Edit tour

Windows Analysis Report
free-pdf-convert.exe

Overview

General Information

Sample Name:free-pdf-convert.exe
Analysis ID:1297035
MD5:76322138cd92b2d7d8358068da5a49ff
SHA1:a601cecfb0df308522d42dffa906550cc3be814d
SHA256:0506153535029472d82dfd03799861a2b2895172016b5b6d20f616e73dcdeb6e
Infos:

Detection

Score:18
Range:0 - 100
Whitelisted:false
Confidence:0%

Compliance

Score:47
Range:0 - 100

Signatures

Yara detected Costura Assembly Loader
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Drops PE files
Tries to load missing DLLs
Uses code obfuscation techniques (call, push, ret)
Binary contains a suspicious time stamp
Checks for available system drives (often done to infect USB drives)
Found dropped PE file which has not been started or loaded

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample is looking for USB drives. Launch the sample with the USB Fake Disk cookbook
Sample searches for specific file, try point organization specific fake files to the analysis machine
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--")
  • System is w10x64native
  • free-pdf-convert.exe (PID: 6256 cmdline: C:\Users\user\Desktop\free-pdf-convert.exe MD5: 76322138CD92B2D7D8358068DA5A49FF)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
free-pdf-convert.exeJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
    SourceRuleDescriptionAuthorStrings
    00000004.00000000.70101092480.00000000013E4000.00000002.00000001.01000000.00000004.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
      00000004.00000002.71387074670.0000000003A61000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
        Process Memory Space: free-pdf-convert.exe PID: 6256JoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
          No Sigma rule has matched
          No Snort rule has matched

          Click to jump to signature section

          Show All Signature Results

          Compliance

          barindex
          Source: free-pdf-convert.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
          Source: free-pdf-convert.exeStatic PE information: certificate valid
          Source: free-pdf-convert.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: Binary string: C:\BridgeDev\freepdf\FreePDFConverter\FreePDFConverterInstallationWizard\obj\Debug\FreePDFConverterInstallationWizard.pdb source: free-pdf-convert.exe
          Source: Binary string: costura=costura.costura.dll.compressed=costura.costura.pdb.compressed+jetbrains.annotationsYcostura.jetbrains.annotations.dll.compressed5microsoft.win32.primitivesccostura.microsoft.win32.primitives.dll.compressed1microsoft.xaml.behaviors_costura.microsoft.xaml.behaviors.dll.compressed_costura.microsoft.xaml.behaviors.pdb.compressed source: free-pdf-convert.exe
          Source: Binary string: $/r/costura.microsoft.xaml.behaviors.pdb.compressed source: free-pdf-convert.exe, 00000004.00000002.71387074670.0000000003A61000.00000004.00000800.00020000.00000000.sdmp
          Source: Binary string: costura.costura.pdb.compressed source: free-pdf-convert.exe
          Source: Binary string: C:\BridgeDev\freepdf\FreePDFConverter\FreePDFConverterInstallationWizard\obj\Debug\FreePDFConverterInstallationWizard.pdb0O source: free-pdf-convert.exe
          Source: Binary string: costura.microsoft.xaml.behaviors.pdb.compressed|||Microsoft.Xaml.Behaviors.pdb|BCE18B21F242FC612C6B69A6E9224582625175B1|482816 source: free-pdf-convert.exe
          Source: Binary string: costura.microsoft.xaml.behaviors.pdb.compressed source: free-pdf-convert.exe
          Source: Binary string: costura.costura.pdb.compressed|||Costura.pdb|6F8FE76A0D5297A4FA7D4F7054093411D51F71B1|2636 source: free-pdf-convert.exe
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: z:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: x:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: v:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: t:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: r:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: p:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: n:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: l:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: j:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: h:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: f:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: d:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: b:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: y:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: w:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: u:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: s:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: q:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: o:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: m:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: k:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: i:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: g:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: e:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: c:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: a:Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\userJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync PlaylistsJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\user\AppData\Local\MicrosoftJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Media PlayerJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\user\AppDataJump to behavior
          Source: free-pdf-convert.exe, FreePDFConvert.exe.4.drString found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
          Source: free-pdf-convert.exe, FreePDFConvert.exe.4.drString found in binary or memory: http://crl.comodoca.com/COMODORSAExtendedValidationCodeSigningCA.crl0
          Source: free-pdf-convert.exe, FreePDFConvert.exe.4.drString found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
          Source: free-pdf-convert.exe, FreePDFConvert.exe.4.drString found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
          Source: free-pdf-convert.exe, FreePDFConvert.exe.4.drString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
          Source: free-pdf-convert.exeString found in binary or memory: http://nsis.sourceforge.net/Docs/AppendixG.html
          Source: free-pdf-convert.exe, FreePDFConvert.exe.4.drString found in binary or memory: http://ocsp.comodoca.com0
          Source: free-pdf-convert.exe, FreePDFConvert.exe.4.drString found in binary or memory: http://ocsp.comodoca.com0N
          Source: free-pdf-convert.exe, FreePDFConvert.exe.4.drString found in binary or memory: http://ocsp.sectigo.com0
          Source: free-pdf-convert.exe, 00000004.00000002.71451126489.0000000015DBD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://upgrades.intel.com/content/CRL/authenticatedkernelprovisioning.crl0
          Source: free-pdf-convert.exeString found in binary or memory: https://marketplace.firefox.com/developers/docs/policies/agreement
          Source: free-pdf-convert.exeString found in binary or memory: https://r.nogosearch.com/
          Source: free-pdf-convert.exeString found in binary or memory: https://r.nogosearch.com/search.php?query=%s
          Source: free-pdf-convert.exe, FreePDFConvert.exe.4.drString found in binary or memory: https://sectigo.com/CPS0
          Source: free-pdf-convert.exe, FreePDFConvert.exe.4.drString found in binary or memory: https://secure.comodo.com/CPS0L
          Source: free-pdf-convert.exeString found in binary or memory: https://www.free-pdf-convert.com/lps/typ/not-completed.html?screen=first
          Source: free-pdf-convert.exeString found in binary or memory: https://www.free-pdf-convert.com/lps/typ/not-completed.html?screen=secondihttps://www.free-pdf-conve
          Source: free-pdf-convert.exe, 00000004.00000002.71451126489.0000000015DBD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.intel.com/0
          Source: free-pdf-convert.exeString found in binary or memory: https://www.nogosearch.com/legal/license.html
          Source: free-pdf-convert.exeString found in binary or memory: https://www.nogosearch.com/legal/privacy.htmlWhttps://r.nogosearch.com/legal/contact.html-edge://set
          Source: free-pdf-convert.exeString found in binary or memory: https://www.wisewebsearch.com/chttps://www.free-pdf-convert.com/legal/terms.htmlghttps://www.free-pd
          Source: free-pdf-convert.exeString found in binary or memory: https://www.wisewebsearch.com/legal/privacy.html.
          Source: free-pdf-convert.exeString found in binary or memory: https://www.wisewebsearch.com/legal/uninstallation.html
          Source: free-pdf-convert.exeString found in binary or memory: https://www.wisewebsearch/legal/contact.html
          Source: free-pdf-convert.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
          Source: free-pdf-convert.exe, 00000004.00000002.71383511867.0000000001C0E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs free-pdf-convert.exe
          Source: free-pdf-convert.exe, 00000004.00000002.71401096768.0000000006156000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamewmp.dllj% vs free-pdf-convert.exe
          Source: free-pdf-convert.exe, 00000004.00000000.70121052191.00000000015F3000.00000002.00000001.01000000.00000004.sdmpBinary or memory string: OriginalFilenameFreePDFConverterInstallationWizard.exef# vs free-pdf-convert.exe
          Source: free-pdf-convert.exeBinary or memory string: OriginalFilenameFreePDFConverterInstallationWizard.exef# vs free-pdf-convert.exe
          Source: C:\Users\user\Desktop\free-pdf-convert.exeSection loaded: edgegdi.dllJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeSection loaded: wmploc.dllJump to behavior
          Source: free-pdf-convert.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: C:\Users\user\Desktop\free-pdf-convert.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: free-pdf-convert.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 50.01%
          Source: C:\Users\user\Desktop\free-pdf-convert.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\01f6936167b38afa142d4ec8a8e5fb01\mscorlib.ni.dllJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InprocServer32Jump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile created: C:\Users\user\AppData\Local\FreePDFConvertJump to behavior
          Source: free-pdf-convert.exeString found in binary or memory: IMPORTANT - PLEASE READ THE FOLLOWING AGREEMENT CAREFULLY. THIS AGREEMENT SHALL GOVERN YOUR USE OF THE SEARCH SOFTWARE AND SERVICE, IF, AFTER READING THIS AGREEMENT, YOU WISH TO USE THE SEARCH SOFTWARE AND ITS FEATURES AS DESCRIBED LATER. This combined End User License Agreement and Privacy policy (The "Agreement") constitutes a valid and binding agreement between NoGo Search, which governs the use of the Search Software and its features and you, for the use of the Extension/add-on, Content and Services as defined below. You must enter into this Agreement in order to install and use the Extension/add-on.
          Source: free-pdf-convert.exeString found in binary or memory: 1.1 Extension/add-on Platform
          Source: free-pdf-convert.exeString found in binary or memory: The Extension/add-on provides a desktop applications platform which allows publishers to develop, maintain and publish their own applications or software (
          Source: free-pdf-convert.exeString found in binary or memory: ). Third Party Software is a software application including any content, links or materials that are made available to you by the publisher via the Extension/add-on and the Search Software ("Content"). Such Third Party Software may be specifically customized by a publisher and may include the publisher's branding or other content owned or licensed to the publisher.
          Source: free-pdf-convert.exeString found in binary or memory: 1.3 Your use of the Third Party Software and Content is at your own discretion and risk. You further assume all responsibility for any data charges that you may incur for use of the Extension/add-on and/or Search Software and/or access to any Third Party Software or Content. Your ability to access or link to Third Party Software, Content, or third party services does not imply any endorsement by NoGo Search. of Third Party Software, Content or any such third party services.
          Source: free-pdf-convert.exeString found in binary or memory: 1.4. NoGo Search. disclaims any liability that you may incur arising from your access to, use of or reliance upon such Third Party Software or Content via the Extension/add-on and/or Search Software. NoGo Search. does not have any obligation to test or check Third Party Software or Content and is not responsible for , and makes no warranty with respect to, the appropriateness, completeness, stability or legality of any Third Party Software or Content and you hereby waive any legal or equitable rights you have or may have against NoGo Search. with respect thereto. You acknowledge and agree that NoGo Search.: (a) is not responsible for the availability or accuracy of such Third Party Software or Content or the products or services on or available from such Third Party Materials or User Content; (b) has no liability to you or any third party for any harm, injuries or losses suffered as a result of your access to, reliance on or use of such Third Party Software or Content; (c) does not undertake or assume any duty to monitor the Extension/add-on and/or Search Software for inappropriate or unlawful content; and (d) does not make any promises to remove Third Party Software or Content from being accessed through the Services. To report any inappropriate or unlawful Content please contact us via our support system
          Source: free-pdf-convert.exeString found in binary or memory: To uninstall the Extension/add-on and the Search Software, please refer to the instructions
          Source: free-pdf-convert.exeString found in binary or memory: 1.8 Third Party Code; Notice and Attribution. The Extension/add-on includes third party software subject to open source license terms, including, without limitation, the following applications: Compression Algorithm, PCRE, Firefox Plug-in Modules, and NSIS Toolkit and Plug-ins. All rights are reserved by the licensors of such code and ownership is attributed as follows:
          Source: free-pdf-convert.exeString found in binary or memory: http://nsis.sourceforge.net/Docs/AppendixG.html Reference to copyright ownership is for attribution purposes only and in no event shall be deemed an endorsement by such owners of the Extension/add-on. You acknowledge and agree that your right to use these publicly available components of the Extension/add-on is governed by the terms applicable to each application (
          Source: free-pdf-convert.exeString found in binary or memory: ). In the event of any conflict with the express terms of this Agreement and the Other Software Terms, the Other Software Terms of such publicly available license shall control your use of the relevant application. In no event shall the Extension/add-on be deemed
          Source: free-pdf-convert.exeString found in binary or memory: software. BY CLICKING ON THE "I ACCEPT" OR SUCH SIMILAR BUTTON OR LINK AS MAY BE DESIGNATED FOR PURPOSES OF INITIATING THE DOWNLOAD OF THE ACCOMPANYING SOFTWARE PRODUCT AND SERVICES (WHICH CONSIST OF THE SEARCH SOFTWARE AND ITS ASSOCIATED FEATURES) OR BY INSTALLING OR USING THE SEARCH SOFTWARE, THE END USER ("YOU") AGREES TO BE LEGALLY BOUND BY THIS EXTENSION/ADD-ON COMBINED END USER LICENSE AGREEMENT/TERMS OF SERVICE/AND PRIVACY POLICY (THE "AGREEMENT"). IF YOU DO NOT AGREE TO THE TERMS OF THIS AGREEMENT, DO NOT INSTALL OR USE THE EXTENSION/ADD-ON. THE SEARCH SOFTWARE (ASIDE FROM THE EXTENSION/ADD-ON FOR FIREFOX) CAN BE UNINSTALLED FROM THE "ADD OR REMOVE PROGRAMS" DIALOG BOX IN THE WINDOWS CONTROL PANEL
          Source: free-pdf-convert.exeString found in binary or memory: The Search Software is being licensed to you by NoGo Search. on an "AS IS" basis, for your private personal and non-commercial use only. Subject to the terms of this Agreement, NoGo Search. and its current, and future, parent and subsidiary companies (collectively "Licensor", "we", "us" or "our") hereby grants you a limited, non-exclusive, personal, non-sub licensable, non-assignable license to download, install and use the Extension/add-on, and/or the Search Software including any online or enclosed documentation, data distributed to your computer for processing and any future programming fixes, updates and upgrades provided to you (collectively, the "Search Software") onto a computer for your sole use to install, interact with and utilize the Extension/add-on and Search Software, including the services thereto ("Services"). The Search Software may only be used in connection with the Services.
          Source: free-pdf-convert.exeString found in binary or memory: (a) Notwithstanding anything to the contrary, you may not: (i) remove any proprietary notices from the Services, Extension/add-on, Search Software or any copy thereof; (ii) cause, permit or authorize the modification, creation of derivative works, translation, reverse engineering, decompiling or disassembling or hacking of the Extension/add-on, Search Software, or the Services; (iii) sell, assign, rent, lease, publish, display, disclose, transmit, act as a service bureau, or grant rights in the Extension/add-on, Search Software or Services, including, without limitation, through sublicense, to any other entity without the prior written consent of NoGo Search. ; (iv) export or re-export the Extension/add-on, Search Software in violation of export laws; (v) use the Extension/add-on, Search Software or Services for any commercial purpose or the benefit of any third party or charge any person for the use of the Extension/add-on, Search Software or Services ; or (vi) use the Extension/add-on, Search Software or Services to, or in any way that would violate any applicable law, regulation or ordinance; (vii) collect any information or communication about users of the Extension/add-on or Search Software or Services by monitoring, interdicting or intercepting any process of the Extension/add-on or Search Software (viii) use any type of bot, spider virus, worm, clock, software lock ,timer, counter, drop dead device, packet-sniffer, Trojan-horse routing, trap door, time bomb or any other codes or instructions that are designed to be used to provide a means of surreptitious or unauthorized access or that are designed to distort, damage , delete or disassemble the Extension/add-on, Search Software or the Services; (ix) Attempt to disable or circumvent any activation protection mechanism accompanying the Extension/add-on, Search Software or assist third parties to do so; or (x) Attempt to create the source code from the object code for the Extension/add-on, Search Software or any component thereof;
          Source: free-pdf-convert.exeString found in binary or memory: Furthermore, you may not use the Extension/add-on, Search Software or Services to develop, generate, transmit, post, distribute or store information (including as a software or other computer files) that: (A) infringes any third party's intellectual property, right of publicity or other proprietary right or contractual right; (B) is defamatory, harmful, abusive, hateful or obscene or promotes violence ; (C) in any way obstructs or otherwise interferes with the normal performance of another person's use of the Extension/add-on, Search Software or Services, (D) performs any unsolicited commercial activity not permitted by applicable law; (E) is harassment or a violation of privacy or threatens other people or groups of people; (F) contain a virus, Trojan horse, worm or other harmful or destructive component; and (G) impersonates any other person, or steals or assumes any person's identity (a real identity, an alias or an online nickname).
          Source: free-pdf-convert.exeString found in binary or memory: The Extension/add-on, Search Software and Services offer and may incorporate content, technology, software and services owned and controlled by third parties. Use of such third party content, technology, software and/ or services is subject to the terms and conditions and privacy policies of the applicable third party license agreements. Such Third Party content, technology, software and/ or services may not be downloaded, copied, reproduced, distributed, transmitted, broadcast, displayed, sold, licensed, or otherwise exploited for any other purpose without the prior written consent of such Third Party content, technology, software and/ or services owner. Your use of the Third Party content, technology, software and/ or services is at your own discretion and risk and you agree to look solely to the applicable third party and not to NoGo Search. to enforce any of your rights. NoGo Search. is not obligated to maintain or support the Extension/add-on, Search Software or Services, to provide all or any specific content through the Extension/add-on, Search Software or Services, or to provide you with updates, upgrades or services related thereto. You understand that NoGo Search., in its sole discretion, may modify or discontinue or suspend for any period of time or permanently your right to access any of its Services or use any of the Extension/add-on, Search Software or Services at any time, and may at any time suspend or terminate any license hereunder and disable any Extension/add-on, Search Software or Services you may already have accessed or installed without prior notice. NoGo Search. reserves the right to add additional features or functions to the Extension/add-on and/or Search Software. When installed on your computer, the Search Software periodically communicates with NoGo Search. servers. We may automatically update or upgrade the version of the Extension/add-on and/or Search Software that you are using. You consent to such automatic updating or upgrading, and agree that the terms and conditions of this End-User License Agreement and Privacy Policy will apply to all such updates or upgrades. All modifications or enhancements to the Search Software and Services remain the sole property of NoGo Search.. The installation and use of the Extension/add-on, Search Software or Services is currently not for charge, but NoGo Search. may begin charging for the installation or use of the Extension/add-on, Search Software or Services or part thereof at any time
          Source: free-pdf-convert.exeString found in binary or memory: NoGo Search.IS TAKING REASONABLE MESURES IN ATTEMPT TO KEEP THE EXTENSION/ADD-ON, SEARCH SOFTWARE AND SERVICE SECURE. HOWEVER, LIKE ALL OTHER INTERNET SOFTWARE PROVIDERS, THE SEARCH SOFTWARE AND SERVICE AND NoGo Search.'S SITES MAY STILL BE VULNERABLE TO VARIOUS SECURITY ISSUES AND FOR THAT REASON, SHOULD NOT BE CONSIDERED SECURE. IF YOU DO NOT WISH TO BE SUBJECTED TO THESE RISKS, YOU ARE ADVISED NOT TO USE THE EXTENSION/ADD-ON, SEARCH SOFTWARE OR SERVICE.
          Source: free-pdf-convert.exeString found in binary or memory: The Extension/add-on, Search Software and Services contain proprietary and confidential information of NoGo Search., including trade secrets, copyrights, and trademarks contained therein, which are protected by international copyright laws. Title to and ownership of the Extension/add-on, Search Software and Services, including without limitation all intellectual property rights therein and thereto, are and shall remain the exclusive property of NoGo Search and its suppliers, and except for the limited license granted to you, NoGo Search. reserves all right, title and interest in and to the Extension/add-on, Search Software and Services. You shall not take any action to jeopardize, limit or interfere with NoGo Search.'s ownership of and rights with respect to the Extension/add-on, Search Software and Services. You acknowledge that any unauthorized copying or unauthorized use of the Extension/add-on, Search Software or Services is a violation of this Agreement and copyright laws and is strictly prohibited.
