URL:

https://easypdfbox.com/dl/thank-you?cid=RKasZnLtmJaVYjXeS

Full analysis: https://app.any.run/tasks/1f5bdee0-e0af-48d7-b08c-95adf5886141
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: March 12, 2025, 10:31:37
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
adware
advancedinstaller
Indicators:
MD5:

BECA042CB87D0DF5796B9B7C4F0B9CD3

SHA1:

9B5B30C6D48939386FBA4C9F9D92018C6BA06745

SHA256:

993AA204933D8E646FE43E2DED38264C5E5AA5C64D9D89FE8AC9C2B31210D195

SSDEEP:

3:N8icVgJTGM4L4dg1A2:2ikTcGK2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • onestart_installer.exe (PID: 2772)
    • Executing a file with an untrusted certificate

      • onestart_installer.exe (PID: 2772)
      • setup.exe (PID: 8060)
      • setup.exe (PID: 840)
    • ADVANCEDINSTALLER has been detected (SURICATA)

      • msiexec.exe (PID: 6344)
    • ADWARE has been detected (SURICATA)

      • onestart_installer.exe (PID: 2772)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 864)
    • Process requests binary or script from the Internet

      • msiexec.exe (PID: 6344)
    • Executable content was dropped or overwritten

      • onestart_installer.exe (PID: 2772)
    • Access to an unwanted program domain was detected

      • onestart_installer.exe (PID: 2772)
      • msiexec.exe (PID: 6344)
    • Application launched itself

      • setup.exe (PID: 8060)
    • Potential Corporate Privacy Violation

      • msiexec.exe (PID: 6344)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 660)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7964)
      • chrome.exe (PID: 660)
      • msiexec.exe (PID: 6268)
    • The sample compiled with english language support

      • msiexec.exe (PID: 7964)
      • msiexec.exe (PID: 6268)
      • onestart_installer.exe (PID: 2772)
      • msiexec.exe (PID: 6344)
    • Manages system restore points

      • SrTasks.exe (PID: 5544)
    • Reads the software policy settings

      • msiexec.exe (PID: 7964)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
158
Monitored processes
18
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs sppextcomobj.exe no specs chrome.exe no specs chrome.exe no specs msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs #ADVANCEDINSTALLER msiexec.exe #ADWARE onestart_installer.exe setup.exe no specs setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
660"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "https://easypdfbox.com/dl/thank-you?cid=RKasZnLtmJaVYjXeS"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\windows\system32\windowscodecs.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\policymanager.dll
c:\windows\system32\msvcp110_win.dll
c:\windows\system32\edputil.dll
c:\windows\system32\windows.ui.appdefaults.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
840"C:\Users\admin\AppData\Local\OneStart.ai\OneStart Installer\CR_0A42B.tmp\setup.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\OneStart.ai\OneStart\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=OneStart --annotation=ver=132.0.6834.161 --initial-client-data=0x28c,0x290,0x294,0x268,0x298,0x7ff7c624e2f8,0x7ff7c624e304,0x7ff7c624e310C:\Users\admin\AppData\Local\OneStart.ai\OneStart Installer\CR_0A42B.tmp\setup.exesetup.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Installer
Version:
132.0.6834.161
Modules
Images
c:\users\admin\appdata\local\onestart.ai\onestart installer\cr_0a42b.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
864C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2088C:\Windows\syswow64\MsiExec.exe -Embedding 9FCDD127506AFA93B48426E5E439C7F6 CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2772"C:\Users\admin\AppData\Local\OneStart.ai\OneStart Installer\onestart_installer.exe" "INSTALL" "15" "2" "1" "1"C:\Users\admin\AppData\Local\OneStart.ai\OneStart Installer\onestart_installer.exe
msiexec.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Installer
Version:
132.0.6834.161
Modules
Images
c:\users\admin\appdata\local\onestart.ai\onestart installer\onestart_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
5544C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6268C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6344C:\Windows\syswow64\MsiExec.exe -Embedding 058317B0A2ED515D06B14A94ADD8C316C:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7276"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2100 --field-trial-handle=1876,i,15159042447846430066,8291261782718829004,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\windows\system32\ntmarta.dll
7308"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2220 --field-trial-handle=1876,i,15159042447846430066,8291261782718829004,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
122.0.6261.70
Total events
11 491
Read events
11 302
Write events
178
Delete events
11

