File name:

Certificazione Partecipazione Corso AML IT15318pdf.exe

Full analysis: https://app.any.run/tasks/22a8e3d1-fc8b-43a9-b170-5fc4856a12f6
Verdict: Malicious activity
Analysis date: November 26, 2023, 17:19:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D37B85B09086C80A3EE953249D2F2127

SHA1:

B6436755F2793A563663064D407734038DE90A5E

SHA256:

C451FB32DD30AD7610E5F569D46468C8BC8C2F19520488C49EB4DEC30B6477E1

SSDEEP:

49152:1XsQZyJtDX8i20KTA2pIDbGaVthoXvJ4Yu/qf+dcKqJ2Ovp6GgG/:RsQ4y0KsiIWa92R4Yu/qfalABkE/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2112)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2244)
    • Connects to the CnC server

      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2120)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2196)
      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2112)
    • Application launched itself

      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2196)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 1728)
    • Executes as Windows Service

      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 1728)
    • Connects to unusual port

      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2120)
  • INFO

    • Checks supported languages

      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2112)
      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2196)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2244)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 1728)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2120)
      • hcs.exe (PID: 2664)
      • hcs.exe (PID: 2452)
      • hcs.exe (PID: 1764)
      • Reader_sl.exe (PID: 2104)
    • Reads the computer name

      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2196)
      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2112)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2244)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 1728)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2120)
      • hcs.exe (PID: 2664)
      • hcs.exe (PID: 2452)
    • Creates files in the program directory

      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2112)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2244)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2120)
    • Application launched itself

      • AcroRd32.exe (PID: 2940)
      • RdrCEF.exe (PID: 280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:16 13:31:25+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.33
CodeSize: 208384
InitializedDataSize: 146432
UninitializedDataSize: -
EntryPoint: 0x205e0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
15
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start certificazione partecipazione corso aml it15318pdf.exe no specs certificazione partecipazione corso aml it15318pdf.exe acrord32.exe sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe no specs acrord32.exe no specs sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe no specs sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe hcs.exe no specs hcs.exe no specs hcs.exe no specs rdrcef.exe rdrcef.exe no specs rdrcef.exe no specs adobearm.exe no specs reader_sl.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
AcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
HIGH
Description:
Adobe RdrCEF
Exit code:
0
Version:
15.7.20033.133275
Modules
Images
c:\program files (x86)\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1308"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --channel=2940.0.1740915730 --type=renderer "C:\Program Files (x86)\Sep\Certificazione Partecipazione Corso AML IT15318.pdf"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
0
Version:
15.7.20033.133275
Modules
Images
c:\program files (x86)\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1728"C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe" /serviceC:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeservices.exe
User:
SYSTEM
Company:
host.exe
Integrity Level:
SYSTEM
Description:
host.exe
Exit code:
0
Version:
7.7.0.0
Modules
Images
c:\program files (x86)\sep\sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1764"C:\ProgramData\Anyplace Control Support\hcs.exe" "/wallpaper=on"C:\ProgramData\Anyplace Control Support\hcs.exesanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\anyplace control support\hcs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2104"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Reader_sl.exe" C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Reader_sl.exeAdobeARM.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
HIGH
Description:
Adobe Acrobat SpeedLauncher
Exit code:
0
Version:
15.7.20033.133275
Modules
Images
c:\program files (x86)\adobe\acrobat reader dc\reader\reader_sl.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2112"C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exe" -el -s2 "-dC:\Program Files (x86)\Sep" "-sp"C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exe
Certificazione Partecipazione Corso AML IT15318pdf.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\certificazione partecipazione corso aml it15318pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2120"" "/runsupportversion"C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
User:
SYSTEM
Company:
host.exe
Integrity Level:
SYSTEM
Description:
host.exe
Exit code:
0
Version:
7.7.0.0
Modules
Images
c:\program files (x86)\sep\sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2196"C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exe" C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\certificazione partecipazione corso aml it15318pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2244"C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe" C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeCertificazione Partecipazione Corso AML IT15318pdf.exe
User:
admin
Company:
host.exe
Integrity Level:
HIGH
Description:
host.exe
Exit code:
0
Version:
7.7.0.0
Modules
Images
c:\program files (x86)\sep\sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2452"C:\ProgramData\Anyplace Control Support\hcs.exe" "/theme=onC:\ProgramData\Anyplace?Control?Support\apc-settings.ini"C:\ProgramData\Anyplace Control Support\hcs.exesanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\anyplace control support\hcs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
7 281
Read events
7 229
Write events
51
Delete events
1

Modification events

(PID) Process:(2196) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2196) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2196) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2196) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2112) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2112) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2112) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2112) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2940) AcroRd32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Acrobatbrokerserverdispatchercpp789
Operation:delete keyName:(default)
Value:
(PID) Process:(1308) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection
Operation:writeName:bLastExitNormal
Value:
1
Executable files
5
Suspicious files
36
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
1308AcroRd32.exeC:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfgtext
MD5:2BD4B1E5E05FF88A44DECFE3EC917933
SHA256:864DDDCAC6BFCE12DF19EF8C75E7856AF5B90F898F04F06BEADC63C5A9960BA4
2244sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeC:\ProgramData\Anyplace Control Support\sessionID.txttext
MD5:A5EA0AD9260B1550A14CC58D2C39B03D
SHA256:F1B2F662800122BED0FF255693DF89C4487FBDCF453D3524A42D4EC20C3D9C04
2244sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeC:\ProgramData\Anyplace Control Support\hcs.exeexecutable
MD5:AC5933067B2C38299AE1443331A61511
SHA256:8C305BB4C07FAC5C88AD1906E6195DD8176F7B6E5014E8FB3E081A45161CF72A
1308AcroRd32.exeC:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919C.tmp
MD5:
SHA256:
1308AcroRd32.exeC:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919D.tmp
MD5:
SHA256:
1308AcroRd32.exeC:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919E.tmp
MD5:
SHA256:
1308AcroRd32.exeC:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919F.tmp
MD5:
SHA256:
2244sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeC:\ProgramData\Anyplace Control Support\libspeex.dllexecutable
MD5:E10DB82C997A756A01B6F954E86B83E0
SHA256:65A9BBD5B3B9161C0DD61A9E185E391CFA68F31171E1A5FCFAD20BCC9EB09480
2120sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeC:\ProgramData\Anyplace Control Support\apc-host.logtext
MD5:81051BCC2CF1BEDF378224B0A93E2877
SHA256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6
1308AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessagesbinary
MD5:65F4CAE473EAC06DB9942E32DBB303A6
SHA256:FE63ACC1C0DB8391B5F544CFE4C45F4F6AB1E2EBE51EEF35D7C71074FC86CFBF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
54
TCP/UDP connections
18
DNS requests
6
Threats
29

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2940
AcroRd32.exe
GET
304
72.247.154.201:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/280.zip
unknown
unknown
2940
AcroRd32.exe
GET
304
72.247.154.201:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/277.zip
unknown
unknown
2940
AcroRd32.exe
GET
304
72.247.154.201:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/278.zip
unknown
unknown
2940
AcroRd32.exe
GET
304
72.247.154.201:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/281.zip
unknown
unknown
2940
AcroRd32.exe
GET
200
72.247.154.201:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/message.zip
unknown
compressed
9.54 Kb
unknown
884
svchost.exe
HEAD
200
88.221.110.112:80
http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp
unknown
unknown
884
svchost.exe
GET
206
88.221.110.112:80
http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp
unknown
5.78 Kb
unknown
884
svchost.exe
GET
206
88.221.110.112:80
http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp
unknown
binary
7.83 Kb
unknown
884
svchost.exe
GET
206
88.221.110.112:80
http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp
unknown
binary
10.6 Kb
unknown
884
svchost.exe
GET
206
88.221.110.112:80
http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp
unknown
binary
10.5 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
216.158.90.159:443
anyplace-gateway.work
WEBNX
US
unknown
280
RdrCEF.exe
44.198.154.229:443
cloud.acrobat.com
AMAZON-AES
US
unknown
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
216.158.90.159:80
anyplace-gateway.work
WEBNX
US
unknown
2940
AcroRd32.exe
72.247.154.201:80
acroipm2.adobe.com
Akamai International B.V.
DE
unknown
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
216.158.90.159:5279
anyplace-gateway.work
WEBNX
US
unknown

DNS requests

Domain
IP
Reputation
anyplace-gateway.work
  • 216.158.90.159
unknown
cloud.acrobat.com
  • 44.198.154.229
  • 34.199.101.34
whitelisted
acroipm2.adobe.com
  • 72.247.154.201
  • 72.247.154.195
  • 72.247.154.202
  • 72.247.154.136
  • 72.247.154.160
  • 72.247.154.163
whitelisted
armmf.adobe.com
  • 23.35.228.137
whitelisted
ardownload.adobe.com
  • 88.221.110.112
  • 88.221.110.104
whitelisted

Threats

PID
Process
Class
Message
324
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .work TLD
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Checkin (051)
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Generic Protocol Command Decode
SURICATA HTTP Response invalid status
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Checkin (051)
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
280
RdrCEF.exe
Unknown Traffic
ET JA3 Hash - Possible Malware - RigEK
280
RdrCEF.exe
Unknown Traffic
ET JA3 Hash - Possible Malware - RigEK
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
No debug info