Analysis

  • max time kernel
    117s
  • max time network
    118s
  • platform
    windows7_x64
  • resource
    win7-20240220-en
  • resource tags

    arch:x64arch:x86image:win7-20240220-enlocale:en-usos:windows7-x64system
  • submitted
    30-06-2024 19:18

General

  • Target

    GYG_Terms_Conditions_de-DE.pdf

  • Size

    280KB

  • MD5

    c275d67ddf2370f7c0219e1ef7a460c4

  • SHA1

    f1d4b2019673587d233799685f39233821fa7c7a

  • SHA256

    2024dd11c9516cc49594a544b300ec4392bf0806153f5917e59bc3000f6b61f3

  • SHA512

    7f1683bfef89840a510f56d07c62e4f80c93f282cf6aed67553b95269d2e3046e4e86b93cfeee979b5133f4b65c00f7a1f0d4d1a0d9e23b7614268eb6870aeaa

  • SSDEEP

    3072:83+VOFzrP1iuuYEhwsPzeXcVkqxrBBBBBBBv/hg2JDbIL1H:8+8FMrhwwoKk

Score
1/10

Malware Config

Signatures

  • Suspicious behavior: GetForegroundWindowSpam 1 IoCs
  • Suspicious use of SetWindowsHookEx 3 IoCs

Processes

  • C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
    "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\GYG_Terms_Conditions_de-DE.pdf"
    1⤵
    • Suspicious behavior: GetForegroundWindowSpam
    • Suspicious use of SetWindowsHookEx
    PID:2252

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents
    Filesize

    3KB

    MD5

    9b4c5e3fcdbcffd0c5a2171fef096b24

    SHA1

    4bf5ba62732217c00035ea599b715eb4888a615f

    SHA256

    62c73d54bb4119d16a2364673283a96bcb1e453a36d72f293921e8c47748e82e

    SHA512

    3da00dae8f694a89382117737e13d85f6c3461028cd4c25ff333a7700349120cb372c0b445917cef8cfda42f411d54e93a498bb15f41ad971d2efae8450dd1ad