ScreenShot
Created 2022.08.16 08:01 Machine s1_win7_x6403
Filename zl.pdf
Type PDF document, version 1.3
AI Score Not founds Behavior Score
2.0
ZERO API file : clean
VT API (file)
md5 84f0f3490acb0a861ce0cf97be914eed
sha256 47ed3c1001783f740ef0d6ca84b1d627b3e02fc6e5d7dd212fcf99da680b07da
ssdeep 49152:Ke4yTzJDobvvE0W/acbLwCT//0bAx1YFMv6zTkIKSkpVq5K3WxYIlR:Ke4KJ2fW/acbjTn0mpiERpVAwWxbR
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch One or more non-whitelisted processes were created
notice Performs some HTTP requests
notice Uses Windows utilities for basic Windows functionality

Rules (1cnts)

Level Name Description Collection
notice PDF_Format_Z PDF Format binaries (upload)

Network (6cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://acroipm2.adobe.com/20/rdr/ENU/win/nooem/none/consumer/277_20_6_20042.zip US CCCH-3 23.43.165.98 clean
http://acroipm2.adobe.com/20/rdr/ENU/win/nooem/none/consumer/281_20_6_20042.zip US CCCH-3 23.43.165.9 clean
http://acroipm2.adobe.com/20/rdr/ENU/win/nooem/none/consumer/280_20_6_20042.zip US CCCH-3 23.43.165.9 clean
http://acroipm2.adobe.com/20/rdr/ENU/win/nooem/none/consumer/278_20_6_20042.zip US CCCH-3 23.43.165.9 clean
http://acroipm2.adobe.com/20/rdr/ENU/win/nooem/none/consumer/message.zip US CCCH-3 23.43.165.98 clean
121.254.136.27 KR LG DACOM Corporation 121.254.136.27 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure