File name:

FreePDF4.14.EXE

Full analysis: https://app.any.run/tasks/25236216-1d77-460c-98a5-c94a833c43a1
Verdict: Malicious activity
Analysis date: March 21, 2024, 09:42:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

51FA9F7E0EE48F9EA9BC231D1DF49556

SHA1:

0B73035D5455489C50413829EEF970C55D91FA71

SHA256:

1BAAB40705FD5ED3B01341FD1EFFAC02803859431D50BD5E8026DAEDD8825DD6

SSDEEP:

98304:Jn2wxNwkrPrf9dEz4n8O/t3ZnY8Axf+Bu+rY3Q+dFDhnI+/rWe6FxkJKU+qNeVe4:xkjr9m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FreePDF4.14.EXE.exe (PID: 1836)
      • setup.exe (PID: 3684)
      • fpsetup.exe (PID: 1824)
    • Registers / Runs the DLL via REGSVR32.EXE

      • fpsetup.exe (PID: 1824)
    • Creates a writable file in the system directory

      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
      • InfDefaultInstall.exe (PID: 2968)
    • Changes the autorun value in the registry

      • fpsetup.exe (PID: 1824)
      • InfDefaultInstall.exe (PID: 2968)
    • Starts NET.EXE for service management

      • cmd.exe (PID: 3776)
      • net.exe (PID: 1860)
      • cmd.exe (PID: 2060)
      • net.exe (PID: 2488)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • FreePDF4.14.EXE.exe (PID: 1836)
      • fpsetup.exe (PID: 1824)
      • InfDefaultInstall.exe (PID: 2968)
    • Starts a Microsoft application from unusual location

      • FreePDF4.14.EXE.exe (PID: 1836)
    • Executable content was dropped or overwritten

      • FreePDF4.14.EXE.exe (PID: 1836)
      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
      • InfDefaultInstall.exe (PID: 2968)
    • Reads the Internet Settings

      • Helper.exe (PID: 2580)
      • runonce.exe (PID: 2780)
      • freepdf.exe (PID: 3504)
    • Reads security settings of Internet Explorer

      • Helper.exe (PID: 2580)
      • freepdf.exe (PID: 3504)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3724)
    • Creates a software uninstall entry

      • setup.exe (PID: 3684)
      • fpsetup.exe (PID: 1824)
    • Uses RUNDLL32.EXE to load library

      • fpsetup.exe (PID: 1824)
    • Starts CMD.EXE for commands execution

      • fpsetup.exe (PID: 1824)
      • cmd.exe (PID: 3776)
    • Application launched itself

      • cmd.exe (PID: 3776)
    • Executes as Windows Service

      • spoolsv.exe (PID: 1336)
  • INFO

    • Create files in a temporary directory

      • fpsetup.exe (PID: 1824)
      • FreePDF4.14.EXE.exe (PID: 1836)
      • freepdf.exe (PID: 3504)
      • fpconfig.exe (PID: 3132)
      • fpassist.exe (PID: 2052)
    • Reads the computer name

      • fpsetup.exe (PID: 1824)
      • setup.exe (PID: 3684)
      • wmpnscfg.exe (PID: 968)
      • freepdf.exe (PID: 3504)
      • Helper.exe (PID: 2580)
    • Checks supported languages

      • Helper.exe (PID: 2580)
      • fpsetup.exe (PID: 1824)
      • Helper.exe (PID: 696)
      • setup.exe (PID: 3684)
      • wmpnscfg.exe (PID: 968)
      • freepdf.exe (PID: 3504)
      • fpconfig.exe (PID: 3132)
      • fpassist.exe (PID: 2052)
      • FreePDF4.14.EXE.exe (PID: 1836)
    • Reads the machine GUID from the registry

      • fpsetup.exe (PID: 1824)
      • fpassist.exe (PID: 2052)
      • fpconfig.exe (PID: 3132)
      • freepdf.exe (PID: 3504)
    • Creates files in the program directory

      • fpsetup.exe (PID: 1824)
    • Drops the executable file immediately after the start

      • InfDefaultInstall.exe (PID: 2968)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 2780)
    • Manual execution by a user

      • explorer.exe (PID: 3976)
      • wmpnscfg.exe (PID: 968)
      • freepdf.exe (PID: 3504)
    • Reads the time zone

      • runonce.exe (PID: 2780)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 MS Cabinet Self-Extractor (WExtract stub) (86.7)
.exe | Win32 Executable MS Visual C++ (generic) (8.9)
.dll | Win32 Dynamic Link Library (generic) (1.8)
.exe | Win32 Executable (generic) (1.2)
.exe | Generic Win/DOS Executable (0.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:10:14 05:50:27+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 26112
InitializedDataSize: 2534400
UninitializedDataSize: -
EntryPoint: 0x67cc
OSVersion: 6.3
ImageVersion: 6.3
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 11.0.9600.16428
ProductVersionNumber: 11.0.9600.16428
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: German
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 11.00.9600.16428 (winblue_gdr.131013-1700)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFileName: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.9600.16428
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
26
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start freepdf4.14.exe.exe helper.exe no specs fpsetup.exe no specs fpsetup.exe helper.exe no specs regsvr32.exe no specs setup.exe rundll32.exe no specs cmd.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs rundll32.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs spoolsv.exe no specs infdefaultinstall.exe runonce.exe no specs grpconv.exe no specs wmpnscfg.exe no specs explorer.exe no specs fpassist.exe no specs freepdf.exe no specs fpconfig.exe no specs fpconfig.exe

Process information

PID
CMD
Path
Indicators
Parent process
696C:\Users\admin\AppData\Local\Temp\IXP000.TMP\Helper.exe waitC:\Users\admin\AppData\Local\Temp\IXP000.TMP\Helper.exeFreePDF4.14.EXE.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
4.00.0063
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\msvbvm50.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
920"C:\Program Files\FreePDF_XP\fpconfig.exe" C:\Program Files\FreePDF_XP\fpconfig.exefreepdf.exe
User:
admin
Company:
.
Integrity Level:
MEDIUM
Description:
Setup for administrative FreePDF settings
Exit code:
3221226540
Version:
4.00.0090
Modules
Images
c:\program files\freepdf_xp\fpconfig.exe
c:\windows\system32\ntdll.dll
968"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1336C:\Windows\System32\spoolsv.exeC:\Windows\System32\spoolsv.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Spooler SubSystem App
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\spoolsv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1572C:\Windows\system32\net1 stop spoolerC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
1824"C:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpsetup.exe" setupC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpsetup.exe
Helper.exe
User:
admin
Company:
shbox
Integrity Level:
HIGH
Description:
FreePDF Setup und Uninstall
Exit code:
0
Version:
4.00.0121
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\fpsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\msvbvm50.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1836"C:\Users\admin\AppData\Local\Temp\FreePDF4.14.EXE.exe" C:\Users\admin\AppData\Local\Temp\FreePDF4.14.EXE.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Win32 Cabinet Self-Extractor
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\users\admin\appdata\local\temp\freepdf4.14.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1860net stop spoolerC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
2052"C:\Program Files\FreePDF_XP\fpassist.exe"C:\Program Files\FreePDF_XP\fpassist.exeHelper.exe
User:
admin
Company:
shbox.de
Integrity Level:
MEDIUM
Description:
FreePDF Assistent für FreePDF3
Exit code:
0
Version:
3.20.0173
Modules
Images
c:\program files\freepdf_xp\fpassist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm50.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2060cmd /c net start spoolerC:\Windows\System32\cmd.exefpsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
5 791
Read events
5 713
Write events
65
Delete events
13

Modification events

(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2580) Helper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1824) fpsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP
Operation:writeName:Style
Value:
vista
(PID) Process:(1824) fpsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP
Operation:writeName:gswin32c
Value:
(PID) Process:(1824) fpsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\shbox\FreePdfXP
Operation:writeName:psDir
Value:
C:\ProgramData\FreePDF\
(PID) Process:(3724) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(3724) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(3724) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
Executable files
67
Suspicious files
12
Text files
49
Unknown types
6

Dropped files

PID
Process
Filename
Type
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpAssist.exeexecutable
MD5:2B282A4050FE3B4B70EF9E3070BBFF78
SHA256:019B667781F5CE411AEB569EAA4095FA2B9942E43A6A1DFC6EEBB2DA214131FE
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpmailer.exeexecutable
MD5:959623BB4D53806AFC595D7D76BCBE05
SHA256:A944A2244E61BB594955EB7DDFDE799A098849281412BC0A42B100F358CB1DE4
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpjoin.exeexecutable
MD5:75F60F658935768BFCE9D15429E4CAA4
SHA256:67192A649DDA0D6C56ED1F2942656DCFFDA7AE0141A8C21114EA767C2725CBB5
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\FreePDFde.pdfpdf
MD5:2427C24B54FC3D80CC08F5763E9FAA3C
SHA256:C9FDCD8837A2997C6C38ECE104D379F976589431BD30A45038AEABFFA198ABE6
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\redpr.exeexecutable
MD5:8166A224BCE403856D9820A3B95FEA64
SHA256:FB42F98A56817B34C8119AAC881A204E1D9FC4007866174FC6115EA885F9E3CA
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\setup.exeexecutable
MD5:4C383F06D906A1A77EB90557F9C180BE
SHA256:08EA1EA8255A77ED93245D6C14A37D6396C20F5E0ED627A56FD06BDD6CE67E0A
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\unredmon.exeexecutable
MD5:2E8C8E9AAE4216A6BA20848F8260BCA6
SHA256:35E2DB103FB458D21B64FC9B3F072AC4979901BEBCD0F69A1AC871C8D8E40FE7
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fpConfig.exeexecutable
MD5:E41D71017C83786EFE740B28A8D25D4D
SHA256:E82E4CC308AFEA6486122C6CED69DA2FBA309CFFED1CE8077CFB3D8F77E584A9
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\unredmon64.exeexecutable
MD5:E6B872F96737A098EE63AB0FDAC30A39
SHA256:14D63C1088F853E24A6807E69F8D857EC9987C24BD14D3A1C9CAE2F7BBEA63D6
1836FreePDF4.14.EXE.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\FreePDFen.pdfpdf
MD5:E9FF79C25C569FBB3D7CDCF70581D998
SHA256:2142E691E72197F1B9A9C6494B191FCC4AE48EF4D172DC3A2BC291ECE7D1B3EC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info