File name:

FreePDF4.14.EXE

Full analysis: https://app.any.run/tasks/25236216-1d77-460c-98a5-c94a833c43a1
Verdict: Malicious activity
Analysis date: March 21, 2024, 09:42:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

51FA9F7E0EE48F9EA9BC231D1DF49556

SHA1:

0B73035D5455489C50413829EEF970C55D91FA71

SHA256:

1BAAB40705FD5ED3B01341FD1EFFAC02803859431D50BD5E8026DAEDD8825DD6

SSDEEP:

98304:Jn2wxNwkrPrf9dEz4n8O/t3ZnY8Axf+Bu+rY3Q+dFDhnI+/rWe6FxkJKU+qNeVe4:xkjr9m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • fpsetup.exe (PID: 1824)
      • FreePDF4.14.EXE.exe (PID: 1836)
      • setup.exe (PID: 3684)
    • Creates a writable file in the system directory

      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
      • InfDefaultInstall.exe (PID: 2968)
    • Registers / Runs the DLL via REGSVR32.EXE

      • fpsetup.exe (PID: 1824)
    • Changes the autorun value in the registry

      • fpsetup.exe (PID: 1824)
      • InfDefaultInstall.exe (PID: 2968)
    • Starts NET.EXE for service management

      • cmd.exe (PID: 2060)
      • cmd.exe (PID: 3776)
      • net.exe (PID: 2488)
      • net.exe (PID: 1860)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
      • InfDefaultInstall.exe (PID: 2968)
      • FreePDF4.14.EXE.exe (PID: 1836)
    • Process drops legitimate windows executable

      • FreePDF4.14.EXE.exe (PID: 1836)
      • fpsetup.exe (PID: 1824)
      • InfDefaultInstall.exe (PID: 2968)
    • Starts a Microsoft application from unusual location

      • FreePDF4.14.EXE.exe (PID: 1836)
    • Creates a software uninstall entry

      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3724)
    • Starts CMD.EXE for commands execution

      • fpsetup.exe (PID: 1824)
      • cmd.exe (PID: 3776)
    • Application launched itself

      • cmd.exe (PID: 3776)
    • Uses RUNDLL32.EXE to load library

      • fpsetup.exe (PID: 1824)
    • Executes as Windows Service

      • spoolsv.exe (PID: 1336)
    • Reads the Internet Settings

      • runonce.exe (PID: 2780)
      • Helper.exe (PID: 2580)
      • freepdf.exe (PID: 3504)
    • Reads security settings of Internet Explorer

      • Helper.exe (PID: 2580)
      • freepdf.exe (PID: 3504)
  • INFO

    • Checks supported languages

      • FreePDF4.14.EXE.exe (PID: 1836)
      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
      • wmpnscfg.exe (PID: 968)
      • fpassist.exe (PID: 2052)
      • Helper.exe (PID: 2580)
      • Helper.exe (PID: 696)
      • freepdf.exe (PID: 3504)
      • fpconfig.exe (PID: 3132)
    • Create files in a temporary directory

      • fpsetup.exe (PID: 1824)
      • FreePDF4.14.EXE.exe (PID: 1836)
      • fpconfig.exe (PID: 3132)
      • freepdf.exe (PID: 3504)
      • fpassist.exe (PID: 2052)
    • Reads the machine GUID from the registry

      • fpsetup.exe (PID: 1824)
      • freepdf.exe (PID: 3504)
      • fpconfig.exe (PID: 3132)
      • fpassist.exe (PID: 2052)
    • Reads the computer name

      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
      • Helper.exe (PID: 2580)
      • freepdf.exe (PID: 3504)
      • wmpnscfg.exe (PID: 968)
    • Creates files in the program directory

      • fpsetup.exe (PID: 1824)
    • Drops the executable file immediately after the start

      • InfDefaultInstall.exe (PID: 2968)
    • Reads the time zone

      • runonce.exe (PID: 2780)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 2780)
    • Manual execution by a user

      • explorer.exe (PID: 3976)
      • wmpnscfg.exe (PID: 968)
      • freepdf.exe (PID: 3504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 MS Cabinet Self-Extractor (WExtract stub) (86.7)
.exe | Win32 Executable MS Visual C++ (generic) (8.9)
.dll | Win32 Dynamic Link Library (generic) (1.8)
.exe | Win32 Executable (generic) (1.2)
.exe | Generic Win/DOS Executable (0.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:10:14 05:50:27+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 26112
InitializedDataSize: 2534400
UninitializedDataSize: -
EntryPoint: 0x67cc
OSVersion: 6.3
ImageVersion: 6.3
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 11.0.9600.16428
ProductVersionNumber: 11.0.9600.16428
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: German
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 11.00.9600.16428 (winblue_gdr.131013-1700)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFileName: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.9600.16428
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
26
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start freepdf4.14.exe.exe helper.exe no specs fpsetup.exe no specs fpsetup.exe helper.exe no specs regsvr32.exe no specs setup.exe rundll32.exe no specs cmd.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs rundll32.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs spoolsv.exe no specs infdefaultinstall.exe runonce.exe no specs grpconv.exe no specs wmpnscfg.exe no specs explorer.exe no specs fpassist.exe no specs freepdf.exe no specs fpconfig.exe no specs fpconfig.exe

Process information

PID
CMD
Path
Indicators
Parent process
696C:\Users\admin\AppData\Local\Temp\IXP000.TMP\Helper.exe waitC:\Users\admin\AppData\Local\Temp\IXP000.TMP\Helper.exeFreePDF4.14.EXE.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
4.00.0063
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\msvbvm50.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
920"C:\Program Files\FreePDF_XP\fpconfig.exe" C:\Program Files\FreePDF_XP\fpconfig.exefreepdf.exe
User:
admin
Company:
.
Integrity Level:
MEDIUM
Description:
Setup for administrative FreePDF settings
Exit code:
3221226540
Version:
4.00.0090
Modules
Images
c:\program files\freepdf_xp\fpconfig.exe
c:\windows\system32\ntdll.dll
968"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1336C:\Windows\System32\spoolsv.exeC:\Windows\System32\spoolsv.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Spooler SubSystem App
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\spoolsv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1572C:\Windows\system32\net1 stop spoolerC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
1824"C:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpsetup.exe" setupC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpsetup.exe
Helper.exe
User:
admin
Company:
shbox
Integrity Level:
HIGH
Description:
FreePDF Setup und Uninstall
Exit code:
0
Version:
4.00.0121
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\fpsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\msvbvm50.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1836"C:\Users\admin\AppData\Local\Temp\FreePDF4.14.EXE.exe" C:\Users\admin\AppData\Local\Temp\FreePDF4.14.EXE.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Win32 Cabinet Self-Extractor
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\users\admin\appdata\local\temp\freepdf4.14.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1860net stop spoolerC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
2052"C:\Program Files\FreePDF_XP\fpassist.exe"C:\Program Files\FreePDF_XP\fpassist.exeHelper.exe
User:
admin
Company:
shbox.de
Integrity Level:
MEDIUM
Description:
FreePDF Assistent für FreePDF3
Exit code:
0
Version:
3.20.0173
Modules
Images
c:\program files\freepdf_xp\fpassist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm50.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2060cmd /c net start spoolerC:\Windows\System32\cmd.exefpsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
5 791
Read events
5 713
Write events
65
Delete events
13

Modification events

(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1824) fpsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP
Operation:writeName:Style
Value:
vista
(PID) Process:(1824) fpsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP
Operation:writeName:gswin32c
Value:
(PID) Process:(1824) fpsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP
Operation:writeName:psDir
Value:
C:\ProgramData\FreePDF\
(PID) Process:(3724) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(3724) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(3724) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
Executable files
67
Suspicious files
12
Text files
49
Unknown types
6

Dropped files

PID
Process
Filename
Type
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\LICENCEtext
MD5:8DE52E24D38622CECD475570DE0AD097
SHA256:1205B859A6FABB0291043C1B2DC880B59EF4CD7072845FD6DD9A2D846F9FFD19
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\FreePDFde.pdfpdf
MD5:2427C24B54FC3D80CC08F5763E9FAA3C
SHA256:C9FDCD8837A2997C6C38ECE104D379F976589431BD30A45038AEABFFA198ABE6
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpConfig.exeexecutable
MD5:E41D71017C83786EFE740B28A8D25D4D
SHA256:E82E4CC308AFEA6486122C6CED69DA2FBA309CFFED1CE8077CFB3D8F77E584A9
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\unredmon.exeexecutable
MD5:2E8C8E9AAE4216A6BA20848F8260BCA6
SHA256:35E2DB103FB458D21B64FC9B3F072AC4979901BEBCD0F69A1AC871C8D8E40FE7
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\unredmon64.exeexecutable
MD5:E6B872F96737A098EE63AB0FDAC30A39
SHA256:14D63C1088F853E24A6807E69F8D857EC9987C24BD14D3A1C9CAE2F7BBEA63D6
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\redrun.exeexecutable
MD5:262203A62F5B2A5FF18E139B0BE0DC8B
SHA256:91CC9EF8F16C8CA8BA4E5B311D5A7581201F6F7BFE0C86CFBCD0D324E355873F
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\setup.exeexecutable
MD5:4C383F06D906A1A77EB90557F9C180BE
SHA256:08EA1EA8255A77ED93245D6C14A37D6396C20F5E0ED627A56FD06BDD6CE67E0A
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\setup64.exeexecutable
MD5:A5B5A716D6D2AB1E677D7E09097D8F7F
SHA256:3A0C692C32D33083844639B66EF54A2CA5D012CF51EC32A5663CDBA79C95905E
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\eBook.fpptext
MD5:39A3586215BF29CFADF1C9E7B968754A
SHA256:C20D336283079BEBDD4074A5F625BE3ED8135B5D8D4AB0886ADE6E99763DB65A
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\FreePDF.exeexecutable
MD5:C353931D67573F33AB8D419866304447
SHA256:7304B9866B213FB933EEE4523140F2376BEF68C976618BDA1D91E5A715D6CABF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info