File name:

IM-1854425174.pdf

Full analysis: https://app.any.run/tasks/6ab0fd7f-9113-419d-8453-1e706a14ec5c
Verdict: Malicious activity
Analysis date: February 15, 2024, 19:26:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: application/pdf
File info: PDF document, version 1.3, 1 pages
MD5:

7F2F7BD338CF0C96DA3529D4EA918290

SHA1:

4B0C8E77E08F298AEABAC81F7369D4FF132DBDE8

SHA256:

10F98E719E1D4338D7CE60B4669F57468A840C548A7C6540D3D378B34391D268

SSDEEP:

384:dSBy+xWUep6IgzkqoJD/5Qw9/WftIJ2uHhAydL8zgvdJ36FAHh:QrxWUu6IgzZA/bWKJvhFdL8zOdJKFk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • sdiagnhost.exe (PID: 2580)
    • Probably uses Microsoft diagnostics tool to execute malicious payload

      • rundll32.exe (PID: 2856)
    • Process drops legitimate windows executable

      • msdt.exe (PID: 2316)
    • Reads settings of System Certificates

      • msdt.exe (PID: 2316)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1404)
    • Process uses IPCONFIG to discover network configuration

      • sdiagnhost.exe (PID: 2580)
    • Uses ROUTE.EXE to obtain the routing table information

      • sdiagnhost.exe (PID: 2580)
    • Uses pipe srvsvc via SMB (transferring data)

      • WinRAR.exe (PID: 1404)
  • INFO

    • Reads Microsoft Office registry keys

      • AcroRd32.exe (PID: 1432)
    • Application launched itself

      • AcroRd32.exe (PID: 2472)
      • msedge.exe (PID: 2584)
      • AcroRd32.exe (PID: 3724)
      • RdrCEF.exe (PID: 2840)
      • msedge.exe (PID: 2656)
      • msedge.exe (PID: 3984)
    • Checks supported languages

      • wmpnscfg.exe (PID: 2972)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2972)
      • rundll32.exe (PID: 2856)
      • AcroRd32.exe (PID: 3724)
    • The process uses the downloaded file

      • msedge.exe (PID: 2316)
      • msedge.exe (PID: 3048)
      • WinRAR.exe (PID: 1864)
      • msedge.exe (PID: 3360)
      • WinRAR.exe (PID: 1404)
    • Reads the computer name

      • wmpnscfg.exe (PID: 2972)
    • Reads security settings of Internet Explorer

      • sdiagnhost.exe (PID: 2580)
      • msdt.exe (PID: 2316)
    • Drops the executable file immediately after the start

      • RdrCEF.exe (PID: 2840)
      • msdt.exe (PID: 2316)
    • Create files in a temporary directory

      • msdt.exe (PID: 2316)
      • sdiagnhost.exe (PID: 2580)
      • makecab.exe (PID: 4012)
    • Reads the software policy settings

      • msdt.exe (PID: 2316)
    • Checks proxy server information

      • WinRAR.exe (PID: 1404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.pdf | Adobe Portable Document Format (100)

EXIF

PDF

PDFVersion: 1.3
Linearized: No
PageCount: 1
Title: Book_2923
Author: Author_182
Subject: Subject_23
Keywords:
  • health
  • education
  • technology
Creator: LibrarySystem_13
Producer: Producer_32
CreateDate: 2024:01:15 00:00:00
ModifyDate: 2024:01:23 00:00:00
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
101
Monitored processes
61
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start acrord32.exe acrord32.exe no specs rdrcef.exe rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe no specs wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe no specs msdt.exe no specs sdiagnhost.exe no specs acrord32.exe no specs acrord32.exe no specs ipconfig.exe no specs route.exe no specs makecab.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
548"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=30 --mojo-platform-channel-handle=3332 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
696"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4540 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
784"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2256 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
908"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=2380 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
920"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6bb4f598,0x6bb4f5a8,0x6bb4f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1020"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6bb4f598,0x6bb4f5a8,0x6bb4f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1352"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=34 --mojo-platform-channel-handle=4900 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=2988 --field-trial-handle=1432,i,17155653749667929040,3476638435799429292,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1404"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\cases_2024-02-15_00-46-26-556835_12.cab"C:\Program Files\WinRAR\WinRAR.exemsedge.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1432"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\Desktop\IM-1854425174.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
0
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
44 642
Read events
44 366
Write events
243
Delete events
33

Modification events

(PID) Process:(1432) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection
Operation:writeName:bLastExitNormal
Value:
0
(PID) Process:(1432) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral
Operation:writeName:aDefaultRHPViewModeL
Value:
Expanded
(PID) Process:(1432) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral
Operation:writeName:bExpandRHPInViewer
Value:
1
(PID) Process:(1432) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral
Operation:writeName:uLastAppLaunchTimeStamp
Value:
(PID) Process:(1432) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral
Operation:writeName:iNumReaderLaunches
Value:
6
(PID) Process:(1432) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\FillSign
Operation:writeName:uFillSignVariantTrackingTime
Value:
(PID) Process:(1432) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\NoTimeOut
Operation:writeName:smailto
Value:
5900
(PID) Process:(1432) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ToolsSearch
Operation:writeName:iSearchHintIndex
Value:
0
(PID) Process:(1432) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\SessionManagement
Operation:writeName:bNormalExit
Value:
0
(PID) Process:(1432) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\SessionManagement\cWindowsCurrent\cWin0\cTab0\cPathInfo
Operation:writeName:sDI
Value:
2F432F55736572732F61646D696E2F4465736B746F702F494D2D313835343432353137342E70646600
Executable files
12
Suspicious files
220
Text files
123
Unknown types
375

