analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://onedrive.live.com/?authkey=%21AJ%2D0Z2D24dEZ5gU&cid=B5CD7FBF659DA24A&id=B5CD7FBF659DA24A%21793&parId=B5CD7FBF659DA24A%21426&o=OneUp

Full analysis: https://app.any.run/tasks/bb994412-4f7d-4e42-9992-cf883fc9d2ad
Verdict: Malicious activity
Analysis date: June 12, 2019, 08:51:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

AFDCF801C341B8FAC2E303D44C90244A

SHA1:

7A647569634DD2CC737EE512CDA6F23EAEAE13D5

SHA256:

2FA6A7D095964848673B97221DDF4C78B22238D3A0BF54E9EABAD7D0FD67945E

SSDEEP:

3:N8Ck3CTZxAXNyVxQYzDGALmUnQMLcEVT0hpIfhwV:2CkSTfAXoEYvVnQ4cdz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the program directory

      • firefox.exe (PID: 3288)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 3288)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • firefox.exe (PID: 3288)
    • Application launched itself

      • firefox.exe (PID: 3288)
    • Reads CPU info

      • firefox.exe (PID: 3288)
    • Reads settings of System Certificates

      • firefox.exe (PID: 3288)
    • Creates files in the user directory

      • firefox.exe (PID: 3288)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
6
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe firefox.exe

Process information

PID
CMD
Path
Indicators
Parent process
3288"C:\Program Files\Mozilla Firefox\firefox.exe" https://onedrive.live.com/?authkey=%21AJ%2D0Z2D24dEZ5gU&cid=B5CD7FBF659DA24A&id=B5CD7FBF659DA24A%21793&parId=B5CD7FBF659DA24A%21426&o=OneUpC:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
65.0.2
2728"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3288.0.127679456\1524193629" -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - "C:\Users\admin\AppData\LocalLow\Mozilla\Temp-{ce348e4c-7d33-445e-89f9-60108c51bcaf}" 3288 "\\.\pipe\gecko-crash-server-pipe.3288" 1128 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
65.0.2
1204"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3288.6.1960698376\707033108" -childID 1 -isForBrowser -prefsHandle 1564 -prefMapHandle 796 -prefsLen 1 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3288 "\\.\pipe\gecko-crash-server-pipe.3288" 1716 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
65.0.2
2644"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3288.13.1868498957\860061705" -childID 2 -isForBrowser -prefsHandle 2528 -prefMapHandle 2532 -prefsLen 216 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3288 "\\.\pipe\gecko-crash-server-pipe.3288" 2544 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
65.0.2
2692"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3288.20.1788877175\2064451172" -childID 3 -isForBrowser -prefsHandle 3000 -prefMapHandle 3480 -prefsLen 5824 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3288 "\\.\pipe\gecko-crash-server-pipe.3288" 3496 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
65.0.2
3460"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3288.27.1279518250\1318520619" -childID 4 -isForBrowser -prefsHandle 3060 -prefMapHandle 1956 -prefsLen 6135 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3288 "\\.\pipe\gecko-crash-server-pipe.3288" 2072 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
65.0.2
Total events
778
Read events
766
Write events
12
Delete events
0

Modification events

(PID) Process:(3288) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3288) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3288) firefox.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
1
Suspicious files
343
Text files
136
Unknown types
92

Dropped files

PID
Process
Filename
Type
3288firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
3288firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
MD5:
SHA256:
3288firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\trash23829
MD5:
SHA256:
3288firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
MD5:
SHA256:
3288firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
MD5:
SHA256:
3288firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal
MD5:
SHA256:
3288firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
MD5:
SHA256:
3288firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.binbinary
MD5:82F61C08D68502377826CA7EA054CEA7
SHA256:85801BCE5D7CE3A2ABC14E3208151AC9D324A6EA82FB2ADA1D10BAA8EF58E7DF
3288firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E5EF019735FC8546CD1A3499781800354D165609der
MD5:07B9A26EDB9658CC742C5EE1D5C1CC71
SHA256:35CED96A0E9A56F512120C9D9BE3CAA674F4A736B9F904D5B415ACAEC44D96B9
3288firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.dbsqlite
MD5:F2871B4F0D5B3823908F33FA9BE68B7E
SHA256:1B833757AFFB2AE47B100139D18BE31D4C2F00FE0FB5F7F0E8D9A5C1C6D5227F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
123
DNS requests
201
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3288
firefox.exe
POST
200
172.217.22.35:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3288
firefox.exe
POST
200
172.217.22.35:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3288
firefox.exe
POST
200
172.217.22.35:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3288
firefox.exe
POST
200
172.217.22.35:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3288
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3288
firefox.exe
POST
200
172.217.22.35:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3288
firefox.exe
POST
200
172.217.22.35:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3288
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3288
firefox.exe
POST
200
104.18.25.243:80
http://ocsp.msocsp.com/
US
der
1.79 Kb
whitelisted
3288
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3288
firefox.exe
2.16.186.112:80
detectportal.firefox.com
Akamai International B.V.
whitelisted
3288
firefox.exe
34.218.159.169:443
aus5.mozilla.org
Amazon.com, Inc.
US
unknown
3288
firefox.exe
2.19.34.64:443
static2.sharepointonline.com
Akamai International B.V.
whitelisted
3288
firefox.exe
52.114.132.22:443
browser.pipe.aria.microsoft.com
Microsoft Corporation
US
whitelisted
3288
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3288
firefox.exe
2.16.186.25:443
spoprod-a.akamaihd.net
Akamai International B.V.
whitelisted
3288
firefox.exe
152.199.19.160:443
az725175.vo.msecnd.net
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3288
firefox.exe
52.25.71.236:443
tiles.services.mozilla.com
Amazon.com, Inc.
US
unknown
3288
firefox.exe
40.90.136.180:443
skyapi.onedrive.live.com
Microsoft Corporation
US
whitelisted
3288
firefox.exe
52.40.28.81:443
shavar.services.mozilla.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 2.16.186.112
  • 2.16.186.50
whitelisted
aus5.mozilla.org
  • 34.218.159.169
  • 52.35.34.27
  • 52.34.120.127
  • 52.40.226.98
  • 52.34.127.169
  • 52.43.79.30
  • 35.165.116.96
  • 35.161.58.143
whitelisted
onedrive.live.com
  • 13.107.42.13
shared
l-0004.l-msedge.net
  • 13.107.42.13
whitelisted
balrog-aus5.r53-2.services.mozilla.com
  • 35.161.58.143
  • 35.165.116.96
  • 52.43.79.30
  • 52.34.127.169
  • 52.40.226.98
  • 52.34.120.127
  • 52.35.34.27
  • 34.218.159.169
whitelisted
a1089.dscd.akamai.net
  • 2.16.186.50
  • 2.16.186.112
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
cs9.wac.phicdn.net
  • 93.184.220.29
whitelisted
search.services.mozilla.com
  • 54.190.222.97
  • 52.11.30.237
  • 34.215.70.240
whitelisted
search.r53-2.services.mozilla.com
  • 34.215.70.240
  • 52.11.30.237
  • 54.190.222.97
whitelisted

Threats

No threats detected
No debug info