| URL: | https://software.informer.com/Security/ |
| Full analysis: | https://app.any.run/tasks/6a2b534d-e5f5-40b1-b380-fe27ca88c03b |
| Verdict: | Malicious activity |
| Analysis date: | February 23, 2024, 21:38:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | C991DEAF3C25B415C1FE342E7C46B12C |
| SHA1: | 00C654BFBB441D3B5EE6D3B6E330C52C7F179990 |
| SHA256: | 3D092B8A408592878977E44EC2A5347B39C0C0F9FAF598CE2373FF5903E26394 |
| SSDEEP: | 3:N8Hd4Erh:2WErh |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 268 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.20.2073170092\676839197" -childID 19 -isForBrowser -prefsHandle 7628 -prefMapHandle 7624 -prefsLen 31420 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {64911309-5fe0-486d-ac4d-f9d5669efc63} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 7540 17f07e00 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 552 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.7.2084610032\2081345524" -childID 6 -isForBrowser -prefsHandle 7784 -prefMapHandle 7780 -prefsLen 29313 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e0c62499-8a8e-4b15-b2ef-689d62243ed9} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 7796 19d02840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 560 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.24.735856018\1228260860" -childID 23 -isForBrowser -prefsHandle 6276 -prefMapHandle 7700 -prefsLen 31420 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f97c6c4d-777f-4e2f-9ec2-0e6fc3a295b3} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 2768 1824df70 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 572 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.25.875895212\858299618" -childID 24 -isForBrowser -prefsHandle 3112 -prefMapHandle 6452 -prefsLen 31420 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6dcc8a8d-460c-4b5a-8889-af07369b6b9a} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 7720 12a9c110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 584 | "C:\Program Files\WinZip System Utilities Suite\WinZip System Utilities Suite.exe" -install -client_id "CC20BBCF-A68A-4D34-AC01-319E938C0BC9" | C:\Program Files\WinZip System Utilities Suite\WinZip System Utilities Suite.exe | f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe | ||||||||||||
User: admin Company: Corel Corporation Integrity Level: HIGH Description: WinZip System Utilities Suite Exit code: 0 Version: 4,0,3,4 Modules
| |||||||||||||||
| 604 | "C:\Users\admin\AppData\Local\Temp\is-CEEIM.tmp\siinst.tmp" /SL5="$A0292,3521793,119296,C:\Users\admin\Downloads\siinst.exe" | C:\Users\admin\AppData\Local\Temp\is-CEEIM.tmp\siinst.tmp | — | siinst.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 896 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.8.148225362\250150908" -childID 7 -isForBrowser -prefsHandle 7692 -prefMapHandle 7600 -prefsLen 29313 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {42c5859b-fb10-47d7-8bf4-8dfc826586cc} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 7716 19f43110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1344 | \f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe /OSOURCE="wzss53" /BUILD_ID="53" | C:\f4ccee8d-04e9-4fd1-97fb-9bfec8def2c7.exe | wzsus53.exe | ||||||||||||
User: admin Company: Corel Corporation Integrity Level: HIGH Description: WinZip System Utilities Suite installer Exit code: 2 Version: 4.0.3.4 Modules
| |||||||||||||||
| 1588 | "C:\Program Files\Software Informer\softinfo.exe" | C:\Program Files\Software Informer\softinfo.exe | siinst.tmp | ||||||||||||
User: admin Company: Informer Technologies, Inc. Integrity Level: MEDIUM Description: Software Informer Exit code: 0 Version: 1.5.1346.0 Modules
| |||||||||||||||
| 1592 | "schtasks.exe" /create /sc onlogon /tn SoftwareInformerService /f /rl highest /tr "\"C:\Program Files\Software Informer\softinfo.exe\" -service" | C:\Windows\System32\schtasks.exe | — | siinst.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: CF9CE14E01000000 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0983E34E01000000 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB |
| Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3656 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:B7A3C61D0C144CC5E166B1E769CA8F8C | SHA256:7FADCB77FFACA6B9E9F15C6F1CD3AAD4C20DCD90FA92429A627A3A7110CA2644 | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journal | binary | |
MD5:033D4029EBAC965F4BDCF93564A59311 | SHA256:54CAF240D5AB41C4E540ECBB690EA6F8005F27CBF75066254473BEE3269A8351 | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3656 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
3656 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
3656 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
3656 | firefox.exe | POST | 200 | 195.138.255.19:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3656 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
3656 | firefox.exe | POST | 200 | 195.138.255.19:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3656 | firefox.exe | POST | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/ | unknown | binary | 472 b | unknown |
3656 | firefox.exe | POST | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/ | unknown | binary | 472 b | unknown |
3656 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
3656 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3656 | firefox.exe | 34.117.188.166:443 | spocs.getpocket.com | — | — | unknown |
3656 | firefox.exe | 142.250.185.106:443 | safebrowsing.googleapis.com | — | — | whitelisted |
3656 | firefox.exe | 100.25.93.238:443 | software.informer.com | AMAZON-AES | US | unknown |
3656 | firefox.exe | 172.217.18.3:443 | fonts.gstatic.com | GOOGLE | US | whitelisted |
3656 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | — | — | unknown |
3656 | firefox.exe | 172.217.16.195:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
3656 | firefox.exe | 74.117.179.70:443 | img.informer.com | WZCOM | US | unknown |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
software.informer.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
gkegw.prod.ads.prod.webservices.mozgcp.net |
| unknown |
firefox.settings.services.mozilla.com |
| whitelisted |
r3.o.lencr.org |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
3656 | firefox.exe | Not Suspicious Traffic | INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code.jquery .com) |
3656 | firefox.exe | Not Suspicious Traffic | INFO [ANY.RUN] Global content delivery network (unpkg .com) |
4400 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Global content delivery network (unpkg .com) |
4400 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code.jquery .com) |
— | — | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
— | — | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
— | — | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
— | — | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
— | — | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
— | — | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |