| File name: | Certificazione Partecipazione Corso AML IT15318pdf.exe |
| Full analysis: | https://app.any.run/tasks/22a8e3d1-fc8b-43a9-b170-5fc4856a12f6 |
| Verdict: | Malicious activity |
| Analysis date: | November 26, 2023, 17:19:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D37B85B09086C80A3EE953249D2F2127 |
| SHA1: | B6436755F2793A563663064D407734038DE90A5E |
| SHA256: | C451FB32DD30AD7610E5F569D46468C8BC8C2F19520488C49EB4DEC30B6477E1 |
| SSDEEP: | 49152:1XsQZyJtDX8i20KTA2pIDbGaVthoXvJ4Yu/qf+dcKqJ2Ovp6GgG/:RsQ4y0KsiIWa92R4Yu/qfalABkE/ |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:16 13:31:25+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.33 |
| CodeSize: | 208384 |
| InitializedDataSize: | 146432 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x205e0 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 280 | "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" | C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | AcroRd32.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: HIGH Description: Adobe RdrCEF Exit code: 0 Version: 15.7.20033.133275 Modules
| |||||||||||||||
| 1308 | "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --channel=2940.0.1740915730 --type=renderer "C:\Program Files (x86)\Sep\Certificazione Partecipazione Corso AML IT15318.pdf" | C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | — | AcroRd32.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe Acrobat Reader DC Exit code: 0 Version: 15.7.20033.133275 Modules
| |||||||||||||||
| 1728 | "C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe" /service | C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | — | services.exe | |||||||||||
User: SYSTEM Company: host.exe Integrity Level: SYSTEM Description: host.exe Exit code: 0 Version: 7.7.0.0 Modules
| |||||||||||||||
| 1764 | "C:\ProgramData\Anyplace Control Support\hcs.exe" "/wallpaper=on" | C:\ProgramData\Anyplace Control Support\hcs.exe | — | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2104 | "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Reader_sl.exe" | C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Reader_sl.exe | — | AdobeARM.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: HIGH Description: Adobe Acrobat SpeedLauncher Exit code: 0 Version: 15.7.20033.133275 Modules
| |||||||||||||||
| 2112 | "C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exe" -el -s2 "-dC:\Program Files (x86)\Sep" "-sp" | C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exe | Certificazione Partecipazione Corso AML IT15318pdf.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2120 | "" "/runsupportversion" | C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | ||||||||||||
User: SYSTEM Company: host.exe Integrity Level: SYSTEM Description: host.exe Exit code: 0 Version: 7.7.0.0 Modules
| |||||||||||||||
| 2196 | "C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exe" | C:\Users\admin\AppData\Local\Temp\Certificazione Partecipazione Corso AML IT15318pdf.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2244 | "C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe" | C:\Program Files (x86)\Sep\sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | — | Certificazione Partecipazione Corso AML IT15318pdf.exe | |||||||||||
User: admin Company: host.exe Integrity Level: HIGH Description: host.exe Exit code: 0 Version: 7.7.0.0 Modules
| |||||||||||||||
| 2452 | "C:\ProgramData\Anyplace Control Support\hcs.exe" "/theme=onC:\ProgramData\Anyplace?Control?Support\apc-settings.ini" | C:\ProgramData\Anyplace Control Support\hcs.exe | — | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2196) Certificazione Partecipazione Corso AML IT15318pdf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2196) Certificazione Partecipazione Corso AML IT15318pdf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2196) Certificazione Partecipazione Corso AML IT15318pdf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2196) Certificazione Partecipazione Corso AML IT15318pdf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2112) Certificazione Partecipazione Corso AML IT15318pdf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2112) Certificazione Partecipazione Corso AML IT15318pdf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2112) Certificazione Partecipazione Corso AML IT15318pdf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2112) Certificazione Partecipazione Corso AML IT15318pdf.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2940) AcroRd32.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Acrobatbrokerserverdispatchercpp789 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1308) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection |
| Operation: | write | Name: | bLastExitNormal |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1308 | AcroRd32.exe | C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg | text | |
MD5:2BD4B1E5E05FF88A44DECFE3EC917933 | SHA256:864DDDCAC6BFCE12DF19EF8C75E7856AF5B90F898F04F06BEADC63C5A9960BA4 | |||
| 2244 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | C:\ProgramData\Anyplace Control Support\sessionID.txt | text | |
MD5:A5EA0AD9260B1550A14CC58D2C39B03D | SHA256:F1B2F662800122BED0FF255693DF89C4487FBDCF453D3524A42D4EC20C3D9C04 | |||
| 2244 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | C:\ProgramData\Anyplace Control Support\hcs.exe | executable | |
MD5:AC5933067B2C38299AE1443331A61511 | SHA256:8C305BB4C07FAC5C88AD1906E6195DD8176F7B6E5014E8FB3E081A45161CF72A | |||
| 1308 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919C.tmp | — | |
MD5:— | SHA256:— | |||
| 1308 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919D.tmp | — | |
MD5:— | SHA256:— | |||
| 1308 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919E.tmp | — | |
MD5:— | SHA256:— | |||
| 1308 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R919F.tmp | — | |
MD5:— | SHA256:— | |||
| 2244 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | C:\ProgramData\Anyplace Control Support\libspeex.dll | executable | |
MD5:E10DB82C997A756A01B6F954E86B83E0 | SHA256:65A9BBD5B3B9161C0DD61A9E185E391CFA68F31171E1A5FCFAD20BCC9EB09480 | |||
| 2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | C:\ProgramData\Anyplace Control Support\apc-host.log | text | |
MD5:81051BCC2CF1BEDF378224B0A93E2877 | SHA256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6 | |||
| 1308 | AcroRd32.exe | C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages | binary | |
MD5:65F4CAE473EAC06DB9942E32DBB303A6 | SHA256:FE63ACC1C0DB8391B5F544CFE4C45F4F6AB1E2EBE51EEF35D7C71074FC86CFBF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2940 | AcroRd32.exe | GET | 304 | 72.247.154.201:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/280.zip | unknown | — | — | unknown |
2940 | AcroRd32.exe | GET | 304 | 72.247.154.201:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/277.zip | unknown | — | — | unknown |
2940 | AcroRd32.exe | GET | 304 | 72.247.154.201:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/278.zip | unknown | — | — | unknown |
2940 | AcroRd32.exe | GET | 304 | 72.247.154.201:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/281.zip | unknown | — | — | unknown |
2940 | AcroRd32.exe | GET | 200 | 72.247.154.201:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/message.zip | unknown | compressed | 9.54 Kb | unknown |
884 | svchost.exe | HEAD | 200 | 88.221.110.112:80 | http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp | unknown | — | — | unknown |
884 | svchost.exe | GET | 206 | 88.221.110.112:80 | http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp | unknown | — | 5.78 Kb | unknown |
884 | svchost.exe | GET | 206 | 88.221.110.112:80 | http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp | unknown | binary | 7.83 Kb | unknown |
884 | svchost.exe | GET | 206 | 88.221.110.112:80 | http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp | unknown | binary | 10.6 Kb | unknown |
884 | svchost.exe | GET | 206 | 88.221.110.112:80 | http://ardownload.adobe.com/pub/adobe/reader/win/AcrobatDC/1502320070/AcroRdrDCUpd1502320070_MUI.msp | unknown | binary | 10.5 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | 216.158.90.159:443 | anyplace-gateway.work | WEBNX | US | unknown |
280 | RdrCEF.exe | 44.198.154.229:443 | cloud.acrobat.com | AMAZON-AES | US | unknown |
2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | 216.158.90.159:80 | anyplace-gateway.work | WEBNX | US | unknown |
2940 | AcroRd32.exe | 72.247.154.201:80 | acroipm2.adobe.com | Akamai International B.V. | DE | unknown |
2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | 216.158.90.159:5279 | anyplace-gateway.work | WEBNX | US | unknown |
Domain | IP | Reputation |
|---|---|---|
anyplace-gateway.work |
| unknown |
cloud.acrobat.com |
| whitelisted |
acroipm2.adobe.com |
| whitelisted |
armmf.adobe.com |
| whitelisted |
ardownload.adobe.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
324 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .work TLD |
2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | Misc activity | ET INFO Anyplace Remote Access Initial Connection Attempt (005) |
2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | Misc activity | ET INFO Anyplace Remote Access Initial Connection Attempt (005) |
2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | Misc activity | ET INFO Anyplace Remote Access Checkin (051) |
2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | Generic Protocol Command Decode | SURICATA HTTP Response invalid status |
2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | Misc activity | ET INFO Anyplace Remote Access Checkin (051) |
2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | Misc activity | ET INFO Anyplace Remote Access Initial Connection Attempt (005) |
280 | RdrCEF.exe | Unknown Traffic | ET JA3 Hash - Possible Malware - RigEK |
280 | RdrCEF.exe | Unknown Traffic | ET JA3 Hash - Possible Malware - RigEK |
2120 | sanexpedito87-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgTk5OTk5O.exe | Misc activity | ET INFO Anyplace Remote Access Initial Connection Attempt (005) |