File name:

pdnob-pdf-editor_8946.exe

Full analysis: https://app.any.run/tasks/33f1cd89-b4f2-4902-a146-7d0966995c52
Verdict: Malicious activity
Analysis date: January 02, 2025, 19:16:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

0717BB6347D511D9EFA74FAD1CF9097C

SHA1:

9B561A1ACAFF6E73CE676B19FB955D0338BAEA42

SHA256:

AABCA2B5CEB657E49FFDA7495805E1CE090634029739CEBECD2AD16D2FED0C4F

SSDEEP:

98304:tC7wWqznnKgE9L0PeP8MOEa2VoovjpxyCsyxcMYdzrOgAFwgC7zy2uHf0lGSWyqB:SHOs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Potential Corporate Privacy Violation

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Checks for external IP

      • svchost.exe (PID: 2192)
      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Reads security settings of Internet Explorer

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Checks Windows Trust Settings

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Reads the Windows owner or organization settings

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Starts CMD.EXE for commands execution

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Get information on the list of running processes

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
      • cmd.exe (PID: 5748)
    • Executable content was dropped or overwritten

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
      • pdfeditor_ts_1.2.0.exe (PID: 624)
    • Drops 7-zip archiver for unpacking

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Process drops legitimate windows executable

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • The process drops C-runtime libraries

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
  • INFO

    • Reads the computer name

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • The sample compiled with english language support

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Creates files in the program directory

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Checks supported languages

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.exe (PID: 624)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Checks proxy server information

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • UPX packer has been detected

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Create files in a temporary directory

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
      • pdfeditor_ts_1.2.0.exe (PID: 624)
    • Reads the machine GUID from the registry

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Reads the software policy settings

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • The process uses the downloaded file

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Process checks computer location settings

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • The sample compiled with chinese language support

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Creates files or folders in the user directory

      • pdnob-pdf-editor_8946.exe (PID: 6164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:03 10:13:58+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1961984
InitializedDataSize: 204800
UninitializedDataSize: 1867776
EntryPoint: 0x3a7990
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.8.5.3
ProductVersionNumber: 2.8.5.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: PDNob
FileDescription: PDNob Software
FileVersion: 2.8.5.3
LegalCopyright: Copyright © 2007-2024 TENORSHARE(HONGKONG)LIMITED All Rights Reserved.
ProductName: 20241203181317
ProductVersion: 2.8.5.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pdnob-pdf-editor_8946.exe svchost.exe pdfeditor_ts_1.2.0.exe pdfeditor_ts_1.2.0.tmp cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs pdnob-pdf-editor_8946.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
396\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
624 /VERYSILENT /SP- /NORESTART /DIR="C:\Program Files (x86)\PDNob\PDNob PDF Editor\" /LANG=en /LOG="C:\Users\admin\AppData\Local\Temp\PDNob PDF Editor_Setup_20250102191740.log" /sptrack "pdnob-pdf-editor_8946.exe"C:\Users\admin\AppData\Local\Temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe
pdnob-pdf-editor_8946.exe
User:
admin
Company:
PDNob
Integrity Level:
HIGH
Description:
PDNob PDF Editor Setup
Version:
1.2.0
Modules
Images
c:\users\admin\appdata\local\temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2192C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3952"C:\Users\admin\AppData\Local\Temp\pdnob-pdf-editor_8946.exe" C:\Users\admin\AppData\Local\Temp\pdnob-pdf-editor_8946.exeexplorer.exe
User:
admin
Company:
PDNob
Integrity Level:
MEDIUM
Description:
PDNob Software
Exit code:
3221226540
Version:
2.8.5.3
Modules
Images
c:\users\admin\appdata\local\temp\pdnob-pdf-editor_8946.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4528find /c /i "PDNob PDF Editor.exe" C:\Windows\SysWOW64\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\find.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4672"C:\Users\admin\AppData\Local\Temp\is-9B1CB.tmp\pdfeditor_ts_1.2.0.tmp" /SL5="$50242,176990026,357376,C:\Users\admin\AppData\Local\Temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe" /VERYSILENT /SP- /NORESTART /DIR="C:\Program Files (x86)\PDNob\PDNob PDF Editor\" /LANG=en /LOG="C:\Users\admin\AppData\Local\Temp\PDNob PDF Editor_Setup_20250102191740.log" /sptrack "pdnob-pdf-editor_8946.exe"C:\Users\admin\AppData\Local\Temp\is-9B1CB.tmp\pdfeditor_ts_1.2.0.tmp
pdfeditor_ts_1.2.0.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9b1cb.tmp\pdfeditor_ts_1.2.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5000tasklist /fo csv C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5748"C:\WINDOWS\system32\cmd.exe" /c tasklist /fo csv | find /c /i "PDNob PDF Editor.exe" > "C:\Users\admin\AppData\Local\Temp\findSoftRes.txt"C:\Windows\SysWOW64\cmd.exepdfeditor_ts_1.2.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6164"C:\Users\admin\AppData\Local\Temp\pdnob-pdf-editor_8946.exe" C:\Users\admin\AppData\Local\Temp\pdnob-pdf-editor_8946.exe
explorer.exe
User:
admin
Company:
PDNob
Integrity Level:
HIGH
Description:
PDNob Software
Version:
2.8.5.3
Modules
Images
c:\users\admin\appdata\local\temp\pdnob-pdf-editor_8946.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
4 226
Read events
4 223
Write events
3
Delete events
0

Modification events

(PID) Process:(6164) pdnob-pdf-editor_8946.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\Downloader2.5.0
Operation:writeName:GA_PC
Value:
1
(PID) Process:(6164) pdnob-pdf-editor_8946.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:guid
Value:
5F368DCB-2E97-4BDD-A771-756F17B0B430
(PID) Process:(6164) pdnob-pdf-editor_8946.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:user_id
Value:
1001
Executable files
473
Suspicious files
61
Text files
3 114
Unknown types
0

Dropped files

PID
Process
Filename
Type
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\Local\Temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe
MD5:
SHA256:
4528find.exeC:\Users\admin\AppData\Local\Temp\findSoftRes.txttext
MD5:21438EF4B9AD4FC266B6129A2F60DE29
SHA256:13BF7B3039C63BF5A50491FA3CFD8EB4E699D1BA1436315AEF9CBE5711530354
4672pdfeditor_ts_1.2.0.tmpC:\Program Files (x86)\PDNob\PDNob PDF Editor\unins000.exeexecutable
MD5:C4B29582F3D11F692AA0945921DD9377
SHA256:57165C688A117FAFA17FFF5512F33F40FD7AD5B214BBD07CC4682AA2E4D7E9AE
4672pdfeditor_ts_1.2.0.tmpC:\Program Files (x86)\PDNob\PDNob PDF Editor\7z.dllexecutable
MD5:5718C312C250DD8909029CCEA5081222
SHA256:11E5FCF30862C299D558D2CC33521E740C426DF8E0C93FCF8B9F98E337FACAC7
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\Local\Temp\pdfeditor_ts\galog.jsonbinary
MD5:F57C1884F1BCDF87A0870F05C0C9516F
SHA256:1CF5920A27AA0CCBED5963CA0B9F2BD62A69EA815633D12BD1B781DABF57D0D8
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:8C3FB99F776E11D2A8BEAB75152C6019
SHA256:170621C91CDAE7999A0626990893A68E603D82C04514B2031798C016F0B3D380
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:7F8E1E56983E3329EA3456A675906D2B
SHA256:38737ECB7E53C3F0E3C3C3834449B9D408394584FDA6476792F87E18B9385F38
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\Local\Temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe.dbtext
MD5:E2A7B4F9DF503D67AC46CC0BA9DD54B1
SHA256:F41F4E4F15BCAC8B0E5BB4323B40E79B0CD0B0DF5220D91C21BDACA254C2418F
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\Local\Temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe.xmltext
MD5:7FDDB299ED4AB79021252DE00541D6E8
SHA256:2E43CD9DD102C7375EF425A064D16F1FD7ED0F7B355C9196EC58CAC43B764C25
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_234E9B04AA8520A2E6CE0C38C9A1AE0Dder
MD5:852582CEE98B9E38D5C7C96CF4B58639
SHA256:D10A77B0B45C2525F639098DF0231048F0A14A3B84C31C1B3FDDF841FDA91266
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
106
DNS requests
32
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6164
pdnob-pdf-editor_8946.exe
GET
301
104.17.192.141:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
whitelisted
5864
svchost.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
6164
pdnob-pdf-editor_8946.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
US
binary
471 b
whitelisted
6164
pdnob-pdf-editor_8946.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
US
text
168 b
shared
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
314 b
whitelisted
6252
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
US
binary
471 b
whitelisted
6164
pdnob-pdf-editor_8946.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTjzY2p9Pa8oibmj%2BNSMWsz63kmWgQUuhbZbU2FL3MpdpovdYxqII%2BeyG8CEAuuZrxaun%2BVh8b56QTjMwQ%3D
US
binary
727 b
whitelisted
5864
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5864
svchost.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5864
svchost.exe
23.37.237.227:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
unknown
5064
SearchApp.exe
2.23.209.140:443
www.bing.com
Akamai International B.V.
GB
whitelisted
6164
pdnob-pdf-editor_8946.exe
104.18.2.37:443
data-service.afirstsoft.cn
CLOUDFLARENET
unknown
6164
pdnob-pdf-editor_8946.exe
104.18.24.249:443
update.tenorshare.com
CLOUDFLARENET
suspicious
6164
pdnob-pdf-editor_8946.exe
104.17.192.141:80
www.tenorshare.com
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 23.37.237.227
whitelisted
google.com
  • 172.217.23.110
whitelisted
www.bing.com
  • 2.23.209.140
  • 2.23.209.130
  • 2.23.209.182
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.179
  • 2.23.209.187
whitelisted
data-service.afirstsoft.cn
  • 104.18.2.37
  • 104.18.3.37
unknown
update.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
unknown
www.tenorshare.com
  • 104.17.192.141
  • 104.17.207.155
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ip-api.com
  • 208.95.112.1
shared

Threats

PID
Process
Class
Message
6164
pdnob-pdf-editor_8946.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2192
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
6164
pdnob-pdf-editor_8946.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
6164
pdnob-pdf-editor_8946.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
2 ETPRO signatures available at the full report
No debug info