| File name: | Foxit.PDF.Editor.Patch-v2024-v13.rar |
| Full analysis: | https://app.any.run/tasks/00eaa35d-cd46-4d7e-9d6c-bd13cd3d4804 |
| Verdict: | Malicious activity |
| Analysis date: | February 25, 2025, 19:16:04 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 6F8FE04933C88323B46042448C0C6932 |
| SHA1: | 9D5FB8B0CA8F9253B3641046AF928AB84711B277 |
| SHA256: | EAA6910D6AE5EB8E044F0E46FE73002EF0264273D800865B6D43DB18AC45D0C5 |
| SSDEEP: | 24576:3bVpBcFvBLZd6/c9juCFU8Y70Lp7coOdVwg07ut3zuyB:3bVpBcJBLZd6/c9juCFU8Y70Lp7coOfV |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
| FileVersion: | RAR v5 |
|---|---|
| CompressedSize: | 542291 |
| UncompressedSize: | 620544 |
| OperatingSystem: | Win32 |
| ArchivedFileName: | Patch/Foxit.PDF.Editor.2024-Patch.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1140 | "C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe" | C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1468 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Foxit.PDF.Editor.Patch-v2024-v13.rar | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1536 | "C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe" | C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2100 | "C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe" | C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3420 | "C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe" | C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3612 | "C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe" | C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3772 | "C:\Users\admin\Desktop\Foxit.PDF.Editor.2024-Patch.exe" | C:\Users\admin\Desktop\Foxit.PDF.Editor.2024-Patch.exe | explorer.exe | ||||||||||||
User: admin Company: Soda120 Integrity Level: HIGH Description: Patch - Foxit PDF Editor [Pro/Suite] Exit code: 0 Version: 1.1 Modules
| |||||||||||||||
| 4076 | "C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe" | C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 4544 | "C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe" | C:\Users\admin\Desktop\FoxitPDFEditor13.1.4 Patch.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 4980 | "C:\Users\admin\Desktop\Foxit.PDF.Editor.2024-Patch.exe" | C:\Users\admin\Desktop\Foxit.PDF.Editor.2024-Patch.exe | — | explorer.exe | |||||||||||
User: admin Company: Soda120 Integrity Level: MEDIUM Description: Patch - Foxit PDF Editor [Pro/Suite] Exit code: 3221226540 Version: 1.1 Modules
| |||||||||||||||
| (PID) Process: | (1468) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (1468) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (1468) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (1468) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Foxit.PDF.Editor.Patch-v2024-v13.rar | |||
| (PID) Process: | (1468) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1468) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1468) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1468) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1468) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 256 | |||
| (PID) Process: | (1468) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5456 | Foxit.PDF.Editor.2024-Patch.exe | C:\Users\admin\AppData\Local\Temp\dup2patcher.dll | executable | |
MD5:A09136A99323D200AAF082519744622D | SHA256:B9E27014E74A7482D1419118C72BB1DDD60DE3111D64B88F05D407B93BF3B738 | |||
| 6240 | FoxitPDFEditor13.1.4 Patch.exe | C:\Users\admin\AppData\Local\Temp\9CE5948F6F706809AD1DF3709868DF94.dll | executable | |
MD5:B89C8298E8CBDC72D9A0A9DABE0A9F2B | SHA256:301EFDA3003A4A40C3BA5071A89BA88ED00A055F95A959A38A5A7EEF88E9A82D | |||
| 7132 | Foxit.PDF.Editor.2024-Patch.exe | C:\Users\admin\AppData\Local\Temp\dup2patcher.dll | executable | |
MD5:A09136A99323D200AAF082519744622D | SHA256:B9E27014E74A7482D1419118C72BB1DDD60DE3111D64B88F05D407B93BF3B738 | |||
| 5456 | Foxit.PDF.Editor.2024-Patch.exe | C:\Users\admin\AppData\Local\Temp\bassmod.dll | executable | |
MD5:E4EC57E8508C5C4040383EBE6D367928 | SHA256:8AD9E47693E292F381DA42DDC13724A3063040E51C26F4CA8E1F8E2F1DDD547F | |||
| 3420 | FoxitPDFEditor13.1.4 Patch.exe | C:\Users\admin\AppData\Local\Temp\9CE5948F6F706809AD1DF3709868DF94.dll | executable | |
MD5:B89C8298E8CBDC72D9A0A9DABE0A9F2B | SHA256:301EFDA3003A4A40C3BA5071A89BA88ED00A055F95A959A38A5A7EEF88E9A82D | |||
| 6704 | FoxitPDFEditor13.1.4 Patch.exe | C:\Users\admin\AppData\Local\Temp\dup2patcher.dll | executable | |
MD5:0A93D9FD3AE543B29ADD55DDA6B43592 | SHA256:B535DD838F0BED162A02DA8950B185891EFDE563631B17A8D6C25A93CC8A2C08 | |||
| 6240 | FoxitPDFEditor13.1.4 Patch.exe | C:\Users\admin\AppData\Local\Temp\dup2patcher.dll | executable | |
MD5:0A93D9FD3AE543B29ADD55DDA6B43592 | SHA256:B535DD838F0BED162A02DA8950B185891EFDE563631B17A8D6C25A93CC8A2C08 | |||
| 3772 | Foxit.PDF.Editor.2024-Patch.exe | C:\Users\admin\AppData\Local\Temp\bassmod.dll | executable | |
MD5:E4EC57E8508C5C4040383EBE6D367928 | SHA256:8AD9E47693E292F381DA42DDC13724A3063040E51C26F4CA8E1F8E2F1DDD547F | |||
| 1140 | FoxitPDFEditor13.1.4 Patch.exe | C:\Users\admin\AppData\Local\Temp\dup2patcher.dll | executable | |
MD5:0A93D9FD3AE543B29ADD55DDA6B43592 | SHA256:B535DD838F0BED162A02DA8950B185891EFDE563631B17A8D6C25A93CC8A2C08 | |||
| 1468 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1468.30089\Patch\Foxit.PDF.Editor.2024-Patch.exe | executable | |
MD5:D117F8BFC3E8CCEB445A192D4A1035FF | SHA256:EB67DB00FACAD9154B98292B91908F051BEFDAB6D7DD6B08F408F763AF4C805B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
444 | svchost.exe | GET | 200 | 2.19.11.105:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.19.11.105:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
444 | svchost.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6464 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6936 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6936 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1684 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
444 | svchost.exe | 2.19.11.105:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.19.11.105:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
444 | svchost.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
5064 | SearchApp.exe | 2.23.227.215:443 | www.bing.com | Ooredoo Q.S.C. | QA | whitelisted |
— | — | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |