Summary | ZeroBOX

제4기AMP 안내자료.pdf

PDF
Category Machine Started Completed
FILE s1_win7_x6402 Aug. 5, 2021, 10:41 a.m. Aug. 5, 2021, 10:43 a.m.
Size 203.2KB
Type PDF document, version 1.6
MD5 70294ac8b61bfb936334bcb6e6e8cc50
SHA256 512ad244c58064dfe102f27c9ec8814f3e3720593fe1e3ed48a8cb385d52ff84
CRC32 E33615E0
ssdeep 3072:xMLZB6xP2cQ8mUjIgBPsP5TUYdFTCrQlGvwJpKz9z7PDHUx2p:KLbGPQ8DZkPDFTCEl7s9z7PbB
Yara
  • PDF_Format_Z - PDF Format

IP Address Status Action
164.124.101.2 Active Moloch
23.201.36.139 Active Moloch
23.40.44.138 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
request GET http://swupmf.adobe.com/manifest/60/win/reader9rdr-en_US.upd
request GET http://swupmf.adobe.com/manifest/60/win/AdobeUpdater.upd
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2056
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x71063000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1248
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000006c00000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2996
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x71b22000
process_handle: 0xffffffff
1 0 0
McAfee Artemis!70294AC8B61B
Kaspersky HEUR:Trojan-Dropper.PDF.Agent.gen
Comodo TrojWare.Win32.Agent.vlynu@0
TrendMicro HEUR_PDFEXP.B
McAfee-GW-Edition Artemis!Trojan
Microsoft Trojan:Win32/Casdet!rfn
ViRobot Trojan.Win32.S.FakePDF.208091
ZoneAlarm HEUR:Trojan-Dropper.PDF.Agent.gen
AhnLab-V3 Exploit/PDF.FakeDocu
ALYac Trojan.PDF.208091A
Fortinet JS/Agent.FF84!tr
parent_process acrord32.exe martian_process "C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe" -AU_LAUNCH_MODE=1 -AU_DISPLAY_LANG=en_US -AU_LAUNCH_APPID=reader9rdr-en_US
parent_process acrord32.exe martian_process "C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe" -doActionAppID=reader9rdr-en_US