File name:

PHISING - DO NOT OPEN - Abdobe E-Doc.pdf

Full analysis: https://app.any.run/tasks/d5fcce1a-fadc-47a0-bac2-197778bc8d70
Verdict: Malicious activity
Threats:

Tycoon 2FA is a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) protections, particularly targeting Microsoft 365 and Gmail accounts. Its advanced evasion techniques and modular architecture make it a significant threat to organizations relying on MFA for security.

Analysis date: April 17, 2025, 08:53:09
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
phishing
storm1747
tycoon
phishing
pdf-secudoc
qrcode
Indicators:
MIME: application/pdf
File info: PDF document, version 2.0
MD5:

286AF8E6256C97C4AD08FB41EC59F6C1

SHA1:

C6659FA7BCC6B37F5D55FFCC332E635D409278B0

SHA256:

C3DF958FADE0D1855D40EC9E9014242EF3A40090CCCF46C849F3E51F92595E80

SSDEEP:

98304:PmKx9DRrJmsTLq1JuX6koov4TGvmC3NnYUA6H4s45+Yu9OBkca9t+mdHUIYe59qj:BJjr2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • PHISHING has been detected (SURICATA)

      • msedge.exe (PID: 6108)
      • svchost.exe (PID: 2196)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • AcroCEF.exe (PID: 1228)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 7848)
      • Acrobat.exe (PID: 7348)
      • AcroCEF.exe (PID: 8004)
    • Reads the computer name

      • identity_helper.exe (PID: 8436)
      • identity_helper.exe (PID: 6248)
      • identity_helper.exe (PID: 8836)
    • Checks supported languages

      • identity_helper.exe (PID: 8436)
      • identity_helper.exe (PID: 8836)
      • identity_helper.exe (PID: 6248)
    • Reads Environment values

      • identity_helper.exe (PID: 8436)
      • identity_helper.exe (PID: 6248)
      • identity_helper.exe (PID: 8836)
    • Connects to unusual port

      • msedge.exe (PID: 6108)
    • Reads the software policy settings

      • slui.exe (PID: 7664)
      • slui.exe (PID: 8732)
    • The sample compiled with english language support

      • msedge.exe (PID: 920)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 920)
    • Checks proxy server information

      • slui.exe (PID: 8732)
    • Manual execution by a user

      • msedge.exe (PID: 8888)
      • msedge.exe (PID: 1328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.pdf | Adobe Portable Document Format (100)

EXIF

PDF

PDFVersion: 2
Linearized: No
PageCount: 1
HasXFA: No
CreateDate: 2024:10:29 04:20:04-07:00
Creator: Adobe Photoshop CC 2019 (Windows)
ModifyDate: 2025:04:16 13:16:19+02:00
Producer: 3.0.24 (5.1.10)

XMP

XMPToolkit: Adobe XMP Core 5.6-c145 79.163499, 2018/08/13-16:40:22
CreatorTool: Adobe Photoshop CC 2019 (Windows)
CreateDate: 2024:10:29 04:20:04-07:00
MetadataDate: 2025:03:28 02:51:29-07:00
ModifyDate: 2025:03:28 02:51:29-07:00
ColorMode: RGB
ICCProfileName: sRGB IEC61966-2.1
TextLayerName:
  • C
  • 2017 Microsoft Privacy & Cookies
TextLayerText:
  • C
  • 2017 Microsoft Privacy & Cookies
DocumentAncestors:
  • 171D52F8643BFADCA813C3CC09B9336C
  • 18CB94BDDFCA3D645577B60CFCF6B5D0
  • 72DEB3F6ACD1FF4E1AA71EBF4E51BBA9
  • C35484A2749B8C538A518734DBB0615E
  • adobe:docid:photoshop:e59a5597-4621-1f45-961c-f8c12655b5d6
Format: application/pdf
InstanceID: uuid:484f9e23-611c-4e6e-b28f-4d59de261afc
DocumentID: adobe:docid:photoshop:fbf7d823-4b59-f843-8d78-fc16e447a3e2
OriginalDocumentID: xmp.did:7e20b0a9-f2e5-2a46-9db4-1c922509a533
HistoryAction:
  • created
  • saved
  • saved
HistoryInstanceID:
  • xmp.iid:7e20b0a9-f2e5-2a46-9db4-1c922509a533
  • xmp.iid:1b9af19b-46cb-0945-81e4-5a5d5243b78a
  • xmp.iid:aaa4724a-f40d-5e4e-8c89-40606f0aa124
HistoryWhen:
  • 2024:10:29 04:20:04-07:00
  • 2024:11:10 20:55:24-08:00
  • 2025:03:28 02:51:26-07:00
HistorySoftwareAgent:
  • Adobe Photoshop CC 2019 (Windows)
  • Adobe Photoshop CC 2019 (Windows)
  • Adobe Photoshop CC 2019 (Windows)
HistoryChanged:
  • /
  • /
Producer: Adobe Photoshop for Windows -- Image Conversion Plug-in

