| URL: | http://cdn.download.comodo.com/browser/release/dragon/dragonsetup.exe |
| Full analysis: | https://app.any.run/tasks/989a1000-4cf1-4f8a-8c23-de98cd79a58e |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | April 10, 2019, 11:55:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 8C5ECAF4D1F2FAB0DB0B68D0CF1548D8 |
| SHA1: | 317B48572ED46958F16DBBCCAD6B53234C60DBAF |
| SHA256: | 170771582E16CBAE7B7FAB01A918B7832E2CB6C2996B1A67DB2A143C5EC50AF6 |
| SSDEEP: | 3:N1KdBLA4JKWKDIGBJAEqx1AvA:CX7JlKJA3xeA |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 876 | "C:\Program Files\Comodo\Dragon\dragon_updater.exe" install -1 | C:\Program Files\Comodo\Dragon\dragon_updater.exe | — | dragonsetup.exe | |||||||||||
User: admin Company: Comodo Integrity Level: HIGH Description: Comodo Dragon Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 908 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\worldwidereturn.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 1152 | "C:\Program Files\Comodo\Dragon\dragon.exe" --type=utility --field-trial-handle=164,9647016568613755179,11295484952087283155,131072 --lang=en-US --service-sandbox-type=utility --utility-allowed-dir="C:\Users\admin\AppData\Local\Temp\scoped_dir2876_31248" --service-request-channel-token=9D884CE8539CC36709D37DF6D7B26A30 --mojo-platform-channel-handle=2696 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Comodo\Dragon\dragon.exe | — | dragon.exe | |||||||||||
User: admin Company: Comodo Integrity Level: LOW Description: Comodo Dragon Exit code: 0 Version: 65.0.3325.146 Modules
| |||||||||||||||
| 1216 | "C:\Users\admin\Downloads\dragonsetup.exe" | C:\Users\admin\Downloads\dragonsetup.exe | firefox.exe | ||||||||||||
User: admin Company: Comodo Integrity Level: MEDIUM Description: Comodo Dragon Exit code: 0 Version: 65.0.3325.146 Modules
| |||||||||||||||
| 1220 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2624.20.1411464658\1307976168" -childID 3 -isForBrowser -prefsHandle 3540 -prefMapHandle 3284 -prefsLen 5824 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2624 "\\.\pipe\gecko-crash-server-pipe.2624" 3536 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 65.0.2 Modules
| |||||||||||||||
| 1336 | "C:\Program Files\Comodo\Dragon\dragon.exe" --type=utility --field-trial-handle=164,9647016568613755179,11295484952087283155,131072 --lang=en-US --service-sandbox-type=utility --utility-allowed-dir="C:\Users\admin\AppData\Local\Temp\scoped_dir2876_20764" --service-request-channel-token=834F55757F5803BB8783B01B276F5AFF --mojo-platform-channel-handle=2336 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Comodo\Dragon\dragon.exe | — | dragon.exe | |||||||||||
User: admin Company: Comodo Integrity Level: LOW Description: Comodo Dragon Exit code: 0 Version: 65.0.3325.146 Modules
| |||||||||||||||
| 1668 | "C:\Program Files\Comodo\Dragon\dragon.exe" --type=gpu-process --field-trial-handle=1164,3968413517685133683,15476904992521218828,131072 --gpu-preferences=KAAAAAAAAAAABwAAAQAAAAAAAAAAAGAAAQAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --gpu-vendor-id=0x1234 --gpu-device-id=0x1111 --gpu-driver-vendor=Microsoft --gpu-driver-version=6.1.7600.16385 --gpu-driver-date=6-21-2006 --service-request-channel-token=B4CB836588C9C205304F1C2DDD9CA442 --mojo-platform-channel-handle=1196 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Comodo\Dragon\dragon.exe | — | dragon.exe | |||||||||||
User: admin Company: Comodo Integrity Level: LOW Description: Comodo Dragon Exit code: 0 Version: 65.0.3325.146 Modules
| |||||||||||||||
| 1784 | "C:\Program Files\Comodo\Dragon\dragon.exe" --type=renderer --field-trial-handle=164,9647016568613755179,11295484952087283155,131072 --service-pipe-token=F6AC4D164C910D9357F9D07579960E66 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=F6AC4D164C910D9357F9D07579960E66 --renderer-client-id=16 --mojo-platform-channel-handle=2220 /prefetch:1 | C:\Program Files\Comodo\Dragon\dragon.exe | — | dragon.exe | |||||||||||
User: admin Company: Comodo Integrity Level: LOW Description: Comodo Dragon Exit code: 0 Version: 65.0.3325.146 Modules
| |||||||||||||||
| 1928 | "C:\Program Files\Comodo\Dragon\dragon_updater.exe" | C:\Program Files\Comodo\Dragon\dragon_updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Comodo Integrity Level: SYSTEM Description: Comodo Dragon Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2308 | "C:\Program Files\Comodo\Dragon\dragon.exe" --type=gpu-process --field-trial-handle=164,9647016568613755179,11295484952087283155,131072 --gpu-preferences=KAAAAAAAAAAABwAAAQAAAAAAAAAAAGAAAQAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --gpu-vendor-id=0x1234 --gpu-device-id=0x1111 --gpu-driver-vendor=Microsoft --gpu-driver-version=6.1.7600.16385 --gpu-driver-date=6-21-2006 --service-request-channel-token=1940EF2F273A389A5423731B4E5BB519 --mojo-platform-channel-handle=1232 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Comodo\Dragon\dragon.exe | — | dragon.exe | |||||||||||
User: admin Company: Comodo Integrity Level: LOW Description: Comodo Dragon Exit code: 4 Version: 65.0.3325.146 Modules
| |||||||||||||||
| (PID) Process: | (2624) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2624) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2624) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2624) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2624) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (1216) dragonsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1216) dragonsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3928) dragonsetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Comodo\Dragon |