          Source: free-pdf-convert.exeString found in binary or memory: (b) You may terminate this Agreement at any time provided you cease all use of the Extension/add-on, Search Software and Services AND destroy or remove from all hard drives, networks, and other storage media all copies of the Extension/add-on and Search Software in your possession. NoGo Search. may terminate this Agreement at any time, with or without cause, by providing immediate notice (except for in case of termination for cause where no notice will be provided) to you and/or by preventing your access to the Extension/add-on, Search Software and/or Services. You agree that NoGo Search. shall not be liable to you or any third party for any termination of your access to, and/or use of, the Extension/add-on, Search Software and Services
          Source: free-pdf-convert.exeString found in binary or memory: (c) Upon termination of this Agreement for any reason (i) all licenses and rights to use the Extension/add-on, Search Software and the Services shall terminate and you must remove the Extension/add-on and Search Software from your computer equipment and dispose of all originals and copies of the Search Software in your possession.
          Source: free-pdf-convert.exeString found in binary or memory: The Extension/add-on will be added to your Internet browser in the form of a Extension/add-on. The Extension/add-on features, widgets and controls are determined by the Publisher. It also provides you with a search box, and easy access to powerful Web search directly from your browser. The Extension/add-on for Internet Explorer can be minimized by right clicking the Extension/add-on and selecting it. In addition, you will receive the Extension/add-on Search Assistance feature which provides you with relevant search results when you place a search query in the browser address bar (as described above under Search Assistance). The Search Software may be added as a shortcut icon in your desktop taskbar, on your desktop andother optional menus. The Extension/add-on includes several other features, such as games, radio and Facebook connect button. Note that Firefox Search Extension/add-on requires the
          Source: free-pdf-convert.exeString found in binary or memory: When a user installs the Search Software, or uses one of the Extension/add-on search feature to search the Web all the download and browsing activity is recorded by NoGo Search servers. As all standard Web pages, besides the keyword query such record may include information such as URL address, software names, files formats, IP address, default language setting, browser type, referring and exit pages, operating system, date/time stamp, clickstream data and an anonymous unique ID. NoGo Search. uses this information in order to appropriately process your download and search request and to serve you relevant and better search results.
          Source: free-pdf-convert.exeString found in binary or memory: The Search Software sends a configuration request when you start your browser. This request includes only data such as browser type & IP address. In addition, occasionally the Extension/add-on platform may send a request to our servers to check for new version releases.
          Source: free-pdf-convert.exeString found in binary or memory: NoGo Search. constantly follows activity and usage of the Extension/add-on and of the Search Software. By analyzing the aggregated information on usage of our product, NoGo Search. can improve the product and offer you better service.
          Source: free-pdf-convert.exeString found in binary or memory: The Extension/add-on and/or Search Software also uses "cookies" and other technologies such as pixel tags and web beacons. We use these technologies to store a code designating a distribution source for the Extension/add-on and/or the Search Software. We may also employ web beacons from third parties and we may work with other companies that advertise on our sites to place web beacons on their sites. This information allows us to properly distinguish the Extension/add-on and/or Search Software for purposes of compensating third parties who distribute our product and of being compensated by relevant Third Party Software's owners and to analyze trends, retention and usage on an aggregated basis (including aggregated statistics regarding the effectiveness of our promotional and advertising activity). The Extension/add-on and/or Search Software also uses cookies to store user preferences. We do not use cookies to track your use of the Internet in any other way or to store any personally-identifiable information. -
          Source: free-pdf-convert.exeString found in binary or memory: If you wish to withdraw your consent to any of the Extension/add-on and/or Search Software features as described herein, you should uninstall the Software from your computer. Uninstall instructions are detailed at https://www.wisewebsearch.com/legal/uninstallation.html
          Source: free-pdf-convert.exeString found in binary or memory: This privacy policy applies to the Extension/add-on and Search Software and each of the related Web sites (the "Web Sites") maintained by NoGo Search. ("we" or "us"). In the event of any inconsistency between this privacy policy and a policy listed on one of the other Web Sites, this policy shall control.
          Source: free-pdf-convert.exeString found in binary or memory: We do not collect personal identification information including names, phone numbers and addresses. Users might be asked to add their email address to get information about NoGo Search's Software and other special offers from NoGo Search. We do collect information necessary to enable certain features in the Extension/add-on Platform. We do not sell, rent or trade any personally identifiable information you provide when using the Extension/add-on, Search Software or the Web Sites.
          Source: free-pdf-convert.exeString found in binary or memory: NoGo Search. is the entity that collects the information either through the Software or as a result of the Software being installed or used (including through third party software being downloaded through the Extension/add-on and/or Search Software).
          Source: free-pdf-convert.exeString found in binary or memory: data security and takes serious steps for the maximum data security. We gather certain information such as internet protocol (IP) addresses, browser user agent, referring page, date/time stamp and cookies and web beacons automatically. We use such information to analyze trends, to administer the site, to track users' movements around the site and to gather demographic information to better provide our services and to facilitate and measure the effectiveness of advertisement and web searches. When you visit the NoGo Search's Web Sites or use the Search Software, we may place a small text file-called a "cookie"-on your computer that allows us to improve the quality of our service, and to store your preferences and settings. Importantly, a cookie does not allow us to obtain any personally identifiable information (such as your real name or address) unless you have specifically provided such information when using the Web Sites or the Software. The search feature sends a request to our servers from time to time including while processing a search query that you have inputted or a third party software download that you have approved. This request includes the keyword query, source (Extension/add-on, IE bar, related links, etc& ) and/or third party software offer details you approved and all HTTP data transferred automatically by the browser (IP Address, User Agent, Cookies, web beacons etc& ). We use this information in order to properly process your search request, downloads facilitated by the Search Software and to make our Services, offers and advertising communication with you more relevant to your interest. For example, this data provides us with information on which language you prefer to use and your geographical location. Such information is recorded on a non-personally identifiable basis and is kept strictly anonymous. If any of the Web Sites or the Software is ever sold or all or substantially all of the assets relating to a Web Site or the Software are transferred to another entity, we may transfer all information provided by or collected from you, including personally identifiable information, in order to ensure continuity of your service. We will disclose information, including personally identifiable information, data acquired by cookies, and other data, where required by a subpoena, interception order or other lawful process. We also reserve the right to disclose such information when we believe, in our sole judgment and to the extent consistent with applicable law, that such disclosure is necessary to protect the rights or safety of others or to enforce, or protect our rights under, this Agreement.
          Source: free-pdf-convert.exeString found in binary or memory: (a) You represent and warrant that (i) you possess the legal right and ability to enter into this Agreement and to comply with its terms, (ii) you will use the Extension/add-on, Search Software and Services for lawful purposes only and in accordance with this Agreement and all applicable laws, regulations and policies, (iii) you will not attempt to decompile, reverse engineer or hack the Extension/add-on, Search Software or to defeat or overcome any encryption and/or other technical protection methods implemented by NoGo Search. with respect to the Extension/add-on , Search Software and/or data transmitted, processed or stored by the Extension/add-on and/or the Search Software or other users of the Extension/add-on and/or Search Software, (iv) you will not take any steps to interfere with or in any manner compromise any of Extension/add-on and/or Search Software security measures, any other individual's or entity's computer on the Network and/or otherwise sharing Services, (v) you will always provide and maintain true, accurate, current and complete information as requested upon installing and/or using the Extension/add-on and/or Search Software, and (vi) you will only use the Extension/add-on , Search Software and Services on a computer on which such use is authorized by the computer's owner.
          Source: free-pdf-convert.exeString found in binary or memory: (b) You agree that you will not use any automatic or manual device or process to interfere or attempt to interfere with the proper working of the Extension/add-on , Search Software or Services, except to remove the Extension/add-on , Search Software from a computer of which you are an owner or authorized user in a manner permitted by this Agreement. You may not violate or attempt to violate the security of the Extension/add-on, Search Software or Services. NoGo Search. reserves the right to investigate occurrences which may involve such violations, and may involve, and cooperate with, law enforcement authorities in prosecuting users who have participated in such violations.
          Source: free-pdf-convert.exeString found in binary or memory: (c) If NoGo Search. has reasonable grounds to suspect that your representations, promises or warranties are inaccurate or breached, NoGo Search. may terminate this license, deny any or all use of the Extension/add-on , Search Software and/or Services, and pursue any appropriate legal remedies.
          Source: free-pdf-convert.exeString found in binary or memory: You agree to indemnify, hold harmless and defend NoGo Search. and its affiliates, parent companies, subsidiaries, officers, directors, employees, agents and network service providers at your expense, against any and all third party claims, actions, proceedings, and suits and all related liabilities, damages, settlements, penalties, fines, costs and expenses (including, without limitation, reasonable attorney fees and other dispute resolution expenses) incurred by NoGo Search. arising out of or relating to your (a) violation or breach of any term of this Agreement or any policy or guidelines referenced herein, or (b) use or misuse of the Extension/add-on, Search Software and/or Services.
          Source: free-pdf-convert.exeString found in binary or memory: The Extension/add-on and/or Search Software may provide, or third parties may provide, search results or other links to other World Wide Web sites or resources or software. Because we have no control over such sites and resources and software, you acknowledge and agree that we are not responsible for the availability of such external sites or resources or software, and do not endorse and are not responsible or liable for any content, advertising, products, or other materials on or available from such sites or resources or software. You further acknowledge and agree that we shall not be responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with use of or reliance on any such content, goods or services available on or through any such site or resource or software.
          Source: free-pdf-convert.exeString found in binary or memory: (A) THE EXTENSION/ADD-ON, SEARCH SOFTWARE AND SERVICES ARE PROVIDED "AS IS" AND THERE ARE NO WARRANTIES, CLAIMS OR REPRESENTATIONS MADE BY NoGo Search. EITHER EXPRESS, IMPLIED, OR STATUTORY, WITH RESPECT TO THE EXTENSION/ADD-ON, SEARCH SOFTWARE OR SERVICES (AND/OR ANY THIRD PARTY SOFTWARE, CONTENT, TECHNOLOGY AND SERVICES), INCLUDING WARRANTIES OF QUALITY, PERFORMANCE, NON-INFRINGEMENT, MERCHANTABILITY, OR FITNESS FOR A PARTICULAR PURPOSE, NOR ARE THERE ANY WARRANTIES CREATED BY COURSE OF DEALING, COURSE OF PERFORMANCE, OR TRADE USAGE. NoGo Search FURTHER DOES NOT REPRESENT OR WARRANT THAT THE EXTENSION/ADD-ON, SEARCH SOFTWARE OR ANY SERVICES WILL ALWAYS BE AVAILABLE, ACCESSIBLE, UNINTERRUPTED, TIMELY, SECURE, ACCURATE, COMPLETE AND ERROR-FREE
          Source: free-pdf-convert.exeString found in binary or memory: (b) YOU ACKNOWLEDGE THAT THE ENTIRE RISK ARISING OUT OF THE USE OR PERFORMANCE OF THE EXTENSION/ADD-ON, SEARCH SOFTWARE OR SERVICES AND SERVICES REMAINS WITH YOU TO THE MAXIMUM EXTENT PERMITTED BY LAW. (c) THE EXTENSION/ADD-ON, SEARCH SOFTWARE OR SERVICES MAY BE UTILIZED AND DISTRIBUTED BY THIRD PARTIES WHICH ARE UNRELATED TO NoGo Search. YOU AGREE THAT NoGo Search WILL NOT BE LIABLE FOR ANY DAMAGE, CLAIM OR LOSS OF ANY KIND WHATSOEVER, INCLUDING BUT NOT LIMITED TO INCIDENTAL , INDIRECT, SPECIAL OR CONSEQUENTIAL DAMAGES AS STATED IN PARAGRAPH 14 (a) ABOVE, RESULTING FROM ANY ACTIONS OR OMISSIONS OF THE OUTSIDE PARTIES.
          Source: free-pdf-convert.exeString found in binary or memory: 15 Limitation of Liability (a) IN NO EVENT AND UNDER NO LEGAL THEORY, SHALL NoGo Search., ITS AFFILIATES, PARENT COMPANIES, SUBSIDIARIES, OFFICERS, DIRECTORS, EMPLOYEES, AGENTS OR NETWORK SERVICE PROVIDERS BE LIABLE WHETHER IN CONTRACT, WARRANTY, TORT (INCLUDING NEGLIGENCE (WHETHER ACTIVE, PASSIVE OR IMPUTED), PRODUCT LIABILITY OR STRICT LIABILITY OR OTHER THEORY), FOR ANY INDIRECT, INCIDENTAL, SPECIAL OR CONSEQUENTIAL DAMAGES (INCLUDING WITHOUT LIMITATION ANY LOSS OF DATA, SERVICE INTERRUPTION, COMPUTER FAILURE OR PECUNIARY LOSS OF ANY TYPE , DAMAGES FOR LOSS OF GOODWILL, BUSINESS INTERRUPTION, COMPUTER FAILURE OR MALFUNCTION, LOSS OF BUSINESS PROFITS, LOSS OF BUSINESS INFORMATION, OR ANY AND ALL OTHER COMMERCIAL DAMAGES OR LOSSES) ARISING OUT OF THE USE OR INABILITY TO USE THE EXTENSION/ADD-ON, SEARCH SOFTWARE OR THE SERVICES, EVEN IF NoGo Search. HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
          Source: free-pdf-convert.exeString found in binary or memory: (b) YOUR ONLY RIGHT WITH RESPECT TO ANY PROBLEMS OR DISSATISFACTION WITH THE EXTENSION/ADD-ON, SEARCH SOFTWARE AND/OR SERVICES IS TO UNINSTALL AND CEASE USE OF SUCH EXTENSION/ADD-ON, SEARCH SOFTWARE AND SERVICES. (C) IN NO EVENT WILL NoGo Search
          Source: free-pdf-convert.exeString found in binary or memory: 17. You acknowledge and agree that by clicking on the button labeled "I ACCEPT" or such similar links as may be designated by NoGo Search. to download the Extension/add-on and/or Search Software and to accept the terms and conditions of this Agreement, you are submitting a legally binding electronic signature and are entering into a legally binding contract. You acknowledge that your electronic submissions constitute your agreement and intent to be bound by this Agreement. Pursuant to any applicable statutes, regulations, rules, ordinances or other laws, YOU HEREBY AGREE TO THE USE OF ELECTRONIC SIGNATURES, CONTRACTS, ORDERS AND OTHER RECORDS AND TO ELECTRONIC DELIVERY OF NOTICES, POLICIES AND RECORDS OF TRANSACTIONS INITIATED OR COMPLETED THROUGH THE Extension/add-on, SEARCH SOFTWARE OR SERVICES. Further, you hereby waive any rights or requirements under any statutes, regulations, rules, ordinances or other laws in any jurisdiction which require an original signature or delivery or retention of non-electronic records.
          Source: free-pdf-convert.exeString found in binary or memory: NoGo Search. reserves all rights not expressly granted herein. NoGo Search. may modify this Agreement at any time by providing such revised Agreement to you or posting the revised Agreement on its website located at NoGo Search. Your continued use of the Extension/add-on, Search Software and/or Services shall constitute your acceptance of such revised Agreement. You may not assign this Agreement or any rights hereunder. Nothing in this Agreement shall constitute a partnership or joint venture between you and NoGo Search.. Should any term or provision hereof be deemed invalid, void or unenforceable either in its entirety or in a particular application, the remainder of this Agreement shall nonetheless remain in full force and effect. The failure of NoGo Search. at any time or times to require performance of any provision hereof shall in no manner affect its right at a later time to enforce the same unless the same is waived in writing. This Agreement shall be governed by and construed in accordance with the laws of the State of Israel without regard to its conflict of law rules. Any legal proceeding arising out or relating to this Agreement will be subject to the exclusive jurisdiction of the Tel-Aviv court of the State of Israel and you irrevocably consent to the jurisdiction of such courts. The terms set forth in this Agreement and any related service agreements constitute the final, complete and exclusive agreement with respect to the Extension/add-on, Search Software and Services and may not be contradicted, explained or supplemented by evidence of any prior agreement, any contemporaneous oral agreement or any consistent additional terms. NoGo Search may at its sole discretion assign this Agreement to a subsidiary or sister company, without giving prior notice.
          Source: free-pdf-convert.exeString found in binary or memory: YOU EXPRESSLY ACKNOWLEDGE THAT YOU HAVE READ THIS AGREEMENT AND UNDERSTAND THE RIGHTS, OBLIGATIONS, TERMS AND CONDITIONS SET FORTH HEREIN. BY CONTINUING TO INSTALL THE EXTENSION/ADD-ON AND/OR THE SEARCH SOFTWARE , YOU EXPRESSLY CONSENT TO BE BOUND BY ITS TERMS AND CONDITIONS AND GRANT TO NoGo Search. THE RIGHTS SET FORTH HEREIN.
          Source: classification engineClassification label: clean18.evad.winEXE@1/7@0/0
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile read: C:\Users\desktop.iniJump to behavior
          Source: Window RecorderWindow detected: More than 3 window changes detected
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
          Source: free-pdf-convert.exeStatic file information: File size 12777560 > 1048576
          Source: free-pdf-convert.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
          Source: free-pdf-convert.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
          Source: free-pdf-convert.exeStatic PE information: certificate valid
          Source: free-pdf-convert.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0xc13000
          Source: free-pdf-convert.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: free-pdf-convert.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
          Source: Binary string: C:\BridgeDev\freepdf\FreePDFConverter\FreePDFConverterInstallationWizard\obj\Debug\FreePDFConverterInstallationWizard.pdb source: free-pdf-convert.exe
          Source: Binary string: costura=costura.costura.dll.compressed=costura.costura.pdb.compressed+jetbrains.annotationsYcostura.jetbrains.annotations.dll.compressed5microsoft.win32.primitivesccostura.microsoft.win32.primitives.dll.compressed1microsoft.xaml.behaviors_costura.microsoft.xaml.behaviors.dll.compressed_costura.microsoft.xaml.behaviors.pdb.compressed source: free-pdf-convert.exe
          Source: Binary string: $/r/costura.microsoft.xaml.behaviors.pdb.compressed source: free-pdf-convert.exe, 00000004.00000002.71387074670.0000000003A61000.00000004.00000800.00020000.00000000.sdmp
          Source: Binary string: costura.costura.pdb.compressed source: free-pdf-convert.exe
          Source: Binary string: C:\BridgeDev\freepdf\FreePDFConverter\FreePDFConverterInstallationWizard\obj\Debug\FreePDFConverterInstallationWizard.pdb0O source: free-pdf-convert.exe
          Source: Binary string: costura.microsoft.xaml.behaviors.pdb.compressed|||Microsoft.Xaml.Behaviors.pdb|BCE18B21F242FC612C6B69A6E9224582625175B1|482816 source: free-pdf-convert.exe
          Source: Binary string: costura.microsoft.xaml.behaviors.pdb.compressed source: free-pdf-convert.exe
          Source: Binary string: costura.costura.pdb.compressed|||Costura.pdb|6F8FE76A0D5297A4FA7D4F7054093411D51F71B1|2636 source: free-pdf-convert.exe

          Data Obfuscation

          barindex
          Source: Yara matchFile source: free-pdf-convert.exe, type: SAMPLE
          Source: Yara matchFile source: 00000004.00000000.70101092480.00000000013E4000.00000002.00000001.01000000.00000004.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000004.00000002.71387074670.0000000003A61000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: free-pdf-convert.exe PID: 6256, type: MEMORYSTR
          Source: C:\Users\user\Desktop\free-pdf-convert.exeCode function: 4_2_020B47F9 pushfd ; iretd 4_2_020B4831
          Source: C:\Users\user\Desktop\free-pdf-convert.exeCode function: 4_2_020B1CAD pushfd ; iretd 4_2_020B1CB1
          Source: C:\Users\user\Desktop\free-pdf-convert.exeCode function: 4_2_020B4CB1 push esp; retf 4_2_020B4CC9
          Source: free-pdf-convert.exeStatic PE information: 0xE29F3472 [Sun Jun 25 14:34:26 2090 UTC]
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile created: C:\Users\user\AppData\Local\FreePDFConvert\FreePDFConvert.exeJump to dropped file
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\FreePDFConvert\FreePDFConvert.exeJump to dropped file
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\userJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync PlaylistsJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\user\AppData\Local\MicrosoftJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Media PlayerJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeFile opened: C:\Users\user\AppDataJump to behavior
          Source: free-pdf-convert.exe, 00000004.00000002.71420108509.000000000B3FA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
          Source: C:\Users\user\Desktop\free-pdf-convert.exeMemory allocated: page read and write | page guardJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Users\user\Desktop\free-pdf-convert.exe VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Users\user\AppData\Local\Microsoft\Media Player\CurrentDatabase_400.wmdb VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\free-pdf-convert.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
          Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
          1
          Replication Through Removable Media
          2
          Command and Scripting Interpreter
          1
          DLL Side-Loading
          1
          DLL Side-Loading
          1
          Masquerading
          OS Credential Dumping1
          Security Software Discovery
          1
          Replication Through Removable Media
          Data from Local SystemExfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
          Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
          Disable or Modify Tools
          LSASS Memory11
          Peripheral Device Discovery
          Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
          Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
          Timestomp
          Security Account Manager2
          File and Directory Discovery
          SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
          Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
          DLL Side-Loading
          NTDS12
          System Information Discovery
          Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
          Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
          Obfuscated Files or Information
          LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet
          behaviorgraph top1 signatures2 2 Behavior Graph ID: 1297035 Sample: free-pdf-convert.exe Startdate: 24/08/2023 Architecture: WINDOWS Score: 18 10 Yara detected Costura Assembly Loader 2->10 5 free-pdf-convert.exe 37 28 2->5         started        process3 file4 8 C:\Users\user\AppData\...\FreePDFConvert.exe, PE32 5->8 dropped

