| URL: | http://ia903108.us.archive.org/25/items/msi-pro-with-b-64_20251111_1931/MSI_PRO_with_b64.png |
| Full analysis: | https://app.any.run/tasks/6363e87d-6a84-4200-800f-367372ce42ff |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | November 14, 2025, 07:52:02 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 53B59A7D2783266FC28A379E1C7A6962 |
| SHA1: | 7F06D66C72173583598D86DEA6110FC71924D9BF |
| SHA256: | 21F849DF872A5FF70FFC9C3C884722953D2F5A04072B93D8310A4A222E4AEBE8 |
| SSDEEP: | 3:N1KX1VW7zXJXQ2GMoa9AmFTKrbHSQYRLV2:CFVWXXZQta9A3SDRh2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 404 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://ia903108.us.archive.org/25/items/msi-pro-with-b-64_20251111_1931/MSI_PRO_with_b64.png | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 3392 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3360 -prefsLen 31065 -prefMapHandle 3364 -prefMapSize 273045 -jsInitHandle 3368 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3376 -initialChannelId {5d6d26af-869b-44c0-b283-c33e241d5a92} -parentPid 404 -crashReporter "\\.\pipe\gecko-crash-server-pipe.404" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 4048 | "C:\Program Files\Mozilla Firefox\firefox.exe" "http://ia903108.us.archive.org/25/items/msi-pro-with-b-64_20251111_1931/MSI_PRO_with_b64.png" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 5168 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6128 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 1932 -prefsLen 36580 -prefMapHandle 1940 -prefMapSize 273045 -ipcHandle 1892 -initialChannelId {6e870cd2-c54b-4405-afc1-fe107a9224ed} -parentPid 404 -crashReporter "\\.\pipe\gecko-crash-server-pipe.404" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 6988 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 2152 -prefsLen 36580 -prefMapHandle 2156 -prefMapSize 273045 -ipcHandle 2164 -initialChannelId {49fc5996-9a70-4f1f-852d-4663057f160d} -parentPid 404 -crashReporter "\\.\pipe\gecko-crash-server-pipe.404" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 7204 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3492 -prefsLen 37056 -prefMapHandle 3496 -prefMapSize 273045 -ipcHandle 3504 -initialChannelId {c2852745-3a7d-4c58-bcb9-dbaa1120232a} -parentPid 404 -crashReporter "\\.\pipe\gecko-crash-server-pipe.404" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 7404 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4028 -prefsLen 45014 -prefMapHandle 4032 -prefMapSize 273045 -jsInitHandle 4036 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4044 -initialChannelId {bf480ae1-9125-43ba-bb2a-a2892bef79ea} -parentPid 404 -crashReporter "\\.\pipe\gecko-crash-server-pipe.404" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 7572 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4596 -prefsLen 45116 -prefMapHandle 4540 -prefMapSize 273045 -ipcHandle 4628 -initialChannelId {06f6289f-e48e-4037-8894-570db7f677ed} -parentPid 404 -crashReporter "\\.\pipe\gecko-crash-server-pipe.404" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 7684 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4776 -prefsLen 39120 -prefMapHandle 4756 -prefMapSize 273045 -jsInitHandle 4784 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4852 -initialChannelId {2ee50898-b04b-4b43-b8f1-112a1d80cab5} -parentPid 404 -crashReporter "\\.\pipe\gecko-crash-server-pipe.404" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 404 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 404 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:B30329D7D2CF4258C22F500CBEA218FF | SHA256:C5E20431B116E1DABD383C6855A36E6DAF13E1CC125B83D59EF68B4BCEFB02E6 | |||
| 404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:5A4C9DDE73CF0A955F39631A11992A1F | SHA256:CF94D4F8843906A9ED6E827E2BCC444A81492EF54C4047D3ABF929DAD7B615F8 | |||
| 404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.bin | binary | |
MD5:A130722A5E9C25C6BDEC942CF9315EFD | SHA256:93064B6C78E52E1E2B4CC281236B71D1F49CA6250DDE882CEF00AF5D116BF693 | |||
| 404 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\activity-stream.contile.json.tmp | binary | |
MD5:9427F70ECC3BC8646065CFF54C58CBC8 | SHA256:B1B80E67905638014326F0E85E9D783FC6044D43552042B1412C637311C2197A | |||
| 404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.js | text | |
MD5:192E0F4992C5799DE792ADF2A1CCEF5B | SHA256:B6747A64BCF303D8484C7245B5B1521C460D8AE07517CE30A6DDED2A369D9B89 | |||
| 404 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
404 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
404 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
404 | firefox.exe | POST | 200 | 216.58.212.131:80 | http://o.pki.goog/s/wr3/25s | unknown | — | — | whitelisted |
404 | firefox.exe | POST | 200 | 216.58.212.131:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
404 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
404 | firefox.exe | POST | 200 | 216.58.212.131:80 | http://o.pki.goog/s/wr3/prs | unknown | — | — | whitelisted |
404 | firefox.exe | POST | 200 | 216.58.212.131:80 | http://o.pki.goog/s/wr3/prs | unknown | — | — | whitelisted |
404 | firefox.exe | POST | 200 | 216.58.212.131:80 | http://o.pki.goog/s/wr3/prs | unknown | — | — | whitelisted |
2456 | svchost.exe | GET | 200 | 23.63.118.230:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5268 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.3.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3032 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5596 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3236 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
404 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
404 | firefox.exe | 207.241.232.148:443 | ia903108.us.archive.org | INTERNET-ARCHIVE | US | unknown |
404 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
404 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
404 | firefox.exe | 151.101.193.91:443 | firefox.settings.services.mozilla.com | FASTLY | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
content-signature-2.cdn.mozilla.net |
| whitelisted |
content-signature-chains.prod.autograph.services.mozaws.net |
| whitelisted |
ia903108.us.archive.org |
| unknown |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
mc.prod.ads.prod.webservices.mozgcp.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | A Network Trojan was detected | PAYLOAD [ANY.RUN] Base64 encoded PE EXE file inside JPEG image |
— | — | A Network Trojan was detected | ET ATTACK_RESPONSE ReverseLoader Base64 Encoded Executable In Image M2 |
— | — | A Network Trojan was detected | ET ATTACK_RESPONSE ReverseLoader Base64 Encoded Executable In Image M1 |
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |