File name:

PDFast.exe

Full analysis: https://app.any.run/tasks/4dd72438-442e-44a9-a9a7-5c0a2d339a88
Verdict: Malicious activity
Analysis date: May 02, 2025, 14:53:29
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
advancedinstaller
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

4B37AF94182C7FB0F196D2A01BC96CBA

SHA1:

667B91D2CCEB9D2D96F40B2A6D66AD0A8D4AA2B7

SHA256:

88F472E68FC40D523B498BA14997FB9006569DF5E843F00CDF1DE2AC5966A010

SSDEEP:

98304:XL0druM/vIX0pafjCHE6B5fMxNRlOqAhcNAjcXILaNyKuvRofk1y2seY6mG+Eb2u:U7LBG/LvtU8E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • PDFast.exe (PID: 7416)
    • ADVANCEDINSTALLER mutex has been found

      • PDFast.exe (PID: 7416)
    • Reads the Windows owner or organization settings

      • PDFast.exe (PID: 7416)
      • msiexec.exe (PID: 7696)
    • Process drops legitimate windows executable

      • PDFast.exe (PID: 7416)
      • msiexec.exe (PID: 7696)
      • PDFast.exe (PID: 5256)
    • Executable content was dropped or overwritten

      • PDFast.exe (PID: 7416)
      • rundll32.exe (PID: 7228)
      • rundll32.exe (PID: 7208)
      • rundll32.exe (PID: 1812)
      • rundll32.exe (PID: 4272)
      • PDFast.exe (PID: 5256)
    • The process drops C-runtime libraries

      • PDFast.exe (PID: 7416)
      • msiexec.exe (PID: 7696)
      • PDFast.exe (PID: 5256)
    • Detects AdvancedInstaller (YARA)

      • PDFast.exe (PID: 7416)
    • There is functionality for taking screenshot (YARA)

      • PDFast.exe (PID: 7416)
  • INFO

    • The sample compiled with english language support

      • PDFast.exe (PID: 7416)
      • msiexec.exe (PID: 7696)
      • PDFast.exe (PID: 5256)
    • Creates files or folders in the user directory

      • PDFast.exe (PID: 7416)
      • msiexec.exe (PID: 7696)
    • Reads the computer name

      • PDFast.exe (PID: 7416)
      • msiexec.exe (PID: 7696)
      • msiexec.exe (PID: 7812)
      • msiexec.exe (PID: 8144)
      • identity_helper.exe (PID: 5204)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 7696)
      • PDFast.exe (PID: 7416)
    • Reads Environment values

      • PDFast.exe (PID: 7416)
      • msiexec.exe (PID: 7812)
      • msiexec.exe (PID: 8144)
      • identity_helper.exe (PID: 5204)
    • Checks proxy server information

      • PDFast.exe (PID: 7416)
      • rundll32.exe (PID: 7228)
      • rundll32.exe (PID: 4272)
    • Checks supported languages

      • PDFast.exe (PID: 7416)
      • msiexec.exe (PID: 7812)
      • msiexec.exe (PID: 7696)
      • msiexec.exe (PID: 8144)
      • identity_helper.exe (PID: 5204)
    • Reads the software policy settings

      • PDFast.exe (PID: 7416)
      • msiexec.exe (PID: 7904)
      • rundll32.exe (PID: 7228)
      • msiexec.exe (PID: 7696)
      • rundll32.exe (PID: 4272)
    • Create files in a temporary directory

      • PDFast.exe (PID: 7416)
      • rundll32.exe (PID: 7228)
      • rundll32.exe (PID: 7208)
      • rundll32.exe (PID: 1812)
      • rundll32.exe (PID: 4272)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 7904)
      • rundll32.exe (PID: 1812)
    • Disables trace logs

      • rundll32.exe (PID: 7228)
      • rundll32.exe (PID: 4272)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7696)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7696)
    • Application launched itself

      • msedge.exe (PID: 1052)
      • msedge.exe (PID: 1348)
    • Manual execution by a user

