File name:

PDFArchitect9Installer.exe

Full analysis: https://app.any.run/tasks/bf07b8e5-fbe3-47d9-b33d-39caa3482e06
Verdict: Malicious activity
Analysis date: November 22, 2024, 11:30:19
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

2C0BF69241486DA37E3E6984894CA574

SHA1:

9374964DDBCE0E79CC36425135C96530FB30940A

SHA256:

0C51E35F7DB0E801022FE897BC1D9CEB2C73A1DC93557F9538330E026DDF9A4D

SSDEEP:

98304:BTchf5Ss0QdblUI713UijtKdffqeVkxKGfV7EMU7GxtsOyEGwEDtvVCML9TOzNiq:i3t5ir8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • PDFArchitect9Installer.exe (PID: 4308)
    • Checks Windows Trust Settings

      • PDFArchitect9Installer.exe (PID: 4308)
    • Executable content was dropped or overwritten

      • PDFArchitect9Installer.exe (PID: 4308)
      • spoolsv.exe (PID: 5300)
      • printer-installer-app.exe (PID: 7108)
    • Starts itself from another location

      • PDFArchitect9Installer.exe (PID: 4308)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6528)
      • activation-service.exe (PID: 1744)
      • spoolsv.exe (PID: 5300)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 6480)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 6480)
  • INFO

    • Checks supported languages

      • PDFArchitect9Installer.exe (PID: 4308)
    • Creates files in the program directory

      • PDFArchitect9Installer.exe (PID: 4308)
    • Reads the computer name

      • PDFArchitect9Installer.exe (PID: 4308)
    • Checks proxy server information

      • PDFArchitect9Installer.exe (PID: 4308)
    • Creates files or folders in the user directory

      • PDFArchitect9Installer.exe (PID: 4308)
    • Reads the software policy settings

      • PDFArchitect9Installer.exe (PID: 4308)
    • Reads the machine GUID from the registry

      • PDFArchitect9Installer.exe (PID: 4308)
    • Reads Microsoft Office registry keys

      • PDFArchitect9Installer.exe (PID: 4308)
    • Manages system restore points

      • SrTasks.exe (PID: 6816)
      • SrTasks.exe (PID: 7872)
      • SrTasks.exe (PID: 7452)
      • SrTasks.exe (PID: 2000)
    • Application launched itself

      • msedge.exe (PID: 4716)
      • msedge.exe (PID: 7456)
      • msiexec.exe (PID: 6480)
      • msedge.exe (PID: 7112)
    • Manual execution by a user

      • msedge.exe (PID: 7112)
      • architect.exe (PID: 5096)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6480)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:06 10:54:20+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.37
CodeSize: 7539200
InitializedDataSize: 4537856
UninitializedDataSize: -
EntryPoint: 0x6084ad
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 9.1.59.3267
ProductVersionNumber: 9.1.59.3267
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Avanquest pdfforge GmbH
FileDescription: PDF Architect 9 Installer
FileVersion: 9.1.59.3267
InternalName: PDF_Architect_9_Installer.exe
LegalCopyright: © Avanquest pdfforge GmbH. All rights reserved.
OriginalFileName: PDF_Architect_9_Installer.exe
ProductName: PDF Architect 9 Installer
ProductVersion: 9.1.59.3267
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
209
Monitored processes
86
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start pdfarchitect9installer.exe pdf_architect_9_installer.exe no specs msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs printer-installer-app.exe spoolsv.exe creator-app.exe no specs creator-ws.exe no specs activation-service.exe no specs msiexec.exe no specs architect.exe no specs update-service.exe no specs stats-com.exe no specs architect-launcher.exe no specs architect.exe no specs activation-service.exe no specs architect.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs architect-launcher.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs srtasks.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs srtasks.exe no specs conhost.exe no specs msedge.exe no specs textinputhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs srtasks.exe no specs conhost.exe no specs pdfarchitect9installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
968"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2860 --field-trial-handle=2240,i,13905471372572924457,8531919060229429822,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
1076"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2236 --field-trial-handle=2240,i,13905471372572924457,8531919060229429822,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
1092"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7068 --field-trial-handle=2560,i,8343246036607057297,3944791950265186653,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
1224"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2672 --field-trial-handle=2560,i,8343246036607057297,3944791950265186653,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
1524"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=3508 --field-trial-handle=2240,i,13905471372572924457,8531919060229429822,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
122.0.2365.59
1744"C:\Program Files\PDF Architect 9\activation-service.exe"C:\Program Files\PDF Architect 9\activation-service.exeservices.exe
User:
SYSTEM
Company:
Avanquest pdfforge GmbH
Integrity Level:
SYSTEM
Description:
PDF Architect 9
Version:
9.1.61.22894
2000C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:14C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
2396"C:\Program Files\PDF Architect 9\stats-com.exe" -RegServerC:\Program Files\PDF Architect 9\stats-com.exemsiexec.exe
User:
admin
Company:
Avanquest pdfforge GmbH
Integrity Level:
HIGH
Description:
PDF Architect 9
Exit code:
0
Version:
9.1.61.22894
2628"C:\Program Files\PDF Architect 9\update-service.exe" -serviceC:\Program Files\PDF Architect 9\update-service.exemsiexec.exe
User:
admin
Company:
Avanquest pdfforge GmbH
Integrity Level:
HIGH
Description:
PDF Architect 9
Exit code:
0
Version:
9.1.61.22894
2692"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4004 --field-trial-handle=2560,i,8343246036607057297,3944791950265186653,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Total events
5 140
Read events
5 088
Write events
43
Delete events
9

Modification events

(PID) Process:(4308) PDFArchitect9Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4308) PDFArchitect9Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4308) PDFArchitect9Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4308) PDFArchitect9Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\PDF Architect 9\Installation
Operation:writeName:INSTALL_FOLDER
Value:
C:\Program Files\PDF Architect 9
(PID) Process:(4308) PDFArchitect9Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D3812FE5-F09C-475F-B0E0-26D4F76DDB80}
Operation:writeName:LaunchPermission
Value:
010014804C0000005C000000140000003000000002001C0001000000110014000400000001010000000000100010000002001C0001000000000014000B0000000101000000000001000000000102000000000005200000002002000001020000000000052000000020020000
(PID) Process:(4308) PDFArchitect9Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D3812FE5-F09C-475F-B0E0-26D4F76DDB80}
Operation:writeName:AccessPermission
Value:
010014804C0000005C000000140000003000000002001C0001000000110014000400000001010000000000100010000002001C0001000000000014000B0000000101000000000001000000000102000000000005200000002002000001020000000000052000000020020000
(PID) Process:(4308) PDFArchitect9Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\PDF Architect 9
Operation:writeName:locale
Value:
en
(PID) Process:(5696) PDF_Architect_9_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D3812FE5-F09C-475F-B0E0-26D4F76DDB80}
Operation:writeName:LaunchPermission
Value:
010014804C0000005C000000140000003000000002001C0001000000110014000400000001010000000000100010000002001C0001000000000014000B0000000101000000000001000000000102000000000005200000002002000001020000000000052000000020020000
(PID) Process:(5696) PDF_Architect_9_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D3812FE5-F09C-475F-B0E0-26D4F76DDB80}
Operation:writeName:AccessPermission
Value:
010014804C0000005C000000140000003000000002001C0001000000110014000400000001010000000000100010000002001C0001000000000014000B0000000101000000000001000000000102000000000005200000002002000001020000000000052000000020020000
(PID) Process:(5696) PDF_Architect_9_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0844C86B-623E-4E33-BEEB-F547ECCA9D4B}\LocalServer32
Operation:writeName:ServerExecutable
Value:
C:\ProgramData\PDF Architect 9\Installation\PDF_Architect_9_Installer.exe
Executable files
218
Suspicious files
893
Text files
171
Unknown types
11

Dropped files

PID
Process
Filename
Type
4308PDFArchitect9Installer.exeC:\ProgramData\PDF Architect 9\Installation\pdf-architect9-startup-9.1.61.22894-x64.msi
MD5:
SHA256:
6480msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6480msiexec.exeC:\Windows\Installer\f4e26.msi
MD5:
SHA256:
6480msiexec.exeC:\Windows\Installer\MSI556B.tmp
MD5:
SHA256:
4308PDFArchitect9Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8der
MD5:971C514F84BBA0785F80AA1C23EDFD79
SHA256:F157ED17FCAF8837FA82F8B69973848C9B10A02636848F995698212A08F31895
4308PDFArchitect9Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:FBD131BD523BE8BA1E346FF5193F663C
SHA256:52B016E59C241322665593E77BD8193249473814CB4954A039153FE023E7CEC5
4308PDFArchitect9Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:C59FE2122C01472472B32153F9357DB9
SHA256:FBE269CBC7E81263EF32C8A3B320697DC8D0B9F90D72C13B7E74B482A640B71B
4308PDFArchitect9Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:FF85935AC98641BE84112106494ABDBD
SHA256:343B9A8CEBA22EFC5885A2730DF008D352CD6BF3090DECDBFCFFBE2C60BBE1AE
4308PDFArchitect9Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:8DA7F18010B6DCB02FDB8671BBAC5F22
SHA256:1FD15FBE27AAD7AD12A9FC7919BD7E9CAF9F27C5D4E1A498AB79CD4FE456F3FF
4308PDFArchitect9Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12der
MD5:67E486B2F148A3FCA863728242B6273E
SHA256:FACAF1C3A4BF232ABCE19A2D534E495B0D3ADC7DBE3797D336249AA6F70ADCFB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
158
DNS requests
172
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.32.238.34:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4308
PDFArchitect9Installer.exe
GET
200
142.250.185.195:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
4308
PDFArchitect9Installer.exe
GET
200
142.250.185.195:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4308
PDFArchitect9Installer.exe
HEAD
302
104.22.30.211:80
http://download9.pdfarchitect.org/x64/module/main
unknown
whitelisted
6368
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4704
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
HEAD
302
104.22.30.211:80
http://download9.pdfarchitect.org/x64/module/edit
unknown
whitelisted
GET
302
104.22.30.211:80
http://download9.pdfarchitect.org/x64/module/edit
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5444
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.32.238.34:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.16.253.202:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4932
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4308
PDFArchitect9Installer.exe
104.22.30.211:443
wsgeoip.pdfarchitect.org
CLOUDFLARENET
whitelisted
4308
PDFArchitect9Installer.exe
142.250.185.195:80
c.pki.goog
GOOGLE
US
whitelisted
4308
PDFArchitect9Installer.exe
172.67.14.205:443
wsgeoip.pdfarchitect.org
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.32.238.34
  • 2.19.198.194
whitelisted
www.microsoft.com
  • 2.16.253.202
whitelisted
google.com
  • 142.250.185.238
whitelisted
wsgeoip.pdfarchitect.org
  • 104.22.30.211
  • 104.22.31.211
  • 172.67.14.205
whitelisted
c.pki.goog
  • 142.250.185.195
  • 142.250.184.195
whitelisted
api-updateservice.pdfarchitect.org
  • 172.67.14.205
  • 104.22.31.211
  • 104.22.30.211
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
download9.pdfarchitect.org
  • 104.22.30.211
  • 104.22.31.211
  • 172.67.14.205
whitelisted
download.pdfforge.org
  • 216.239.38.21
  • 216.239.32.21
  • 216.239.34.21
  • 216.239.36.21
unknown

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
No debug info