Summary | ZeroBOX

제4기AMP 안내자료.pdf

Kimsuky Javascript ShellCode PDF
Category Machine Started Completed
FILE s1_win7_x6403_us Aug. 9, 2021, 10:55 p.m. Aug. 9, 2021, 10:57 p.m.
Size 203.2KB
Type PDF document, version 1.6
MD5 70294ac8b61bfb936334bcb6e6e8cc50
SHA256 512ad244c58064dfe102f27c9ec8814f3e3720593fe1e3ed48a8cb385d52ff84
CRC32 E33615E0
ssdeep 3072:xMLZB6xP2cQ8mUjIgBPsP5TUYdFTCrQlGvwJpKz9z7PDHUx2p:KLbGPQ8DZkPDFTCEl7s9z7PbB
Yara
  • PDF_Javascript_ShellCode - PDF Javascript ShellCode
  • APT_Kimsuky_PDF_Enc_Shellcode_Aug_2021_1 - Detect encoded Kimsuky shellcode used in fake PDF against South Korea
  • PDF_Format_Z - PDF Format

IP Address Status Action
164.124.101.2 Active Moloch
23.203.135.139 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

request GET http://acroipm2.adobe.com/20/rdr/ENU/win/nooem/none/consumer/278_20_6_20042.zip
request GET http://acroipm2.adobe.com/20/rdr/ENU/win/nooem/none/consumer/281_20_6_20042.zip
request GET http://acroipm2.adobe.com/20/rdr/ENU/win/nooem/none/consumer/280_20_6_20042.zip
request GET http://acroipm2.adobe.com/20/rdr/ENU/win/nooem/none/consumer/277_20_6_20042.zip
cmdline "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --backgroundcolor=16514043
parent_process acrord32.exe martian_process "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --backgroundcolor=16514043
Lionic Trojan.PDF.Agent.b!c
MicroWorld-eScan Trojan.GenericKD.46739119
ALYac Trojan.PDF.208091A
Arcabit Trojan.Generic.D2C92EAF
ESET-NOD32 PDF/Exploit.Pidief.AAY
TrendMicro-HouseCall TROJ_FRS.0NA103H621
Avast Other:Malware-gen [Trj]
Kaspersky HEUR:Trojan.Script.Agent.gen
BitDefender Trojan.GenericKD.46739119
ViRobot Trojan.Win32.S.FakePDF.208091
Ad-Aware Trojan.GenericKD.46739119
Emsisoft Trojan.GenericKD.46739119 (B)
Comodo Malware@#2f67s3zn21jr2
TrendMicro TROJ_FRS.0NA103H621
McAfee-GW-Edition RDN/Generic Exploit
FireEye Trojan.GenericKD.46739119
Sophos Troj/PDFEx-JN
Ikarus Exploit.Pidief
Avira EXP/Pidief.nynzr
Gridinsoft Trojan.U.Agent.oa
ZoneAlarm HEUR:Trojan.Script.Agent.gen
GData Trojan.GenericKD.46739119
Cynet Malicious (score: 99)
AhnLab-V3 Exploit/PDF.FakeDocu
McAfee RDN/Generic Exploit
Fortinet JS/Agent.FF84!tr
AVG Other:Malware-gen [Trj]