analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Catalogo-Balocco_2019.pdf

Full analysis: https://app.any.run/tasks/65f086c5-97b1-4e06-bbaf-9238bfb227a8
Verdict: Malicious activity
Analysis date: November 16, 2019, 13:50:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/pdf
File info: PDF document, version 1.5
MD5:

F3C082585A441963E3D0769C33597AF6

SHA1:

1184694372D8C760BE024D4B181ABF80D624B6FD

SHA256:

11A1B594E4802A17D207F894517E222C612A98F9871E5B41699DBD7BC4B742B8

SSDEEP:

24576:A3B023Nk1GW899uz2wLQOVkfzUcxW8NiQN/Gjsdm:EeMWCVwxkf9xWNQN+5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts Internet Explorer

      • AcroRd32.exe (PID: 2040)
    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 2104)
    • Creates files in the program directory

      • AdobeARM.exe (PID: 3772)
  • INFO

    • Reads the hosts file

      • RdrCEF.exe (PID: 3696)
    • Creates files in the user directory

      • AcroRd32.exe (PID: 2040)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 2104)
      • iexplore.exe (PID: 1516)
      • iexplore.exe (PID: 784)
    • Application launched itself

      • AcroRd32.exe (PID: 2040)
      • RdrCEF.exe (PID: 3696)
      • iexplore.exe (PID: 1516)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 784)
    • Changes internet zones settings

      • iexplore.exe (PID: 1516)
    • Reads internet explorer settings

      • iexplore.exe (PID: 784)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.pdf | Adobe Portable Document Format (100)

EXIF

PDF

PDFVersion: 1.5
Linearized: No
PageCount: 6
Language: en-US
TaggedPDF: Yes
Author: user
Creator: Microsoft® Word 2016
CreateDate: 2019:10:15 15:20:36+01:00
ModifyDate: 2019:10:15 15:20:36+01:00
Producer: Microsoft® Word 2016
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
10
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start acrord32.exe acrord32.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs adobearm.exe no specs reader_sl.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2040"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\AppData\Local\Temp\Catalogo-Balocco_2019.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
explorer.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat Reader DC
Version:
15.23.20070.215641
3908"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\AppData\Local\Temp\Catalogo-Balocco_2019.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Version:
15.23.20070.215641
3696"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --backgroundcolor=16448250C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe RdrCEF
Version:
15.23.20053.211670
3984"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3696.0.1807847542\1347365965" --allow-no-sandbox-job /prefetch:673131151C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Version:
15.23.20053.211670
3848"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3696.1.884288137\852504911" --allow-no-sandbox-job /prefetch:673131151C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Version:
15.23.20053.211670
1516"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
AcroRd32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
784"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1516 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
3221225547
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
2104C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Exit code:
0
Version:
26,0,0,131
3772"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" /PRODUCT:Reader /VERSION:15.0 /MODE:3C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Reader and Acrobat Manager
Version:
1.824.27.2646
3356"C:\Program Files\Adobe\Acrobat Reader DC\Reader\Reader_sl.exe" C:\Program Files\Adobe\Acrobat Reader DC\Reader\Reader_sl.exeAdobeARM.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat SpeedLauncher
Exit code:
0
Version:
15.23.20053.211670
Total events
1 005
Read events
647
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
7
Text files
220
Unknown types
26

Dropped files

PID
Process
Filename
Type
1516iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
1516iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\V2EPNMMX\supermarketitaly_ru[1].txt
MD5:
SHA256:
784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:5CFEC98C0CB528CC644A45125952C25D
SHA256:F6E551339BFC66F5022171D364E4840AA34D173E93701A2ADB64367B5DB02E58
3908AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessagessqlite
MD5:0B8BDBB076B08E5036ED7E9D59564860
SHA256:60E1FE70C2C455F22D9BE3E19CAB4FF36C4D12D92B5058EE5CE71A8C8373E3EB
3908AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\UserCache.binbinary
MD5:1BEFDB1BA3C9C00E2D2807F592C97962
SHA256:CE3C34E248F53C72C032496C8A0E3D7F332A31C2320B939F98569DCB5DEB1BA7
3908AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journalbinary
MD5:DEBDDBD78F94E821B57A29893F64C5E6
SHA256:F982E848DC1D4564D9C0D58A6255A21B89630DE86E9C61DA2572071234F5FB8F
784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WS1N5DL3\main[2].css
MD5:
SHA256:
784iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@supermarketitaly[1].txttext
MD5:B4839C71DFABCA0780513808BDB17FAA
SHA256:67F709F3EA9AA8AC9D060A488CA32E6DEBCAEAA0E026A807574A757622A09BFD
784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MU83IJQZ\fonts[1].csstext
MD5:AB59F2F73470EFBE9A86FC8DE9565D1F
SHA256:A16367B7B1ABE099FCE1D10A7D5D0730B8C26493F4DBA33B1A7AFED08B0E9FBC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
85
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
784
iexplore.exe
GET
301
136.243.210.61:80
http://www.supermarketitaly.ru/
DE
whitelisted
784
iexplore.exe
GET
301
144.76.241.36:80
http://supermarketitaly.ru/
DE
html
751 b
suspicious
2040
AcroRd32.exe
GET
304
2.16.186.97:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/278_15_23_20070.zip
unknown
whitelisted
2040
AcroRd32.exe
GET
304
2.16.186.97:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/277_15_23_20070.zip
unknown
whitelisted
2040
AcroRd32.exe
GET
304
2.16.186.97:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/281_15_23_20070.zip
unknown
whitelisted
2040
AcroRd32.exe
GET
304
2.16.186.97:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/message.zip
unknown
whitelisted
2040
AcroRd32.exe
GET
304
2.16.186.97:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/280_15_23_20070.zip
unknown
whitelisted
1516
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1516
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
784
iexplore.exe
136.243.210.61:80
www.supermarketitaly.ru
Hetzner Online GmbH
DE
unknown
784
iexplore.exe
87.250.250.119:443
mc.yandex.ru
YANDEX LLC
RU
whitelisted
784
iexplore.exe
172.217.22.106:443
fonts.googleapis.com
Google Inc.
US
whitelisted
784
iexplore.exe
144.76.241.36:80
supermarketitaly.ru
Hetzner Online GmbH
DE
suspicious
784
iexplore.exe
144.76.241.36:443
supermarketitaly.ru
Hetzner Online GmbH
DE
suspicious
784
iexplore.exe
94.130.133.70:443
sl-h-statistics-ch-1.storeland.ru
Hetzner Online GmbH
DE
unknown
784
iexplore.exe
104.17.64.4:443
cdnjs.cloudflare.com
Cloudflare Inc
US
unknown
784
iexplore.exe
172.217.16.163:443
fonts.gstatic.com
Google Inc.
US
whitelisted
784
iexplore.exe
144.76.183.239:443
statistics3.storeland.ru
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.supermarketitaly.ru
  • 136.243.210.61
  • 144.76.135.58
  • 144.76.135.61
unknown
supermarketitaly.ru
  • 144.76.241.36
  • 144.76.135.60
  • 94.130.215.93
suspicious
fonts.googleapis.com
  • 172.217.22.106
whitelisted
d.stat01.com
  • 104.24.11.75
  • 104.24.10.75
suspicious
cdnjs.cloudflare.com
  • 104.17.64.4
  • 104.17.65.4
whitelisted
fonts.gstatic.com
  • 172.217.16.163
whitelisted
statistics3.storeland.ru
  • 144.76.183.239
unknown
sl-h-statistics-ch-1.storeland.ru
  • 94.130.133.70
whitelisted
mc.yandex.ru
  • 87.250.250.119
  • 93.158.134.119
  • 77.88.21.119
  • 87.250.251.119
whitelisted

Threats

No threats detected
No debug info