| File name: | Agreement1.pdf |
| Full analysis: | https://app.any.run/tasks/bfc598b4-01a2-43b0-a56b-8252f6c27ba5 |
| Verdict: | Malicious activity |
| Analysis date: | September 20, 2024, 14:11:23 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/pdf |
| File info: | PDF document, version 1.7 (zip deflate encoded) |
| MD5: | 3001330BD20008DD828AA54EA4F77A28 |
| SHA1: | 8A3B45BA38924041FF9F462854D293795BE54481 |
| SHA256: | EB692AEF288B4C445D4C0A43544A89F044DE9291D07E2CD5778D77BBC0D94B8A |
| SSDEEP: | 12288:KJmL1EU40U81UheU9rH3Ta/xXZXJ4cgNxoCyolt:KJmL1EU40U8iheU9rH3e/xXBJwoCt7 |
| | | Adobe Portable Document Format (100) |
| PDFVersion: | 1.7 |
|---|---|
| Linearized: | No |
| Author: | 1935211 |
| CreateDate: | 2013:05:10 15:06:36-07:00 |
| Creator: | PScript5.dll Version 5.2.2 |
| ModifyDate: | 2024:09:18 16:07:58-04:00 |
| Producer: | Acrobat Distiller 10.0.0 (Windows); modified using iTextSharp 5.3.0 (c) 1T3XT BVBA |
| Title: | Microsoft Word - LAF_MI_FITNESS (FI, UA) - Mar 2013 |
| HasXFA: | No |
| PageCount: | 5 |
| SigningDate: | 2024:05:13 16:12:01-07:00 |
| SigningAuthority: | ARE Production V8.1 G3 P24 1007657 |
| AnnotationUsageRights: |
|
| DocumentUsageRights: | FullSave |
| FormUsageRights: |
|
| SignatureUsageRights: | Modify |
| XMPToolkit: | Adobe XMP Core 9.1-c001 79.675d0f7, 2023/06/11-19:21:16 |
|---|---|
| Format: | application/pdf |
| Title: | Microsoft Word - LAF_MI_FITNESS (FI, UA) - Mar 2013 |
| Creator: | 1935211 |
| CreateDate: | 2013:05:10 15:06:36-07:00 |
| CreatorTool: | PScript5.dll Version 5.2.2 |
| ModifyDate: | 2024:09:18 16:07:58-04:00 |
| MetadataDate: | 2024:09:18 16:07:58-04:00 |
| Producer: | Acrobat Distiller 10.0.0 (Windows); modified using iTextSharp 5.3.0 (c) 1T3XT BVBA |
| DocumentID: | uuid:70eb18a7-42cc-461b-9132-378900e19e05 |
| InstanceID: | uuid:9ceeac09-4ac6-4e46-a996-12b58a8c60fa |
| State: | 1 |
| Version: | 1.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1612 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" --type=renderer /prefetch:1 "C:\Users\admin\AppData\Local\Temp\Agreement1.pdf" | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | — | Acrobat.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe Acrobat Version: 23.1.20093.0 Modules
| |||||||||||||||
| 1728 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=disabled --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2788 --field-trial-handle=1624,i,3615593387255245582,10518285548358821860,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | — | AcroCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe AcroCEF Version: 23.1.20093.0 Modules
| |||||||||||||||
| 2144 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe" GetChannelUri | C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | — | AdobeCollabSync.exe | |||||||||||
User: admin Integrity Level: LOW Exit code: 3221225547 Modules
| |||||||||||||||
| 2932 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2104 --field-trial-handle=1624,i,3615593387255245582,10518285548358821860,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | AcroCEF.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe AcroCEF Version: 23.1.20093.0 Modules
| |||||||||||||||
| 2976 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2616 --field-trial-handle=1624,i,3615593387255245582,10518285548358821860,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | — | AcroCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe AcroCEF Exit code: 0 Version: 23.1.20093.0 Modules
| |||||||||||||||
| 3376 | "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" /PRODUCT:Acrobat /VERSION:23.0 /MODE:3 | C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe | Acrobat.exe | ||||||||||||
User: admin Company: Adobe Inc. Integrity Level: MEDIUM Description: Adobe Reader and Acrobat Manager Version: 1.824.460.1042 Modules
| |||||||||||||||
| 4040 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2084 --field-trial-handle=1624,i,3615593387255245582,10518285548358821860,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | — | AcroCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe AcroCEF Version: 23.1.20093.0 Modules
| |||||||||||||||
| 5116 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1532 --field-trial-handle=1624,i,3615593387255245582,10518285548358821860,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | — | AcroCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe AcroCEF Exit code: 0 Version: 23.1.20093.0 Modules
| |||||||||||||||
| 5148 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=6360 | C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | AdobeCollabSync.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Acrobat Collaboration Synchronizer 23.1 Version: 23.1.20093.0 Modules
| |||||||||||||||
| 5532 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=2776 --field-trial-handle=1624,i,3615593387255245582,10518285548358821860,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | — | AcroCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe AcroCEF Version: 23.1.20093.0 Modules
| |||||||||||||||
| (PID) Process: | (5916) Acrobat.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-2034283098-2252572593-1072577386-2659511007-3245387615-27016815-3920691934 |
| Operation: | write | Name: | DisplayName |
Value: Adobe Acrobat Reader Protected Mode | |||
| (PID) Process: | (1612) Acrobat.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ExitSection |
| Operation: | write | Name: | bLastExitNormal |
Value: 0 | |||
| (PID) Process: | (1612) Acrobat.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c290FA7E61053E8763C6055E6333A99EFB83ECACB\cAdobe_OCSPRevChecker\cAuthorizedResponder\c0 |
| Operation: | write | Name: | bValue |
Value: 1 | |||
| (PID) Process: | (1612) Acrobat.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0 |
| Operation: | write | Name: | iEnd |
Value: 1 | |||
| (PID) Process: | (1612) Acrobat.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0 |
| Operation: | write | Name: | iStart |
Value: 1 | |||
| (PID) Process: | (1612) Acrobat.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue |
| Operation: | write | Name: | s0 |
Value: 312E322E3834302E3131343032312E312E362E3100 | |||
| (PID) Process: | (1612) Acrobat.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue |
| Operation: | write | Name: | s1 |
Value: 312E322E3834302E3131343032312E312E322E3100 | |||
| (PID) Process: | (1612) Acrobat.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1 |
| Operation: | write | Name: | iEnd |
Value: 2 | |||
| (PID) Process: | (1612) Acrobat.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1 |
| Operation: | write | Name: | iStart |
Value: 2 | |||
| (PID) Process: | (1612) Acrobat.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue |
| Operation: | write | Name: | s0 |
Value: 312E322E3834302E3131343032312E312E342E3100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5148 | AdobeCollabSync.exe | C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Reader\Synchronizer\resources\resource-18 | — | |
MD5:— | SHA256:— | |||
| 5148 | AdobeCollabSync.exe | C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Reader\Synchronizer\resources\resource-18.bak | — | |
MD5:— | SHA256:— | |||
| 5148 | AdobeCollabSync.exe | C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Reader\Synchronizer\resources\resource-19 | — | |
MD5:— | SHA256:— | |||
| 5148 | AdobeCollabSync.exe | C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Reader\Synchronizer\resources\resource-19.bak | — | |
MD5:— | SHA256:— | |||
| 1612 | Acrobat.exe | C:\Users\admin\AppData\Local\Temp\acrobat_sbx\A910q32bz_amdwbb_18s.tmp\SecuritySettings.xml | — | |
MD5:— | SHA256:— | |||
| 1612 | Acrobat.exe | C:\Users\admin\AppData\Local\Temp\acrobat_sbx\A9in1z0t_amdwbc_18s.tmp | — | |
MD5:— | SHA256:— | |||
| 1612 | Acrobat.exe | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json | binary | |
MD5:8268AD130BDEB146DEC78F6A8B24BBCC | SHA256:E58E6BD37D9EDE6BB536C58862AFD1087D3B4D6FE91E20542F9ECF50DA7B698F | |||
| 5148 | AdobeCollabSync.exe | C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Reader\Synchronizer\metadata\Synchronizer-journal | binary | |
MD5:FC63B5C991F627B89B2707A739A37773 | SHA256:1359B80B00A84DF67B9F3409052DEC5C7BB48D1534F7F5A09EF3A4E248AFDD08 | |||
| 1612 | Acrobat.exe | C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata | text | |
MD5:32FCA302C8B872738373D7CCB1E75FD4 | SHA256:CD0DD26304B88C20801FE80B33C49C009E2E5D4411B5D7F83252E1D90CD461C6 | |||
| 5148 | AdobeCollabSync.exe | C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Reader\Synchronizer\inprogress\download-19 | ||
MD5:A49FE08FD28CC93BB302AB5769A2C50C | SHA256:380044B1AA1DFA0F2FDC9229EA91AAEDCEEC4ACEA88D7F07E063B67B33BF66D5 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5916 | Acrobat.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | — | — | unknown |
5148 | AdobeCollabSync.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5916 | Acrobat.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | — | — | unknown |
3356 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
3376 | AdobeARM.exe | GET | 304 | 23.48.23.54:80 | http://acroipm2.adobe.com/assets/Owner/arm/ReportOwner.txt | unknown | — | — | whitelisted |
5916 | Acrobat.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | — | — | unknown |
3376 | AdobeARM.exe | GET | 404 | 23.48.23.54:80 | http://acroipm2.adobe.com/assets/Owner/arm/2024/9/UC/Other.txt | unknown | — | — | whitelisted |
3376 | AdobeARM.exe | GET | 404 | 23.48.23.54:80 | http://acroipm2.adobe.com/assets/Owner/arm/2024/9/OwnerAPI/Rdr.txt | unknown | — | — | whitelisted |
3376 | AdobeARM.exe | GET | 404 | 23.48.23.54:80 | http://acroipm2.adobe.com/assets/Owner/arm/2024/9/MRU/Rdr.txt | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 52.137.106.217:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1776 | RUXIMICS.exe | 52.137.106.217:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2120 | MoUsoCoreWorker.exe | 52.137.106.217:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4324 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5148 | AdobeCollabSync.exe | 23.73.140.157:443 | trustlist.adobe.com | AKAMAI-AS | CZ | whitelisted |
5148 | AdobeCollabSync.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
trustlist.adobe.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
armmf.adobe.com |
| whitelisted |
geo2.adobe.com |
| whitelisted |
p13n.adobe.io |
| whitelisted |
acroipm2.adobe.com |
| whitelisted |