File name:

Soda_PDF_6_Installer.exe

Full analysis: https://app.any.run/tasks/ca377ad7-42b1-471e-8f93-cde34ca0b508
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 21, 2019, 01:12:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
loader
PUA
Lulu
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

AF71FB9E57248DA7EA50999B85394147

SHA1:

E9F86405B764E40D571EAE91E82844B0C56E85B0

SHA256:

E72717ABCBCA323E60C3B5E3BF685967D0707A2492E6C14099B81C0B93BC191C

SSDEEP:

196608:x3247Rar3qw6aYqRC2HbFyuA9+NoYc+Z04cp4ArqNjeBEp2NJXCS8ZBlyAv0RbI:bYRCFVZYc+ZJc7rqNBp2NJToBUbI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • Soda_PDF_6_Installer.exe (PID: 2276)
    • Loads dropped or rewritten executable

      • Soda_PDF_6_Installer.exe (PID: 2276)
      • regsvr32.exe (PID: 1304)
      • MsiExec.exe (PID: 2788)
      • crash-handler-ws.exe (PID: 1440)
      • MsiExec.exe (PID: 2468)
      • ws.exe (PID: 3212)
      • MsiExec.exe (PID: 2228)
    • Downloads executable files from the Internet

      • Soda_PDF_6_Installer.exe (PID: 2276)
    • Application was dropped or rewritten from another process

      • Soda Manager.exe (PID: 3288)
      • crash-handler-ws.exe (PID: 1440)
      • ws.exe (PID: 3212)
      • Soda Manager.exe (PID: 184)
    • Changes settings of System certificates

      • msiexec.exe (PID: 2796)
  • SUSPICIOUS

    • Starts itself from another location

      • Soda_PDF_6_Installer.exe (PID: 2276)
    • Executable content was dropped or overwritten

      • Soda_PDF_6_Installer.exe (PID: 2276)
      • msiexec.exe (PID: 2796)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 1304)
      • MsiExec.exe (PID: 2468)
      • MsiExec.exe (PID: 2228)
      • MsiExec.exe (PID: 2788)
    • Creates files in the program directory

      • Soda_PDF_6_Installer.exe (PID: 2276)
    • Executed as Windows Service

      • vssvc.exe (PID: 2736)
      • Soda Manager.exe (PID: 184)
    • Executed via COM

      • DrvInst.exe (PID: 2544)
      • DrvInst.exe (PID: 1796)
      • DrvInst.exe (PID: 676)
      • DrvInst.exe (PID: 2244)
      • DrvInst.exe (PID: 1412)
      • DrvInst.exe (PID: 3540)
      • DrvInst.exe (PID: 3324)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 2796)
    • Creates a software uninstall entry

      • Soda_PDF_6_Installer.exe (PID: 2276)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 2796)
    • Adds / modifies Windows certificates

      • msiexec.exe (PID: 2796)
  • INFO

    • Searches for installed software

      • msiexec.exe (PID: 2796)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 2736)
    • Adds / modifies Windows certificates

      • DrvInst.exe (PID: 2544)
      • DrvInst.exe (PID: 676)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 2544)
      • DrvInst.exe (PID: 676)
    • Application launched itself

      • msiexec.exe (PID: 2796)
    • Dropped object may contain Bitcoin addresses

      • msiexec.exe (PID: 2796)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2796)
    • Creates files in the program directory

      • msiexec.exe (PID: 2796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.ax | DirectShow filter (53.2)
.odttf | Obfuscated subsetted Font (13.7)
.exe | Win32 Executable (generic) (1.1)
.exe | Generic Win/DOS Executable (0.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:12:09 15:46:47+01:00
PEType: PE32
LinkerVersion: 10
CodeSize: 4476416
InitializedDataSize: 5869568
UninitializedDataSize: -
EntryPoint: 0x3c4fd4
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 6.5.22.26218
ProductVersionNumber: 6.5.22.26218
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: LULU Software Limited
FileDescription: Soda PDF 6 Installer
FileVersion: 6.5.22.26218
InternalName: PDF Installer.exe
LegalCopyright: © "LULU Software Limited" 2010-2013. All rights reserved.
OriginalFileName: PDF Installer.exe
ProductName: Soda PDF 6 Installer
ProductVersion: 6.5.22.26218

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 09-Dec-2015 14:46:47
Detected languages:
  • English - United States
  • Russian - Russia
TLS Callbacks: 1 callback(s) detected.
Debug artifacts:
  • W:\TemporaryBuilds\29\166\src\Trunk\_bin\Win32\Release\GlamInstallerCom\GlamInstallerCom.pdb
CompanyName: LULU Software Limited
FileDescription: Soda PDF 6 Installer
FileVersion: 6.5.22.26218
InternalName: PDF Installer.exe
LegalCopyright: © "LULU Software Limited" 2010-2013. All rights reserved.
OriginalFilename: PDF Installer.exe
ProductName: Soda PDF 6 Installer
ProductVersion: 6.5.22.26218

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000118

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 6
Time date stamp: 09-Dec-2015 14:46:47
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00444D80
0x00444E00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.67336
.rdata
0x00446000
0x000E3C06
0x000E3E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.38831
.data
0x0052A000
0x00048EA4
0x00030200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.57987
.tls
0x00573000
0x00000002
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x00574000
0x00423D90
0x00423E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.06646
.reloc
0x00998000
0x00060FE6
0x00061000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
4.98372

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.13457
560
Latin 1 / Western European
English - United States
RT_MANIFEST
2
4.23411
4264
Latin 1 / Western European
English - United States
RT_ICON
3
3.90074
9640
Latin 1 / Western European
English - United States
RT_ICON
4
3.04588
308
Latin 1 / Western European
English - United States
RT_CURSOR
5
2.63031
308
Latin 1 / Western European
English - United States
RT_CURSOR
6
2.1867
308
Latin 1 / Western European
English - United States
RT_CURSOR
7
1.78405
64
Latin 1 / Western European
English - United States
RT_STRING
13
1.8271
64
Latin 1 / Western European
Russian - Russia
RT_STRING
101
2.79248
12
Latin 1 / Western European
English - United States
REGISTRY
106
5.32964
477
Latin 1 / Western European
Russian - Russia
REGISTRY

Imports

ADVAPI32.dll (delay-loaded)
COMCTL32.dll
COMDLG32.dll
GDI32.dll
IMM32.dll
KERNEL32.dll
OLEACC.dll
OLEAUT32.dll
SHELL32.dll
SHLWAPI.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
22
Malicious processes
5
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start soda_pdf_6_installer.exe soda_pdf_6_installer.exe no specs regsvr32.exe no specs msiexec.exe vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs soda manager.exe no specs soda manager.exe no specs drvinst.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs crash-handler-ws.exe no specs ws.exe no specs msiexec.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs soda_pdf_6_installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
184"C:\ProgramData\LULU Software\Soda PDF 6 Manager\Soda PDF 6\Soda Manager.exe"C:\ProgramData\LULU Software\Soda PDF 6 Manager\Soda PDF 6\Soda Manager.exeservices.exe
User:
SYSTEM
Company:
LULU Software Limited
Integrity Level:
SYSTEM
Description:
Messenger service
Exit code:
0
Version:
8.1.0.0
Modules
Images
c:\programdata\lulu software\soda pdf 6 manager\soda pdf 6\soda manager.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
676DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot20" "" "" "65dbac317" "00000000" "000003C4" "000003EC"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1304regsvr32.exe /s "C:\ProgramData\Soda PDF 6\Installation\Statistics.dll"C:\Windows\system32\regsvr32.exeSoda_PDF_6_Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1412DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot21" "" "" "6f9bf5bcb" "00000000" "000003EC" "00000544"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1440"C:\Program Files\Soda PDF 6\crash-handler-ws.exe" -serviceC:\Program Files\Soda PDF 6\crash-handler-ws.exemsiexec.exe
User:
admin
Company:
LULU SOFTWARE LIMITED
Integrity Level:
HIGH
Description:
Soda PDF 6
Exit code:
0
Version:
6.5.6.26201
Modules
Images
c:\program files\soda pdf 6\crash-handler-ws.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1796DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot19" "" "" "61530dda3" "00000000" "000004AC" "00000334"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2228"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Soda PDF 6\ie-pdf-previewer.dll"C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2244DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot23" "" "" "631c88d3b" "00000000" "000003C4" "0000055C"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2276"C:\Users\admin\AppData\Local\Temp\Soda_PDF_6_Installer.exe" C:\Users\admin\AppData\Local\Temp\Soda_PDF_6_Installer.exe
explorer.exe
User:
admin
Company:
LULU Software Limited
Integrity Level:
HIGH
Description:
Soda PDF 6 Installer
Exit code:
0
Version:
6.5.22.26218
Modules
Images
c:\users\admin\appdata\local\temp\soda_pdf_6_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\wininet.dll
2468"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Soda PDF 6\ax-pdf-viewer.dll"C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
7 376
Read events
5 111
Write events
2 181
Delete events
84

Modification events

(PID) Process:(2276) Soda_PDF_6_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Soda PDF 6\Installation
Operation:writeName:INSTALL_FOLDER
Value:
C:\Program Files\Soda PDF 6
(PID) Process:(2276) Soda_PDF_6_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Soda_PDF_6_Installer_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2276) Soda_PDF_6_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Soda_PDF_6_Installer_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2276) Soda_PDF_6_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Soda_PDF_6_Installer_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(2276) Soda_PDF_6_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Soda_PDF_6_Installer_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(2276) Soda_PDF_6_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Soda_PDF_6_Installer_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2276) Soda_PDF_6_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Soda_PDF_6_Installer_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2276) Soda_PDF_6_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Soda_PDF_6_Installer_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2276) Soda_PDF_6_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Soda_PDF_6_Installer_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2276) Soda_PDF_6_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Soda_PDF_6_Installer_RASMANCS
Operation:writeName:FileTracingMask
Value:
4294901760
Executable files
118
Suspicious files
240
Text files
719
Unknown types
7

