File name:

PDFNexus.exe

Full analysis: https://app.any.run/tasks/6d1b2486-16bc-4a6d-85e2-49da71fa3707
Verdict: Malicious activity
Analysis date: July 16, 2024, 12:18:35
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
MD5:

C7974B329EF5787872C6A60045628BB6

SHA1:

0541718CADA0115D086C971462F1382CF442CB86

SHA256:

0C5C08FE244110EC1CE9F11E0C44F203194270970A73A485B94B57B557724F0B

SSDEEP:

98304:laPGf3Lx51clR43g0ZtKC5/TF4i9bYvQCPjhPXq2fZWwZmchG6QjvOr/av7Vx6dO:Gm3qrzPw0jtrQr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PDFNexus.exe (PID: 5896)
    • Scans artifacts that could help determine the target

      • PDFNexus.exe (PID: 5896)
    • Actions looks like stealing of personal data

      • SumatraPDF-3.5.2-64.exe (PID: 6408)
      • SumatraPDF-3.5.2-64.exe (PID: 7020)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PDFNexus.exe (PID: 5896)
    • Searches for installed software

      • PDFNexus.exe (PID: 5896)
    • Reads the date of Windows installation

      • PDFNexus.exe (PID: 5896)
    • Creates a software uninstall entry

      • PDFNexus.exe (PID: 5896)
    • Reads security settings of Internet Explorer

      • PDFNexus.exe (PID: 5896)
      • SumatraPDF-3.5.2-64.exe (PID: 7020)
    • Reads Microsoft Outlook installation path

      • PDFNexus.exe (PID: 5896)
    • Checks Windows Trust Settings

      • PDFNexus.exe (PID: 5896)
    • Reads Internet Explorer settings

      • PDFNexus.exe (PID: 5896)
  • INFO

    • Reads the computer name

      • PDFNexus.exe (PID: 5896)
      • SumatraPDF-3.5.2-64.exe (PID: 6408)
      • SumatraPDF-3.5.2-64.exe (PID: 7020)
    • Checks supported languages

      • PDFNexus.exe (PID: 5896)
      • SumatraPDF-3.5.2-64.exe (PID: 6408)
      • SumatraPDF-3.5.2-64.exe (PID: 7020)
    • Creates files or folders in the user directory

      • PDFNexus.exe (PID: 5896)
      • SumatraPDF-3.5.2-64.exe (PID: 6408)
    • Process checks computer location settings

      • PDFNexus.exe (PID: 5896)
    • Reads CPU info

      • SumatraPDF-3.5.2-64.exe (PID: 6408)
      • SumatraPDF-3.5.2-64.exe (PID: 7020)
    • Reads the machine GUID from the registry

      • PDFNexus.exe (PID: 5896)
    • Manual execution by a user

      • SumatraPDF-3.5.2-64.exe (PID: 7020)
    • Reads the software policy settings

      • slui.exe (PID: 6760)
      • PDFNexus.exe (PID: 5896)
    • Checks proxy server information

      • PDFNexus.exe (PID: 5896)
    • Process checks Internet Explorer phishing filters

      • PDFNexus.exe (PID: 5896)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2070:01:06 02:11:59+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 80
CodeSize: 8270848
InitializedDataSize: 114688
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: PDFNexus
FileVersion: 1.0.0.0
InternalName: PDFNexus.exe
LegalCopyright: Copyright © 2024
LegalTrademarks: -
OriginalFileName: PDFNexus.exe
ProductName: PDFNexus
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pdfnexus.exe sumatrapdf-3.5.2-64.exe sppextcomobj.exe no specs slui.exe sumatrapdf-3.5.2-64.exe slui.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3676C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5896"C:\Users\admin\AppData\Local\Temp\PDFNexus.exe" C:\Users\admin\AppData\Local\Temp\PDFNexus.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
PDFNexus
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\pdfnexus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6408"C:\Users\admin\AppData\Roaming\SumatraPDF\SumatraPDF-3.5.2-64.exe" C:\Users\admin\AppData\Roaming\SumatraPDF\SumatraPDF-3.5.2-64.exe
PDFNexus.exe
User:
admin
Company:
Krzysztof Kowalczyk
Integrity Level:
MEDIUM
Description:
SumatraPDF
Exit code:
0
Version:
3.5.2
Modules
Images
c:\users\admin\appdata\roaming\sumatrapdf\sumatrapdf-3.5.2-64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6728C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6760"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6904C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7020"C:\Users\admin\AppData\Roaming\SumatraPDF\SumatraPDF-3.5.2-64.exe" C:\Users\admin\AppData\Roaming\SumatraPDF\SumatraPDF-3.5.2-64.exe
explorer.exe
User:
admin
Company:
Krzysztof Kowalczyk
Integrity Level:
MEDIUM
Description:
SumatraPDF
Exit code:
0
Version:
3.5.2
Modules
Images
c:\users\admin\appdata\roaming\sumatrapdf\sumatrapdf-3.5.2-64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
24 745
Read events
24 101
Write events
611
Delete events
33

Modification events

(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SumatraPDFUninstall
Operation:writeName:DisplayName
Value:
SumatraPDF
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SumatraPDFUninstall
Operation:writeName:UninstallString
Value:
cmd /c rmdir /s /q "C:\Users\admin\AppData\Roaming\SumatraPDF" & del "C:\Users\admin\Desktop\SumatraPDF.lnk" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SumatraPDFUninstall /f
(PID) Process:(5896) PDFNexus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
Executable files
1
Suspicious files
13
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8der
MD5:1BFE0A81DB078EA084FF82FE545176FE
SHA256:5BA8817F13EEE00E75158BAD93076AB474A068C6B52686579E0F728FDA68499F
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:EA6D3FA922F2B38F523BBDBA170D299A
SHA256:29A76F619FA4DCFA583CD95734D6CA9A66D956ACC023799C02669525B7E07435
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199der
MD5:8D1040B12A663CA4EC7277CFC1CE44F0
SHA256:3086094D4198A5BBD12938B0D2D5F696C4DFC77E1EAE820ADDED346A59AA8727
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12der
MD5:7FB5FA1534DCF77F2125B2403B30A0EE
SHA256:33A39E9EC2133230533A686EC43760026E014A3828C703707ACBC150FE40FD6F
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:2F7347A600F689A32C1418309A6D157F
SHA256:DB1F42376640063F0B149B8FFDB4A65023D12F6BA2E6CFDCAEF831D89ABB2435
5896PDFNexus.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\email-decode.min[1].jshtml
MD5:9E8F56E8E1806253BA01A95CFC3D392C
SHA256:2595496FE48DF6FCF9B1BC57C29A744C121EB4DD11566466BC13D2E52E6BBCC8
5896PDFNexus.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\9WQ6HXYV.htmhtml
MD5:92F59508FC881453513CE0031D7DFA1A
SHA256:ECE2AA949A49BD90B1D275C56D03C63F3213CE41AC07A7F9A76D8072F30F1E2D
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199binary
MD5:7B3AFA8373F6F4D5FDA54098E0FA8383
SHA256:0BD3A7699AFC92DFB49CFD6AF8EDC87031A7C08512D9029765410419BDD50E20
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B3513D73A177A2707D910183759B389B_32201FF65E9A20A693462A3946A29CAEder
MD5:5D5650AB608CD61702DE4FA6B7457044
SHA256:4FF3F940A74F047AF60829D14365CE7744F3ADF895580338878CDF465ABCBF3F
5896PDFNexus.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B3513D73A177A2707D910183759B389B_32201FF65E9A20A693462A3946A29CAEbinary
MD5:E2FF727AFBB225022DE6DF1E1EB60B92
SHA256:AF0C0CD82DC1FF2FE6FD8B92F8BAE3D6AB2902852661DF9351C7EC86901D99D9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
73
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3540
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4392
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4392
svchost.exe
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5896
PDFNexus.exe
GET
200
142.250.185.227:80
http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQC1wDSQwr%2F7UxDebtw0D9JJ
unknown
whitelisted
5896
PDFNexus.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
5896
PDFNexus.exe
GET
200
142.250.185.227:80
http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEHViWUaptL4MEEkSmq4OScg%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5896
PDFNexus.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
5896
PDFNexus.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
5820
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4392
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3828
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
444
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4656
SearchApp.exe
104.126.37.136:443
www.bing.com
Akamai International B.V.
DE
unknown
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
5896
PDFNexus.exe
188.114.97.3:443
pixel.pdfnexus.com
CLOUDFLARENET
NL
unknown
5896
PDFNexus.exe
142.250.184.195:80
c.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.46
whitelisted
www.bing.com
  • 104.126.37.136
  • 104.126.37.184
  • 104.126.37.131
  • 104.126.37.185
  • 104.126.37.186
  • 104.126.37.178
  • 104.126.37.139
  • 104.126.37.138
  • 104.126.37.130
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
pixel.pdfnexus.com
  • 188.114.97.3
  • 188.114.96.3
unknown
c.pki.goog
  • 142.250.184.195
whitelisted
fonts.googleapis.com
  • 142.250.185.234
whitelisted
o.pki.goog
  • 142.250.185.227
whitelisted
fonts.gstatic.com
  • 142.250.186.67
whitelisted
login.live.com
  • 20.190.159.75
  • 40.126.31.73
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.2
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.67
whitelisted

Threats

No threats detected
No debug info