| URL: | https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab |
| Full analysis: | https://app.any.run/tasks/97e13bb3-8324-4fba-ba22-6c916e959b1d |
| Verdict: | Malicious activity |
| Analysis date: | October 15, 2019, 18:58:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 50DAC2EE5B4056A431B3E761E49B9C7B |
| SHA1: | 981BF34B37D719159F1C3BF861EC620DBD9018E0 |
| SHA256: | 46264FFB5532EA8A82793DC0D925018A7EB780DBB5671368864B63C54DB6876B |
| SSDEEP: | 3:N8SElfvyTHNNKZ3d+ETEHn:2SKfKTHfKZ3QEIH |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 320 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3196 CREDAT:14343 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 920 | "C:\Users\admin\Desktop\FP_AX_CAB_INSTALLER64.exe" | C:\Users\admin\Desktop\FP_AX_CAB_INSTALLER64.exe | explorer.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: HIGH Description: Adobe® Flash® Player Installer/Uninstaller 32.0 r0 Exit code: 0 Version: 32,0,0,270 Modules
| |||||||||||||||
| 1328 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4080.3.806715711\1054923503" -childID 1 -isForBrowser -prefsHandle 1348 -prefMapHandle 1584 -prefsLen 1 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 4080 "\\.\pipe\gecko-crash-server-pipe.4080" 1336 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 1504 | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe | — | svchost.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe® Flash® Player Installer/Uninstaller 26.0 r0 Exit code: 0 Version: 26,0,0,131 Modules
| |||||||||||||||
| 1796 | "C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_270_ActiveX.exe" -refreshIEElevationPolicies | C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_270_ActiveX.exe | — | 8AA08247-E109-4C12-BAD3-F8447DAD6942 | |||||||||||
User: admin Company: Adobe Integrity Level: HIGH Description: Adobe® Flash® Player Installer/Uninstaller 32.0 r0 Exit code: 0 Version: 32,0,0,270 Modules
| |||||||||||||||
| 2128 | "C:\Users\admin\AppData\Local\Adobe\B25E093D-3923-487A-AA73-A9B20EC9BCAD\gccheck_small.exe" -chromeEligibilityTest -shellMode:standard | C:\Users\admin\AppData\Local\Adobe\B25E093D-3923-487A-AA73-A9B20EC9BCAD\gccheck_small.exe | — | flashplayer32axau_ra_install[1].exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Chrome Pre-Install Exit code: 2 Version: 1.0 Modules
| |||||||||||||||
| 2352 | explorer.exe | C:\Windows\explorer.exe | flashplayer32axau_ra_install[1].exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 3221225477 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2360 | "C:\Windows\system32\cmd.exe" /c del "C:\Users\admin\AppData\Local\Adobe\B25E093D-3923-487A-AA73-A9B20EC9BCAD\39ACA7A8-1E77-4CE3-A199-284CC74AA451\8AA08247-E109-4C12-BAD3-F8447DAD6942" >> NUL | C:\Windows\system32\cmd.exe | — | 8AA08247-E109-4C12-BAD3-F8447DAD6942 | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2396 | "C:\Users\admin\AppData\Local\Adobe\B25E093D-3923-487A-AA73-A9B20EC9BCAD\gtcheck.exe" | C:\Users\admin\AppData\Local\Adobe\B25E093D-3923-487A-AA73-A9B20EC9BCAD\gtcheck.exe | — | flashplayer32axau_ra_install[1].exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2428 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| (PID) Process: | (4080) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 3470F01703000000 | |||
| (PID) Process: | (2428) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 457AEC1703000000 | |||
| (PID) Process: | (4080) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (4080) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (4080) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4080) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4080) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\p2pcollab.dll,-8042 |
Value: Peer to Peer Trust | |||
| (PID) Process: | (4080) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\qagentrt.dll,-10 |
Value: System Health Authentication | |||
| (PID) Process: | (4080) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\dnsapi.dll,-103 |
Value: Domain Name System (DNS) Server Trust | |||
| (PID) Process: | (4080) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\fveui.dll,-843 |
Value: BitLocker Drive Encryption | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4080 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 4080 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 4080 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
| 4080 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
| 4080 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp | — | |
MD5:— | SHA256:— | |||
| 4080 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.bin | binary | |
MD5:— | SHA256:— | |||
| 4080 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:— | SHA256:— | |||
| 4080 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 4080 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4 | jsonlz4 | |
MD5:— | SHA256:— | |||
| 4080 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstore | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2872 | iexplore.exe | GET | 301 | 2.18.233.74:80 | http://get3.adobe.com/flashplayer/update/activex/ | unknown | — | — | whitelisted |
3904 | iexplore.exe | GET | 301 | 2.18.233.74:80 | http://get3.adobe.com/flashplayer/update/activex/ | unknown | — | — | whitelisted |
4072 | flashplayer32axau_ra_install[1].exe | GET | 302 | 52.31.190.58:80 | http://stats.adobe.com/b/ss/adbacdcprod/1/H.25.4/s83590690895671?AQB=1&ndh=1&t=15%2F9%2F2019%2020%3A1%3A39%202%20-60&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_update_adm_launched&g=res%3A%2F%2FC%3A%5CUsers%5Cadmin%5CAppData%5CLocal%5CMicrosoft%5CWindows%5CTemporary%20Internet%20Files%5CContent.IE5%5CLH043OAM%5Cflashplayer32axau_ra_install%5B1%5D.exe%2F160&ch=acdc_flashplayer&events=event96&products=%3Bflashplayer_update&c1=adm&c2=acdc%20downloads&c3=get3.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_update_adm_launched&v18=new&v22=tuesday%20-%201%3A00pm&v73=acdc_flashplayer_update&s=1280x720&c=32&j=1.5&v=Y&k=N&bw=620&bh=358&ct=lan&hp=N&AQE=1 | IE | — | — | whitelisted |
4080 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
4080 | firefox.exe | POST | 200 | 172.217.18.3:80 | http://ocsp.pki.goog/gts1o1 | US | der | 471 b | whitelisted |
2768 | 8AA08247-E109-4C12-BAD3-F8447DAD6942 | GET | 404 | 2.16.106.193:80 | http://fpdownload2.macromedia.com/get/flashplayer/update/current/install/version.xml32.0.0.270~installVector=10&previousVersion=26.0.0.131&pProc=flashplayer32axau_ra_install[1].exe&lang=en&cpuWordLength=32&playerType=ax&os=win&osVer=13&isDebug=0 | unknown | html | 441 b | whitelisted |
4080 | firefox.exe | GET | 404 | 23.58.216.121:80 | http://download.macromedia.com/get/ | US | html | 202 b | suspicious |
4072 | flashplayer32axau_ra_install[1].exe | GET | 200 | 52.31.190.58:80 | http://stats.adobe.com/b/ss/adbacdcprod/1/H.25.4/s84602204244114?AQB=1&ndh=1&t=15%2F9%2F2019%2020%3A1%3A43%202%20-60&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_update_adm_pref_0&g=res%3A%2F%2FC%3A%5CUsers%5Cadmin%5CAppData%5CLocal%5CMicrosoft%5CWindows%5CTemporary%20Internet%20Files%5CContent.IE5%5CLH043OAM%5Cflashplayer32axau_ra_install%5B1%5D.exe%2F160&ch=acdc_flashplayer&products=%3Bflashplayer_update&c1=adm&c2=acdc%20downloads&c3=get3.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_update_adm_pref_0&v18=new&v22=tuesday%20-%201%3A00pm&v73=acdc_flashplayer_update&s=1280x720&c=32&j=1.5&v=Y&k=N&bw=620&bh=358&ct=lan&hp=N&AQE=1 | IE | image | 43 b | whitelisted |
3040 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
4080 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4080 | firefox.exe | 2.16.106.224:80 | detectportal.firefox.com | Akamai International B.V. | — | whitelisted |
4080 | firefox.exe | 52.43.52.149:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
4080 | firefox.exe | 2.18.235.69:443 | download.macromedia.com | Akamai International B.V. | — | whitelisted |
4080 | firefox.exe | 13.35.253.94:443 | tracking-protection.cdn.mozilla.net | — | US | suspicious |
4080 | firefox.exe | 2.16.106.147:80 | detectportal.firefox.com | Akamai International B.V. | — | whitelisted |
2872 | iexplore.exe | 2.18.233.74:443 | get3.adobe.com | Akamai International B.V. | — | whitelisted |
4080 | firefox.exe | 13.32.166.60:443 | firefox.settings.services.mozilla.com | Amazon.com, Inc. | US | unknown |
4080 | firefox.exe | 172.217.18.3:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
4080 | firefox.exe | 13.32.166.205:443 | firefox.settings.services.mozilla.com | Amazon.com, Inc. | US | unknown |
4080 | firefox.exe | 52.40.41.239:443 | shavar.services.mozilla.com | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
a1089.dscd.akamai.net |
| whitelisted |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
download.macromedia.com |
| suspicious |
e13914.dscd.akamaiedge.net |
| suspicious |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
cs9.wac.phicdn.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |