Windows Analysis Report
I&A_mileageForm.pdf

Overview

General Information

Sample name: I&A_mileageForm.pdf
Analysis ID: 1429077
MD5: b568796cfd232fbac356dee878e8bfe5
SHA1: 4c4faf0406d299c7763f7e2c166a180f88fdb35b
SHA256: 625134da02fcda22e28fb938495e38717ddcf61df6df1f90cee39d712e3c0c9d
Infos:

Detection

Score: 3
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

Contains long sleeps (>= 3 min)
IP address seen in connection with other malware
PDF has an OpenAction (likely to launch a dropper script)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Uses a known web browser user agent for HTTP communication

Classification

Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49737
Source: global traffic TCP traffic: 192.168.2.4:49737 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 192.168.2.4:49738 -> 52.5.13.197:443
Source: global traffic TCP traffic: 52.5.13.197:443 -> 192.168.2.4:49738
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 192.168.2.4:49745 -> 23.54.200.159:443
Source: global traffic TCP traffic: 23.54.200.159:443 -> 192.168.2.4:49745
Source: Joe Sandbox View IP Address: 52.5.13.197 52.5.13.197
Source: Joe Sandbox View IP Address: 23.54.200.159 23.54.200.159
Source: global traffic HTTP traffic detected: OPTIONS /psdk/v2/content?surfaceId=ACROBAT_READER_MASTER_SURFACEID&surfaceId=DC_READER_LAUNCH_CARD&surfaceId=DC_Reader_RHP_Banner&surfaceId=DC_Reader_RHP_Retention&surfaceId=Edit_InApp_Aug2020&surfaceId=DC_FirstMile_Right_Sec_Surface&surfaceId=DC_Reader_Upsell_Cards&surfaceId=DC_FirstMile_Home_View_Surface&surfaceId=DC_Reader_RHP_Intent_Banner&surfaceId=DC_Reader_Disc_LHP_Banner&surfaceId=DC_Reader_Edit_LHP_Banner&surfaceId=DC_Reader_Convert_LHP_Banner&surfaceId=DC_Reader_Sign_LHP_Banner&surfaceId=DC_Reader_More_LHP_Banner&surfaceId=DC_Reader_Disc_LHP_Retention&surfaceId=DC_Reader_Home_LHP_Trial_Banner&adcProductLanguage=en-us&adcVersion=23.6.20320&adcProductType=SingleClientMini&adcOSType=WIN&adcCountryCode=US&adcXAPIClientID=api_reader_desktop_win_23.6.20320&encodingScheme=BASE_64 HTTP/1.1Host: p13n.adobe.ioConnection: keep-aliveAccept: */*Access-Control-Request-Method: GETAccess-Control-Request-Headers: x-adobe-uuid,x-adobe-uuid-type,x-api-keyOrigin: https://rna-resource.acrobat.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Sec-Fetch-Mode: corsSec-Fetch-Site: cross-siteSec-Fetch-Dest: emptyReferer: https://rna-resource.acrobat.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /psdk/v2/content?surfaceId=ACROBAT_READER_MASTER_SURFACEID&surfaceId=DC_READER_LAUNCH_CARD&surfaceId=DC_Reader_RHP_Banner&surfaceId=DC_Reader_RHP_Retention&surfaceId=Edit_InApp_Aug2020&surfaceId=DC_FirstMile_Right_Sec_Surface&surfaceId=DC_Reader_Upsell_Cards&surfaceId=DC_FirstMile_Home_View_Surface&surfaceId=DC_Reader_RHP_Intent_Banner&surfaceId=DC_Reader_Disc_LHP_Banner&surfaceId=DC_Reader_Edit_LHP_Banner&surfaceId=DC_Reader_Convert_LHP_Banner&surfaceId=DC_Reader_Sign_LHP_Banner&surfaceId=DC_Reader_More_LHP_Banner&surfaceId=DC_Reader_Disc_LHP_Retention&surfaceId=DC_Reader_Home_LHP_Trial_Banner&adcProductLanguage=en-us&adcVersion=23.6.20320&adcProductType=SingleClientMini&adcOSType=WIN&adcCountryCode=US&adcXAPIClientID=api_reader_desktop_win_23.6.20320&encodingScheme=BASE_64 HTTP/1.1Host: p13n.adobe.ioConnection: keep-alivesec-ch-ua: "Chromium";v="105"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Accept: application/json, text/javascript, */*; q=0.01x-adobe-uuid: a4ecfc44-3976-4051-8c45-0a7e26b55a37x-adobe-uuid-type: visitorIdx-api-key: AdobeReader9sec-ch-ua-platform: "Windows"Origin: https://rna-resource.acrobat.comAccept-Language: en-US,en;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://rna-resource.acrobat.com/Accept-Encoding: gzip, deflate, br
Source: global traffic HTTP traffic detected: GET /onboarding/smskillreader.txt HTTP/1.1Host: armmf.adobe.comConnection: keep-aliveAccept-Language: en-US,en;q=0.9User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brIf-None-Match: "78-5faa31cce96da"If-Modified-Since: Mon, 01 May 2023 15:02:33 GMT
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 52.5.13.197
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.54.200.159
Source: global traffic HTTP traffic detected: GET /psdk/v2/content?surfaceId=ACROBAT_READER_MASTER_SURFACEID&surfaceId=DC_READER_LAUNCH_CARD&surfaceId=DC_Reader_RHP_Banner&surfaceId=DC_Reader_RHP_Retention&surfaceId=Edit_InApp_Aug2020&surfaceId=DC_FirstMile_Right_Sec_Surface&surfaceId=DC_Reader_Upsell_Cards&surfaceId=DC_FirstMile_Home_View_Surface&surfaceId=DC_Reader_RHP_Intent_Banner&surfaceId=DC_Reader_Disc_LHP_Banner&surfaceId=DC_Reader_Edit_LHP_Banner&surfaceId=DC_Reader_Convert_LHP_Banner&surfaceId=DC_Reader_Sign_LHP_Banner&surfaceId=DC_Reader_More_LHP_Banner&surfaceId=DC_Reader_Disc_LHP_Retention&surfaceId=DC_Reader_Home_LHP_Trial_Banner&adcProductLanguage=en-us&adcVersion=23.6.20320&adcProductType=SingleClientMini&adcOSType=WIN&adcCountryCode=US&adcXAPIClientID=api_reader_desktop_win_23.6.20320&encodingScheme=BASE_64 HTTP/1.1Host: p13n.adobe.ioConnection: keep-alivesec-ch-ua: "Chromium";v="105"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Accept: application/json, text/javascript, */*; q=0.01x-adobe-uuid: a4ecfc44-3976-4051-8c45-0a7e26b55a37x-adobe-uuid-type: visitorIdx-api-key: AdobeReader9sec-ch-ua-platform: "Windows"Origin: https://rna-resource.acrobat.comAccept-Language: en-US,en;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://rna-resource.acrobat.com/Accept-Encoding: gzip, deflate, br
