| download: | pdfforgeExtension.exe |
| Full analysis: | https://app.any.run/tasks/13d83b5d-9c4b-4f9b-986e-b603db2b527d |
| Verdict: | Malicious activity |
| Threats: | Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email. |
| Analysis date: | March 19, 2018, 06:56:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3B2E52BCEE1538F26F2688CCF3EB5740 |
| SHA1: | 51838F4BE589EFC63EEBB010103EA47EBDBD4BE9 |
| SHA256: | 753CBAE11A881B871E3295D65449954817061DB5DEC53DF7B379FEE9F21C33D1 |
| SSDEEP: | 98304:vnA5OLieju6bZfHHnwEwELln0WmAMaOA71pEmx3hqd/31wL+isCoE:fA50jBfHHnwETnyA35RpEM01whN |
| .exe | | | InstallShield setup (36.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (26.6) |
| .exe | | | Win64 Executable (generic) (23.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:04:25 03:16:12+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 713728 |
| InitializedDataSize: | 498176 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x6aabb |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 27.8.0.0 |
| ProductVersionNumber: | 27.8.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | CloudSoftware |
| FileDescription: | Setup Launcher Unicode |
| FileVersion: | 27.8 |
| InternalName: | Setup |
| LegalCopyright: | Copyright © 2005-2017 CloudSoftware |
| OriginalFileName: | InstallShield Setup.exe |
| ProductName: | pdfforge Extension v27.8 |
| ProductVersion: | 27.8 |
| InternalBuildNumber: | 115289 |
| ISInternalVersion: | 19.0.160 |
| ISInternalDescription: | Setup Launcher Unicode |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 25-Apr-2012 01:16:12 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | CloudSoftware |
| FileDescription: | Setup Launcher Unicode |
| FileVersion: | 27.8 |
| InternalName: | Setup |
| LegalCopyright: | Copyright © 2005-2017 CloudSoftware |
| OriginalFilename: | InstallShield Setup.exe |
| ProductName: | pdfforge Extension v27.8 |
| ProductVersion: | 27.8 |
| Internal Build Number: | 115289 |
| ISInternalVersion: | 19.0.160 |
| ISInternalDescription: | Setup Launcher Unicode |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000F8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 4 |
| Time date stamp: | 25-Apr-2012 01:16:12 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000AE20D | 0x000AE400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.58831 |
.rdata | 0x000B0000 | 0x000291E0 | 0x00029200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.91329 |
.data | 0x000DA000 | 0x00008828 | 0x00002800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.54163 |
.rsrc | 0x000E3000 | 0x0004DF10 | 0x0004E000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.57484 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.22609 | 1210 | Latin 1 / Western European | UNKNOWN | RT_MANIFEST |
2 | 3.835 | 744 | Latin 1 / Western European | UNKNOWN | RT_ICON |
3 | 3.35696 | 296 | Latin 1 / Western European | UNKNOWN | RT_ICON |
4 | 6.14965 | 3752 | Latin 1 / Western European | UNKNOWN | RT_ICON |
5 | 6.18448 | 2216 | Latin 1 / Western European | UNKNOWN | RT_ICON |
6 | 4.85842 | 1384 | Latin 1 / Western European | UNKNOWN | RT_ICON |
7 | 5.57777 | 9640 | Latin 1 / Western European | UNKNOWN | RT_ICON |
8 | 5.81004 | 4264 | Latin 1 / Western European | UNKNOWN | RT_ICON |
9 | 6.06596 | 1128 | Latin 1 / Western European | UNKNOWN | RT_ICON |
10 | 3.22977 | 744 | Latin 1 / Western European | UNKNOWN | RT_ICON |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
OLEAUT32.dll |
RPCRT4.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
msi.dll (delay-loaded) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 772 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1252 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | — | MsiExec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2172 | "C:\Program Files\Application Updater\ApplicationUpdater.exe" | C:\Program Files\Application Updater\ApplicationUpdater.exe | — | services.exe | |||||||||||
User: SYSTEM Company: CloudSoftware Integrity Level: SYSTEM Description: Application Updater Exit code: 0 Version: 27, 8, 0, 3 Modules
| |||||||||||||||
| 2336 | C:\Windows\system32\MsiExec.exe -Embedding 49999F1712F5A4D37176174D0FA32297 M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2652 | C:\Windows\system32\MsiExec.exe -Embedding A1F8C218C11B86FC76FCEB6E458C8EA7 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2756 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2956 | "C:\Users\admin\AppData\Local\Temp\pdfforgeExtension.exe" | C:\Users\admin\AppData\Local\Temp\pdfforgeExtension.exe | — | explorer.exe | |||||||||||
User: admin Company: CloudSoftware Integrity Level: MEDIUM Description: Setup Launcher Unicode Exit code: 3221226540 Version: 27.8 | |||||||||||||||
| 3400 | "C:\Program Files\Common Files\Spigot\Preferences Manager\PreferencesManager.exe" /reset 0 DFROMKIT | C:\Program Files\Common Files\Spigot\Preferences Manager\PreferencesManager.exe | — | msiexec.exe | |||||||||||
User: admin Company: CloudSoftware Integrity Level: HIGH Description: Preferences Manager Exit code: 0 Version: 27, 8, 0, 3 Modules
| |||||||||||||||
| 3448 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3660 | "C:\Users\admin\AppData\Local\Temp\pdfforgeExtension.exe" | C:\Users\admin\AppData\Local\Temp\pdfforgeExtension.exe | explorer.exe | ||||||||||||
User: admin Company: CloudSoftware Integrity Level: HIGH Description: Setup Launcher Unicode Exit code: 0 Version: 27.8 Modules
| |||||||||||||||
| (PID) Process: | (3448) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000006A2356794FBFD301780D00000C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3448) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000006A2356794FBFD301780D00000C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3448) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 47 | |||
| (PID) Process: | (3448) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000500CA0794FBFD301780D00000C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3448) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000AA6EA2794FBFD301780D000068080000E8030000010000000000000000000000E6FAF3FCA9A13545A3DA11012E9308250000000000000000 | |||
| (PID) Process: | (2756) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000006C5AAE794FBFD301C40A0000B00C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2756) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000006C5AAE794FBFD301C40A0000CC080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2756) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000006C5AAE794FBFD301C40A0000D8080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2756) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000006C5AAE794FBFD301C40A0000A80C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2756) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000002E46BA794FBFD301C40A0000CC080000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3660 | pdfforgeExtension.exe | C:\Users\admin\AppData\Local\Temp\~EDB5.tmp | — | |
MD5:— | SHA256:— | |||
| 3660 | pdfforgeExtension.exe | C:\Users\admin\AppData\Local\Temp\~EDB6.tmp | — | |
MD5:— | SHA256:— | |||
| 3660 | pdfforgeExtension.exe | C:\Users\admin\AppData\Local\Temp\{9F7D4DEE-35AA-4736-9011-2FB0E1008B2D}\pdfforgeExtension.msi | — | |
MD5:— | SHA256:— | |||
| 3848 | MSIEXEC.EXE | C:\Users\admin\AppData\Local\Temp\MSI331.tmp | — | |
MD5:— | SHA256:— | |||
| 3848 | MSIEXEC.EXE | C:\Users\admin\AppData\Local\Temp\MSI3AF.tmp | — | |
MD5:— | SHA256:— | |||
| 3848 | MSIEXEC.EXE | C:\Users\admin\AppData\Local\Temp\MSI3C0.tmp | — | |
MD5:— | SHA256:— | |||
| 3848 | MSIEXEC.EXE | C:\Users\admin\AppData\Local\Temp\MSI3E0.tmp | — | |
MD5:— | SHA256:— | |||
| 3448 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3448 | msiexec.exe | C:\Windows\Installer\163d8a.msi | — | |
MD5:— | SHA256:— | |||
| 3448 | msiexec.exe | C:\Windows\Installer\MSI40E7.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 200 | 174.37.213.243:80 | http://api.cloudnetworktools.com/cgi/api.cgi/589518/F66225B313384DD19E22CE568FF15717/vloc/10 | US | text | 1.08 Kb | malicious |
— | — | POST | 200 | 174.37.213.243:80 | http://www.cloudnetworktools.com/cgi/api.cgi/589518/F66225B313384DD19E22CE568FF15717/vaus/14/ | US | text | 58 b | malicious |
— | — | GET | 200 | 174.37.213.243:80 | http://pdfforge.cloudnetworktools.com/image/1/2/pdfforge/1261096968/pdfc_portal_tb.gif | US | image | 14.2 Kb | malicious |
— | — | GET | 200 | 172.217.22.78:80 | http://ocsp.pki.goog/GTSGIAG3/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCCAFKQNmFeVVo | US | der | 463 b | whitelisted |
— | — | POST | 200 | 174.37.213.243:80 | http://pdfforge.cloudnetworktools.com/cgi/api.cgi/589518/F66225B313384DD19E22CE568FF15717/vloc/1 | US | text | 1.08 Kb | malicious |
— | — | GET | 200 | 174.37.213.243:80 | http://pdfforge.cloudnetworktools.com/styles/toolbar_site.css | US | text | 1.61 Kb | malicious |
— | — | POST | 200 | 174.37.213.243:80 | http://www.cloudnetworktools.com/cgi/api.cgi/589518/F66225B313384DD19E22CE568FF15717/ping/14/73/ | US | text | 58 b | malicious |
— | — | POST | 200 | 174.37.213.243:80 | http://pdfforge.cloudnetworktools.com/cgi/api.cgi/589518/F66225B313384DD19E22CE568FF15717/vrst/4 | US | text | 43 b | malicious |
— | — | POST | 200 | 174.37.213.243:80 | http://api.cloudnetworktools.com/cgi/api.cgi/589518/F66225B313384DD19E22CE568FF15717/ping/10/73/ | US | text | 58 b | malicious |
— | — | GET | 200 | 174.37.213.243:80 | http://pdfforge.cloudnetworktools.com/images/partners/msg_bkg.png | US | image | 168 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 174.37.213.243:80 | www.cloudnetworktools.com | SoftLayer Technologies Inc. | US | malicious |
— | — | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
— | — | 172.217.22.78:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
— | — | 172.217.22.78:80 | www.google-analytics.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.cloudnetworktools.com |
| malicious |
pdfforge.cloudnetworktools.com |
| malicious |
api.cloudnetworktools.com |
| malicious |
www.bing.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | A Network Trojan was detected | ET MALWARE W32/Toolbar.WIDGI User-Agent (WidgiToolbar-) |
— | — | A Network Trojan was detected | ET MALWARE W32/Toolbar.WIDGI User-Agent (WidgiToolbar-) |
— | — | A Network Trojan was detected | ET MALWARE W32/Toolbar.WIDGI User-Agent (WidgiToolbar-) |
— | — | A Network Trojan was detected | ET MALWARE W32/Toolbar.WIDGI User-Agent (WidgiToolbar-) |
— | — | A Network Trojan was detected | ET MALWARE W32/Toolbar.WIDGI User-Agent (WidgiToolbar-) |
— | — | A Network Trojan was detected | ET MALWARE W32/Toolbar.WIDGI User-Agent (WidgiToolbar-) |
— | — | A Network Trojan was detected | ET MALWARE W32/Toolbar.WIDGI User-Agent (WidgiToolbar-) |