Windows Analysis Report
00. business card_Luca STRANIERO.pdf

Overview

General Information

Sample name: 00. business card_Luca STRANIERO.pdf
Analysis ID: 1431108
MD5: 8729536ff1fc73f263c67050fa1e9aaa
SHA1: 4b2445ddfdae6a556102f466d8dc51711b0c0bb9
SHA256: 0be36f317fbd8ac2ab33fd81020ce6d768ea60f0fbd850b12efbe42f26f71e39
Infos:

Detection

Score: 2
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

Contains long sleeps (>= 3 min)
IP address seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)

Classification

Source: global traffic DNS query: name: chrome.cloudflare-dns.com
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49740
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49741
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49740
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49741
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49740
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49740
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49740
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49741
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49741
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49740
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49740
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49741
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49741
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49741
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49744
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49744
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49740
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49740
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49740 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49740
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49741
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49741
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49741 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49741
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49744
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49744
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49744
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49744
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49744
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49744
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49744
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 192.168.2.4:49744 -> 162.159.61.3:443
Source: global traffic TCP traffic: 162.159.61.3:443 -> 192.168.2.4:49744
Source: Joe Sandbox View IP Address: 162.159.61.3 162.159.61.3
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: chrome.cloudflare-dns.com
Source: unknown HTTP traffic detected: POST /dns-query HTTP/1.1Host: chrome.cloudflare-dns.comConnection: keep-aliveContent-Length: 128Accept: application/dns-messageAccept-Language: *User-Agent: ChromeAccept-Encoding: identityContent-Type: application/dns-message
Source: FullTrustNotifier.exe, 0000000D.00000002.1792383673.0000000000C0E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByAppb2
Source: FullTrustNotifier.exe, 0000000D.00000002.1792383673.0000000000C0E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://android.notify.windows.com/iOS
Source: FullTrustNotifier.exe, 0000000D.00000002.1792383673.0000000000C0E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://android.notify.windows.com/iOS5
Source: AdobeCollabSync.exe, 00000002.00000002.2895596795.0000022A37CA7000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adob
Source: AdobeCollabSync.exe, 00000002.00000003.2474174803.0000022A37E9A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io
Source: AdobeCollabSync.exe, 00000002.00000003.2474174803.0000022A37E9A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/schem
Source: AdobeCollabSync.exe, 00000002.00000002.2895596795.0000022A37CA7000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/schemas/bulk_entity_v1.json
Source: AdobeCollabSync.exe, 00000002.00000003.2400254283.0000022A37D1F000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.2739231297.0000022A37EA2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/schemas/entity_v1.json
Source: AdobeCollabSync.exe, 00000002.00000003.2400254283.0000022A37D1F000.00000004.00000020.00020000.00000000.sdmp, EntitySync-2024-04-24.log.2.dr String found in binary or memory: https://comments.adobe.io/sync/
Source: AdobeCollabSync.exe, 00000002.00000002.2895596795.0000022A37CED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/-
Source: AdobeCollabSync.exe, 00000002.00000002.2895596795.0000022A37CED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.io/sync/b
Source: AdobeCollabSync.exe, 00000002.00000002.2895075237.0000022A35FE4000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://comments.adobe.iorobat.com1
Source: AdobeCollabSync.exe, 00000001.00000002.2895077233.000001DEFC3D0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com
Source: AdobeCollabSync.exe, 00000002.00000002.2895596795.0000022A37CED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://reviews.adobe.io
Source: AdobeCollabSync.exe, 00000002.00000002.2895596795.0000022A37CED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://reviews.adobe.io153952.552:
Source: FullTrustNotifier.exe, 0000000D.00000002.1792383673.0000000000C0E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://wns.windows.com/
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: classification engine Classification label: clean2.winPDF@40/55@1/1
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe File created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe File created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-04-24 15-39-27-473.log Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA Jump to behavior
Source: AdobeCollabSync.exe, 00000002.00000002.2895596795.0000022A37C5F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE IF NOT EXISTS content_item_revisions( content_item_revision_id TEXT PRIMARY KEY NOT NULL, cloud_etag TEXT DEFAULT NULL, cloud_version_id TEXT DEFAULT NULL, updated TIMESTAMP DEFAULT NULL, acl TEXT DEFAULT NULL, local_etag TEXT DEFAULT NULL, local_version_id TEXT DEFAULT NULL, request_id TEXT DEFAULT NULL, content_name TEXT DEFAULT NULL);
Source: AdobeCollabSync.exe, 00000002.00000003.2728708884.0000022A37D12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SELECT pending_request_id, request_type, content_item_id, context, pending_request_created, request_status, message, status_code, device_mapping_id FROM pending_requests;
Source: AdobeCollabSync.exe, 00000002.00000003.1667612689.0000022A37C72000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.1668010695.0000022A37C72000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.1668242366.0000022A37C73000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000002.2895596795.0000022A37C5F000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.1667423091.0000022A37C72000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000002.00000003.1668930216.0000022A37C6B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE resources(rid integer not null primary key autoincrement, url text(512) not null unique, state integer not null default 0, lastsynchronized integer default 0, ttl integer not null default 3600, ttloverride integer default NULL, skiphours integer default 0, skipdays integer default 0, synchpriority integer not null default 0, synchretries integer default 0, flags integer default 0, contentsize integer default 0, cursyncetag text(128) default NULL, cursynclastmodi@;
Source: AdobeCollabSync.exe, 00000002.00000002.2895596795.0000022A37D00000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: select rid, url, state, lastsynchronized, ttl, skiphours, skipdays, synchpriority, synchretries, flags, contentsize, cursyncetag, cursynclastmodified, cursynccontentsize, cursynctotalsynced, responsecode, hash, guid from resources where synchpriority< 50 and state !=0 and state !=5 and ttl!=2147483647 and flags & ? == 0 order by synchpriority asc limit ?quot;x-api-client-id&quot;:&quot61
Source: unknown Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\00. business card_Luca STRANIERO.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7788
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7960
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=8068
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=8176
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7372
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7352
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe" GetChannelUri
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2084 --field-trial-handle=1732,i,15913500959655005552,13017635812736798014,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7788 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe" GetChannelUri Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7960 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=8068 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=8176 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7372 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7352 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2084 --field-trial-handle=1732,i,15913500959655005552,13017635812736798014,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: vccorlib140.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: appcontracts.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: cdprt.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: cdp.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: dsreg.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: 00. business card_Luca STRANIERO.pdf Initial sample: PDF keyword /JS count = 0
Source: 00. business card_Luca STRANIERO.pdf Initial sample: PDF keyword /JavaScript count = 0
Source: 00. business card_Luca STRANIERO.pdf Initial sample: PDF keyword stream count = 63
Source: 00. business card_Luca STRANIERO.pdf Initial sample: PDF keyword /EmbeddedFile count = 0
Source: 00. business card_Luca STRANIERO.pdf Initial sample: PDF keyword obj count = 66
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Thread delayed: delay time: 86400000 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Thread delayed: delay time: 30000 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Thread delayed: delay time: 86400000 Jump to behavior
Source: AdobeCollabSync.exe, 00000004.00000002.1684521506.000002B29A1A0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll1
Source: AdobeCollabSync.exe, 00000003.00000003.1685308882.00000210F3F9B000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000003.00000002.1685924785.00000210F3F9C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllOOt&P
Source: AdobeCollabSync.exe, 00000005.00000002.1705700117.000001DADE1D9000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000007.00000002.1727780487.000001F125DAB000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000007.00000003.1727363942.000001F125DAA000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000008.00000002.1725757020.0000019AF4809000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 00000009.00000002.1746771609.0000020E64AA8000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 0000000B.00000002.1766994449.000001DE917B7000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: AdobeCollabSync.exe, 00000001.00000002.2894222228.000001DEFA4CC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllrr
Source: AdobeCollabSync.exe, 00000002.00000002.2895075237.0000022A35EF8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll88
Source: AdobeCollabSync.exe, 00000006.00000002.1704612512.0000020796A58000.00000004.00000020.00020000.00000000.sdmp, AdobeCollabSync.exe, 0000000C.00000002.1765549351.000002C110CC8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll{{
Source: AdobeCollabSync.exe, 0000000A.00000002.1745308289.000002AA6B608000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll;;
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs