| File name: | FreePDF4.14.EXE |
| Full analysis: | https://app.any.run/tasks/25236216-1d77-460c-98a5-c94a833c43a1 |
| Verdict: | Malicious activity |
| Analysis date: | March 21, 2024, 09:42:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 51FA9F7E0EE48F9EA9BC231D1DF49556 |
| SHA1: | 0B73035D5455489C50413829EEF970C55D91FA71 |
| SHA256: | 1BAAB40705FD5ED3B01341FD1EFFAC02803859431D50BD5E8026DAEDD8825DD6 |
| SSDEEP: | 98304:Jn2wxNwkrPrf9dEz4n8O/t3ZnY8Axf+Bu+rY3Q+dFDhnI+/rWe6FxkJKU+qNeVe4:xkjr9m |
| .exe | | | Win32 MS Cabinet Self-Extractor (WExtract stub) (86.7) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (8.9) |
| .dll | | | Win32 Dynamic Link Library (generic) (1.8) |
| .exe | | | Win32 Executable (generic) (1.2) |
| .exe | | | Generic Win/DOS Executable (0.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2013:10:14 05:50:27+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 26112 |
| InitializedDataSize: | 2534400 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x67cc |
| OSVersion: | 6.3 |
| ImageVersion: | 6.3 |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 11.0.9600.16428 |
| ProductVersionNumber: | 11.0.9600.16428 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | German |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Win32 Cabinet Self-Extractor |
| FileVersion: | 11.00.9600.16428 (winblue_gdr.131013-1700) |
| InternalName: | Wextract |
| LegalCopyright: | © Microsoft Corporation. Alle Rechte vorbehalten. |
| OriginalFileName: | WEXTRACT.EXE .MUI |
| ProductName: | Internet Explorer |
| ProductVersion: | 11.00.9600.16428 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 696 | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\Helper.exe wait | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\Helper.exe | — | FreePDF4.14.EXE.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 4.00.0063 Modules
| |||||||||||||||
| 920 | "C:\Program Files\FreePDF_XP\fpconfig.exe" | C:\Program Files\FreePDF_XP\fpconfig.exe | — | freepdf.exe | |||||||||||
User: admin Company: . Integrity Level: MEDIUM Description: Setup for administrative FreePDF settings Exit code: 3221226540 Version: 4.00.0090 Modules
| |||||||||||||||
| 968 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1336 | C:\Windows\System32\spoolsv.exe | C:\Windows\System32\spoolsv.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Spooler SubSystem App Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1572 | C:\Windows\system32\net1 stop spooler | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1824 | "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpsetup.exe" setup | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpsetup.exe | Helper.exe | ||||||||||||
User: admin Company: shbox Integrity Level: HIGH Description: FreePDF Setup und Uninstall Exit code: 0 Version: 4.00.0121 Modules
| |||||||||||||||
| 1836 | "C:\Users\admin\AppData\Local\Temp\FreePDF4.14.EXE.exe" | C:\Users\admin\AppData\Local\Temp\FreePDF4.14.EXE.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Win32 Cabinet Self-Extractor Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 1860 | net stop spooler | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2052 | "C:\Program Files\FreePDF_XP\fpassist.exe" | C:\Program Files\FreePDF_XP\fpassist.exe | — | Helper.exe | |||||||||||
User: admin Company: shbox.de Integrity Level: MEDIUM Description: FreePDF Assistent für FreePDF3 Exit code: 0 Version: 3.20.0173 Modules
| |||||||||||||||
| 2060 | cmd /c net start spooler | C:\Windows\System32\cmd.exe | — | fpsetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2580) Helper.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2580) Helper.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2580) Helper.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2580) Helper.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1824) fpsetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP |
| Operation: | write | Name: | Style |
Value: vista | |||
| (PID) Process: | (1824) fpsetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP |
| Operation: | write | Name: | gswin32c |
Value: | |||
| (PID) Process: | (1824) fpsetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP |
| Operation: | write | Name: | psDir |
Value: C:\ProgramData\FreePDF\ | |||
| (PID) Process: | (3724) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3724) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
| (PID) Process: | (3724) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1836 | FreePDF4.14.EXE.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpAssist.exe | executable | |
MD5:2B282A4050FE3B4B70EF9E3070BBFF78 | SHA256:019B667781F5CE411AEB569EAA4095FA2B9942E43A6A1DFC6EEBB2DA214131FE | |||
| 1836 | FreePDF4.14.EXE.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpmailer.exe | executable | |
MD5:959623BB4D53806AFC595D7D76BCBE05 | SHA256:A944A2244E61BB594955EB7DDFDE799A098849281412BC0A42B100F358CB1DE4 | |||
| 1836 | FreePDF4.14.EXE.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpjoin.exe | executable | |
MD5:75F60F658935768BFCE9D15429E4CAA4 | SHA256:67192A649DDA0D6C56ED1F2942656DCFFDA7AE0141A8C21114EA767C2725CBB5 | |||
| 1836 | FreePDF4.14.EXE.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\FreePDFde.pdf | ||
MD5:2427C24B54FC3D80CC08F5763E9FAA3C | SHA256:C9FDCD8837A2997C6C38ECE104D379F976589431BD30A45038AEABFFA198ABE6 | |||
| 1836 | FreePDF4.14.EXE.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\redpr.exe | executable | |
MD5:8166A224BCE403856D9820A3B95FEA64 | SHA256:FB42F98A56817B34C8119AAC881A204E1D9FC4007866174FC6115EA885F9E3CA | |||
| 1836 | FreePDF4.14.EXE.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\setup.exe | executable | |
MD5:4C383F06D906A1A77EB90557F9C180BE | SHA256:08EA1EA8255A77ED93245D6C14A37D6396C20F5E0ED627A56FD06BDD6CE67E0A | |||
| 1836 | FreePDF4.14.EXE.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\unredmon.exe | executable | |
MD5:2E8C8E9AAE4216A6BA20848F8260BCA6 | SHA256:35E2DB103FB458D21B64FC9B3F072AC4979901BEBCD0F69A1AC871C8D8E40FE7 | |||
| 1836 | FreePDF4.14.EXE.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpConfig.exe | executable | |
MD5:E41D71017C83786EFE740B28A8D25D4D | SHA256:E82E4CC308AFEA6486122C6CED69DA2FBA309CFFED1CE8077CFB3D8F77E584A9 | |||
| 1836 | FreePDF4.14.EXE.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\unredmon64.exe | executable | |
MD5:E6B872F96737A098EE63AB0FDAC30A39 | SHA256:14D63C1088F853E24A6807E69F8D857EC9987C24BD14D3A1C9CAE2F7BBEA63D6 | |||
| 1836 | FreePDF4.14.EXE.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\FreePDFen.pdf | ||
MD5:E9FF79C25C569FBB3D7CDCF70581D998 | SHA256:2142E691E72197F1B9A9C6494B191FCC4AE48EF4D172DC3A2BC291ECE7D1B3EC | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |