File name:

pdfPilot.exe

Full analysis: https://app.any.run/tasks/72e0124d-7145-4101-9337-25d63bca829c
Verdict: Malicious activity
Analysis date: April 14, 2024, 16:31:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

9E6CB4DF7A1B7A85C1809126E04FB03A

SHA1:

22EF55E88389DAD7C86FA4590A94318ECD9B16BC

SHA256:

E29D3F18C7E0A9B5F4A20E2CB5BFA756337ADD7B25DF0198C3B04C3698A21A2E

SSDEEP:

49152:zqLYShdfUrINjoRRyfxBS1euYhrpS83GHncItqGzh38REYt51yWzZIumltbCsnUE:2L9vUrsj2RybSkrjS8Onc6t38bny2IuM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • pdfPilot.exe (PID: 1836)
    • Actions looks like stealing of personal data

      • pdfPilot.exe (PID: 1836)
  • SUSPICIOUS

    • Reads the Internet Settings

      • pdfPilot.exe (PID: 1836)
    • Reads settings of System Certificates

      • pdfPilot.exe (PID: 1836)
    • Reads security settings of Internet Explorer

      • pdfPilot.exe (PID: 1836)
  • INFO

    • Checks supported languages

      • pdfPilot.exe (PID: 1836)
    • Reads Environment values

      • pdfPilot.exe (PID: 1836)
    • Reads the machine GUID from the registry

      • pdfPilot.exe (PID: 1836)
    • Reads the software policy settings

      • pdfPilot.exe (PID: 1836)
    • Reads the computer name

      • pdfPilot.exe (PID: 1836)
    • Application launched itself

      • firefox.exe (PID: 2792)
      • firefox.exe (PID: 2064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (49.4)
.scr | Windows screen saver (23.4)
.dll | Win32 Dynamic Link Library (generic) (11.7)
.exe | Win32 Executable (generic) (8)
.exe | Generic Win/DOS Executable (3.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2040:06:03 23:53:01+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 1534464
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0x17891a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.20.2.7
ProductVersionNumber: 5.20.2.7
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: PDFPilot
FileVersion: 5.20.2.7
InternalName: pdfPilot.exe
LegalCopyright: © 2024 B.L.A ASPIRE LTD. All rights reserved.
LegalTrademarks: -
OriginalFileName: pdfPilot.exe
ProductName: PDFPilot
ProductVersion: 5.20.2.7
AssemblyVersion: 5.20.2.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
15
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pdfpilot.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
492"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2064.9.1507213021\1211303154" -childID 8 -isForBrowser -prefsHandle 4252 -prefMapHandle 4500 -prefsLen 31122 -prefMapSize 244195 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {58fddb41-0345-43a0-809b-3429c8695c0e} 2064 "\\.\pipe\gecko-crash-server-pipe.2064" 3680 ea83110 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
896"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2064.6.800988864\95487941" -childID 5 -isForBrowser -prefsHandle 3912 -prefMapHandle 4036 -prefsLen 29102 -prefMapSize 244195 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ff1b38a6-d8f9-4aaf-91f6-9a748845164c} 2064 "\\.\pipe\gecko-crash-server-pipe.2064" 4120 194fc280 tabC:\Program Files\mozilla firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
924"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2064.3.534530564\837459200" -childID 2 -isForBrowser -prefsHandle 2860 -prefMapHandle 2856 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2a5d0e09-952e-4f09-a5d7-e4a6350188fd} 2064 "\\.\pipe\gecko-crash-server-pipe.2064" 2872 164ed280 tabC:\Program Files\mozilla firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1652"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2064.4.910006480\1453054602" -childID 3 -isForBrowser -prefsHandle 3756 -prefMapHandle 3752 -prefsLen 29102 -prefMapSize 244195 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {70798df4-8ad1-4dd5-8706-36cea6705687} 2064 "\\.\pipe\gecko-crash-server-pipe.2064" 3784 1502cc90 tabC:\Program Files\mozilla firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1836"C:\Users\admin\AppData\Local\Temp\pdfPilot.exe" C:\Users\admin\AppData\Local\Temp\pdfPilot.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
PDFPilot
Version:
5.20.2.7
Modules
Images
c:\users\admin\appdata\local\temp\pdfpilot.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2064"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\mozilla firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2564"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2064.1.1516021514\1716034553" -parentBuildID 20230710165010 -prefsHandle 1404 -prefMapHandle 1400 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1981e36a-181e-4f58-9d67-fcd26879fb2c} 2064 "\\.\pipe\gecko-crash-server-pipe.2064" 1416 ea301a0 socketC:\Program Files\mozilla firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2736"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2064.5.1389971666\1743084075" -childID 4 -isForBrowser -prefsHandle 3860 -prefMapHandle 3876 -prefsLen 29102 -prefMapSize 244195 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {60137dad-a17b-4739-a0b7-af69e002bd46} 2064 "\\.\pipe\gecko-crash-server-pipe.2064" 3904 185d46d0 tabC:\Program Files\mozilla firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2792"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\mozilla firefox\firefox.exepdfPilot.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2832"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2064.0.1633914676\1268103202" -parentBuildID 20230710165010 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {251a7a6e-5455-418d-a521-d389fe6661f7} 2064 "\\.\pipe\gecko-crash-server-pipe.2064" 1196 cfa71a0 gpuC:\Program Files\mozilla firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
22 043
Read events
21 953
Write events
85
Delete events
5

Modification events

(PID) Process:(1836) pdfPilot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfPilot_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1836) pdfPilot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfPilot_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1836) pdfPilot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfPilot_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1836) pdfPilot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfPilot_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(1836) pdfPilot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfPilot_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(1836) pdfPilot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfPilot_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(1836) pdfPilot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfPilot_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1836) pdfPilot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfPilot_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1836) pdfPilot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfPilot_RASMANCS
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1836) pdfPilot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pdfPilot_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
Executable files
0
Suspicious files
83
Text files
22
Unknown types
37

Dropped files

PID
Process
Filename
Type
2064firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:
SHA256:
2064firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:
SHA256:
2064firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:
SHA256:
2064firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsonbinary
MD5:
SHA256:
2064firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:
SHA256:
2064firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:
SHA256:
2064firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:
SHA256:
2064firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:
SHA256:
2064firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:
SHA256:
2064firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
68
DNS requests
141
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2064
firefox.exe
POST
200
172.217.16.195:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
unknown
2064
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
unknown
POST
200
95.101.54.130:80
http://r3.o.lencr.org/
unknown
unknown
POST
95.101.54.130:80
http://r3.o.lencr.org/
unknown
unknown
POST
200
95.101.54.130:80
http://r3.o.lencr.org/
unknown
unknown
2064
firefox.exe
POST
95.101.54.130:80
http://r3.o.lencr.org/
unknown
unknown
2064
firefox.exe
POST
95.101.54.130:80
http://r3.o.lencr.org/
unknown
unknown
2064
firefox.exe
POST
200
172.217.16.195:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
2064
firefox.exe
POST
200
95.101.54.130:80
http://r3.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
1836
pdfPilot.exe
69.164.214.227:443
vrg.pltclient.com
Linode, LLC
US
unknown
4
System
192.168.100.255:138
whitelisted
2064
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
2064
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2064
firefox.exe
142.250.185.138:443
safebrowsing.googleapis.com
whitelisted
2064
firefox.exe
172.217.16.195:80
ocsp.pki.goog
GOOGLE
US
whitelisted
2064
firefox.exe
34.117.188.166:443
spocs.getpocket.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2064
firefox.exe
34.107.243.93:443
push.services.mozilla.com
GOOGLE
US
unknown
2064
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
vrg.pltclient.com
  • 69.164.214.227
unknown
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
spocs.getpocket.com
  • 34.117.188.166
shared
prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
unknown
r3.o.lencr.org
  • 95.101.54.130
  • 2.16.202.115
  • 2.16.241.15
  • 2.16.241.8
shared
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted

Threats

No threats detected
No debug info