| File name: | test.PDF |
| Full analysis: | https://app.any.run/tasks/5dc3b747-bc83-4c6c-b42f-a67c0097dd24 |
| Verdict: | No threats detected |
| Analysis date: | July 18, 2018, 12:52:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/pdf |
| File info: | PDF document, version 1.6 |
| MD5: | 6CFAF55FE96F89284D7FFB52223A2868 |
| SHA1: | A1A00D716E7676451DD514E8FA061473A740F76D |
| SHA256: | CDE95811D8A8C19559564B1B2BAAE6CF6476AAE60A2B4D5D7ED150B0EB7BA922 |
| SSDEEP: | 3072:Az2JJpQFHXk02CxRml4ibnSKPy32tw01p/CNIcOsyNDV75P+gVUxA4zz8:jJpQFHXk0SLTHUT01p/QKsaV664z |
| | | Adobe Portable Document Format (100) |
| PDFVersion: | 1.6 |
|---|---|
| Linearized: | No |
| SigningDate: | 2018:07:10 16:25:39+01:00 |
| SigningAuthority: | ARE_SAP Production V6.0.2 P1 0003309 |
| DocumentUsageRights: | FullSave |
| AnnotationUsageRights: |
|
| FormUsageRights: |
|
| UsageRightsMessage: | ReaderRights credential |
| EmbeddedFileUsageRights: |
|
| SignatureUsageRights: | Modify |
| HasXFA: | Yes |
| PageCount: | 1 |
| CreateDate: | 2018:07:10 16:25:39+01:00 |
| Creator: | Adobe XML Form Module Library |
| Producer: | Adobe XML Form Module Library |
| ModifyDate: | 2018:07:10 16:25:39+01:00 |
| XMPToolkit: | Adobe XMP Core 4.0-c317 44.274336, Sun Feb 04 2007 17:12:46 |
|---|---|
| MetadataDate: | 2018:07:10 16:25:39+01:00 |
| CreatorTool: | Adobe XML Form Module Library |
| ModifyDate: | 2018:07:10 16:25:39+01:00 |
| CreateDate: | 2018:07:10 16:25:39+01:00 |
| Producer: | Adobe XML Form Module Library |
| DocumentID: | uuid:4df753ee-4e34-434f-9ee5-476018684157 |
| InstanceID: | uuid:3685fa40-c976-43c0-a42d-05d8139514c7 |
| Format: | application/pdf |
| Version: | 8.1.2.4246.1.597341.521646 |
| VersionRef: | /template/subform[1] |
| EmbeddedHref: | http://gbrdsr00178.intranet.barcapint.com:50087/sap/bc/fp/form/layout/Unknown Embedded URI |
| EmbeddedHrefRef: | /template/subform[1]/pageSet[1]/pageArea[1]/subform[1]/field[1] |
| Schema_Annotation: | Character Length 11 |
| Schema_AnnotationRef: | /template/subform[1]/subform[1]/subform[11]/subform[1]/field[1] |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 348 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-delegated-renderer --disable-desktop-notifications --disable-file-system --disable-shared-workers --disable-speech-input --disable-threaded-compositing --disable-webaudio --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.7.20033 Chrome/35.0.1916.138" --disable-accelerated-compositing --disable-accelerated-video-decode --enable-software-compositing --disable-gpu-compositing --channel="1200.0.317929115\1851760419" --allow-no-sandbox-job /prefetch:673131151 | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | — | RdrCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe RdrCEF Exit code: 0 Version: 15.7.20033.133275 Modules
| |||||||||||||||
| 960 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-delegated-renderer --disable-desktop-notifications --disable-file-system --disable-shared-workers --disable-speech-input --disable-threaded-compositing --disable-webaudio --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.7.20033 Chrome/35.0.1916.138" --disable-accelerated-compositing --disable-accelerated-video-decode --enable-software-compositing --disable-gpu-compositing --channel="1200.1.1683494491\366381937" --allow-no-sandbox-job /prefetch:673131151 | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | — | RdrCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe RdrCEF Exit code: 0 Version: 15.7.20033.133275 Modules
| |||||||||||||||
| 1200 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | AcroRd32.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe RdrCEF Exit code: 0 Version: 15.7.20033.133275 Modules
| |||||||||||||||
