Sample: 28238ef968e7ee2b976c38a08f2ef574

Note: if you are new to ThreatMiner, check out the how-to page to find out how you can get the most out of this portal.

Metadata
File name:Cover letter of BfArM.pdf
File type:PDF document, version 1.5
File size:69650 bytes
Analysis date:2016-11-07 06:50:10
MD5:28238ef968e7ee2b976c38a08f2ef574
SHA1:1f7b7d049c3c2e763e0cef59ea0ec4150bf4fb08
SHA256:93cb4dc68c16b1d87ea057b3db11a4b321cb4f6dd9825e0bd10ba199c7fee795
SHA512:339453eb1002c6ace472cb0b84c8eeeee39a085d4f709c43b2a85c03d4bd0db8f9df681303b198388b0427f82926cb04c771b40377507c9af53e3d9e991f2076
SSDEEP:1536:qAWUvxjZdihSWcZXrPL8sMkufqc4MMqX72nETJ4Ex7B:qlUNOIvPh3ufYMMqCnYfj
IMPHASH:N/A
Authentihash:N/A
Related resources
APTNotes
Cyber threat intelligence reports associated with 28238ef968e7ee2b976c38a08f2ef574.
Loading...
Domains
Domains the malware sample communicates with.
Hosts
Hosts the malware sample communicates with.
HTTP Requests
HTTP requests the malware sample makes.
AV Detections
AV detection names associated with the malware sample.
Mutants
Mutants created by the malware sample.
Registry keys
Registry keys created by the malware sample.
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\9.0\Security
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\ORO
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\IMM
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\SystemShared
HKEY_LOCAL_MACHINE\System
HKEY_LOCAL_MACHINE\System\Acrobatviewercpp304
HKEY_LOCAL_MACHINE\Software\Adobe
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Installer\Migrated
HKEY_LOCAL_MACHINE\Software\Adobe\Repair\Acrobat Reader\9.0\IOD
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Language\current
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Installer
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1547161642-507921405-839522115-1004\Installer\Products\68AB67CA7DA73301B7449A0400000010
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Installer\Products\68AB67CA7DA73301B7449A0400000010
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\68AB67CA7DA73301B7449A0400000010
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA73301B7449A0400000010\InstallProperties
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\9.0\Installer\Migrated
HKEY_CURRENT_USER\Software\Adobe\Acrobat Distiller\9.0\Installer\Migrated
HKEY_CURRENT_USER\Software\Adobe\Acrobat Elements\9.0\Installer\Migrated
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Installer\Migrate
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Language\path
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Language\path
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Language\select
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Language\next
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Language\next
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Language\UseMUI
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AdobeViewer
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVGeneral
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\SDI
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Originals
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVPrivate
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Private
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Private
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Hotfix
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Hotfix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVGeneral
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\AcroRd32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{475c7950-e3d2-11e0-8d7a-806d6172696f}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{475c7952-e3d2-11e0-8d7a-806d6172696f}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{475c7952-e3d2-11e0-8d7a-806d6172696f}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{475c7950-e3d2-11e0-8d7a-806d6172696f}\
HKEY_CLASSES_ROOT\Directory
HKEY_CLASSES_ROOT\Directory\CurVer
HKEY_CLASSES_ROOT\Directory\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CLASSES_ROOT\Directory\\ShellEx\IconHandler
HKEY_CLASSES_ROOT\Directory\\Clsid
HKEY_CLASSES_ROOT\Folder
HKEY_CLASSES_ROOT\Folder\Clsid
HKEY_CLASSES_ROOT\CLSID
HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Type 1 Installer\Type 1 Fonts
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVConversionToPDF
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVConversionToPDF
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVConversionFromPDF
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVConversionFromPDF
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Language\current
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Intl
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVPrivate
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Intl
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RIF
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\RIF
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Selection
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Selection
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\9.0\FeatureLockdown
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\9.0\FeatureLockdown\cDefaultExecMenuItems
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\9.0\FeatureLockdown\cDefaultLaunchAttachmentPerms
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\9.0\FeatureLockdown\cDefaultLaunchURLPerms
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Originals
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVDisplay
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVDisplay
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
HKEY_CLASSES_ROOT\AppID\AcroRd32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ComputerName
ActiveComputerName
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Workflows
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Workflows
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\SDI
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Annots
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Annots
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVAlert
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVAlert
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\9.0
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\9.0\DiskCabs
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Collab
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Collab
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVTracker
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVTracker
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\TaskButtons
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\TaskButtons
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AutoSaveDocs
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AutoSaveDocs
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AdobeViewer
HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\9.0
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\9.1024\AVPrivate
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Preview
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Preview
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Access
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Access
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\LayoutAndZoom
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\LayoutAndZoom
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\General
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\General
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\NoTimeOut
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\NoTimeOut
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\RememberedViews
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004_Classes
HKEY_LOCAL_MACHINE\Software\Classes
\REGISTRY\USER
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}
CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\TreatAs
\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}
\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocServer32
\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocServerX86
\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\LocalServer32
\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocHandler32
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\MeasuringGeo
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\MeasuringGeo
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\UsageMeasurement
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\UsageMeasurement
HKEY_CURRENT_USER\Software\Adobe\CommonFiles\Usage\Reader 9
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Updater
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Updater
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_LOCAL_MACHINE\System\WSZXSGANXFJVAYSXYQGNXKQY
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe ARM\1.0\ARM
Comments
User comments about 28238ef968e7ee2b976c38a08f2ef574.
NOTICE: We have updated our privacy terms and conditions in accordance to GDPR. By using our site, you acknowledge that you have read and understand our Privacy Policy. Your use of ThreatMiner’s Products and Services is subject to these policies and terms.