File name:

00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043

Full analysis: https://app.any.run/tasks/36f215cb-8025-4a4f-b498-c46f9aadc2e1
Verdict: Malicious activity
Analysis date: April 15, 2024, 06:23:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6F776E9782C231B5FF969A0F16C1821A

SHA1:

1F6FE84939DA4051CE47B81130823665298A2B60

SHA256:

00165A5A0AF9312110E3E579DC8E599F5DA540A33F12F3E55B098653A8A4D043

SSDEEP:

3072:VMs3fGBjN1Jrpi0kOBzleK6VU6SaQFQMg6WB:Vn3MN1JlveK6VUsQOjz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 3936)
      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
    • Create files in the Startup directory

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
    • Changes appearance of the Explorer extensions

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
  • SUSPICIOUS

    • Reads the Internet Settings

      • rundll32.exe (PID: 696)
    • Creates file in the systems drive root

      • AcroRd32.exe (PID: 3684)
    • Drops a file with a rarely used extension (PIF)

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
    • Executable content was dropped or overwritten

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
  • INFO

    • Reads the machine GUID from the registry

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 3936)
      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 3392)
      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
    • Checks supported languages

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 3936)
      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 3392)
      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
    • Reads the computer name

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 3936)
      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 3392)
      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
    • Create files in a temporary directory

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 3936)
      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 3392)
      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
    • Manual execution by a user

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 3392)
      • rundll32.exe (PID: 696)
      • WinRAR.exe (PID: 3556)
      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
      • notepad++.exe (PID: 1124)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 696)
    • Application launched itself

      • AcroRd32.exe (PID: 3724)
      • RdrCEF.exe (PID: 1236)
    • Drops the executable file immediately after the start

      • RdrCEF.exe (PID: 1236)
    • Creates files in the program directory

      • 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe (PID: 124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2007:07:23 13:18:13+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 36864
InitializedDataSize: 32768
UninitializedDataSize: -
EntryPoint: 0x12b4
OSVersion: 4
ImageVersion: 15.5
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 15.5.0.88
ProductVersionNumber: 15.5.0.88
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Dossier de fichiers
ProductName: xcv
FileVersion: 15.05.0088
ProductVersion: 15.05.0088
InternalName: essai
OriginalFileName: essai.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
14
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe no specs 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe no specs rundll32.exe no specs acrord32.exe no specs acrord32.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs winrar.exe no specs 00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe explorer.exe no specs notepad++.exe

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Users\admin\Desktop\00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe" C:\Users\admin\Desktop\00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Dossier de fichiers
Exit code:
0
Version:
15.05.0088
Modules
Images
c:\users\admin\desktop\00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
680"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --touch-events=enabled --field-trial-handle=1180,2791543636520251090,7259784861273648348,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-gpu-compositing --lang=en-US --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8082554907168084924 --renderer-client-id=2 --mojo-platform-channel-handle=1188 --allow-no-sandbox-job /prefetch:1C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
696"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1124"C:\Program Files\Notepad++\notepad++.exe" "C:\Users\admin\Desktop\00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1236"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --backgroundcolor=16514043C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1816"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=gpu-process --field-trial-handle=1180,2791543636520251090,7259784861273648348,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --lang=en-US --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAABAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --service-request-channel-token=10634306304859590278 --mojo-platform-channel-handle=1380 --allow-no-sandbox-job --ignored=" --type=renderer " /prefetch:2C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
1
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2248"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=gpu-process --field-trial-handle=1180,2791543636520251090,7259784861273648348,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --lang=en-US --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAABAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --service-request-channel-token=2164906221880986593 --mojo-platform-channel-handle=1264 --allow-no-sandbox-job --ignored=" --type=renderer " /prefetch:2C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
1
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2516C:\windows\explorer.exeC:\Windows\explorer.exe00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3392"C:\Users\admin\Desktop\00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe" C:\Users\admin\Desktop\00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Dossier de fichiers
Exit code:
0
Version:
15.05.0088
Modules
Images
c:\users\admin\desktop\00165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3404"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=gpu-process --field-trial-handle=1180,2791543636520251090,7259784861273648348,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --lang=en-US --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAABAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --service-request-channel-token=11917360591770200898 --mojo-platform-channel-handle=1216 --allow-no-sandbox-job --ignored=" --type=renderer " /prefetch:2C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
1
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
12 951
Read events
12 711
Write events
232
Delete events
8

Modification events

(PID) Process:(696) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Value:
Adobe Acrobat Reader DC
(PID) Process:(696) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\eHome\ehshell.exe
Value:
Windows Media Center
(PID) Process:(696) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
Firefox
(PID) Process:(696) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Internet Explorer\iexplore.exe
Value:
Internet Explorer
(PID) Process:(696) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\system32\mspaint.exe
Value:
Paint
(PID) Process:(696) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\system32\NOTEPAD.EXE
Value:
Notepad
(PID) Process:(696) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\PROGRA~1\MICROS~1\Office14\OIS.EXE
Value:
Microsoft Office 2010
(PID) Process:(696) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Windows Photo Viewer\PhotoViewer.dll
Value:
Windows Photo Viewer
(PID) Process:(696) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\VideoLAN\VLC\vlc.exe
Value:
VLC media player
(PID) Process:(696) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Value:
Microsoft Word
Executable files
2
Suspicious files
24
Text files
4
Unknown types
20

Dropped files

PID
Process
Filename
Type
393600165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exeC:\Users\admin\AppData\Local\Temp\~DF20A32EEF6ACDB1CC.TMPbinary
MD5:
SHA256:
339200165a5a0af9312110e3e579dc8e599f5da540a33f12f3e55b098653a8a4d043.exeC:\Users\admin\AppData\Local\Temp\~DF7121D38F09A6393A.TMPbinary
MD5:
SHA256:
3684AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\SOPHIA.jsonbinary
MD5:
SHA256:
3684AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\TESTINGmp3
MD5:
SHA256:
3684AcroRd32.exeC:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storebinary
MD5:
SHA256:
3684AcroRd32.exeC:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storeibinary
MD5:
SHA256:
3684AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\IconCacheRdr65536.datbinary
MD5:
SHA256:
1236RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0binary
MD5:
SHA256:
1236RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0binary
MD5:
SHA256:
1236RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3