Windows Analysis Report 8795156_490162680Email_Correspondence.pdf

Overview

General Information

Sample Name: 8795156_490162680Email_Correspondence.pdf
Analysis ID: 483802
MD5: 20da3e9fb6519f8ec141e8aa156c0aaf
SHA1: 1d064b479bb9c3561cc80e64fee9c37a43460bf1
SHA256: 65492564da5ba6456e2e2a7f6b91946945833ac33d8334193993b751fd8b5e6a
Infos:

Most interesting Screenshot:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: AcroRd32.exe, 00000002.00000000.254800589.000000000B470000.00000004.00000001.sdmp String found in binary or memory: http://...............Acrobat
Source: AcroRd32.exe, 00000002.00000000.284840503.000000000BFAC000.00000004.00000001.sdmp String found in binary or memory: http://ns.ado
Source: AcroRd32.exe, 00000002.00000000.254521660.000000000B18E000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.253353779.000000000A2DF000.00000004.00000001.sdmp String found in binary or memory: http://www.dictionary.com/cgi-bin/dict.pl?term=
Source: AcroRd32.exe, 00000002.00000000.274213381.0000000008656000.00000004.00000001.sdmp String found in binary or memory: http://www.quicktime.com.Acrobat
Source: AcroRd32.exe, 00000002.00000000.254800589.000000000B470000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.267336039.000000000B62F000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.256934961.000000000B704000.00000004.00000001.sdmp String found in binary or memory: http://www.sars.gov.za/forms/
Source: AcroRd32.exe, 00000002.00000000.267336039.000000000B62F000.00000004.00000001.sdmp String found in binary or memory: http://www.sars.gov.za/forms/_
Source: AcroRd32.exe, 00000002.00000000.277848368.000000000A6B1000.00000004.00000001.sdmp String found in binary or memory: http://www.w3.o
Source: AcroRd32.exe, 00000002.00000000.254800589.000000000B470000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.284188338.000000000BD77000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.284840503.000000000BFAC000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.277848368.000000000A6B1000.00000004.00000001.sdmp String found in binary or memory: http://www.xfa.org/schema/xci/2.6/
Source: AcroRd32.exe, 00000002.00000000.270257827.000000000BE64000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.249194846.00000000046EB000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.256934961.000000000B704000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.283263192.000000000BB34000.00000004.00000001.sdmp String found in binary or memory: http://www.xfa.org/schema/xfa-data/1.0/
Source: AcroRd32.exe, 00000002.00000000.270257827.000000000BE64000.00000004.00000001.sdmp String found in binary or memory: http://www.xfa.org/schema/xfa-data/1.0/ns#/
Source: AcroRd32.exe, 00000002.00000000.275263678.0000000009DBF000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.277848368.000000000A6B1000.00000004.00000001.sdmp, 8795156_490162680Email_Correspondence.pdf String found in binary or memory: http://www.xfa.org/schema/xfa-form/2.6/
Source: AcroRd32.exe, 00000002.00000000.254800589.000000000B470000.00000004.00000001.sdmp String found in binary or memory: http://www.xfa.org/schema/xfa-form/2.8/
Source: AcroRd32.exe, 00000002.00000000.283263192.000000000BB34000.00000004.00000001.sdmp String found in binary or memory: http://www.xfa.org/schema/xfa-locale-set/2.6/
Source: AcroRd32.exe, 00000002.00000000.256934961.000000000B704000.00000004.00000001.sdmp String found in binary or memory: http://www.xfa.org/schema/xfa-locale-set/2.6/e
Source: AcroRd32.exe, 00000002.00000000.270257827.000000000BE64000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.256934961.000000000B704000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.284840503.000000000BFAC000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.283220249.000000000BABC000.00000004.00000001.sdmp, AcroRd32.exe, 00000002.00000000.283263192.000000000BB34000.00000004.00000001.sdmp String found in binary or memory: http://www.xfa.org/schema/xfa-template/2.6/
Source: AcroRd32.exe, 00000002.00000000.264453316.000000000A406000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/
Source: AcroRd32.exe, 00000002.00000000.264453316.000000000A406000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/
Source: AcroRd32.exe, 00000002.00000000.264453316.000000000A406000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/&
Source: AcroRd32.exe, 00000002.00000000.264453316.000000000A406000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/8
Source: AcroRd32.exe, 00000002.00000000.264453316.000000000A406000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/F
Source: AcroRd32.exe, 00000002.00000000.264453316.000000000A406000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/X
Source: AcroRd32.exe, 00000002.00000000.264453316.000000000A406000.00000004.00000001.sdmp String found in binary or memory: https://idisk.mac.com/
Source: AcroRd32.exe, 00000002.00000000.262531952.00000000089F4000.00000004.00000001.sdmp String found in binary or memory: https://ims-na1.adobelogin.com
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe File created: C:\Users\user\AppData\Local\Temp\acrord32_sbx Jump to behavior
Source: classification engine Classification label: clean0.winPDF@13/54@0/1
Source: unknown Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe' 'C:\Users\user\Desktop\8795156_490162680Email_Correspondence.pdf'
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe' --type=renderer /prefetch:1 'C:\Users\user\Desktop\8795156_490162680Email_Correspondence.pdf'
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --backgroundcolor=16514043
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,49734726695296726,14708380478045234943,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=12528180285023581782 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12528180285023581782 --renderer-client-id=2 --mojo-platform-channel-handle=1724 --allow-no-sandbox-job /prefetch:1
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=gpu-process --field-trial-handle=1692,49734726695296726,14708380478045234943,131072 --disable-features=VizDisplayCompositor --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --lang=en-US --gpu-preferences=KAAAAAAAAACAAwABAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --service-request-channel-token=13295799918542925837 --mojo-platform-channel-handle=1744 --allow-no-sandbox-job --ignored=' --type=renderer ' /prefetch:2
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,49734726695296726,14708380478045234943,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=14045389042154872069 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14045389042154872069 --renderer-client-id=4 --mojo-platform-channel-handle=1840 --allow-no-sandbox-job /prefetch:1
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,49734726695296726,14708380478045234943,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=8578766355593294049 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8578766355593294049 --renderer-client-id=5 --mojo-platform-channel-handle=2112 --allow-no-sandbox-job /prefetch:1
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe' --type=renderer /prefetch:1 'C:\Users\user\Desktop\8795156_490162680Email_Correspondence.pdf' Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --backgroundcolor=16514043 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,49734726695296726,14708380478045234943,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=12528180285023581782 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12528180285023581782 --renderer-client-id=2 --mojo-platform-channel-handle=1724 --allow-no-sandbox-job /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=gpu-process --field-trial-handle=1692,49734726695296726,14708380478045234943,131072 --disable-features=VizDisplayCompositor --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --lang=en-US --gpu-preferences=KAAAAAAAAACAAwABAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --service-request-channel-token=13295799918542925837 --mojo-platform-channel-handle=1744 --allow-no-sandbox-job --ignored=' --type=renderer ' /prefetch:2 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,49734726695296726,14708380478045234943,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=14045389042154872069 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14045389042154872069 --renderer-client-id=4 --mojo-platform-channel-handle=1840 --allow-no-sandbox-job /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,49734726695296726,14708380478045234943,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=8578766355593294049 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8578766355593294049 --renderer-client-id=5 --mojo-platform-channel-handle=2112 --allow-no-sandbox-job /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe File read: C:\Program Files (x86)\desktop.ini Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe File created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeFnt16.lst.6472 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe File opened: C:\Windows\SysWOW64\Msftedit.dll Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: 8795156_490162680Email_Correspondence.pdf Initial sample: PDF keyword /JS count = 0
Source: 8795156_490162680Email_Correspondence.pdf Initial sample: PDF keyword /JavaScript count = 0
Source: A9Rgq07pf_3n1fzb_4zs.tmp.2.dr Initial sample: PDF keyword /JS count = 0
Source: A9Rgq07pf_3n1fzb_4zs.tmp.2.dr Initial sample: PDF keyword /JavaScript count = 0
Source: A9R1vhrw39_3n1fzc_4zs.tmp.2.dr Initial sample: PDF keyword /JS count = 0
Source: A9R1vhrw39_3n1fzc_4zs.tmp.2.dr Initial sample: PDF keyword /JavaScript count = 0
Source: 8795156_490162680Email_Correspondence.pdf Initial sample: PDF keyword /EmbeddedFile count = 0
Source: 8795156_490162680Email_Correspondence.pdf Initial sample: PDF keyword /AcroForm count = 2
Source: 8795156_490162680Email_Correspondence.pdf Initial sample: PDF keyword /ObjStm count = 6
Source: 8795156_490162680Email_Correspondence.pdf Initial sample: PDF keyword stream count = 25
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process information queried: ProcessInformation Jump to behavior
Source: AcroRd32.exe, 00000002.00000000.260995878.0000000004EA0000.00000002.00020000.sdmp Binary or memory string: Shell_TrayWnd
Source: AcroRd32.exe, 00000002.00000000.260995878.0000000004EA0000.00000002.00020000.sdmp Binary or memory string: Progman
Source: AcroRd32.exe, 00000002.00000000.260995878.0000000004EA0000.00000002.00020000.sdmp Binary or memory string: SProgram Managerl
Source: AcroRd32.exe, 00000002.00000000.260995878.0000000004EA0000.00000002.00020000.sdmp Binary or memory string: Shell_TrayWnd,
Source: AcroRd32.exe, 00000002.00000000.260995878.0000000004EA0000.00000002.00020000.sdmp Binary or memory string: Progmanlock
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs