analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

cb7c86b23fe81bcf2a8fedf7273fe0d7.pdf

Full analysis: https://app.any.run/tasks/bb6fc88b-c504-4589-a31e-8d993ad0dd48
Verdict: Malicious activity
Analysis date: January 24, 2022, 15:53:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/pdf
File info: PDF document, version 1.4
MD5:

CB7C86B23FE81BCF2A8FEDF7273FE0D7

SHA1:

C4C22A81B42F1657A8158AC8F98008056511A11C

SHA256:

A82E9297DA902F3E4C68758BD5EEC73E965CD88DB7CB34B1C6AB5C1E84DBD8F6

SSDEEP:

3072:9KCC+9PJfbL9MSStadBsq2aZ1SDuR6diwz/n0:97C+9Pl9jBbrxZUldzc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • pingsender.exe (PID: 1864)
      • pingsender.exe (PID: 2212)
      • pingsender.exe (PID: 2728)
      • pingsender.exe (PID: 3712)
      • pingsender.exe (PID: 760)
      • pingsender.exe (PID: 3644)
      • pingsender.exe (PID: 3708)
      • pingsender.exe (PID: 1004)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3836)
      • helper.exe (PID: 3820)
    • Actions looks like stealing of personal data

      • pingsender.exe (PID: 2212)
      • pingsender.exe (PID: 1864)
      • pingsender.exe (PID: 2728)
      • pingsender.exe (PID: 3712)
      • pingsender.exe (PID: 760)
      • pingsender.exe (PID: 3644)
      • pingsender.exe (PID: 3708)
      • pingsender.exe (PID: 1004)
    • Drops executable file immediately after starts

      • helper.exe (PID: 3820)
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • firefox.exe (PID: 1404)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 1404)
      • AdobeARM.exe (PID: 3264)
      • helper.exe (PID: 3820)
    • Loads DLL from Mozilla Firefox

      • pingsender.exe (PID: 1864)
      • pingsender.exe (PID: 2212)
      • pingsender.exe (PID: 2728)
      • pingsender.exe (PID: 760)
      • pingsender.exe (PID: 3712)
      • pingsender.exe (PID: 3644)
      • pingsender.exe (PID: 3708)
      • pingsender.exe (PID: 1004)
    • Reads the computer name

      • AdobeARM.exe (PID: 3264)
      • pingsender.exe (PID: 1864)
      • pingsender.exe (PID: 2212)
      • helper.exe (PID: 3820)
      • pingsender.exe (PID: 2728)
      • pingsender.exe (PID: 3712)
      • pingsender.exe (PID: 760)
      • pingsender.exe (PID: 3644)
      • pingsender.exe (PID: 3708)
      • pingsender.exe (PID: 1004)
    • Checks supported languages

      • Reader_sl.exe (PID: 2404)
      • AdobeARM.exe (PID: 3264)
      • pingsender.exe (PID: 1864)
      • pingsender.exe (PID: 2212)
      • helper.exe (PID: 3820)
      • pingsender.exe (PID: 2728)
      • pingsender.exe (PID: 3712)
      • pingsender.exe (PID: 760)
      • pingsender.exe (PID: 3644)
      • pingsender.exe (PID: 3708)
      • pingsender.exe (PID: 1004)
    • Changes default file association

      • helper.exe (PID: 3820)
    • Creates files in the program directory

      • AdobeARM.exe (PID: 3264)
    • Drops a file with too old compile date

      • helper.exe (PID: 3820)
  • INFO

    • Checks supported languages

      • AcroRd32.exe (PID: 1324)
      • RdrCEF.exe (PID: 3720)
      • AcroRd32.exe (PID: 1304)
      • RdrCEF.exe (PID: 1632)
      • RdrCEF.exe (PID: 3008)
      • RdrCEF.exe (PID: 2504)
      • RdrCEF.exe (PID: 3228)
      • RdrCEF.exe (PID: 1444)
      • firefox.exe (PID: 3544)
      • RdrCEF.exe (PID: 3048)
      • firefox.exe (PID: 2492)
      • firefox.exe (PID: 276)
      • RdrCEF.exe (PID: 880)
      • firefox.exe (PID: 3068)
      • firefox.exe (PID: 3912)
      • firefox.exe (PID: 1292)
      • firefox.exe (PID: 2972)
      • firefox.exe (PID: 3428)
      • firefox.exe (PID: 1404)
      • firefox.exe (PID: 2252)
      • firefox.exe (PID: 3456)
      • firefox.exe (PID: 2508)
      • firefox.exe (PID: 2560)
      • firefox.exe (PID: 2712)
      • firefox.exe (PID: 3628)
      • firefox.exe (PID: 3988)
      • firefox.exe (PID: 3876)
      • firefox.exe (PID: 3564)
      • firefox.exe (PID: 2140)
      • firefox.exe (PID: 2508)
      • firefox.exe (PID: 3576)
      • firefox.exe (PID: 1800)
      • firefox.exe (PID: 2952)
      • firefox.exe (PID: 3244)
      • firefox.exe (PID: 3696)
      • firefox.exe (PID: 3160)
      • firefox.exe (PID: 2608)
      • firefox.exe (PID: 1968)
      • firefox.exe (PID: 1548)
      • firefox.exe (PID: 4092)
      • firefox.exe (PID: 2892)
    • Reads the computer name

      • RdrCEF.exe (PID: 3720)
      • AcroRd32.exe (PID: 1324)
      • AcroRd32.exe (PID: 1304)
      • firefox.exe (PID: 3544)
      • firefox.exe (PID: 276)
      • firefox.exe (PID: 3428)
      • firefox.exe (PID: 3068)
      • firefox.exe (PID: 2972)
      • firefox.exe (PID: 1292)
      • firefox.exe (PID: 1404)
      • firefox.exe (PID: 2508)
      • firefox.exe (PID: 3628)
      • firefox.exe (PID: 3456)
      • firefox.exe (PID: 2560)
      • firefox.exe (PID: 2252)
      • firefox.exe (PID: 2712)
      • firefox.exe (PID: 3988)
      • firefox.exe (PID: 2140)
      • firefox.exe (PID: 2508)
      • firefox.exe (PID: 3564)
      • firefox.exe (PID: 2952)
      • firefox.exe (PID: 1800)
      • firefox.exe (PID: 3576)
      • firefox.exe (PID: 3244)
      • firefox.exe (PID: 3696)
      • firefox.exe (PID: 2608)
      • firefox.exe (PID: 1968)
      • firefox.exe (PID: 2892)
      • firefox.exe (PID: 1548)
      • firefox.exe (PID: 4092)
    • Reads CPU info

      • AcroRd32.exe (PID: 1304)
      • firefox.exe (PID: 3544)
      • firefox.exe (PID: 1404)
      • firefox.exe (PID: 2140)
      • firefox.exe (PID: 3696)
    • Application launched itself

      • AcroRd32.exe (PID: 1324)
      • RdrCEF.exe (PID: 3720)
      • firefox.exe (PID: 2492)
      • firefox.exe (PID: 3544)
      • firefox.exe (PID: 3912)
      • firefox.exe (PID: 1404)
      • firefox.exe (PID: 3876)
      • firefox.exe (PID: 2140)
      • firefox.exe (PID: 3696)
      • firefox.exe (PID: 3160)
    • Searches for installed software

      • AcroRd32.exe (PID: 1324)
      • AcroRd32.exe (PID: 1304)
    • Reads the hosts file

      • RdrCEF.exe (PID: 3720)
    • Reads settings of System Certificates

      • AcroRd32.exe (PID: 1324)
      • RdrCEF.exe (PID: 3720)
      • pingsender.exe (PID: 2212)
      • pingsender.exe (PID: 1864)
      • AdobeARM.exe (PID: 3264)
      • pingsender.exe (PID: 3712)
      • pingsender.exe (PID: 2728)
      • pingsender.exe (PID: 760)
      • pingsender.exe (PID: 3644)
      • pingsender.exe (PID: 3708)
      • pingsender.exe (PID: 1004)
    • Manual execution by user

      • firefox.exe (PID: 2492)
      • firefox.exe (PID: 3876)
    • Checks Windows Trust Settings

      • AcroRd32.exe (PID: 1324)
      • pingsender.exe (PID: 1864)
      • pingsender.exe (PID: 2212)
      • AdobeARM.exe (PID: 3264)
      • pingsender.exe (PID: 2728)
      • pingsender.exe (PID: 3712)
      • pingsender.exe (PID: 760)
      • pingsender.exe (PID: 3644)
      • pingsender.exe (PID: 3708)
      • pingsender.exe (PID: 1004)
    • Creates files in the program directory

      • firefox.exe (PID: 3544)
      • firefox.exe (PID: 1404)
      • firefox.exe (PID: 2140)
      • firefox.exe (PID: 3696)
    • Reads the date of Windows installation

      • firefox.exe (PID: 3544)
      • firefox.exe (PID: 1404)
      • firefox.exe (PID: 2140)
      • firefox.exe (PID: 3696)
    • Creates files in the user directory

      • firefox.exe (PID: 3544)
      • firefox.exe (PID: 1404)
      • firefox.exe (PID: 2140)
      • firefox.exe (PID: 3696)
    • Dropped object may contain Bitcoin addresses

      • firefox.exe (PID: 1404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.pdf | Adobe Portable Document Format (100)

EXIF

PDF

PDFVersion: 1.4
Linearized: No
Title: Božanstvena komedija cijela knjiga pdf
Creator: Inkscape
Producer: Inkscape
CreateDate: 2020:02:13 09:55:03
Author: Sotacebu Silefa
Subject: Božanstvena komedija cijela knjiga pdf. https://dereta.rs/a.aspx?autor_uid=2791ab40-d633-4f85-bd81-da90e858f04d Thank you for interestin
PageCount: 4

XMP

XMPToolkit: Inkscape
Format: application/pdf
Creator: Sotacebu Silefa
Description: Božanstvena komedija cijela knjiga pdf. https://dereta.rs/a.aspx?autor_uid=2791ab40-d633-4f85-bd81-da90e858f04d Thank you for interestin
Subject: Božanstvena komedija cijela knjiga pdf. https://dereta.rs/a.aspx?autor_uid=2791ab40-d633-4f85-bd81-da90e858f04d Thank you for interestin
Title: Božanstvena komedija cijela knjiga pdf
Producer: Inkscape
CreateDate: 2020:02:13 09:55:03
CreatorTool: Inkscape
DocumentID: eec9757d-ee0b-451f-91a9-0608dfbe2cca
InstanceID: 36cda9d6-2384-4d85-b73f-c225e147cbc8
Marked:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
100
Monitored processes
53
Malicious processes
1
Suspicious processes
9

Behavior graph

Click at the process to see the details
start acrord32.exe acrord32.exe no specs rdrcef.exe rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs searchprotocolhost.exe no specs adobearm.exe reader_sl.exe no specs pingsender.exe pingsender.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs helper.exe pingsender.exe pingsender.exe pingsender.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs pingsender.exe pingsender.exe pingsender.exe

Process information

PID
CMD
Path
Indicators
Parent process
1324"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\Downloads\cb7c86b23fe81bcf2a8fedf7273fe0d7.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Explorer.EXE
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
20.13.20064.405839
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
1304"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\Downloads\cb7c86b23fe81bcf2a8fedf7273fe0d7.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3720"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --backgroundcolor=16514043C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
AcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
3221225547
Version:
20.13.20064.405839
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3008"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --touch-events=enabled --field-trial-handle=1072,12114310001360454744,16838138385981954358,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-gpu-compositing --lang=en-US --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=2971682892284735912 --renderer-client-id=2 --mojo-platform-channel-handle=1192 --allow-no-sandbox-job /prefetch:1C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
1632"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=gpu-process --field-trial-handle=1072,12114310001360454744,16838138385981954358,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --lang=en-US --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAABAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --service-request-channel-token=1731422808162453349 --mojo-platform-channel-handle=1208 --allow-no-sandbox-job --ignored=" --type=renderer " /prefetch:2C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
1
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
880"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=gpu-process --field-trial-handle=1072,12114310001360454744,16838138385981954358,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --lang=en-US --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAABAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --service-request-channel-token=612659250271828516 --mojo-platform-channel-handle=1220 --allow-no-sandbox-job --ignored=" --type=renderer " /prefetch:2C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
1
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2504"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=gpu-process --field-trial-handle=1072,12114310001360454744,16838138385981954358,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --lang=en-US --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAABAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --service-request-channel-token=9026043130047053408 --mojo-platform-channel-handle=1400 --allow-no-sandbox-job --ignored=" --type=renderer " /prefetch:2C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
1
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
1444"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --touch-events=enabled --field-trial-handle=1072,12114310001360454744,16838138385981954358,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-gpu-compositing --lang=en-US --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4818284746225099426 --renderer-client-id=6 --mojo-platform-channel-handle=1536 --allow-no-sandbox-job /prefetch:1C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
20.13.20064.405839
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
3228"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --touch-events=enabled --field-trial-handle=1072,12114310001360454744,16838138385981954358,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-gpu-compositing --lang=en-US --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11621941460926863078 --renderer-client-id=7 --mojo-platform-channel-handle=1608 --allow-no-sandbox-job /prefetch:1C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
20.13.20064.405839
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3048"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --touch-events=enabled --field-trial-handle=1072,12114310001360454744,16838138385981954358,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-gpu-compositing --lang=en-US --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4055974349953833185 --renderer-client-id=8 --mojo-platform-channel-handle=1644 --allow-no-sandbox-job /prefetch:1C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
20.13.20064.405839
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
77 662
Read events
76 936
Write events
707
Delete events
19

Modification events

(PID) Process:(1304) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection
Operation:writeName:bLastExitNormal
Value:
0
(PID) Process:(1304) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral
Operation:writeName:iNumReaderLaunches
Value:
2
(PID) Process:(1304) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\FTEDialog
Operation:writeName:bShowUpdateFTE
Value:
1
(PID) Process:(1304) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\HomeWelcome
Operation:writeName:bIsAcrobatUpdated
Value:
1
(PID) Process:(1304) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\HomeWelcomeFirstMileReader
Operation:writeName:iCardCountShown
Value:
2
(PID) Process:(1304) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\FTEDialog
Operation:delete valueName:iLastCardShown
Value:
0
(PID) Process:(1324) AcroRd32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1304) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\SessionManagement
Operation:writeName:bNormalExit
Value:
0
(PID) Process:(1304) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\SessionManagement\cWindowsCurrent\cWin0\cTab0\cPathInfo
Operation:writeName:sDI
Value:
2F432F55736572732F61646D696E2F446F776E6C6F6164732F63623763383662323366653831626366326138666564663732373366653064372E70646600
(PID) Process:(1304) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\SessionManagement\cWindowsCurrent\cWin0\cTab0\cPathInfo
Operation:writeName:tDIText
Value:
/C/Users/admin/Downloads/cb7c86b23fe81bcf2a8fedf7273fe0d7.pdf
Executable files
6
Suspicious files
544
Text files
197
Unknown types
158