| Operation: | write | Name: | PAAR_MACHINE_ID |
Value: E1E436CFA7405B264AE951FB8D82D5CC | |||
| (PID) Process: | (908) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | 5*" |
Value: 352A22008C030000010000000000000000000000 | |||
| (PID) Process: | (908) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2624 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 2624 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\trash29464 | — | |
MD5:— | SHA256:— | |||
| 2624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
| 2624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
| 2624 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.bin | binary | |
MD5:— | SHA256:— | |||
| 2624 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 2624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:— | SHA256:— | |||
| 2624 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B3813A896493E276EDCD2794D945AF7EC5B7C790 | der | |
MD5:— | SHA256:— | |||
| 2624 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstore | binary | |
MD5:— | SHA256:— | |||
| 2624 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\doomed\19288 | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3928 | dragonsetup.exe | GET | 200 | 199.66.201.26:80 | http://licensing.security.comodo.com/info?comp=E1E436CFA7405B264AE951FB8D82D5CC&product=19&affiliate=25050030001&version=65.0.3325.146&activitytype=1&key=&email=&oslang=1033&applang=1033&osid=1&osplat=32&fback= | US | — | — | whitelisted |
1928 | dragon_updater.exe | GET | — | 104.37.182.3:80 | http://cdn.download.comodo.com/browser/release/dragon/x86/dragonsetup.exe | US | — | — | whitelisted |
2624 | firefox.exe | GET | 200 | 104.37.182.3:80 | http://cdn.download.comodo.com/browser/release/dragon/dragonsetup.exe | US | executable | 74.6 Mb | whitelisted |
2624 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3928 | dragonsetup.exe | GET | 200 | 104.37.182.3:80 | http://cdn.download.comodo.com/browsers/offers/config.ini | US | text | 19 b | whitelisted |
1928 | dragon_updater.exe | GET | 200 | 104.37.182.3:80 | http://cdn.download.comodo.com/browser/release/dragon/x86/dragon.inf | US | xml | 154 b | whitelisted |
2624 | firefox.exe | POST | 200 | 172.217.23.131:80 | http://ocsp.pki.goog/GTSGIAG3 | US | der | 471 b | whitelisted |
2624 | firefox.exe | POST | 200 | 172.217.23.131:80 | http://ocsp.pki.goog/GTSGIAG3 | US | der | 471 b | whitelisted |
1928 | dragon_updater.exe | GET | 200 | 104.37.182.3:80 | http://cdn.download.comodo.com/browser/release/dragon/x86/dragon.inf | US | xml | 154 b | whitelisted |
2624 | firefox.exe | POST | 200 | 172.217.18.163:80 | http://ocsp.pki.goog/GTSGIAG3 | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2624 | firefox.exe | 23.62.98.16:80 | detectportal.firefox.com | Akamai International B.V. | NL | whitelisted |
2624 | firefox.exe | 104.37.182.3:80 | cdn.download.comodo.com | ISPrime, Inc. | US | suspicious |
2624 | firefox.exe | 52.88.150.81:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
2624 | firefox.exe | 13.32.159.2:443 | snippets.cdn.mozilla.net | Amazon.com, Inc. | US | unknown |
2624 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2624 | firefox.exe | 172.217.18.10:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
2624 | firefox.exe | 172.217.18.163:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
2624 | firefox.exe | 52.26.235.130:443 | shavar.services.mozilla.com | Amazon.com, Inc. | US | unknown |
2624 | firefox.exe | 13.32.158.115:443 | tracking-protection.cdn.mozilla.net | Amazon.com, Inc. | US | unknown |
2624 | firefox.exe | 13.32.158.226:443 | firefox.settings.services.mozilla.com | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
cdn.download.comodo.com |
| whitelisted |
a1089.dscd.akamai.net |
| whitelisted |
cdn.download.comodo.com.i.belugacdn.com |
| suspicious |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
tiles.services.mozilla.com |
| whitelisted |
tiles.r53-2.services.mozilla.com |
| whitelisted |
snippets.cdn.mozilla.net |
| whitelisted |
drcwo519tnci7.cloudfront.net |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
2624 | firefox.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1928 | dragon_updater.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1928 | dragon_updater.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
2624 | firefox.exe | Generic Protocol Command Decode | SURICATA STREAM excessive retransmissions |
2624 | firefox.exe | Generic Protocol Command Decode | SURICATA STREAM reassembly overlap with different data |
2876 | dragon.exe | Potential Corporate Privacy Violation | ET POLICY Known External IP Lookup Service Domain in SNI |
Process | Message |
|---|---|
dragonsetup.exe | -------------------------------Previous Chromodo Shortcut does not exist ----------------------------- |
dragonsetup.exe | -------------------------------Previous Chromodo Shortcut does not exist ----------------------------- |
dragonsetup.exe | [Dragon] CSecureDNSPluginApp::InitializeSecureDNS |
dragon.exe | in DragonUpdateManager::CreateUpdater4.1 |
dragon_updater.exe | http://download.comodo.com/browser/release/dragon/x86/dragon.inf |
dragon_updater.exe | C:\Windows\temp\dragon_version.inf |
dragon_updater.exe |
Download Function Exit
|
dragon_updater.exe | http://download.comodo.com/browser/release/dragon/x86/dragonsetup.exe |
dragon_updater.exe | C:\Windows\temp\dragon_setup.exe |