File name:

pdftk_free-2.02-win-setup.exe

Full analysis: https://app.any.run/tasks/b877426d-042f-4af1-98db-784cff27eba6
Verdict: Malicious activity
Analysis date: February 28, 2024, 20:33:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A989BC6260363205A7D13A5DEDD8594C

SHA1:

B96937B422970F1F8C3C8413929EBAD3E6E747FD

SHA256:

6D9CD2CBDFF1B00A1C6C84335DCF1199AD65519CFA782C3A631C32B1144EB4C9

SSDEEP:

98304:Zzi8B829qomvXalnlqyue9mvnFX8kesq5Xnua3:Z5B8Do8qhYmQFXqsq5XuC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • pdftk_free-2.02-win-setup.exe (PID: 3700)
      • pdftk_free-2.02-win-setup.exe (PID: 2840)
      • pdftk_free-2.02-win-setup.tmp (PID: 3944)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • pdftk_free-2.02-win-setup.exe (PID: 3700)
      • pdftk_free-2.02-win-setup.tmp (PID: 3944)
      • pdftk_free-2.02-win-setup.exe (PID: 2840)
    • Reads the Windows owner or organization settings

      • pdftk_free-2.02-win-setup.tmp (PID: 3944)
    • Reads the Internet Settings

      • PdftkXp.exe (PID: 2304)
    • Process drops legitimate windows executable

      • pdftk_free-2.02-win-setup.tmp (PID: 3944)
  • INFO

    • Checks supported languages

      • pdftk_free-2.02-win-setup.exe (PID: 3700)
      • pdftk_free-2.02-win-setup.tmp (PID: 3656)
      • pdftk_free-2.02-win-setup.exe (PID: 2840)
      • pdftk_free-2.02-win-setup.tmp (PID: 3944)
      • PdftkXp.exe (PID: 2304)
      • pdftk.exe (PID: 2740)
    • Create files in a temporary directory

      • pdftk_free-2.02-win-setup.exe (PID: 3700)
      • pdftk_free-2.02-win-setup.exe (PID: 2840)
      • pdftk_free-2.02-win-setup.tmp (PID: 3944)
    • Reads the computer name

      • pdftk_free-2.02-win-setup.tmp (PID: 3656)
      • pdftk_free-2.02-win-setup.tmp (PID: 3944)
      • PdftkXp.exe (PID: 2304)
    • Creates files in the program directory

      • pdftk_free-2.02-win-setup.tmp (PID: 3944)
    • Application launched itself

      • msedge.exe (PID: 2340)
    • Manual execution by a user

      • pdftk.exe (PID: 2740)
    • Creates a software uninstall entry

      • pdftk_free-2.02-win-setup.tmp (PID: 3944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:10:09 08:48:22+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 60416
InitializedDataSize: 266240
UninitializedDataSize: -
EntryPoint: 0xf3bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: PDF Labs
FileDescription: PDFtk - The PDF Toolkit Setup
FileVersion:
LegalCopyright: Copyright 2003-2013 Steward and Lee, LLC
ProductName: PDFtk - The PDF Toolkit
ProductVersion: 2.02
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
22
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start pdftk_free-2.02-win-setup.exe pdftk_free-2.02-win-setup.tmp no specs pdftk_free-2.02-win-setup.exe pdftk_free-2.02-win-setup.tmp pdftkxp.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs pdftk.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1004 --field-trial-handle=1268,i,7514724288084114744,7126418389453028939,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
696"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1620 --field-trial-handle=1268,i,7514724288084114744,7126418389453028939,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1824"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1436 --field-trial-handle=1268,i,7514724288084114744,7126418389453028939,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2120"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6bcdf598,0x6bcdf5a8,0x6bcdf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2304"C:\Program Files\PDFtk\bin\PdftkXp.exe"C:\Program Files\PDFtk\bin\PdftkXp.exepdftk_free-2.02-win-setup.tmp
User:
admin
Company:
PDF Labs
Integrity Level:
MEDIUM
Description:
Easily merge, split, rotate, watermark, stamp or secure your PDFs.
Exit code:
0
Version:
2.0.2
Modules
Images
c:\program files\pdftk\bin\pdftkxp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
2324"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2496 --field-trial-handle=1268,i,7514724288084114744,7126418389453028939,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2340"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.pdflabs.com/tools/pdftk-pro/C:\Program Files\Microsoft\Edge\Application\msedge.exe
PdftkXp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2348"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3872 --field-trial-handle=1268,i,7514724288084114744,7126418389453028939,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2404"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3832 --field-trial-handle=1268,i,7514724288084114744,7126418389453028939,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2468"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3476 --field-trial-handle=1268,i,7514724288084114744,7126418389453028939,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
6 032
Read events
5 945
Write events
75
Delete events
12

Modification events

(PID) Process:(3944) pdftk_free-2.02-win-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
680F0000CEB7D87A856ADA01
(PID) Process:(3944) pdftk_free-2.02-win-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
DB2F78E86EF2561FD5093B0317E72D99EE982FF9373CE603ECF464D27B58B475
(PID) Process:(3944) pdftk_free-2.02-win-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3944) pdftk_free-2.02-win-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\PDFtk\bin\libiconv2.dll
(PID) Process:(3944) pdftk_free-2.02-win-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
6AD19EBBBCA4981369CB1EEB4EF8453F3C9D4B407D2AD10D28ACCAB73EB0C31A
(PID) Process:(3944) pdftk_free-2.02-win-setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C65EA7B8-FC21-4896-AD44-9CE952BB1255}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.2 (u)
(PID) Process:(3944) pdftk_free-2.02-win-setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C65EA7B8-FC21-4896-AD44-9CE952BB1255}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\PDFtk
(PID) Process:(3944) pdftk_free-2.02-win-setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C65EA7B8-FC21-4896-AD44-9CE952BB1255}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\PDFtk\
(PID) Process:(3944) pdftk_free-2.02-win-setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C65EA7B8-FC21-4896-AD44-9CE952BB1255}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
PDFtk - The PDF Toolkit
(PID) Process:(3944) pdftk_free-2.02-win-setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C65EA7B8-FC21-4896-AD44-9CE952BB1255}_is1
Operation:writeName:Inno Setup: No Icons
Value:
1
Executable files
12
Suspicious files
43
Text files
108
Unknown types
20

Dropped files

PID
Process
Filename
Type
3944pdftk_free-2.02-win-setup.tmpC:\Program Files\PDFtk\unins000.exeexecutable
MD5:FA3811C9B4F4DB4B8E3EC1A2AA0DF5C9
SHA256:890DB97864F61DCBB9A0E64FE26F2CB6F0B4DDDB87C8EF4102306FCFA6726096
3944pdftk_free-2.02-win-setup.tmpC:\Program Files\PDFtk\bin\libiconv2.dllexecutable
MD5:FD1DC6C680299A2ED1EEDCC3EABDA601
SHA256:CB016E794D3311C71F21D87803E10A0E1133995F62A485EB37B321CD9B9E1087
3944pdftk_free-2.02-win-setup.tmpC:\Program Files\PDFtk\bin\PdftkXp.exeexecutable
MD5:F22B4517223F1E5AD973C9BEFD327FE4
SHA256:687CCFC00C7C25366C6D876B5CE600B46249135F4183C6DF9F9A4CB1350B708E
3944pdftk_free-2.02-win-setup.tmpC:\Program Files\PDFtk\is-JK5SV.tmpimage
MD5:D511D05DA344F48621CF89582AC0700D
SHA256:4030AC600263FDDA6223DB1894316B757F5F98A16E9393FB30E71E5A8459910E
3944pdftk_free-2.02-win-setup.tmpC:\Users\admin\AppData\Local\Temp\is-TPNUF.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3944pdftk_free-2.02-win-setup.tmpC:\Program Files\PDFtk\bin\PdftkXp.chmchm
MD5:FF04B2CAEF0C8C93C75949718ECEC519
SHA256:E7CA7B6530347CFBEE12C1E6FCB4EAE0FC9808D330818CA0C68E2099BCF4D082
3944pdftk_free-2.02-win-setup.tmpC:\Program Files\PDFtk\bin\is-5G6QI.tmpexecutable
MD5:84E0D5EC5117114B21F26DC9C1F38B48
SHA256:5E5CBE817ECC3CC1875369D81119472559C9624D55C7176852C8827750AFA00A
3944pdftk_free-2.02-win-setup.tmpC:\Program Files\PDFtk\license\is-9P074.tmptext
MD5:EFE33594EC65E4945E8FAD40AEE15143
SHA256:6A3943E132F3C0179844A1F2AC69909F5DF6BFA33CF8FA3A5F7BD5DB2C7C5CBB
3944pdftk_free-2.02-win-setup.tmpC:\Program Files\PDFtk\bin\is-SFL2E.tmpchm
MD5:FF04B2CAEF0C8C93C75949718ECEC519
SHA256:E7CA7B6530347CFBEE12C1E6FCB4EAE0FC9808D330818CA0C68E2099BCF4D082
3944pdftk_free-2.02-win-setup.tmpC:\Program Files\PDFtk\bin\pdftk.exeexecutable
MD5:84E0D5EC5117114B21F26DC9C1F38B48
SHA256:5E5CBE817ECC3CC1875369D81119472559C9624D55C7176852C8827750AFA00A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
25
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1824
msedge.exe
GET
301
104.239.142.193:80
http://www.pdflabs.com/tools/pdftk-pro/
unknown
html
329 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2340
msedge.exe
239.255.255.250:1900
unknown
1824
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1824
msedge.exe
104.239.142.193:80
www.pdflabs.com
RMH-14
US
unknown
1824
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1824
msedge.exe
104.239.142.193:443
www.pdflabs.com
RMH-14
US
unknown
1824
msedge.exe
142.250.185.110:443
www.google-analytics.com
whitelisted
1824
msedge.exe
172.217.23.104:443
www.googletagmanager.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
www.pdflabs.com
  • 104.239.142.193
unknown
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.google-analytics.com
  • 142.250.185.110
whitelisted
www.googletagmanager.com
  • 172.217.23.104
whitelisted
www.bing.com
  • 92.123.104.33
  • 92.123.104.25
  • 92.123.104.26
  • 92.123.104.27
  • 92.123.104.32
  • 92.123.104.28
  • 92.123.104.30
  • 92.123.104.31
  • 92.123.104.29
whitelisted
region1.google-analytics.com
  • 216.239.32.36
  • 216.239.34.36
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted

Threats

No threats detected
No debug info