acrobatprodc_00000000000000000000000409.exe

Adobe Acrobat Installer

Adobe Systems, Incorporated

This is a setup and installation application. The file has been seen being downloaded from dl-mail.ymail.com and multiple other hosts.
Publisher:
Adobe  (signed by Adobe Systems, Incorporated)

Product:
Adobe Acrobat Installer

Version:
3.6.1.4

MD5:
d0988db7e4e23cf05a9ed4f5597feee0

SHA-1:
b188ff33a0827fb2061240d42d7a642dce478399

SHA-256:
830aeeddb007cf2e42371f467f8c4ed4e67586f27ac9148e85f5a7be675db26e

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/23/2024 10:06:03 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Detection.Undefined
7.0.302.0

File size:
2 MB (2,072,160 bytes)

Product version:
1.5.0.5

Copyright:
Copyright © Adobe Systems Incorporated

Original file name:
host.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\acrobatprodc_00000000000000000000000409.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/3/2015 6:00:00 PM

Valid to:
5/7/2017 5:59:59 PM

Subject:
CN="Adobe Systems, Incorporated", OU=Acrobat XI, O="Adobe Systems, Incorporated", L=San Jose, S=California, C=US, SERIALNUMBER=2748129, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6CF9CF47C58EBF93623DCBB2BF3B55F7

File PE Metadata
Compilation timestamp:
2/19/2014 7:56:38 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:UI4LHKGY/6VbH2ubVUmGdtZpuPWoMNsv4e5+4:6LHxYyRH5bVhGdTpuPWoCswe

Entry address:
0x6488D

Entry point:
E8, 8A, 4F, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 98, AD, 48, 00, E8, 8D, 4D, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, 80, 74, 49, 00, 03, 75, 43, 6A, 04, E8, 74, 51, 00, 00, 59, 83, 65, FC, 00, 56, E8, 9C, 51, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, BD, 51, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, 60, 50, 00, 00, 59, C3, 56, 6A, 00, FF, 35, 94, 22, 49, 00, FF, 15, 3C, A1, 47, 00, 85, C0, 75, 16, E8, ED, 2B, 00...
 
[+]

Entropy:
7.3171

Code size:
481 KB (492,544 bytes)

The file acrobatprodc_00000000000000000000000409.exe has been seen being distributed by the following 28 URLs.

https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjJ-d7BGQ2UxyAA-BvTeGMPuOBr5i8o3m2zGVEgo52r86RQLs2FyITvzkB46TIHecrW_UWhjIv2uHVC2R0Wv8Q9VgQ/messages/@.id==AFeti2IAABzVVe2ynQ3a4H4VukE/content/parts/@.id==2/raw?appid=YahooMailNeo&token=zitEzqOML3j84e6ealFTT5U7-km5qEQF52lp7AcCuBZ7vUEMEUnn167X2Xhnt0SR7WZfWbmyXID5AF-PYps2SBh-J5C6LyUnkpuuSevalNc&error=https://us-mg6.mail.yahoo.com/.../iframemsg?id=9890fe13-11ba-d829-adf4-eb9da8122174&ymreqid=2583ca1b-5e3b-dea5-01d3-d100e1010000

about:internet

http://www.logitheque.com/.../c5ffffba.dl

temp:ARISE INVOICE (1).exe