File name:

SodaPDFDesktop14.exe

Full analysis: https://app.any.run/tasks/c32825f6-7485-46cd-888c-ecbf3f2d1a22
Verdict: Malicious activity
Analysis date: April 11, 2024, 15:20:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

870D949F9544AE37CF645BEF6BDF982F

SHA1:

EF52D28804B96AB2C2D843457C98D64482EF393A

SHA256:

DC83925AF905F5A13806CEE2AFAE21F61D56B88969B8D268A672623B37B666F2

SSDEEP:

98304:JbOi5cc2TWJu3EKMNEZqB/UNSOfuiI12GJZAV8L+Xvrk3JNv8S5CGrLv8kFfguW1:F0NzRN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SodaPDFDesktop14.exe (PID: 2408)
    • Creates a writable file in the system directory

      • spoolsv.exe (PID: 3456)
      • activation-service.exe (PID: 3748)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • SodaPDFDesktop14.exe (PID: 2408)
      • soda.exe (PID: 4012)
      • soda.exe (PID: 3644)
    • Reads security settings of Internet Explorer

      • SodaPDFDesktop14.exe (PID: 2408)
      • soda.exe (PID: 4012)
      • activation-service.exe (PID: 3748)
      • creator-app.exe (PID: 3232)
      • soda.exe (PID: 3644)
    • Reads the Internet Settings

      • SodaPDFDesktop14.exe (PID: 2408)
      • soda.exe (PID: 4012)
      • soda-launcher.exe (PID: 1264)
      • soda-launcher.exe (PID: 1592)
      • creator-app.exe (PID: 3232)
      • stats-com.exe (PID: 2784)
    • Adds/modifies Windows certificates

      • SodaPDFDesktop14.exe (PID: 2408)
    • Starts itself from another location

      • SodaPDFDesktop14.exe (PID: 2408)
    • Executable content was dropped or overwritten

      • SodaPDFDesktop14.exe (PID: 2408)
      • spoolsv.exe (PID: 3456)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2788)
      • spoolsv.exe (PID: 2656)
      • spoolsv.exe (PID: 3456)
      • activation-service.exe (PID: 3748)
      • creator-ws.exe (PID: 3572)
    • Checks Windows Trust Settings

      • SodaPDFDesktop14.exe (PID: 2408)
      • activation-service.exe (PID: 3748)
      • soda.exe (PID: 4012)
      • soda.exe (PID: 3644)
    • Creates a software uninstall entry

      • SodaPDFDesktop14.exe (PID: 2408)
    • Application launched itself

      • soda-launcher.exe (PID: 1264)
      • soda.exe (PID: 4012)
    • Searches for installed software

      • stats-com.exe (PID: 2784)
  • INFO

    • Checks supported languages

      • SodaPDFDesktop14.exe (PID: 2408)
      • SodaPDFDesktop14.exe (PID: 2832)
      • soda.exe (PID: 4012)
      • activation-service.exe (PID: 3748)
      • soda-launcher.exe (PID: 1264)
      • soda-launcher.exe (PID: 1592)
      • creator-app.exe (PID: 3232)
      • creator-ws.exe (PID: 3572)
      • soda.exe (PID: 3644)
      • tray-app.exe (PID: 2820)
      • soda.exe (PID: 3924)
      • stats-com.exe (PID: 2784)
    • Checks proxy server information

      • SodaPDFDesktop14.exe (PID: 2408)
      • activation-service.exe (PID: 3748)
    • Reads the computer name

      • SodaPDFDesktop14.exe (PID: 2408)
      • SodaPDFDesktop14.exe (PID: 2832)
      • activation-service.exe (PID: 3748)
      • soda.exe (PID: 4012)
      • soda-launcher.exe (PID: 1264)
      • soda-launcher.exe (PID: 1592)
      • creator-app.exe (PID: 3232)
      • creator-ws.exe (PID: 3572)
      • tray-app.exe (PID: 2820)
      • soda.exe (PID: 3644)
      • stats-com.exe (PID: 2784)
      • soda.exe (PID: 3924)
    • Reads the machine GUID from the registry

      • SodaPDFDesktop14.exe (PID: 2408)
      • activation-service.exe (PID: 3748)
      • soda.exe (PID: 4012)
      • soda-launcher.exe (PID: 1264)
      • creator-app.exe (PID: 3232)
      • creator-ws.exe (PID: 3572)
      • soda-launcher.exe (PID: 1592)
      • soda.exe (PID: 3644)
      • tray-app.exe (PID: 2820)
      • stats-com.exe (PID: 2784)
    • Reads the software policy settings

      • SodaPDFDesktop14.exe (PID: 2408)
      • activation-service.exe (PID: 3748)
      • soda.exe (PID: 4012)
      • soda.exe (PID: 3644)
    • Creates files or folders in the user directory

