| File name: | Advanced CMC US_May2024_info+booking (2).pdf |
| Full analysis: | https://app.any.run/tasks/556dc5ef-4c31-4859-9c96-de85248de644 |
| Verdict: | Malicious activity |
| Analysis date: | April 23, 2024, 15:03:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/pdf |
| File info: | PDF document, version 1.7, 7 pages |
| MD5: | 1C5ECA8C0EA2AE6AB77318B739D02A86 |
| SHA1: | C2C69EF206A034E31A4633AC20D3B78BF3008A3C |
| SHA256: | 86EF9DA8A40E7A12685EF248BD17AF1C95B0DDC29BCFB58CFD9F3761C895DA73 |
| SSDEEP: | 24576:vwc6NFMQZpvJmS4i3z7AiW8AGSGvDpj3G4ZNEQZCgy/X/ouFQujaBzx8a+9vrVRW:vwc6NFMQZpvJmS4i3z7AiWXGSGvDpj3P |
| | | Adobe Portable Document Format (100) |
| PDFVersion: | 1.7 |
|---|---|
| Linearized: | No |
| PageCount: | 7 |
| Language: | hu |
| HasXFA: | No |
| ModifyDate: | 2024:04:01 08:44:22Z |
| Producer: | 3-Heights™ PDF Toolbox API 6.12.0.6 (http://www.pdf-tools.com) |
| ProfileCMMType: | Linotronic |
|---|---|
| ProfileVersion: | 2.1.0 |
| ProfileClass: | Display Device Profile |
| ColorSpaceData: | RGB |
| ProfileConnectionSpace: | XYZ |
| ProfileDateTime: | 1998:02:09 06:49:00 |
| ProfileFileSignature: | acsp |
| PrimaryPlatform: | Microsoft Corporation |
| CMMFlags: | Not Embedded, Independent |
| DeviceManufacturer: | Hewlett-Packard |
| DeviceModel: | sRGB |
| DeviceAttributes: | Reflective, Glossy, Positive, Color |
| RenderingIntent: | Perceptual |
| ConnectionSpaceIlluminant: | 0.9642 1 0.82491 |
| ProfileCreator: | Hewlett-Packard |
| ProfileID: | - |
| ProfileCopyright: | Copyright (c) 1998 Hewlett-Packard Company |
| ProfileDescription: | sRGB IEC61966-2.1 |
| MediaWhitePoint: | 0.95045 1 1.08905 |
| MediaBlackPoint: | 0 0 0 |
| RedMatrixColumn: | 0.43607 0.22249 0.01392 |
| GreenMatrixColumn: | 0.38515 0.71687 0.09708 |
| BlueMatrixColumn: | 0.14307 0.06061 0.7141 |
| DeviceMfgDesc: | IEC http://www.iec.ch |
| DeviceModelDesc: | IEC 61966-2.1 Default RGB colour space - sRGB |
| ViewingCondDesc: | Reference Viewing Condition in IEC61966-2.1 |
| ViewingCondIlluminant: | 19.6445 20.3718 16.8089 |
| ViewingCondSurround: | 3.92889 4.07439 3.36179 |
| ViewingCondIlluminantType: | D50 |
| Luminance: | 76.03647 80 87.12462 |
| MeasurementObserver: | CIE 1931 |
| MeasurementBacking: | 0 0 0 |
| MeasurementGeometry: | Unknown |
| MeasurementFlare: | 0.999% |
| MeasurementIlluminant: | D65 |
| Technology: | Cathode Ray Tube Display |
| RedTRC: | (Binary data 2060 bytes, use -b option to extract) |
| GreenTRC: | (Binary data 2060 bytes, use -b option to extract) |
| BlueTRC: | (Binary data 2060 bytes, use -b option to extract) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 324 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\AppData\Local\Temp\Advanced CMC US_May2024_info+booking (2).pdf" | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | explorer.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe Acrobat Reader DC Version: 20.13.20064.405839 Modules
| |||||||||||||||
| 492 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3336 --field-trial-handle=1404,i,5517750732356388729,3216520126779351915,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 568 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4816 --field-trial-handle=1404,i,5517750732356388729,3216520126779351915,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 572 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=gpu-process --field-trial-handle=1192,15417427592172085651,16368106669321679514,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --lang=en-US --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAABAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --service-request-channel-token=6877376219195879314 --mojo-platform-channel-handle=1240 --allow-no-sandbox-job --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | — | RdrCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe RdrCEF Exit code: 1 Version: 20.13.20064.405839 Modules
| |||||||||||||||
| 584 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --touch-events=enabled --field-trial-handle=1192,15417427592172085651,16368106669321679514,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-gpu-compositing --lang=en-US --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8576465769715843335 --renderer-client-id=2 --mojo-platform-channel-handle=1200 --allow-no-sandbox-job /prefetch:1 | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | — | RdrCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe RdrCEF Exit code: 0 Version: 20.13.20064.405839 Modules
| |||||||||||||||
| 584 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x640bf598,0x640bf5a8,0x640bf5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 604 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1204 --field-trial-handle=1404,i,5517750732356388729,3216520126779351915,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 796 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=gpu-process --field-trial-handle=1192,15417427592172085651,16368106669321679514,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --lang=en-US --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAABAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --service-request-channel-token=11028437182706036236 --mojo-platform-channel-handle=1272 --allow-no-sandbox-job --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | — | RdrCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe RdrCEF Exit code: 1 Version: 20.13.20064.405839 Modules
| |||||||||||||||
| 876 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=4340 --field-trial-handle=1404,i,5517750732356388729,3216520126779351915,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 908 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5760 --field-trial-handle=1404,i,5517750732356388729,3216520126779351915,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3248) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection |
| Operation: | write | Name: | bLastExitNormal |
Value: 0 | |||
| (PID) Process: | (3248) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral |
| Operation: | write | Name: | aDefaultRHPViewModeL |
Value: Expanded | |||
| (PID) Process: | (3248) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral |
| Operation: | write | Name: | bExpandRHPInViewer |
Value: 1 | |||
| (PID) Process: | (3248) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral |
| Operation: | write | Name: | uLastAppLaunchTimeStamp |
Value: 192691896 | |||
| (PID) Process: | (3248) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral |
| Operation: | write | Name: | iNumReaderLaunches |
Value: 6 | |||
| (PID) Process: | (3248) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\FillSign |
| Operation: | write | Name: | uFillSignVariantTrackingTime |
Value: | |||
| (PID) Process: | (3248) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\NoTimeOut |
| Operation: | write | Name: | smailto |
Value: 5900 | |||
| (PID) Process: | (3248) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ToolsSearch |
| Operation: | write | Name: | iSearchHintIndex |
Value: 0 | |||
| (PID) Process: | (3248) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs |
| Operation: | write | Name: | bForms_AdhocWorkflowBackup |
Value: 0 | |||
| (PID) Process: | (3248) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs |
| Operation: | write | Name: | bJSCache_GlobData |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3264 | RdrCEF.exe | — | ||
MD5:— | SHA256:— | |||
| 3248 | AcroRd32.exe | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\SOPHIA.json | binary | |
MD5:01F233C92A89C705229A0D63D09F846A | SHA256:62137C4381ACC2DE8BCA158AD9D9CE730BD7A96A39A2FB64CE7CFA5C861CF7B4 | |||
| 3264 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0 | binary | |
MD5:7E0BBEAAD587944400A9468B626970AE | SHA256:56278C7DA6203F320350D81091C93E8AC34875983A88B1FA003ACCC8F52A1AD6 | |||
| 3264 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c84d92a9dbce3e0_0 | binary | |
MD5:23A49C2F9139F95A47B3ACD7F6C875BE | SHA256:83B63AB96659AB865E7CFB315B40CEE28B952472E8DF2472FCB2D2E5499C86D7 | |||
| 3264 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8e417e79df3bf0e9_0 | binary | |
MD5:D6DD3390FECA4F4939841D09792F99B2 | SHA256:8CFEFB441844E5E0890E1932575D0BE930CAA437BF4983087A5B422486870B98 | |||
| 3264 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\946896ee27df7947_0 | binary | |
MD5:56FBDBDE98AD8EE892DFBB2879297ADB | SHA256:D9393162D34E193D8985A06D5BE90C7B80AD7DE600DA58165FD3A1ADFE4D4052 | |||
| 3264 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old~RF1bfab8.TMP | text | |
MD5:FF09ACD52BCF65FACA015BE3EC091DCA | SHA256:75176465D641ECB19503834BA4480B78CDE201E3A8256CC02219E5706FFD007A | |||
| 3264 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0 | binary | |
MD5:6D82FB1941638CD203714B07335DE9F6 | SHA256:C7A432F47D78773B1D910522B1D2F76996775F301B85B29890F4A73A6D5B07D4 | |||
| 3264 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\72d9f526d2e2e7c8_0 | binary | |
MD5:17C29EB5FFA99DDF5E77D1D097741329 | SHA256:3593BC8E8AA5F8CCD9511E20B787DB56E5CD5EC860AF06B29D27C2775AA829ED | |||
| 3264 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old | text | |
MD5:5705BEF2F423E8D5EF921B2CBEE16FB9 | SHA256:154DF2B4012DEAA86794EF8A0C44FB435615A3143AA3336EA79D2A9544C14900 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3348 | msedge.exe | GET | 200 | 192.229.221.95:80 | http://cacerts.digicert.com/DigiCertGlobalRootCA.crt | unknown | — | — | unknown |
3348 | msedge.exe | GET | 200 | 192.229.221.95:80 | http://cacerts.digicert.com/DigiCertSHA2SecureServerCA-2.crt | unknown | — | — | unknown |
324 | AcroRd32.exe | GET | 304 | 2.21.240.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e7774ef999103f84 | unknown | — | — | unknown |
324 | AcroRd32.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | unknown | — | — | unknown |
1080 | svchost.exe | GET | — | 2.21.240.200:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2c6b76ad7be093c1 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2240 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
3348 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3348 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3264 | RdrCEF.exe | 184.30.152.141:443 | geo2.adobe.com | AKAMAI-AS | CA | unknown |
3348 | msedge.exe | 13.107.42.14:443 | www.linkedin.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3264 | RdrCEF.exe | 34.193.227.236:443 | p13n.adobe.io | AMAZON-AES | US | unknown |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| whitelisted |
geo2.adobe.com |
| whitelisted |
www.linkedin.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
p13n.adobe.io |
| whitelisted |
static.licdn.com |
| whitelisted |
arc.msn.com |
| whitelisted |
media.licdn.com |
| whitelisted |
ponf.linkedin.com |
| unknown |
accounts.google.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
3348 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
3348 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
3348 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
3348 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
3348 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
3348 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
3348 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] A free CDN for open source projects (jsdelivr .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] A free CDN for open source projects (jsdelivr .net) |
Process | Message |
|---|---|
msedge.exe | [0423/160423.196:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)
|
msedge.exe | [0423/160437.806:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)
|