| File name: | IM-1854425174.pdf |
| Full analysis: | https://app.any.run/tasks/6ab0fd7f-9113-419d-8453-1e706a14ec5c |
| Verdict: | Malicious activity |
| Analysis date: | February 15, 2024, 19:26:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/pdf |
| File info: | PDF document, version 1.3, 1 pages |
| MD5: | 7F2F7BD338CF0C96DA3529D4EA918290 |
| SHA1: | 4B0C8E77E08F298AEABAC81F7369D4FF132DBDE8 |
| SHA256: | 10F98E719E1D4338D7CE60B4669F57468A840C548A7C6540D3D378B34391D268 |
| SSDEEP: | 384:dSBy+xWUep6IgzkqoJD/5Qw9/WftIJ2uHhAydL8zgvdJ36FAHh:QrxWUu6IgzZA/bWKJvhFdL8zOdJKFk |
| | | Adobe Portable Document Format (100) |
| PDFVersion: | 1.3 |
|---|---|
| Linearized: | No |
| PageCount: | 1 |
| Title: | Book_2923 |
| Author: | Author_182 |
| Subject: | Subject_23 |
| Keywords: |
|
| Creator: | LibrarySystem_13 |
| Producer: | Producer_32 |
| CreateDate: | 2024:01:15 00:00:00 |
| ModifyDate: | 2024:01:23 00:00:00 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 548 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=30 --mojo-platform-channel-handle=3332 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 696 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4540 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 784 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2256 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 908 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=2380 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 920 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6bb4f598,0x6bb4f5a8,0x6bb4f5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1020 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6bb4f598,0x6bb4f5a8,0x6bb4f5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1352 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=34 --mojo-platform-channel-handle=4900 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1392 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=2988 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1404 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\cases_2024-02-15_00-46-26-556835_12.cab" | C:\Program Files\WinRAR\WinRAR.exe | — | msedge.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1432 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\Desktop\IM-1854425174.pdf" | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | — | AcroRd32.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe Acrobat Reader DC Exit code: 0 Version: 20.13.20064.405839 Modules
| |||||||||||||||
| (PID) Process: | (1432) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection |
| Operation: | write | Name: | bLastExitNormal |
Value: 0 | |||
| (PID) Process: | (1432) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral |
| Operation: | write | Name: | aDefaultRHPViewModeL |
Value: Expanded | |||
| (PID) Process: | (1432) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral |
| Operation: | write | Name: | bExpandRHPInViewer |
Value: 1 | |||
| (PID) Process: | (1432) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral |
| Operation: | write | Name: | uLastAppLaunchTimeStamp |
Value: | |||
| (PID) Process: | (1432) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral |
| Operation: | write | Name: | iNumReaderLaunches |
Value: 6 | |||
| (PID) Process: | (1432) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\FillSign |
| Operation: | write | Name: | uFillSignVariantTrackingTime |
Value: | |||
| (PID) Process: | (1432) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\NoTimeOut |
| Operation: | write | Name: | smailto |
Value: 5900 | |||
| (PID) Process: | (1432) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ToolsSearch |
| Operation: | write | Name: | iSearchHintIndex |
Value: 0 | |||
| (PID) Process: | (1432) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\SessionManagement |
| Operation: | write | Name: | bNormalExit |
Value: 0 | |||
| (PID) Process: | (1432) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\SessionManagement\cWindowsCurrent\cWin0\cTab0\cPathInfo |
| Operation: | write | Name: | sDI |
Value: 2F432F55736572732F61646D696E2F4465736B746F702F494D2D313835343432353137342E70646600 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2840 | RdrCEF.exe | — | ||
MD5:— | SHA256:— | |||
| 1432 | AcroRd32.exe | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\TESTING | binary | |
MD5:DC84B0D741E5BEAE8070013ADDCC8C28 | SHA256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 | |||
