| File name: | documento 43542562784.pdf |
| Full analysis: | https://app.any.run/tasks/bd36f7b0-cd33-4661-8035-58cf8a63378d |
| Verdict: | Malicious activity |
| Threats: | njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world. |
| Analysis date: | January 22, 2019, 21:45:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/pdf |
| File info: | PDF document, version 1.5 |
| MD5: | 18759B028F308219AF5A5E9E68877358 |
| SHA1: | B712232133B7DF38A532B00BF1654FBAB5EB396D |
| SHA256: | 5D3E39CF694A9DF75E688C44F34DF016EB201C83D7E604E9A81186C36C065328 |
| SSDEEP: | 1536:u/3Wq9pkWtkltWA+1LYiJbsJnTE4bcIO90naLGNVgGO8uQA8tqc0fuwvE:u/3WqLkW4piM4shE4pO90nrNqG7g8V0A |
| | | Adobe Portable Document Format (100) |
| PDFVersion: | 1.5 |
|---|---|
| Linearized: | No |
| PageCount: | 1 |
| Language: | es-CO |
| TaggedPDF: | Yes |
| Title: | - |
| Author: | USUARIO |
| CreateDate: | 2019:01:22 16:05:01-05:00 |
| ModifyDate: | 2019:01:22 16:05:01-05:00 |
| Producer: | Microsoft® PowerPoint® 2013 |
| Creator: | Microsoft® PowerPoint® 2013 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 800 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1784 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1412 | "C:\Users\admin\Downloads\DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe" | C:\Users\admin\Downloads\DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe | — | explorer.exe | |||||||||||
User: admin Company: bielbrief Integrity Level: MEDIUM Description: appropriately Exit code: 1 Version: 4.7.2.2 Modules
| |||||||||||||||
| 1688 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2264.18560\DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | — | DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 1784 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | AcroRd32.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1948 | "C:\Users\admin\Downloads\DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | — | DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 2264 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\DocumentoImagenVista032452348573%20%20DocumentoImagenVista03245234857[2].UUE" | C:\Program Files\WinRAR\WinRAR.exe | iexplore.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2332 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\AppData\Local\Temp\documento 43542562784.pdf" | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | — | AcroRd32.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe Acrobat Reader DC Exit code: 0 Version: 15.23.20070.215641 Modules
| |||||||||||||||
| 2444 | "C:\Users\admin\Downloads\DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | — | DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 2492 | "C:\Users\admin\Downloads\DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe" | C:\Users\admin\Downloads\DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe | — | explorer.exe | |||||||||||
User: admin Company: bielbrief Integrity Level: MEDIUM Description: appropriately Exit code: 1 Version: 4.7.2.2 Modules
| |||||||||||||||
| 2584 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2264.18560\DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2264.18560\DocumentoImagenVista032452348573 DocumentoImagenVista032452348573 DocumentoImagenVista032452348573.exe | — | WinRAR.exe | |||||||||||
User: admin Company: bielbrief Integrity Level: MEDIUM Description: appropriately Exit code: 1 Version: 4.7.2.2 Modules
| |||||||||||||||
| (PID) Process: | (2332) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection |
| Operation: | write | Name: | bLastExitNormal |
Value: 0 | |||
| (PID) Process: | (2332) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral |
| Operation: | write | Name: | bExpandRHPInViewer |
Value: 1 | |||
| (PID) Process: | (2332) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\NoTimeOut |
| Operation: | write | Name: | smailto |
Value: 5900 | |||
| (PID) Process: | (2828) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2828) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2828) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2828) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (2828) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2828) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2828) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active |
| Operation: | write | Name: | {28C2091B-1E8F-11E9-91D7-5254004A04AF} |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2332 | AcroRd32.exe | C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal | — | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF7340AA88E31076D7.TMP | — | |
MD5:— | SHA256:— | |||
| 2332 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R1gq6jos_c4w2g5_1ss.tmp | — | |
MD5:— | SHA256:— | |||
| 2332 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9Rriwwhs_c4w2g4_1ss.tmp | — | |
MD5:— | SHA256:— | |||
| 2332 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R1mvn3wu_c4w2g3_1ss.tmp | — | |
MD5:— | SHA256:— | |||
| 2332 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R1758v0y_c4w2g2_1ss.tmp | — | |
MD5:— | SHA256:— | |||
| 2332 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R1pdl2nl_c4w2g6_1ss.tmp | — | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFC96E42C99F6BE1F4.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2972 | AcroRd32.exe | GET | 304 | 2.16.186.33:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/281_15_23_20070.zip | unknown | — | — | whitelisted |
2972 | AcroRd32.exe | GET | 304 | 2.16.186.33:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/message.zip | unknown | — | — | whitelisted |
2828 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
2972 | AcroRd32.exe | GET | 304 | 2.16.186.33:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/277_15_23_20070.zip | unknown | — | — | whitelisted |
2972 | AcroRd32.exe | GET | 304 | 2.16.186.33:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/280_15_23_20070.zip | unknown | — | — | whitelisted |
1784 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
3076 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
2972 | AcroRd32.exe | GET | 304 | 2.16.186.33:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/278_15_23_20070.zip | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2828 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3536 | iexplore.exe | 162.125.66.6:443 | dl.dropbox.com | Dropbox, Inc. | DE | shared |
2972 | AcroRd32.exe | 2.18.233.74:443 | armmf.adobe.com | Akamai International B.V. | — | whitelisted |
2972 | AcroRd32.exe | 2.16.186.33:80 | acroipm2.adobe.com | Akamai International B.V. | — | whitelisted |
— | — | 2.18.233.74:443 | armmf.adobe.com | Akamai International B.V. | — | whitelisted |
— | — | 23.211.8.250:443 | armmf.adobe.com | Akamai Technologies, Inc. | NL | whitelisted |
3420 | RegAsm.exe | 186.146.240.24:1992 | nuevonjcristal.duckdns.org | Telmex Colombia S.A. | CO | malicious |
1784 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
800 | iexplore.exe | 162.125.66.6:443 | dl.dropbox.com | Dropbox, Inc. | DE | shared |
3076 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
dl.dropbox.com |
| shared |
dl.dropboxusercontent.com |
| shared |
acroipm2.adobe.com |
| whitelisted |
armmf.adobe.com |
| whitelisted |
ardownload2.adobe.com |
| whitelisted |
nuevonjcristal.duckdns.org |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1060 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain |
3420 | RegAsm.exe | A Network Trojan was detected | MALWARE [PTsecurity] njRAT.Gen RAT outbound connection |
3420 | RegAsm.exe | A Network Trojan was detected | ET TROJAN Bladabindi/njRAT CnC Command (ll) |