File name:

pdnob-pdf-editor_8946.exe

Full analysis: https://app.any.run/tasks/33f1cd89-b4f2-4902-a146-7d0966995c52
Verdict: Malicious activity
Analysis date: January 02, 2025, 19:16:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

0717BB6347D511D9EFA74FAD1CF9097C

SHA1:

9B561A1ACAFF6E73CE676B19FB955D0338BAEA42

SHA256:

AABCA2B5CEB657E49FFDA7495805E1CE090634029739CEBECD2AD16D2FED0C4F

SSDEEP:

98304:tC7wWqznnKgE9L0PeP8MOEa2VoovjpxyCsyxcMYdzrOgAFwgC7zy2uHf0lGSWyqB:SHOs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks for external IP

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • svchost.exe (PID: 2192)
    • Potential Corporate Privacy Violation

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Reads security settings of Internet Explorer

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Executable content was dropped or overwritten

      • pdfeditor_ts_1.2.0.exe (PID: 624)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Checks Windows Trust Settings

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Reads the Windows owner or organization settings

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Starts CMD.EXE for commands execution

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Get information on the list of running processes

      • cmd.exe (PID: 5748)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Drops 7-zip archiver for unpacking

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • The process drops C-runtime libraries

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Process drops legitimate windows executable

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
  • INFO

    • Checks supported languages

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.exe (PID: 624)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Reads the computer name

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • The sample compiled with english language support

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Checks proxy server information

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Creates files in the program directory

      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • UPX packer has been detected

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Reads the machine GUID from the registry

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Creates files or folders in the user directory

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Create files in a temporary directory

      • pdfeditor_ts_1.2.0.exe (PID: 624)
      • pdnob-pdf-editor_8946.exe (PID: 6164)
      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • Reads the software policy settings

      • pdnob-pdf-editor_8946.exe (PID: 6164)
    • Process checks computer location settings

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • The process uses the downloaded file

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
    • The sample compiled with chinese language support

      • pdfeditor_ts_1.2.0.tmp (PID: 4672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:03 10:13:58+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1961984
InitializedDataSize: 204800
UninitializedDataSize: 1867776
EntryPoint: 0x3a7990
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.8.5.3
ProductVersionNumber: 2.8.5.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: PDNob
FileDescription: PDNob Software
FileVersion: 2.8.5.3
LegalCopyright: Copyright © 2007-2024 TENORSHARE(HONGKONG)LIMITED All Rights Reserved.
ProductName: 20241203181317
ProductVersion: 2.8.5.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pdnob-pdf-editor_8946.exe svchost.exe pdfeditor_ts_1.2.0.exe pdfeditor_ts_1.2.0.tmp cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs pdnob-pdf-editor_8946.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
396\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
624 /VERYSILENT /SP- /NORESTART /DIR="C:\Program Files (x86)\PDNob\PDNob PDF Editor\" /LANG=en /LOG="C:\Users\admin\AppData\Local\Temp\PDNob PDF Editor_Setup_20250102191740.log" /sptrack "pdnob-pdf-editor_8946.exe"C:\Users\admin\AppData\Local\Temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe
pdnob-pdf-editor_8946.exe
User:
admin
Company:
PDNob
Integrity Level:
HIGH
Description:
PDNob PDF Editor Setup
Version:
1.2.0
Modules
Images
c:\users\admin\appdata\local\temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2192C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3952"C:\Users\admin\AppData\Local\Temp\pdnob-pdf-editor_8946.exe" C:\Users\admin\AppData\Local\Temp\pdnob-pdf-editor_8946.exeexplorer.exe
User:
admin
Company:
PDNob
Integrity Level:
MEDIUM
Description:
PDNob Software
Exit code:
3221226540
Version:
2.8.5.3
Modules
Images
c:\users\admin\appdata\local\temp\pdnob-pdf-editor_8946.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4528find /c /i "PDNob PDF Editor.exe" C:\Windows\SysWOW64\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\find.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4672"C:\Users\admin\AppData\Local\Temp\is-9B1CB.tmp\pdfeditor_ts_1.2.0.tmp" /SL5="$50242,176990026,357376,C:\Users\admin\AppData\Local\Temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe" /VERYSILENT /SP- /NORESTART /DIR="C:\Program Files (x86)\PDNob\PDNob PDF Editor\" /LANG=en /LOG="C:\Users\admin\AppData\Local\Temp\PDNob PDF Editor_Setup_20250102191740.log" /sptrack "pdnob-pdf-editor_8946.exe"C:\Users\admin\AppData\Local\Temp\is-9B1CB.tmp\pdfeditor_ts_1.2.0.tmp
pdfeditor_ts_1.2.0.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9b1cb.tmp\pdfeditor_ts_1.2.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5000tasklist /fo csv C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5748"C:\WINDOWS\system32\cmd.exe" /c tasklist /fo csv | find /c /i "PDNob PDF Editor.exe" > "C:\Users\admin\AppData\Local\Temp\findSoftRes.txt"C:\Windows\SysWOW64\cmd.exepdfeditor_ts_1.2.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6164"C:\Users\admin\AppData\Local\Temp\pdnob-pdf-editor_8946.exe" C:\Users\admin\AppData\Local\Temp\pdnob-pdf-editor_8946.exe
explorer.exe
User:
admin
Company:
PDNob
Integrity Level:
HIGH
Description:
PDNob Software
Version:
2.8.5.3
Modules
Images
c:\users\admin\appdata\local\temp\pdnob-pdf-editor_8946.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
4 226
Read events
4 223
Write events
3
Delete events
0

Modification events

(PID) Process:(6164) pdnob-pdf-editor_8946.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\Downloader2.5.0
Operation:writeName:GA_PC
Value:
1
(PID) Process:(6164) pdnob-pdf-editor_8946.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:guid
Value:
5F368DCB-2E97-4BDD-A771-756F17B0B430
(PID) Process:(6164) pdnob-pdf-editor_8946.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:user_id
Value:
1001
Executable files
473
Suspicious files
61
Text files
3 114
Unknown types
0

Dropped files

PID
Process
Filename
Type
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\Local\Temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe
MD5:
SHA256:
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\Local\Temp\pdfeditor_ts\galog.jsonbinary
MD5:F57C1884F1BCDF87A0870F05C0C9516F
SHA256:1CF5920A27AA0CCBED5963CA0B9F2BD62A69EA815633D12BD1B781DABF57D0D8
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:8C3FB99F776E11D2A8BEAB75152C6019
SHA256:170621C91CDAE7999A0626990893A68E603D82C04514B2031798C016F0B3D380
624pdfeditor_ts_1.2.0.exeC:\Users\admin\AppData\Local\Temp\is-9B1CB.tmp\pdfeditor_ts_1.2.0.tmpexecutable
MD5:C4B29582F3D11F692AA0945921DD9377
SHA256:57165C688A117FAFA17FFF5512F33F40FD7AD5B214BBD07CC4682AA2E4D7E9AE
4672pdfeditor_ts_1.2.0.tmpC:\Users\admin\AppData\Local\Temp\is-AKDJJ.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\Local\Temp\pdfeditor_ts\pdfeditor_ts_1.2.0.exe.dbtext
MD5:E2A7B4F9DF503D67AC46CC0BA9DD54B1
SHA256:F41F4E4F15BCAC8B0E5BB4323B40E79B0CD0B0DF5220D91C21BDACA254C2418F
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:7F8E1E56983E3329EA3456A675906D2B
SHA256:38737ECB7E53C3F0E3C3C3834449B9D408394584FDA6476792F87E18B9385F38
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\3E3E9689537B6B136ECF210088069D55_E93D4349D1D2AF4AE2F3CBFF382A5C9Dbinary
MD5:21B2166E2620A1FB1641C1E625FE9C7F
SHA256:17ABF8FA2438E097DA12DB3F61BF82DFF794B8B03AB62FF9AF96119725B30BB5
6164pdnob-pdf-editor_8946.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_234E9B04AA8520A2E6CE0C38C9A1AE0Dbinary
MD5:F84278A67EA73063D996D242A5534236
SHA256:59AA0634475B60FA47944742F9D052F3113A4B3DC3D459FFA07099976BCD5D10
4672pdfeditor_ts_1.2.0.tmpC:\Program Files (x86)\PDNob\PDNob PDF Editor\PDNob PDF Editor.exeexecutable
MD5:102434248C51E5DFA7C2932AD8876BCE
SHA256:7301A475CE28E977AAFD1B3663A3CF068B7C761AFA128652B75BBDBAD15171D4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
106
DNS requests
32
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5864
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6164
pdnob-pdf-editor_8946.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
whitelisted
5864
svchost.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6164
pdnob-pdf-editor_8946.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
unknown
shared
6164
pdnob-pdf-editor_8946.exe
GET
301
104.17.192.141:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
whitelisted
6252
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7160
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7160
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5864
svchost.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5864
svchost.exe
23.37.237.227:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
unknown
5064
SearchApp.exe
2.23.209.140:443
www.bing.com
Akamai International B.V.
GB
whitelisted
6164
pdnob-pdf-editor_8946.exe
104.18.2.37:443
data-service.afirstsoft.cn
CLOUDFLARENET
unknown
6164
pdnob-pdf-editor_8946.exe
104.18.24.249:443
update.tenorshare.com
CLOUDFLARENET
suspicious
6164
pdnob-pdf-editor_8946.exe
104.17.192.141:80
www.tenorshare.com
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 23.37.237.227
whitelisted
google.com
  • 172.217.23.110
whitelisted
www.bing.com
  • 2.23.209.140
  • 2.23.209.130
  • 2.23.209.182
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.179
  • 2.23.209.187
whitelisted
data-service.afirstsoft.cn
  • 104.18.2.37
  • 104.18.3.37
unknown
update.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
unknown
www.tenorshare.com
  • 104.17.192.141
  • 104.17.207.155
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ip-api.com
  • 208.95.112.1
shared

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
2 ETPRO signatures available at the full report
No debug info