IPTC

ApplicationRecordVersion: -

Photoshop

IPTCDigest: e8f15cf32fc118a1a27b67adc564d5ba
XResolution: 300
DisplayedUnitsX: inches
YResolution: 300
DisplayedUnitsY: inches
PrintStyle: Centered
PrintPosition: 0 0
PrintScale: 1
GlobalAngle: 90
GlobalAltitude: 30
URL_List:
    SlicesGroupName: -
    NumSlices: 1
    PixelAspectRatio: 1
    HasRealMergedData: Yes
    WriterName: Adobe Photoshop
    ReaderName: Adobe Photoshop CC 2019

    EXIF

    Orientation: Horizontal (normal)
    XResolution: 300
    YResolution: 300
    ResolutionUnit: inches
    Software: Adobe Photoshop CC 2019 (Windows)
    ModifyDate: 2025:03:28 02:51:26
    ColorSpace: sRGB
    ExifImageWidth: 2480
    ExifImageHeight: 3208
    Compression: JPEG (old-style)
    ThumbnailOffset: 306
    ThumbnailLength: -

    ICC_Profile

    ProfileCMMType: Linotronic
    ProfileVersion: 2.1.0
    ProfileClass: Display Device Profile
    ColorSpaceData: RGB
    ProfileConnectionSpace: XYZ
    ProfileDateTime: 1998:02:09 06:49:00
    ProfileFileSignature: acsp
    PrimaryPlatform: Microsoft Corporation
    CMMFlags: Not Embedded, Independent
    DeviceManufacturer: Hewlett-Packard
    DeviceModel: sRGB
    DeviceAttributes: Reflective, Glossy, Positive, Color
    RenderingIntent: Media-Relative Colorimetric
    ConnectionSpaceIlluminant: 0.9642 1 0.82491
    ProfileCreator: Hewlett-Packard
    ProfileID: -
    ProfileCopyright: Copyright (c) 1998 Hewlett-Packard Company
    ProfileDescription: sRGB IEC61966-2.1
    MediaWhitePoint: 0.95045 1 1.08905
    MediaBlackPoint: 0 0 0
    RedMatrixColumn: 0.43607 0.22249 0.01392
    GreenMatrixColumn: 0.38515 0.71687 0.09708
    BlueMatrixColumn: 0.14307 0.06061 0.7141
    DeviceMfgDesc: IEC http://www.iec.ch
    DeviceModelDesc: IEC 61966-2.1 Default RGB colour space - sRGB
    ViewingCondDesc: Reference Viewing Condition in IEC61966-2.1
    ViewingCondIlluminant: 19.6445 20.3718 16.8089
    ViewingCondSurround: 3.92889 4.07439 3.36179
    ViewingCondIlluminantType: D50
    Luminance: 76.03647 80 87.12462
    MeasurementObserver: CIE 1931
    MeasurementBacking: 0 0 0
    MeasurementGeometry: Unknown
    MeasurementFlare: 0.999%
    MeasurementIlluminant: D65
    Technology: Cathode Ray Tube Display
    RedTRC: (Binary data 2060 bytes, use -b option to extract)
    GreenTRC: (Binary data 2060 bytes, use -b option to extract)
    BlueTRC: (Binary data 2060 bytes, use -b option to extract)
    No data.
    screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
    All screenshots are available in the full report
    All screenshots are available in the full report
    Total processes
    227
    Monitored processes
    88
    Malicious processes
    4
    Suspicious processes
    0

    Behavior graph

    Click at the process to see the details
    start acrobat.exe acrobat.exe no specs sppextcomobj.exe no specs slui.exe acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs #PHISHING msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs acrocef.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs #PHISHING svchost.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

    Process information

    PID
    CMD
    Path
    Indicators
    Parent process
    920"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4540 --field-trial-handle=2416,i,370691542950520719,5426081355244068384,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
    msedge.exe
    User:
    admin
    Company:
    Microsoft Corporation
    Integrity Level:
    LOW
    Description:
    Microsoft Edge
    Exit code:
    0
    Version:
    122.0.2365.59
    Modules
    Images
    c:\program files (x86)\microsoft\edge\application\msedge.exe
    c:\windows\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
    c:\windows\system32\oleaut32.dll
    c:\windows\system32\msvcp_win.dll
    c:\windows\system32\ucrtbase.dll
    c:\windows\system32\combase.dll
    c:\windows\system32\rpcrt4.dll
    924"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=8100 --field-trial-handle=2416,i,370691542950520719,5426081355244068384,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
    User:
    admin
    Company:
    Microsoft Corporation
    Integrity Level:
    LOW
    Description:
    Microsoft Edge
    Exit code:
    0
    Version:
    122.0.2365.59
    Modules
    Images
    c:\program files (x86)\microsoft\edge\application\msedge.exe
    c:\windows\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
    c:\windows\system32\oleaut32.dll
    c:\windows\system32\msvcp_win.dll
    c:\windows\system32\ucrtbase.dll
    c:\windows\system32\combase.dll
    c:\windows\system32\rpcrt4.dll
    1012"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7736 --field-trial-handle=2416,i,370691542950520719,5426081355244068384,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
    User:
    admin
    Company:
    Microsoft Corporation
    Integrity Level:
    LOW
    Description:
    Microsoft Edge
    Exit code:
    0
    Version:
    122.0.2365.59
    Modules
    Images
    c:\program files (x86)\microsoft\edge\application\msedge.exe
    c:\windows\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
    c:\windows\system32\oleaut32.dll
    c:\windows\system32\msvcp_win.dll
    c:\windows\system32\ucrtbase.dll
    c:\windows\system32\combase.dll
    c:\windows\system32\rpcrt4.dll
    1228"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=disabled --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2752 --field-trial-handle=1328,i,13590391258791176079,15293111461648195507,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
    User:
    admin
    Company:
    Adobe Systems Incorporated
    Integrity Level:
    LOW
    Description:
    Adobe AcroCEF
    Version:
    23.1.20093.0
    Modules
    Images
    c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
    c:\windows\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\windows\system32\user32.dll
    c:\windows\system32\win32u.dll
    c:\windows\system32\gdi32.dll
    c:\windows\system32\gdi32full.dll
    c:\windows\system32\msvcp_win.dll
    c:\windows\system32\ucrtbase.dll
    1272"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2412 --field-trial-handle=2416,i,370691542950520719,5426081355244068384,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
    User:
    admin
    Company:
    Microsoft Corporation
    Integrity Level:
    LOW
    Description:
    Microsoft Edge
    Version:
    122.0.2365.59
    Modules
    Images
    c:\program files (x86)\microsoft\edge\application\msedge.exe
    c:\windows\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
    c:\windows\system32\oleaut32.dll
    c:\windows\system32\msvcp_win.dll
    c:\windows\system32\ucrtbase.dll
    c:\windows\system32\combase.dll
    c:\windows\system32\rpcrt4.dll
    1300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6448 --field-trial-handle=2416,i,370691542950520719,5426081355244068384,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
    User:
    admin
    Company:
    Microsoft Corporation
    Integrity Level:
    LOW
    Description:
    Microsoft Edge
    Exit code:
    0
    Version:
    122.0.2365.59
    Modules
    Images
    c:\program files (x86)\microsoft\edge\application\msedge.exe
    c:\windows\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
    c:\windows\system32\oleaut32.dll
    c:\windows\system32\msvcp_win.dll
    c:\windows\system32\ucrtbase.dll
    c:\windows\system32\combase.dll
    c:\windows\system32\rpcrt4.dll
    1328"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=DefaultC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeexplorer.exe
    User:
    admin
    Company:
    Microsoft Corporation
    Integrity Level:
    MEDIUM
    Description:
    Microsoft Edge
    Exit code:
    0
    Version:
    122.0.2365.59
    Modules
    Images
    c:\program files (x86)\microsoft\edge\application\msedge.exe
    c:\windows\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
    c:\windows\system32\oleaut32.dll
    c:\windows\system32\msvcp_win.dll
    c:\windows\system32\ucrtbase.dll
    c:\windows\system32\combase.dll
    c:\windows\system32\rpcrt4.dll
    1568"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-databases --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=45 --mojo-platform-channel-handle=3724 --field-trial-handle=2416,i,370691542950520719,5426081355244068384,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
    User:
    admin
    Company:
    Microsoft Corporation
    Integrity Level:
    LOW
    Description:
    Microsoft Edge
    Exit code:
    0
    Version:
    122.0.2365.59
    Modules
    Images
    c:\program files (x86)\microsoft\edge\application\msedge.exe
    c:\windows\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
    c:\windows\system32\oleaut32.dll
    c:\windows\system32\msvcp_win.dll
    c:\windows\system32\ucrtbase.dll
    c:\windows\system32\combase.dll
    c:\windows\system32\rpcrt4.dll
    1660"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3692 --field-trial-handle=2416,i,370691542950520719,5426081355244068384,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
    User:
    admin
    Company:
    Microsoft Corporation
    Integrity Level:
    LOW
    Description:
    Microsoft Edge
    Version:
    122.0.2365.59
    Modules
    Images
    c:\program files (x86)\microsoft\edge\application\msedge.exe
    c:\windows\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
    c:\windows\system32\oleaut32.dll
    c:\windows\system32\msvcp_win.dll
    c:\windows\system32\ucrtbase.dll
    c:\windows\system32\combase.dll
    c:\windows\system32\rpcrt4.dll
    1672"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=50 --mojo-platform-channel-handle=7448 --field-trial-handle=2416,i,370691542950520719,5426081355244068384,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
    User:
    admin
    Company:
    Microsoft Corporation
    Integrity Level:
    LOW
    Description:
    Microsoft Edge
    Exit code:
    0
    Version:
    122.0.2365.59
    Modules
    Images
    c:\program files (x86)\microsoft\edge\application\msedge.exe
    c:\windows\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
    c:\windows\system32\oleaut32.dll
    c:\windows\system32\msvcp_win.dll
    c:\windows\system32\ucrtbase.dll
    c:\windows\system32\combase.dll
    c:\windows\system32\rpcrt4.dll
    Total events
    23 414
    Read events
    23 201
    Write events
    190
    Delete events
    23

    Modification events

    (PID) Process:(7348) Acrobat.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-2034283098-2252572593-1072577386-2659511007-3245387615-27016815-3920691934
    Operation:writeName:DisplayName
    Value:
    Adobe Acrobat Reader Protected Mode
    (PID) Process:(7480) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ExitSection
    Operation:writeName:bLastExitNormal
    Value:
    0
    (PID) Process:(7480) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
    Operation:writeName:bSynchronizeOPL
    Value:
    0
    (PID) Process:(7480) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral
    Operation:writeName:uLastAppLaunchTimeStamp
    Value:
    (PID) Process:(7480) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral
    Operation:writeName:iNumAcrobatLaunches
    Value:
    7
    (PID) Process:(7480) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\NoTimeOut
    Operation:writeName:smailto
    Value:
    5900
    (PID) Process:(7480) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ToolsSearch
    Operation:writeName:iSearchHintIndex
    Value:
    3
    (PID) Process:(7480) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
    Operation:writeName:sProductGUID
    Value:
    4143524F4241545F475549445F4E474C5F44554D4D5900
    (PID) Process:(7348) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer
    Operation:delete valueName:ProductInfoCache
    Value:
    (PID) Process:(7480) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DiskCabs
    Operation:writeName:bForms_AdhocWorkflowBackup
    Value:
    0
    Executable files
    35
    Suspicious files
    1 227
    Text files
    188
    Unknown types
    0

    Dropped files

    PID
    Process
    Filename
    Type
    8004AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old~RF10d6da.TMPtext
    MD5:7383516745DEC1E86152192435F92D1F
    SHA256:E22D34BBD915EEB277D4F4138D176EACE5577CF035EF7C2C80A4BC4D9B6C0E1D
    8004AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0binary
    MD5:EF1E98417402F6D659ABF89F0216968C
    SHA256:8DBC34169A4E076C52A2C2DC4585EE03A3356E5A35F900B2F267589F6DFCC3BA
    8004AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.oldtext
    MD5:EB1590F2607E1CE46DBF6A521F772EA0
    SHA256:4355D9A8A115BA4E41178B456A8A5578846EB1F7EC9509249C2405F758F31731
    8004AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old~RF10d6e9.TMPtext
    MD5:ED7D8AAE48211E2BFAF557130572C62A
    SHA256:A5CF8D8ADC86DCA357396AF7E3A24A116072D5C1E5552EEB76601AE2673DED6E
    8004AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.oldtext
    MD5:2EF1F7C0782D1A46974286420D24F629
    SHA256:D3A9BB7E09E1F4B0C41FF7808E930DDACF5DB3BACD98ECCF5BC7DB4863D1FCF5
    7480Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTINGbinary
    MD5:DC84B0D741E5BEAE8070013ADDCC8C28
    SHA256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
    8004AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old~RF10d4e6.TMPtext
    MD5:D012E5B4EB91B61F6E8AE2F8EC3C623E
    SHA256:1BDA750084F20306722008016420E1912BA608CA8EFB9C661F7E7EFCF5E89673
    7480Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.jsonbinary
    MD5:837C1211E392A24D64C670DC10E8DA1B
    SHA256:8013AC030684B86D754BBFBAB8A9CEC20CAA4DD9C03022715FF353DC10E14031
    8004AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.oldtext
    MD5:8412AEEF2309E13FC954061D9BCEFFF4
    SHA256:D062D7B5DF5F3BCB753E97AB5D1DCD9CF62058D9103DA383DBE1F482FC1D4644
    8004AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0binary
    MD5:1906EB84FA38C711624C2385D4753849
    SHA256:35BF013922986E73B927AF3CA843C60B0B7B583A40A1FEAAD40270716C5363F1
    Download PCAP, analyze network streams, HTTP content and a lot more at the full report
    HTTP(S) requests
    43
    TCP/UDP connections
    221
    DNS requests
    299
    Threats
    31

    HTTP requests

    PID
    Process
    Method
    HTTP Code
    IP
    URL
    CN
    Type
    Size
    Reputation
    6544
    svchost.exe
    GET
    200
    2.17.190.73:80
    http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
    unknown
    whitelisted
    5496
    MoUsoCoreWorker.exe
    GET
    200
    23.53.40.176:80
    http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
    unknown
    whitelisted
    2104
    svchost.exe
    GET
    200
    23.53.40.176:80
    http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
    unknown
    whitelisted
    7348
    Acrobat.exe
    GET
    200
    2.17.190.73:80
    http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfy81yHqHeveu%2FpR5k1Jb0%3D
    unknown
    whitelisted
    8576
    SIHClient.exe
    GET
    200
    95.101.149.131:80
    http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
    unknown
    whitelisted
    8576
    SIHClient.exe
    GET
    200
    95.101.149.131:80
    http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
    unknown
    whitelisted
    3768
    svchost.exe
    HEAD
    200
    199.232.214.172:80
    http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1745357331&P2=404&P3=2&P4=DXc3vOSsloGd%2bxYQQm%2bqnFAXUpmnZ9iCX4pqgZ5aw3AFx%2bTj%2fO%2fQ8WgVdvad%2f%2b9yn3xaGl%2bNSK6AdIS9B%2b5J6g%3d%3d
    unknown
    whitelisted
    3768
    svchost.exe
    GET
    206
    199.232.214.172:80
    http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1745357331&P2=404&P3=2&P4=DXc3vOSsloGd%2bxYQQm%2bqnFAXUpmnZ9iCX4pqgZ5aw3AFx%2bTj%2fO%2fQ8WgVdvad%2f%2b9yn3xaGl%2bNSK6AdIS9B%2b5J6g%3d%3d
    unknown
    whitelisted
    3768
    svchost.exe
    GET
    206
    199.232.214.172:80
    http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1745357331&P2=404&P3=2&P4=DXc3vOSsloGd%2bxYQQm%2bqnFAXUpmnZ9iCX4pqgZ5aw3AFx%2bTj%2fO%2fQ8WgVdvad%2f%2b9yn3xaGl%2bNSK6AdIS9B%2b5J6g%3d%3d
    unknown
    whitelisted
    3768
    svchost.exe
    GET
    206
    199.232.214.172:80
    http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1745357331&P2=404&P3=2&P4=DXc3vOSsloGd%2bxYQQm%2bqnFAXUpmnZ9iCX4pqgZ5aw3AFx%2bTj%2fO%2fQ8WgVdvad%2f%2b9yn3xaGl%2bNSK6AdIS9B%2b5J6g%3d%3d
    unknown
    whitelisted
    Download PCAP, analyze network streams, HTTP content and a lot more at the full report