Dropped files

PID
Process
Filename
Type
3720RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\983b7a3da8f39a46_0binary
MD5:74818D5521DDE9B233215D0B610D56FB
SHA256:E87EB5A915B23D0965ED7A4B07C71C6BB01DB6B44BC59F5ED25A5DA5BD68092D
3720RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0binary
MD5:4C5370B8FF0A6E0FA69FDA2C61EAF2EC
SHA256:03A3670DDB5D4FB1A13A02387485AC5202250FCF7CE2D3898F4ECD53322FD469
3720RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0binary
MD5:8FD2F78D6D01A5199FF3335FF5279778
SHA256:3F1FAAEAE24D560C1A471D18C70E34C292858B2B4F14FABE935A062336C94A34
3720RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\946896ee27df7947_0binary
MD5:8A8963E910EA1F31E203A3B5249DC562
SHA256:6811F281398CDABCBACE37C138F8BCB712C7439E83E01FDEBC3E76605ECA31C5
3720RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fd17b2d8331c91e8_0binary
MD5:F36D03AF10A5154E073741C831154565
SHA256:090E23F18EBC92701FCAB6953A09BC6F2496B32E93F7A872AB92A0C7B42F06BE
3720RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c84d92a9dbce3e0_0binary
MD5:9B0CA12EEBFF7D4C39D99EC8CCCC44CF
SHA256:E8526C49FABAEAE08AE99F2DA494FC7A97F17D43FA6AB2B33B6EE23DD74D8DFE
3720RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\aba6710fde0876af_0binary
MD5:4EAC694AB4C3601979DD1BAFCB398C80
SHA256:AECC4B2421EAE352DF13E9A2937D66083FFA15D68C6DF34A5F4106074366A20E
3720RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c159cc5880890bc_0binary
MD5:F2DECA06F6E8BF9813BF9135839CCE61
SHA256:B05DDC2CBA32BC6032DD892AC7393E2C5D2615245FCBBDC8330343A344A1357D
3720RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\560e9c8bff5008d8_0binary
MD5:7E4FF1427458853D3C5EFA718A8C59D9
SHA256:3AF39D9C285EA60289913BD1473ED4A94A8D514EB01B86B37C9CD35AE6A566FE
3720RdrCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\92c56fa2a6c4d5ba_0binary
MD5:04109918A249D1F8E40207573458B909
SHA256:C4B9494CBA471BFFF262A5D6103C62862AA08077821FE1F693FF58CF7573C843
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
102
DNS requests
137
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1324
AcroRd32.exe
GET
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
whitelisted
3544
firefox.exe
POST
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
3544
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
1404
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
1404
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3544
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
1404
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
1864
pingsender.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAzmtf2PsbB81NVMrv5Nv1c%3D
US
der
471 b
whitelisted
2140
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt
US
text
8 b
whitelisted
3544
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt
US
text
8 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3544
firefox.exe
142.250.185.163:80
ocsp.pki.goog
Google Inc.
US
whitelisted
3544
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3544
firefox.exe
172.217.18.106:443
safebrowsing.googleapis.com
Google Inc.
US
whitelisted
3544
firefox.exe
143.204.215.75:443
firefox.settings.services.mozilla.com
US
suspicious
3720
RdrCEF.exe
23.22.254.206:443
p13n.adobe.io
Amazon.com, Inc.
US
suspicious
3544
firefox.exe
143.204.215.44:443
content-signature-2.cdn.mozilla.net
US
malicious
3720
RdrCEF.exe
104.108.144.144:443
geo2.adobe.com
TOT Public Company Limited
US
unknown
3544
firefox.exe
34.107.221.82:80
detectportal.firefox.com
US
whitelisted
3544
firefox.exe
35.163.112.241:443
location.services.mozilla.com
Amazon.com, Inc.
US
unknown
1324
AcroRd32.exe
23.32.238.123:443
acroipm2.adobe.com
XO Communications
US
suspicious

DNS requests

Domain
IP
Reputation
geo2.adobe.com
  • 104.108.144.144
whitelisted
p13n.adobe.io
  • 23.22.254.206
  • 54.227.187.23
  • 52.202.204.11
  • 52.5.13.197
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
firefox.settings.services.mozilla.com
  • 143.204.215.75
  • 143.204.215.126
  • 143.204.215.37
  • 143.204.215.95
whitelisted
location.services.mozilla.com
  • 35.163.112.241
  • 34.215.15.15
  • 52.89.115.53
  • 52.89.132.147
  • 54.187.205.23
  • 35.82.27.113
whitelisted
locprod2-elb-us-west-2.prod.mozaws.net
  • 35.82.27.113
  • 54.187.205.23
  • 52.89.132.147
  • 52.89.115.53
  • 34.215.15.15
  • 35.163.112.241
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

PID
Process
Class
Message
3544
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
3544
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
1404
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
Potentially Bad Traffic
ET INFO Observed DNS Query to .cloud TLD
Potentially Bad Traffic
ET INFO Observed DNS Query to .cloud TLD
1404
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
2140
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
2140
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
3696
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
3696
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
No debug info