File name: | SodaPDFDesktop14.exe |
Full analysis: | https://app.any.run/tasks/c32825f6-7485-46cd-888c-ecbf3f2d1a22 |
Verdict: | Malicious activity |
Analysis date: | April 11, 2024, 15:20:08 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 870D949F9544AE37CF645BEF6BDF982F |
SHA1: | EF52D28804B96AB2C2D843457C98D64482EF393A |
SHA256: | DC83925AF905F5A13806CEE2AFAE21F61D56B88969B8D268A672623B37B666F2 |
SSDEEP: | 98304:JbOi5cc2TWJu3EKMNEZqB/UNSOfuiI12GJZAV8L+Xvrk3JNv8S5CGrLv8kFfguW1:F0NzRN |
.exe | | | Win32 Executable (generic) (52.9) |
---|---|---|
.exe | | | Generic Win/DOS Executable (23.5) |
.exe | | | DOS Executable Generic (23.5) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2024:03:14 09:04:25+00:00 |
ImageFileCharacteristics: | Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 14.37 |
CodeSize: | 7525888 |
InitializedDataSize: | 4367872 |
UninitializedDataSize: | - |
EntryPoint: | 0x60552f |
OSVersion: | 5.1 |
ImageVersion: | - |
SubsystemVersion: | 5.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 14.0.407.3242 |
ProductVersionNumber: | 14.0.407.3242 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Windows NT 32-bit |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Windows, Latin1 |
CompanyName: | Avanquest Software |
FileDescription: | Soda PDF Desktop 14 Installer |
FileVersion: | 14.0.407.3242 |
InternalName: | SodaPDFDesktop14.exe |
LegalCopyright: | © 2010-2023 Avanquest Software. All rights reserved. |
OriginalFileName: | SodaPDFDesktop14.exe |
ProductName: | Soda PDF Desktop 14 Installer |
ProductVersion: | 14.0.407.3242 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
324 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3700 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
852 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2384 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
924 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1500 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1056 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1632 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1168 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4728 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1264 | "C:\Program Files\Soda PDF Desktop 14\soda-launcher.exe" --check-notifications | C:\Program Files\Soda PDF Desktop 14\soda-launcher.exe | activation-service.exe | ||||||||||||
User: admin Company: Avanquest Software Integrity Level: HIGH Description: Soda PDF Desktop 14 Exit code: 0 Version: 14.0.407.21614 Modules
| |||||||||||||||
1392 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3320 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1592 | "C:\Program Files\Soda PDF Desktop 14\soda-launcher.exe" --show-message-in-notifications "C:\Users\admin\AppData\Roaming\Soda PDF Desktop 14\mini-messages\m_AA71F4D8-FCC8-469F-9CFF-CD05DA83912F\ecdc541e-e3a9-440d-9f0d-30124bd7b65f" --channel 0 | C:\Program Files\Soda PDF Desktop 14\soda-launcher.exe | soda-launcher.exe | ||||||||||||
User: admin Company: Avanquest Software Integrity Level: HIGH Description: Soda PDF Desktop 14 Exit code: 0 Version: 14.0.407.21614 Modules
| |||||||||||||||
1656 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=ppapi --lang=en-US --device-scale-factor=1 --ppapi-antialiased-text-enabled=0 --ppapi-subpixel-rendering-setting=0 --mojo-platform-channel-handle=3972 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:6 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1776 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3328 --field-trial-handle=1292,i,13111906167732777384,4334410258498314332,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
|
(PID) Process: | (2408) SodaPDFDesktop14.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (2408) SodaPDFDesktop14.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (2408) SodaPDFDesktop14.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (2408) SodaPDFDesktop14.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (2408) SodaPDFDesktop14.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | delete value | Name: | ProxyServer |
Value: | |||
(PID) Process: | (2408) SodaPDFDesktop14.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | delete value | Name: | ProxyOverride |
Value: | |||
(PID) Process: | (2408) SodaPDFDesktop14.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
(PID) Process: | (2408) SodaPDFDesktop14.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | delete value | Name: | AutoDetect |
Value: | |||
(PID) Process: | (2408) SodaPDFDesktop14.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (2408) SodaPDFDesktop14.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2408 | SodaPDFDesktop14.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:— | SHA256:— | |||
2408 | SodaPDFDesktop14.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | binary | |
MD5:— | SHA256:— | |||
2408 | SodaPDFDesktop14.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | binary | |
MD5:— | SHA256:— | |||
2408 | SodaPDFDesktop14.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464 | binary | |
MD5:— | SHA256:— | |||
2408 | SodaPDFDesktop14.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464 | binary | |
MD5:— | SHA256:— | |||
2408 | SodaPDFDesktop14.exe | C:\ProgramData\Soda PDF Desktop 14\Installation\installer-cache | text | |
MD5:— | SHA256:— | |||
2408 | SodaPDFDesktop14.exe | C:\ProgramData\Soda PDF Desktop 14\Installation\SodaPDFDesktop14.exe | executable | |
MD5:— | SHA256:— | |||
2408 | SodaPDFDesktop14.exe | C:\ProgramData\Soda PDF Desktop 14\Installation\soda-desktop14-startup-14.0.407.21614-x86.msi | — | |
MD5:— | SHA256:— | |||
2408 | SodaPDFDesktop14.exe | C:\ProgramData\Soda PDF Desktop 14\Installation\app-config.json | binary | |
MD5:— | SHA256:— | |||
3456 | spoolsv.exe | C:\Windows\system32\spool\DRIVERS\W32X86\3\New\brand_solution_name_pdfprn_v.6.23.0.2.dll | executable | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2408 | SodaPDFDesktop14.exe | HEAD | 302 | 64.15.159.230:80 | http://download14-desktop.sodapdf.com/x86/module/main | unknown | — | — | — |
2408 | SodaPDFDesktop14.exe | GET | 304 | 23.216.77.45:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8771f4e6f85bff9e | unknown | — | — | — |
2408 | SodaPDFDesktop14.exe | GET | 302 | 64.15.159.230:80 | http://download14-desktop.sodapdf.com/x86/module/main | unknown | — | — | — |
2408 | SodaPDFDesktop14.exe | GET | 200 | 142.250.186.35:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | — | — | — |
2408 | SodaPDFDesktop14.exe | GET | 200 | 142.250.186.35:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D | unknown | — | — | — |
2408 | SodaPDFDesktop14.exe | HEAD | 302 | 64.15.159.230:80 | http://download14-desktop.sodapdf.com/x86/module/main | unknown | — | — | — |
1080 | svchost.exe | GET | 200 | 23.32.238.192:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e90c163b6659448e | unknown | — | — | — |
2408 | SodaPDFDesktop14.exe | HEAD | 302 | 64.15.159.230:80 | http://download14-desktop.sodapdf.com/x86/module/edit | unknown | — | — | — |
2408 | SodaPDFDesktop14.exe | GET | 302 | 64.15.159.230:80 | http://download14-desktop.sodapdf.com/x86/module/edit | unknown | — | — | — |
2408 | SodaPDFDesktop14.exe | HEAD | 302 | 64.15.159.230:80 | http://download14-desktop.sodapdf.com/x86/module/ocr | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
2408 | SodaPDFDesktop14.exe | 104.19.146.4:443 | wsgeoip.sodapdf.com | CLOUDFLARENET | — | unknown |
2408 | SodaPDFDesktop14.exe | 23.216.77.45:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
2408 | SodaPDFDesktop14.exe | 142.250.186.35:80 | ocsp.pki.goog | GOOGLE | US | unknown |
2408 | SodaPDFDesktop14.exe | 104.18.6.41:443 | avqservice.avanquest.com | CLOUDFLARENET | — | unknown |
2408 | SodaPDFDesktop14.exe | 104.19.145.4:443 | wsgeoip.sodapdf.com | CLOUDFLARENET | — | unknown |
2408 | SodaPDFDesktop14.exe | 64.15.159.230:80 | download14-desktop.sodapdf.com | IWEB-AS | CA | unknown |
2408 | SodaPDFDesktop14.exe | 64.15.159.230:443 | download14-desktop.sodapdf.com | IWEB-AS | CA | unknown |
Domain | IP | Reputation |
---|---|---|
wsgeoip.sodapdf.com |
| unknown |
ctldl.windowsupdate.com |
| unknown |
ocsp.pki.goog |
| unknown |
avqservice.avanquest.com |
| unknown |
api-updateservice.sodapdf.com |
| unknown |
download14-desktop.sodapdf.com |
| unknown |
redmtl.sodapdf.com |
| unknown |
oauth.sodapdf.com |
| unknown |
paygw.sodapdf.com |
| unknown |
edge.microsoft.com |
| unknown |
Process | Message |
---|---|
soda.exe | d&d: mk elem droppable div.[object Element.ClassList]#mdi-tabs-strip
|
soda.exe | d&d: initializing drag'n'drop
|
soda.exe | d&d: mk elem droppable div.[object Element.ClassList]#
|
soda.exe | doc #main: aspect checkUpdates to el button#options-panel
|
soda.exe | UMButton: componentDidMount
|
soda.exe | doc #main: el button#options-panel: updatesAvailable: false
|
soda.exe | NotificationPanel attached
|
soda.exe | NotificationPanel attached
|
soda.exe | #RibbonPanelView: call checkScrollBtns on reduce, sp:0 is_left:false is_right:false
|
soda.exe | UMButton: componentWillUnmount
|