Summary | ZeroBOX

Kula A.- protokół luty 2024 r..pdf

PDF
Category Machine Started Completed
FILE s1_win7_x6402 April 15, 2025, 8:54 a.m. April 15, 2025, 8:57 a.m.
Size 71.6KB
Type PDF document, version 1.6
MD5 13a484df8cbb1f389825687e79337be3
SHA256 64235f80edb6b6fb9d11820dee61afef6aaa04ebcb6012b0993ba7d38fb2e666
CRC32 C14D7F5B
ssdeep 1536:28qRByPQMVzDtNZEHOJXeKBDPP2ef6vWCF01Fga3y/vnh86jA1HF:aclIHO9bBDfy+CF6+Oy/vnC6jkl
Yara
  • PDF_Format_Z - PDF Format

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2032
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x70ef3000
process_handle: 0xffffffff
1 0 0
cmdline "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --locale=ko-kr --backgroundcolor=16514043
parent_process acrord32.exe martian_process "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --locale=ko-kr --backgroundcolor=16514043