334950352108 |
TrID: |
|
File name: | AlisonMarshall.pdf |
File size: | 29'799 bytes |
MD5: | 0daf716d2a8903b2d4ea1d979fd8b496 |
SHA1: | cd700bc3ee2c28c20ec178db9c6fa49d6083175d |
SHA256: | 8938dbda5acf5d8870d745181731a016fe8fbafa881ea572f3a2b44ec3fd3992 |
SHA512: | 7ee342e1b2ecca616e1cc1f87e8e0619ff8695c6190b1fecd35c4bffacc40586ab63214b6a3237c0ec69ad86e8ec9b7f679a1213a043155d5345420bf4b8621b |
SSDEEP: | 768:S/Lm47wiGE2k7tjpKHWUivL9SI/H5bVkSz2F/CpR5:U602k7tjpKH+wW5qWA6pf |
TLSH: | 22D2BF36DDD51C9CF4E79F9B80AABC9F5C3CB2470BC46EDA70B80B148E05C816646A5B |
File Content Preview: | %PDF-1.4.1 0 obj.<<./Title (..)./Creator (..)./Producer (...Q.t. .5...5...1)./CreationDate (D:20241023204931).>>.endobj.2 0 obj.<<./Type /Catalog./Pages 3 0 R.>>.endobj.4 0 obj.<<./Type /ExtGState./SA true./SM 0.02./ca 1.0./CA 1.0./AIS false./SMask /None> |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.4 |
Total Entropy: | 7.831335 |
Total Bytes: | 29799 |
Stream Entropy: | 7.946303 |
Stream Bytes: | 26482 |
Entropy outside Streams: | 5.074480 |
Bytes outside Streams: | 3317 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 27 |
endobj | 27 |
stream | 6 |
endstream | 5 |
xref | 1 |
trailer | 1 |
startxref | 1 |
/Page | 2 |
/Encrypt | 0 |
/ObjStm | 0 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 24, 2024 17:23:59.216614962 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Oct 24, 2024 17:23:59.216629982 CEST | 443 | 49734 | 96.7.168.138 | 192.168.2.7 |
Oct 24, 2024 17:23:59.216811895 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Oct 24, 2024 17:23:59.217027903 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Oct 24, 2024 17:23:59.217035055 CEST | 443 | 49734 | 96.7.168.138 | 192.168.2.7 |
Oct 24, 2024 17:23:59.934432983 CEST | 443 | 49734 | 96.7.168.138 | 192.168.2.7 |
Oct 24, 2024 17:23:59.934813023 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Oct 24, 2024 17:23:59.934823036 CEST | 443 | 49734 | 96.7.168.138 | 192.168.2.7 |
Oct 24, 2024 17:23:59.935831070 CEST | 443 | 49734 | 96.7.168.138 | 192.168.2.7 |
Oct 24, 2024 17:23:59.936024904 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Oct 24, 2024 17:23:59.983603954 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Oct 24, 2024 17:23:59.983774900 CEST | 443 | 49734 | 96.7.168.138 | 192.168.2.7 |
Oct 24, 2024 17:23:59.983887911 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Oct 24, 2024 17:23:59.983906984 CEST | 443 | 49734 | 96.7.168.138 | 192.168.2.7 |
Oct 24, 2024 17:24:00.038863897 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Oct 24, 2024 17:24:00.107778072 CEST | 443 | 49734 | 96.7.168.138 | 192.168.2.7 |
Oct 24, 2024 17:24:00.108459949 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Oct 24, 2024 17:24:00.108513117 CEST | 443 | 49734 | 96.7.168.138 | 192.168.2.7 |
Oct 24, 2024 17:24:00.108659983 CEST | 443 | 49734 | 96.7.168.138 | 192.168.2.7 |
Oct 24, 2024 17:24:00.108668089 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Oct 24, 2024 17:24:00.108835936 CEST | 49734 | 443 | 192.168.2.7 | 96.7.168.138 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 24, 2024 17:23:54.733517885 CEST | 59944 | 53 | 192.168.2.7 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 24, 2024 17:23:54.733517885 CEST | 192.168.2.7 | 1.1.1.1 | 0xbb8 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 24, 2024 17:23:54.741306067 CEST | 1.1.1.1 | 192.168.2.7 | 0xbb8 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 24, 2024 17:23:55.648147106 CEST | 1.1.1.1 | 192.168.2.7 | 0x1bc1 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 17:23:55.648147106 CEST | 1.1.1.1 | 192.168.2.7 | 0x1bc1 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49734 | 96.7.168.138 | 443 | 2256 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-24 15:23:59 UTC | 475 | OUT | |
2024-10-24 15:24:00 UTC | 198 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:23:44 |
Start date: | 24/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702560000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:23:45 |
Start date: | 24/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 11:23:46 |
Start date: | 24/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |