Windows
Analysis Report
OFICIO SMEG.pdf
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 4276 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\O FICIO SMEG .pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 4124 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6552 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 12 --field -trial-han dle=1608,i ,167965271 8213647617 0,62936935 1464493109 2,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1544490 |
Start date and time: | 2024-10-29 13:52:20 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 13s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | OFICIO SMEG.pdf |
Detection: | CLEAN |
Classification: | clean0.winPDF@14/32@0/0 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 52.5.13.197, 23.22.254.206, 52.202.204.11, 54.227.187.23, 172.64.41.3, 162.159.61.3, 199.232.210.172, 2.23.197.184, 88.221.168.141, 2.19.126.143, 2.19.126.149, 192.168.2.8, 23.47.194.65, 88.221.110.91, 2.16.100.168
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, e4578.dscb.akamaiedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, a767.dspw65.akamai.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, ssl.adobe.com.edgekey.net, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: OFICIO SMEG.pdf
Time | Type | Description |
---|---|---|
08:53:35 | API Interceptor |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.24296582160523 |
Encrypted: | false |
SSDEEP: | 6:ctW6Q+q2PCHhJ2nKuAl9OmbnIFUt8Ht1vwgZmw+Hti6QVkwOCHhJ2nKuAl9Ombjd:iWGvBHAahFUt8NX/+Nit56HAaSJ |
MD5: | 3DEB2E7E9A67C0F23D05FC1575662B9E |
SHA1: | 9D499027DF3BFB862724101AF9EDF73C77D3BE13 |
SHA-256: | DA8C4947525C4A5706F50C2476E21EA211683DB05EA8D80B0AF5EB19C21A3205 |
SHA-512: | 10227BC1B6F6D8637BEEB3842706EE1B0FA616C238F63E61A4B49B4A3C842061D5A7D1356A6E42B1C2EB2D99DFD066D93C6D2F997B79AD01878FC99E9668E5DE |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.24296582160523 |
Encrypted: | false |
SSDEEP: | 6:ctW6Q+q2PCHhJ2nKuAl9OmbnIFUt8Ht1vwgZmw+Hti6QVkwOCHhJ2nKuAl9Ombjd:iWGvBHAahFUt8NX/+Nit56HAaSJ |
MD5: | 3DEB2E7E9A67C0F23D05FC1575662B9E |
SHA1: | 9D499027DF3BFB862724101AF9EDF73C77D3BE13 |
SHA-256: | DA8C4947525C4A5706F50C2476E21EA211683DB05EA8D80B0AF5EB19C21A3205 |
SHA-512: | 10227BC1B6F6D8637BEEB3842706EE1B0FA616C238F63E61A4B49B4A3C842061D5A7D1356A6E42B1C2EB2D99DFD066D93C6D2F997B79AD01878FC99E9668E5DE |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 335 |
Entropy (8bit): | 5.214771872156734 |
Encrypted: | false |
SSDEEP: | 6:ctcE+q2PCHhJ2nKuAl9Ombzo2jMGIFUt8HtPZZmw+HtPNVkwOCHhJ2nKuAl9OmbX:iSvBHAa8uFUt8NB/+Nb56HAa8RJ |
MD5: | 8ED658E905EBB842EE9F78C6B4580624 |
SHA1: | D7F0D83C70025BFDD80F9E0AA169FDBFB8E1749F |
SHA-256: | 076A7EA0D5076C5A32289254CADD7F322962CBE95506ACD53630C0DD5D6C11F8 |
SHA-512: | 72D1682D797BFDD036A713B71E22615C1BB65A928B84F4B636BBC9442D13D136CE6E29D34DACBCA685C5B09F1918DA3DEA77833FE4464EE15194271FB3996247 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 335 |
Entropy (8bit): | 5.214771872156734 |
Encrypted: | false |
SSDEEP: | 6:ctcE+q2PCHhJ2nKuAl9Ombzo2jMGIFUt8HtPZZmw+HtPNVkwOCHhJ2nKuAl9OmbX:iSvBHAa8uFUt8NB/+Nb56HAa8RJ |
MD5: | 8ED658E905EBB842EE9F78C6B4580624 |
SHA1: | D7F0D83C70025BFDD80F9E0AA169FDBFB8E1749F |
SHA-256: | 076A7EA0D5076C5A32289254CADD7F322962CBE95506ACD53630C0DD5D6C11F8 |
SHA-512: | 72D1682D797BFDD036A713B71E22615C1BB65A928B84F4B636BBC9442D13D136CE6E29D34DACBCA685C5B09F1918DA3DEA77833FE4464EE15194271FB3996247 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\9d737c9c-4094-414f-a076-ac14670e67a7.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.975824910517686 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqlhsBdOg2H4pHgcaq3QYiub6P7E4T3y:Y2sRdsmydMHW3QYhbS7nby |
MD5: | 7813166B51ECB56F3C6639C99DD286E5 |
SHA1: | 7F7015504A747B3FB32B483624EA5EB7DDAD96C7 |
SHA-256: | 8A9195368DB8DFF42AD6AD796357CE443464C32B71919676189FAF9F123B712E |
SHA-512: | 90F841490D0DFD6C241EC5F7520A93693FB4A0488B4C0327D9383EACE4E4975BB5EA289C35CCAD983AD96B414A5309AC3285C800DA2D4B9FB7647A7907F1B33D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.975824910517686 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqlhsBdOg2H4pHgcaq3QYiub6P7E4T3y:Y2sRdsmydMHW3QYhbS7nby |
MD5: | 7813166B51ECB56F3C6639C99DD286E5 |
SHA1: | 7F7015504A747B3FB32B483624EA5EB7DDAD96C7 |
SHA-256: | 8A9195368DB8DFF42AD6AD796357CE443464C32B71919676189FAF9F123B712E |
SHA-512: | 90F841490D0DFD6C241EC5F7520A93693FB4A0488B4C0327D9383EACE4E4975BB5EA289C35CCAD983AD96B414A5309AC3285C800DA2D4B9FB7647A7907F1B33D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4288 |
Entropy (8bit): | 5.2264436026583985 |
Encrypted: | false |
SSDEEP: | 96:S4bz5vsZ4CzSAsfTxiVud4TxY0CIOr3MCWO3VxBaw+bO/vDHsDgZ:S43C4mS7fFi0KFYDjr3LWO3V3aw+bO/3 |
MD5: | ACEC24EF607EF78282812086C66E24D6 |
SHA1: | 6685DD7EE8A036338073A4B51FD2D3CF46F61104 |
SHA-256: | 53491588AD5DFE7CB87A46B0117F49D3C7C24F1205777A213F26C6DDB1BDBB73 |
SHA-512: | B11AF8D0025D2E877D0831C227254F19B2A9A2CAF8CE9129F0C60A046C67E4341138FEFFE4EAF2A6639F0CF38992811967B9131D35B57340FCBA56BD6343346A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 323 |
Entropy (8bit): | 5.244675023952448 |
Encrypted: | false |
SSDEEP: | 6:ctavt+q2PCHhJ2nKuAl9OmbzNMxIFUt8HttZmw+HtY/NVkwOCHhJ2nKuAl9OmbzE:iaQvBHAa8jFUt8Nt/+N2z56HAa84J |
MD5: | 8871D048BC586E61B6DA452881217DDC |
SHA1: | 49E9F3067E5080D353A1B452B3FC402DC634AB5A |
SHA-256: | C7448F2B29CE489D1A6C1C4B6B358F66F1D0C446E325D83B3C35E1166BE2EEEE |
SHA-512: | 6AD6B9A59B3B19E68306CEC17871B0FF6F99CC73849AF70DE498C8114D4B8CA6982E8E3CB088E7283D1DDDE8419858AA9CA8A0CB406B40CA47955BC889CCAD97 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 323 |
Entropy (8bit): | 5.244675023952448 |
Encrypted: | false |
SSDEEP: | 6:ctavt+q2PCHhJ2nKuAl9OmbzNMxIFUt8HttZmw+HtY/NVkwOCHhJ2nKuAl9OmbzE:iaQvBHAa8jFUt8Nt/+N2z56HAa84J |
MD5: | 8871D048BC586E61B6DA452881217DDC |
SHA1: | 49E9F3067E5080D353A1B452B3FC402DC634AB5A |
SHA-256: | C7448F2B29CE489D1A6C1C4B6B358F66F1D0C446E325D83B3C35E1166BE2EEEE |
SHA-512: | 6AD6B9A59B3B19E68306CEC17871B0FF6F99CC73849AF70DE498C8114D4B8CA6982E8E3CB088E7283D1DDDE8419858AA9CA8A0CB406B40CA47955BC889CCAD97 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241029125327Z-173.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65110 |
Entropy (8bit): | 1.7541674312795401 |
Encrypted: | false |
SSDEEP: | 96:WAj7VF0LKY7CxiBmT8MYxfdb1OgqMJJbMZU9JkgC+EMRem6Yv6jUldMMMMM7MNeX:/eC6fdbRFec/ApPXCrojxcr2frBl |
MD5: | 6628D52746998AE2E3EBC68D4BA21F4D |
SHA1: | EAB5A182C983A14A26B6EA6452B30FE085E3B6A3 |
SHA-256: | E0352C20C19AD607ED3C54F99D16CA2CFDC5A1CD1D99502DAD8F96A8C3DBE1F5 |
SHA-512: | E1BD5608B3050D4C73C6547531FE0A899A1F5EC643AA7E07689BD07AD715515DAE71DD962A65B245C8061804BD976AB118CD0312C9C696F3989BA8421964F083 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.29379800543989 |
Encrypted: | false |
SSDEEP: | 192:PedRBuVui5V4R4dcQ5V4R4RtYWtEV2UUTTchqGp8F/7/z+FP:Pekci5H5FY+EUUUTTcHqFzqFP |
MD5: | 22F6BC4888704F6E46A0B09B03C59C5A |
SHA1: | 044E6280D6557E1AD3AD2886FB34AB5E96398BDE |
SHA-256: | BBE48B967969B74A37AD99651E72568A9E4E49BB2584F5370715CD009917BA0D |
SHA-512: | C11FD5A28BEEA4D8E1258C2A0A84509B1C061BCCC90F19ED41D76589DFA9A0CEAC3B3CB0519ECE49B2CD300503E6F18E695B14E88A6DC9F58B9A87DA59A2F992 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.213957546475127 |
Encrypted: | false |
SSDEEP: | 24:7+t9dMwKnqLKzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mzb:7MD0nqOmFTIF3XmHjBoGGR+jMz+LhK |
MD5: | 9D0098C778CEA494FFE33C4A329FC8C0 |
SHA1: | 094D91C65DB6D3C5C5FD17C1B0DFF37C2BEFB2FC |
SHA-256: | D49C74C6031A6B0E38C030166D09B9C0C089F3A9D6963ADA786F64D94612AB23 |
SHA-512: | 644A4833422B93F19FF7437137CEA96526AAD3C77E2CCB43DBE13407974B30453806CC36A48362EEE75A0E21D1E7549178B1D0F41F07FEE681441B2EA8F63B08 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.73533016978716 |
Encrypted: | false |
SSDEEP: | 3:kkFkl3B53l1fllXlE/HT8ktFhlltNNX8RolJuRdxLlGB9lQRYwpDdt:kKzT8kFRNMa8RdWBwRd |
MD5: | 5D423B7A12B290A66D98C6C103CB1AEC |
SHA1: | 15B4ADB6EA5F84660F183EF91DC0AF3D69B745BA |
SHA-256: | 6407193517E2AAB00AD8A5DF21F9343D24E87644A0E7FC2ACEDA7DEC7A23BB40 |
SHA-512: | 4B80404C7B6AF95696E1098947EF8D8048516BDB769A0998FE4C40715471708B7E2816B7318945A7812FF6BEB5891DB2537761D243BD49900BC555421504578A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.2407377588831796 |
Encrypted: | false |
SSDEEP: | 6:kKM9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:HDImsLNkPlE99SNxAhUe/3 |
MD5: | 24CE3237FA8B749C80D8F6C5C790F86D |
SHA1: | DC0772972EE3AE0CD8E977FAADA810E9E487D3F1 |
SHA-256: | 4A17B05EC280BBCD7F18B9E71BAD8B623C434ECDB7922890970D5A4824490025 |
SHA-512: | 47C722488ADF499035762E05BA107D4ED852AB7C242ECCB1B621086A032B738726402F271A9E054A216823320D991A5460580360D2AB7076BD693D3FACDB67C8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2145 |
Entropy (8bit): | 5.07046401025013 |
Encrypted: | false |
SSDEEP: | 48:Y5o+eHIYH8TFSGTFXwiTFgCTF3bTFDL0ToT3UTpNMaTN:hhoJLWNMu |
MD5: | 53C814AC6A89DB079E2304041D3CA439 |
SHA1: | D180E325072CFDF3E0DD7726904DA3AED3033553 |
SHA-256: | B00C7D1079233D0B0173E0BD50502E837C00736093BA52E3AD5AD0288ACB4D77 |
SHA-512: | 525FA830959DC04D28C13699D67345C2473B72FE79011519C7A0DB996C0F826273D20A0F7FCC0278A081A3AF464C960DF32631CC3A19DB3522A4E3914ACAC1C8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.320286232351537 |
Encrypted: | false |
SSDEEP: | 24:TLKufx/XYKQvGJF7urs9Ohn07oz7oF0Hl0FopUEiP66UEiPbnPnNknNMeotqVpaD:TGufl2GL7ms9WR1CPmPbPahSypilIW |
MD5: | 9F01CD3E33B2A78CEF40ECD7AF8A5F90 |
SHA1: | D5D9A24AEFCEF377FB3A2EB7EA03E6FAC0ABD590 |
SHA-256: | 9A4CB9D372344AF35E16754B9ACE9DC6E8D9DF9B877F70BDE4F10DDFAA0D5C2E |
SHA-512: | 4FDD01234477B18C33CED45EFA603E5FCB2A11DF20B1D944D5AD1CBE0C6B121B7B83350268D59145787AC257B4C4365198BACFF99DA1C929B910C93C2E2D16A3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.781169568137311 |
Encrypted: | false |
SSDEEP: | 24:7+tSlhn07oz7oF0Hl0FopUEiP66UEiPbnPnNknNMeo4qVpaVrScVr0InuZqLhx/c:7MZWR1CPmPbPahTypilINZqFl2GL7msS |
MD5: | 164A2E62D086CD05A2A772CB08B9D00E |
SHA1: | 3E5C7E7098D6FBDC01E8CFE3BB6CA0156C1BA8A9 |
SHA-256: | 5E6E14133D735CC22BA28CF944926AC91EA5276F3EBF7A4E533BB9BE902D2429 |
SHA-512: | 9F88633689EF6F3338FE2B92E49513BB60420DAB7E047E3BFB753E1C8BF1C3BA191EF8518949010114C6CC024F7A5322BCAEF68031C69ECA2B32E1FA8A8B82BB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5390718303530573 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8xOlQklW6wlYH:Qw946cPbiOxDlbYnuRK58lYH |
MD5: | 05780D439E5C19539F70B0E7558CCB49 |
SHA1: | CB1E1B5B57F0081A2CDA2F57479EFFE09FABE3CB |
SHA-256: | 0B9A20E139C4FA9A7B541728F0A6DE43C7FB5BCCBC96AA32D86196A46BA6FAE7 |
SHA-512: | 7E66475B1C15A3A9D1C1DE9081D4C246B2067C265BDB84965D043046A75FB3095D6613C11B26203507D9E86B6253A886936863A920B4B92D7DF7DCE8FC37D9DD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-10-29 08-53-24-918.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.33860678500249 |
Encrypted: | false |
SSDEEP: | 384:IC2heaVGJMUPhP80d0Wc+9eG/CCihFomva7RVRkfKhZmWWyC7rjgNgXo6ge5iaW0:X8B |
MD5: | C3FEDB046D1699616E22C50131AAF109 |
SHA1: | C9EEA5A1A16BD2CD8154E8C308C8A336E990CA8D |
SHA-256: | EA948BAC75D609B74084113392C9F0615D447B7F4AACA78D818205503EACC3FD |
SHA-512: | 845CDB5166B35B39215A051144452BEF9161FFD735B3F8BD232FB9A7588BA016F7939D91B62E27D6728686DFA181EFC3F3CC9954B2EDAB7FC73FCCE850915185 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.377493142314839 |
Encrypted: | false |
SSDEEP: | 384:5kzNkMBkMUkM5kMdkMYkM2skMEkMHk5nk5ik58k5Nk5q7k5gkqKkjD8kjD6kjD0N:5uH+HHiUsulQbxMv7DSXpNTTcrF8i2MK |
MD5: | A4483C1821E1F2CC176CA5A3600D5E38 |
SHA1: | 406026F5016A4B2C7F2E4E968ABF708762E06185 |
SHA-256: | BF194AC2B71CFCD3FE3FA34315F7F3CFDFC60978E474D7CFEE14138ACBB11E01 |
SHA-512: | 0117EBBE8BC98224D771667D5C1C40453D50477CAFDF27D491F9DD525D04902629DD4DEE533DD0FAD0412F54CBCA3012A44442EEF7D22ACD1C477D2339940AFB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.413010863653587 |
Encrypted: | false |
SSDEEP: | 192:TcbeIewcbVcbqI4ucbrcbQIrJcb6cbCIC4cbvjJJNiZUvySJdCjVWjCjZKDe/Mcs:ceo4+rsCjiFIp |
MD5: | 1CAF2B253B0CC5A6383CA21BA4960B20 |
SHA1: | FE75659458367C8B66925732A2D27F9948B88721 |
SHA-256: | 6DE9A197C2AE220ACCF1CAFFEA9AA10E9D553858948B7C1EA281E8C92FD5C9CD |
SHA-512: | 47E9297FB2CCC827EAB146096BC347A3DDE255BEBE105CA2C6FA2602FE6B3EE926BD01091D24C61DA1663FD05158E8B82B00AFA327DC1E11883102DF6C57DE4C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZzZwYIGNPJe:RB3mlind9i4ufFXpAXkrfUs03WLaGZze |
MD5: | 198F4E288D1DB22C155F252BF364EFCB |
SHA1: | 690AE63F7824B05C2B6A021E590703F050824B8E |
SHA-256: | 05F1AF075AB733EB1888CFA62B650396358C211C6DAE4C8159A176E6563E5934 |
SHA-512: | A11CB4DE3A4B38BB5FD8AFA7842FB2F9887AE0DA440999A175049B205ED8649C3A5C6BD12716BC406A6CA68440852BE2ABD92C6E31F102A253DBA6AB97860BE5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/9wYIGNPQmeWL07oXGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:lwZG2XWLxXGZN3mlind9i4ufFXpAXkru |
MD5: | CDB0A9F62FD4871F0603FBBF1FE6BD06 |
SHA1: | C972A2B8E6E7CD72A156C1EAB8F5F31E76A7DA24 |
SHA-256: | 85BD3F2168D078DFF0ECEB670C3DC651E8797522C6A2921EC478EAD5A09E415F |
SHA-512: | 7FC3B110A45F9D518FEA45930B73F196FEE7DF472A17FB2CBB19A3BCBF5C78D439F68E2C615D8DACD5821EF60C1447112FB86431D768E28D9F08457563011F28 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.977045182569651 |
TrID: |
|
File name: | OFICIO SMEG.pdf |
File size: | 300'110 bytes |
MD5: | ff426638417b9244dbbc4bfc0f1aab4b |
SHA1: | 72b3d199dcde65a9279254f5e3b13dedd5b45f66 |
SHA256: | 4f12c165c0374507733f9524525f16a9d93359f1289b3399ae52100519301e1c |
SHA512: | 8d453f63c600a4d480cc3012d385d420aee0d04b7faf54b77c7e1e4e8d6cecf85612477db3942864763fedd1dda61388de60cb3a97f262e84e8c7b4a0749f9a4 |
SSDEEP: | 6144:cyutLiyxtnNap+eLpnnFaVEZY/X5uW9auPCddy7/WJV0kQhIY7vZj:cyutLiyxtNK+sFmPTgdyDWDQT7x |
TLSH: | 9F541201EF88C9CDE3812785AF7B7C197B6FB33AB1C010A20D7C97570A80D65E563A5A |
File Content Preview: | %PDF-1.5..%......1 0 obj..<</Type/Catalog/Pages 2 0 R/Lang(es-ES) /StructTreeRoot 46 0 R/MarkInfo<</Marked true>>>>..endobj..2 0 obj..<</Type/Pages/Count 2/Kids[ 3 0 R 30 0 R] >>..endobj..3 0 obj..<</Type/Page/Parent 2 0 R/Resources<</Font<</F1 5 0 R/F2 9 |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.5 |
Total Entropy: | 7.977045 |
Total Bytes: | 300110 |
Stream Entropy: | 7.996356 |
Stream Bytes: | 284518 |
Entropy outside Streams: | 4.917420 |
Bytes outside Streams: | 15592 |
Number of EOF found: | 2 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 66 |
endobj | 66 |
stream | 17 |
endstream | 17 |
xref | 2 |
trailer | 2 |
startxref | 2 |
/Page | 2 |
/Encrypt | 0 |
/ObjStm | 1 |
/URI | 0 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
14 | 4a6b159135454b1a | ff8c0b9404dc0bc6ca93f0beee241c90 | |
15 | 0e2bd4d6179c96dc | f74ef4c321b29c809ba98630706eda7c | |
32 | 4a6b159135454b1a | ff8c0b9404dc0bc6ca93f0beee241c90 | |
33 | 0e2bd4d6179c96dc | f74ef4c321b29c809ba98630706eda7c | |
44 | 6373b3b3b3f1b766 | 3d5f8f15a3c8835fd712f08afdd96b7b |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 08:53:21 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e8200000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 08:53:22 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79c940000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 08:53:23 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79c940000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |