Windows Analysis Report
aios3.exe

Overview

General Information

Sample name: aios3.exe
Analysis ID: 1431848
MD5: a1ad4d0b5f70c0bf97e5ef59e814c03d
SHA1: 583b88811550e7683916795306df383f06f08237
SHA256: ecdc7fc83fb0574ae1b35deffe21e8e778e3e21b760469851312e7d6483a8f03
Infos:

Detection

Score: 52
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for dropped file
Machine Learning detection for dropped file
Creates a process in suspended mode (likely to inject code)
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
IP address seen in connection with other malware
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files

Classification

AV Detection

barindex
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.$$A Virustotal: Detection: 19% Perma Link
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe (copy) Virustotal: Detection: 19% Perma Link
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.$$A Joe Sandbox ML: detected
Source: aios3.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\aios3.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E-Sticker Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user\AppData\Roaming\Adobe\Acrobat\E-Sticker Style 3 Uninstaller.$$A Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user\AppData\Roaming\Adobe\Acrobat Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user\AppData\Roaming\Adobe Jump to behavior
Source: Joe Sandbox View IP Address: 184.25.164.138 184.25.164.138
Source: Joe Sandbox View IP Address: 23.22.254.206 23.22.254.206
Source: aios3.exe String found in binary or memory: http://www.clickteam.com
Source: aios3.exe String found in binary or memory: http://www.clickteam.com/pub
Source: aios3.exe String found in binary or memory: http://www.clickteam.com/pub.bmp
Source: aios3.exe String found in binary or memory: http://www.clickteam.comc
Source: 01369b0e-588f-48a3-93ee-1c761f7cac52.tmp.16.dr String found in binary or memory: https://chrome.cloudflare-dns.com
Source: aios3.exe, 00000001.00000000.1214640044.000000000042D000.00000002.00000001.01000000.00000006.sdmp Binary or memory string: OriginalFilename vs aios3.exe
Source: aios3.exe, 00000001.00000003.1749291168.000000000272A000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename vs aios3.exe
Source: aios3.exe Binary or memory string: OriginalFilename vs aios3.exe
Source: aios3.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: mal52.winEXE@23/113@0/3
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\E-Sticker Style 3 Uninstaller.$$A Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6960:120:WilError_03
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe File created: C:\Users\user\AppData\Local\Temp\afolder Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\ztmp\t15594.bat" "C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe" "
Source: aios3.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\aios3.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File read: C:\Users\user\Desktop\aios3.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\aios3.exe "C:\Users\user\Desktop\aios3.exe"
Source: C:\Users\user\Desktop\aios3.exe Process created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe "C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe"
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\ztmp\t15594.bat" "C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe" "
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\ZGGKNSUKOP.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1640 --field-trial-handle=1568,i,13351684638296647614,3962373673390658352,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Users\user\Desktop\aios3.exe Process created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe "C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\ztmp\t15594.bat" "C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe" " Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1640 --field-trial-handle=1568,i,13351684638296647614,3962373673390658352,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: cmdext.dll Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\aios3.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E-Sticker Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\E-Sticker Style 3 Uninstaller.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\E-Sticker Style 3 Uninstaller.exe Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\2015\Stamps\AIO S3.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\2017\Stamps\AIO S3.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\2019\Stamps\AIO S3.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\2020\Stamps\AIO S3.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Stamps\AIO S3.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\E-Sticker Style 3 Uninstaller.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\10.0\Stamps\AIO S3.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe File created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\11.0\Stamps\AIO S3.$$A Jump to dropped file
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Adobe\Acrobat\E-Sticker Style 3 Uninstaller.$$A Jump to dropped file
Source: C:\Users\user\Desktop\aios3.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Adobe\Acrobat\E-Sticker Style 3 Uninstaller.exe Jump to dropped file
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\aios3.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user\AppData\Roaming\Adobe\Acrobat\E-Sticker Style 3 Uninstaller.$$A Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user\AppData\Roaming\Adobe\Acrobat Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe File opened: C:\Users\user\AppData\Roaming\Adobe Jump to behavior
Source: C:\Users\user\Desktop\aios3.exe Process created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe "C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\ztmp\t15594.bat" "C:\Users\user\AppData\Roaming\Adobe\Acrobat\CleanUpFilesAIOS3.exe" " Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs