File name:

FreePDF4.14.EXE

Full analysis: https://app.any.run/tasks/25236216-1d77-460c-98a5-c94a833c43a1
Verdict: Malicious activity
Analysis date: March 21, 2024, 09:42:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

51FA9F7E0EE48F9EA9BC231D1DF49556

SHA1:

0B73035D5455489C50413829EEF970C55D91FA71

SHA256:

1BAAB40705FD5ED3B01341FD1EFFAC02803859431D50BD5E8026DAEDD8825DD6

SSDEEP:

98304:Jn2wxNwkrPrf9dEz4n8O/t3ZnY8Axf+Bu+rY3Q+dFDhnI+/rWe6FxkJKU+qNeVe4:xkjr9m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FreePDF4.14.EXE.exe (PID: 1836)
      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
    • Creates a writable file in the system directory

      • setup.exe (PID: 3684)
      • fpsetup.exe (PID: 1824)
      • InfDefaultInstall.exe (PID: 2968)
    • Registers / Runs the DLL via REGSVR32.EXE

      • fpsetup.exe (PID: 1824)
    • Changes the autorun value in the registry

      • fpsetup.exe (PID: 1824)
      • InfDefaultInstall.exe (PID: 2968)
    • Starts NET.EXE for service management

      • cmd.exe (PID: 3776)
      • cmd.exe (PID: 2060)
      • net.exe (PID: 1860)
      • net.exe (PID: 2488)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • FreePDF4.14.EXE.exe (PID: 1836)
      • fpsetup.exe (PID: 1824)
      • InfDefaultInstall.exe (PID: 2968)
    • Starts a Microsoft application from unusual location

      • FreePDF4.14.EXE.exe (PID: 1836)
    • Reads the Internet Settings

      • Helper.exe (PID: 2580)
      • runonce.exe (PID: 2780)
      • freepdf.exe (PID: 3504)
    • Reads security settings of Internet Explorer

      • Helper.exe (PID: 2580)
      • freepdf.exe (PID: 3504)
    • Executable content was dropped or overwritten

      • FreePDF4.14.EXE.exe (PID: 1836)
      • setup.exe (PID: 3684)
      • fpsetup.exe (PID: 1824)
      • InfDefaultInstall.exe (PID: 2968)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3724)
    • Creates a software uninstall entry

      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
    • Uses RUNDLL32.EXE to load library

      • fpsetup.exe (PID: 1824)
    • Executes as Windows Service

      • spoolsv.exe (PID: 1336)
    • Starts CMD.EXE for commands execution

      • fpsetup.exe (PID: 1824)
      • cmd.exe (PID: 3776)
    • Application launched itself

      • cmd.exe (PID: 3776)
  • INFO

    • Checks supported languages

      • FreePDF4.14.EXE.exe (PID: 1836)
      • Helper.exe (PID: 2580)
      • fpsetup.exe (PID: 1824)
      • Helper.exe (PID: 696)
      • setup.exe (PID: 3684)
      • freepdf.exe (PID: 3504)
      • fpconfig.exe (PID: 3132)
      • wmpnscfg.exe (PID: 968)
      • fpassist.exe (PID: 2052)
    • Reads the computer name

      • Helper.exe (PID: 2580)
      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
      • freepdf.exe (PID: 3504)
      • wmpnscfg.exe (PID: 968)
    • Create files in a temporary directory

      • FreePDF4.14.EXE.exe (PID: 1836)
      • fpsetup.exe (PID: 1824)
      • fpassist.exe (PID: 2052)
      • freepdf.exe (PID: 3504)
      • fpconfig.exe (PID: 3132)
    • Reads the machine GUID from the registry

      • fpsetup.exe (PID: 1824)
      • fpassist.exe (PID: 2052)
      • freepdf.exe (PID: 3504)
      • fpconfig.exe (PID: 3132)
    • Creates files in the program directory

      • fpsetup.exe (PID: 1824)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 2780)
    • Reads the time zone

      • runonce.exe (PID: 2780)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 968)
      • freepdf.exe (PID: 3504)
      • explorer.exe (PID: 3976)
    • Drops the executable file immediately after the start

      • InfDefaultInstall.exe (PID: 2968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 MS Cabinet Self-Extractor (WExtract stub) (86.7)
.exe | Win32 Executable MS Visual C++ (generic) (8.9)
.dll | Win32 Dynamic Link Library (generic) (1.8)
.exe | Win32 Executable (generic) (1.2)
.exe | Generic Win/DOS Executable (0.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:10:14 05:50:27+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 26112
InitializedDataSize: 2534400
UninitializedDataSize: -
EntryPoint: 0x67cc
OSVersion: 6.3
ImageVersion: 6.3
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 11.0.9600.16428
ProductVersionNumber: 11.0.9600.16428
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: German
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 11.00.9600.16428 (winblue_gdr.131013-1700)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFileName: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.9600.16428
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
26
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start freepdf4.14.exe.exe helper.exe no specs fpsetup.exe no specs fpsetup.exe helper.exe no specs regsvr32.exe no specs setup.exe rundll32.exe no specs cmd.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs rundll32.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs spoolsv.exe no specs infdefaultinstall.exe runonce.exe no specs grpconv.exe no specs wmpnscfg.exe no specs explorer.exe no specs fpassist.exe no specs freepdf.exe no specs fpconfig.exe no specs fpconfig.exe

Process information

PID
CMD
Path
Indicators
Parent process
696C:\Users\admin\AppData\Local\Temp\IXP000.TMP\Helper.exe waitC:\Users\admin\AppData\Local\Temp\IXP000.TMP\Helper.exeFreePDF4.14.EXE.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
4.00.0063
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\msvbvm50.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
920"C:\Program Files\FreePDF_XP\fpconfig.exe" C:\Program Files\FreePDF_XP\fpconfig.exefreepdf.exe
User:
admin
Company:
.
Integrity Level:
MEDIUM
Description:
Setup for administrative FreePDF settings
Exit code:
3221226540
Version:
4.00.0090
Modules
Images
c:\program files\freepdf_xp\fpconfig.exe
c:\windows\system32\ntdll.dll
968"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1336C:\Windows\System32\spoolsv.exeC:\Windows\System32\spoolsv.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Spooler SubSystem App
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\spoolsv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1572C:\Windows\system32\net1 stop spoolerC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
1824"C:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpsetup.exe" setupC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpsetup.exe
Helper.exe
User:
admin
Company:
shbox
Integrity Level:
HIGH
Description:
FreePDF Setup und Uninstall
Exit code:
0
Version:
4.00.0121
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\fpsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\msvbvm50.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1836"C:\Users\admin\AppData\Local\Temp\FreePDF4.14.EXE.exe" C:\Users\admin\AppData\Local\Temp\FreePDF4.14.EXE.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Win32 Cabinet Self-Extractor
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\users\admin\appdata\local\temp\freepdf4.14.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1860net stop spoolerC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
2052"C:\Program Files\FreePDF_XP\fpassist.exe"C:\Program Files\FreePDF_XP\fpassist.exeHelper.exe
User:
admin
Company:
shbox.de
Integrity Level:
MEDIUM
Description:
FreePDF Assistent für FreePDF3
Exit code:
0
Version:
3.20.0173
Modules
Images
c:\program files\freepdf_xp\fpassist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm50.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2060cmd /c net start spoolerC:\Windows\System32\cmd.exefpsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
5 791
Read events
5 713
Write events
65
Delete events
13

Modification events

(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1824) fpsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP
Operation:writeName:Style
Value:
vista
(PID) Process:(1824) fpsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP
Operation:writeName:gswin32c
Value:
(PID) Process:(1824) fpsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP
Operation:writeName:psDir
Value:
C:\ProgramData\FreePDF\
(PID) Process:(3724) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(3724) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(3724) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
Executable files
67
Suspicious files
12
Text files
49
Unknown types
6

Dropped files

PID
Process
Filename
Type
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\FreePDF.exeexecutable
MD5:C353931D67573F33AB8D419866304447
SHA256:7304B9866B213FB933EEE4523140F2376BEF68C976618BDA1D91E5A715D6CABF
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\FreePDFen.pdfpdf
MD5:E9FF79C25C569FBB3D7CDCF70581D998
SHA256:2142E691E72197F1B9A9C6494B191FCC4AE48EF4D172DC3A2BC291ECE7D1B3EC
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\unredmon.exeexecutable
MD5:2E8C8E9AAE4216A6BA20848F8260BCA6
SHA256:35E2DB103FB458D21B64FC9B3F072AC4979901BEBCD0F69A1AC871C8D8E40FE7
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\Helper.exeexecutable
MD5:B00F9B49467BD8372CCE6F5EF5BA7F5D
SHA256:FEFB58316207688A21D0D791E770E04B8483D083A88393FA5F26ADB2485B0144
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpsetup.exeexecutable
MD5:119A5B8FBF30AB333D3440E9C2B0E377
SHA256:F93B8A50E4AEAA4D93988A6797862314F2EE849838D4DAE1FB181C8D952EC657
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpjoin.exeexecutable
MD5:75F60F658935768BFCE9D15429E4CAA4
SHA256:67192A649DDA0D6C56ED1F2942656DCFFDA7AE0141A8C21114EA767C2725CBB5
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpmailer.exeexecutable
MD5:959623BB4D53806AFC595D7D76BCBE05
SHA256:A944A2244E61BB594955EB7DDFDE799A098849281412BC0A42B100F358CB1DE4
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\redrun.exeexecutable
MD5:262203A62F5B2A5FF18E139B0BE0DC8B
SHA256:91CC9EF8F16C8CA8BA4E5B311D5A7581201F6F7BFE0C86CFBCD0D324E355873F
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\unredmon64.exeexecutable
MD5:E6B872F96737A098EE63AB0FDAC30A39
SHA256:14D63C1088F853E24A6807E69F8D857EC9987C24BD14D3A1C9CAE2F7BBEA63D6
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpConfig.exeexecutable
MD5:E41D71017C83786EFE740B28A8D25D4D
SHA256:E82E4CC308AFEA6486122C6CED69DA2FBA309CFFED1CE8077CFB3D8F77E584A9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info