File name:

Certificazione Partecipazione Corso AML IT15318pdf.exe

Full analysis: https://app.any.run/tasks/22a8e3d1-fc8b-43a9-b170-5fc4856a12f6
Verdict: Malicious activity
Analysis date: November 26, 2023, 17:19:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D37B85B09086C80A3EE953249D2F2127

SHA1:

B6436755F2793A563663064D407734038DE90A5E

SHA256:

C451FB32DD30AD7610E5F569D46468C8BC8C2F19520488C49EB4DEC30B6477E1

SSDEEP:

49152:1XsQZyJtDX8i20KTA2pIDbGaVthoXvJ4Yu/qf+dcKqJ2Ovp6GgG/:RsQ4y0KsiIWa92R4Yu/qfalABkE/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2120)
    • Drops the executable file immediately after the start

      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2244)
      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2112)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2112)
      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2196)
    • Executes as Windows Service

      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 1728)
    • Application launched itself

      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 1728)
      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2196)
    • Connects to unusual port

      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2120)
  • INFO

    • Checks supported languages

      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2112)
      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2196)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2244)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 1728)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2120)
      • hcs.exe (PID: 2664)
      • hcs.exe (PID: 1764)
      • hcs.exe (PID: 2452)
      • Reader_sl.exe (PID: 2104)
    • Reads the computer name

      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2196)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2244)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 1728)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2120)
      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2112)
      • hcs.exe (PID: 2664)
      • hcs.exe (PID: 2452)
    • Creates files in the program directory

      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2244)
      • sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe (PID: 2120)
      • Certificazione Partecipazione Corso AML IT15318pdf.exe (PID: 2112)
    • Application launched itself

      • AcroRd32.exe (PID: 2940)
      • RdrCEF.exe (PID: 280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:16 13:31:25+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.33
CodeSize: 208384
InitializedDataSize: 146432
UninitializedDataSize: -
EntryPoint: 0x205e0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
15
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start certificazione partecipazione corso aml it15318pdf.exe no specs certificazione partecipazione corso aml it15318pdf.exe acrord32.exe sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe no specs acrord32.exe no specs sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe no specs sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe hcs.exe no specs hcs.exe no specs hcs.exe no specs rdrcef.exe rdrcef.exe no specs rdrcef.exe no specs adobearm.exe no specs reader_sl.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
AcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
HIGH
Description:
Adobe RdrCEF
Exit code:
0
Version:
15.7.20033.133275
Modules
Images
c:\program files (x86)\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1308"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --channel=2940.0.1740915730 --type=renderer "C:\Program Files (x86)\Sep\Certificazione Partecipazione Corso AML IT15318.pdf"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
0
Version:
15.7.20033.133275
Modules
Images
c:\program files (x86)\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1728"C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe" /serviceC:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeservices.exe
User:
SYSTEM
Company:
host.exe
Integrity Level:
SYSTEM
Description:
host.exe
Exit code:
0
Version:
7.7.0.0
Modules
Images
c:\program files (x86)\sep\sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1764"C:\ProgramData\Anyplace Control Support\hcs.exe" "/wallpaper=on"C:\ProgramData\Anyplace Control Support\hcs.exesanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\anyplace control support\hcs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2104"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Reader_sl.exe" C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Reader_sl.exeAdobeARM.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
HIGH
Description:
Adobe Acrobat SpeedLauncher
Exit code:
0
Version:
15.7.20033.133275
Modules
Images
c:\program files (x86)\adobe\acrobat reader dc\reader\reader_sl.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2112"C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exe" -el -s2 "-dC:\Program Files (x86)\Sep" "-sp"C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exe
Certificazione Partecipazione Corso AML IT15318pdf.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\certificazione partecipazione corso aml it15318pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2120"" "/runsupportversion"C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
User:
SYSTEM
Company:
host.exe
Integrity Level:
SYSTEM
Description:
host.exe
Exit code:
0
Version:
7.7.0.0
Modules
Images
c:\program files (x86)\sep\sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2196"C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exe" C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\certificazione partecipazione corso aml it15318pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2244"C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe" C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeCertificazione Partecipazione Corso AML IT15318pdf.exe
User:
admin
Company:
host.exe
Integrity Level:
HIGH
Description:
host.exe
Exit code:
0
Version:
7.7.0.0
Modules
Images
c:\program files (x86)\sep\sanexpedito87-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgtk5otk5o.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2452"C:\ProgramData\Anyplace Control Support\hcs.exe" "/theme=onC:\ProgramData\Anyplace?Control?Support\apc-settings.ini"C:\ProgramData\Anyplace Control Support\hcs.exesanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\anyplace control support\hcs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
7 281
Read events
7 229
Write events
51
Delete events
1

Modification events

(PID) Process:(2196) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2196) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2196) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2196) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2112) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2112) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2112) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2112) Certificazione Partecipazione Corso AML IT15318pdf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2940) AcroRd32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Acrobatbrokerserverdispatchercpp789
Operation:delete keyName:(default)
Value:
(PID) Process:(1308) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection
Operation:writeName:bLastExitNormal
Value:
1
Executable files
5
Suspicious files
36
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
2112Certificazione Partecipazione Corso AML IT15318pdf.exeC:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeexecutable
MD5:E1D228F6E0F0C3AE48209A4CBC9BD0CD
SHA256:E77EFB3FA3E19FED95448CDE1862F72DD2458A01AAF1CD703930296AEE7E5630
2120sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeC:\ProgramData\Anyplace Control Support\apc-settings.initext
MD5:121AC859755B7C695EB1C01672737112
SHA256:A05B97EDEDFEF9654C33966BD7281D8C9B7563CC71C2C22F97525A309DEE04FB
2244sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeC:\ProgramData\Anyplace Control Support\apcErrorsLog.txttext
MD5:D8D444CEA633E284E2940DB3DB7BB1A9
SHA256:7C5A3E0A1395112BFE0BB06C835F12706B6930A2195EA2B3935A634067A6B664
1308AcroRd32.exeC:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919C.tmp
MD5:
SHA256:
1308AcroRd32.exeC:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919D.tmp
MD5:
SHA256:
1308AcroRd32.exeC:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919E.tmp
MD5:
SHA256:
1308AcroRd32.exeC:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919F.tmp
MD5:
SHA256:
2112Certificazione Partecipazione Corso AML IT15318pdf.exeC:\Program Files (x86)\Sep\Certificazione Partecipazione Corso AML IT15318.pdfpdf
MD5:D033511D0D69D7C6E3A64EB523370F52
SHA256:849476BFAFB0481BD33B970E6A2CC312D0BDCB8F52A7BAFF083691BCFD096162
2244sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeC:\ProgramData\Anyplace Control Support\libspeex.dllexecutable
MD5:E10DB82C997A756A01B6F954E86B83E0
SHA256:65A9BBD5B3B9161C0DD61A9E185E391CFA68F31171E1A5FCFAD20BCC9EB09480
2244sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exeC:\ProgramData\Anyplace Control Support\hcs.exeexecutable
MD5:AC5933067B2C38299AE1443331A61511
SHA256:8C305BB4C07FAC5C88AD1906E6195DD8176F7B6E5014E8FB3E081A45161CF72A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
54
TCP/UDP connections
18
DNS requests
6
Threats
29

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2940
AcroRd32.exe
GET
304
72.247.154.201:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/278.zip
unknown
unknown
2940
AcroRd32.exe
GET
304
72.247.154.201:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/281.zip
unknown
unknown
2940
AcroRd32.exe
GET
304
72.247.154.201:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/277.zip
unknown
unknown
2940
AcroRd32.exe
GET
304
72.247.154.201:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/280.zip
unknown
unknown
884
svchost.exe
HEAD
200
88.221.110.112:80
http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp
unknown
unknown
2940
AcroRd32.exe
GET
200
72.247.154.201:80
http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/message.zip
unknown
compressed
9.54 Kb
unknown
884
svchost.exe
GET
206
88.221.110.112:80
http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp
unknown
5.78 Kb
unknown
884
svchost.exe
GET
206
88.221.110.112:80
http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp
unknown
binary
10.6 Kb
unknown
884
svchost.exe
GET
206
88.221.110.112:80
http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp
unknown
binary
22.7 Kb
unknown
884
svchost.exe
GET
206
88.221.110.112:80
http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp
unknown
binary
10.5 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
216.158.90.159:443
anyplace-gateway.work
WEBNX
US
unknown
280
RdrCEF.exe
44.198.154.229:443
cloud.acrobat.com
AMAZON-AES
US
unknown
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
216.158.90.159:80
anyplace-gateway.work
WEBNX
US
unknown
2940
AcroRd32.exe
72.247.154.201:80
acroipm2.adobe.com
Akamai International B.V.
DE
unknown
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
216.158.90.159:5279
anyplace-gateway.work
WEBNX
US
unknown

DNS requests

Domain
IP
Reputation
anyplace-gateway.work
  • 216.158.90.159
unknown
cloud.acrobat.com
  • 44.198.154.229
  • 34.199.101.34
whitelisted
acroipm2.adobe.com
  • 72.247.154.201
  • 72.247.154.195
  • 72.247.154.202
  • 72.247.154.136
  • 72.247.154.160
  • 72.247.154.163
whitelisted
armmf.adobe.com
  • 23.35.228.137
whitelisted
ardownload.adobe.com
  • 88.221.110.112
  • 88.221.110.104
whitelisted

Threats

PID
Process
Class
Message
324
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .work TLD
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Checkin (051)
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Generic Protocol Command Decode
SURICATA HTTP Response invalid status
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Checkin (051)
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
280
RdrCEF.exe
Unknown Traffic
ET JA3 Hash - Possible Malware - RigEK
280
RdrCEF.exe
Unknown Traffic
ET JA3 Hash - Possible Malware - RigEK
2120
sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
No debug info