File name:

DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Full analysis: https://app.any.run/tasks/733a4118-9e8a-4c63-9aa7-d81a3308c473
Verdict: No threats detected
Analysis date: June 16, 2018, 21:16:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/CDFV2
File info: Composite Document File V2 Document, Cannot read section info
MD5:

EA83B2D19E892C1944D90771280268BA

SHA1:

CBAC6A8D28BF22BFEF9787E0651FF44E48A79385

SHA256:

C98B154BF6E410A19CA5B9887B917BCA88C137C473A984B0D61B5D8190B9A9F8

SSDEEP:

12:rl0VGFnIgjyV7w1YnpzqN30FCFntjyVIw1YUpzqN30aohUEY7VtxvBMZq77/hUEO:rX2c1YC/uX1YpUhUEYhtxOahUEYhtxX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Dropped object may contain URL's

      • AcroRd32.exe (PID: 3868)
      • RdrCEF.exe (PID: 4080)
    • Creates files in the user directory

      • AcroRd32.exe (PID: 3532)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

. | Generic OLE2 / Multistream Compound File (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
5
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rundll32.exe no specs acrord32.exe no specs acrord32.exe no specs rdrcef.exe rdrcef.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2352"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-delegated-renderer --disable-desktop-notifications --disable-file-system --disable-shared-workers --disable-speech-input --disable-threaded-compositing --disable-webaudio --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.7.20033 Chrome/35.0.1916.138" --disable-accelerated-compositing --disable-accelerated-video-decode --enable-software-compositing --disable-gpu-compositing --channel="4080.0.1028637002\884869553" --allow-no-sandbox-job /prefetch:673131151C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe RdrCEF
Exit code:
0
Version:
15.7.20033.133275
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3268"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Roaming\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini.C:\Windows\system32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3532"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\AppData\Roaming\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exerundll32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat Reader DC
Exit code:
0
Version:
15.7.20033.133275
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3868"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --channel=3532.0.601868191 --type=renderer "C:\Users\admin\AppData\Roaming\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
0
Version:
15.7.20033.133275
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
4080"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
AcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe RdrCEF
Exit code:
0
Version:
15.7.20033.133275
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
542
Read events
472
Write events
70
Delete events
0

Modification events

(PID) Process:(3268) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.\OpenWithList
Operation:writeName:a
Value:
AcroRd32.exe
(PID) Process:(3268) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.\OpenWithList
Operation:writeName:MRUList
Value:
a
(PID) Process:(3868) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection
Operation:writeName:bLastExitNormal
Value:
0
(PID) Process:(3268) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\93\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4080) RdrCEF.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\93\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
0
Suspicious files
3
Text files
1
Unknown types
6

Dropped files

PID
Process
Filename
Type
3868AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
MD5:
SHA256:
4080RdrCEF.exeC:\Users\admin\AppData\Local\Temp\scoped_dir4080_26318\index
MD5:
SHA256:
4080RdrCEF.exeC:\Users\admin\AppData\Local\Temp\scoped_dir4080_26318\data_0
MD5:
SHA256:
4080RdrCEF.exeC:\Users\admin\AppData\Local\Temp\scoped_dir4080_26318\data_1
MD5:
SHA256:
4080RdrCEF.exeC:\Users\admin\AppData\Local\Temp\scoped_dir4080_26318\data_2
MD5:
SHA256:
4080RdrCEF.exeC:\Users\admin\AppData\Local\Temp\scoped_dir4080_26318\data_3
MD5:
SHA256:
4080RdrCEF.exeC:\Users\admin\AppData\Local\Temp\Cab6DEB.tmp
MD5:
SHA256:
4080RdrCEF.exeC:\Users\admin\AppData\Local\Temp\Tar6DEC.tmp
MD5:
SHA256:
4080RdrCEF.exeC:\Users\admin\AppData\Local\Temp\Cab6E0C.tmp
MD5:
SHA256:
4080RdrCEF.exeC:\Users\admin\AppData\Local\Temp\Tar6E0D.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4080
RdrCEF.exe
GET
304
2.16.186.56:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
whitelisted
4080
RdrCEF.exe
GET
304
2.16.186.56:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4080
RdrCEF.exe
2.16.186.56:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted
4080
RdrCEF.exe
34.203.96.224:443
cloud.acrobat.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
cloud.acrobat.com
  • 34.203.96.224
  • 54.164.230.230
whitelisted
www.download.windowsupdate.com
  • 2.16.186.56
  • 2.16.186.81
whitelisted

Threats

No threats detected
No debug info