File name: | pdfcentral (2).exe |
Full analysis: | https://app.any.run/tasks/e7f7779f-13d3-42ac-a57a-44db8a19cbaf |
Verdict: | Malicious activity |
Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
Analysis date: | August 19, 2024, 18:40:36 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows |
MD5: | 7DB429CAF383BE84EE8EADF9132DCA15 |
SHA1: | C2BA41129A0C99B00E0FDE88658E9855A93361C8 |
SHA256: | 9A728306B499B5884E51F5B784FA834E76BECD06F9206594E99D5AD36A8BE7C9 |
SSDEEP: | 12288:tLDCgVCXOpvoI621L7szM97lmeq8MNCwYMUGql9:RCgVCeZoI621L7szelpq8oCwYMUNl9 |
.exe | | | Win64 Executable (generic) (87.3) |
---|---|---|
.exe | | | Generic Win/DOS Executable (6.3) |
.exe | | | DOS Executable Generic (6.3) |
MachineType: | AMD AMD64 |
---|---|
TimeStamp: | 2103:09:02 10:05:46+00:00 |
ImageFileCharacteristics: | Executable, Large address aware |
PEType: | PE32+ |
LinkerVersion: | 48 |
CodeSize: | 658432 |
InitializedDataSize: | 106496 |
UninitializedDataSize: | - |
EntryPoint: | 0x0000 |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 6 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.0.9.82 |
ProductVersionNumber: | 1.0.9.82 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | - |
CompanyName: | - |
FileDescription: | PDFCentral |
FileVersion: | 1.0.9.82 |
InternalName: | PDF Central.exe |
LegalCopyright: | Copyright © 2022 |
LegalTrademarks: | - |
OriginalFileName: | PDF Central.exe |
ProductName: | PDFCentral |
ProductVersion: | 1.0.9.82 |
AssemblyVersion: | 1.0.9.82 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1064 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
1124 | "C:\Users\admin\Desktop\pdfcentral (2).exe" | C:\Users\admin\Desktop\pdfcentral (2).exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: PDFCentral Exit code: 0 Version: 1.0.9.82 Modules
| |||||||||||||||
1748 | "C:\Users\admin\Desktop\pdfcentral (2).exe" | C:\Users\admin\Desktop\pdfcentral (2).exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: PDFCentral Exit code: 0 Version: 1.0.9.82 Modules
| |||||||||||||||
2384 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
3112 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1920 -parentBuildID 20240213221259 -prefsHandle 1852 -prefMapHandle 1832 -prefsLen 30537 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b2cf48b1-0bb0-4554-81ba-b1e7bf0b681e} 1064 "\\.\pipe\gecko-crash-server-pipe.1064" 21cff3e1710 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
3784 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2292 -parentBuildID 20240213221259 -prefsHandle 2284 -prefMapHandle 2280 -prefsLen 30537 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7b6f8eaa-177f-46c8-8980-48f51bd39230} 1064 "\\.\pipe\gecko-crash-server-pipe.1064" 21cf287f710 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
5124 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2968 -childID 1 -isForBrowser -prefsHandle 2960 -prefMapHandle 2956 -prefsLen 30953 -prefMapSize 244343 -jsInitHandle 1500 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e074d05f-4744-4189-9e7e-d439b236da00} 1064 "\\.\pipe\gecko-crash-server-pipe.1064" 21c84d53150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
5372 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5800 -childID 5 -isForBrowser -prefsHandle 5792 -prefMapHandle 5680 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1500 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8c1dec72-753e-452b-81e4-00ac11e8e314} 1064 "\\.\pipe\gecko-crash-server-pipe.1064" 21c8a2834d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
5956 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2820 -childID 4 -isForBrowser -prefsHandle 5556 -prefMapHandle 5532 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1500 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b26f854e-ac5b-4e57-9988-cd215ed68abd} 1064 "\\.\pipe\gecko-crash-server-pipe.1064" 21c8a283310 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
6244 | "C:\Users\admin\Desktop\pdfcentral (2).exe" | C:\Users\admin\Desktop\pdfcentral (2).exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: PDFCentral Exit code: 0 Version: 1.0.9.82 Modules
|
(PID) Process: | (6648) pdfcentral (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfcentral (2)_RASAPI32 |
Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
(PID) Process: | (6648) pdfcentral (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfcentral (2)_RASAPI32 |
Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
(PID) Process: | (6648) pdfcentral (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfcentral (2)_RASAPI32 |
Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
(PID) Process: | (6648) pdfcentral (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfcentral (2)_RASAPI32 |
Operation: | write | Name: | FileTracingMask |
Value: | |||
(PID) Process: | (6648) pdfcentral (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfcentral (2)_RASAPI32 |
Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
(PID) Process: | (6648) pdfcentral (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfcentral (2)_RASAPI32 |
Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
(PID) Process: | (6648) pdfcentral (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfcentral (2)_RASAPI32 |
Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
(PID) Process: | (6648) pdfcentral (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfcentral (2)_RASMANCS |
Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
(PID) Process: | (6648) pdfcentral (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfcentral (2)_RASMANCS |
Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
(PID) Process: | (6648) pdfcentral (2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfcentral (2)_RASMANCS |
Operation: | write | Name: | EnableConsoleTracing |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
6648 | pdfcentral (2).exe | C:\Users\admin\AppData\Local\Temp\PDF Central\uifirstscreen.json | binary | |
MD5:F0F1AA6D4FD045044559F863AB0E4B21 | SHA256:A170C2561709684FD849AACE098CD02D0215584241AEF32F6AD62EA556B3A829 | |||
1064 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
6648 | pdfcentral (2).exe | C:\Users\admin\AppData\Local\Temp\PDF Central\installing_cen.gif | image | |
MD5:40A2B2DF564C68FE985A63CC46F0C05E | SHA256:61F9A196D7AE40C6E4A240781080318E480BD8A2CFF720C0B8A76CEC6BC013A4 | |||
1064 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:297E88D7CEB26E549254EC875649F4EB | SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702 | |||
6648 | pdfcentral (2).exe | C:\Users\admin\AppData\Local\Temp\PDF Central\uisecondscreen.json | binary | |
MD5:8F90AEC2BFD098101D6E73E0E4C28C6A | SHA256:FDF2CA75D382827AEF164651C4998A97A672D603A02A6AB5C1C903BABF6FDBA7 | |||
6648 | pdfcentral (2).exe | C:\Users\admin\AppData\Local\Temp\PDF Central\favicon.ico | image | |
MD5:1950DC998B26282B687D2AD1DF3D3E8A | SHA256:E250E769F83B852BBFBA6CE843E89E42F09F7E0E3370454A2E1E5F1DD4907737 | |||
1064 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
1064 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.bin | binary | |
MD5:AD96ADC21745D300436EA6C167D6C722 | SHA256:B5DFB978CB8CF04FD3C6D192C62B0C8733B6E007C9801A3D32A8AC6B372683E2 | |||
1064 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
1064 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3268 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6372 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1064 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
1064 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6156 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
1064 | firefox.exe | POST | 200 | 2.16.202.112:80 | http://r11.o.lencr.org/ | unknown | — | — | — |
1064 | firefox.exe | POST | 200 | 2.16.202.120:80 | http://r10.o.lencr.org/ | unknown | — | — | — |
1064 | firefox.exe | POST | 200 | 2.16.202.112:80 | http://r11.o.lencr.org/ | unknown | — | — | — |
1064 | firefox.exe | POST | 200 | 2.16.202.120:80 | http://r10.o.lencr.org/ | unknown | — | — | — |
1064 | firefox.exe | POST | 200 | 2.16.202.120:80 | http://r10.o.lencr.org/ | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
5904 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6016 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5904 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3260 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3268 | svchost.exe | 40.126.32.68:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
3268 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
6156 | backgroundTaskHost.exe | 20.199.58.43:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | unknown |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
xif.centlint.com |
| unknown |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |