Windows Analysis Report
Request for corporate Gifts.pdf

Overview

General Information

Sample name: Request for corporate Gifts.pdf
Analysis ID: 1541325
MD5: f1609805b3682c3a139a3425e3ac561b
SHA1: 2a4f73342591567e62e7d4523e83e3210b5ebf68
SHA256: 7431804982501ebd1d190f322c85cf022db6bcd47fd94ee807171763164f08b5
Infos:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: ReaderMessages.0.dr String found in binary or memory: http://www.adobe.
Source: classification engine Classification label: clean0.winPDF@2/6@0/0
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe File created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe File created: C:\Users\user\AppData\Local\Temp\acrord32_sbx\A91p164vk_1d9xjg7_58c.tmp Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA Jump to behavior
Source: unknown Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\user\Desktop\Request for corporate Gifts.pdf"
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: unknown unknown Jump to behavior
Source: Request for corporate Gifts.pdf Initial sample: PDF keyword /JS count = 0
Source: Request for corporate Gifts.pdf Initial sample: PDF keyword /JavaScript count = 0
Source: Request for corporate Gifts.pdf Initial sample: PDF keyword stream count = 47
Source: Request for corporate Gifts.pdf Initial sample: PDF keyword /EmbeddedFile count = 0
Source: Request for corporate Gifts.pdf Initial sample: PDF keyword obj count = 50
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process information queried: ProcessInformation Jump to behavior
No contacted IP infos