      • PDFast.exe (PID: 5256)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:08:08 12:49:22+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.36
CodeSize: 2534912
InitializedDataSize: 964608
UninitializedDataSize: -
EntryPoint: 0x1e0862
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: Debug
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: PDFast
FileDescription: PDFast Installer
FileVersion: 1.0.0
InternalName: PDFast
LegalCopyright: Copyright (C) 2025 PDFast
OriginalFileName: PDFast.exe
ProductName: PDFast
ProductVersion: 1.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
193
Monitored processes
60
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start pdfast.exe sppextcomobj.exe no specs slui.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs rundll32.exe rundll32.exe rundll32.exe msedge.exe rundll32.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs pdfast.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
1052"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://pdf-fast.com/thankyou.htmlC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1096"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=5320 --field-trial-handle=2548,i,12379480452351892646,7823431221760931541,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1348"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-windowC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1568"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=3532 --field-trial-handle=2432,i,595194119012662785,18038018648688283250,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
1812rundll32.exe "C:\WINDOWS\Installer\MSIDC54.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1105000 54 RequestSender!RequestSender.CustomActions.OpenUrlC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2340"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6436 --field-trial-handle=2548,i,12379480452351892646,7823431221760931541,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2772"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=6048 --field-trial-handle=2548,i,12379480452351892646,7823431221760931541,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3100"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7ffc89bc5fd8,0x7ffc89bc5fe4,0x7ffc89bc5ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3956"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6204 --field-trial-handle=2548,i,12379480452351892646,7823431221760931541,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
26 475
Read events
26 277
Write events
186
Delete events
12

Modification events

(PID) Process:(7696) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
101E00002A672AFD71BBDB01
(PID) Process:(7696) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
9E9FD26805A5BAF74130E235FE5711A2BBF99A0473178DEC4D9796ECAF4F1E9F
(PID) Process:(7696) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(7696) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\015A73038BCCE9A4D9CB5DB9BB9D3A25
Operation:writeName:2869F0CE147ABAD43AAB440DC66A40AD
Value:
C:\Users\admin\AppData\Roaming\PDFast\PDFast.exe
(PID) Process:(7696) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\6F7C244855AA08A448CDAA0F9BE83E00
Operation:writeName:2869F0CE147ABAD43AAB440DC66A40AD
Value:
21:\Software\Microsoft\Windows\CurrentVersion\Uninstall\PDFast 1.0.0\DisplayName
(PID) Process:(7696) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\CB2CF82A73501EB48982555B20352FBE
Operation:writeName:2869F0CE147ABAD43AAB440DC66A40AD
Value:
C:\Users\admin\AppData\Roaming\PDFast\upd.exe
(PID) Process:(7696) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\1F71B56C260FA0044A47ADA58AA028D2
Operation:writeName:2869F0CE147ABAD43AAB440DC66A40AD
Value:
01:\Software\Microsoft\Windows\CurrentVersion\Uninstall\PDFast 1.0.0\NoModify
(PID) Process:(7696) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\FB5BAD0881B0D654BB0972B991982266
Operation:writeName:2869F0CE147ABAD43AAB440DC66A40AD
Value:
C:\Users\admin\AppData\Roaming\PDFast\PDFast.exe.config
(PID) Process:(7696) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\88F1AE2693BC2454CA950689F5DB6F6E
Operation:writeName:2869F0CE147ABAD43AAB440DC66A40AD
Value:
C:\Users\admin\AppData\Roaming\PDFast\Core.dll
(PID) Process:(7696) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\67B966FC90AF5E348843A28F5C75FBB8
Operation:writeName:2869F0CE147ABAD43AAB440DC66A40AD
Value:
C:\Users\admin\AppData\Roaming\PDFast\msvcp140.dll
Executable files
234
Suspicious files
305
Text files
187
Unknown types
0

Dropped files

PID
Process
Filename
Type
7416PDFast.exeC:\Users\admin\AppData\Roaming\PDFast\PDFast 1.0.0\install\holder0.aiphbinary
MD5:95A1A9A51DCE1275FAAE60DAB1813C28
SHA256:A7B52877998683DDA666C889C0AEBA640ECF702665DE45EF9BD04ACB25CDA1FE
7416PDFast.exeC:\Users\admin\AppData\Roaming\PDFast\PDFast 1.0.0\install\CA604DA\PDFast.msiexecutable
MD5:B2B9E8F52F0D74109FFB3443B633DBF2
SHA256:053B80BD6A6B47FD74AF194B731A2F8D30284981AB5A8E25A3CA839AB2804AFD
7416PDFast.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\357F04AD41BCF5FE18FCB69F60C6680F_4A9E0CB487DCAD37DE0BF8934D0E9988binary
MD5:85A7577B7FE16A70C22A37ABFF423226
SHA256:735FE41F38306237E5849654DF4EE4BA07324009042F18D9EF310CE94AF9C40E
7696msiexec.exeC:\Windows\Installer\10c91e.msiexecutable
MD5:B2B9E8F52F0D74109FFB3443B633DBF2
SHA256:053B80BD6A6B47FD74AF194B731A2F8D30284981AB5A8E25A3CA839AB2804AFD
7416PDFast.exeC:\Users\admin\AppData\Local\Temp\shiC5C3.tmpexecutable
MD5:84A34BF3486F7B9B7035DB78D78BDD1E
SHA256:F85911C910B660E528D2CF291BAA40A92D09961996D6D84E7A53A7095C7CD96E
7416PDFast.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554Ebinary
MD5:7E5B8FCFA504C5716D081E36EB8FFD0A
SHA256:9392EA3CCC6225BF3F763408160F850F9BC2AA0AE4F8F4051AD881E5C4BFD8A1
7416PDFast.exeC:\Users\admin\AppData\Local\Temp\MSIC71D.tmpexecutable
MD5:B7A6A99CBE6E762C0A61A8621AD41706
SHA256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
7416PDFast.exeC:\Users\admin\AppData\Local\Temp\MSIC612.tmpexecutable
MD5:B7A6A99CBE6E762C0A61A8621AD41706
SHA256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
7416PDFast.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554Ebinary
MD5:9A954114062D7C6DAF134B06A73A1E93
SHA256:34DFEC2D79F3BF8D20562C51BD50508F99DFC86751E7734FB4B6AFF011355D91
7228rundll32.exeC:\Users\admin\AppData\Local\Temp\SFXCA953EE4FF9B4D834BA11F31034681F3F0\Microsoft.Win32.TaskScheduler.dllexecutable
MD5:0616EA42B68A8F5F2F01BCD985BDCBC7
SHA256:EA27C65491119EEE5C8E87CE3D470783580DB8FC5BD141C496768D7D0CCE779A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
76
DNS requests
67
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.22:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.216.77.22:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7416
PDFast.exe
GET
200
104.18.21.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D
unknown
whitelisted
7416
PDFast.exe
GET
200
104.18.21.226:80
http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDDbMOaoiAw9%2FpxWS%2BA%3D%3D
unknown
whitelisted
8176
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8176
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5936
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.22:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.216.77.22:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
7416
PDFast.exe
104.18.21.226:80
ocsp.globalsign.com
CLOUDFLARENET
whitelisted
6544
svchost.exe
40.126.31.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 23.216.77.22
  • 23.216.77.33
  • 23.216.77.29
  • 23.216.77.26
  • 23.216.77.20
  • 23.216.77.28
  • 23.216.77.32
  • 23.216.77.30
  • 23.216.77.25
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
ocsp.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
login.live.com
  • 40.126.31.3
  • 40.126.31.67
  • 20.190.159.64
  • 20.190.159.23
  • 40.126.31.0
  • 40.126.31.130
  • 40.126.31.73
  • 20.190.159.130
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
b.pdf-fast.com
  • 169.150.247.39
malicious
config.edge.skype.com
  • 13.107.42.16
whitelisted
pdf-fast.com
  • 169.150.247.37
malicious

Threats

No threats detected
No debug info