File name:

PDFSparkOnSoft_683918.exe

Full analysis: https://app.any.run/tasks/76cba640-dabd-420e-bda4-1ae186bb1fe7
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: October 27, 2025, 20:19:47
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
adware
innosetup
nodejs
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

8978D3F6DF743C76B5127755A3BC78A6

SHA1:

733E6BD2BBF753DB8E7DF1AEE7BF1824301B4833

SHA256:

717C2728B957A7FAECB7D1AC057BB03053F6397BBC369092C493DAF6D45DC67C

SSDEEP:

98304:sLVIF8P3n1BLHxtD59KEKjSvDXMY5lCh8AKmawhO3SSIL4qECo6xjaVHE33bsjEE:g/RMRLCiRMJxx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
    • Process drops legitimate windows executable

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
    • Executable content was dropped or overwritten

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
    • Application launched itself

      • PDFSpark.exe (PID: 7716)
    • There is functionality for taking screenshot (YARA)

      • PDFSpark.exe (PID: 7728)
  • INFO

    • Reads Environment values

      • PDFSparkOnSoft_683918.exe (PID: 7432)
      • PDFSparkOnSoft_683918.tmp (PID: 7456)
      • PDFSpark.exe (PID: 7716)
      • PDFSpark.exe (PID: 7864)
    • Checks supported languages

      • PDFSparkOnSoft_683918.exe (PID: 7432)
      • PDFSparkOnSoft_683918.tmp (PID: 7456)
      • PDFSpark.exe (PID: 7716)
      • PDFSpark.exe (PID: 6412)
      • PDFSpark.exe (PID: 7728)
      • PDFSpark.exe (PID: 7864)
      • PDFSpark.exe (PID: 8164)
    • Create files in a temporary directory

      • PDFSparkOnSoft_683918.exe (PID: 7432)
      • PDFSparkOnSoft_683918.tmp (PID: 7456)
      • PDFSpark.exe (PID: 7716)
    • The sample compiled with english language support

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
    • Reads the computer name

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
      • PDFSpark.exe (PID: 7716)
      • PDFSpark.exe (PID: 6412)
      • PDFSpark.exe (PID: 7728)
      • PDFSpark.exe (PID: 8164)
    • Detects InnoSetup installer (YARA)

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
      • PDFSparkOnSoft_683918.exe (PID: 7432)
    • Compiled with Borland Delphi (YARA)

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
      • PDFSparkOnSoft_683918.exe (PID: 7432)
    • Reads the software policy settings

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
      • PDFSpark.exe (PID: 7716)
      • slui.exe (PID: 1312)
    • Checks proxy server information

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
      • PDFSpark.exe (PID: 7716)
      • slui.exe (PID: 1312)
    • Creates files or folders in the user directory

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
      • PDFSpark.exe (PID: 7716)
      • PDFSpark.exe (PID: 6412)
      • PDFSpark.exe (PID: 8164)
    • Creates a software uninstall entry

      • PDFSparkOnSoft_683918.tmp (PID: 7456)
    • Reads product name

      • PDFSpark.exe (PID: 7716)
      • PDFSpark.exe (PID: 7864)
    • Process checks computer location settings

      • PDFSpark.exe (PID: 7716)
      • PDFSpark.exe (PID: 7864)
    • Reads the machine GUID from the registry

      • PDFSpark.exe (PID: 7716)
      • PDFSpark.exe (PID: 8164)
    • Node.js compiler has been detected

      • PDFSpark.exe (PID: 7728)
      • PDFSpark.exe (PID: 7716)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:05:03 14:45:36+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 704512
InitializedDataSize: 466944
UninitializedDataSize: -
EntryPoint: 0xacfe0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Mainstay Crypto LLC
FileDescription: PDF_Spark Setup
FileVersion: 1.0.0.0
LegalCopyright: Mainstay Crypto LLC 2025
OriginalFileName:
ProductName: PDF_Spark
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
8
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start pdfsparkonsoft_683918.exe no specs pdfsparkonsoft_683918.tmp slui.exe pdfspark.exe no specs pdfspark.exe no specs pdfspark.exe pdfspark.exe no specs pdfspark.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1312C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6412"C:\Users\admin\AppData\Local\Programs\PDF_Spark\PDFSpark.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\pdfspark-nativefier-41608d" --mojo-platform-channel-handle=2056 --field-trial-handle=1684,i,4273930577381349610,6182149997990227209,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\Programs\PDF_Spark\PDFSpark.exe
PDFSpark.exe
User:
admin
Company:
Jia Hao
Integrity Level:
MEDIUM
Description:
PDFSpark
Version:
1.0.0.5
Modules
Images
c:\users\admin\appdata\local\programs\pdf_spark\pdfspark.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7432"C:\Users\admin\AppData\Local\Temp\PDFSparkOnSoft_683918.exe" C:\Users\admin\AppData\Local\Temp\PDFSparkOnSoft_683918.exeexplorer.exe
User:
admin
Company:
Mainstay Crypto LLC
Integrity Level:
MEDIUM
Description:
PDF_Spark Setup
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\pdfsparkonsoft_683918.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
7456"C:\Users\admin\AppData\Local\Temp\is-Q4VLJ.tmp\PDFSparkOnSoft_683918.tmp" /SL5="$80330,9359100,1172480,C:\Users\admin\AppData\Local\Temp\PDFSparkOnSoft_683918.exe" C:\Users\admin\AppData\Local\Temp\is-Q4VLJ.tmp\PDFSparkOnSoft_683918.tmp
PDFSparkOnSoft_683918.exe
User:
admin
Company:
Mainstay Crypto LLC
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-q4vlj.tmp\pdfsparkonsoft_683918.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
7716"C:\Users\admin\AppData\Local\Programs\PDF_Spark\PDFSpark.exe"C:\Users\admin\AppData\Local\Programs\PDF_Spark\PDFSpark.exePDFSparkOnSoft_683918.tmp
User:
admin
Company:
Jia Hao
Integrity Level:
MEDIUM
Description:
PDFSpark
Version:
1.0.0.5
Modules
Images
c:\users\admin\appdata\local\programs\pdf_spark\pdfspark.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7728"C:\Users\admin\AppData\Local\Programs\PDF_Spark\PDFSpark.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\pdfspark-nativefier-41608d" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1660 --field-trial-handle=1684,i,4273930577381349610,6182149997990227209,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2C:\Users\admin\AppData\Local\Programs\PDF_Spark\PDFSpark.exePDFSpark.exe
User:
admin
Company:
Jia Hao
Integrity Level:
LOW
Description:
PDFSpark
Version:
1.0.0.5
Modules
Images
c:\users\admin\appdata\local\programs\pdf_spark\pdfspark.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7864"C:\Users\admin\AppData\Local\Programs\PDF_Spark\PDFSpark.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\pdfspark-nativefier-41608d" --app-user-model-id=pdfspark-nativefier-41608d --app-path="C:\Users\admin\AppData\Local\Programs\PDF_Spark\resources\app" --no-sandbox --no-zygote --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2440 --field-trial-handle=1684,i,4273930577381349610,6182149997990227209,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\Programs\PDF_Spark\PDFSpark.exePDFSpark.exe
User:
admin
Company:
Jia Hao
Integrity Level:
MEDIUM
Description:
PDFSpark
Version:
1.0.0.5
Modules
Images
c:\users\admin\appdata\local\programs\pdf_spark\pdfspark.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8164"C:\Users\admin\AppData\Local\Programs\PDF_Spark\PDFSpark.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --user-data-dir="C:\Users\admin\AppData\Roaming\pdfspark-nativefier-41608d" --gpu-preferences=UAAAAAAAAADoAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=3324 --field-trial-handle=1684,i,4273930577381349610,6182149997990227209,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2C:\Users\admin\AppData\Local\Programs\PDF_Spark\PDFSpark.exePDFSpark.exe
User:
admin
Company:
Jia Hao
Integrity Level:
MEDIUM
Description:
PDFSpark
Exit code:
0
Version:
1.0.0.5
Modules
Images
c:\users\admin\appdata\local\programs\pdf_spark\pdfspark.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
8 824
Read events
8 781
Write events
25
Delete events
18

Modification events

(PID) Process:(7456) PDFSparkOnSoft_683918.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
201D00005BD0D70D7F47DC01
(PID) Process:(7456) PDFSparkOnSoft_683918.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
4465BA25DEA8902BBECFEC446A2EB4E94D1BE0F1027C688CE7C3725296A3F0BE
(PID) Process:(7456) PDFSparkOnSoft_683918.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(7456) PDFSparkOnSoft_683918.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDF_Spark_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.4.3
(PID) Process:(7456) PDFSparkOnSoft_683918.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDF_Spark_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Users\admin\AppData\Local\Programs\PDF_Spark
(PID) Process:(7456) PDFSparkOnSoft_683918.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDF_Spark_is1
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\PDF_Spark\
(PID) Process:(7456) PDFSparkOnSoft_683918.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDF_Spark_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(7456) PDFSparkOnSoft_683918.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDF_Spark_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(7456) PDFSparkOnSoft_683918.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDF_Spark_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
desktopicon
(PID) Process:(7456) PDFSparkOnSoft_683918.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDF_Spark_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
Executable files
14
Suspicious files
173
Text files
21
Unknown types
2

Dropped files

PID
Process
Filename
Type
7456PDFSparkOnSoft_683918.tmpC:\Users\admin\AppData\Local\Temp\is-UMGA6.tmp\is-RT4K5.tmp
MD5:
SHA256:
7456PDFSparkOnSoft_683918.tmpC:\Users\admin\AppData\Local\Temp\is-UMGA6.tmp\PDFSparkFiles.7z
MD5:
SHA256:
7456PDFSparkOnSoft_683918.tmpC:\Users\admin\AppData\Local\Programs\PDF_Spark\is-HKSHF.tmp
MD5:
SHA256:
7456PDFSparkOnSoft_683918.tmpC:\Users\admin\AppData\Local\Programs\PDF_Spark\LICENSES.chromium.html
MD5:
SHA256:
7456PDFSparkOnSoft_683918.tmpC:\Users\admin\AppData\Local\Temp\is-UMGA6.tmp\_isetup\_setup64.tmpbinary
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
7456PDFSparkOnSoft_683918.tmpC:\Users\admin\AppData\Local\Temp\is-UMGA6.tmp\turbojpeg.dllexecutable
MD5:C48074304A3D18DC7C197EC466427E03
SHA256:09109DAF67D7A056CEC5C09CE3EAC1AA2999B613E297C56BD5176AFDA427E624
7456PDFSparkOnSoft_683918.tmpC:\Users\admin\AppData\Local\Programs\PDF_Spark\is-HAQH4.tmpimage
MD5:F54BD60198E6A27BDF18B2AECB6954F2
SHA256:D074A6B6095580BC4D87A28949FFE6E4E1634EC48C742CADCFE2A3BF20995757
7456PDFSparkOnSoft_683918.tmpC:\Users\admin\AppData\Local\Programs\PDF_Spark\chrome_100_percent.pakbinary
MD5:0CF9DE69DCFD8227665E08C644B9499C
SHA256:D2C299095DBBD3A3CB2B4639E5B3BD389C691397FFD1A681E586F2CFE0E2AB88
7456PDFSparkOnSoft_683918.tmpC:\Users\admin\AppData\Local\Programs\PDF_Spark\is-494HK.tmpbinary
MD5:0CF9DE69DCFD8227665E08C644B9499C
SHA256:D2C299095DBBD3A3CB2B4639E5B3BD389C691397FFD1A681E586F2CFE0E2AB88
7456PDFSparkOnSoft_683918.tmpC:\Users\admin\AppData\Local\Programs\PDF_Spark\is-0Q2J9.tmpexecutable
MD5:FB6227F1DC3D4E7FE853FCE7111876FD
SHA256:BC431CCBEB4E6000065B863B79BAF6CE1D4051933DA942232EFA62213920B674
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
30
DNS requests
18
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5376
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
8148
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.3.crl
QA
binary
813 b
whitelisted
8148
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.3.crl
QA
binary
401 b
whitelisted
8148
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
QA
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5376
svchost.exe
20.190.160.66:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1036
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5596
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
7456
PDFSparkOnSoft_683918.tmp
104.26.3.176:443
appsecuredata.com
CLOUDFLARENET
US
unknown
5376
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3440
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5376
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5596
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.160.66
  • 40.126.32.133
  • 20.190.160.65
  • 20.190.160.131
  • 40.126.32.136
  • 40.126.32.68
  • 20.190.160.128
  • 20.190.160.22
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 172.217.18.14
whitelisted
appsecuredata.com
  • 104.26.3.176
  • 172.67.69.126
  • 104.26.2.176
unknown
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
pdfsparkcomponent.s3.us-east-2.amazonaws.com
  • 52.219.179.122
  • 3.5.133.64
  • 16.12.65.178
  • 3.5.131.15
  • 52.219.106.130
  • 3.5.129.99
  • 52.219.142.34
  • 52.219.93.114
unknown
slscr.update.microsoft.com
  • 135.233.95.144
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
No debug info