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          free-pdf-convert.exe3%ReversingLabs
          free-pdf-convert.exe0%VirustotalBrowse
          SourceDetectionScannerLabelLink
          C:\Users\user\AppData\Local\FreePDFConvert\FreePDFConvert.exe4%ReversingLabs
          No Antivirus matches
          No Antivirus matches
          SourceDetectionScannerLabelLink
          http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t0%Avira URL Cloudsafe
          https://www.wisewebsearch.com/chttps://www.free-pdf-convert.com/legal/terms.htmlghttps://www.free-pd0%Avira URL Cloudsafe
          http://ocsp.sectigo.com00%Avira URL Cloudsafe
          https://r.nogosearch.com/search.php?query=%s0%Avira URL Cloudsafe
          https://sectigo.com/CPS00%Avira URL Cloudsafe
          http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t0%VirustotalBrowse
          https://www.wisewebsearch.com/legal/privacy.html.0%Avira URL Cloudsafe
          http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#0%Avira URL Cloudsafe
          https://sectigo.com/CPS00%VirustotalBrowse
          https://www.nogosearch.com/legal/privacy.htmlWhttps://r.nogosearch.com/legal/contact.html-edge://set0%Avira URL Cloudsafe
          https://r.nogosearch.com/0%Avira URL Cloudsafe
          https://www.wisewebsearch.com/legal/uninstallation.html0%Avira URL Cloudsafe
          https://www.wisewebsearch/legal/contact.html0%Avira URL Cloudsafe
          https://www.free-pdf-convert.com/lps/typ/not-completed.html?screen=secondihttps://www.free-pdf-conve0%Avira URL Cloudsafe
          https://www.nogosearch.com/legal/license.html0%Avira URL Cloudsafe
          https://www.free-pdf-convert.com/lps/typ/not-completed.html?screen=first0%Avira URL Cloudsafe
          No contacted domains info
          NameSourceMaliciousAntivirus DetectionReputation
          https://www.wisewebsearch.com/chttps://www.free-pdf-convert.com/legal/terms.htmlghttps://www.free-pdfree-pdf-convert.exefalse
          • Avira URL Cloud: safe
          unknown
          http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0tfree-pdf-convert.exe, FreePDFConvert.exe.4.drfalse
          • 0%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          https://marketplace.firefox.com/developers/docs/policies/agreementfree-pdf-convert.exefalse
            high
            http://nsis.sourceforge.net/Docs/AppendixG.htmlfree-pdf-convert.exefalse
              high
              https://sectigo.com/CPS0free-pdf-convert.exe, FreePDFConvert.exe.4.drfalse
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              http://ocsp.sectigo.com0free-pdf-convert.exe, FreePDFConvert.exe.4.drfalse
              • Avira URL Cloud: safe
              unknown
              https://r.nogosearch.com/search.php?query=%sfree-pdf-convert.exefalse
              • Avira URL Cloud: safe
              unknown
              https://www.wisewebsearch.com/legal/privacy.html.free-pdf-convert.exefalse
              • Avira URL Cloud: safe
              unknown
              http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#free-pdf-convert.exe, FreePDFConvert.exe.4.drfalse
              • Avira URL Cloud: safe
              unknown
              https://www.nogosearch.com/legal/privacy.htmlWhttps://r.nogosearch.com/legal/contact.html-edge://setfree-pdf-convert.exefalse
              • Avira URL Cloud: safe
              unknown
              https://r.nogosearch.com/free-pdf-convert.exefalse
              • Avira URL Cloud: safe
              unknown
              https://secure.comodo.com/CPS0Lfree-pdf-convert.exe, FreePDFConvert.exe.4.drfalse
                high
                https://www.wisewebsearch.com/legal/uninstallation.htmlfree-pdf-convert.exefalse
                • Avira URL Cloud: safe
                unknown
                https://www.intel.com/0free-pdf-convert.exe, 00000004.00000002.71451126489.0000000015DBD000.00000004.00000020.00020000.00000000.sdmpfalse
                  high
                  http://nsis.sf.net/NSIS_ErrorErrorfree-pdf-convert.exe, FreePDFConvert.exe.4.drfalse
                    high
                    https://www.wisewebsearch/legal/contact.htmlfree-pdf-convert.exefalse
                    • Avira URL Cloud: safe
                    unknown
                    http://upgrades.intel.com/content/CRL/authenticatedkernelprovisioning.crl0free-pdf-convert.exe, 00000004.00000002.71451126489.0000000015DBD000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      https://www.free-pdf-convert.com/lps/typ/not-completed.html?screen=secondihttps://www.free-pdf-convefree-pdf-convert.exefalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.nogosearch.com/legal/license.htmlfree-pdf-convert.exefalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.free-pdf-convert.com/lps/typ/not-completed.html?screen=firstfree-pdf-convert.exefalse
                      • Avira URL Cloud: safe
                      unknown
                      No contacted IP infos
                      Joe Sandbox Version:38.0.0 Beryl
                      Analysis ID:1297035
                      Start date and time:2023-08-24 23:46:45 +02:00
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:0h 7m 27s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, IE 11, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
                      Number of analysed new started processes analysed:8
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • HDC enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample file name:free-pdf-convert.exe
                      Detection:CLEAN
                      Classification:clean18.evad.winEXE@1/7@0/0
                      EGA Information:Failed
                      HDC Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 66
                      • Number of non-executed functions: 0
                      Cookbook Comments:
                      • Found application associated with file extension: .exe
                      • Exclude process from analysis (whitelisted): dllhost.exe, audiodg.exe, RuntimeBroker.exe, backgroundTaskHost.exe, svchost.exe
                      • Excluded domains from analysis (whitelisted): spclient.wg.spotify.com, array806.prod.do.dsp.mp.microsoft.com, ctldl.windowsupdate.com
                      • Execution Graph export aborted for target free-pdf-convert.exe, PID 6256 because it is empty
                      • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                      • Report size getting too big, too many NtDeviceIoControlFile calls found.
                      • Report size getting too big, too many NtOpenFile calls found.
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtProtectVirtualMemory calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      TimeTypeDescription
                      23:48:44API Interceptor3x Sleep call for process: free-pdf-convert.exe modified
                      No context
                      No context
                      No context
                      No context
                      No context
                      Process:C:\Users\user\Desktop\free-pdf-convert.exe
                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
                      Category:dropped
                      Size (bytes):4787704
                      Entropy (8bit):7.987860060021222
                      Encrypted:false
                      SSDEEP:98304:u6uBJ/KZ4wPPTnNEKHOg1Y/84n4Ay3+TN/6L6d+xSVl4P3A:u6uBJ/xkTNLug1c8FIN/66som/A
                      MD5:354CC27E45A46BF185D6CFE227583478
                      SHA1:938F2C50FA4C4ECE6CE06F44A7E0AD93B98B8564
                      SHA-256:DE08BBD33EF34AF776C6F101BAFAC7759EEE2C331FB8BB7309F6F6AE9C8AA866
                      SHA-512:699B4D5FB74BE55D319B27492E21563F3964E5BBE35360EDB5E52578B5388DA40621AB5EA8D2F5D727AF5CE6BEDA520A15FA62D907CBD430617781C631D73C26
                      Malicious:false
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 4%
                      Reputation:low
                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...Pf..Pf..Pf.*_9..Pf..Pg.LPf.*_;..Pf.sV..Pf..V`..Pf.Rich.Pf.........................PE..L...Z.Oa.................j..........-5............@..........................P.......QI...@.............................................(r............H.X"...........................................................................................text....h.......j.................. ..`.rdata...............n..............@..@.data...............................@....ndata...p...`...........................rsrc...(r.......t..................@..@................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Users\user\Desktop\free-pdf-convert.exe
                      File Type:Microsoft ASF
                      Category:dropped
                      Size (bytes):6177250
                      Entropy (8bit):6.302543655671548
                      Encrypted:false
                      SSDEEP:49152:4U/wPCvXHexLbMU4gCeAiVf5M2eGfHQl8zT9AbcuthA7V62o6fXb:4U/OcXHeKU4gAef5leGfwWzKjD+c2Hz
                      MD5:5264B77B3172971032B0AA787A49424A
                      SHA1:0888408A871C29771EEBAEF48CB7D8810FC2C83E
                      SHA-256:10FE19955C27C5470F23F2DC5295CB343A820A54199F24CF706579E08634F6ED
                      SHA-512:B7E1C7D457707815A46D9C3BFC434650BC80B3D8C3F611B71DA56CD38142A6C90BC28C3ADAAFE9FAD68B5B34772E49E65A8CB869C7AA34C11D52AA116749EEBF
                      Malicious:false
                      Reputation:low
                      Preview:0&.u.f.......b.l.................G........ Seh........................A^.......>................................................@......_......... Se.................... Se.......FC|...K.)9>.A\.!..........e.n......r.2C...iR.[ZX.......................@...........@......................................r.2C...iR.[ZX.......................................................................@............^.P............m.a.j.o.r._.b.r.a.n.d.......m.p.4.2.....m.i.n.o.r._.v.e.r.s.i.o.n.......0...$.c.o.m.p.a.t.i.b.l.e._.b.r.a.n.d.s.......m.p.4.2.m.p.4.1...(.W.M./.E.n.c.o.d.i.n.g.S.e.t.t.i.n.g.s.......L.a.v.f.6.0...4...1.0.0............... Se............M[......_\D+.W. U[......_\D+........7.................8....,.,.......8.......WMV2..^................................ Ser.......@.i.M[......_\D+P...a......... ......................a...D....>..........................@R..1........H.z.......AR..1........H.........w.m.v.2.......WMV2....W.i.n.d.o.w.s. .M.e.d.i.a. .A.u.d.i.o. .V.8.......a.6&.u.f
                      Process:C:\Users\user\Desktop\free-pdf-convert.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):1048576
                      Entropy (8bit):0.9610093552429441
                      Encrypted:false
                      SSDEEP:768:/0aleDxcg7KGVp3zT13VuI61HOdrrA9abhr8fEwPRzitFrzAqUmNKX08oJImdbaT:xZP2tFPovqY8UqEMeTaBacg
                      MD5:813A29C2164C3BD7DE80ADD4D3277CA1
                      SHA1:2D802330088471EDA6433D8347D82F3B5144B993
                      SHA-256:829B55D8A14CAEF8C66E2F2007A210FE8903E419B8C847D870AD75CD091BAB52
                      SHA-512:5E13FA495743405E5A2960EE2DDCFA11D359C1A39EA5094EB516B16DF9B778AC87CC9519DB7EC02EC5FDF8BEA1D00440DE76D49540AF77DF297FC3206703FF9C
                      Malicious:false
                      Reputation:low
                      Preview:..a...............=.....B...........................S ..............J...............................................................................................................................................a. .P.l.a.y.e.r.\.C.u.r.r.e.n.t.D.a.t.a.b.a.s.e._.4.0.0...w.m.d.b...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Users\user\Desktop\free-pdf-convert.exe
                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):498
                      Entropy (8bit):5.103913616294899
                      Encrypted:false
                      SSDEEP:12:TMbhJpIO1mcROtW/yF0T8YA+it/0zsFE/TYEGs/4w:qhJ+CTRSnF1wlwFUY6
                      MD5:90BE2701C8112BEBC6BD58A7DE19846E
                      SHA1:A95BE407036982392E2E684FB9FF6602ECAD6F1E
                      SHA-256:644FBCDC20086E16D57F31C5BAD98BE68D02B1C061938D2F5F91CBE88C871FBF
                      SHA-512:D618B473B68B48D746C912AC5FC06C73B047BD35A44A6EFC7A859FE1162D68015CF69DA41A5DB504DCBC4928E360C095B32A3B7792FCC6A38072E1EBD12E7CBE
                      Malicious:false
                      Reputation:moderate, very likely benign file
                      Preview:<?xml version="1.0" standalone="yes"?>..<!DOCTYPE document [..<!ELEMENT document (node*)>.. <!ATTLIST document WMSNameSpaceVersion CDATA "2.0">....<!ELEMENT node (node*)>.. <!ATTLIST node name CDATA #REQUIRED>.. <!ATTLIST node opcode ( create | remove | setval | clearval | rename | movebefore ) #REQUIRED>.. <!ATTLIST node secure ( true | false ) #IMPLIED>.. <!ATTLIST node type ( string | boolean | int32 | binary | int64 ) #IMPLIED>.. <!ATTLIST node value CDATA #IMPLIED>..]>..
                      Process:C:\Users\user\Desktop\free-pdf-convert.exe
                      File Type:exported SGML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):10191
                      Entropy (8bit):4.792342140217129
                      Encrypted:false
                      SSDEEP:96:/YkZRAF6zyHUhm77yB1pZYCEnfHrHH7B6xTGH+YCLV3zwULJEYCJWyHBt3zwFRh+:/2FV0bBPCfUdY
                      MD5:7050D5AE8ACFBE560FA11073FEF8185D
                      SHA1:5BC38E77FF06785FE0AEC5A345C4CCD15752560E
                      SHA-256:CB87767C4A384C24E4A0F88455F59101B1AE7B4FB8DE8A5ADB4136C5F7EE545B
                      SHA-512:A7A295AC8921BB3DDE58D4BCDE9372ED59DEF61D4B7699057274960FA8C1D1A1DAFF834A93F7A0698E9E5C16DB43AF05E9FD2D6D7C9232F7D26FFCFF5FC5900B
                      Malicious:false
                      Reputation:moderate, very likely benign file
                      Preview:.<document WMSNameSpaceVersion="2.0">.... <node name="Control Protocol" opcode="create" >.. <node name="Object Store" opcode="create" >.. <node name="RTSP" opcode="create" >.. <node name="CLSID" opcode="create" type="string" value="{308786f0-8b15-11d2-b25f-006097d2e41e}" />.. <node name="Enabled" opcode="create" type="int32" value="0x1" />.. <node name="Properties" opcode="create" >.. <node name="Protocol" opcode="create" type="string" value="RTSP,RTSPA,RTSPT,RTSPU,RTSPM" />.. </node> Properties -->.... </node> RTSP -->.... <node name="Sessionless Multicast" opcode="create" >.. <node name="CLSID" opcode="create" type="string" value="{f9377800-f38d-11d2-b26c-006097d2e41e}" />.. <node name="Enabled" opcode="create" type="int32" value="0x1" />.. <node name="Properties" opcode="create" >.. <node name="Protocol" opcode="create" type="string" value="MCAST,RTP" />.. </node> Properties
                      Process:C:\Users\user\Desktop\free-pdf-convert.exe
                      File Type:exported SGML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):10191
                      Entropy (8bit):4.792342140217129
                      Encrypted:false
                      SSDEEP:96:/YkZRAF6zyHUhm77yB1pZYCEnfHrHH7B6xTGH+YCLV3zwULJEYCJWyHBt3zwFRh+:/2FV0bBPCfUdY
                      MD5:7050D5AE8ACFBE560FA11073FEF8185D
                      SHA1:5BC38E77FF06785FE0AEC5A345C4CCD15752560E
                      SHA-256:CB87767C4A384C24E4A0F88455F59101B1AE7B4FB8DE8A5ADB4136C5F7EE545B
                      SHA-512:A7A295AC8921BB3DDE58D4BCDE9372ED59DEF61D4B7699057274960FA8C1D1A1DAFF834A93F7A0698E9E5C16DB43AF05E9FD2D6D7C9232F7D26FFCFF5FC5900B
                      Malicious:false
                      Preview:.<document WMSNameSpaceVersion="2.0">.... <node name="Control Protocol" opcode="create" >.. <node name="Object Store" opcode="create" >.. <node name="RTSP" opcode="create" >.. <node name="CLSID" opcode="create" type="string" value="{308786f0-8b15-11d2-b25f-006097d2e41e}" />.. <node name="Enabled" opcode="create" type="int32" value="0x1" />.. <node name="Properties" opcode="create" >.. <node name="Protocol" opcode="create" type="string" value="RTSP,RTSPA,RTSPT,RTSPU,RTSPM" />.. </node> Properties -->.... </node> RTSP -->.... <node name="Sessionless Multicast" opcode="create" >.. <node name="CLSID" opcode="create" type="string" value="{f9377800-f38d-11d2-b26c-006097d2e41e}" />.. <node name="Enabled" opcode="create" type="int32" value="0x1" />.. <node name="Properties" opcode="create" >.. <node name="Protocol" opcode="create" type="string" value="MCAST,RTP" />.. </node> Properties
                      Process:C:\Users\user\Desktop\free-pdf-convert.exe
                      File Type:ASCII text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):53
                      Entropy (8bit):4.66869469064966
                      Encrypted:false
                      SSDEEP:3:sLRaE92JWyhHX9ovy4dduRun:sLzTyRXKvndI0
                      MD5:A9B5DA9AEC61657B32393D96217165F0
                      SHA1:80B5C577155ACD269B450D70F6B2CBED693EDF49
                      SHA-256:9F4611369CF65B33D886489B2486FCA7B1E83E0DC998D35B15B3AA4C8478A28D
                      SHA-512:0B73B232C03FFD5CE526A1EDE481A57C753D15D9EE39D4247ABFA52819B59FA676C63E30825DAF233E3139038C353DF84D652C4CE2CB71A706DDDBDFE0C70335
                      Malicious:false
                      Preview:<document WMSNameSpaceVersion="2.0">....</document>..
                      File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                      Entropy (8bit):7.413859949785409
                      TrID:
                      • Win32 Executable (generic) Net Framework (10011505/4) 50.01%
                      • Win32 Executable (generic) a (10002005/4) 49.97%
                      • Generic Win/DOS Executable (2004/3) 0.01%
                      • DOS Executable Generic (2002/1) 0.01%
                      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                      File name:free-pdf-convert.exe
                      File size:12'777'560 bytes
                      MD5:76322138cd92b2d7d8358068da5a49ff
                      SHA1:a601cecfb0df308522d42dffa906550cc3be814d
                      SHA256:0506153535029472d82dfd03799861a2b2895172016b5b6d20f616e73dcdeb6e
                      SHA512:8eeab2b9c74a65f296f4989724c5158954500957108fe5dbd4c88e7ece2b1d872a62b6fe35290814fe764422b09fe675ffa274e6bb5ed92f110c17331c0db2eb
                      SSDEEP:196608:HPecwtAef5lCWe+cX6uBJ/xkTNLug1c8FIN/66som/fUykSIQiFUc9R:HPE1XKraTUN/6h/MykS0nr
                      TLSH:2ED69DB27BF48509D1C9337102A627F24794EF2498F542471B923FAD72B0ACAD673D1A
                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...r4............"...0..0..........^O... ........@.. .......................@......|_....`................................
                      Icon Hash:2060cac86c0e4000
                      Entrypoint:0x1014f5e
                      Entrypoint Section:.text
                      Digitally signed:true
                      Imagebase:0x400000
                      Subsystem:windows gui
                      Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
                      DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                      Time Stamp:0xE29F3472 [Sun Jun 25 14:34:26 2090 UTC]
                      TLS Callbacks:
                      CLR (.Net) Version:v4.0.30319
                      OS Version Major:4
                      OS Version Minor:0
                      File Version Major:4
                      File Version Minor:0
                      Subsystem Version Major:4
                      Subsystem Version Minor:0
                      Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                      Signature Valid:true
                      Signature Issuer:CN=COMODO RSA Extended Validation Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
                      Signature Validation Error:The operation completed successfully
                      Error Number:0
                      Not Before, Not After
                      • 03/05/2021 01:00:00 03/05/2024 00:59:59
                      Subject Chain
                      • CN=Shopcut LLC, O=Shopcut LLC, L=Fair Lawn, S=New Jersey, C=US, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=New Jersey, OID.1.3.6.1.4.1.311.60.2.1.3=US, SERIALNUMBER=0450508549
                      Version:3
                      Thumbprint MD5:8FC006D69CB97E4928F6D983C3CE0B40
                      Thumbprint SHA-1:4E21AE8053EEF3ABA5676F1B868D9837821FAA3F
                      Thumbprint SHA-256:1AF9C91884704DC177AA9870E3F155D89F587805BBD8196D83AA05D96BF8182C
                      Serial:0C7B374BA35C5F9539D3712A21DE78CC
                      Instruction
                      jmp dword ptr [00402000h]
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      NameVirtual AddressVirtual Size Is in Section
                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IMPORT0xc14f080x53.text
                      IMAGE_DIRECTORY_ENTRY_RESOURCE0xc160000x1a070.rsrc
                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                      IMAGE_DIRECTORY_ENTRY_SECURITY0xc2d6000x2258.rsrc
                      IMAGE_DIRECTORY_ENTRY_BASERELOC0xc320000xc.reloc
                      IMAGE_DIRECTORY_ENTRY_DEBUG0xc14e3c0x38.text
                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                      NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                      .text0x20000xc12f640xc13000unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      .rsrc0xc160000x1a0700x1a200False0.08875037380382775data2.501708169506309IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      .reloc0xc320000xc0x200False0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      NameRVASizeTypeLanguageCountryZLIB Complexity
                      RT_ICON0xc161a00x130dPNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.8987082222677876
                      RT_ICON0xc174c00x10828Device independent bitmap graphic, 128 x 256 x 32, image size 655360.0289246421388856
                      RT_ICON0xc27cf80x4228Device independent bitmap graphic, 64 x 128 x 32, image size 163840.0507203589985829
                      RT_ICON0xc2bf300x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 92160.07230290456431536
                      RT_ICON0xc2e4e80x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 40960.1024859287054409
                      RT_ICON0xc2f5a00x468Device independent bitmap graphic, 16 x 32 x 32, image size 10240.1950354609929078
                      RT_GROUP_ICON0xc2fa180x5adata0.7666666666666667
                      RT_VERSION0xc2fa840x3ecdata0.36254980079681276
                      RT_MANIFEST0xc2fe800x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                      DLLImport
                      mscoree.dll_CorExeMain
                      No network behavior found
                      050100s020406080100

                      Click to jump to process

                      050100s0.0050100150MB

                      Click to jump to process

                      • File
                      • Registry

                      Click to dive into process behavior distribution

                      Target ID:4
                      Start time:23:48:41
                      Start date:24/08/2023
                      Path:C:\Users\user\Desktop\free-pdf-convert.exe
                      Wow64 process (32bit):true
                      Commandline:C:\Users\user\Desktop\free-pdf-convert.exe
                      Imagebase:0x9d0000
                      File size:12'777'560 bytes
                      MD5 hash:76322138CD92B2D7D8358068DA5A49FF
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:.Net C# or VB.NET
                      Yara matches:
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000004.00000000.70101092480.00000000013E4000.00000002.00000001.01000000.00000004.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000004.00000002.71387074670.0000000003A61000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      Reputation:low
                      Has exited:false
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                      Executed Functions

                      Strings
                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID: 4'/r$H3r$H3r$H3r$H3r$H3r$p</r
                      • API String ID: 0-2123425722
                      • Opcode ID: 05cc94ee4e8bf184689fe824b568778fd962dc30cdb66dc68368f308ab6e05e7
                      • Instruction ID: aeae9b7062af99e06420a8f44ec53cff18b1f1c654f6985a70c2102616b2f0fc
                      • Opcode Fuzzy Hash: 05cc94ee4e8bf184689fe824b568778fd962dc30cdb66dc68368f308ab6e05e7
                      • Instruction Fuzzy Hash: 58D1E374E013188FDB55DFA8C994B9DBBB2BF89300F1081A9D509AB361DB34AD85CF51
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Strings
                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID: 4'/r$H3r$H3r$H3r$H3r$H3r$p</r
                      • API String ID: 0-2123425722
                      • Opcode ID: d50819223ec92735ffc4b029c8136d75aee9f3d9dc3cc22b34907aabb2500628
                      • Instruction ID: dd82ec005c49ea6ee0b526ca71b073c6a7f1b462415c67ba28e852e6a69c3133
                      • Opcode Fuzzy Hash: d50819223ec92735ffc4b029c8136d75aee9f3d9dc3cc22b34907aabb2500628
                      • Instruction Fuzzy Hash: 0FC1E474E012188FDB55DFA8C994B9DBBB2BF89300F1081A9D509AB361DB34AE85CF51
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Strings
                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID: (A4r$H3r$p3r
                      • API String ID: 0-1665784538
                      • Opcode ID: aa5ce01b8a31a2f582ccd78e9d8906dc1b204d7cda5664db9c3af58d25ca41c3
                      • Instruction ID: 3cc3de01a44963ceb5942c6a30a722c83807a6ca412b94f4f8e9dafa04687d57
                      • Opcode Fuzzy Hash: aa5ce01b8a31a2f582ccd78e9d8906dc1b204d7cda5664db9c3af58d25ca41c3
                      • Instruction Fuzzy Hash: F6229035A00214DFDB568FA4C944E99BBB2FF49314F1680D9E609AB272CB32DD91EF50
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Strings
                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID: `Q/r$i
                      • API String ID: 0-3605492622
                      • Opcode ID: caffac5f2f8a239d921a33a7ec6a4244bf57f656b9ab523caa78bf3af844977f
                      • Instruction ID: 5287b1318b78c42c6aca35b569240ecf8941023e8397c260b8035ff361348c5b
                      • Opcode Fuzzy Hash: caffac5f2f8a239d921a33a7ec6a4244bf57f656b9ab523caa78bf3af844977f
                      • Instruction Fuzzy Hash: 9B91AD74D01218CFCB25DFA9D584A9DBBF2FF89305F20856AD415AB360DB35A986CF40
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Strings
                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID: `Q/r$i
                      • API String ID: 0-3605492622
                      • Opcode ID: 07891c6506b694a43f26d29718525add7de6ec09653fc840f0851bf07e724c8b
                      • Instruction ID: 2c2c73e0b580b93357a240a68dbfaf88912f3a88d2fa00c2d5825e1e3a183ad8
                      • Opcode Fuzzy Hash: 07891c6506b694a43f26d29718525add7de6ec09653fc840f0851bf07e724c8b
                      • Instruction Fuzzy Hash: DB81AC74D01218CFCB25DFA8D584A9DBBF2FF89305F20856AE415AB364DB35A986CF40
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Strings
                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID: p</r$p</r
                      • API String ID: 0-1708091687
                      • Opcode ID: 8cf72181f26139a78413e1f842108275e9be2920f4746a2117bb7191f71a4159
                      • Instruction ID: 093d5dff6b19d6c965286d9f06b716a4ea5debe59364eff878ae2d3441e7494a
                      • Opcode Fuzzy Hash: 8cf72181f26139a78413e1f842108275e9be2920f4746a2117bb7191f71a4159
                      • Instruction Fuzzy Hash: B971BF75E00318CFDB25CFA9C984ADDBBF6BF89301F24812AD405AB264DB349986DF10
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Strings
                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID: p</r
                      • API String ID: 0-3407694601
                      • Opcode ID: 5f7e10635859a204bbd0c1cdc741c3b0a6d8a958fb6a2a59692f18befb4c5995
                      • Instruction ID: 6d5c590476895d7d6564037d323b00f5eade0f56334b3767e27ca2f99bc3b9a5
                      • Opcode Fuzzy Hash: 5f7e10635859a204bbd0c1cdc741c3b0a6d8a958fb6a2a59692f18befb4c5995
                      • Instruction Fuzzy Hash: CB61B275D01318CFDB25CFA9C888AEDBBF6BF49301F248169E405AB264DB359986DF10
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Strings
                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID: qq^
                      • API String ID: 0-671998621
                      • Opcode ID: 6b3973737c811966265c03576740dc6d84cd6d9e781b90eeac89996a87083eac
                      • Instruction ID: 2778c857aa4eeb3e99599efc14b0c8668ae8e3b351770e48865cc5a554d5d48b
                      • Opcode Fuzzy Hash: 6b3973737c811966265c03576740dc6d84cd6d9e781b90eeac89996a87083eac
                      • Instruction Fuzzy Hash: 1531EA34E012099FCB15DFA8D8989EEB7B1FF8A302F2095A9D415A7354DB31AD05CF91
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Strings
                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID: $/r
                      • API String ID: 0-3087845175
                      • Opcode ID: 4134298074711cb4c13eca4f90c0107c02b03ab8618ef9579685f7f510aa50b0
                      • Instruction ID: 85cfdb2b6488192f85d8c9320a7d0c9f3a0c9905c6f3b7aa032c424f9d92522d
                      • Opcode Fuzzy Hash: 4134298074711cb4c13eca4f90c0107c02b03ab8618ef9579685f7f510aa50b0
                      • Instruction Fuzzy Hash: 1BF0F431B402201FE76A93AD9C90ABF77E6EFCA760B04057BC506CB381DE654C0287A5
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Strings
                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID: $/r
                      • API String ID: 0-3087845175
                      • Opcode ID: f485019df8f48b9601c26341200c87dd882a954b00510db5c86edd7549e06146
                      • Instruction ID: 9753d8a314278d5105b3fad94faf5b9ad99353e6503573a713bd23f99937ffaa
                      • Opcode Fuzzy Hash: f485019df8f48b9601c26341200c87dd882a954b00510db5c86edd7549e06146
                      • Instruction Fuzzy Hash: E8F02431B402241FE7AA92ED9C50BBF76DAEBC9A20F00043BD50AC7384EE714C0183E5
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 8af235d5e30b07e328b002de5bb285df0b10f3c786f31dd0b86cccdb47533ff2
                      • Instruction ID: ff53b4bf661bb9c28995b00fe1e7beb09c1b81e84c424a13776396a3a7cd5b34
                      • Opcode Fuzzy Hash: 8af235d5e30b07e328b002de5bb285df0b10f3c786f31dd0b86cccdb47533ff2
                      • Instruction Fuzzy Hash: 80D14574E112188FCB15DFB8D994A9EBBB2FF89301F1085A9D409AB355DB30AD46CF50
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 8741a1d8a063b1bc8fc7e330d980bcddf81636e2433e753c38f8a1e086ef6a54
                      • Instruction ID: ea3f6b23ce054fd602d135abd682cc2414a2ebd13e78f09090aee3a21bd24f24
                      • Opcode Fuzzy Hash: 8741a1d8a063b1bc8fc7e330d980bcddf81636e2433e753c38f8a1e086ef6a54
                      • Instruction Fuzzy Hash: 3EC1F674E10219DFCB14EFA8E994A9DBBB2FF89301F109569E409AB354DB30AD46CF50
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: e46c2315f2b1341f07c210b0d754647b87ca84e4130b1870a5bb5bfaf9779c1b
                      • Instruction ID: b3f0b4dc317f395a0ff76b82c266f350977da48f3f6f49e66a4c011ff9122dff
                      • Opcode Fuzzy Hash: e46c2315f2b1341f07c210b0d754647b87ca84e4130b1870a5bb5bfaf9779c1b
                      • Instruction Fuzzy Hash: 2381F038624213CBE725EB60EA6895E37A3FBB4386B508515D512473C4EB796C07CBD2
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 8236f2126814dca1139bbed28ddcc9734198a83f3ea7aaa4357a893569d5956d
                      • Instruction ID: 2b2be64cc4b8c2cc71c88773e90c1177b6ece36b091656fff12877c8257165bb
                      • Opcode Fuzzy Hash: 8236f2126814dca1139bbed28ddcc9734198a83f3ea7aaa4357a893569d5956d
                      • Instruction Fuzzy Hash: 7581E038624217CBF714EB60EA6895E33A3FBB4386B509615D512473C4EB792C07CBD2
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: ddd4592da2f91ea3a906e14813249f1ca28b42ffca37ca188404af8e2a04a79a
                      • Instruction ID: 0201d7c5f79325d111990c3eabeba2ececafec9fee54d2a0e22c2eaf9250c131
                      • Opcode Fuzzy Hash: ddd4592da2f91ea3a906e14813249f1ca28b42ffca37ca188404af8e2a04a79a
                      • Instruction Fuzzy Hash: 7A41D430B002159FDB559B65D418AAEFAF7EFC8354F10802AE906AB790CF718C01DBA1
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: ab47d99a3aa688cc5c10495f182bbd0f68edacd710334084e02954386b678212
                      • Instruction ID: 55d48b5f0fbd7c9beb039f740fd5cef9b7a29ed5cd773b04b8eb5575101383c7
                      • Opcode Fuzzy Hash: ab47d99a3aa688cc5c10495f182bbd0f68edacd710334084e02954386b678212
                      • Instruction Fuzzy Hash: 3251B374E112189FDB58DFA9D994AADBBF2BF89300F14906AE415AB3A4DB309C01CF54
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 33ec19ab8efe805384f42ab8a5468f41882bae615c68f65ded5c7a2e00c412f6
                      • Instruction ID: 25a7ce434c3ad610318739d4af500a56436b35896846d5e74727b8f55972e288
                      • Opcode Fuzzy Hash: 33ec19ab8efe805384f42ab8a5468f41882bae615c68f65ded5c7a2e00c412f6
                      • Instruction Fuzzy Hash: 2751D474E11218DFDB58CFA9D894AADBBF2BF89300F109069E815AB3A4DB319D01CF54
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 59040bc573ee2f32600d8b2c2123d9cd9af3b8fb22c6abe2e56d4ad4ac5303ed
                      • Instruction ID: 6b6827ab12b91c7d7d08062fb1025de074a736c23fd68df7d228aeb511a5378f
                      • Opcode Fuzzy Hash: 59040bc573ee2f32600d8b2c2123d9cd9af3b8fb22c6abe2e56d4ad4ac5303ed
                      • Instruction Fuzzy Hash: 0F31CF75E01219AFDB55CFA8E984AEEBBF1BF89310F10416AE505B7360DB309941CFA4
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: e67552df9d632fc94b82f9707e71fb256cc9828e68d65b6ece9d92340716bd70
                      • Instruction ID: bad9301aab7d275d5fa2583e6c2e164b29db7c3c1a40752d3dc6659319952f7a
                      • Opcode Fuzzy Hash: e67552df9d632fc94b82f9707e71fb256cc9828e68d65b6ece9d92340716bd70
                      • Instruction Fuzzy Hash: B631A072500200EFDF469F54E9C0F5A7F76FB88314F2495A9EE090A26AD33BD461DBA1
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 3cdad489524d6915e081790973b6d4eb126cced99c10ac567bed2ead88a97923
                      • Instruction ID: 0af6961d3057bd95a787fd4270b08a707b298843b1d9aa10ad48e483f9eabc7e
                      • Opcode Fuzzy Hash: 3cdad489524d6915e081790973b6d4eb126cced99c10ac567bed2ead88a97923
                      • Instruction Fuzzy Hash: F631C075E01218AFDB16CFA8D994AEEBBB1FF89300F10516AE501B7264DB305A41CFA1
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 67dc301eeb94b08ad75d92f36fd2571f11b108e6d81700f47fe92c1e11fb600f
                      • Instruction ID: c84f58cea9c254462b26da0f27f57495cb171ed437a212af64afac325aaa8cfb
                      • Opcode Fuzzy Hash: 67dc301eeb94b08ad75d92f36fd2571f11b108e6d81700f47fe92c1e11fb600f
                      • Instruction Fuzzy Hash: 8B31C372100240EFDF069F54E9C0F1ABF66FB48318F24D5A9E9094E267C33AD865DB61
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 1fd2876e7202cc56a86fe36bd32b165cb399823f486a81bc3b60b15b21e89100
                      • Instruction ID: edb10a6d546f8e3122a7d12213425aec92b2354250ba05041e8ab4d97eb0ef55
                      • Opcode Fuzzy Hash: 1fd2876e7202cc56a86fe36bd32b165cb399823f486a81bc3b60b15b21e89100
                      • Instruction Fuzzy Hash: 2E310672100200EFDF169F54E9C0F1ABF66FB88314F248599F9090A256C33AD8A2CB61
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 73c5c6fa2c649ca74e73084b9b44784f32c9278dd9701250e4fd502628246deb
                      • Instruction ID: 37885a2ab216b0b776d2cb39d037907ba96c35d5bca90ee3c4b6c377849f15d4
                      • Opcode Fuzzy Hash: 73c5c6fa2c649ca74e73084b9b44784f32c9278dd9701250e4fd502628246deb
                      • Instruction Fuzzy Hash: 5721F871500200EFDF158F58E9C4B1ABB66FB8C314F248599E9490A257C33AD466CB61
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 84f33a2dc01e2d66d5365be28e47788079d91cae9f735c1036e6d2a45a1b87bc
                      • Instruction ID: 89f1a490410d142ccc483fcd43fe14eaa8a7d46fe4ae157c6f71a18184d952eb
                      • Opcode Fuzzy Hash: 84f33a2dc01e2d66d5365be28e47788079d91cae9f735c1036e6d2a45a1b87bc
                      • Instruction Fuzzy Hash: 7141C3B4518373EFFB228F11E41E5593BE6BB0138DB424608EB0D8E282D7B8A148DF15
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385573767.0000000001E3D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E3D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e3d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 76cca8b5608e7f6624dbf079d99120795e52f7c32a1432164252dad756d5bc17
                      • Instruction ID: cbc852b1517e7fdd3fe5bbb494cbd12d8025900b14ecf93154fdc86b2d4f0769
                      • Opcode Fuzzy Hash: 76cca8b5608e7f6624dbf079d99120795e52f7c32a1432164252dad756d5bc17
                      • Instruction Fuzzy Hash: 89210371504340EFDB01DF94DDC8B2ABF65FBC8318F6485A9E8090B296C336D455DAA2
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 4a5e8a5b632381dde052a38eb4a32a86f9a94f219371d3ba8ce79829846e5099
                      • Instruction ID: 6c21bd67bcbdce7b3ba59bf1f115e81b64a18d8a115f2a6cd2ce0c3e8293fc2e
                      • Opcode Fuzzy Hash: 4a5e8a5b632381dde052a38eb4a32a86f9a94f219371d3ba8ce79829846e5099
                      • Instruction Fuzzy Hash: 292136306143548BDF2ABBB4E86D4ED3BA3AF813463400834A647C72A5EEB84C42DF44
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: bddcf6efdfc1c68f1f071af4f324d94e2b1328dadf841dea99f638d7ee0f8ea1
                      • Instruction ID: 43b3cd923ea82f1e25557cbd10bf3baddd07699698eac113e6fb78c8e6974853
                      • Opcode Fuzzy Hash: bddcf6efdfc1c68f1f071af4f324d94e2b1328dadf841dea99f638d7ee0f8ea1
                      • Instruction Fuzzy Hash: A8212571604300DFDB15DF94E9C4B1ABB66FB98354F20C56DE8094B386C33AD846CA62
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 23705791b84a32d5c051e5ec5e4335b229d9d6adf7ba538485b75acc2dca3692
                      • Instruction ID: f456a29fcf457fdf6f4aabf02022fb76f79d0f4d12fcae55e161f1386419f92d
                      • Opcode Fuzzy Hash: 23705791b84a32d5c051e5ec5e4335b229d9d6adf7ba538485b75acc2dca3692
                      • Instruction Fuzzy Hash: A7213871604340DFE711DF58E9C4B2EBBA5FBD4328F20C56DD8094B246C73AE446CAA2
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 026c3334a23080c6a89fd725dcd6e0315a3aa5af2309bb840a7ad32383926c90
                      • Instruction ID: cb96d29e46c96e15a1a3edcf71d09d1d41788eef280bee9b473fd021467632dd
                      • Opcode Fuzzy Hash: 026c3334a23080c6a89fd725dcd6e0315a3aa5af2309bb840a7ad32383926c90
                      • Instruction Fuzzy Hash: 5F21A771604340DFEB15DF28E5C4F1ABBA5FB88318F24C56DE8494B256C33AD846CA62
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 20cc1c27b117e546fde33f78f48b28926690c1982e1c2d49ab186e1c9f1045fc
                      • Instruction ID: 96792ef77072228156857e8ec377df87179ea76377e5d1a3452de2abde890a6d
                      • Opcode Fuzzy Hash: 20cc1c27b117e546fde33f78f48b28926690c1982e1c2d49ab186e1c9f1045fc
                      • Instruction Fuzzy Hash: 9D31E0B0D01248DFEB25CFA9D988BDEFBF1AF48304F24842AD408AB254D7756845CF55
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 551c715cc35b7ca00fa17138999322a4988e6894f77c150930f6a7525ea58687
                      • Instruction ID: f596c83472ddd660a70f008b410dbd4dcfca25ee5609dc7a55d935663c51a7fc
                      • Opcode Fuzzy Hash: 551c715cc35b7ca00fa17138999322a4988e6894f77c150930f6a7525ea58687
                      • Instruction Fuzzy Hash: 87216B76400240EFCF068F44D9C0B59BF72FB88314F248199EE080A22AD33BD466DB91
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 3bf0f77d295cb8431102ad2803d725016d8b45b86927bfaa18bff9288b70fb14
                      • Instruction ID: 7bfac3bf2e02d6fea3d8e21935c97762d43e4d95f22f8e2efca81fd3adfa14ba
                      • Opcode Fuzzy Hash: 3bf0f77d295cb8431102ad2803d725016d8b45b86927bfaa18bff9288b70fb14
                      • Instruction Fuzzy Hash: F031DFB0D013489FEB25CFAAD984BDEBBF5AF48304F24802AD408AB250D7756885CF55
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: f16282219a50b415584369aebbc608e0cf0a69b93d909432acadaf29fbaab310
                      • Instruction ID: 640cef57afa0bd9d5da4ceb715169ea6ff789fc020a1a90050c7c81b8cea38ef
                      • Opcode Fuzzy Hash: f16282219a50b415584369aebbc608e0cf0a69b93d909432acadaf29fbaab310
                      • Instruction Fuzzy Hash: 5A217F76404240DFCF128F54D9C4B55BF72FB88314F248699ED494A26BC33AD8A6DB51
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: ea52929a99a5d17f6c7eba5ab11341d1668b3c561aa404b23b4acdd2e0f3bc2b
                      • Instruction ID: 9e3ccc72f48218d82be110a5041c6da6a6e1654c8b03f01d6d5cf7d0083934a9
                      • Opcode Fuzzy Hash: ea52929a99a5d17f6c7eba5ab11341d1668b3c561aa404b23b4acdd2e0f3bc2b
                      • Instruction Fuzzy Hash: 7721E674D00209DFCB08DFA5C4586AEBBB2FF8A301F2084A9D405A7354DB359A45CF61
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 42ae6b521f502e848143f90aed0beb6486f4f6dd881d44a9050e4e98147badbf
                      • Instruction ID: 6cb07a249b2beec63b88e7360fe8be5398f7f5ed805d4f4d2e07d729c1c1478e
                      • Opcode Fuzzy Hash: 42ae6b521f502e848143f90aed0beb6486f4f6dd881d44a9050e4e98147badbf
                      • Instruction Fuzzy Hash: 8A11D8307143548BDF6ABB75E86D4ED3AA7AF807467400838AA07D72A5FEB84C42DF44
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 1bdcf9b865d59d6189dcec387a56c0f0cf969612aa9d33050653d240d8b4da2e
                      • Instruction ID: 6b8ea1523cf435c2681c98324ce312e43cc98be116dcbe7d3e28d1e268139b7a
                      • Opcode Fuzzy Hash: 1bdcf9b865d59d6189dcec387a56c0f0cf969612aa9d33050653d240d8b4da2e
                      • Instruction Fuzzy Hash: C7119131B052285FCB76D77AAD209AE7BD6EFC8690309416BC905C7385EE249C0387D5
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: f37fca7cf6d36573a0265212d1153cd67fd74cc33b82a5b6ce0624391643ec9e
                      • Instruction ID: 916ea82ad470af7aa3512b64b922c93d42234c4647d9f502df0fd6c997b2c58b
                      • Opcode Fuzzy Hash: f37fca7cf6d36573a0265212d1153cd67fd74cc33b82a5b6ce0624391643ec9e
                      • Instruction Fuzzy Hash: 4D215976500240EFDF16CF54D9C0B15BF62FB48318F2486A9EE094A26BC33AD4A6DB51
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: d7788e890bf81552fdbd05d8cd29e659ea6f206491b76417a390b6b8413a70bf
                      • Instruction ID: 13b4c645a6045790db89618169acfde5e0c363699743ad260bc3fadbaa2ad7d8
                      • Opcode Fuzzy Hash: d7788e890bf81552fdbd05d8cd29e659ea6f206491b76417a390b6b8413a70bf
                      • Instruction Fuzzy Hash: E9218E755083808FDB12CF64D994715BF72FB46314F28C5EAD8498B2A7C33A984ACB62
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 43c47c083260c4751dfc98176744e960caf77b4c5f64dc41b5d17a30a081536b
                      • Instruction ID: 6dbd0bd7cda756dcb35797ef7661c081cfedf2bbc6521804e7d95ff7668e4c27
                      • Opcode Fuzzy Hash: 43c47c083260c4751dfc98176744e960caf77b4c5f64dc41b5d17a30a081536b
                      • Instruction Fuzzy Hash: 0F114934A11214DFCB18DF79E848AADB7B2FF8A302F00A039D406A7354DB75A806CB94
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: c6c6ca5af68db5cf6d8ce195ce6d4a6732d1e939ea15e74f69b2e4b3ef6115cf
                      • Instruction ID: 01662348a690191e88b28b22ed5cf6f1f99b223f26b7b96c5204b89d6a613e10
                      • Opcode Fuzzy Hash: c6c6ca5af68db5cf6d8ce195ce6d4a6732d1e939ea15e74f69b2e4b3ef6115cf
                      • Instruction Fuzzy Hash: 45218B72404240DFCF22CF54D9C4B5ABF72FB88314F2486A9E9484A267C33AD466CF92
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385573767.0000000001E3D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E3D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e3d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: ecdd1007858a5ab751f0291dbb77ab66ae8569b94fa8dd568a91174c9a81c9b3
                      • Instruction ID: 30afc06f47b8a577a812cb6d6a44cfd3eff8f0e5468d5b0de62d5b360f212217
                      • Opcode Fuzzy Hash: ecdd1007858a5ab751f0291dbb77ab66ae8569b94fa8dd568a91174c9a81c9b3
                      • Instruction Fuzzy Hash: B411B176504280CFDB12CF54D9C4B1ABF72FBC8314F2485A9D8094B257C33AD45ADBA1
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 09cf3cac9e0d390d4c53f9ecf8b39c0d8b824e77d59732a339ffd90e22e3dbd3
                      • Instruction ID: b6267eaaef774eefb716da42cfd4d36328ce4aa96f4b9b8f023c44f7b4e49e12
                      • Opcode Fuzzy Hash: 09cf3cac9e0d390d4c53f9ecf8b39c0d8b824e77d59732a339ffd90e22e3dbd3
                      • Instruction Fuzzy Hash: D1110634A01214DFCB18DF65E4589ADB7B2FF8E302F00602AD406A7354DB759846CB95
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 9a4b349168404008a2422a2dff0264e8fefb43983aec9a0da8e07df2ff229d83
                      • Instruction ID: d6ca1a25d8b0f248e56d70f22ff51eca87374f42e061505b493b457bc9946b87
                      • Opcode Fuzzy Hash: 9a4b349168404008a2422a2dff0264e8fefb43983aec9a0da8e07df2ff229d83
                      • Instruction Fuzzy Hash: B8119176504280DFDB12CF58E9C4B19BF71FB84328F24C6AAD8494B656C33AD54ACB92
