| File name: | pdf_fast.exe |
| Full analysis: | https://app.any.run/tasks/40ca07a9-6083-41e5-a323-4529b82ea29a |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 10:03:51 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 4B37AF94182C7FB0F196D2A01BC96CBA |
| SHA1: | 667B91D2CCEB9D2D96F40B2A6D66AD0A8D4AA2B7 |
| SHA256: | 88F472E68FC40D523B498BA14997FB9006569DF5E843F00CDF1DE2AC5966A010 |
| SSDEEP: | 98304:XL0druM/vIX0pafjCHE6B5fMxNRlOqAhcNAjcXILaNyKuvRofk1y2seY6mG+Eb2u:U7LBG/LvtU8E |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:08:08 12:49:22+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.36 |
| CodeSize: | 2534912 |
| InitializedDataSize: | 964608 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1e0862 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Debug |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | PDFast |
| FileDescription: | PDFast Installer |
| FileVersion: | 1.0.0 |
| InternalName: | PDFast |
| LegalCopyright: | Copyright (C) 2025 PDFast |
| OriginalFileName: | PDFast.exe |
| ProductName: | PDFast |
| ProductVersion: | 1.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 208 | "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | C:\Windows\System32\BackgroundTransferHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Download/Upload Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 496 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6224 --field-trial-handle=2036,i,12777810056146450320,1386920382877402074,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 872 | "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | C:\Windows\System32\BackgroundTransferHost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Download/Upload Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 924 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6932 --field-trial-handle=2036,i,12777810056146450320,1386920382877402074,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1096 | rundll32.exe "C:\WINDOWS\Installer\MSI18F1.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1120671 58 RequestSender!RequestSender.CustomActions.Finish | C:\Windows\SysWOW64\rundll32.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1300 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x290,0x294,0x298,0x288,0x2a0,0x7ffc88705fd8,0x7ffc88705fe4,0x7ffc88705ff0 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1324 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4696 --field-trial-handle=2036,i,12777810056146450320,1386920382877402074,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1512 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5380 --field-trial-handle=2036,i,12777810056146450320,1386920382877402074,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1600 | "C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca | C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Shell Experience Host Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1616 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5920 --field-trial-handle=2036,i,12777810056146450320,1386920382877402074,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (7216) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders |
| Operation: | write | Name: | C:\Users\admin\AppData\Roaming\Microsoft\Installer\ |
Value: | |||
| (PID) Process: | (7216) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\C838C4529A8903C499B4533DE8B85105 |
| Operation: | write | Name: | 2869F0CE147ABAD43AAB440DC66A40AD |
Value: C:\Users\admin\AppData\Roaming\PDFast\ | |||
| (PID) Process: | (7216) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\470B5FC30B2A7304482B53E9A273F07F |
| Operation: | write | Name: | 2869F0CE147ABAD43AAB440DC66A40AD |
Value: C:\Users\admin\AppData\Roaming\PDFast\msvcp140_2.dll | |||
| (PID) Process: | (7216) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\1A16A140BE5EC164184991A55331F85A |
| Operation: | write | Name: | 2869F0CE147ABAD43AAB440DC66A40AD |
Value: C:\Users\admin\AppData\Roaming\PDFast\vcruntime140.dll | |||
| (PID) Process: | (7216) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\43BA13D9F275DCB4BBFA04780FE1CE05 |
| Operation: | write | Name: | 2869F0CE147ABAD43AAB440DC66A40AD |
Value: C:\Users\admin\AppData\Roaming\PDFast\vcruntime140_1.dll | |||
| (PID) Process: | (7216) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\43061ED4E80B4114EA89628D45680312 |
| Operation: | write | Name: | 2869F0CE147ABAD43AAB440DC66A40AD |
Value: 01:\Software\Caphyon\Advanced Installer\LZMA\{EC0F9682-A741-4DAB-A3BA-44D06CA604DA}\1.0.0\AI_ExePath | |||
| (PID) Process: | (7216) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\6A16DD2A090807E49AB08E904426792B |
| Operation: | write | Name: | 2869F0CE147ABAD43AAB440DC66A40AD |
Value: 01:\Software\ | |||
| (PID) Process: | (7216) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\CA4F623C721465F4FA667B0473959BB7 |
| Operation: | write | Name: | 2869F0CE147ABAD43AAB440DC66A40AD |
Value: 01:\Software\PDFast\Path | |||
| (PID) Process: | (7216) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\6A19015DD0FEFE14BA72A88D8FBC8E85 |
| Operation: | write | Name: | 2869F0CE147ABAD43AAB440DC66A40AD |
Value: 01:\Software\PDFast\Version | |||
| (PID) Process: | (7216) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\070A425E6F286974EBCD7236596A4C03 |
| Operation: | write | Name: | 2869F0CE147ABAD43AAB440DC66A40AD |
Value: 01:\Software\PDFast\PDFast\DownloadFolder | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1628 | pdf_fast.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\357F04AD41BCF5FE18FCB69F60C6680F_4A9E0CB487DCAD37DE0BF8934D0E9988 | binary | |
MD5:EDD39DEFA774FE224F10FBF403EEE90E | SHA256:249C74A62BC299E1C74B2E3E29CAEB97E05749E2C1F90E4445AF6C31DFD56B97 | |||
| 1628 | pdf_fast.exe | C:\Users\admin\AppData\Roaming\PDFast\PDFast 1.0.0\install\holder0.aiph | binary | |
MD5:95A1A9A51DCE1275FAAE60DAB1813C28 | SHA256:A7B52877998683DDA666C889C0AEBA640ECF702665DE45EF9BD04ACB25CDA1FE | |||
| 1628 | pdf_fast.exe | C:\Users\admin\AppData\Roaming\PDFast\PDFast 1.0.0\install\CA604DA\PDFast.msi | executable | |
MD5:B2B9E8F52F0D74109FFB3443B633DBF2 | SHA256:053B80BD6A6B47FD74AF194B731A2F8D30284981AB5A8E25A3CA839AB2804AFD | |||
| 1628 | pdf_fast.exe | C:\Users\admin\AppData\Local\Temp\shiE38C.tmp | executable | |
MD5:84A34BF3486F7B9B7035DB78D78BDD1E | SHA256:F85911C910B660E528D2CF291BAA40A92D09961996D6D84E7A53A7095C7CD96E | |||
| 7216 | msiexec.exe | C:\Windows\Installer\10e948.msi | executable | |
MD5:B2B9E8F52F0D74109FFB3443B633DBF2 | SHA256:053B80BD6A6B47FD74AF194B731A2F8D30284981AB5A8E25A3CA839AB2804AFD | |||
| 8116 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\SFXCA0DD13E935C42519828C3D43F7763A7C1\Microsoft.Win32.TaskScheduler.dll | executable | |
MD5:0616EA42B68A8F5F2F01BCD985BDCBC7 | SHA256:EA27C65491119EEE5C8E87CE3D470783580DB8FC5BD141C496768D7D0CCE779A | |||
| 1628 | pdf_fast.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\357F04AD41BCF5FE18FCB69F60C6680F_4A9E0CB487DCAD37DE0BF8934D0E9988 | binary | |
MD5:76B877CFC89C421D8486E65D677D296C | SHA256:1ED5B0B2A9E9ED938BA984B103A249A623B0B43137F87B44E4D972669D6084A4 | |||
| 7216 | msiexec.exe | C:\Windows\Installer\MSIF1E4.tmp | executable | |
MD5:FF28F8D0B16C52D475C6E06BD2FA24FA | SHA256:076ABA76E5FE015AFF3C42B3ADC0623B2DD1ABCB0E35B2F13CF2848F1A7A1CE8 | |||
| 8116 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\SFXCA0DD13E935C42519828C3D43F7763A7C1\RequestSender.dll | executable | |
MD5:2BECD9A34C47E04A7F4780ECAB9CC9E8 | SHA256:69D1B22734FD95A761CA79AA8C1B9392CD8EE1331E23BC3E6F64A2243F2575C9 | |||
| 8116 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\SFXCA0DD13E935C42519828C3D43F7763A7C1\WixToolset.Dtf.WindowsInstaller.dll | executable | |
MD5:EF8D5785AC8669F5FD54E22F52770E6B | SHA256:A614884EA627DA1925131EBF41E8AE202CAEAC0FE543B86384F5EB2BFAF1AA75 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.16.164.131:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
2644 | svchost.exe | HEAD | 200 | 146.75.122.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1742976739&P2=404&P3=2&P4=Cu%2bxGYxjtpOppszmKiwphZ19rjyDdorzbhd83AsnMWKwgtiV6VWTxAGD7wLK5QOq1xN9lD%2fAd8XYy4SFF0AAxw%3d%3d | unknown | — | — | whitelisted |
1628 | pdf_fast.exe | GET | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D | unknown | — | — | whitelisted |
1628 | pdf_fast.exe | GET | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDDbMOaoiAw9%2FpxWS%2BA%3D%3D | unknown | — | — | whitelisted |
8124 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
2644 | svchost.exe | GET | 206 | 146.75.122.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1742976739&P2=404&P3=2&P4=Cu%2bxGYxjtpOppszmKiwphZ19rjyDdorzbhd83AsnMWKwgtiV6VWTxAGD7wLK5QOq1xN9lD%2fAd8XYy4SFF0AAxw%3d%3d | unknown | — | — | whitelisted |
2644 | svchost.exe | GET | 206 | 146.75.122.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1742976739&P2=404&P3=2&P4=Cu%2bxGYxjtpOppszmKiwphZ19rjyDdorzbhd83AsnMWKwgtiV6VWTxAGD7wLK5QOq1xN9lD%2fAd8XYy4SFF0AAxw%3d%3d | unknown | — | — | whitelisted |
2644 | svchost.exe | GET | 206 | 146.75.122.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1742976739&P2=404&P3=2&P4=Cu%2bxGYxjtpOppszmKiwphZ19rjyDdorzbhd83AsnMWKwgtiV6VWTxAGD7wLK5QOq1xN9lD%2fAd8XYy4SFF0AAxw%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 2.16.164.131:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 40.126.31.3:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
1628 | pdf_fast.exe | 104.18.21.226:80 | ocsp.globalsign.com | CLOUDFLARENET | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
8116 | rundll32.exe | 169.150.247.39:443 | b.pdf-fast.com | — | GB | unknown |
2852 | backgroundTaskHost.exe | 20.31.169.57:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ocsp.globalsign.com |
| whitelisted |
b.pdf-fast.com |
| unknown |
arc.msn.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |