Summary | ZeroBOX

free-mega-vip-roblox.pdf

PDF Suspicious Link PDF
Category Machine Started Completed
FILE s1_win7_x6402 Aug. 9, 2021, 9:15 a.m. Aug. 9, 2021, 9:17 a.m.
Size 41.5KB
Type PDF document, version 1.4
MD5 bd2cde8cfd6faa5405a6d3b337cd1543
SHA256 5ae6fccbbeb36d5271c2f06ee18b6f86091260b8c2ae224298e071f5084dcd0c
CRC32 793DA671
ssdeep 768:RhhJCQpMt7bhg/LOo5g7baa32NimyMreISQBIYl3MznyEK+:NTa9bhBoEaTN6KfqYl8bK+
Yara
  • PDF_Suspicious_Link_Z - PDF Suspicious Link
  • PDF_Format_Z - PDF Format

IP Address Status Action
164.124.101.2 Active Moloch
23.212.12.57 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
request GET http://swupmf.adobe.com/manifest/60/win/reader9rdr-en_US.upd
request GET http://swupmf.adobe.com/manifest/60/win/AdobeUpdater.upd
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x71093000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1248
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000005410000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 3048
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x71b22000
process_handle: 0xffffffff
1 0 0
parent_process acrord32.exe martian_process "C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe" -AU_LAUNCH_MODE=1 -AU_DISPLAY_LANG=en_US -AU_LAUNCH_APPID=reader9rdr-en_US
parent_process acrord32.exe martian_process "C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe" -doActionAppID=reader9rdr-en_US