Dropped files

PID
Process
Filename
Type
2840RdrCEF.exe
MD5:
SHA256:
1432AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\TESTINGbinary
MD5:DC84B0D741E5BEAE8070013ADDCC8C28
SHA256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
1432AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\SOPHIA.jsonbinary
MD5:01F233C92A89C705229A0D63D09F846A
SHA256:62137C4381ACC2DE8BCA158AD9D9CE730BD7A96A39A2FB64CE7CFA5C861CF7B4
2840RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0binary
MD5:CDBF823D014000B87337AB022755ACF9
SHA256:1DCBD00202B67CBC6821AD39D42E81EA2BE174C555F971764CA979F5DD5A5A6A
1432AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-240215192643Z-155.bmpimage
MD5:D392FF5C9D64D6F5A7AFCBCD3DF350CF
SHA256:A3A1A352DFBA96CF4873B8DA101F3FF832FAFB4C0D7EF49041C1BF23450E0DD6
2840RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\72d9f526d2e2e7c8_0binary
MD5:7934B9B6147DFFFB32E380642B411BF7
SHA256:C8C715CFE470E374A46BE02E47DCD5166A2BA6B1A67C7A9D2FD8D3542B449609
2840RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0binary
MD5:14894BCE8EBCC192BBD1784B84EB4AE9
SHA256:063BFAC96A41817E48FFE5605B3F11FD4E29A6C39B3BE511B4E69EFD46179ECD
2840RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0binary
MD5:152EA050B4A0F5C89FF5654CB1AC9FD4
SHA256:3454D5F3C52DBCBCDC8884593330ABE8E3FB695723960F46102F7B799AFB2B7A
2840RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0binary
MD5:35EB63C713A29DD3B9D0DCC2DDE90F42
SHA256:C6733DD6C71FEE22893C44C1D77D4E512F4BFFB1CE302EA8A2CD3001F268E077
2840RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\aba6710fde0876af_0binary
MD5:F3B77F9B6479B9A6CA9EB4830B9E0E7E
SHA256:A34F3EED5042A8C6D7B0AE0593C06F27DCDDB9D44B27FC13368B72D85D6A6071
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
69
DNS requests
82
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2472
AcroRd32.exe
GET
304
2.16.115.177:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?adf0414906a3d192
unknown
unknown
2472
AcroRd32.exe
GET
304
2.16.115.177:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?956c1609c0d25c3f
unknown
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e90c163b6659448e
unknown
compressed
65.2 Kb
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e2ddf83a2417bb20
unknown
compressed
65.2 Kb
unknown
3728
SearchProtocolHost.exe
OPTIONS
200
193.178.210.226:80
http://193.178.210.226/
unknown
unknown
2472
AcroRd32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
binary
471 b
unknown
828
svchost.exe
OPTIONS
400
193.178.210.226:80
http://193.178.210.226/documents/reader_update.zip/reader_update.exe
unknown
html
226 b
unknown
828
svchost.exe
OPTIONS
400
193.178.210.226:80
http://193.178.210.226/documents/reader_update.zip/reader_update.exe
unknown
html
226 b
unknown
828
svchost.exe
OPTIONS
400
193.178.210.226:80
http://193.178.210.226/documents/reader_update.zip/reader_update.exe
unknown
html
226 b
unknown
828
svchost.exe
OPTIONS
400
193.178.210.226:80
http://193.178.210.226/documents/reader_update.zip/reader_update.exe
unknown
html
226 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2840
RdrCEF.exe
104.124.108.165:443
geo2.adobe.com
AKAMAI-AS
FR
unknown
2840
RdrCEF.exe
52.202.204.11:443
p13n.adobe.io
AMAZON-AES
US
unknown
2472
AcroRd32.exe
2.16.115.178:443
acroipm2.adobe.com
Akamai International B.V.
GB
unknown
2472
AcroRd32.exe
2.16.115.177:80
ctldl.windowsupdate.com
Akamai International B.V.
GB
unknown
2472
AcroRd32.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2840
RdrCEF.exe
23.41.212.24:443
armmf.adobe.com
AKAMAI-AS
DE
unknown
3984
msedge.exe
239.255.255.250:1900
unknown

DNS requests

Domain
IP
Reputation
geo2.adobe.com
  • 104.124.108.165
whitelisted
p13n.adobe.io
  • 52.202.204.11
  • 54.227.187.23
  • 23.22.254.206
  • 52.5.13.197
whitelisted
armmf.adobe.com
  • 23.41.212.24
whitelisted
acroipm2.adobe.com
  • 2.16.115.178
  • 2.16.115.152
whitelisted
ctldl.windowsupdate.com
  • 2.16.115.177
  • 2.16.115.176
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
monitor.clickcease.com
  • 20.234.104.33
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
otiunmonisky2m.com
  • 185.248.144.235
unknown

Threats

PID
Process
Class
Message
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
1 ETPRO signatures available at the full report
Process
Message
msedge.exe
[0215/192754.744:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)