| 1432 | AcroRd32.exe | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\SOPHIA.json | binary | |
MD5:01F233C92A89C705229A0D63D09F846A | SHA256:62137C4381ACC2DE8BCA158AD9D9CE730BD7A96A39A2FB64CE7CFA5C861CF7B4 | |||
| 2840 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0 | binary | |
MD5:CDBF823D014000B87337AB022755ACF9 | SHA256:1DCBD00202B67CBC6821AD39D42E81EA2BE174C555F971764CA979F5DD5A5A6A | |||
| 1432 | AcroRd32.exe | C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-240215192643Z-155.bmp | image | |
MD5:D392FF5C9D64D6F5A7AFCBCD3DF350CF | SHA256:A3A1A352DFBA96CF4873B8DA101F3FF832FAFB4C0D7EF49041C1BF23450E0DD6 | |||
| 2840 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\72d9f526d2e2e7c8_0 | binary | |
MD5:7934B9B6147DFFFB32E380642B411BF7 | SHA256:C8C715CFE470E374A46BE02E47DCD5166A2BA6B1A67C7A9D2FD8D3542B449609 | |||
| 2840 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0 | binary | |
MD5:14894BCE8EBCC192BBD1784B84EB4AE9 | SHA256:063BFAC96A41817E48FFE5605B3F11FD4E29A6C39B3BE511B4E69EFD46179ECD | |||
| 2840 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0 | binary | |
MD5:152EA050B4A0F5C89FF5654CB1AC9FD4 | SHA256:3454D5F3C52DBCBCDC8884593330ABE8E3FB695723960F46102F7B799AFB2B7A | |||
| 2840 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0 | binary | |
MD5:35EB63C713A29DD3B9D0DCC2DDE90F42 | SHA256:C6733DD6C71FEE22893C44C1D77D4E512F4BFFB1CE302EA8A2CD3001F268E077 | |||
| 2840 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\aba6710fde0876af_0 | binary | |
MD5:F3B77F9B6479B9A6CA9EB4830B9E0E7E | SHA256:A34F3EED5042A8C6D7B0AE0593C06F27DCDDB9D44B27FC13368B72D85D6A6071 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2472 | AcroRd32.exe | GET | 304 | 2.16.115.177:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?adf0414906a3d192 | unknown | — | — | unknown |
2472 | AcroRd32.exe | GET | 304 | 2.16.115.177:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?956c1609c0d25c3f | unknown | — | — | unknown |
1080 | svchost.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e90c163b6659448e | unknown | compressed | 65.2 Kb | unknown |
1080 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e2ddf83a2417bb20 | unknown | compressed | 65.2 Kb | unknown |
3728 | SearchProtocolHost.exe | OPTIONS | 200 | 193.178.210.226:80 | http://193.178.210.226/ | unknown | — | — | unknown |
2472 | AcroRd32.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | unknown | binary | 471 b | unknown |
828 | svchost.exe | OPTIONS | 400 | 193.178.210.226:80 | http://193.178.210.226/documents/reader_update.zip/reader_update.exe | unknown | html | 226 b | unknown |
828 | svchost.exe | OPTIONS | 400 | 193.178.210.226:80 | http://193.178.210.226/documents/reader_update.zip/reader_update.exe | unknown | html | 226 b | unknown |
828 | svchost.exe | OPTIONS | 400 | 193.178.210.226:80 | http://193.178.210.226/documents/reader_update.zip/reader_update.exe | unknown | html | 226 b | unknown |
828 | svchost.exe | OPTIONS | 400 | 193.178.210.226:80 | http://193.178.210.226/documents/reader_update.zip/reader_update.exe | unknown | html | 226 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2840 | RdrCEF.exe | 104.124.108.165:443 | geo2.adobe.com | AKAMAI-AS | FR | unknown |
2840 | RdrCEF.exe | 52.202.204.11:443 | p13n.adobe.io | AMAZON-AES | US | unknown |
2472 | AcroRd32.exe | 2.16.115.178:443 | acroipm2.adobe.com | Akamai International B.V. | GB | unknown |
2472 | AcroRd32.exe | 2.16.115.177:80 | ctldl.windowsupdate.com | Akamai International B.V. | GB | unknown |
2472 | AcroRd32.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2840 | RdrCEF.exe | 23.41.212.24:443 | armmf.adobe.com | AKAMAI-AS | DE | unknown |
3984 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
geo2.adobe.com |
| whitelisted |
p13n.adobe.io |
| whitelisted |
armmf.adobe.com |
| whitelisted |
acroipm2.adobe.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
monitor.clickcease.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
otiunmonisky2m.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
828 | svchost.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
828 | svchost.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
828 | svchost.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
828 | svchost.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
Process | Message |
|---|---|
msedge.exe | [0215/192754.744:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)
|