Modification events

(PID) Process:(7944) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
0100000000000000934D63F73993DB01
(PID) Process:(660) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msi\OpenWithProgids
Operation:writeName:Msi.Package
Value:
(PID) Process:(6268) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
480000000000000000B116FE3993DB017C18000004150000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6268) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000007FFD16FE3993DB017C18000004150000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6268) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000EB8856FE3993DB017C18000004150000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6268) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000F0AC53FE3993DB017C18000004150000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6268) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000F0AC53FE3993DB017C18000004150000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6268) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000CF275AFE3993DB017C18000004150000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6268) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6268) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
480000000000000099D9C6FE3993DB017C18000004150000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
19
Suspicious files
48
Text files
20
Unknown types
0

Dropped files

PID
Process
Filename
Type
660chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF10bfb8.TMP
MD5:
SHA256:
660chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF10bfb8.TMP
MD5:
SHA256:
660chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF10bfb8.TMP
MD5:
SHA256:
660chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF10bfb8.TMP
MD5:
SHA256:
660chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
660chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
660chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
660chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
660chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF10bfc7.TMP
MD5:
SHA256:
660chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
48
DNS requests
38
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1388
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
660
chrome.exe
GET
200
108.138.36.51:80
http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSoEwb5tith0jIBy9frSyNGB1lsAAQUNr1J%2FzEs669qQP6ZwBbtuvxI3V8CEEhAwkRt2T9xBNbvBB%2BwDhI%3D
unknown
whitelisted
7724
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6344
msiexec.exe
GET
200
143.204.98.59:80
http://resources.onestart.ai/onestart_installer_132.0.6834.161.exe
unknown
unknown
1388
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2772
onestart_installer.exe
POST
200
18.173.187.111:80
http://log.onestart.ai/
unknown
unknown
660
chrome.exe
GET
200
108.138.36.51:80
http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQg3SSkKA74hABkhmlBtJTz8w3hlAQU%2BWC71OPVNPa49QaAJadz20ZpqJ4CEEJLalPOx2YUHCpjsaUcQQQ%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:137
whitelisted
192.168.100.255:138
whitelisted
52.85.65.5:443
easypdfbox.com
AMAZON-02
US
unknown
239.255.255.250:1900
whitelisted
108.177.119.84:443
accounts.google.com
GOOGLE
US
whitelisted
104.18.30.234:443
app.termly.io
CLOUDFLARENET
suspicious
52.85.65.110:443
res.easypdfbox.com
AMAZON-02
US
unknown
52.85.65.113:443
simpframeprove.com
AMAZON-02
US
unknown
20.198.162.78:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.212.174
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
easypdfbox.com
  • 52.85.65.5
  • 52.85.65.92
  • 52.85.65.35
  • 52.85.65.107
unknown
accounts.google.com
  • 108.177.119.84
whitelisted
app.termly.io
  • 104.18.30.234
  • 104.18.31.234
unknown
res.easypdfbox.com
  • 52.85.65.110
  • 52.85.65.109
  • 52.85.65.79
  • 52.85.65.61
unknown
simpframeprove.com
  • 52.85.65.113
  • 52.85.65.85
  • 52.85.65.29
  • 52.85.65.127
unknown
client.wns.windows.com
  • 20.198.162.78
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.71
  • 20.190.159.130
  • 40.126.31.128
  • 20.190.159.4
  • 40.126.31.69
  • 20.190.159.128
  • 20.190.159.75
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

PID
Process
Class
Message
6344
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] AdvancedInstaller User-Agent
6344
msiexec.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
6344
msiexec.exe
Potentially Bad Traffic
ET INFO Executable served from Amazon S3
2772
onestart_installer.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Onestart AI Program Version Checkin (POST)
No debug info