File name:

analisis.pdf

Full analysis: https://app.any.run/tasks/2f71a042-2daf-4526-88f4-cf7f9ffb147c
Verdict: Malicious activity
Analysis date: January 22, 2019, 16:51:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/pdf
File info: PDF document, version 1.5
MD5:

F28BAA94FF32D8A4B006004B3C9C4261

SHA1:

54677341B7E233D8C0B6DCD38DC5E9D1A58511EF

SHA256:

CC48D8C645C27DD850652C0A66E22DD2E1B62BBF6AD208F94B8F5847684A8D17

SSDEEP:

3072:cyu1+HubW8lW1Sn6WEQKLy0jSaMWyAKCxxDghhiR9j4BIIADNI63Cv3UOLn5ZVv1:cyu1PdWEHEQlWyA/7am9kBAJIECvv5bd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • informe_payload.exe (PID: 3572)
      • winlogon.exe (PID: 2880)
      • informe_payload.exe (PID: 2628)
    • Changes the autorun value in the registry

      • winlogon.exe (PID: 2880)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AcroRd32.exe (PID: 2304)
      • informe_payload.exe (PID: 3572)
    • Starts itself from another location

      • informe_payload.exe (PID: 3572)
  • INFO

    • Reads Internet Cache Settings

      • AcroRd32.exe (PID: 2976)
    • Application launched itself

      • AcroRd32.exe (PID: 2976)
      • RdrCEF.exe (PID: 3492)
    • Creates files in the user directory

      • AcroRd32.exe (PID: 2976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.pdf | Adobe Portable Document Format (100)

EXIF

PDF

PDFVersion: 1.5
Linearized: No
PageCount: 1
Language: en-US
TaggedPDF: Yes
Author: PoC
Creator: Microsoft® Word 2013
CreateDate: 2017:12:07 18:08:14-05:00
ModifyDate: 2017:12:07 18:08:14-05:00
Producer: Microsoft® Word 2013
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start acrord32.exe no specs acrord32.exe rdrcef.exe no specs rdrcef.exe no specs informe_payload.exe winlogon.exe informe_payload.exe

Process information

PID
CMD
Path
Indicators
Parent process
2304"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\AppData\Local\Temp\analisis.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
AcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2580"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3492.0.1086833937\1484432619" --allow-no-sandbox-job /prefetch:673131151C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeRdrCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe RdrCEF
Exit code:
0
Version:
15.23.20053.211670
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2628"C:\Users\admin\Desktop\informe_payload.exe" C:\Users\admin\Desktop\informe_payload.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\informe_payload.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2880"C:\Users\admin\appdata\local\winlogon.exe" C:\Users\admin\appdata\local\winlogon.exe
informe_payload.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\winlogon.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2976"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\AppData\Local\Temp\analisis.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeexplorer.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3492"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --backgroundcolor=16448250C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe RdrCEF
Exit code:
3221225547
Version:
15.23.20053.211670
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3572"C:\Users\admin\Desktop\informe_payload.exe" C:\Users\admin\Desktop\informe_payload.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\informe_payload.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 110
Read events
900
Write events
207
Delete events
3

Modification events

(PID) Process:(2304) AcroRd32.exeKey:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection
Operation:writeName:bLastExitNormal
Value:
0
(PID) Process:(2976) AcroRd32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(2976) AcroRd32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
0100000000000000020000000700000006000000030000000500000004000000FFFFFFFF
(PID) Process:(2976) AcroRd32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
Operation:writeName:MRUListEx
Value:
0200000001000000000000000400000003000000FFFFFFFF
(PID) Process:(2976) AcroRd32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2
Operation:writeName:1
Value:
5600310000000000744D863A100053797374656D333200003E0008000400EFBEEE3AA414744D863A2A000000F8060000000001000000000000000000000000000000530079007300740065006D0033003200000018000000
(PID) Process:(2976) AcroRd32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2
Operation:writeName:MRUListEx
Value:
0100000000000000FFFFFFFF
(PID) Process:(2976) AcroRd32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(2976) AcroRd32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\1
Operation:writeName:NodeSlot
Value:
95
(PID) Process:(2976) AcroRd32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\1
Operation:writeName:MRUListEx
Value:
FFFFFFFF
(PID) Process:(2976) AcroRd32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
Operation:writeName:KnownFolderDerivedFolderType
Value:
{57807898-8C4F-4462-BB63-71042380B109}
Executable files
2
Suspicious files
3
Text files
1
Unknown types
2

Dropped files

PID
Process
Filename
Type
2304AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
MD5:
SHA256:
2304AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
MD5:
SHA256:
2304AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\IconCacheRdr65536.datbinary
MD5:
SHA256:
2304AcroRd32.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessagessqlite
MD5:
SHA256:
2304AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SharedDataEventssqlite
MD5:
SHA256:
2304AcroRd32.exeC:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettingstext
MD5:DD4A3BD8B9FF61628346391EA9987E1D
SHA256:7C22C759CA704106556BBC4FC10B7F53404CA1F8B40F01038D3F7C4B8183F486
3572informe_payload.exeC:\users\admin\appdata\local\winlogon.exeexecutable
MD5:8606FAA60B008DA0CE43437DC81BE1E2
SHA256:4DE3DDE86D66424D79FCB561ACE579D6B22919F52505AA177BD161BCF4157C4F
2304AcroRd32.exeC:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\TMDocs.savbinary
MD5:5C6B932A79952B4B27833691305E61DB
SHA256:DEE5A5925227B125F4AC6D9B70A277E6EC8494FFC73D1CCE9E08CC7A78D6208A
2304AcroRd32.exeC:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\TMGrpPrm.savbinary
MD5:6A614A7743B0C781AAECA60448E861D6
SHA256:9703120DC62C2C3F843BAD5B1E77594682CA7820F0345AE0BBD73021C1427146
2304AcroRd32.exeC:\Users\admin\Desktop\informe_payload.pdfexecutable
MD5:8606FAA60B008DA0CE43437DC81BE1E2
SHA256:4DE3DDE86D66424D79FCB561ACE579D6B22919F52505AA177BD161BCF4157C4F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2880
winlogon.exe
190.85.249.45:443
Telmex Colombia S.A.
CO
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
informe_payload.exe
BILGE:TONYUKUK:BEN:ÖZÜM:TABGAC:ILINGE:KILINDIM:TÜRK:BODUNU:TABGACKA:KÖRÜK:ERTI
winlogon.exe
BILGE:TONYUKUK:BEN:ÖZÜM:TABGAC:ILINGE:KILINDIM:TÜRK:BODUNU:TABGACKA:KÖRÜK:ERTI
informe_payload.exe
BILGE:TONYUKUK:BEN:ÖZÜM:TABGAC:ILINGE:KILINDIM:TÜRK:BODUNU:TABGACKA:KÖRÜK:ERTI