| URL: | https://www.nvidia.com/en-us/software/nvidia-app/ |
| Full analysis: | https://app.any.run/tasks/4312ca44-b291-42ae-b97e-d81f934657e3 |
| Verdict: | Malicious activity |
| Analysis date: | November 15, 2024, 18:16:03 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MD5: | 2F4C4CEF6DEEE010E318D6CBCF6AF44D |
| SHA1: | 35CC4C36E265A5A6BD80C3F92604200B0AFDC260 |
| SHA256: | 02F4604B81F7BE4C4F0188882C83C4CC05790B3556288A11956910ED2AF8A79A |
| SSDEEP: | 3:N8DSLnM6EZ3sAuMzVKn:2OLpEZ3Bon |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 512 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2192 -parentBuildID 20240213221259 -prefsHandle 2184 -prefMapHandle 2180 -prefsLen 30705 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {968fc7e7-bc14-4594-a12f-1ec46c899bd5} 6288 "\\.\pipe\gecko-crash-server-pipe.6288" 2804bc81b10 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 696 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7264 -childID 9 -isForBrowser -prefsHandle 5720 -prefMapHandle 6868 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1120 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e8e36836-d84a-499f-86f3-7cca02ae7776} 6288 "\\.\pipe\gecko-crash-server-pipe.6288" 2805e665850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 1332 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7516 -childID 10 -isForBrowser -prefsHandle 6816 -prefMapHandle 7200 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1120 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7fac7f16-85f0-49dd-9e6c-e9830cc9060c} 6288 "\\.\pipe\gecko-crash-server-pipe.6288" 2805e665f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 1712 | "C:\Users\admin\Downloads\NVIDIA_app_v11.0.1.163.exe" | C:\Users\admin\Downloads\NVIDIA_app_v11.0.1.163.exe | — | explorer.exe | |||||||||||
User: admin Company: NVIDIA Corporation Integrity Level: MEDIUM Description: NVIDIA app Exit code: 3221226540 Version: 1.0.14.0 Modules
| |||||||||||||||
| 5168 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5332 -childID 8 -isForBrowser -prefsHandle 7188 -prefMapHandle 7048 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1120 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {bbfbade1-64f5-46c6-ab0d-5377e8eefb76} 6288 "\\.\pipe\gecko-crash-server-pipe.6288" 28063197150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 6028 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4432 -childID 2 -isForBrowser -prefsHandle 4400 -prefMapHandle 2448 -prefsLen 36339 -prefMapSize 244343 -jsInitHandle 1120 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4587b860-0c3b-4165-b1f0-0e245c04d8f2} 6288 "\\.\pipe\gecko-crash-server-pipe.6288" 2805d8c7690 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 6224 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://www.nvidia.com/en-us/software/nvidia-app/" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 6288 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://www.nvidia.com/en-us/software/nvidia-app/ | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 6560 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5664 -childID 11 -isForBrowser -prefsHandle 7384 -prefMapHandle 7684 -prefsLen 31242 -prefMapSize 244343 -jsInitHandle 1120 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b19836ff-c3b1-4be3-8e3e-62f051a60107} 6288 "\\.\pipe\gecko-crash-server-pipe.6288" 28063197310 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 6564 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1808 -parentBuildID 20240213221259 -prefsHandle 1724 -prefMapHandle 1708 -prefsLen 30705 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d95335c9-05df-4075-b82d-fe0b7690b85e} 6288 "\\.\pipe\gecko-crash-server-pipe.6288" 28057ac4f10 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (6288) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (8756) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Logging\Definitions\LogChannels\SimpleChannel |
| Operation: | write | Name: | LogFilter |
Value: PassFilter | |||
| (PID) Process: | (8756) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Logging\Definitions\LogChannels\SimpleChannel |
| Operation: | write | Name: | LogPrinter |
Value: SimplePrinter | |||
| (PID) Process: | (8756) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Logging\Definitions\LogChannels\SimpleChannel\LogManagers |
| Operation: | write | Name: | DebugOut |
Value: 00000000 | |||
| (PID) Process: | (8756) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Logging\Definitions\LogChannels\SimpleChannel\LogManagers |
| Operation: | write | Name: | FileOut |
Value: 00000000 | |||
| (PID) Process: | (8756) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Logging\Definitions\LogFilters\PassFilter |
| Operation: | write | Name: | DefaultLogLevel |
Value: 6 | |||
| (PID) Process: | (8756) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Logging\Definitions\LogManagers\DebugOut |
| Operation: | write | Name: | ClassName |
Value: DebugOutputLogManager | |||
| (PID) Process: | (8756) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Logging\Definitions\LogManagers\FileOut |
| Operation: | write | Name: | ClassName |
Value: FileLogManager | |||
| (PID) Process: | (8756) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Logging\Definitions\LogManagers\FileOut |
| Operation: | write | Name: | PathPrefix |
Value: C:\ProgramData\\NVIDIA Corporation\\NVIDIA app\\Installer\\Logs\LOG | |||
| (PID) Process: | (8756) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Logging\Definitions\LogManagers\FileOut |
| Operation: | write | Name: | AppendProcessNameToPathPrefix |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6288 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 6288 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:C09FF302D57C404B61E6A89B0B9F36E7 | SHA256:6A5B4F82595799346D0E501FE6CC8629E0FD6ED27B74D0E6CB5073DDB2E3C40B | |||
| 6288 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6288 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 6288 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6288 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6288 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:8BD997F90ECBED0083C0F3B144B2F721 | SHA256:25EC68792A8D0944AEC3A5C97A589369B3CEF2F6F5F2721E09A1570C270E8255 | |||
| 6288 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.js | text | |
MD5:8BD997F90ECBED0083C0F3B144B2F721 | SHA256:25EC68792A8D0944AEC3A5C97A589369B3CEF2F6F5F2721E09A1570C270E8255 | |||
| 6288 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6288 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.53.41.96:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6288 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
6288 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6288 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/wr2 | unknown | — | — | whitelisted |
6288 | firefox.exe | POST | 200 | 184.24.77.58:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
6288 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/s/wr3/yvU | unknown | — | — | whitelisted |
6288 | firefox.exe | POST | 200 | 184.24.77.58:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
6288 | firefox.exe | POST | 200 | 184.24.77.58:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
6288 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/wr2 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6944 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.53.41.96:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6288 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
6288 | firefox.exe | 23.36.162.222:443 | www.nvidia.com | Akamai International B.V. | DE | suspicious |
6288 | firefox.exe | 34.117.188.166:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
www.nvidia.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
e33907.a.akamaiedge.net |
| unknown |
contile.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
Process | Message |
|---|---|
setup.exe | 0.663 | INFO: [system] 487@Nvidia::Logging::Logger::Logger : 2024-Nov-15 18:17:27 : Logging init OK. Using configuration from HKLM for DefaultProcess, for the setup.exe.
|
setup.exe | 0.665 | INFO: [NVI2.Config.ManifestParser] 2511@CConfigManifestParser::Parse : Entering Checkpoint: Loading Configuration Manifest.
|
setup.exe | 0.664 | INFO: [NVI2.NVInstaller] 363@CNVInstaller::HandleDeferredCleanupInstance : No deferred cleanup instance found running.
|
setup.exe | 0.684 | INFO: [NVI2.ConfigConstraintParser] 25@CNVConfigConstraintsParser::Parse : Entering Checkpoint: Loading configuration file C:\NVIDIA\NVAPP2\setup.CFG.
|
setup.exe | 0.683 | INFO: [NVI2.Config.ManifestParser] 2511@CConfigManifestParser::Parse : Exiting Checkpoint: Loading Configuration Manifest ( 32 ms ).
|
setup.exe | 0.693 | INFO: [NVI2.ConfigConstraintParser] 25@CNVConfigConstraintsParser::Parse : Entering Checkpoint: Loading configuration file C:\NVIDIA\NVAPP2\setup.CFG.
|
setup.exe | 0.693 | INFO: [NVI2.ConfigConstraintParser] 25@CNVConfigConstraintsParser::Parse : Exiting Checkpoint: Loading configuration file C:\NVIDIA\NVAPP2\setup.CFG ( 0 ms ).
|
setup.exe | 0.703 | INFO: [NVI2.CEngineCache] 2123@CEngineCache::CachePerManifest : Entering Checkpoint: Caching "installer".
|
setup.exe | 0.705 | INFO: [NVI2.CEngineCache] 2033@CEngineCache::CacheManifestFiles : Manifest dump ".\NvApp\EULA.txt".
|
setup.exe | 0.701 | INFO: [NVI2.ConfigConstraintParser] 25@CNVConfigConstraintsParser::Parse : Exiting Checkpoint: Loading configuration file C:\NVIDIA\NVAPP2\setup.CFG ( 15 ms ).
|