File name:

32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe

Full analysis: https://app.any.run/tasks/74fce610-eac4-40a2-83d6-576a84d4220f
Verdict: Malicious activity
Analysis date: December 14, 2024, 07:01:18
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

290905106503753D8BD791403E04FB04

SHA1:

A9BA718E1742482506325C18B3559F2282528343

SHA256:

32E950B63131F1AAF640047618A1AC8E380131C01D5A1A823DCE9711308272E3

SSDEEP:

49152:RTcoT2qHn9lkx0KQ1uBH9jIMfk3+Xc1c7DUiVQoxiWtQHcXBc+kA7hH7AvH5F0g2:T2qHnkxJB9jIMM3+M1c7DUiqoxicQHcL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 4684)
      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6160)
      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6292)
      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 3560)
  • SUSPICIOUS

    • Creates file in the systems drive root

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
    • Reads security settings of Internet Explorer

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
    • Application launched itself

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
  • INFO

    • Checks supported languages

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
    • Reads the computer name

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
    • Reads the machine GUID from the registry

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
    • Disables trace logs

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
    • Process checks computer location settings

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
    • Checks proxy server information

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
    • The process uses the downloaded file

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
    • Application launched itself

      • Acrobat.exe (PID: 1064)
      • AcroCEF.exe (PID: 5460)
    • Reads the software policy settings

      • 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe (PID: 6688)
    • Sends debugging messages

      • Acrobat.exe (PID: 4592)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1995:05:25 03:45:10+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 80
CodeSize: 1606656
InitializedDataSize: 51712
UninitializedDataSize: -
EntryPoint: 0x18a35e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.5.6.7
ProductVersionNumber: 3.5.6.7
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: 9C84JF2JE82EE;385G?J7J?3
CompanyName: =2>46A4BBI=<2EE:@
FileDescription: EBFBIA<6@FG=29CE355@D:?H
FileVersion: 3.5.6.7
InternalName: FINAL_PDF.exe
LegalCopyright: Copyright © 1998 =2>46A4BBI=<2EE:@
OriginalFileName: FINAL_PDF.exe
ProductName: EBFBIA<6@FG=29CE355@D:?H
ProductVersion: 3.5.6.7
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
16
Malicious processes
1
Suspicious processes
4

Behavior graph

Click at the process to see the details
start 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe acrobat.exe no specs acrobat.exe no specs 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe no specs 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe no specs acrocef.exe no specs acrocef.exe no specs 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1064"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\admin\Documents\OUCH_SOKHENG.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1476"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=2752 --field-trial-handle=1660,i,9779327856426164901,5009466532814939512,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2676"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --first-renderer-process --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2336 --field-trial-handle=1660,i,9779327856426164901,5009466532814939512,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3172"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2192 --field-trial-handle=1660,i,9779327856426164901,5009466532814939512,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
AcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3560"C:\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe"C:\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
User:
admin
Company:
=2>46A4BBI=<2EE:@
Integrity Level:
MEDIUM
Description:
EBFBIA<6@FG=29CE355@D:?H
Version:
3.5.6.7
3632"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=3020 --field-trial-handle=1660,i,9779327856426164901,5009466532814939512,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3640"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=disabled --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1844 --field-trial-handle=1660,i,9779327856426164901,5009466532814939512,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4592"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" --type=renderer /prefetch:1 "C:\Users\admin\Documents\OUCH_SOKHENG.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4684"C:\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe"C:\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
User:
admin
Company:
=2>46A4BBI=<2EE:@
Integrity Level:
MEDIUM
Description:
EBFBIA<6@FG=29CE355@D:?H
Exit code:
4294967295
Version:
3.5.6.7
Modules
Images
c:\32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5460"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16514043C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
10 685
Read events
10 628
Write events
52
Delete events
5

Modification events

(PID) Process:(6688) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6688) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6688) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6688) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6688) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6688) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6688) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6688) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6688) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6688) 32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
0
Suspicious files
119
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
4592Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SharedDataEventsbinary
MD5:F4BDA26D39EA05439AAC0764EBBC5F40
SHA256:3B8A872ADAAD93EEA5A79F8F642078952B9A7B0D1EF088E1257375EC70ED2341
4592Acrobat.exeC:\Users\admin\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txttext
MD5:EF65172D43F973622160E30E16C00B1C
SHA256:CD0901B1EADE1D9D11D9CEEA7DBD4EECFFEA904D2662D5E762901B9B6B498682
4592Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTINGbinary
MD5:DC84B0D741E5BEAE8070013ADDCC8C28
SHA256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
4592Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\AdobeFnt23.lst.4592binary
MD5:366B140BAFC863B7E366AA1E51604759
SHA256:CBC8B288DBD2C72432081CF33CEF431572A94C7FB89DBCD59973B99E3871814E
1064Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lstbinary
MD5:366B140BAFC863B7E366AA1E51604759
SHA256:CBC8B288DBD2C72432081CF33CEF431572A94C7FB89DBCD59973B99E3871814E
4592Acrobat.exeC:\Users\admin\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.1.20093.6 2024-12-14 07-02-19-680.logtext
MD5:460C6041966002D8384A18C895A65EB0
SHA256:C83EC6E8FB3EC62481289C033238C1D9B08DB8076EAAD304099FD7A7F594F1B9
4592Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.jsonbinary
MD5:837C1211E392A24D64C670DC10E8DA1B
SHA256:8013AC030684B86D754BBFBAB8A9CEC20CAA4DD9C03022715FF353DC10E14031
668832e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exeC:\Users\admin\Documents\OUCH_SOKHENG.pdfpdf
MD5:A1F5622DDD5E328E8873DBBCF9203F6D
SHA256:A1E96ED0D011F7731B7DABCDDF559A19DD1B3C7C453122D44F8477CF21507E7B
5460AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.oldtext
MD5:EB1590F2607E1CE46DBF6A521F772EA0
SHA256:4355D9A8A115BA4E41178B456A8A5578846EB1F7EC9509249C2405F758F31731
5460AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0binary
MD5:34EB222DBDEC3563278EA1E51BFF16F0
SHA256:8CB4F040BF40CEEAA15B8779180543BC0A6869154206A28FECFED2033A6F8CB7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
35
DNS requests
19
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1228
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1228
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
440
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
23.212.110.162:443
www.bing.com
Akamai International B.V.
CZ
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4712
MoUsoCoreWorker.exe
2.19.217.218:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6688
32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
91.134.10.168:443
i.ibb.co
OVH SAS
FR
shared
1176
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
www.bing.com
  • 23.212.110.162
  • 23.212.110.170
  • 23.212.110.176
  • 23.212.110.171
  • 23.212.110.202
  • 23.212.110.184
  • 23.212.110.203
  • 23.212.110.186
  • 23.212.110.200
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.microsoft.com
  • 2.19.217.218
whitelisted
google.com
  • 142.250.181.238
whitelisted
i.ibb.co
  • 91.134.10.168
  • 91.134.10.182
  • 91.134.9.159
  • 91.134.10.127
  • 91.134.82.79
  • 91.134.9.160
shared
login.live.com
  • 40.126.32.76
  • 40.126.32.72
  • 20.190.160.22
  • 40.126.32.140
  • 40.126.32.134
  • 40.126.32.138
  • 40.126.32.68
  • 40.126.32.133
whitelisted
go.microsoft.com
  • 184.30.17.189
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

PID
Process
Class
Message
6688
32e950b63131f1aaf640047618a1ac8e380131c01d5a1a823dce9711308272e3.exe
Not Suspicious Traffic
INFO [ANY.RUN] Image hosting service ImgBB
No debug info