Size | 34.4KB |
---|---|
Type | PDF document, version 1.4, 0 pages |
MD5 | 3d2bd8257dc80fb2beb079d1f8edda8f |
SHA1 | a7504afd65e23cf8402edb57db8cbfe634314bc6 |
SHA256 | 34685e2c0b97660f518bea909c8aa2606c55eafcefa0213a9a694fe4ad5e34ed |
SHA512 |
408560555af1e80af7e966b8f0c8e8e3df86ee015aa713f0156fd0731369016226022d765623d5ce9115d3b3181c3997ce1e5eb5ea0b835f6faa4907e618f665
|
CRC32 | C72F7070 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 8.0 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Dec. 25, 2024, 8:42 p.m. | Dec. 25, 2024, 8:43 p.m. | 56 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2024-12-25 19:42:43,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp2pjrvv 2024-12-25 19:42:43,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\SKzofwuQqXzwnIoOxTigSafpqlb 2024-12-25 19:42:43,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\DnYkCxGYXvXQiKRS 2024-12-25 19:42:43,280 [analyzer] DEBUG: Started auxiliary module Curtain 2024-12-25 19:42:43,280 [analyzer] DEBUG: Started auxiliary module DbgView 2024-12-25 19:42:43,655 [analyzer] DEBUG: Started auxiliary module Disguise 2024-12-25 19:42:43,842 [analyzer] DEBUG: Loaded monitor into process with pid 504 2024-12-25 19:42:43,842 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2024-12-25 19:42:43,842 [analyzer] DEBUG: Started auxiliary module Human 2024-12-25 19:42:43,842 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2024-12-25 19:42:43,842 [analyzer] DEBUG: Started auxiliary module Reboot 2024-12-25 19:42:43,921 [analyzer] DEBUG: Started auxiliary module RecentFiles 2024-12-25 19:42:43,921 [analyzer] DEBUG: Started auxiliary module Screenshots 2024-12-25 19:42:43,921 [analyzer] DEBUG: Started auxiliary module Sysmon 2024-12-25 19:42:43,937 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2024-12-25 19:42:44,046 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\AcroRd32.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\how-to-get-free-robux-please.pdf'] and pid 1944 2024-12-25 19:42:44,217 [analyzer] DEBUG: Loaded monitor into process with pid 1944 2024-12-25 19:42:45,967 [analyzer] INFO: Added new file to list with pid 1944 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin 2024-12-25 19:42:46,203 [analyzer] INFO: Added new file to list with pid 1944 and path C:\Users\Administrator\AppData\Local\Adobe\Color\Profiles\wscRGB.icc 2024-12-25 19:42:46,233 [analyzer] INFO: Added new file to list with pid 1944 and path C:\Users\Administrator\AppData\Local\Adobe\Color\Profiles\wsRGB.icc 2024-12-25 19:42:46,250 [analyzer] INFO: Added new file to list with pid 1944 and path C:\Users\Administrator\AppData\Local\Adobe\Color\ACECache10.lst 2024-12-25 19:43:13,092 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2024-12-25 19:43:13,500 [analyzer] INFO: Terminating remaining processes before shutdown. 2024-12-25 19:43:13,500 [lib.api.process] INFO: Successfully terminated process with pid 1944. 2024-12-25 19:43:13,530 [analyzer] INFO: Analysis completed.
2024-12-25 20:42:49,634 [cuckoo.core.scheduler] INFO: Task #5695861: acquired machine win7x648 (label=win7x648) 2024-12-25 20:42:49,635 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.208 for task #5695861 2024-12-25 20:42:49,925 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 276184 (interface=vboxnet0, host=192.168.168.208) 2024-12-25 20:42:49,959 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x648 2024-12-25 20:42:50,546 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x648 to vmcloak 2024-12-25 20:42:58,355 [cuckoo.core.guest] INFO: Starting analysis #5695861 on guest (id=win7x648, ip=192.168.168.208) 2024-12-25 20:42:59,361 [cuckoo.core.guest] DEBUG: win7x648: not ready yet 2024-12-25 20:43:04,388 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x648, ip=192.168.168.208) 2024-12-25 20:43:04,486 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x648, ip=192.168.168.208, monitor=latest, size=6660546) 2024-12-25 20:43:05,604 [cuckoo.core.resultserver] DEBUG: Task #5695861: live log analysis.log initialized. 2024-12-25 20:43:06,389 [cuckoo.core.resultserver] DEBUG: Task #5695861 is sending a BSON stream 2024-12-25 20:43:06,764 [cuckoo.core.resultserver] DEBUG: Task #5695861 is sending a BSON stream 2024-12-25 20:43:07,690 [cuckoo.core.resultserver] DEBUG: Task #5695861: File upload for 'shots/0001.jpg' 2024-12-25 20:43:07,704 [cuckoo.core.resultserver] DEBUG: Task #5695861 uploaded file length: 133502 2024-12-25 20:43:08,813 [cuckoo.core.resultserver] DEBUG: Task #5695861: File upload for 'shots/0002.jpg' 2024-12-25 20:43:08,827 [cuckoo.core.resultserver] DEBUG: Task #5695861 uploaded file length: 125305 2024-12-25 20:43:09,917 [cuckoo.core.resultserver] DEBUG: Task #5695861: File upload for 'shots/0003.jpg' 2024-12-25 20:43:09,926 [cuckoo.core.resultserver] DEBUG: Task #5695861 uploaded file length: 40233 2024-12-25 20:43:20,253 [cuckoo.core.guest] DEBUG: win7x648: analysis #5695861 still processing 2024-12-25 20:43:35,342 [cuckoo.core.guest] DEBUG: win7x648: analysis #5695861 still processing 2024-12-25 20:43:36,005 [cuckoo.core.resultserver] DEBUG: Task #5695861: File upload for 'curtain/1735152193.38.curtain.log' 2024-12-25 20:43:36,008 [cuckoo.core.resultserver] DEBUG: Task #5695861 uploaded file length: 36 2024-12-25 20:43:36,123 [cuckoo.core.resultserver] DEBUG: Task #5695861: File upload for 'sysmon/1735152193.48.sysmon.xml' 2024-12-25 20:43:36,127 [cuckoo.core.resultserver] DEBUG: Task #5695861 uploaded file length: 125842 2024-12-25 20:43:36,138 [cuckoo.core.resultserver] DEBUG: Task #5695861: File upload for 'files/e1d986bd7937df38_wscrgb.icc' 2024-12-25 20:43:36,143 [cuckoo.core.resultserver] DEBUG: Task #5695861: File upload for 'files/3c404b451100b523_wsrgb.icc' 2024-12-25 20:43:36,145 [cuckoo.core.resultserver] DEBUG: Task #5695861 uploaded file length: 2676 2024-12-25 20:43:36,147 [cuckoo.core.resultserver] DEBUG: Task #5695861 uploaded file length: 66208 2024-12-25 20:43:36,149 [cuckoo.core.resultserver] DEBUG: Task #5695861: File upload for 'files/e4aa4572532fe692_acecache10.lst' 2024-12-25 20:43:36,151 [cuckoo.core.resultserver] DEBUG: Task #5695861 uploaded file length: 1946 2024-12-25 20:43:36,158 [cuckoo.core.resultserver] DEBUG: Task #5695861: File upload for 'files/2cbbfbe12768f624_usercache.bin' 2024-12-25 20:43:36,164 [cuckoo.core.resultserver] DEBUG: Task #5695861 uploaded file length: 69063 2024-12-25 20:43:36,876 [cuckoo.core.resultserver] DEBUG: Task #5695861: File upload for 'shots/0004.jpg' 2024-12-25 20:43:36,898 [cuckoo.core.resultserver] DEBUG: Task #5695861 uploaded file length: 133498 2024-12-25 20:43:36,910 [cuckoo.core.resultserver] DEBUG: Task #5695861 had connection reset for <Context for LOG> 2024-12-25 20:43:38,371 [cuckoo.core.guest] INFO: win7x648: analysis completed successfully 2024-12-25 20:43:38,384 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2024-12-25 20:43:38,410 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2024-12-25 20:43:39,018 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x648 to path /srv/cuckoo/cwd/storage/analyses/5695861/memory.dmp 2024-12-25 20:43:39,020 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x648 2024-12-25 20:43:46,200 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.208 for task #5695861 2024-12-25 20:43:46,479 [cuckoo.core.scheduler] DEBUG: Released database task #5695861 2024-12-25 20:43:46,498 [cuckoo.core.scheduler] INFO: Task #5695861: analysis procedure completed
description | (no description) | rule | invalid_trailer_structure | ||||||
description | The first entry in a cross-reference table is always free and has a generation number of 65,535 | rule | invalid_xref_numbers |
G Data Antivirus (Windows) | Virus: PDF.Trojan-Stealer.Phish.HW (Engine B) |
Windows Defender (Windows) | Trojan:PDF/Phish.CFN!MTB |
Forticlient (Linux) | PDF/Phishing.0931!tr |
McAfee CLI scanner (Linux) | PDF/Phish-TWM |
DrWeb Antivirus (Linux) | PDF.Phisher.296 |
Trend Micro SProtect (Linux) | Trojan.PDF.PHISH.SMTPTMAG |