      • SodaPDFDesktop14.exe (PID: 2408)
      • activation-service.exe (PID: 3748)
      • soda.exe (PID: 4012)
      • soda-launcher.exe (PID: 1264)
      • soda-launcher.exe (PID: 1592)
      • creator-ws.exe (PID: 3572)
      • tray-app.exe (PID: 2820)
      • soda.exe (PID: 3924)
      • soda.exe (PID: 3644)
      • stats-com.exe (PID: 2784)
    • Creates files in the program directory

      • SodaPDFDesktop14.exe (PID: 2408)
      • soda.exe (PID: 4012)
      • spoolsv.exe (PID: 3456)
      • stats-com.exe (PID: 2784)
    • Manual execution by a user

      • soda.exe (PID: 4012)
      • msedge.exe (PID: 2256)
    • Application launched itself

      • msedge.exe (PID: 3004)
      • msedge.exe (PID: 2256)
    • Drops the executable file immediately after the start

      • spoolsv.exe (PID: 3456)
    • Create files in a temporary directory

      • creator-app.exe (PID: 3232)
      • soda.exe (PID: 4012)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:14 09:04:25+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.37
CodeSize: 7525888
InitializedDataSize: 4367872
UninitializedDataSize: -
EntryPoint: 0x60552f
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 14.0.407.3242
ProductVersionNumber: 14.0.407.3242
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Avanquest Software
FileDescription: Soda PDF Desktop 14 Installer
FileVersion: 14.0.407.3242
InternalName: SodaPDFDesktop14.exe
LegalCopyright: © 2010-2023 Avanquest Software. All rights reserved.
OriginalFileName: SodaPDFDesktop14.exe
ProductName: Soda PDF Desktop 14 Installer
ProductVersion: 14.0.407.3242
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
105
Monitored processes
45
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sodapdfdesktop14.exe sodapdfdesktop14.exe no specs vssvc.exe no specs rundll32.exe no specs spoolsv.exe no specs spoolsv.exe activation-service.exe soda.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs soda-launcher.exe soda-launcher.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs creator-app.exe no specs creator-ws.exe no specs msedge.exe no specs msedge.exe no specs soda.exe no specs tray-app.exe soda.exe no specs stats-com.exe sodapdfdesktop14.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
324"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3700 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
852"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2384 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
924"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1500 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1056"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1632 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1168"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4728 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1264"C:\Program Files\Soda PDF Desktop 14\soda-launcher.exe" --check-notificationsC:\Program Files\Soda PDF Desktop 14\soda-launcher.exe
activation-service.exe
User:
admin
Company:
Avanquest Software
Integrity Level:
HIGH
Description:
Soda PDF Desktop 14
Exit code:
0
Version:
14.0.407.21614
Modules
Images
c:\program files\soda pdf desktop 14\soda-launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
1392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3320 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1592"C:\Program Files\Soda PDF Desktop 14\soda-launcher.exe" --show-message-in-notifications "C:\Users\admin\AppData\Roaming\Soda PDF Desktop 14\mini-messages\m_AA71F4D8-FCC8-469F-9CFF-CD05DA83912F\ecdc541e-e3a9-440d-9f0d-30124bd7b65f" --channel 0C:\Program Files\Soda PDF Desktop 14\soda-launcher.exe
soda-launcher.exe
User:
admin
Company:
Avanquest Software
Integrity Level:
HIGH
Description:
Soda PDF Desktop 14
Exit code:
0
Version:
14.0.407.21614
Modules
Images
c:\program files\soda pdf desktop 14\soda-launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
1656"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=ppapi --lang=en-US --device-scale-factor=1 --ppapi-antialiased-text-enabled=0 --ppapi-subpixel-rendering-setting=0 --mojo-platform-channel-handle=3972 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:6C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1776"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3328 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
58 367
Read events
57 387
Write events
938
Delete events
42

Modification events

(PID) Process:(2408) SodaPDFDesktop14.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2408) SodaPDFDesktop14.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2408) SodaPDFDesktop14.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2408) SodaPDFDesktop14.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2408) SodaPDFDesktop14.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(2408) SodaPDFDesktop14.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(2408) SodaPDFDesktop14.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(2408) SodaPDFDesktop14.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(2408) SodaPDFDesktop14.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2408) SodaPDFDesktop14.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
7
Suspicious files
72
Text files
85
Unknown types
58

Dropped files

PID
Process
Filename
Type
2408SodaPDFDesktop14.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
2408SodaPDFDesktop14.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:
SHA256:
2408SodaPDFDesktop14.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:
SHA256:
2408SodaPDFDesktop14.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:
SHA256:
2408SodaPDFDesktop14.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:
SHA256:
2408SodaPDFDesktop14.exeC:\ProgramData\Soda PDF Desktop 14\Installation\installer-cachetext
MD5:
SHA256:
2408SodaPDFDesktop14.exeC:\ProgramData\Soda PDF Desktop 14\Installation\SodaPDFDesktop14.exeexecutable
MD5:
SHA256:
2408SodaPDFDesktop14.exeC:\ProgramData\Soda PDF Desktop 14\Installation\soda-desktop14-startup-14.0.407.21614-x86.msi
MD5:
SHA256:
2408SodaPDFDesktop14.exeC:\ProgramData\Soda PDF Desktop 14\Installation\app-config.jsonbinary
MD5:
SHA256:
3456spoolsv.exeC:\Windows\system32\spool\DRIVERS\W32X86\3\New\brand_solution_name_pdfprn_v.6.23.0.2.dllexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
72
DNS requests
69
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2408
SodaPDFDesktop14.exe
HEAD
302
64.15.159.230:80
http://download14-desktop.sodapdf.com/x86/module/main
unknown
2408
SodaPDFDesktop14.exe
GET
304
23.216.77.45:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8771f4e6f85bff9e
unknown
2408
SodaPDFDesktop14.exe
GET
302
64.15.159.230:80
http://download14-desktop.sodapdf.com/x86/module/main
unknown
2408
SodaPDFDesktop14.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
2408
SodaPDFDesktop14.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
unknown
2408
SodaPDFDesktop14.exe
HEAD
302
64.15.159.230:80
http://download14-desktop.sodapdf.com/x86/module/main
unknown
1080
svchost.exe
GET
200
23.32.238.192:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e90c163b6659448e
unknown
2408
SodaPDFDesktop14.exe
HEAD
302
64.15.159.230:80
http://download14-desktop.sodapdf.com/x86/module/edit
unknown
2408
SodaPDFDesktop14.exe
GET
302
64.15.159.230:80
http://download14-desktop.sodapdf.com/x86/module/edit
unknown
2408
SodaPDFDesktop14.exe
HEAD
302
64.15.159.230:80
http://download14-desktop.sodapdf.com/x86/module/ocr
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
2408
SodaPDFDesktop14.exe
104.19.146.4:443
wsgeoip.sodapdf.com
CLOUDFLARENET
unknown
2408
SodaPDFDesktop14.exe
23.216.77.45:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2408
SodaPDFDesktop14.exe
142.250.186.35:80
ocsp.pki.goog
GOOGLE
US
unknown
2408
SodaPDFDesktop14.exe
104.18.6.41:443
avqservice.avanquest.com
CLOUDFLARENET
unknown
2408
SodaPDFDesktop14.exe
104.19.145.4:443
wsgeoip.sodapdf.com
CLOUDFLARENET
unknown
2408
SodaPDFDesktop14.exe
64.15.159.230:80
download14-desktop.sodapdf.com
IWEB-AS
CA
unknown
2408
SodaPDFDesktop14.exe
64.15.159.230:443
download14-desktop.sodapdf.com
IWEB-AS
CA
unknown

DNS requests

Domain
IP
Reputation
wsgeoip.sodapdf.com
  • 104.19.146.4
  • 104.19.145.4
unknown
ctldl.windowsupdate.com
  • 23.216.77.45
  • 23.216.77.62
  • 23.216.77.44
  • 23.32.238.192
  • 23.32.238.201
  • 23.32.238.171
  • 23.32.238.232
  • 23.32.238.179
  • 23.32.238.241
  • 23.32.238.169
  • 23.32.238.226
  • 23.32.238.240
unknown
ocsp.pki.goog
  • 142.250.186.35
unknown
avqservice.avanquest.com
  • 104.18.6.41
  • 104.18.7.41
unknown
api-updateservice.sodapdf.com
  • 104.19.145.4
  • 104.19.146.4
unknown
download14-desktop.sodapdf.com
  • 64.15.159.230
unknown
redmtl.sodapdf.com
  • 104.19.145.4
  • 104.19.146.4
unknown
oauth.sodapdf.com
  • 104.19.146.4
  • 104.19.145.4
unknown
paygw.sodapdf.com
  • 104.19.145.4
  • 104.19.146.4
unknown
edge.microsoft.com
  • 13.107.22.239
  • 131.253.33.239
unknown

Threats

No threats detected
Process
Message
soda.exe
d&d: mk elem droppable div.[object Element.ClassList]#mdi-tabs-strip
soda.exe
d&d: initializing drag'n'drop
soda.exe
d&d: mk elem droppable div.[object Element.ClassList]#
soda.exe
doc #main: aspect checkUpdates to el button#options-panel
soda.exe
UMButton: componentDidMount
soda.exe
doc #main: el button#options-panel: updatesAvailable: false
soda.exe
NotificationPanel attached
soda.exe
NotificationPanel attached
soda.exe
#RibbonPanelView: call checkScrollBtns on reduce, sp:0 is_left:false is_right:false
soda.exe
UMButton: componentWillUnmount