Summary | ZeroBOX

1.pdf

PDF
Category Machine Started Completed
FILE s1_win7_x6402 Aug. 5, 2021, 10:31 a.m. Aug. 5, 2021, 10:34 a.m.
Size 693.6KB
Type PDF document, version 2.0
MD5 a0c7e9dc69e439cb431e6dea9f0d5930
SHA256 359ab5e0b57da0307ca9472e5b225dcd0f9dc9bf2efd2f15b1ca45b78791b6bc
CRC32 308D9976
ssdeep 12288:e9wwBpdbie7g84OTKuBqOX1BNVT5m+YH+JARGEwuxkIOcaj/5vDTWjaOyG2:Xkdz7y2DBJ1dYHoARzTkjcwvDTWOL
Yara
  • PDF_Format_Z - PDF Format

IP Address Status Action
164.124.101.2 Active Moloch
23.212.12.57 Active Moloch
23.40.44.138 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
request GET http://swupmf.adobe.com/manifest/60/win/reader9rdr-en_US.upd
request GET http://swupmf.adobe.com/manifest/60/win/AdobeUpdater.upd
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2004
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6fe73000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1248
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000006c00000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x71b22000
process_handle: 0xffffffff
1 0 0
ALYac Trojan.PDF.208091A
Kaspersky UDS:Trojan-Dropper.PDF.Agent.a
ViRobot Trojan.Win32.S.FakePDF.710268
McAfee-GW-Edition Artemis
AhnLab-V3 Exploit/PDF.FakeDocu
McAfee Artemis!A0C7E9DC69E4
Qihoo-360 susp.pdf.jsexp.gen
parent_process acrord32.exe martian_process "C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe" -AU_LAUNCH_MODE=1 -AU_DISPLAY_LANG=en_US -AU_LAUNCH_APPID=reader9rdr-en_US
parent_process acrord32.exe martian_process "C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe" -doActionAppID=reader9rdr-en_US