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385702759.0000000001E4D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E4D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e4d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: f2452829189e95b9624ddd4bacab1f21c5718544d1b53b395e6647c57ac37938
                      • Instruction ID: 9e92a6fdda210da1f7c8a51cd4f959815562f0d20607929cee5265db1cdb0c69
                      • Opcode Fuzzy Hash: f2452829189e95b9624ddd4bacab1f21c5718544d1b53b395e6647c57ac37938
                      • Instruction Fuzzy Hash: 73119075504280CFDB12CF28D5C4B19BFA1FB84218F24C6ADD8894B652C33AD44ACB51
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 877b3f2d5bdd7cd0e4635df7e35072c34e798649190b1e629de50274667b40f3
                      • Instruction ID: 5c8bf60ee0f0697a6d81b52cd126fc88a797919dbc1d3f8b098bc7b428d3edc5
                      • Opcode Fuzzy Hash: 877b3f2d5bdd7cd0e4635df7e35072c34e798649190b1e629de50274667b40f3
                      • Instruction Fuzzy Hash: 3C111074D002498FDB15CFAAC458AEEFBF2AF89304F04942AC811B7295DB701806CB64
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 2d9385fe654c1101f99ef7e296461129a7457d09e871c2b5f3b9dee28c03d1b9
                      • Instruction ID: ffdf7ec6b3e841a998e2f61de50a84e09dedba82db0d70c6aa8310ed2f318e3d
                      • Opcode Fuzzy Hash: 2d9385fe654c1101f99ef7e296461129a7457d09e871c2b5f3b9dee28c03d1b9
                      • Instruction Fuzzy Hash: 2B010579D002098BDB15DFBAD558AEEFBF2AF8D304F04D42AC811B7284DB745906CB65
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385573767.0000000001E3D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E3D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e3d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 1777f23b76476aa20476862709accd47f5bb60b085d5a01db6a281d93c00bda5
                      • Instruction ID: b7a1ceba5fa457358c234952e4147f0b4ae97ee3768768e1a57922f6b66dfd59
                      • Opcode Fuzzy Hash: 1777f23b76476aa20476862709accd47f5bb60b085d5a01db6a281d93c00bda5
                      • Instruction Fuzzy Hash: E901F7310083409FE7108B56CEC8B6ABF9CFFC5265F58942AED491B283D2799845C672
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 48fa95967a5cb0ce3896c5a5421cae1e6a81aef117c0a335e4cb06df83a01c45
                      • Instruction ID: 13349cb30dd76a852cd6326f30eda4c7f01fc9686a05c9f04c8e44e35cf278d0
                      • Opcode Fuzzy Hash: 48fa95967a5cb0ce3896c5a5421cae1e6a81aef117c0a335e4cb06df83a01c45
                      • Instruction Fuzzy Hash: AD11B374E002099FCB14EFA8D584AADB7F1FF49300F109599E815A7354D771AE41DF41
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 9276c05bd788b1401ff24188c0b80651bbb8a35bb091fd81ea66bd1de8a06968
                      • Instruction ID: 3adbc64503eec26dddf34ea2b787ca04ddb215a2a8759565e0f730882c3e572e
                      • Opcode Fuzzy Hash: 9276c05bd788b1401ff24188c0b80651bbb8a35bb091fd81ea66bd1de8a06968
                      • Instruction Fuzzy Hash: F00116B4E013099FDB15EFA9C548BADBBF1FF49304F1089AAC864A7391D7709A45CB50
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71385573767.0000000001E3D000.00000040.00000800.00020000.00000000.sdmp, Offset: 01E3D000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_1e3d000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 7c41f90a4e497db6b8a3beea6beb276214154512f54c6619655609b6e9582625
                      • Instruction ID: e2eec4f458f5d7aec3e4cb4755b12050d3a9fa2631c877f00a82edf3b1a1232b
                      • Opcode Fuzzy Hash: 7c41f90a4e497db6b8a3beea6beb276214154512f54c6619655609b6e9582625
                      • Instruction Fuzzy Hash: 78F0C232408344AEE7108B4ADDC8B66FF98EF80374F18C45AED085B283C3799849CA71
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: a98bc42a2d178dd6366a5576fa83ccba3f599eafc99859bef7db9a688bc33575
                      • Instruction ID: b43f6b8cc9b8edc809567c47972ce0c9ac6287f1bebab96d6d01900c0c2ba9ef
                      • Opcode Fuzzy Hash: a98bc42a2d178dd6366a5576fa83ccba3f599eafc99859bef7db9a688bc33575
                      • Instruction Fuzzy Hash: 20E0D835A09350CFCB124BA1A4190F8BF30FE47302B4010EBD14AE7161D3B5C516D711
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 7bb6035981db99e9059f73584e734f05e2a236cb759c31fed2a170444f0bbd15
                      • Instruction ID: fd4cea6183112bf49cea6c848c795148a9161570ad200ee0631b438c319977a0
                      • Opcode Fuzzy Hash: 7bb6035981db99e9059f73584e734f05e2a236cb759c31fed2a170444f0bbd15
                      • Instruction Fuzzy Hash: 4CE06D30902204CFCB25CF74E485ADC7BB0EF0B301F1091A9D804A7215C7315952DB54
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: bb5b96e2f8ac3507a08c2efa508d7ed7e030edd8de16b04e5bf2db3c7c96ac02
                      • Instruction ID: cf106c04e294d5bba6e0cdab2540c66af8498763c2de83c212429a980db02688
                      • Opcode Fuzzy Hash: bb5b96e2f8ac3507a08c2efa508d7ed7e030edd8de16b04e5bf2db3c7c96ac02
                      • Instruction Fuzzy Hash: 87F0ED30901309DFCB02EBB0D949A8CB7F6EF02200F4444A9C000EB250DB322A01EB41
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 80fc6dbf1fd9df2a141eb1cca555708cf1fec4cea66765a58ad26795dc4c9cc1
                      • Instruction ID: 4ae870efaf51fbc3c7eab47413daabeb46e1e380b89a12118d766e2ad83e3a21
                      • Opcode Fuzzy Hash: 80fc6dbf1fd9df2a141eb1cca555708cf1fec4cea66765a58ad26795dc4c9cc1
                      • Instruction Fuzzy Hash: 5DE02630809308AFC315CF74D946A6DBB79EF03644F0012E9E004A32A0CB306D40DBA5
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: fb8e63db9495acf8ddc17b15d1534e3362c30fde2e2442683dfbed6c2273d559
                      • Instruction ID: 4107aba3d0a587fe0cbf65de327bf145d751398f36a7252a97577c20b9ff73d4
                      • Opcode Fuzzy Hash: fb8e63db9495acf8ddc17b15d1534e3362c30fde2e2442683dfbed6c2273d559
                      • Instruction Fuzzy Hash: 22E0C2B280D3489FC726CF64D8157697B39AB13209F0505EAD84493292DF664A04D3A6
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 9c7b3feec65003aa2be10448ffabb38893dac49d270b6b1e3bf63b9186a6eed3
                      • Instruction ID: e0773d8c16fa9dbda3c00981294053546970b9777f8ae3c218fdeffafab664b5
                      • Opcode Fuzzy Hash: 9c7b3feec65003aa2be10448ffabb38893dac49d270b6b1e3bf63b9186a6eed3
                      • Instruction Fuzzy Hash: 32E08C70A0130AEFCB11EFB4E904A9DB3EAEF46204F5044A89404AB240DB721E01EB91
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 987423ecaba8d6f4bc32367b884c6b2d9e3f3bdba8f7e508902efff7368c671f
                      • Instruction ID: 99a60d7f40bd05314ec5e17ed3540162ac933babf04f2b590e10ec58a833f475
                      • Opcode Fuzzy Hash: 987423ecaba8d6f4bc32367b884c6b2d9e3f3bdba8f7e508902efff7368c671f
                      • Instruction Fuzzy Hash: A5E0C234901308DFC714DFB4E144A9CBBF4FB0A301F1041A8D80423344C7319A41DB94
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: bcfcd16fda639f016028cca52e075d95fd23d9ed68d9a493ecb6fbe4c4f4e4ba
                      • Instruction ID: 3351c1aeedc95914c2a8ef2fcae14a0757c59227ae02dc02ce6b181e51cc9507
                      • Opcode Fuzzy Hash: bcfcd16fda639f016028cca52e075d95fd23d9ed68d9a493ecb6fbe4c4f4e4ba
                      • Instruction Fuzzy Hash: 3ED0A7329043414FFB7B5F6048043D63BD0EE0911070601E38C019B092D6B4D4C19B11
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 752c414ee55ec185751056652f0ec09b7e2d128843a56c6338a6fa0aa5aef7ca
                      • Instruction ID: 4bbea060aa6a713b59399b3e74baf31c98bc67bf63c961dafafc012b2454f0b8
                      • Opcode Fuzzy Hash: 752c414ee55ec185751056652f0ec09b7e2d128843a56c6338a6fa0aa5aef7ca
                      • Instruction Fuzzy Hash: 48D0A7B010D3508FD77357209C90AA07FE0AF8A344B0600DAE941CB0A2C7785C81DB21
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: ddcc42d49d3a03e5be84d5d5bf221dd846f911b39844af02d363c7615f54cc70
                      • Instruction ID: 00c01d9a5e86263a91305f0dd8c116c91f993d35f03677d55fa80c843cee33fc
                      • Opcode Fuzzy Hash: ddcc42d49d3a03e5be84d5d5bf221dd846f911b39844af02d363c7615f54cc70
                      • Instruction Fuzzy Hash: 4ED01775E04248DBCF14EFA4C85559E7BB5EF09244F0001E99C0A97251EA706A10DB81
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: eeac5e10d3c314189a1c103ac2621a309e086af5cd6149445bdc36da8a323ff1
                      • Instruction ID: f0bb78572347da04a7fcf127125d845359c407eac8ecdf56624c2dbb9d79cc42
                      • Opcode Fuzzy Hash: eeac5e10d3c314189a1c103ac2621a309e086af5cd6149445bdc36da8a323ff1
                      • Instruction Fuzzy Hash: 4FD09239900208DFCF14DFA0E1044EDB772FF8E316B6010A9D006B2210D7369E55CB14
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 3063832da1f59a80cb201ee4f6f869f5189b48d9de000e8605e7d0ce4948d98e
                      • Instruction ID: 4dd91fa003d9568a7ea215e43724789ca47dee12e7b71d8e0ece653dc0d3901c
                      • Opcode Fuzzy Hash: 3063832da1f59a80cb201ee4f6f869f5189b48d9de000e8605e7d0ce4948d98e
                      • Instruction Fuzzy Hash: A3C08C22F043024FBFBBAA3108283BB60D2DF8C100784806F4982CB1C4FFA4C800A722
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 7d3877caa05f5036a0c595f7818f1a92315e7cb7dd4e0af75bfcff15b8de29c3
                      • Instruction ID: 558ad88e213fb13d64f46ea59c228ab9767ff062205f76aaa0884e17ddafd1aa
                      • Opcode Fuzzy Hash: 7d3877caa05f5036a0c595f7818f1a92315e7cb7dd4e0af75bfcff15b8de29c3
                      • Instruction Fuzzy Hash: 6CC012A07083305FD7B746345815375B5E29FC9244B80402EA946C6194DF788C409621
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 27911810f4a49286f4fe1e77d981fe01edcba49bf8f12d2b1b04d2ba985fa809
                      • Instruction ID: fcac829889cd6277a76b7b41ea28c7b21119b34173fdbd6444be3dbe06e9aab2
                      • Opcode Fuzzy Hash: 27911810f4a49286f4fe1e77d981fe01edcba49bf8f12d2b1b04d2ba985fa809
                      • Instruction Fuzzy Hash: 3CD012354506168BCA119B60E91978677BDBF10105F400404E95F03604B62A39728696
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 6a51563c5e80eacfd9b302b286b6f528c2dd2c8bc5bda46bfb6bd01d02d2e0a5
                      • Instruction ID: 8227c92057faaf3f96db89947b7bf95a91c11b684418cb71806624c4b4f9ef46
                      • Opcode Fuzzy Hash: 6a51563c5e80eacfd9b302b286b6f528c2dd2c8bc5bda46bfb6bd01d02d2e0a5
                      • Instruction Fuzzy Hash: 40B09B35100F0447D9355A95B40C76972D9A702615F451524954C4149C4B645055D7E5
                      Uniqueness

                      Uniqueness Score: -1.00%

                      Memory Dump Source
                      • Source File: 00000004.00000002.71386345441.00000000020B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 020B0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_4_2_20b0000_free-pdf-convert.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: e58f27c41cda0383bd2ffbfbe4c8821c78192e4bf5869d60d0934ceef5fdd6ad
                      • Instruction ID: 923c9611567aab317002403b6569364eece23a6b9cb47e4d466f91c4953fd10c
                      • Opcode Fuzzy Hash: e58f27c41cda0383bd2ffbfbe4c8821c78192e4bf5869d60d0934ceef5fdd6ad
                      • Instruction Fuzzy Hash: 4AB0123406031F8BC6406761F61854D775EA560105B404410F10D06500696A2C418686
                      Uniqueness

                      Uniqueness Score: -1.00%