| 2588 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\AppData\Local\Temp\test.PDF" | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | explorer.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe Acrobat Reader DC Exit code: 0 Version: 15.7.20033.133275 Modules
| |||||||||||||||
| 2940 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --channel=2588.0.2053394659 --type=renderer "C:\Users\admin\AppData\Local\Temp\test.PDF" | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | — | AcroRd32.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe Acrobat Reader DC Exit code: 0 Version: 15.7.20033.133275 Modules
| |||||||||||||||
| (PID) Process: | (2940) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection |
| Operation: | write | Name: | bLastExitNormal |
Value: 0 | |||
| (PID) Process: | (2940) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs |
| Operation: | write | Name: | bForms_AdhocWorkflowBackup |
Value: 0 | |||
| (PID) Process: | (2940) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs |
| Operation: | write | Name: | bJSCache_GlobSettings |
Value: 0 | |||
| (PID) Process: | (2940) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs |
| Operation: | write | Name: | bJSCache_GlobData |
Value: 1 | |||
| (PID) Process: | (1200) RdrCEF.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1200) RdrCEF.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\p2pcollab.dll,-8042 |
Value: Peer to Peer Trust | |||
| (PID) Process: | (1200) RdrCEF.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\qagentrt.dll,-10 |
Value: System Health Authentication | |||
| (PID) Process: | (1200) RdrCEF.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\dnsapi.dll,-103 |
Value: Domain Name System (DNS) Server Trust | |||
| (PID) Process: | (1200) RdrCEF.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\fveui.dll,-843 |
Value: BitLocker Drive Encryption | |||
| (PID) Process: | (1200) RdrCEF.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\fveui.dll,-844 |
Value: BitLocker Data Recovery Agent | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2940 | AcroRd32.exe | C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal | — | |
MD5:— | SHA256:— | |||
| 1200 | RdrCEF.exe | C:\Users\admin\AppData\Local\Temp\scoped_dir1200_21119\index | — | |
MD5:— | SHA256:— | |||
| 1200 | RdrCEF.exe | C:\Users\admin\AppData\Local\Temp\scoped_dir1200_21119\data_0 | — | |
MD5:— | SHA256:— | |||
| 1200 | RdrCEF.exe | C:\Users\admin\AppData\Local\Temp\scoped_dir1200_21119\data_1 | — | |
MD5:— | SHA256:— | |||
| 1200 | RdrCEF.exe | C:\Users\admin\AppData\Local\Temp\scoped_dir1200_21119\data_2 | — | |
MD5:— | SHA256:— | |||
| 1200 | RdrCEF.exe | C:\Users\admin\AppData\Local\Temp\scoped_dir1200_21119\data_3 | — | |
MD5:— | SHA256:— | |||
| 2940 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R60E3.tmp | — | |
MD5:— | SHA256:— | |||
| 2940 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R60E2.tmp | — | |
MD5:— | SHA256:— | |||
| 2940 | AcroRd32.exe | C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R60E0.tmp | ||
MD5:— | SHA256:— | |||
| 1200 | RdrCEF.exe | C:\Users\admin\AppData\Local\Temp\scoped_dir1200_21119\f_000001 | compressed | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2588 | AcroRd32.exe | GET | 304 | 2.16.186.33:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/278.zip | unknown | — | — | whitelisted |
2588 | AcroRd32.exe | GET | 304 | 2.16.186.33:80 | http://acroipm2.adobe.com/15/rdr/ENU/win/nooem/none/consumer/277.zip | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1200 | RdrCEF.exe | 52.6.202.91:443 | cloud.acrobat.com | Amazon.com, Inc. | US | unknown |
2588 | AcroRd32.exe | 2.16.186.33:80 | acroipm2.adobe.com | Akamai International B.V. | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
cloud.acrobat.com |
| whitelisted |
acroipm2.adobe.com |
| whitelisted |