    Connections

    PID
    Process
    IP
    Domain
    ASN
    CN
    Reputation
    5588
    RUXIMICS.exe
    20.73.194.208:443
    settings-win.data.microsoft.com
    MICROSOFT-CORP-MSN-AS-BLOCK
    NL
    whitelisted
    4
    System
    192.168.100.255:137
    whitelisted
    4
    System
    192.168.100.255:138
    whitelisted
    20.73.194.208:443
    settings-win.data.microsoft.com
    MICROSOFT-CORP-MSN-AS-BLOCK
    NL
    whitelisted
    5496
    MoUsoCoreWorker.exe
    23.53.40.176:80
    crl.microsoft.com
    Akamai International B.V.
    DE
    whitelisted
    2104
    svchost.exe
    23.53.40.176:80
    crl.microsoft.com
    Akamai International B.V.
    DE
    whitelisted
    6544
    svchost.exe
    20.190.159.129:443
    login.live.com
    MICROSOFT-CORP-MSN-AS-BLOCK
    IE
    whitelisted
    6544
    svchost.exe
    2.17.190.73:80
    ocsp.digicert.com
    AKAMAI-AS
    DE
    whitelisted
    2104
    svchost.exe
    20.73.194.208:443
    settings-win.data.microsoft.com
    MICROSOFT-CORP-MSN-AS-BLOCK
    NL
    whitelisted
    8156
    AcroCEF.exe
    23.213.164.167:443
    geo2.adobe.com
    AKAMAI-AS
    DE
    whitelisted

    DNS requests

    Domain
    IP
    Reputation
    settings-win.data.microsoft.com
    • 20.73.194.208
    whitelisted
    google.com
    • 142.250.185.206
    whitelisted
    crl.microsoft.com
    • 23.53.40.176
    • 23.53.40.178
    whitelisted
    login.live.com
    • 20.190.159.129
    • 40.126.31.129
    • 40.126.31.1
    • 40.126.31.69
    • 20.190.159.68
    • 20.190.159.128
    • 20.190.159.75
    • 20.190.159.0
    whitelisted
    ocsp.digicert.com
    • 2.17.190.73
    whitelisted
    geo2.adobe.com
    • 23.213.164.167
    • 95.100.184.205
    whitelisted
    adobe.com
    • 23.48.23.59
    • 23.48.23.63
    whitelisted
    p13n.adobe.io
    • 3.219.243.226
    • 52.6.155.20
    • 52.22.41.97
    • 3.233.129.217
    whitelisted
    config.edge.skype.com
    • 13.107.42.16
    whitelisted
    acrobat.adobe.com
    • 2.23.7.25
    • 2.23.7.34
    whitelisted

    Threats

    PID
    Process
    Class
    Message
    6108
    msedge.exe
    Misc activity
    ET FILE_SHARING Document Sharing Site Domain Observed in DNS Query (docsend .com)
    6108
    msedge.exe
    Misc activity
    ET FILE_SHARING Document Sharing Site Domain Observed in DNS Query (docsend .com)
    6108
    msedge.exe
    Misc activity
    ET INFO Document Sharing Site Domain Observed in TLS SNI (docsend .com)
    6108
    msedge.exe
    Not Suspicious Traffic
    INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
    6108
    msedge.exe
    Not Suspicious Traffic
    INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
    6108
    msedge.exe
    Not Suspicious Traffic
    INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
    6108
    msedge.exe
    Not Suspicious Traffic
    INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
    6108
    msedge.exe
    Not Suspicious Traffic
    INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
    6108
    msedge.exe
    Not Suspicious Traffic
    INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
    6108
    msedge.exe
    Possible Social Engineering Attempted
    PHISHING [ANY.RUN] Suspected Phishing Domain (uishkfyv .ru)
    No debug info