download:

PDFConverter_P2W147-zx-1097.exe

Full analysis: https://app.any.run/tasks/64727b7c-e86e-4b4e-98ab-8e318f06074c
Verdict: Malicious activity
Analysis date: August 11, 2020, 23:46:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4D47CAB1884F7EFF79FE1E911E706D93

SHA1:

05E2ECF75FFF54CA8643E21FE76D101A7DE2D55D

SHA256:

084681F6053B458C2E805F98987E1D75C3274956E0E0D5F76F0F0F4F52F27AD8

SSDEEP:

24576:JiRpPXDOBXjADe8nNExekun1/VItx2POTZyC70QDyyex0HIx/AXhpIpNKe:OXDk8Dwxe1tuv2PKZz70QWrx0HIsopNR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • PDFConverter_P2W147-zx-1097.exe (PID: 2384)
      • pdfctools.exe (PID: 2488)
    • Connects to CnC server

      • PDFConverter_P2W147-zx-1097.exe (PID: 2384)
    • Loads dropped or rewritten executable

      • pdf2word.exe (PID: 2752)
      • regsvr32.exe (PID: 3752)
      • regsvr32.exe (PID: 3176)
    • Application was dropped or rewritten from another process

      • pdfctools.exe (PID: 2488)
      • pdf2word.exe (PID: 2752)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PDFConverter_P2W147-zx-1097.exe (PID: 2384)
      • pdf2word.exe (PID: 2752)
    • Creates files in the user directory

      • pdf2word.exe (PID: 2752)
      • PDFConverter_P2W147-zx-1097.exe (PID: 2384)
    • Creates a software uninstall entry

      • PDFConverter_P2W147-zx-1097.exe (PID: 2384)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 3752)
      • regsvr32.exe (PID: 3176)
    • Changes IE settings (feature browser emulation)

      • pdf2word.exe (PID: 2752)
    • Executed via COM

      • DllHost.exe (PID: 3752)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (18)
.exe | Win32 Executable (generic) (2.9)
.exe | Generic Win/DOS Executable (1.3)
.exe | DOS Executable Generic (1.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:07:11 05:10:05+02:00
PEType: PE32
LinkerVersion: 14
CodeSize: 872960
InitializedDataSize: 1188352
UninitializedDataSize: -
EntryPoint: 0xa35d8
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2020.711.1109.54
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: Shanghai Shaji Network Technology Co., Ltd
FileDescription: 风云PDF转换器-安装程序
FileVersion: 1.1.0.1
InternalName: setup.exe
LegalCopyright: Copyright (C) 2020 Shanghai Shaji Network Technology Co., Ltd
OriginalFileName: setup.exe
ProductName: 风云PDF转换器
ProductVersion: 1.0.0.1

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 11-Jul-2020 03:10:05
Detected languages:
  • Chinese - PRC
  • English - United States
Debug artifacts:
  • D:\去秀网络\VS\SetupDui\bin\setup_ff.pdb
CompanyName: Shanghai Shaji Network Technology Co., Ltd
FileDescription: 风云PDF转换器-安装程序
FileVersion: 1.1.0.1
InternalName: setup.exe
LegalCopyright: Copyright (C) 2020 Shanghai Shaji Network Technology Co., Ltd
OriginalFilename: setup.exe
ProductName: 风云PDF转换器
ProductVersion: 1.0.0.1

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000138

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 7
Time date stamp: 11-Jul-2020 03:10:05
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x000D5027
0x000D5200
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.57225
.rdata
0x000D7000
0x0002FF4A
0x00030000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.40595
.data
0x00107000
0x00003BE0
0x00002400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.27124
.gfids
0x0010B000
0x000001D0
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.47863
.tls
0x0010C000
0x00000009
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.0203931
.rsrc
0x0010D000
0x000E2960
0x000E2A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.54572
.reloc
0x001F0000
0x0000B7CC
0x0000B800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.56769

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.06216
651
UNKNOWN
English - United States
RT_MANIFEST
2
3.58125
67624
UNKNOWN
Chinese - PRC
RT_ICON
3
3.7309
38056
UNKNOWN
Chinese - PRC
RT_ICON
4
3.82968
21640
UNKNOWN
Chinese - PRC
RT_ICON
5
3.90545
16936
UNKNOWN
Chinese - PRC
RT_ICON
6
4.04814
9640
UNKNOWN
Chinese - PRC
RT_ICON
7
1.90494
64
UNKNOWN
Chinese - PRC
RT_STRING
8
4.33496
2440
UNKNOWN
Chinese - PRC
RT_ICON
9
4.73087
1128
UNKNOWN
Chinese - PRC
RT_ICON
103
3.26314
288
UNKNOWN
Chinese - PRC
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
IMM32.dll
KERNEL32.dll
OLEAUT32.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
VERSION.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
7
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start pdfconverter_p2w147-zx-1097.exe pdfctools.exe no specs regsvr32.exe no specs regsvr32.exe no specs pdf2word.exe Shell Security Editor no specs pdfconverter_p2w147-zx-1097.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2384"C:\Users\admin\AppData\Local\Temp\PDFConverter_P2W147-zx-1097.exe" C:\Users\admin\AppData\Local\Temp\PDFConverter_P2W147-zx-1097.exe
explorer.exe
User:
admin
Company:
Shanghai Shaji Network Technology Co., Ltd
Integrity Level:
HIGH
Description:
风云PDF转换器-安装程序
Exit code:
0
Version:
1.1.0.1
Modules
Images
c:\users\admin\appdata\local\temp\pdfconverter_p2w147-zx-1097.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2488"C:\Users\admin\AppData\Roaming\fypdfconvert\pdfctools.exe" regdll=C:\Users\admin\AppData\Roaming\fypdfconvert\pdfconvectMenu.dllC:\Users\admin\AppData\Roaming\fypdfconvert\pdfctools.exePDFConverter_P2W147-zx-1097.exe
User:
admin
Company:
Shanghai Shaji Network Technology Co., Ltd
Integrity Level:
HIGH
Description:
PDF转换器工具程序
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\roaming\fypdfconvert\pdfctools.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2752C:\Users\admin\AppData\Roaming\fypdfconvert\pdf2word.exeC:\Users\admin\AppData\Roaming\fypdfconvert\pdf2word.exe
PDFConverter_P2W147-zx-1097.exe
User:
admin
Company:
Shanghai Shaji Network Technology
Integrity Level:
MEDIUM
Description:
风云PDF转换器
Exit code:
0
Version:
2019.11.11.1
Modules
Images
c:\users\admin\appdata\roaming\fypdfconvert\pdf2word.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
3044"C:\Users\admin\AppData\Local\Temp\PDFConverter_P2W147-zx-1097.exe" C:\Users\admin\AppData\Local\Temp\PDFConverter_P2W147-zx-1097.exeexplorer.exe
User:
admin
Company:
Shanghai Shaji Network Technology Co., Ltd
Integrity Level:
MEDIUM
Description:
风云PDF转换器-安装程序
Exit code:
3221226540
Version:
1.1.0.1
Modules
Images
c:\users\admin\appdata\local\temp\pdfconverter_p2w147-zx-1097.exe
c:\systemroot\system32\ntdll.dll
3176"C:\Windows\system32\regsvr32.exe" /s C:\Users\admin\AppData\Roaming\fypdfconvert\Rtf\beconv.dllC:\Windows\system32\regsvr32.exePDFConverter_P2W147-zx-1097.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3752C:\Windows\system32\DllHost.exe /Processid:{4D111E08-CBF7-4F12-A926-2C7920AF52FC}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\users\admin\appdata\roaming\fypdfconvert\pdfconvectmenu.dll
c:\windows\system32\msctf.dll
c:\windows\system32\regsvr32.exe
c:\windows\system32\wininet.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\devobj.dll
c:\windows\system32\setupapi.dll
3752"C:\Windows\system32\regsvr32.exe" /s "C:\Users\admin\AppData\Roaming\fypdfconvert\pdfconvectMenu.dll"C:\Windows\system32\regsvr32.exepdfctools.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 654
Read events
1 248
Write events
405
Delete events
1

Modification events

(PID) Process:(3176) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5364FF97-FC20-49C4-87D1-EF1393AF1494}
Operation:writeName:(default)
Value:
EasyConverter
(PID) Process:(3176) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\EasyConverter.DLL
Operation:writeName:AppID
Value:
{5364FF97-FC20-49C4-87D1-EF1393AF1494}
(PID) Process:(3176) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EasyConverter.PDF2Excel.5
Operation:writeName:(default)
Value:
PDF2Excel Class
(PID) Process:(3176) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EasyConverter.PDF2Excel.5\CLSID
Operation:writeName:(default)
Value:
{B7065CBD-0F57-4E69-8C6B-6FE692752652}
(PID) Process:(3176) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EasyConverter.PDF2Excel
Operation:writeName:(default)
Value:
PDF2Excel Class
(PID) Process:(3176) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EasyConverter.PDF2Excel\CLSID
Operation:writeName:(default)
Value:
{B7065CBD-0F57-4E69-8C6B-6FE692752652}
(PID) Process:(3176) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EasyConverter.PDF2Excel\CurVer
Operation:writeName:(default)
Value:
EasyConverter.PDF2Excel.5
(PID) Process:(3176) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7065CBD-0F57-4E69-8C6B-6FE692752652}
Operation:writeName:(default)
Value:
PDF2Excel Class
(PID) Process:(3176) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7065CBD-0F57-4E69-8C6B-6FE692752652}\ProgID
Operation:writeName:(default)
Value:
EasyConverter.PDF2Excel.5
(PID) Process:(3176) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7065CBD-0F57-4E69-8C6B-6FE692752652}\VersionIndependentProgID
Operation:writeName:(default)
Value:
EasyConverter.PDF2Excel
Executable files
47
Suspicious files
1
Text files
13
Unknown types
127

Dropped files

PID
Process
Filename
Type
2384PDFConverter_P2W147-zx-1097.exeC:\Users\admin\AppData\Roaming\fypdfconvert\Aspose.PDF.dll
MD5:
SHA256:
2384PDFConverter_P2W147-zx-1097.exeC:\Users\admin\AppData\Roaming\fypdfconvert\Aspose.Cells.dllexecutable
MD5:961D921477F476EF62F54BD12E6C5E4D
SHA256:E3365974381B3D130A97F6E26133FBF559576C8D6F7F1793DA08C7532FD1BA0F
2384PDFConverter_P2W147-zx-1097.exeC:\Users\admin\AppData\Roaming\fypdfconvert\Aspose.Slides.dllexecutable
MD5:B53D94B69CEC2878D07CCC897A323D1B
SHA256:56C75D327AFEE86CF21AC8B32DF419D5F5B6E00CBEFD80557B6A4552D200C1FB
2384PDFConverter_P2W147-zx-1097.exeC:\Users\admin\AppData\Roaming\fypdfconvert\Common\easyConverterLoader-jacob.jarjava
MD5:B3E760C5A8CA15E70DA4DA934866DCEF
SHA256:669B0111EF443A15ACAC4D6D8EECF65CFCB3A87BC66CED88117823ED433F7B95
2384PDFConverter_P2W147-zx-1097.exeC:\Users\admin\AppData\Roaming\fypdfconvert\Common\easyConverterExcel.jarjava
MD5:8A932136DD09D216CD41450D668CCF72
SHA256:016C60A762619E173E37897B4495A8615EF96A98E1CD06CAE73A87E7DD744C22
2384PDFConverter_P2W147-zx-1097.exeC:\Users\admin\AppData\Roaming\fypdfconvert\Common\easyConverterHTML.jarjava
MD5:DD859C514BD1449C2EFB0BAD873640F5
SHA256:95C914DCC138C4D5B8AA19DABB394090CD0F8CE8D800FD515FDCAACDA303A1CF
2384PDFConverter_P2W147-zx-1097.exeC:\Users\admin\AppData\Roaming\fypdfconvert\Common\pdf2image.dllexecutable
MD5:9FA651EC8A26B9ABC6CBF743F50D2C7B
SHA256:35BD1BFD861977303FEC412D8410DC14EFB25DBE4E838F5D056FD6DF4AA6E6C1
2384PDFConverter_P2W147-zx-1097.exeC:\Users\admin\AppData\Roaming\fypdfconvert\Common\easyConverterWord.jarjava
MD5:2AFD0D635373711D276E12063C87580A
SHA256:0D749AC690E528CFC1AE587084FB21B1B16685B7036CBD0173FF3DA5050FAEF8
2384PDFConverter_P2W147-zx-1097.exeC:\Users\admin\AppData\Roaming\fypdfconvert\Common\jacob.jarjava
MD5:4F7EC303B1431D49175F2B52FC5A60E5
SHA256:CB39349FBDD6EFBC7D929CBA0D187E07436A10AC6D874B54AC4B802FD35F4209
2384PDFConverter_P2W147-zx-1097.exeC:\Users\admin\AppData\Roaming\fypdfconvert\Common\easyConverter.rscbinary
MD5:E35A8666ADBA3314A493F675E5B9A529
SHA256:29BAEF711D442C402C1FE5F2AEF755988C0267F651EC3C5748D4B0506E819E94
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
6
DNS requests
3
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2384
PDFConverter_P2W147-zx-1097.exe
GET
301
62.234.146.167:80
http://fufei.ahhxwavi.cn/api/soft/download-info/pdf/1/2020071111
CN
malicious
2384
PDFConverter_P2W147-zx-1097.exe
POST
200
192.144.196.87:80
http://log.ahhxwavi.cn/api/data/sync
CN
text
47 b
malicious
2384
PDFConverter_P2W147-zx-1097.exe
GET
200
220.194.223.87:80
http://softdl.ahhxwavi.cn/package/pdfconvert/package.zip
CN
compressed
66.6 Mb
malicious
2752
pdf2word.exe
GET
200
62.234.146.167:80
http://fufei.ahhxwavi.cn/api/soft/pc-update?soft=pdf&pos=p2w147-zx-1097&ver=20200711&uid=pdf
CN
text
3.93 Kb
malicious
2752
pdf2word.exe
GET
200
62.234.146.167:80
http://fufei.ahhxwavi.cn/api/plan/list?soft=pdf&retall=1&uid=pdf
CN
text
4.30 Kb
malicious
2384
PDFConverter_P2W147-zx-1097.exe
POST
200
192.144.196.87:80
http://log.ahhxwavi.cn/api/data/sync
CN
text
47 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2384
PDFConverter_P2W147-zx-1097.exe
192.144.196.87:80
log.ahhxwavi.cn
CN
malicious
2384
PDFConverter_P2W147-zx-1097.exe
62.234.146.167:80
fufei.ahhxwavi.cn
CN
unknown
2384
PDFConverter_P2W147-zx-1097.exe
220.194.223.87:80
softdl.ahhxwavi.cn
CHINA UNICOM China169 Backbone
CN
malicious
2752
pdf2word.exe
62.234.146.167:80
fufei.ahhxwavi.cn
CN
unknown

DNS requests

Domain
IP
Reputation
log.ahhxwavi.cn
  • 192.144.196.87
malicious
fufei.ahhxwavi.cn
  • 62.234.146.167
malicious
softdl.ahhxwavi.cn
  • 220.194.223.87
  • 218.11.11.245
  • 221.204.166.81
  • 123.6.33.60
  • 218.11.11.191
  • 27.221.54.246
  • 42.56.79.189
  • 218.11.11.246
  • 221.204.166.20
  • 220.194.87.190
  • 113.1.0.98
  • 220.194.223.71
  • 221.204.166.24
  • 113.1.0.63
malicious

Threats

Found threats are available for the paid subscriptions
2 ETPRO signatures available at the full report
Process
Message
pdf2word.exe
scrt_initialize_thread_safe_statics