| URL: | https://downloads.hpanalytics.net/PROD/{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}/installer/latestversion/TAInstaller.exe.gz |
| Full analysis: | https://app.any.run/tasks/b32af133-61e6-488f-bb7a-8ab19eca5edd |
| Verdict: | Malicious activity |
| Analysis date: | August 24, 2021, 06:15:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | A6ADDE32D2534B7D5F16E948498C3976 |
| SHA1: | 2A1B8C1AE45355A9ADE9BF32D99EFEFB71665647 |
| SHA256: | 1FB084CDD4D203F0E28930191B4D996A28DE87C53B768364B5056C9AD799D70E |
| SSDEEP: | 3:N8SE4LHSRMVKciVPT7WNRDwJqOXKJfjzWEJOXLN2f:2SLSRMXA+NVwoOXsVOXL8f |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 508 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3564.0.1063424239\598472539" -parentBuildID 20210804193234 -prefsHandle 1104 -prefMapHandle 1096 -prefsLen 1 -prefMapSize 246031 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3564 "\\.\pipe\gecko-crash-server-pipe.3564" 1176 d19a378 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 2692 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3564.3.1708052845\1003087194" -childID 2 -isForBrowser -prefsHandle 2840 -prefMapHandle 1376 -prefsLen 5260 -prefMapSize 246031 -jsInit 908 285716 -parentBuildID 20210804193234 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3564 "\\.\pipe\gecko-crash-server-pipe.3564" 2860 17869a38 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 2932 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://downloads.hpanalytics.net/PROD/{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}/installer/latestversion/TAInstaller.exe.gz" | C:\Program Files\Mozilla Firefox\firefox.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 3264 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3744.40172\TAInstaller.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3744.40172\TAInstaller.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: HP Touchpoint Analytics Installer Exit code: 0 Version: 1.0.1.1491 Modules
| |||||||||||||||
| 3564 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://downloads.hpanalytics.net/PROD/{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}/installer/latestversion/TAInstaller.exe.gz | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 3620 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3744.40172\TAInstaller.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3744.40172\TAInstaller.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: HP Touchpoint Analytics Installer Exit code: 3221226540 Version: 1.0.1.1491 Modules
| |||||||||||||||
| 3696 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3564.5.1185311614\1435602543" -childID 3 -isForBrowser -prefsHandle 3432 -prefMapHandle 3428 -prefsLen 5920 -prefMapSize 246031 -jsInit 908 285716 -parentBuildID 20210804193234 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3564 "\\.\pipe\gecko-crash-server-pipe.3564" 3440 184c6b88 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 3744 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\TAInstaller.exe.gz" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3840 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3564.1.1418859405\1117898523" -childID 1 -isForBrowser -prefsHandle 1916 -prefMapHandle 1912 -prefsLen 282 -prefMapSize 246031 -jsInit 908 285716 -parentBuildID 20210804193234 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3564 "\\.\pipe\gecko-crash-server-pipe.3564" 1928 d14bb88 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 4064 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3564.7.1824307132\837860207" -childID 4 -isForBrowser -prefsHandle 3792 -prefMapHandle 3816 -prefsLen 6092 -prefMapSize 246031 -jsInit 908 285716 -parentBuildID 20210804193234 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3564 "\\.\pipe\gecko-crash-server-pipe.3564" 3832 158fa108 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| (PID) Process: | (2932) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: D0D64A5A86000000 | |||
| (PID) Process: | (3564) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: BEE24A5A86000000 | |||
| (PID) Process: | (3564) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (3564) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (3564) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (3564) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (3564) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (3564) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (3564) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|ServicesSettingsServer |
Value: https://firefox.settings.services.mozilla.com/v1 | |||
| (PID) Process: | (3564) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash |
Value: 97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3564 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 3564 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.bin | binary | |
MD5:— | SHA256:— | |||
| 3564 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:— | SHA256:— | |||
| 3564 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:— | SHA256:— | |||
| 3564 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal | — | |
MD5:— | SHA256:— | |||
| 3564 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 3564 | firefox.exe | C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\update-config.json | text | |
MD5:— | SHA256:— | |||
| 3564 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | text | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3564 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3564 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
3564 | firefox.exe | POST | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gts1o1core | US | der | 472 b | whitelisted |
3564 | firefox.exe | POST | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gts1c3 | US | der | 471 b | whitelisted |
3564 | firefox.exe | POST | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gts1o1core | US | der | 472 b | whitelisted |
3564 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3564 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3564 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | US | text | 90 b | whitelisted |
3564 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | US | text | 90 b | whitelisted |
3564 | firefox.exe | POST | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gts1c3 | US | der | 471 b | whitelisted |
3564 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | US | text | 8 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3264 | TAInstaller.exe | 65.9.71.10:443 | downloads.hpanalytics.net | AT&T Services, Inc. | US | unknown |
3564 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | — | US | whitelisted |
3564 | firefox.exe | 143.204.207.111:443 | firefox.settings.services.mozilla.com | — | US | unknown |
3564 | firefox.exe | 65.9.71.10:443 | downloads.hpanalytics.net | AT&T Services, Inc. | US | unknown |
3564 | firefox.exe | 172.217.18.106:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
3564 | firefox.exe | 13.32.22.114:443 | content-signature-2.cdn.mozilla.net | Amazon.com, Inc. | US | unknown |
3564 | firefox.exe | 142.250.185.99:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
3564 | firefox.exe | 52.40.130.105:443 | push.services.mozilla.com | Amazon.com, Inc. | US | unknown |
3564 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3564 | firefox.exe | 142.250.185.110:443 | www.youtube.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
downloads.hpanalytics.net |
| malicious |
d3qwgtv7nf9cah.cloudfront.net |
| suspicious |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
safebrowsing.googleapis.com |
| whitelisted |
content-signature-2.cdn.mozilla.net |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
— | — | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
Process | Message |
|---|---|
TAInstaller.exe | TAInstaller.exe Information: 0 : |
TAInstaller.exe | 8/24/2021 7:15:46 AM - Global TAInstaller new mutex created
|
TAInstaller.exe | TAInstaller.exe Information: 0 : |
TAInstaller.exe | 8/24/2021 7:15:47 AM - MDMKey does not exist at 32-bit location
|
TAInstaller.exe | TAInstaller.exe Information: 0 : |
TAInstaller.exe | 8/24/2021 7:15:47 AM - Init Device Policy Data updater.
|