File name:

sodapdf.exe

Full analysis: https://app.any.run/tasks/88a4c8fb-b187-4801-a37d-515980e14b51
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: March 10, 2025, 10:42:49
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
adware
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

77B428CFB9F3B6B2AAE9D88E25B3BACA

SHA1:

2106866A5F589E7C9D3D08E04F20EAE4BC1AA73B

SHA256:

6E84D3CC633514433BC902954E6C92009E9D6F168BC8FAFB9B6681CA18DCA819

SSDEEP:

98304:xs07tZkL6PMcVP3BPGBva4aWGF/l9dDs810OJd62NLDbRz2FQuiqew9p2U0bBNTl:nvTb6olT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADWARE has been detected (SURICATA)

      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
  • SUSPICIOUS

    • Adds/modifies Windows certificates

      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Reads security settings of Internet Explorer

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Starts itself from another location

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_0.0.0.0.exe (PID: 2616)
    • Executable content was dropped or overwritten

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_0.0.0.0.exe (PID: 2616)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Access to an unwanted program domain was detected

      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7668)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 7460)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 7460)
  • INFO

    • The sample compiled with english language support

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_0.0.0.0.exe (PID: 2616)
      • msiexec.exe (PID: 7460)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Reads Microsoft Office registry keys

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Creates files in the program directory

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
      • SodaPDFDesktop14.exe (PID: 7600)
      • SodaPDFDesktop14_0.0.0.0.exe (PID: 2616)
    • Checks supported languages

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Reads the software policy settings

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Reads the computer name

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Checks proxy server information

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Creates files or folders in the user directory

      • sodapdf.exe (PID: 7828)
      • BackgroundTransferHost.exe (PID: 1168)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Reads the machine GUID from the registry

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Create files in a temporary directory

      • sodapdf.exe (PID: 7828)
      • SodaPDFDesktop14.exe (PID: 7600)
      • SodaPDFDesktop14_14.0.288.2572.exe (PID: 8080)
    • Manages system restore points

      • SrTasks.exe (PID: 5112)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7460)
    • Application launched itself

      • msiexec.exe (PID: 7460)
    • The sample compiled with russian language support

      • msiexec.exe (PID: 7460)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:11:10 16:04:01+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 9602560
InitializedDataSize: 6411264
UninitializedDataSize: -
EntryPoint: 0x7d386d
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 14.0.288.2572
ProductVersionNumber: 14.0.288.2572
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileVersion: 14.0.288.2572
ProductVersion: 14.0.288.2572
CompanyName: Avanquest Software
FileDescription: Soda PDF Desktop 14 Installer
InternalName: SodaPDFDesktop14.exe
LegalCopyright: © 2010-2022 Avanquest Software. All rights reserved.
OriginalFileName: SodaPDFDesktop14.exe
ProductName: Soda PDF Desktop 14 Installer
CommitID: c5d79bd75a487c9ac1ed9f05cfee1b215e2f0c16
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
18
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start sodapdf.exe #ADWARE sodapdfdesktop14_14.0.288.2572.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe sodapdfdesktop14_0.0.0.0.exe backgroundtransferhost.exe no specs sodapdfdesktop14.exe no specs sodapdfdesktop14.exe sodapdfdesktop14.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs slui.exe no specs sodapdf.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1168"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
1272"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
2616"C:\Users\admin\AppData\Local\Temp\188d7787-40bf-434e-836d-72a9ef3b6cbf\SodaPDFDesktop14_0.0.0.0.exe" /update=finish /second-instanceC:\Users\admin\AppData\Local\Temp\188d7787-40bf-434e-836d-72a9ef3b6cbf\SodaPDFDesktop14_0.0.0.0.exe
SodaPDFDesktop14_14.0.288.2572.exe
User:
admin
Integrity Level:
HIGH
Exit code:
15
Modules
Images
c:\users\admin\appdata\local\temp\188d7787-40bf-434e-836d-72a9ef3b6cbf\sodapdfdesktop14_0.0.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msi.dll
4180C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5112C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5216"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7460C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7600"C:\ProgramData\Soda PDF Desktop 14\Installation\SodaPDFDesktop14.exe" /welcome /no-check-updatesC:\ProgramData\Soda PDF Desktop 14\Installation\SodaPDFDesktop14.exe
SodaPDFDesktop14_0.0.0.0.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\programdata\soda pdf desktop 14\installation\sodapdfdesktop14.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3996_none_d954cb49e10154a6\gdiplus.dll
7640"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7668C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
22 588
Read events
22 237
Write events
336
Delete events
15

Modification events

(PID) Process:(7828) sodapdf.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Soda PDF Desktop 14\Installation
Operation:writeName:INSTALL_FOLDER
Value:
C:\Program Files\Soda PDF Desktop 14
(PID) Process:(7828) sodapdf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7828) sodapdf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7828) sodapdf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7828) sodapdf.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Soda PDF Desktop 14
Operation:writeName:Common data
Value:
7B22636D70223A22737064665F6672655F625F64655F735F615F63726561746F72222C22636F756E7472795F69736F32223A225553222C22444F574E4C4F41445F4C494E4B223A22646F776E6C6F616431342D6465736B746F702E736F64617064662E636F6D2F222C226B657931223A2270646663726561746F72222C226B657932223A2270646663726561746F723072304643525061323130373231222C226D6B657931223A22736F64617064662E636F6D2F6D622F7064662D63726561746F72222C22706172616D73223A226C737069643D4C55313730313031534F44415F444E266C616E673D646526706172746E65723D6D625F736F646132303231267174693D31636662636665312D313434322D393466392D393837342D6438353032383364363737315F323032322D31322D3038266D6B6579363D31636662636665312D313434322D393466392D393837342D6438353032383364363737315F323032322D31322D3038267569643D3130313531333626636D703D737064665F6672655F625F64655F735F615F63726561746F72266B6579313D70646663726561746F72266B6579323D70646663726561746F723072304643525061323130373231266B6579623D655F7064663234266D6B6579353D70616964266D6B6579373D737064665F6232635F305F70617977616C6C736176655F6E615F6C6F635F61267769643D38303034266D6B6579313D736F64617064662E636F6D2F6D622F7064662D63726561746F722664776C643D646F776E6C6F616431342D6465736B746F702E736F64617064662E636F6D2F266D6B6579323D39463831363842312D443138392D344144362D413831452D354445423641463044324130222C22706172746E6572223A226D625F736F646132303231222C2272656469726563746F725F6C696E6B223A2268747470733A2F2F70617967772E736F64617064662E636F6D2F72656469726563742F222C22726566223A2268747470733A2F2F7777772E736F64617064662E64652F222C22756964223A2231303135313336222C227369676E6174757265223A226744697150694E2F57696976736B464152325230706B54723150613743517868755342684B504A44324D7335456E532F615848353942457337666451556A397A7963397666486E71336E6E36744774704F4F734E305949316D6A6D3850746170725152522F4650705A732F7434656B526E6D766E76494848502B4D466A686E52796C774A2F48374147745072514F436459774158566467375264384451374B2B2F614F4567625078506B46376765466E2B47716C7052515455417349555745753277764D4952472F51744971766C3158715437562F3868624D3249667235487A65736D43467532764343666B4B3264686853644F5558374761706248436E6750354E55465073485A4F4459347957593358584575416B7633526377456F7676736850596855625764544535364D702F6E5A496D6B6733517A692F694E7964466F65623569784A7A6A414B6D6B7A4A4F524B4D484B44773D3D227D
(PID) Process:(8080) SodaPDFDesktop14_14.0.288.2572.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Soda PDF Desktop 14\Installation
Operation:writeName:INSTALL_FOLDER
Value:
C:\Program Files\Soda PDF Desktop 14
(PID) Process:(8080) SodaPDFDesktop14_14.0.288.2572.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{3369AF1C-BCC1-4977-89E8-F8B79497C982}
Operation:writeName:LaunchPermission
Value:
010014804C0000005C000000140000003000000002001C0001000000110014000400000001010000000000100010000002001C0001000000000014000B0000000101000000000001000000000102000000000005200000002002000001020000000000052000000020020000
(PID) Process:(8080) SodaPDFDesktop14_14.0.288.2572.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{3369AF1C-BCC1-4977-89E8-F8B79497C982}
Operation:writeName:AccessPermission
Value:
010014804C0000005C000000140000003000000002001C0001000000110014000400000001010000000000100010000002001C0001000000000014000B0000000101000000000001000000000102000000000005200000002002000001020000000000052000000020020000
(PID) Process:(8080) SodaPDFDesktop14_14.0.288.2572.exeKey:HKEY_CURRENT_USER\SOFTWARE\Soda PDF Desktop 14
Operation:writeName:locale
Value:
en
(PID) Process:(8080) SodaPDFDesktop14_14.0.288.2572.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
112
Suspicious files
53
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
8080SodaPDFDesktop14_14.0.288.2572.exeC:\ProgramData\Soda PDF Desktop 14\Installation\PlayaSDK\PlayaSDK.dllexecutable
MD5:11A813C0972B740937D3A7E2DAF9FFCB
SHA256:3F933BCED2D9F65D48F7C48715BF286FD431341A74E1CE15D39B7C4C96603CF9
1168BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\86327e8e-a3bd-434c-b5f8-8109618b4831.down_data
MD5:
SHA256:
7828sodapdf.exeC:\ProgramData\Soda PDF Desktop 14\Installation\logs\2025.03.10_10.43.00_sodapdf_7828.txttext
MD5:320B6EA405B537E6E0ADBF2ABF15E5B3
SHA256:E4ACF796E444460CEA86C1913766F0CD8514FF5D6F6A20AB4EBDE1CF2567FCF1
7828sodapdf.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:810581BADAA6320715ACCB6D71EA15A6
SHA256:1862B2511F2BD3A6D2E700D000D270A7F6574F3DFB9666EE83A0186E14438FC5
8080SodaPDFDesktop14_14.0.288.2572.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A37B8BA80004D3266CB4D93B2052DC10_EBDB5A7037F08CDFB408DBFC0D44B43Dbinary
MD5:6992400A85B6FEDB24D608D3159DA3A2
SHA256:346538E343DD7FD3A28A9E572B6111D6116AC4DDEA661E11D0D43BF262D0ECED
7828sodapdf.exeC:\ProgramData\Soda PDF Desktop 14\Installation\updates-info.jsonbinary
MD5:86C5167CC6EAD95E0A1225B950865972
SHA256:766F89CC351C6F979A00A60FEE75D02DC4E1ED76477280F3E3D3FB371851A2DF
8080SodaPDFDesktop14_14.0.288.2572.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\AF360AACB1570042DEFBC833317997D0_8917E994F38ED1F3FC4CA01952ED873Abinary
MD5:EA3B858B13D4C2D8179635ADD4100620
SHA256:842841BB5E47C59DF7D0E0A312538DCC2738B773EBBBC595F9BC4A4AA72FB11C
7828sodapdf.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C9BE626E9715952E9B70F92F912B9787
SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4
8080SodaPDFDesktop14_14.0.288.2572.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\AF360AACB1570042DEFBC833317997D0_8917E994F38ED1F3FC4CA01952ED873Abinary
MD5:7279B13B3320A98C54934A6193577844
SHA256:61E315617DF49D2B460B6BF927D497CD801AAC69F4FD55125D64CF2789B86B22
8080SodaPDFDesktop14_14.0.288.2572.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\026A86A161D256DBB33076EDF20C0E5E_86AB612B21DEDF3B8CD155ED2E4114FFbinary
MD5:113834E9AF5E0EF8CB14306D25BBB5F1
SHA256:4F91D3CA4CCDA6A25C0377F7B1AB882C4CCF21F18831511CEBEA93C17B350499
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
55
DNS requests
24
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7828
sodapdf.exe
GET
200
142.250.185.163:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7828
sodapdf.exe
GET
200
142.250.185.163:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
8080
SodaPDFDesktop14_14.0.288.2572.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEB2iSDBvmyYY0ILgln0z02o%3D
unknown
whitelisted
8080
SodaPDFDesktop14_14.0.288.2572.exe
GET
200
2.19.246.105:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRr2bwARTxMtEy9aspRAZg5QFhagQQUgrrWPZfOn89x6JI3r%2F2ztWk1V88CEDWvt3udNB9q%2FI%2BERqsxNSs%3D
unknown
whitelisted
8080
SodaPDFDesktop14_14.0.288.2572.exe
GET
200
2.19.246.105:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRp%2BmQDKauE4nIg%2FgknZHuBlLkfKgQUzolPglGqFaKEYsoxI2HSYfv4%2FngCEBEDvjXU4Qc%2BQAIf63tfAy0%3D
unknown
whitelisted
7956
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
8080
SodaPDFDesktop14_14.0.288.2572.exe
GET
200
2.19.246.105:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRp%2BmQDKauE4nIg%2FgknZHuBlLkfKgQUzolPglGqFaKEYsoxI2HSYfv4%2FngCEE%2BTYlqiAoAT%2F2vgOJ%2Fnf0E%3D
unknown
whitelisted
8080
SodaPDFDesktop14_14.0.288.2572.exe
GET
200
2.19.246.105:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCEE5A5DdU7eaMAAAAAFHTlH8%3D
unknown
whitelisted
8080
SodaPDFDesktop14_14.0.288.2572.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
7828
sodapdf.exe
104.19.145.4:443
wsgeoip.sodapdf.com
CLOUDFLARENET
suspicious
7828
sodapdf.exe
142.250.185.163:80
c.pki.goog
GOOGLE
US
whitelisted
7828
sodapdf.exe
104.19.146.4:443
wsgeoip.sodapdf.com
CLOUDFLARENET
suspicious
6544
svchost.exe
20.190.160.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
8080
SodaPDFDesktop14_14.0.288.2572.exe
104.19.146.4:443
wsgeoip.sodapdf.com
CLOUDFLARENET
suspicious

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.238
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
wsgeoip.sodapdf.com
  • 104.19.145.4
  • 104.19.146.4
unknown
c.pki.goog
  • 142.250.185.163
whitelisted
api-updateservice.sodapdf.com
  • 104.19.145.4
  • 104.19.146.4
unknown
cdn-msi.sodapdf.com
  • 104.19.146.4
  • 104.19.145.4
unknown
login.live.com
  • 20.190.160.2
  • 20.190.160.128
  • 20.190.160.17
  • 40.126.32.68
  • 20.190.160.131
  • 40.126.32.140
  • 20.190.160.22
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
ocsp.entrust.net
  • 2.19.246.105
whitelisted

Threats

PID
Process
Class
Message
8080
SodaPDFDesktop14_14.0.288.2572.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
No debug info