File name:

PDFFlex-v4.102.1215.0.msi

Full analysis: https://app.any.run/tasks/23d17151-0a2a-4a8a-a351-4edfcd370681
Verdict: Malicious activity
Analysis date: February 21, 2025, 13:19:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: PDFFlex, Author: PDFFlex.io, Keywords: Installer, MSI, Database, Comments: A base dados do instalador contm a lgica e os dados necessrios para instalar o PDFFlex., Create Time/Date: Mon May 27 08:55:12 2024, Name of Creating Application: PDFFlex, Security: 0, Template: ;1033, Last Saved By: ;1046, Revision Number: {A101E974-EF6E-40A4-8532-07B644806946}4.102.1215.0;{A101E974-EF6E-40A4-8532-07B644806946}4.102.1215.0;{50C54027-847F-4B86-849A-9C02C888EE0B}, Number of Pages: 450, Number of Characters: 63
MD5:

F1C8A85FCE3AEC53C4B2BB45452D453A

SHA1:

9476A698165F4C3E89D370BD3135108D8D3DD476

SHA256:

2F9F2BB7999A0FA67A92203A5AE4E7DF47818835845BC170C50063CE333FE92B

SSDEEP:

98304:r9ISotSpkqN/2Wgx0xaAW9o+9DE+mzSE5lIP4GASazPtiG6CPUF0csMof+iZZjDJ:iNGPJx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes powershell execution policy (Bypass)

      • msiexec.exe (PID: 2244)
      • msiexec.exe (PID: 1280)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 856)
      • powershell.exe (PID: 3072)
      • powershell.exe (PID: 3628)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 1136)
  • SUSPICIOUS

    • Reads the Internet Settings

      • msiexec.exe (PID: 1936)
      • powershell.exe (PID: 3072)
      • msiexec.exe (PID: 1280)
      • powershell.exe (PID: 3628)
      • msiexec.exe (PID: 2244)
    • The process executes Powershell scripts

      • msiexec.exe (PID: 2244)
      • msiexec.exe (PID: 1280)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 1136)
    • The process bypasses the loading of PowerShell profile settings

      • msiexec.exe (PID: 2244)
      • msiexec.exe (PID: 1280)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3104)
    • The process hide an interactive prompt from the user

      • msiexec.exe (PID: 2244)
      • msiexec.exe (PID: 1280)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 1136)
      • msiexec.exe (PID: 1280)
    • Starts POWERSHELL.EXE for commands execution

      • msiexec.exe (PID: 2244)
      • msiexec.exe (PID: 1280)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 1136)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 1280)
      • msiexec.exe (PID: 2244)
    • Node.exe was dropped

      • msiexec.exe (PID: 1280)
  • INFO

    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 1936)
      • powershell.exe (PID: 856)
      • powershell.exe (PID: 3072)
      • powershell.exe (PID: 3628)
    • An automatically generated document

      • msiexec.exe (PID: 1936)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 1936)
      • msiexec.exe (PID: 1136)
      • msiexec.exe (PID: 1280)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1828)
      • notepad.exe (PID: 2720)
      • notepad.exe (PID: 664)
    • Create files in a temporary directory

      • msiexec.exe (PID: 1936)
      • msiexec.exe (PID: 2244)
      • powershell.exe (PID: 856)
      • msiexec.exe (PID: 1280)
      • msiexec.exe (PID: 1136)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1828)
      • msiexec.exe (PID: 1136)
      • msiexec.exe (PID: 2244)
      • msiexec.exe (PID: 1280)
      • PDFFlex.exe (PID: 3860)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1828)
      • msiexec.exe (PID: 1136)
      • msiexec.exe (PID: 2244)
      • msiexec.exe (PID: 1280)
    • Reads the software policy settings

      • msiexec.exe (PID: 1936)
      • msiexec.exe (PID: 1136)
      • msiexec.exe (PID: 1280)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1136)
      • msiexec.exe (PID: 2244)
      • msiexec.exe (PID: 1280)
    • Application launched itself

      • msiexec.exe (PID: 1136)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1936)
      • msiexec.exe (PID: 1136)
      • msiexec.exe (PID: 1280)
    • Reads Environment values

      • msiexec.exe (PID: 2244)
      • msiexec.exe (PID: 1280)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 856)
      • powershell.exe (PID: 3072)
      • powershell.exe (PID: 3628)
    • The sample compiled with english language support

      • msiexec.exe (PID: 1936)
      • msiexec.exe (PID: 1136)
      • msiexec.exe (PID: 1280)
    • Disables trace logs

      • powershell.exe (PID: 3072)
      • powershell.exe (PID: 3628)
    • Checks proxy server information

      • msiexec.exe (PID: 1280)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {7832C14D-212E-47F1-A394-F04540F58CE1}
Words: 10
Subject: PDFFlex
Author: PDFFlex.io
LastModifiedBy: -
Software: PDFFlex
Template: ;1033,1046,3082,1055
Comments: PDFFlex 4.102.1215.0
Title: Installation Database
Keywords: Installer, MSI, Database
CreateDate: 2024:05:27 08:55:29
ModifyDate: 2024:05:27 08:55:29
LastPrinted: 2024:05:27 08:55:29
Pages: 450
Characters: 63
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe wmpnscfg.exe no specs msiexec.exe msiexec.exe no specs powershell.exe no specs vssvc.exe no specs msiexec.exe powershell.exe powershell.exe pdfflex.exe notepad.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
664"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\PDFFlex\PDFFlex.iniC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
856 -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Local\Temp\pssC364.ps1" -propFile "C:\Users\admin\AppData\Local\Temp\msiC2B5.txt" -scriptFile "C:\Users\admin\AppData\Local\Temp\scrC2B6.ps1" -scriptArgsFile "C:\Users\admin\AppData\Local\Temp\scrC334.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1136C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1280C:\Windows\system32\MsiExec.exe -Embedding 495C01009FD7242234B251A0172BD017C:\Windows\System32\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1828"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1936"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\Downloads\PDFFlex-v4.102.1215.0.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2244C:\Windows\system32\MsiExec.exe -Embedding 245E12C756D0BAB771DF1C318A434615 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2720"C:\Windows\System32\Notepad.exe" C:\Users\admin\AppData\Local\PDFFlex\update.jsC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3072 -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Local\Temp\pss4C2C.ps1" -propFile "C:\Users\admin\AppData\Local\Temp\msi4C19.txt" -scriptFile "C:\Users\admin\AppData\Local\Temp\scr4C1A.ps1" -scriptArgsFile "C:\Users\admin\AppData\Local\Temp\scr4C1B.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3104C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
24 865
Read events
24 500
Write events
341
Delete events
24

Modification events

(PID) Process:(1936) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1136) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000007EAA83486384DB0170040000280C0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1136) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000007EAA83486384DB0170040000280C0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1136) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
75
(PID) Process:(1136) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000B0FBF9496384DB017004000094020000E8030000010000000000000000000000682646A32E3D274AA8F388C49F551AF80000000000000000
(PID) Process:(1136) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000005699F7496384DB0170040000280C0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3104) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DA700F4A6384DB01200C000038040000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3104) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DA700F4A6384DB01200C00008C010000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3104) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DA700F4A6384DB01200C000014040000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3104) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DA700F4A6384DB01200C000090050000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
22
Suspicious files
52
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
2244msiexec.exeC:\Users\admin\AppData\Local\Temp\msiC2B5.txt
MD5:
SHA256:
2244msiexec.exeC:\Users\admin\AppData\Local\Temp\scrC2B6.ps1
MD5:
SHA256:
2244msiexec.exeC:\Users\admin\AppData\Local\Temp\scrC334.txt
MD5:
SHA256:
2244msiexec.exeC:\Users\admin\AppData\Local\Temp\pssC364.ps1
MD5:
SHA256:
1136msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1136msiexec.exeC:\Windows\Installer\1145d0.msi
MD5:
SHA256:
1280msiexec.exeC:\Users\admin\AppData\Local\Temp\msi4C19.txt
MD5:
SHA256:
1280msiexec.exeC:\Users\admin\AppData\Local\Temp\scr4C1A.ps1
MD5:
SHA256:
1280msiexec.exeC:\Users\admin\AppData\Local\Temp\scr4C1B.txt
MD5:
SHA256:
1280msiexec.exeC:\Users\admin\AppData\Local\Temp\pss4C2C.ps1
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
11
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1936
msiexec.exe
GET
200
151.101.66.133:80
http://secure.globalsign.com/cacert/codesigningrootr45.crt
US
binary
1.37 Kb
whitelisted
3072
powershell.exe
POST
200
52.85.65.128:80
http://d1jorhhovk7rc8.cloudfront.net/
US
binary
19 b
whitelisted
1280
msiexec.exe
GET
200
18.173.189.168:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
binary
1.52 Kb
whitelisted
3628
powershell.exe
POST
200
52.85.65.128:80
http://d1jorhhovk7rc8.cloudfront.net/
US
binary
19 b
whitelisted
1280
msiexec.exe
GET
200
18.173.189.168:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
US
binary
1.40 Kb
whitelisted
1280
msiexec.exe
GET
200
108.138.34.140:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
binary
2.02 Kb
whitelisted
1936
msiexec.exe
GET
200
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?42f62a370965a9cc
US
compressed
70.2 Kb
whitelisted
1280
msiexec.exe
GET
200
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1addb934cad116d4
US
compressed
4.65 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1936
msiexec.exe
151.101.66.133:80
secure.globalsign.com
FASTLY
US
whitelisted
1936
msiexec.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
whitelisted
4
System
192.168.100.255:138
whitelisted
3072
powershell.exe
52.85.65.128:80
d1jorhhovk7rc8.cloudfront.net
AMAZON-02
US
whitelisted
1280
msiexec.exe
54.239.192.106:443
dn0diw4x4ljz4.cloudfront.net
AMAZON-02
US
whitelisted
1280
msiexec.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
whitelisted
1280
msiexec.exe
108.138.34.140:80
o.ss2.us
AMAZON-02
US
whitelisted
1280
msiexec.exe
18.173.189.168:80
ocsp.rootg2.amazontrust.com
US
whitelisted
3628
powershell.exe
52.85.65.128:80
d1jorhhovk7rc8.cloudfront.net
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.46
whitelisted
secure.globalsign.com
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
  • 151.101.2.133
whitelisted
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
d1jorhhovk7rc8.cloudfront.net
  • 52.85.65.128
  • 52.85.65.56
  • 52.85.65.63
  • 52.85.65.40
whitelisted
dn0diw4x4ljz4.cloudfront.net
  • 54.239.192.106
  • 54.239.192.136
  • 54.239.192.208
  • 54.239.192.165
whitelisted
o.ss2.us
  • 108.138.34.140
  • 108.138.34.188
  • 108.138.34.92
  • 108.138.34.63
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.173.189.168
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.173.189.168
whitelisted

Threats

No threats detected
Process
Message
PDFFlex.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.