| File name: | pdfalcon.exe |
| Full analysis: | https://app.any.run/tasks/47a71ff5-8aa6-4fd7-ac36-e70ed9a17868 |
| Verdict: | Malicious activity |
| Analysis date: | February 05, 2024, 11:52:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 3A5C8A22531484CB9735135397A0F252 |
| SHA1: | C9A8F3295F5B64310951C21DCDD93EA1E77D98CF |
| SHA256: | 3E5735B42CD947280043E8D4746CE647498405076EEBA26A15F7D6126FD8E6A7 |
| SSDEEP: | 49152:A/8xt9PK2/KV9Y8NyW565Y8NyW56Sh3lgKQm3zR56STGe0KGQnsY8NyW56pY8NyL:g+t9yD9Y80W565Y80W56SDgKQuGSTGeg |
| .exe | | | Win64 Executable (generic) (61.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.6) |
| .exe | | | Win32 Executable (generic) (10) |
| .exe | | | Win16/32 Executable Delphi generic (4.6) |
| .exe | | | Generic Win/DOS Executable (4.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2067:09:20 03:54:02+02:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 841216 |
| InitializedDataSize: | 154112 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xcf4f6 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.0.2.4 |
| ProductVersionNumber: | 3.0.2.4 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | PDFalcon |
| FileVersion: | 3.0.2.4 |
| InternalName: | PDFalcon.exe |
| LegalCopyright: | Copyright © 2022 |
| LegalTrademarks: | - |
| OriginalFileName: | PDFalcon.exe |
| ProductName: | PDFalcon |
| ProductVersion: | 3.0.2.4 |
| AssemblyVersion: | 3.0.2.4 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 292 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --mojo-platform-channel-handle=1140 --field-trial-handle=1344,i,3122404166346748226,9891479083778670569,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 968 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_collections.mojom.CollectionsDataManager --lang=en-US --service-sandbox-type=collections --mojo-platform-channel-handle=1456 --field-trial-handle=1344,i,3122404166346748226,9891479083778670569,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1028 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" http://lookup.seekitfalc.com?f74dfa0499dceec34125c2be258f9c6f=H1xAXFNHXlxaWVQNEQQwBw9cQ1pZQ1deWVRAXlhDXFlbV1QJDB0LU11WFAgEFg1aRldBXVJZW1paB19UBRdeQ19QFwhYTFtfUgJEW0cXBw8FDxcAPh0LU1s%253D | C:\Program Files\Microsoft\Edge\Application\msedge.exe | pdfalcon.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1040 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1280 --field-trial-handle=1344,i,3122404166346748226,9891479083778670569,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1196 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=1376 --field-trial-handle=1344,i,533907994053699468,11358961188309679392,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1380 | "C:\Users\admin\AppData\Local\Temp\pdfalcon.exe" | C:\Users\admin\AppData\Local\Temp\pdfalcon.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: PDFalcon Exit code: 3221225547 Version: 3.0.2.4 Modules
| |||||||||||||||
| 1432 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1532 --field-trial-handle=1344,i,3122404166346748226,9891479083778670569,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1540 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --instant-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2172 --field-trial-handle=1344,i,533907994053699468,11358961188309679392,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1656 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument microsoft-edge: | C:\Program Files\Microsoft\Edge\Application\msedge.exe | pdfalcon.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1696 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=108 --field-trial-handle=1344,i,3122404166346748226,9891479083778670569,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (1380) pdfalcon.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1380) pdfalcon.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1380) pdfalcon.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1380) pdfalcon.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1380) pdfalcon.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1380) pdfalcon.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: Explorer.EXE | |||
| (PID) Process: | (1380) pdfalcon.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1380) pdfalcon.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1380) pdfalcon.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | AutoMetadataCurrentDownloadCount |
Value: 0 | |||
| (PID) Process: | (1380) pdfalcon.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | AutoMetadataCurrent500ServerErrorCount |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1380 | pdfalcon.exe | C:\Users\admin\AppData\Local\Temp\PDFalcon\installing.gif | image | |
MD5:BF5EC1EB84820DDE9C4F8541BF5B3B50 | SHA256:D47A7398D08DAA4C6CDD002D84C8EC4B6DE2B3E42A1BA97D6EA8674ACD2BC26C | |||
| 1380 | pdfalcon.exe | C:\Users\admin\AppData\Local\Temp\PDFalcon\jsonassets.json | binary | |
MD5:04EFF338234A1664173F4BA286430ED6 | SHA256:3921DAE2C37879CD6DCF901640EE5D433E0EDA251768F119EA6C2A24D2E97082 | |||
| 1380 | pdfalcon.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:097DE13072E5486A51EA087B9E30B9C5 | SHA256:1673E0A11D85E30455CACA0C9DC0BFA427F4BE782D38FDBFE2B04A0A44B23E93 | |||
| 1380 | pdfalcon.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C5C8CC0A7FE31816B4641D0465402560 | binary | |
MD5:C42C675C24E4428223C8D175CE41CD1C | SHA256:8D80B1C23DB274CC3FC347EDFECF16A536BE40D4D6F5BC82223CA787C625467A | |||
| 1380 | pdfalcon.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C5C8CC0A7FE31816B4641D0465402560 | binary | |
MD5:E94FB54871208C00DF70F708AC47085B | SHA256:7B9D553E1C92CB6E8803E137F4F287D4363757F5D44B37D52F9FCA22FB97DF86 | |||
| 1380 | pdfalcon.exe | C:\Users\admin\AppData\Local\Temp\Tar3984.tmp | binary | |
MD5:9C0C641C06238516F27941AA1166D427 | SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F | |||
| 1028 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1666ec.TMP | — | |
MD5:— | SHA256:— | |||
| 1380 | pdfalcon.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 1380 | pdfalcon.exe | C:\Users\admin\AppData\Local\Temp\PDFalcon\jsonuiclosewindow.json | binary | |
MD5:F13E812B7D03FB57416C53CA815C738A | SHA256:B01AA23148BFCED36883A0B5FBFD314C380108BE89A8B55578C53D423753499C | |||
| 1028 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1380 | pdfalcon.exe | GET | 200 | 104.18.20.226:80 | http://secure.globalsign.com/cacert/codesigningrootr45.crt | unknown | binary | 1.37 Kb | unknown |
1432 | msedge.exe | GET | 301 | 45.76.20.180:80 | http://falcon-app.com/thankyou/?tyid=67fdebb4-6313-441f-8dc1-41ed98419c67 | unknown | text | 17 b | unknown |
1380 | pdfalcon.exe | GET | 200 | 23.32.238.232:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c5559cb6f02dcccb | unknown | compressed | 65.2 Kb | unknown |
3056 | msedge.exe | GET | 301 | 138.197.40.235:80 | http://lookup.seekitfalc.com/?f74dfa0499dceec34125c2be258f9c6f=H1xAXFNHXlxaWVQNEQQwBw9cQ1pZQ1deWVRAXlhDXFlbV1QJDB0LU11WFAgEFg1aRldBXVJZW1paB19UBRdeQ19QFwhYTFtfUgJEW0cXBw8FDxcAPh0LU1s%253D | unknown | text | 17 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1380 | pdfalcon.exe | 104.18.20.226:80 | secure.globalsign.com | CLOUDFLARENET | — | shared |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1380 | pdfalcon.exe | 23.32.238.232:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1380 | pdfalcon.exe | 165.227.211.116:443 | por.pdfalcon.com | DIGITALOCEAN-ASN | US | unknown |
3056 | msedge.exe | 13.107.43.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1028 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
3056 | msedge.exe | 131.253.33.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3056 | msedge.exe | 138.197.40.235:80 | lookup.seekitfalc.com | DIGITALOCEAN-ASN | US | unknown |
Domain | IP | Reputation |
|---|---|---|
secure.globalsign.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
por.pdfalcon.com |
| unknown |
config.edge.skype.com |
| whitelisted |
lookup.seekitfalc.com |
| unknown |
edge.microsoft.com |
| whitelisted |
ajax.googleapis.com |
| whitelisted |
www.bing.com |
| whitelisted |
nleditor.osi.office.net |
| whitelisted |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
msedge.exe | [0205/115425.209:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)
|