Source: global traffic HTTP traffic detected: GET /onboarding/smskillreader.txt HTTP/1.1Host: armmf.adobe.comConnection: keep-aliveAccept-Language: en-US,en;q=0.9User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brIf-None-Match: "78-5faa31cce96da"If-Modified-Since: Mon, 01 May 2023 15:02:33 GMT
Source: I&A_mileageForm.pdf String found in binary or memory: http://www.aiim.org/pdfua/ns/id/
Source: FullTrustNotifier.exe, 00000010.00000002.1813207671.0000000000E1E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp
Source: FullTrustNotifier.exe, 00000010.00000002.1813207671.0000000000E1E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://android.notify.windows.com/iOS
Source: FullTrustNotifier.exe, 00000010.00000002.1813207671.0000000000E1E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://android.notify.windows.com/iOSr
Source: AdobeCollabSync.exe, 00000002.00000002.2971304927.000002C527264000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io
Source: AdobeCollabSync.exe, 00000002.00000002.2972363435.000002C529260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/s
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52906F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/schemas/bulk_entity_v1.json
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/schemas/e
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/schemas/entity_v1.json
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp, EntitySync-2024-04-20.log.2.dr String found in binary or memory: https://comments.adobe.io/sync/
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/&u
Source: AdobeCollabSync.exe, 00000002.00000003.2716714595.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2350913944.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2297374515.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000002.2972363435.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2676306990.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2879713769.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2797758676.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2318202667.000002C52926C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/-
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/.esuser.
Source: AdobeCollabSync.exe, 00000002.00000003.2716714595.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2350913944.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2297374515.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000002.2972363435.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2676306990.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2879713769.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2797758676.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2318202667.000002C52926C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/0
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/0t
Source: AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/3
Source: AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/5
Source: AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/8
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/:t
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/Cu
Source: AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/D
Source: AdobeCollabSync.exe, 00000002.00000002.2972363435.000002C529260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/S
Source: AdobeCollabSync.exe, 00000002.00000003.2716714595.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2350913944.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2297374515.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000002.2972363435.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2676306990.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2879713769.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2797758676.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2318202667.000002C52926C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/Windows
Source: AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/e
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/ju
Source: AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/n
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/pi-clien
Source: AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/r
Source: AdobeCollabSync.exe, 00000002.00000002.2971304927.000002C527264000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io28)
Source: AdobeCollabSync.exe, 00000001.00000002.2970690946.00000294587BC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://reviews.adobe.io
Source: FullTrustNotifier.exe, 00000010.00000002.1813207671.0000000000E1E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://wns.windows.com/47
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engine Classification label: clean3.winPDF@40/61@0/2
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe File created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe File created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\A9h8w0s7_1winam8_140.tmp Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA Jump to behavior
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C529039000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE IF NOT EXISTS resource_revisions ( revision_id TEXT PRIMARY KEY NOT NULL, rel_to_content_item TEXT NOT NULL, resource_type TEXT NOT NULL, media_type TEXT NOT NULL, locator TEXT NOT NULL, committed INTEGER NOT NULL, hashType TEXT DEFAULT NULL, hash TEXT DEFAULT NULL, storageSize INTEGER DEFAULT 0, width INTEGER DEFAULT 0, height INTEGER DEFAULT 0);
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C529039000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE IF NOT EXISTS resource_revisions ( revision_id TEXT PRIMARY KEY NOT NULL, rel_to_content_item TEXT NOT NULL, resource_type TEXT NOT NULL, media_type TEXT NOT NULL, locator TEXT NOT NULL, committed INTEGER NOT NULL, hashType TEXT DEFAULT NULL, hash TEXT DEFAULT NULL, storageSize INTEGER DEFAULT 0, width INTEGER DEFAULT 0, height INTEGER DEFAULT 0);G
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C529039000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE resource_revisions ( revision_id TEXT PRIMARY KEY NOT NULL, rel_to_content_item TEXT NOT NULL, resource_type TEXT NOT NULL, media_type TEXT NOT NULL, locator TEXT NOT NULL, committed INTEGER NOT NULL, hashType TEXT DEFAULT NULL, hash TEXT DEFAULT NULL, storageSize INTEGER DEFAULT 0, width INTEGER DEFAULT 0, height INTEGER DEFAULT 0));_
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C529039000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE IF NOT EXISTS sync_tokens ( content_item_id TEXT PRIMARY KEY NOT NULL, token TEXT DEFAULT NULL, last_sync_time TIMESTAMP DEFAULT NULL, device_mapping_id TEXT DEFAULT NULL);
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C5290AE000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SELECT pending_request_id, request_type, content_item_id, context, pending_request_created, request_status, message, status_code, device_mapping_id FROM pending_requests;
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C5290BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE IF NOT EXISTS content_item_resources ( content_item_revision_id TEXT NOT NULL, resource_revision_id TEXT NOT NULL, resource_id TEXT DEFAULT NULL, resource_cloud_etag TEXT DEFAULT NULL, resource_cloud_version_id TEXT DEFAULT NULL, resource_local_etag TEXT DEFAULT NULL, resource_local_version_id TEXT DEFAULT NULL, PRIMARY KEY (content_item_revision_id, resource_revision_id));
Source: AdobeCollabSync.exe, 00000002.00000002.2971863917.000002C52908E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: select rid, url, state, lastsynchronized, ttl, skiphours, skipdays, synchpriority, synchretries, flags, contentsize, cursyncetag, cursynclastmodified, cursynccontentsize, cursynctotalsynced, responsecode, hash, guid from resources where synchpriority< 50 and state !=0 and state !=5 and ttl!=2147483647 and flags & ? == 0 order by synchpriority asc limit ?=;~
Source: AdobeCollabSync.exe, 00000002.00000003.2716714595.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2286813002.000002C529268000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2350913944.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2297374515.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000002.2972363435.000002C52926D000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2676306990.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2879713769.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2797758676.000002C52926C000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2318202667.000002C52926C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE sync_tokens ( content_item_id TEXT PRIMARY KEY NOT NULL, token TEXT DEFAULT NULL, last_sync_time TIMESTAMP DEFAULT NULL, device_mapping_id TEXT DEFAULT NULL)T NULL, pending_request_created TIMESTAMP DEFAULT (strftime('%Y-%m-%dT%H:%M:%SZ', 'now', 'localtime')) NOT NULL, request_status TEXT DEFAULT "CREATED" NOT NULL, message TEXT DEFAULT NULL, status_code INTEGER DEFAULT -1 NOT NULL, device_mapping_id TEXT DEFAULT NULL, UNIQUE (content_item_id, request_type, request_status))UNIQUE (content_item_id, branch))<;~
Source: unknown Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\I&A_mileageForm.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=6352
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7316
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7416
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7524
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7628
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7728
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2104 --field-trial-handle=1540,i,13543496977365774410,5141392604321544278,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe" GetChannelUri
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=6352 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe" GetChannelUri Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7316 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7416 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7524 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7628 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7728 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2104 --field-trial-handle=1540,i,13543496977365774410,5141392604321544278,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: apphelp.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: vccorlib140.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: msvcp140.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: vcruntime140.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: vcruntime140.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: msvcp140.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: vcruntime140.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: appcontracts.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: wintypes.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: cdprt.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: cdp.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: windows.storage.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: wldp.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: umpdc.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: propsys.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: dsreg.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: msvcp110_win.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: cryptsp.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: I&A_mileageForm.pdf Initial sample: PDF keyword /JS count = 0
Source: I&A_mileageForm.pdf Initial sample: PDF keyword /JavaScript count = 0
Source: A9h8w0s7_1winam8_140.tmp.0.dr Initial sample: PDF keyword /JS count = 0
Source: A9h8w0s7_1winam8_140.tmp.0.dr Initial sample: PDF keyword /JavaScript count = 0
Source: A913kty8z_1winama_140.tmp.0.dr Initial sample: PDF keyword /JS count = 0
Source: A913kty8z_1winama_140.tmp.0.dr Initial sample: PDF keyword /JavaScript count = 0
Source: I&A_mileageForm.pdf Initial sample: PDF keyword stream count = 97
Source: I&A_mileageForm.pdf Initial sample: PDF keyword /EmbeddedFile count = 0
Source: I&A_mileageForm.pdf Initial sample: PDF keyword /ObjStm count = 12
Source: I&A_mileageForm.pdf Initial sample: PDF keyword obj count = 101
Source: I&A_mileageForm.pdf Initial sample: PDF keyword /OpenAction
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Thread delayed: delay time: 86400000 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Thread delayed: delay time: 30000 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Thread delayed: delay time: 86400000 Jump to behavior
Source: AdobeCollabSync.exe, 00000001.00000002.2970690946.00000294586DC000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000003.00000002.1706311165.0000018B814C9000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000004.00000002.1705333970.000001BDE919A000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000005.00000002.1725526727.00000266248A8000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000006.00000002.1724500565.00000254CE199000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000007.00000002.1746043376.000001C70BEFA000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000008.00000002.1744578255.0000022C75698000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000009.00000002.1766045414.000002582199B000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000009.00000003.1765630948.000002582199A000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 0000000A.00000002.1764877053.0000023B81588000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: AdobeCollabSync.exe, 00000002.00000002.2971304927.000002C527208000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 0000000C.00000002.1785175847.000001D0A6028000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll{{
Source: AdobeCollabSync.exe, 0000000B.00000002.1786467257.000001AF4C688000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllgg
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs