analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

analisis.pdf

Full analysis: https://app.any.run/tasks/2f71a042-2daf-4526-88f4-cf7f9ffb147c
Verdict: Malicious activity
Analysis date: January 22, 2019, 16:51:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/pdf
File info: PDF document, version 1.5
MD5:

F28BAA94FF32D8A4B006004B3C9C4261

SHA1:

54677341B7E233D8C0B6DCD38DC5E9D1A58511EF

SHA256:

CC48D8C645C27DD850652C0A66E22DD2E1B62BBF6AD208F94B8F5847684A8D17

SSDEEP:

3072:cyu1+HubW8lW1Sn6WEQKLy0jSaMWyAKCxxDghhiR9j4BIIADNI63Cv3UOLn5ZVv1:cyu1PdWEHEQlWyA/7am9kBAJIECvv5bd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • informe_payload.exe (PID: 3572)
      • winlogon.exe (PID: 2880)
      • informe_payload.exe (PID: 2628)
    • Changes the autorun value in the registry

      • winlogon.exe (PID: 2880)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AcroRd32.exe (PID: 2304)
      • informe_payload.exe (PID: 3572)
    • Starts itself from another location

      • informe_payload.exe (PID: 3572)
  • INFO

    • Application launched itself

      • RdrCEF.exe (PID: 3492)
      • AcroRd32.exe (PID: 2976)
    • Reads Internet Cache Settings

      • AcroRd32.exe (PID: 2976)
    • Creates files in the user directory

      • AcroRd32.exe (PID: 2976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.pdf | Adobe Portable Document Format (100)

EXIF

PDF

Producer: Microsoft® Word 2013
ModifyDate: 2017:12:07 18:08:14-05:00
CreateDate: 2017:12:07 18:08:14-05:00
Creator: Microsoft® Word 2013
Author: PoC
TaggedPDF: Yes
Language: en-US
PageCount: 1
Linearized: No
PDFVersion: 1.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start acrord32.exe no specs acrord32.exe rdrcef.exe no specs rdrcef.exe no specs informe_payload.exe winlogon.exe informe_payload.exe

Process information

PID
CMD
Path
Indicators
Parent process
2976"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\AppData\Local\Temp\analisis.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeexplorer.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
2304"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\AppData\Local\Temp\analisis.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
AcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
3492"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --backgroundcolor=16448250C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe RdrCEF
Exit code:
3221225547
Version:
15.23.20053.211670
2580"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3492.0.1086833937\1484432619" --allow-no-sandbox-job /prefetch:673131151C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
15.23.20053.211670
3572"C:\Users\admin\Desktop\informe_payload.exe" C:\Users\admin\Desktop\informe_payload.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
2880"C:\Users\admin\appdata\local\winlogon.exe" C:\Users\admin\appdata\local\winlogon.exe
informe_payload.exe
User:
admin
Integrity Level:
MEDIUM
2628"C:\Users\admin\Desktop\informe_payload.exe" C:\Users\admin\Desktop\informe_payload.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Total events
1 110
Read events
900
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
3
Text files
1
Unknown types
2

Dropped files

PID
Process
Filename
Type
2304AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
MD5:
SHA256:
2304AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
MD5:
SHA256:
2304AcroRd32.exeC:\Users\admin\Desktop\informe_payload.pdfexecutable
MD5:8606FAA60B008DA0CE43437DC81BE1E2
SHA256:4DE3DDE86D66424D79FCB561ACE579D6B22919F52505AA177BD161BCF4157C4F
2304AcroRd32.exeC:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettingstext
MD5:DD4A3BD8B9FF61628346391EA9987E1D
SHA256:7C22C759CA704106556BBC4FC10B7F53404CA1F8B40F01038D3F7C4B8183F486
3572informe_payload.exeC:\users\admin\appdata\local\winlogon.exeexecutable
MD5:8606FAA60B008DA0CE43437DC81BE1E2
SHA256:4DE3DDE86D66424D79FCB561ACE579D6B22919F52505AA177BD161BCF4157C4F
2304AcroRd32.exeC:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\TMGrpPrm.savbinary
MD5:6A614A7743B0C781AAECA60448E861D6
SHA256:9703120DC62C2C3F843BAD5B1E77594682CA7820F0345AE0BBD73021C1427146
2304AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\IconCacheRdr65536.datbinary
MD5:BA16B8525827F2B37E3636DDAF884E9B
SHA256:800D447AC2A1740C1EDC412169D2C3729F54EABABCA4D7D956F66192EE676537
2304AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessagessqlite
MD5:71289F8F8D3000638A846F994C51E52B
SHA256:A67239B25EF289BB16B95FEB12A1D0A77FEF6772CD26901970BCE3116D81FCB9
2304AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SharedDataEventssqlite
MD5:02540E9F140C6E6C9C8240E98D2053CD
SHA256:5DE7F56E1136732CBBD4E6FA6D045F4E724AE6D4E00158847F0083EECF69CA79
2304AcroRd32.exeC:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\TMDocs.savbinary
MD5:5C6B932A79952B4B27833691305E61DB
SHA256:DEE5A5925227B125F4AC6D9B70A277E6EC8494FFC73D1CCE9E08CC7A78D6208A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2880
winlogon.exe
190.85.249.45:443
Telmex Colombia S.A.
CO
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
informe_payload.exe
BILGE:TONYUKUK:BEN:ÖZÜM:TABGAC:ILINGE:KILINDIM:TÜRK:BODUNU:TABGACKA:KÖRÜK:ERTI
winlogon.exe
BILGE:TONYUKUK:BEN:ÖZÜM:TABGAC:ILINGE:KILINDIM:TÜRK:BODUNU:TABGACKA:KÖRÜK:ERTI
informe_payload.exe
BILGE:TONYUKUK:BEN:ÖZÜM:TABGAC:ILINGE:KILINDIM:TÜRK:BODUNU:TABGACKA:KÖRÜK:ERTI