pdfconverterhq.9fa0ed06a12a43409bb5eede58a83735.exe

PDFConverterHQ

Mindspark Interactive Network

The file pdfconverterhq.9fa0ed06a12a43409bb5eede58a83735.exe, “PDFConverterHQ Setup” by Mindspark Interactive Network has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from ak.imgfarm.com and multiple other hosts. While running, it connects to the Internet address 74.113.233.180.df.iaccap.com on port 443.
Publisher:
Mindspark Interactive Network, Inc.  (signed by Mindspark Interactive Network)

Product:
PDFConverterHQ

Description:
PDFConverterHQ Setup

Version:
2.7.1.1000

MD5:
de6dd955c09f7a5b30d80ca5f63ec90c

SHA-1:
8956d694d08dbc9195a833f1d65f8eda67c2fdde

SHA-256:
2fc84e17bf479304557bea08762c0b7f042388f4213c8a236d13738ea9ac2dbe

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
8/22/2018 6:46:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Mindspark (M)
16.10.24.18

File size:
365.3 KB (374,064 bytes)

Product version:
2.7.1.1000

Copyright:
© 2015 Mindspark Interactive Network, Inc. An IAC Company. All rights reserved.

Trademarks:
® & ™ Mindspark Interactive Network, Inc. An IAC Company. All rights reserved.

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\pdfconverterhq.9fa0ed06a12a43409bb5eede58a83735.exe.81weu9d.partial

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/20/2015 1:00:00 AM

Valid to:
6/19/2018 12:59:59 AM

Subject:
CN=Mindspark Interactive Network, O=Mindspark Interactive Network, L=Yonkers, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
438D4291E43C2DFFEEAAAEE5B6C070B5

File PE Metadata
Compilation timestamp:
12/25/2013 5:01:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:obUTp1XXVkcxHXM+/87wBeat1RAAx94DqoJJDFHFXPRSDJikrHLAPS7EQRMuOBfk:oIHXVB87wBe2Rf4DqozVpPRSDskrHMB7

Entry address:
0x3229

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 14, C7, 44, 24, 10, D8, A2, 40, 00, 89, 6C, 24, 1C, FF, 15, 34, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, 34, 81, 40, 00, 55, FF, 15, AC, 82, 40, 00, 6A, 08, A3, 58, 4F, 43, 00, E8, 9F, 2E, 00, 00, A3, A4, 4E, 43, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, B8, B1, 42, 00, FF, 15, 7C, 81, 40, 00, 68, C0, A2, 40, 00, 68, A0, 3E, 43, 00, E8, 0A, 2B, 00, 00, FF, 15, 38, 81, 40, 00, BB, 00, F0, 43, 00, 50, 53, E8, F8, 2A, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file pdfconverterhq.9fa0ed06a12a43409bb5eede58a83735.exe has been seen being distributed by the following 50 URLs.

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.a43a10e4909d4957ab2372e460162fc7.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.c38157b526884da6b356a28583c4a586.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.7036dd1616684d42b57b1087d68b41ed.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.9c28a311c25b4487945dd20ccdcf681a.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.123548cbf3e048cdb946e246fef0c054.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.02770909bc824f8e849035bd28eea4ff.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.4f63f3d9207b46ea806d3a21b3f39c85.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.72d51b0816174ec5b08a8a43044ec841.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.6b73e402fd1b490ebfa8aa057403ab73.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.dc608a352c224426bfd64d9aa90c11ce.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.181be20a971d4979bf863caf22faa2df.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.90145ce7ff224c4f9c211f7e1cb3ce49.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.0531379c1c5f4266b74d4ff91dd051fb.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.c1a73e9c374543dcb93ee902cc2c41ac.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.409aa888b2024094999f080def9035de.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.c0959e99c0f04ee2bf3bc2a2ddc1146a.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.7e08a5a611d74789b3610f98dfbc718f.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.a31278c718424bebbd3f24adec10567a.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.e4ab7b596b3d47adacbf693a76b6de95.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.240d36a08d0e4abda99ce2a7a87ff1b1.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.7af983243ae04153a2bcdfb296065fe3.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.789db252453d4f6da140274ac5cf9f74.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.9afa25b02613404abf50680a9d3ab7bf.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.f4eb5cf4718a41e096271f19a2e9178e.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.6afbc32a0d19488191e29968ee21e517.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.3330c8ba667545ecb06d53e74fac54e7.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.67872a2c66a146708e067c551b6ca78f.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.01921d5c13244ecfb6bc8c4b8b24403c.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.6c74c7476d2f48c79c9aa181387f2c40.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/226333724.TTAB02.1/nsis/696016-TTAB02.1/161023121520854/.../PDFConverterHQ.f3b23f968a6e4cdcb5c4b575b9116b15.exe

Latest 30 of 2,098 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to 74.113.235.138.dub.iaccap.com  (74.113.235.138:443)

TCP (HTTP SSL):
Connects to 74.113.233.180.df.iaccap.com  (74.113.233.180:443)

TCP (HTTP):

TCP (HTTP SSL):
Connects to 74.113.237.180.lv.iaccap.com  (74.113.237.180:443)

TCP (HTTP SSL):
Connects to a104-103-114-70.deploy.static.akamaitechnologies.com  (104.103.114.70:443)

TCP (HTTP):
Connects to 74.113.233.192.df.iaccap.com  (74.113.233.192:80)

TCP (HTTP SSL):
Connects to a104-127-35-32.deploy.static.akamaitechnologies.com  (104.127.35.32:443)

TCP (HTTP SSL):
Connects to a23-209-176-56.deploy.static.akamaitechnologies.com  (23.209.176.56:443)

TCP (HTTP):
Connects to www.minhaoi.com.br  (200.223.247.114:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP SSL):
Connects to a23-52-235-192.deploy.static.akamaitechnologies.com  (23.52.235.192:443)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP SSL):
Connects to a23-79-203-232.deploy.static.akamaitechnologies.com  (23.79.203.232:443)