| URL: | https://downloads.sourceforge.net/project/seb/seb/SEB_3.7.1/SEB_3.7.1.704_SetupBundle.exe?ts=gAAAAABmeDHFexWIJpzfGlIn47oeJTmLs1C9p3yw1fTGf4e397JEpxx7eKkrIoAFVEyjTwGjXH0WcLdCGssspiZLBp6qupQXmA%3D%3D&r=https%3A%2F%2Fsourceforge.net%2Fprojects%2Fseb%2Ffiles%2Fseb%2FSEB_3.7.1%2FSEB_3.7.1.704_SetupBundle.exe%2Fdownload |
| Full analysis: | https://app.any.run/tasks/1e5b6cc5-ab3b-4cc3-a2e6-5ae829d9cd15 |
| Verdict: | Malicious activity |
| Analysis date: | June 23, 2024, 14:33:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | BED884C9C7619ECED2D366301A125B32 |
| SHA1: | 2C5FEF94111970FC6CD8DF5F7DF2BD8BBED8B557 |
| SHA256: | 0FC29A09829EF43C8BE41671E75B7C32B1C6625D57392BC4A648C42825CD9787 |
| SSDEEP: | 6:2SBnCtTNOIR61sJOdQ6Gd7pwVWh7d3zC2nILL5yqGLRO2z:2gaTz81sL9FGWxd35I4vv |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1420 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.5.740444807\367732106" -childID 4 -isForBrowser -prefsHandle 3796 -prefMapHandle 3800 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {202a958b-ab31-4b2e-ad54-9bccab428a33} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 3900 210b1110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1616 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.3.855659882\622768334" -childID 2 -isForBrowser -prefsHandle 2800 -prefMapHandle 2796 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {43a60d83-b7ba-47f7-87f6-937795b6d3c8} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 2812 1eff6c90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1648 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.6.935866821\684149160" -childID 5 -isForBrowser -prefsHandle 3880 -prefMapHandle 3884 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {701c11e6-0fc7-4044-8cec-9453a757d9e9} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 3868 210b1280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1796 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.8.214382933\1623097919" -childID 7 -isForBrowser -prefsHandle 8296 -prefMapHandle 8300 -prefsLen 29435 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e54daedd-97a2-47ae-9ddc-288d0ea49f08} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 8288 232d8c90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1828 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.11.829215020\1563861332" -childID 10 -isForBrowser -prefsHandle 7644 -prefMapHandle 7648 -prefsLen 31203 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0d5f7cfd-79c7-4fd5-a8e2-b2f0da1a96ff} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 7632 17db03f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1992 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.9.152879594\1991948024" -childID 8 -isForBrowser -prefsHandle 2724 -prefMapHandle 3008 -prefsLen 31122 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {9f4a9ab5-87c2-403f-9d92-99dfb85a5a3a} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 8096 23d52f70 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 2100 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.1.810501931\1866613619" -parentBuildID 20230710165010 -prefsHandle 1408 -prefMapHandle 1404 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7856cbfe-0353-4b4f-a7ca-416f3a938359} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 1420 1651bf40 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 2112 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.10.561096364\752061830" -childID 9 -isForBrowser -prefsHandle 7888 -prefMapHandle 7892 -prefsLen 31122 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {5016b643-9cae-4927-90a8-a25ae79ed512} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 7796 24fbcb20 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 2124 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.7.1463087142\1747058192" -childID 6 -isForBrowser -prefsHandle 3852 -prefMapHandle 3856 -prefsLen 34370 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {41eb794a-8d4b-4a24-8c4c-1395ba26d1c6} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 3584 210b13f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 2180 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.4.1859259973\1529747444" -childID 3 -isForBrowser -prefsHandle 3540 -prefMapHandle 3584 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b9aae4ab-d4c9-40c2-9d96-436aaa51e1a3} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 3512 1f236280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (3416) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 9893704400000000 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: DAF4714400000000 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB |
| Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3700 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:A4C0253717519EB0B07D5D8DD14F5D02 | SHA256:115B88AA451EA9D5CD010C60DB4B97759E55ECE806CF6C4EBA737C6290C0D044 | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:04BADC0A17F546BBD91CC2404D2776D9 | SHA256:54CD83D3031D15EA1F5B1C5D73416C0B2F9151F93E130DD525DDA488A8EB9110 | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.tmp | dbf | |
MD5:7D3D11283370585B060D50A12715851A | SHA256:86BFF840E1BEC67B7C91F97F4D37E3A638C5FDC7B56AAE210B01745F292347B9 | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db | binary | |
MD5:DA445D3981DDA1C987369216BE8CE5C1 | SHA256:FA1ECDE1772F910DAC4B4E98810CCAECD9B72E14E8B23EBCC0E47A6A2A4DAA66 | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.bin | dbf | |
MD5:7D3D11283370585B060D50A12715851A | SHA256:86BFF840E1BEC67B7C91F97F4D37E3A638C5FDC7B56AAE210B01745F292347B9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | unknown |
3700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 95.101.54.201:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 142.250.185.131:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
3700 | firefox.exe | POST | — | 142.250.185.131:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1372 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3700 | firefox.exe | 204.68.111.105:443 | downloads.sourceforge.net | Cloudflare London, LLC | US | unknown |
3700 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
3700 | firefox.exe | 34.117.188.166:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
3700 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
3700 | firefox.exe | 142.250.185.138:443 | safebrowsing.googleapis.com | — | — | whitelisted |
3700 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
downloads.sourceforge.net |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
prod.ads.prod.webservices.mozgcp.net |
| unknown |
firefox.settings.services.mozilla.com |
| whitelisted |
safebrowsing.googleapis.com |
| whitelisted |