top title background image
flash

Send-Data-City_Center_Waco_Project_Report-_#9073955_942 (1).pdf

Status: finished
Submission Time: 2021-02-25 21:21:40 +01:00
Suspicious

Comments

Tags

Details

  • Analysis ID:
    358572
  • API (Web) ID:
    619150
  • Analysis Started:
    2021-02-25 21:21:41 +01:00
  • Analysis Finished:
    2021-02-25 21:28:31 +01:00
  • MD5:
    dbfaf169fa1ba4c2a4f321a57d06a9af
  • SHA1:
    49602a3acf1bf4199e940fa7c2d6435e900b431c
  • SHA256:
    5a53c07a8d9d58bdc22bc1ebae72d1a20d63803ffec3b28b667640928c45bd54
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
suspicious
Score: 22
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
80.0.0.0
United Kingdom
209.95.50.27
United States

Domains

Name IP Detection
lb.joomag.com
209.95.50.27
joom.ag
209.95.50.27
www.joomag.com
0.0.0.0
Click to see the 4 hidden entries
use.typekit.net
0.0.0.0
p.typekit.net
0.0.0.0
js-agent.newrelic.com
0.0.0.0
bam-cell.nr-data.net
0.0.0.0

URLs

Name Detection
https://joom.ag/9JYI
http://cipa.jp/exif/1.0/_1
https://joom.agt
Click to see the 61 hidden entries
https://p.typekit.net/p.gif
https://use.typekit.net/af/1eef01/0000000000000000000148ac/23/
https://use.typekit.net/af/3d81f6/0000000000000000000148a2/23/
https://joom.ag/ZJYI)
https://joom.ag1)
http://www.dynaforms.com
https://joom.ag/9JYIRoot
https://use.typekit.net/af/bc719c/00000000000000000001499c/23/
https://www.pdfescape.com)/CreationDate(D:20210222193218
https://www.radpdf.com)/Creator(PDFescape
https://use.typekit.net/af/42fca5/0000000000000000000148a4/23/
http://www.aiim.org/pdfe/ns/id/
http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/
http://www.osmf.org/layout/anchor
http://iptc.org/std/Iptc4xmpExt/2008-02-29/
http://www.youtube.com/
https://joom.ag
http://typekit.com/eulas/0000000000000000000148ac
http://www.aiim.org/pdfa/ns/field#
http://www.osmf.org/layout/padding%http://www.osmf.org/layout/attributes
http://www.wikipedia.com/
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/y
http://typekit.com/eulas/00000000000000000001499c
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/
http://www.live.com/
http://www.quicktime.com.Acrobat
https://ims-na1.adobelogin.com
https://www.radpdf.com
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/p
https://api.echosign.com
http://www.aiim.org/pdfa/ns/schema#
https://www.pdfescape.com8g~_)
http://www.osmf.org/region/target#http://www.osmf.org/layout/renderer#http://www.osmf.org/layout/abs
http://typekit.com/eulas/0000000000000000000148a0
https://joom.ag/9JYI)
http://www.aiim.org/pdfe/ns/id/(2
http://www.amazon.com/
http://cipa.jp/exif/1.0/
http://www.osmf.org/default/1.0%http://www.osmf.org/mediatype/default
http://www.twitter.com/
http://typekit.com/eulas/0000000000000000000148a6
http://typekit.com/eulas/0000000000000000000148a4
http://typekit.com/eulas/0000000000000000000148a2
http://www.aiim.org/pdfa/ns/type#
https://use.typekit.net/af/e0b8be/0000000000000000000148a6/23/
https://www.pdfescape.com
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/
http://www.npes.org/pdfx/ns/id/
http://www.osmf.org/drm/default
https://use.typekit.net/af/3ba24d/0000000000000000000148a0/23/
http://www.osmf.org/elementId%http://www.osmf.org/temporal/embedded$http://www.osmf.org/temporal/dyn
https://joom.ag/9JYI
http://www.aiim.org/pdfa/ns/extension/
http://cipa.jp/exif/1.0/1.0/l4XRg
http://www.aiim.org/pdfa/ns/type#R
http://www.reddit.com/
http://www.osmf.org/subclip/1.0
http://www.aiim.org/pdfa/ns/property#
http://ns.useplus.org/ldf/xmp/1.0/
http://www.nytimes.com/
http://www.aiim.org/pdfa/ns/id/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{51AA8481-77A7-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
Click to see the 75 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{51AA8484-77A7-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{51AA8483-77A7-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\E5F0NRSV\joom[1].xml
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache.bin
data
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\Cache\AdobeFnt16.lst.7148
PostScript document text
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeFnt16.lst.7148
PostScript document text
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
data
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages
SQLite 3.x database, last written using SQLite version 3024000
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-210225202231Z-228.bmp
PC bitmap, Windows 3.x format, 164 x -126 x 32
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Visited Links
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\d[2]
Web Open Font Format, TrueType, length 55916, version 0.0
#
C:\Users\user\AppData\Local\Temp\~DFE5BD3A345DA22996.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFC49E28F8A7C615D6.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF5B4354179DD05C79.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\nr-1198.min[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\limitedAccessPages[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\fonts[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\d[5]
Web Open Font Format, TrueType, length 61612, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\d[4]
Web Open Font Format, TrueType, length 60240, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\d[3]
Web Open Font Format, TrueType, length 59940, version 0.0
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\temp-index
Maple help database
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\d[1]
Web Open Font Format, TrueType, length 58272, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\joomag.responsive[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\e2270d116b[1].js
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\cross[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\p[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\olb8zpk[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\d[1]
Web Open Font Format, TrueType, length 61728, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\560e9c8bff5008d8_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\91cec06bb2836fa5_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8e417e79df3bf0e9_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c84d92a9dbce3e0_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c159cc5880890bc_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\86b8040b7132b608_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\71febec55d5c75cd_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\7120c35b509b0fae_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6fb6d030c4ebbc21_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\56c4cd218555ae2b_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\927a1596c37ebe5e_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\3a4ae3940784292a_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2798067b152b83c7_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\230e5fe3e6f82b2c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0f25049d69125b1e_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0ace9ee3d914a5c0_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0998db3a32ab3f41_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d449e58cb15daaf1_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\febb41df4ea2b63a_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fdd733564de6fbcb_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fd17b2d8331c91e8_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f971b7eda7fa05c3_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f941376b2efdd6e6_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f4a0d4ca2f3b95da_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f0cf6dfa8a1afa3d_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\de789e80edd740d6_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d88192ac53852604_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\05349744be1ad4ad_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\cf3e34002cde7e9c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bf0ac66ae1eb4a7f_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\b6d5deb4812ac6e9_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\aba6710fde0876af_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\983b7a3da8f39a46_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\946896ee27df7947_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\92c56fa2a6c4d5ba_0
data
#