File name:

PDFNexus.exe

Full analysis: https://app.any.run/tasks/6d1b2486-16bc-4a6d-85e2-49da71fa3707
Verdict: Malicious activity
Analysis date: July 16, 2024, 12:18:35
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
MD5:

C7974B329EF5787872C6A60045628BB6

SHA1:

0541718CADA0115D086C971462F1382CF442CB86

SHA256:

0C5C08FE244110EC1CE9F11E0C44F203194270970A73A485B94B57B557724F0B

SSDEEP:

98304:laPGf3Lx51clR43g0ZtKC5/TF4i9bYvQCPjhPXq2fZWwZmchG6QjvOr/av7Vx6dO:Gm3qrzPw0jtrQr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PDFNexus.exe (PID: 5896)
    • Scans artifacts that could help determine the target

      • PDFNexus.exe (PID: 5896)
    • Actions looks like stealing of personal data

      • SumatraPDF-3.5.2-64.exe (PID: 6408)
      • SumatraPDF-3.5.2-64.exe (PID: 7020)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • PDFNexus.exe (PID: 5896)
      • SumatraPDF-3.5.2-64.exe (PID: 7020)
    • Reads Microsoft Outlook installation path

      • PDFNexus.exe (PID: 5896)
    • Checks Windows Trust Settings

      • PDFNexus.exe (PID: 5896)
    • Reads Internet Explorer settings

      • PDFNexus.exe (PID: 5896)
    • Creates a software uninstall entry

      • PDFNexus.exe (PID: 5896)
    • Executable content was dropped or overwritten

      • PDFNexus.exe (PID: 5896)
    • Searches for installed software

      • PDFNexus.exe (PID: 5896)
    • Reads the date of Windows installation

      • PDFNexus.exe (PID: 5896)
  • INFO

    • Checks supported languages

      • PDFNexus.exe (PID: 5896)
      • SumatraPDF-3.5.2-64.exe (PID: 7020)
      • SumatraPDF-3.5.2-64.exe (PID: 6408)
    • Reads the machine GUID from the registry

      • PDFNexus.exe (PID: 5896)
    • Reads CPU info

      • SumatraPDF-3.5.2-64.exe (PID: 6408)
      • SumatraPDF-3.5.2-64.exe (PID: 7020)
    • Reads the computer name

      • PDFNexus.exe (PID: 5896)
      • SumatraPDF-3.5.2-64.exe (PID: 6408)
      • SumatraPDF-3.5.2-64.exe (PID: 7020)
    • Process checks Internet Explorer phishing filters

      • PDFNexus.exe (PID: 5896)
    • Checks proxy server information

      • PDFNexus.exe (PID: 5896)
    • Creates files or folders in the user directory

      • PDFNexus.exe (PID: 5896)
      • SumatraPDF-3.5.2-64.exe (PID: 6408)
    • Manual execution by a user

      • SumatraPDF-3.5.2-64.exe (PID: 7020)
    • Reads the software policy settings

      • slui.exe (PID: 6760)
      • PDFNexus.exe (PID: 5896)
    • Process checks computer location settings

      • PDFNexus.exe (PID: 5896)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2070:01:06 02:11:59+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 80
CodeSize: 8270848
InitializedDataSize: 114688
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: PDFNexus
FileVersion: 1.0.0.0
InternalName: PDFNexus.exe
LegalCopyright: Copyright © 2024
LegalTrademarks: -
OriginalFileName: PDFNexus.exe
ProductName: PDFNexus
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pdfnexus.exe sumatrapdf-3.5.2-64.exe sppextcomobj.exe no specs slui.exe sumatrapdf-3.5.2-64.exe slui.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3676C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5896"C:\Users\admin\AppData\Local\Temp\PDFNexus.exe" C:\Users\admin\AppData\Local\Temp\PDFNexus.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
PDFNexus
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\pdfnexus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6408"C:\Users\admin\AppData\Roaming\SumatraPDF\SumatraPDF-3.5.2-64.exe" C:\Users\admin\AppData\Roaming\SumatraPDF\SumatraPDF-3.5.2-64.exe
PDFNexus.exe
User:
admin
Company:
Krzysztof Kowalczyk
Integrity Level:
MEDIUM
Description:
SumatraPDF
Exit code:
0
Version:
3.5.2
Modules
Images
c:\users\admin\appdata\roaming\sumatrapdf\sumatrapdf-3.5.2-64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6728C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6760"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6904C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7020"C:\Users\admin\AppData\Roaming\SumatraPDF\SumatraPDF-3.5.2-64.exe" C:\Users\admin\AppData\Roaming\SumatraPDF\SumatraPDF-3.5.2-64.exe
explorer.exe
User:
admin
Company:
Krzysztof Kowalczyk
Integrity Level:
MEDIUM
Description:
SumatraPDF
Exit code:
0
Version:
3.5.2
Modules
Images
c:\users\admin\appdata\roaming\sumatrapdf\sumatrapdf-3.5.2-64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
24 745
Read events
24 101
Write events
611
Delete events
33

Modification events

(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SumatraPDFUninstall
Operation:writeName:DisplayName
Value:
SumatraPDF
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SumatraPDFUninstall
Operation:writeName:UninstallString
Value:
cmd /c rmdir /s /q "C:\Users\admin\AppData\Roaming\SumatraPDF" & del "C:\Users\admin\Desktop\SumatraPDF.lnk" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SumatraPDFUninstall /f
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
Executable files
1
Suspicious files
13
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B3513D73A177A2707D910183759B389B_32201FF65E9A20A693462A3946A29CAEder
MD5:5D5650AB608CD61702DE4FA6B7457044
SHA256:4FF3F940A74F047AF60829D14365CE7744F3ADF895580338878CDF465ABCBF3F
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B3513D73A177A2707D910183759B389B_32201FF65E9A20A693462A3946A29CAEbinary
MD5:E2FF727AFBB225022DE6DF1E1EB60B92
SHA256:AF0C0CD82DC1FF2FE6FD8B92F8BAE3D6AB2902852661DF9351C7EC86901D99D9
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199der
MD5:8D1040B12A663CA4EC7277CFC1CE44F0
SHA256:3086094D4198A5BBD12938B0D2D5F696C4DFC77E1EAE820ADDED346A59AA8727
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DDE8B1B7E253A9758EC380BD648952AF_857450206B889F4FEA0F888FA03D68DBder
MD5:5472B509C2B20FDBB61940A5C1949DB9
SHA256:CF1D223E59007BB49AAC397F89AB34B75A086424211E884FA5FFDE34BDDF4167
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12der
MD5:7FB5FA1534DCF77F2125B2403B30A0EE
SHA256:33A39E9EC2133230533A686EC43760026E014A3828C703707ACBC150FE40FD6F
6408SumatraPDF-3.5.2-64.exeC:\Users\admin\AppData\Roaming\SumatraPDF\SumatraPDF-settings.txttext
MD5:DBD1BFC3642664DE96C153D2691D5D9D
SHA256:270684C878654FF89DC144DCDC6B56ED164E286A13F9E14999CEEE0F8C57D776
5896PDFNexus.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\font[1].eotbinary
MD5:C6B85601ADBF8C674B4B444DAD696A5D
SHA256:EC8671B432FF49E1E77F48692397E57ECFA584555AC664C932DCCEA0C9A16044
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DDE8B1B7E253A9758EC380BD648952AF_857450206B889F4FEA0F888FA03D68DBbinary
MD5:51938265154C159EB01917073A037451
SHA256:0E1AA5D936A5E5B1BB6C074932E26CDD1A5594FAB0C572FB88804116790B61C7
5896PDFNexus.exeC:\Users\admin\AppData\Roaming\SumatraPDF\SumatraPDF-3.5.2-64.exeexecutable
MD5:C02DC2CA96FE9841963883C0FE177399
SHA256:290E4AA7ED64C728138711C011E89AAB7AA48DBC1AE430371DC2BE4100B92BF0
5896PDFNexus.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\email-decode.min[1].jshtml
MD5:9E8F56E8E1806253BA01A95CFC3D392C
SHA256:2595496FE48DF6FCF9B1BC57C29A744C121EB4DD11566466BC13D2E52E6BBCC8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
73
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5896
PDFNexus.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
5896
PDFNexus.exe
GET
200
142.250.185.227:80
http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQC1wDSQwr%2F7UxDebtw0D9JJ
unknown
whitelisted
5896
PDFNexus.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
5896
PDFNexus.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
4392
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4536
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6624
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4392
svchost.exe
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5896
PDFNexus.exe
GET
200
142.250.185.227:80
http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEHViWUaptL4MEEkSmq4OScg%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4392
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3828
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
444
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4656
SearchApp.exe
104.126.37.136:443
www.bing.com
Akamai International B.V.
DE
unknown
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
5896
PDFNexus.exe
188.114.97.3:443
pixel.pdfnexus.com
CLOUDFLARENET
NL
unknown
5896
PDFNexus.exe
142.250.184.195:80
c.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.46
whitelisted
www.bing.com
  • 104.126.37.136
  • 104.126.37.184
  • 104.126.37.131
  • 104.126.37.185
  • 104.126.37.186
  • 104.126.37.178
  • 104.126.37.139
  • 104.126.37.138
  • 104.126.37.130
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
pixel.pdfnexus.com
  • 188.114.97.3
  • 188.114.96.3
unknown
c.pki.goog
  • 142.250.184.195
whitelisted
fonts.googleapis.com
  • 142.250.185.234
whitelisted
o.pki.goog
  • 142.250.185.227
whitelisted
fonts.gstatic.com
  • 142.250.186.67
whitelisted
login.live.com
  • 20.190.159.75
  • 40.126.31.73
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.2
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.67
whitelisted

Threats

No threats detected
No debug info