Windows
Analysis Report
2014-10-14 Title Abstract-Jamestown Plat 11 Lots 10-12.pdf
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 6456 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\2 014-10-14 Title Abst ract-James town Plat 11 Lots 10 -12.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 6976 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 5100 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 00 --field -trial-han dle=1520,i ,360025319 057947509, 1524881543 2717213400 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Static file information: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Non-Application Layer Protocol | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
x1.i.lencr.org | unknown | unknown | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1544733 |
Start date and time: | 2024-10-29 17:01:16 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2014-10-14 Title Abstract-Jamestown Plat 11 Lots 10-12.pdf |
Detection: | CLEAN |
Classification: | clean0.winPDF@14/29@3/0 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 2.19.11.117, 2.19.11.122, 52.5.13.197, 23.22.254.206, 52.202.204.11, 54.227.187.23, 162.159.61.3, 172.64.41.3, 2.23.197.184, 88.221.168.141, 2.19.126.143, 2.19.126.149
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, e4578.dscb.akamaiedge.net, ctldl.windowsupdate.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ssl.adobe.com.edgekey.net, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: 2014-10-14 Title Abstract-Jamestown Plat 11 Lots 10-12.pdf
Time | Type | Description |
---|---|---|
12:02:38 | API Interceptor |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.144467781219992 |
Encrypted: | false |
SSDEEP: | 6:19ApGq2Pwkn2nKuAl9OmbnIFUt869ApkTvZZmw+69ApJkwOwkn2nKuAl9OmbjLJ:19A8vYfHAahFUt869Aoh/+69Aj5JfHAR |
MD5: | BA8951A14E26AD8B0E5C02DE2F005E58 |
SHA1: | 5BAEB7D95BE5EA48E9DA4A016F1D2E55B025F094 |
SHA-256: | 7929A5234BF79A48B836705BC7B459BFFC67554B0EDFAA2CD40041EB0D8A9931 |
SHA-512: | 443D92D93B05B066111C74AAB74C37FDB1EA906B5D3932839CE7E2624714751D0E97E4590ED45AED5F44E7FE64E180D902F7C51D87E6DF9AAFD0BC00B6ED1195 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.144467781219992 |
Encrypted: | false |
SSDEEP: | 6:19ApGq2Pwkn2nKuAl9OmbnIFUt869ApkTvZZmw+69ApJkwOwkn2nKuAl9OmbjLJ:19A8vYfHAahFUt869Aoh/+69Aj5JfHAR |
MD5: | BA8951A14E26AD8B0E5C02DE2F005E58 |
SHA1: | 5BAEB7D95BE5EA48E9DA4A016F1D2E55B025F094 |
SHA-256: | 7929A5234BF79A48B836705BC7B459BFFC67554B0EDFAA2CD40041EB0D8A9931 |
SHA-512: | 443D92D93B05B066111C74AAB74C37FDB1EA906B5D3932839CE7E2624714751D0E97E4590ED45AED5F44E7FE64E180D902F7C51D87E6DF9AAFD0BC00B6ED1195 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 333 |
Entropy (8bit): | 5.184449678813361 |
Encrypted: | false |
SSDEEP: | 6:19AiWaL+q2Pwkn2nKuAl9Ombzo2jMGIFUt869AiULoKWZmw+69Aic31LVkwOwknV:19AiWaL+vYfHAa8uFUt869AiqXW/+69r |
MD5: | C06CE7CFFE2BBFE08F7C8DDC2A413A40 |
SHA1: | 556059E705FAC5F3B93E7DC4879ED0FACD8B1839 |
SHA-256: | 600C8F80E8D47A405357EC97BE3F618EF16406E3EE04661F1836C7FA9EB85E7A |
SHA-512: | 40603A2CF473442442957D9511CA65EB8A06CFEA556A213884F77CEBD0D7BC7861D34E35E8DB15F72A32A570EEEA177BC140E0494F949095940E1CFCCEAD177A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 333 |
Entropy (8bit): | 5.184449678813361 |
Encrypted: | false |
SSDEEP: | 6:19AiWaL+q2Pwkn2nKuAl9Ombzo2jMGIFUt869AiULoKWZmw+69Aic31LVkwOwknV:19AiWaL+vYfHAa8uFUt869AiqXW/+69r |
MD5: | C06CE7CFFE2BBFE08F7C8DDC2A413A40 |
SHA1: | 556059E705FAC5F3B93E7DC4879ED0FACD8B1839 |
SHA-256: | 600C8F80E8D47A405357EC97BE3F618EF16406E3EE04661F1836C7FA9EB85E7A |
SHA-512: | 40603A2CF473442442957D9511CA65EB8A06CFEA556A213884F77CEBD0D7BC7861D34E35E8DB15F72A32A570EEEA177BC140E0494F949095940E1CFCCEAD177A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\092a9bdc-2265-4873-872b-907c3496e9a7.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.9655162853550765 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqEsBdOg2HdHAcaq3QYiubInP7E4T3y:Y2sRds0dMHZr3QYhbG7nby |
MD5: | C5B9150FDAB5DEAD5546668B14C0F926 |
SHA1: | 907226674366E212FF39E909ABFB247B90816E0F |
SHA-256: | B4FF6A074729A4F8FB5064AF2BDAE2F6223A12556DA4DC3EEA774C4FAA8D1E0E |
SHA-512: | 2B1A1955F0FD965C2ADABEE319B01919478D2C0A1066C137B374ED08CD770F8DF459DA951EC84109F49C0B56337468F8FC488BC3560C0B6A0A82DFFBB2546D6A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.9655162853550765 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqEsBdOg2HdHAcaq3QYiubInP7E4T3y:Y2sRds0dMHZr3QYhbG7nby |
MD5: | C5B9150FDAB5DEAD5546668B14C0F926 |
SHA1: | 907226674366E212FF39E909ABFB247B90816E0F |
SHA-256: | B4FF6A074729A4F8FB5064AF2BDAE2F6223A12556DA4DC3EEA774C4FAA8D1E0E |
SHA-512: | 2B1A1955F0FD965C2ADABEE319B01919478D2C0A1066C137B374ED08CD770F8DF459DA951EC84109F49C0B56337468F8FC488BC3560C0B6A0A82DFFBB2546D6A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4730 |
Entropy (8bit): | 5.2493717509053734 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7rQCp3PJtZ:etJCV4FiN/jTN/2r8Mta02fEhgO73go/ |
MD5: | F1EDF39DE530FEAF96630AF7CDFBA189 |
SHA1: | 377CF67406CB5993576199528AADF130B1180251 |
SHA-256: | 4D8BB70D9B28089A239BFF452307A74EFDADE9B828A52632EC57D967271F6B42 |
SHA-512: | 1EB548446A1418499B7CFC59678E6BCF215133ABED86782629F852BBF4BCD515E5A49A4896C02B0A4E3615C41B039AE2AF1827E370D744AF2E7BB0987FE8195E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 321 |
Entropy (8bit): | 5.190967705684544 |
Encrypted: | false |
SSDEEP: | 6:19AmhzlL+q2Pwkn2nKuAl9OmbzNMxIFUt869Am4KWZmw+69AmYLVkwOwkn2nKuAo:19AmhzlL+vYfHAa8jFUt869AmHW/+690 |
MD5: | 930AC3AB9DA4DA8F95D677E32A2BA9EB |
SHA1: | F6AE5CC45432FA4DA82EC8700DFB956420DE0277 |
SHA-256: | 8EFA60F07606132962ED94CF4147B13CE42FDE71B8A7E018C5DE664EED388334 |
SHA-512: | 745BD1879DC84FF5884B9EABE8CA2456CCA26E9AFC83F34875CDBDB57BF9E15C4AD0DAE5C55D2C562E4CF1B322028FD45F227ED19FC356C304BF75BD72B251EB |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 321 |
Entropy (8bit): | 5.190967705684544 |
Encrypted: | false |
SSDEEP: | 6:19AmhzlL+q2Pwkn2nKuAl9OmbzNMxIFUt869Am4KWZmw+69AmYLVkwOwkn2nKuAo:19AmhzlL+vYfHAa8jFUt869AmHW/+690 |
MD5: | 930AC3AB9DA4DA8F95D677E32A2BA9EB |
SHA1: | F6AE5CC45432FA4DA82EC8700DFB956420DE0277 |
SHA-256: | 8EFA60F07606132962ED94CF4147B13CE42FDE71B8A7E018C5DE664EED388334 |
SHA-512: | 745BD1879DC84FF5884B9EABE8CA2456CCA26E9AFC83F34875CDBDB57BF9E15C4AD0DAE5C55D2C562E4CF1B322028FD45F227ED19FC356C304BF75BD72B251EB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241029160230Z-182.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 70582 |
Entropy (8bit): | 2.96577800189958 |
Encrypted: | false |
SSDEEP: | 384:fwxxvDbzMN83I2xvakACaoIrqmyf9L3dvxqNLY3EbZ2gAvj8sl525V9WBLnBRb:fwxRDMG3law0qmyF+LAKS/lhBV |
MD5: | 6F7F9085C6D611A1A38FAEF58A5810D5 |
SHA1: | 314D61722FF60DD38AB181B3DDD16A775B72F635 |
SHA-256: | BA57CDC161CCD9A110FA819C021FDCBDEA42F913A0A1FD259C3D67FBB28374BA |
SHA-512: | 1F9EE172BFC4DE14222AF3858E74EA883435FA8A002CE925781662865DCFADC25736B38D74C8C17FA3875FA5D3D4E9BC67CCAECB264BEB83E17A5E1C285E22E1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444861470963684 |
Encrypted: | false |
SSDEEP: | 384:yezci5tuiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:rBs3OazzU89UTTgUL |
MD5: | 7228ACF67E68DBC367AB9DE2577F8071 |
SHA1: | 82AD648DB79FBDF77B599D9E41C1AD4F7C703EF7 |
SHA-256: | B8C9E8B3EFCF78BE583C3299474AB5E4A9F75CDFF791C16466D2CC87612440CA |
SHA-512: | F27EBA2134B79EE17FA1F994F6774EC84E1F4F8448E159E10B3929A81AB8432CF79C65B34E965B46A65615FF779077FEF291A4B3C2A1DB6C448C8E53144088AA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.7735395490114763 |
Encrypted: | false |
SSDEEP: | 48:7MUp/E2ioyVq4ioy9oWoy1Cwoy1vbKOioy1noy1AYoy1Wioy1hioybioyFtoy1nD:7bpjunF6XKQG+b9IVXEBodRBkK |
MD5: | C04A70CD0C84791D24D4325FA0C78D33 |
SHA1: | 3E7AACB944C796E1F9B324481EE6011424FC0A7A |
SHA-256: | E19B5F50D32FD546756EB607B375CA44DBB204E22F11EAEA5DD052FCE5602E1B |
SHA-512: | 10BCD6F25DD437504217F5F16E47E6BBA0D1994E4B6A10A6CE535D2FE286D14F3866607ECB264006722FD5E5434E260C690D59CEDC47FFCAA90FB06DFC28E2E5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.779094196322516 |
Encrypted: | false |
SSDEEP: | 3:kkFklJsvfllXlE/HT8kybulltNNX8RolJuRdxLlGB9lQRYwpDdt:kKrQT8mTNMa8RdWBwRd |
MD5: | 66B094F0BAD09CCEE29B98818C9B2113 |
SHA1: | 49989387A355278087E0009184F99674F9FBE7D4 |
SHA-256: | 53DFC321BD9444359538217D891651402651412D8386FAB345884C20F02D06CA |
SHA-512: | 672FE116FFDDE950C781E75E07DC5EAD12A430D402205FF9914B0172CBA7230499D90CEB035DBFB69F56D3843AE28823357A1A4FCDE0A1A7EECE43F2EECAA07E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | 1536:JsVoWFMWQNk1KUQII5J5lZRT95tFiQibVJDS+Stu/3IVQBrp3Mv9df0CXLhNHqTM:bViyFXE07ZmandGCyN2mM7IgOP0gC |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185099 |
Entropy (8bit): | 5.182478651346149 |
Encrypted: | false |
SSDEEP: | 1536:JsVoWFMWQNk1KUQII5J5lZRT95tFiQibVJDS+Stu/3IVQBrp3Mv9df0CXLhNHqTM:bViyFXE07ZmandGCyN2mM7IgOP0gC |
MD5: | 94185C5850C26B3C6FC24ABC385CDA58 |
SHA1: | 42F042285037B0C35BC4226D387F88C770AB5CAA |
SHA-256: | 1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808 |
SHA-512: | 652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 243196 |
Entropy (8bit): | 3.3450692389394283 |
Encrypted: | false |
SSDEEP: | 1536:vKPCPiyzDtrh1cK3XEivK7VK/3AYvYwgqErRo+RQn:yPClJ/3AYvYwghFo+RQn |
MD5: | F5567C4FF4AB049B696D3BE0DD72A793 |
SHA1: | EBEADDE9FF0AF2C201A5F7CC747C9EA61CFA6916 |
SHA-256: | D8DBFE71873929825A420F73821F3FF0254D51984FAAA82E1B89D31188F77C04 |
SHA-512: | E769735991E5B1331E259608854D00CDA4F3E92285FDC500158CBD09CBCCEAD8A387F78256A43919B13EBE70C995D19242377C315B0CCBBD4F813251608C1D56 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2145 |
Entropy (8bit): | 5.066908656139369 |
Encrypted: | false |
SSDEEP: | 48:Yo2sL0/EY0bMSlMtCM5mMOpiMAW0MretMSMmkaMY:Ov/SYtt55V6AWLre6JmkhY |
MD5: | 8CC239E3BD1C4867028CBF5FC1212949 |
SHA1: | 5056B080777B149F760B2CBA35781022DF06F07F |
SHA-256: | ED2F0D7989C9743B41C69298366DA4824E88D741C3D3D07EA71A85C7EB902227 |
SHA-512: | 5843998BA0245487EBE884F2C05D3B42296E8429FC11A974B15CC345142D128F4AAFB8282D3C1BAF7318279B3CBFD60EBE9E0FDDAA45F6D6A79DF0FAB88E1658 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.187637807870451 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUDSvR9H9vxFGiDIAEkGVvp3:lNVmswUUUUUUUUD+FGSItb |
MD5: | 2B13071D89853259FF22F34FF83E79EE |
SHA1: | DB500D32EB69651D64BF3C25865E6A8476CD4C00 |
SHA-256: | 0776C5BF7B7890CDA510DA31D91CBB2FE89B63392702D20DCD09CD646D0D6E65 |
SHA-512: | 3CB7C91929215FF7687C539C052D4EE10840703A87C813EC5A9A045D075D669B6D029FF3BFF821E03991B7FD646E2D873BEB13A3AB0A509CC0A22B2CB4D12CF3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6041880788856544 |
Encrypted: | false |
SSDEEP: | 48:7MuKUUUUUUUUUUnvR9H9vxFGiDIAEkGVveqFl2GL7msKo:7yUUUUUUUUUUfFGSIt4KVmsp |
MD5: | 96296A7D36495DB84779BAEFD1441C0D |
SHA1: | 9699531EA679C37E04D13B47454DA62B074D66C7 |
SHA-256: | C43411D2B0D437D05BAAF0942B4B847DD46501F1223AD1D6275A9E8DF930BBA1 |
SHA-512: | AEA9553D5F7D4283685C205918098300B1851B6B85B251F96ADC1155B6CAE10A5A5A84A677C9C24A1E7EAA103ED2DB5C0BE8AFB5E38E1ADD6C35B8819B72DACD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5085442896850614 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8xOlQq3UlWKCH:Qw946cPbiOxDlbYnuRK51URw |
MD5: | 3CCD94ACFFC7C738A9AB57DDB049297A |
SHA1: | 9D6D1FC316D86D0DAFD489E7A8B218CDFA16F2E6 |
SHA-256: | 1FE0733A79DD67EF65BD4CD741DC4CCE71AB91B36A8CF68006788DC44E6504FB |
SHA-512: | BDC3BE89E7B731F6FCE1D8BC148D669B48E278ECD02381722ACDD407E7906A65D80AF1447B1AC7A2256CA643F7956C85CEEFBF28791FB0A55879927641B43DB5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-10-29 12-02-27-615.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.352656845605611 |
Encrypted: | false |
SSDEEP: | 384:RsGhOkfdeHu8/V+7vu7uXglhqNThySe9c/O64EIgV9NWowJNdG7ezwzSQ2YWX9l/:7vM |
MD5: | 3707E00589EEBABB3A04811DD8137391 |
SHA1: | 28999EBB2BFC63306717CC7D7E60ADE6EE269FF9 |
SHA-256: | E8453B26A1C6698E26951BC4361C22CCB3317366129916CB4E0FE463D1E9CF65 |
SHA-512: | 664AD40834979C7AD3FBE9860FAF245768B06EC25E6B660DF43E0CE9C73A2F1DA59C23EE3B6327FCE1A98E1FA54FE92AAD0D7BEBB62825FF7994CDE05E259E0F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.386648774381744 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rv:MK |
MD5: | AAC5EEBFD493EE098EC4F52EE10DF9A5 |
SHA1: | A8F149D1F41ADFE911A9C66D0BA761E5EE977976 |
SHA-256: | 4F509C5B1035A3E054A9C08AF23D9D1FB35AC5D9DF983BBDD64A1704FC06FB68 |
SHA-512: | 0385AD3A1DB49AF05CAA485195B5D33886FCF9BB29DE61CD83BDFB004276618645C0690E04867FCE343FD8C0BEBAA023FDFC4D19A0D688D552534A7F6B5E6DBC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLaGZDwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLaGZDwZGk3mlind9i4ufFXpAXkru |
MD5: | 18E3D04537AF72FDBEB3760B2D10C80E |
SHA1: | B313CD0B25E41E5CF0DFB83B33AB3E3C7678D5CC |
SHA-256: | BBEF113A2057EE7EAC911DC960D36D4A62C262DAE5B1379257908228243BD6F4 |
SHA-512: | 2A5B9B0A5DC98151AD2346055DF2F7BFDE62F6069A4A6A9AB3377B644D61AE31609B9FC73BEE4A0E929F84BF30DA4C1CDE628915AC37C7542FD170D12DE41298 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.972348788033585 |
TrID: |
|
File name: | 2014-10-14 Title Abstract-Jamestown Plat 11 Lots 10-12.pdf |
File size: | 14'483'399 bytes |
MD5: | 57d994cfccf66e4059dc1317cbd894f3 |
SHA1: | 748572f9674629d6079cb3ccf928a497e525111c |
SHA256: | a4c35d272391d639e83aa6cbe6fa34993c7262d0c4bf2ef6b244742af0827d99 |
SHA512: | 660180e7a7a858076785c95c87277743c3cae958a9578c262ba9acc59904ad034b9d7bd562497fb82e78c44d51df70ff2551e47909cc517c6d755e6cdb382cf2 |
SSDEEP: | 393216:bbGVuKIfGFRG15v9cPFita0i0K+8hntMZfp:biVudGFRGnCtSNoJtMZfp |
TLSH: | ACE623B2ABFFC485DD4F03B1725A07B9481AC4A50AC990B32B7D6F6CF6546D5EA33840 |
File Content Preview: | %PDF-1.6.%......1417 0 obj.<</Filter/FlateDecode/First 1200/Length 4995/N 129/Type/ObjStm>>stream..h..[..d...*....eK.!.$..!,;d...a......;L.@...t.zu......2.W.n.}d..H..-ly.....n1nL.....[,[.%l..H.n....[".(.-..+.-.F....!{3'.4.-.F.h....uL[....-%..eK......}ho.. |
Icon Hash: | 62cc8caeb29e8ae0 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 29, 2024 17:02:38.637459993 CET | 63797 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 29, 2024 17:02:50.911202908 CET | 61064 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 29, 2024 17:03:06.593518019 CET | 65193 | 53 | 192.168.2.4 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 29, 2024 17:02:38.637459993 CET | 192.168.2.4 | 1.1.1.1 | 0xe5a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 29, 2024 17:02:50.911202908 CET | 192.168.2.4 | 1.1.1.1 | 0x9d38 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 29, 2024 17:03:06.593518019 CET | 192.168.2.4 | 1.1.1.1 | 0x9c03 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 29, 2024 17:02:38.646239996 CET | 1.1.1.1 | 192.168.2.4 | 0xe5a0 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 29, 2024 17:02:50.925049067 CET | 1.1.1.1 | 192.168.2.4 | 0x9d38 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 29, 2024 17:03:06.604306936 CET | 1.1.1.1 | 192.168.2.4 | 0x9c03 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 12:02:24 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 12:02:24 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 12:02:25 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |