URL:

https://www.autodesk.com/latam/viewers

Full analysis: https://app.any.run/tasks/4b739c6b-601d-4b04-84fb-560e4484cb12
Verdict: Malicious activity
Analysis date: October 29, 2024, 15:59:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

80DA83FC08B622AD9C88A2FA63735EDB

SHA1:

80E5E15463702A7831AAB7635FF7E5E31C276550

SHA256:

120D088AD79CB4F060E22FEB2E4FB63BC8BA0EAA4C1C1EB23C73CD4A72A1BE81

SSDEEP:

3:N8DSLP3KN3AG:2OLyhF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Autodesk_DWG_TrueView_2025_en-US_setup_webinstall.exe (PID: 5792)
      • AdODIS-installer.exe (PID: 6352)
      • 7za.exe (PID: 1028)
      • AdODIS-installer.exe (PID: 7972)
    • Executable content was dropped or overwritten

      • Autodesk_DWG_TrueView_2025_en-US_setup_webinstall.exe (PID: 5792)
      • AdODIS-installer.exe (PID: 6352)
      • install_manager.exe (PID: 4792)
      • AdODIS-installer.exe (PID: 7972)
      • 7za.exe (PID: 1028)
    • Drops 7-zip archiver for unpacking

      • Autodesk_DWG_TrueView_2025_en-US_setup_webinstall.exe (PID: 5792)
      • AdODIS-installer.exe (PID: 6352)
      • AdODIS-installer.exe (PID: 7972)
    • The process drops C-runtime libraries

      • Autodesk_DWG_TrueView_2025_en-US_setup_webinstall.exe (PID: 5792)
      • AdODIS-installer.exe (PID: 7972)
      • AdODIS-installer.exe (PID: 6352)
    • Application launched itself

      • AdskAccessUIHost.exe (PID: 6188)
    • Starts CMD.EXE for commands execution

      • AdskAccessUIHost.exe (PID: 4548)
    • Uses WMIC.EXE to obtain local storage devices information

      • cmd.exe (PID: 1568)
  • INFO

    • Manual execution by a user

      • Autodesk_DWG_TrueView_2025_en-US_setup_webinstall.exe (PID: 2632)
      • Autodesk_DWG_TrueView_2025_en-US_setup_webinstall.exe (PID: 5792)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 5584)
    • Application launched itself

      • chrome.exe (PID: 5584)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
200
Monitored processes
63
Malicious processes
4
Suspicious processes
3

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs rundll32.exe no specs autodesk_dwg_trueview_2025_en-us_setup_webinstall.exe no specs autodesk_dwg_trueview_2025_en-us_setup_webinstall.exe setup.exe downloadmanager.exe conhost.exe no specs downloadmanager.exe conhost.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs 7za.exe no specs conhost.exe no specs adodis-installer.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs installer.exe no specs adskaccessuihost.exe no specs adskaccessuihost.exe no specs adskaccessuihost.exe no specs adskaccessuihost.exe no specs downloadmanager.exe no specs conhost.exe no specs processmanager.exe no specs conhost.exe no specs chrome.exe no specs install_manager.exe loganalyzer.exe no specs 7za.exe no specs 7za.exe no specs 7za.exe no specs 7za.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs chrome.exe no specs adodis-installer.exe 7za.exe no specs 7za.exe chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
528"C:\Users\admin\AppData\Local\Temp\7z981656A0\ODIS\DownloadManager.exe" -u "https://efulfillment.autodesk.com/NetSWDLD/ODIS/prd/2025/PLC0000037/984E9F0B-8BB2-3CE8-BCF5-2D3899919001/WI/Autodesk_DWG_TrueView_2025_en-US_setup.dat" -p "C:\Users\admin\AppData\Local\Temp\odis_download_dest\2236788610448611187\Autodesk_DWG_TrueView_2025_en-US_setup.dat" --productname Bootstrap --productversion 2.10.0.4C:\Users\admin\AppData\Local\Temp\7z981656A0\ODIS\DownloadManager.exe
Setup.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
HIGH
Description:
Autodesk Desktop Delivery Application
Exit code:
0
Version:
2.10.0.2
Modules
Images
c:\users\admin\appdata\local\temp\7z981656a0\odis\downloadmanager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
860"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6856 --field-trial-handle=1828,i,884150886784427670,660228154829244697,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
1028"C:\Users\admin\AppData\Local\Temp\odis_download_dest\14358554287545933867\Setup/7za.exe" x -ttar -si -aoa -bsp2 -o"C:\Users\admin\AppData\Local\Temp\{984E9F0B-8BB2-3CE8-BCF5-2D3899919001}"C:\Users\admin\AppData\Local\Temp\odis_download_dest\14358554287545933867\Setup\7za.exe
DownloadManager.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
1344"C:\Users\admin\AppData\Local\Temp\odis_download_dest\14358554287545933867\Setup/7za.exe" x -txz "C:/Autodesk/WI/5915482498758831709/pkg.vcredist2022x86.tar.xz" -bsp2 -soC:\Users\admin\AppData\Local\Temp\odis_download_dest\14358554287545933867\Setup\7za.exeDownloadManager.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
1452"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6604 --field-trial-handle=1828,i,884150886784427670,660228154829244697,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1568"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6460 --field-trial-handle=1828,i,884150886784427670,660228154829244697,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1568C:\WINDOWS\system32\cmd.exe /d /s /c "wmic logicaldisk Where DriveType=4 get DeviceID"C:\Windows\System32\cmd.exeAdskAccessUIHost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
2088"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6984 --field-trial-handle=1828,i,884150886784427670,660228154829244697,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
2464C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2632"C:\Users\admin\Downloads\Autodesk_DWG_TrueView_2025_en-US_setup_webinstall.exe" C:\Users\admin\Downloads\Autodesk_DWG_TrueView_2025_en-US_setup_webinstall.exeexplorer.exe
User:
admin
Company:
Autodesk, Inc.
Integrity Level:
MEDIUM
Description:
Autodesk Installation Services
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\downloads\autodesk_dwg_trueview_2025_en-us_setup_webinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
16 122
Read events
16 089
Write events
27
Delete events
6

Modification events

(PID) Process:(5584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(5584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(5584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(5584) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(5584) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(1568) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
01000000000000000FD439C01B2ADB01
(PID) Process:(528) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\2.10.0.2
Operation:writeName:SessionStartCount
Value:
1
(PID) Process:(528) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\2.10.0.2
Operation:writeName:SessionCleanCloseCount
Value:
1
(PID) Process:(528) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\2.10.0.2
Operation:writeName:Uptime
Value:
C2EB0B0000000000
(PID) Process:(528) DownloadManager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Autodesk\DDA\DLM\CER\2.10.0.2
Operation:writeName:CalUptime
Value:
2A37CE0000000000
Executable files
257
Suspicious files
599
Text files
195
Unknown types
7

Dropped files

PID
Process
Filename
Type
5584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF8d395.TMP
MD5:
SHA256:
5584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
5584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF8d395.TMP
MD5:
SHA256:
5584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
5584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF8d3a4.TMP
MD5:
SHA256:
5584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
5584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF8d3a4.TMP
MD5:
SHA256:
5584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
5584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF8d3c4.TMP
MD5:
SHA256:
5584chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
51
TCP/UDP connections
297
DNS requests
304
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
104.76.201.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5784
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4232
SIHClient.exe
GET
200
104.76.201.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4232
SIHClient.exe
GET
200
104.76.201.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2692
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6408
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/aclz7ibkvp257t2vgob3ecc555sa_20241018.689539685.14/obedbbhbpmojnkanicioggnmelmoomoc_20241018.689539685.14_all_ENUS500000_admgvmzxgughtxzk6ailm7o5nzqa.crx3
unknown
whitelisted
6408
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/aclz7ibkvp257t2vgob3ecc555sa_20241018.689539685.14/obedbbhbpmojnkanicioggnmelmoomoc_20241018.689539685.14_all_ENUS500000_admgvmzxgughtxzk6ailm7o5nzqa.crx3
unknown
whitelisted
6408
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/aclz7ibkvp257t2vgob3ecc555sa_20241018.689539685.14/obedbbhbpmojnkanicioggnmelmoomoc_20241018.689539685.14_all_ENUS500000_admgvmzxgughtxzk6ailm7o5nzqa.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4360
SearchApp.exe
184.86.251.16:443
www.bing.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
104.76.201.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5584
chrome.exe
239.255.255.250:1900
whitelisted
6768
chrome.exe
23.212.223.77:443
www.autodesk.com
AKAMAI-AS
AU
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 184.86.251.16
  • 184.86.251.10
  • 184.86.251.19
  • 184.86.251.20
  • 184.86.251.11
  • 184.86.251.6
  • 184.86.251.14
  • 184.86.251.15
  • 184.86.251.8
  • 184.86.251.22
  • 184.86.251.21
  • 184.86.251.23
  • 184.86.251.18
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.48.23.176
  • 23.48.23.147
  • 23.48.23.166
  • 23.48.23.143
  • 23.48.23.145
  • 23.48.23.194
  • 23.48.23.156
  • 23.48.23.164
  • 2.16.164.106
  • 2.16.164.18
  • 2.16.164.43
  • 2.16.164.51
whitelisted
www.microsoft.com
  • 104.76.201.160
  • 88.221.169.152
whitelisted
google.com
  • 142.250.185.174
whitelisted
www.autodesk.com
  • 23.212.223.77
whitelisted
accounts.google.com
  • 108.177.127.84
whitelisted
login.live.com
  • 40.126.32.140
  • 20.190.160.20
  • 40.126.32.136
  • 40.126.32.72
  • 40.126.32.134
  • 40.126.32.76
  • 40.126.32.74
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.52.121.103
whitelisted

Threats

PID
Process
Class
Message
6768
chrome.exe
Potentially Bad Traffic
ET HUNTING Observed AutoDesk Domain in TLS SNI (api .autodesk .com)
6768
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to newrelic .com
6768
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to newrelic .com
6768
chrome.exe
Potentially Bad Traffic
ET HUNTING Observed AutoDesk Domain in TLS SNI (api .autodesk .com)
6768
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to newrelic .com
6768
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to newrelic .com
No debug info