Dropped files

PID
Process
Filename
Type
2276Soda_PDF_6_Installer.exeC:\ProgramData\Soda PDF 6\Installation\statistic.xml.zip
MD5:
SHA256:
2796msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2544DrvInst.exeC:\Windows\INF\setupapi.ev1binary
MD5:
SHA256:
2276Soda_PDF_6_Installer.exeC:\Users\admin\AppData\Local\Temp\WebCompanionInstaller.exeexecutable
MD5:
SHA256:
2276Soda_PDF_6_Installer.exeC:\ProgramData\Soda PDF 6\Installation\statistic.xmlcompressed
MD5:
SHA256:
2276Soda_PDF_6_Installer.exeC:\ProgramData\Soda PDF 6\Installation\Statistics.dllexecutable
MD5:
SHA256:
2544DrvInst.exeC:\Windows\INF\setupapi.dev.logini
MD5:
SHA256:
2276Soda_PDF_6_Installer.exeC:\ProgramData\Soda PDF 6\Installation\Soda_Manager_Setup_6.0.0.0.msiexecutable
MD5:
SHA256:
2796msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:
SHA256:
2796msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{e8a846cf-5a5f-4165-a509-0a74a6cc7de7}_OnDiskSnapshotPropbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
97
TCP/UDP connections
97
DNS requests
7
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2276
Soda_PDF_6_Installer.exe
HEAD
302
64.15.159.202:80
http://download6.sodapdf.com/module/main
CA
suspicious
2276
Soda_PDF_6_Installer.exe
HEAD
302
64.15.159.203:80
http://cdn.lulusoft.com/download/sodapdf/sodapdf6/main
CA
suspicious
2276
Soda_PDF_6_Installer.exe
HEAD
200
64.15.159.204:80
http://redamex.sodapdf.com/sodapdf6/6.5.6.26201/soda6-startup-6.5.6.26201.msi
CA
suspicious
2276
Soda_PDF_6_Installer.exe
HEAD
302
64.15.159.202:80
http://download6.sodapdf.com/module/main
CA
suspicious
2276
Soda_PDF_6_Installer.exe
HEAD
302
64.15.159.202:80
http://download6.sodapdf.com/module/review
CA
suspicious
2276
Soda_PDF_6_Installer.exe
HEAD
200
64.15.159.204:80
http://redamex.sodapdf.com/sodapdf6/6.5.6.26201/soda6-startup-6.5.6.26201.msi
CA
suspicious
2276
Soda_PDF_6_Installer.exe
HEAD
302
64.15.159.203:80
http://cdn.lulusoft.com/download/sodapdf/sodapdf6/main
CA
suspicious
2276
Soda_PDF_6_Installer.exe
HEAD
302
64.15.159.203:80
http://cdn.lulusoft.com/download/sodapdf/sodapdf6/review
CA
suspicious
2276
Soda_PDF_6_Installer.exe
HEAD
200
64.15.159.204:80
http://redamex.sodapdf.com/sodapdf6/6.5.6.26201/soda6-review-module-6.5.6.26201.msi
CA
suspicious
2276
Soda_PDF_6_Installer.exe
HEAD
302
64.15.159.202:80
http://download6.sodapdf.com/module/insert
CA
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2276
Soda_PDF_6_Installer.exe
64.15.159.203:80
update.lulusoft.com
iWeb Technologies Inc.
CA
suspicious
2276
Soda_PDF_6_Installer.exe
64.15.159.202:80
download6.sodapdf.com
iWeb Technologies Inc.
CA
suspicious
2276
Soda_PDF_6_Installer.exe
64.15.159.204:80
redamex.sodapdf.com
iWeb Technologies Inc.
CA
suspicious
64.15.159.204:80
redamex.sodapdf.com
iWeb Technologies Inc.
CA
suspicious
2276
Soda_PDF_6_Installer.exe
104.17.177.102:80
webcompanion.com
Cloudflare Inc
US
shared
2796
msiexec.exe
205.185.216.42:80
www.download.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
update.lulusoft.com
  • 64.15.159.203
suspicious
wsgeoip.lulusoft.com
  • 64.15.159.203
suspicious
download6.sodapdf.com
  • 64.15.159.202
unknown
cdn.lulusoft.com
  • 64.15.159.203
suspicious
redamex.sodapdf.com
  • 64.15.159.204
suspicious
webcompanion.com
  • 104.17.177.102
  • 104.17.178.102
malicious
www.download.windowsupdate.com
  • 205.185.216.42
  • 205.185.216.10
whitelisted

Threats

PID
Process
Class
Message
2276
Soda_PDF_6_Installer.exe
Misc activity
SUSPICIOUS [PTsecurity] External IP Lookup (lulusoft.com)
2276
Soda_PDF_6_Installer.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2276
Soda_PDF_6_Installer.exe
Misc activity
ET INFO EXE - Served Attached HTTP
1 ETPRO signatures available at the full report
No debug info