IOC Report
https://acrobat%5B.%5Dadobe%5B.%5Dcom/id/urn:aaid:sc:EU:808ca57f-ca88-4942-80db-831b76d880f8

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Desktop\cmdline.out
ASCII text, with CRLF line terminators
modified

Processes

Path
Cmdline
Malicious
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://acrobat%5B.%5Dadobe%5B.%5Dcom/id/urn:aaid:sc:EU:808ca57f-ca88-4942-80db-831b76d880f8" > cmdline.out 2>&1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\wget.exe
wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://acrobat%5B.%5Dadobe%5B.%5Dcom/id/urn:aaid:sc:EU:808ca57f-ca88-4942-80db-831b76d880f8"

URLs

Name
IP
Malicious
https://acrobat%5B.%5Dadobe%5B.%5Dcom/id/urn:aaid:sc:EU:808ca57f-ca88-4942-80db-831b76d880f8
https://acrobat%5B.%5Dadobe%5B.%5Dcom/id/urn:aaid:sc:EU:808ca57f-ca88-4942-80db-831b76d880f8R_OF_P
unknown
https://acrobat%5B.%5Dadobe%5B.%5Dcom/id/urn:aaid:sc:EU:808ca57f-ca88-4942-80db-831b76d880f8ata
unknown
https://acrobat%5B.%5Dadobe%5B.%5Dcom/id/urn:aaid:sc:EU:808ca57f-ca88-4942-80db-831b76d880f8
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
B08000
heap
page read and write
170000
heap
page read and write
FFF000
stack
page read and write
ADE000
stack
page read and write
2DEF000
stack
page read and write
14E000
stack
page read and write
B00000
heap
page read and write
100000
heap
page read and write
1BE000
stack
page read and write
9C000
stack
page read and write
1C0000
heap
page read and write
1000000
heap
page read and write
DFF000
stack
page read and write
1100000
heap
page read and write
176000
heap
page read and write
150000
heap
page read and write
1105000
heap
page read and write
9CD000
stack
page read and write
100B000
heap
page read and write
1D0000
heap
page read and write
There are 10 hidden memdumps, click here to show them.