URL:

https://www.minecraft.net/en-us/download

Full analysis: https://app.any.run/tasks/b4fa5822-42fc-486d-9245-4470ba55ffa3
Verdict: Malicious activity
Analysis date: July 18, 2021, 08:45:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

A7F56903A5D6B07D351552EE0B4C516D

SHA1:

F3E2283A5C4AA77EB74F6D720389962B45B21D2E

SHA256:

3CA624430FC285396A3E100917D1475BEA3BE5E2A4FA22C108BE3977327CE298

SSDEEP:

3:N8DSLdE10Qd4z:2OLGKQdM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • firefox.exe (PID: 2312)
      • msiexec.exe (PID: 3008)
    • Drops a file with too old compile date

      • firefox.exe (PID: 2312)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 2312)
      • msiexec.exe (PID: 3008)
    • Executed as Windows Service

      • msiexec.exe (PID: 1024)
      • vssvc.exe (PID: 2320)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3008)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3008)
    • Application launched itself

      • msiexec.exe (PID: 1024)
    • Reads Environment values

      • vssvc.exe (PID: 2320)
    • Searches for installed software

      • msiexec.exe (PID: 1024)
  • INFO

    • Checks supported languages

      • firefox.exe (PID: 2716)
      • firefox.exe (PID: 2936)
      • firefox.exe (PID: 2312)
      • firefox.exe (PID: 3048)
      • firefox.exe (PID: 1936)
      • firefox.exe (PID: 3040)
      • firefox.exe (PID: 2084)
      • firefox.exe (PID: 3976)
      • firefox.exe (PID: 1208)
      • firefox.exe (PID: 3800)
      • firefox.exe (PID: 1604)
      • msiexec.exe (PID: 3008)
      • msiexec.exe (PID: 1024)
      • vssvc.exe (PID: 2320)
      • MsiExec.exe (PID: 3668)
    • Application launched itself

      • firefox.exe (PID: 2716)
      • firefox.exe (PID: 2312)
    • Reads the computer name

      • firefox.exe (PID: 3040)
      • firefox.exe (PID: 1208)
      • firefox.exe (PID: 3048)
      • firefox.exe (PID: 1936)
      • firefox.exe (PID: 2936)
      • firefox.exe (PID: 2084)
      • firefox.exe (PID: 3976)
      • firefox.exe (PID: 2312)
      • firefox.exe (PID: 3800)
      • firefox.exe (PID: 1604)
      • msiexec.exe (PID: 3008)
      • msiexec.exe (PID: 1024)
      • MsiExec.exe (PID: 3668)
      • vssvc.exe (PID: 2320)
    • Reads CPU info

      • firefox.exe (PID: 2312)
    • Creates files in the program directory

      • firefox.exe (PID: 2312)
    • Creates files in the user directory

      • firefox.exe (PID: 2312)
    • Reads settings of System Certificates

      • firefox.exe (PID: 2312)
      • msiexec.exe (PID: 3008)
    • Checks Windows Trust Settings

      • firefox.exe (PID: 2312)
      • msiexec.exe (PID: 3008)
    • Dropped object may contain Bitcoin addresses

      • firefox.exe (PID: 2312)
    • Manual execution by user

      • msiexec.exe (PID: 3008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
18
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs minecraftlauncher.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1024C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1208"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2312.29.1286250954\215393615" -childID 6 -isForBrowser -prefsHandle 4124 -prefMapHandle 4116 -prefsLen 7770 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2312 "\\.\pipe\gecko-crash-server-pipe.2312" 4232 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1604"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2312.55.1686310009\1938654853" -childID 8 -isForBrowser -prefsHandle 7292 -prefMapHandle 7300 -prefsLen 9517 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2312 "\\.\pipe\gecko-crash-server-pipe.2312" 7280 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
1808C:\Windows\system32\MsiExec.exe -Embedding 0E15A83896A0DF53DC031B03F9EB615B E Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1936"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2312.27.1275708485\555008690" -childID 4 -isForBrowser -prefsHandle 4088 -prefMapHandle 4084 -prefsLen 7770 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2312 "\\.\pipe\gecko-crash-server-pipe.2312" 4132 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msasn1.dll
2084"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2312.20.687320149\1017074367" -childID 3 -isForBrowser -prefsHandle 1680 -prefMapHandle 3544 -prefsLen 7399 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2312 "\\.\pipe\gecko-crash-server-pipe.2312" 1692 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
2312"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.minecraft.net/en-us/downloadC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
2320C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft� Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gdi32.dll
2716"C:\Program Files\Mozilla Firefox\firefox.exe" "https://www.minecraft.net/en-us/download"C:\Program Files\Mozilla Firefox\firefox.exeExplorer.EXE
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msasn1.dll
2936"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2312.6.154460532\104430862" -childID 1 -isForBrowser -prefsHandle 1844 -prefMapHandle 1840 -prefsLen 245 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2312 "\\.\pipe\gecko-crash-server-pipe.2312" 1856 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msasn1.dll
Total events
26 086
Read events
25 783
Write events
291
Delete events
12

Modification events

(PID) Process:(2716) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
C6B5B14526000000
(PID) Process:(2312) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
41C1B14526000000
(PID) Process:(2312) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(2312) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(2312) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(2312) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(2312) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|ServicesSettingsServer
Value:
https://firefox.settings.services.mozilla.com/v1
(PID) Process:(2312) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash
Value:
97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E
(PID) Process:(2312) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2312) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
4
Suspicious files
89
Text files
40
Unknown types
17

Dropped files

PID
Process
Filename
Type
2312firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
2312firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
2312firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:
SHA256:
2312firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\settings\main\ms-language-packs\asrouter.ftl.tmptext
MD5:
SHA256:
2312firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\settings\main\ms-language-packs\asrouter.ftltext
MD5:
SHA256:
2312firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-walsqlite-wal
MD5:
SHA256:
2312firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:
SHA256:
2312firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-walbinary
MD5:
SHA256:
2312firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite-walsqlite-wal
MD5:
SHA256:
2312firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journalbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
44
TCP/UDP connections
174
DNS requests
382
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2312
firefox.exe
GET
301
104.21.87.64:80
http://easymc.io/
US
malicious
2312
firefox.exe
GET
200
172.67.142.1:80
http://easymc.io/.well-known/http-opportunistic
US
text
40 b
malicious
2312
firefox.exe
POST
200
142.250.181.227:80
http://ocsp.pki.goog/gts1o1core
US
der
471 b
whitelisted
2312
firefox.exe
POST
200
142.250.181.227:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
2312
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2312
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2312
firefox.exe
POST
200
93.184.220.29:80
http://status.geotrust.com/
US
der
471 b
whitelisted
2312
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2312
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2312
firefox.exe
POST
200
142.250.181.227:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2312
firefox.exe
34.107.221.82:80
detectportal.firefox.com
US
whitelisted
2312
firefox.exe
92.122.244.18:443
www.minecraft.net
GTT Communications Inc.
FR
suspicious
2312
firefox.exe
143.204.98.29:443
firefox.settings.services.mozilla.com
US
malicious
2312
firefox.exe
143.204.98.120:443
content-signature-2.cdn.mozilla.net
US
suspicious
2312
firefox.exe
35.83.75.254:443
location.services.mozilla.com
Merit Network Inc.
US
unknown
2312
firefox.exe
142.250.185.170:443
safebrowsing.googleapis.com
Google Inc.
US
whitelisted
2312
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2312
firefox.exe
2.18.232.23:443
assets.adobedtm.com
Akamai International B.V.
whitelisted
2312
firefox.exe
152.199.19.160:443
az725175.vo.msecnd.net
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2312
firefox.exe
13.107.246.60:443
consentdeliveryfd.azurefd.net
Microsoft Corporation
US
malicious

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
whitelisted
www.minecraft.net
  • 92.122.244.18
  • 92.122.244.59
  • 104.86.111.169
  • 104.86.111.145
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
a1897.r.akamai.net
  • 92.122.244.59
  • 92.122.244.18
  • 104.86.111.145
  • 104.86.111.169
whitelisted
firefox.settings.services.mozilla.com
  • 143.204.98.29
  • 143.204.98.23
  • 143.204.98.33
  • 143.204.98.76
whitelisted
location.services.mozilla.com
  • 35.83.75.254
  • 54.186.181.218
  • 34.215.35.6
  • 54.149.13.197
  • 54.186.138.163
  • 44.236.127.247
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
locprod2-elb-us-west-2.prod.mozaws.net
  • 44.236.127.247
  • 54.186.138.163
  • 54.149.13.197
  • 34.215.35.6
  • 54.186.181.218
  • 35.83.75.254
whitelisted
content-signature-2.cdn.mozilla.net
  • 143.204.98.120
  • 143.204.98.118
  • 143.204.98.30
  • 143.204.98.36
whitelisted

Threats

No threats detected
No debug info