Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Aug. 5, 2021, 10:31 a.m. | Aug. 5, 2021, 10:34 a.m. |
-
AcroRd32.exe "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" C:\Users\test22\AppData\Local\Temp\1.pdf
2004-
Adobe_Updater.exe "C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe" -doActionAppID=reader9rdr-en_US
2460 -
Adobe_Updater.exe "C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe" -AU_LAUNCH_MODE=1 -AU_DISPLAY_LANG=en_US -AU_LAUNCH_APPID=reader9rdr-en_US
2112
-
-
explorer.exe C:\Windows\Explorer.EXE
1248
Name | Response | Post-Analysis Lookup |
---|---|---|
swupmf.adobe.com | 104.109.240.143 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
request | GET http://swupmf.adobe.com/manifest/60/win/reader9rdr-en_US.upd |
request | GET http://swupmf.adobe.com/manifest/60/win/AdobeUpdater.upd |
ALYac | Trojan.PDF.208091A |
Kaspersky | UDS:Trojan-Dropper.PDF.Agent.a |
ViRobot | Trojan.Win32.S.FakePDF.710268 |
McAfee-GW-Edition | Artemis |
AhnLab-V3 | Exploit/PDF.FakeDocu |
McAfee | Artemis!A0C7E9DC69E4 |
Qihoo-360 | susp.pdf.jsexp.gen |
parent_process | acrord32.exe | martian_process | "C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe" -AU_LAUNCH_MODE=1 -AU_DISPLAY_LANG=en_US -AU_LAUNCH_APPID=reader9rdr-en_US | ||||||
parent_process | acrord32.exe | martian_process | "C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe" -doActionAppID=reader9rdr-en_US |