Analysis
-
max time kernel
119s -
max time network
121s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 14:34
Behavioral task
behavioral1
Sample
BZV_Werdenberg_Sommerbehandlung24_Seite1-2.pdf
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
BZV_Werdenberg_Sommerbehandlung24_Seite1-2.pdf
Resource
win10v2004-20240508-en
General
-
Target
BZV_Werdenberg_Sommerbehandlung24_Seite1-2.pdf
-
Size
398KB
-
MD5
bea4f4ec3a3aee232662966de338e459
-
SHA1
09eb5c4be64bec5bc308daa3563f3f67c7783332
-
SHA256
e081daeff57b0b37d611eeb9a040df295bd90fcd193058baaaa1dc114c50252b
-
SHA512
8d84c4b68adf97b5b378149728ab4de6ccfdc827e08ec1603b86ece8cf73fefdf5961962bf50f003e9cfdec1eb551fabb3621cd7851f409691ecefb26991695c
-
SSDEEP
12288:5hWnLMR9wdFyQdt8LmC5ZfitzCzaF3vAKu1I0NApOR6bJLNXBvgbHHZQCAlGAX:mnoRuyQjAmC5ZfKzCzaF3vAKu1I0NApv
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 1960 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 4 IoCs
Processes:
AcroRd32.exepid process 1960 AcroRd32.exe 1960 AcroRd32.exe 1960 AcroRd32.exe 1960 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\BZV_Werdenberg_Sommerbehandlung24_Seite1-2.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD595b70c00da76186b757131d22fd436f0
SHA1b4625e41c74f1217d6121f002f85a7c6188da4b6
SHA2562f07d5196ab08070031d0a94459ac91c93a99f077ad451242c45bafb9741a3d5
SHA5129ad39a47e64b1d8fde081e294a52a8f44021428efc574ba8c59dd7fe156f253589b8d92cf06b23022b47d13075bb3ef45cf8265bc1450bf6870f6e79953a5164