analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://www.divertigames.net/gioco-v-728x90/index.html

Full analysis: https://app.any.run/tasks/1656dc77-7795-4597-9708-30394f3bf665
Verdict: Malicious activity
Analysis date: April 29, 2021, 14:49:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

D3D81732BC0E6BA9255E0ABC7C360CF6

SHA1:

7F40778E5045D67473452372AEC14D7FB8FA9873

SHA256:

497A007FAC5485AA389B0B1BDD5BC58594126586ED18554F40723D676227A744

SSDEEP:

3:N1KJS4NXqH9bsPK1fW5G:Cc4YH9bNkG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • firefox.exe (PID: 2732)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 2732)
  • INFO

    • Checks supported languages

      • firefox.exe (PID: 2732)
      • firefox.exe (PID: 3568)
      • firefox.exe (PID: 3540)
      • firefox.exe (PID: 3516)
      • firefox.exe (PID: 2840)
      • firefox.exe (PID: 3852)
      • firefox.exe (PID: 1416)
      • firefox.exe (PID: 996)
      • firefox.exe (PID: 2072)
    • Reads the computer name

      • firefox.exe (PID: 2732)
      • firefox.exe (PID: 3540)
      • firefox.exe (PID: 3516)
      • firefox.exe (PID: 2840)
      • firefox.exe (PID: 1416)
      • firefox.exe (PID: 996)
      • firefox.exe (PID: 3852)
      • firefox.exe (PID: 2072)
    • Reads CPU info

      • firefox.exe (PID: 2732)
    • Application launched itself

      • firefox.exe (PID: 3568)
      • firefox.exe (PID: 2732)
    • Creates files in the program directory

      • firefox.exe (PID: 2732)
    • Dropped object may contain Bitcoin addresses

      • firefox.exe (PID: 2732)
    • Reads the date of Windows installation

      • firefox.exe (PID: 2732)
    • Creates files in the user directory

      • firefox.exe (PID: 2732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
9
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3568"C:\Program Files\Mozilla Firefox\firefox.exe" "http://www.divertigames.net/gioco-v-728x90/index.html"C:\Program Files\Mozilla Firefox\firefox.exeExplorer.EXE
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
83.0
2732"C:\Program Files\Mozilla Firefox\firefox.exe" http://www.divertigames.net/gioco-v-728x90/index.htmlC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
83.0
3540"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2732.0.1403537740\517613406" -parentBuildID 20201112153044 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 1 -prefMapSize 238726 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2732 "\\.\pipe\gecko-crash-server-pipe.2732" 1180 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
83.0
3516"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2732.6.1861716586\836143607" -childID 1 -isForBrowser -prefsHandle 1852 -prefMapHandle 1848 -prefsLen 245 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2732 "\\.\pipe\gecko-crash-server-pipe.2732" 1864 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
2840"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2732.13.973636977\67576787" -childID 2 -isForBrowser -prefsHandle 3004 -prefMapHandle 3000 -prefsLen 6644 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2732 "\\.\pipe\gecko-crash-server-pipe.2732" 3016 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
3852"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2732.20.1109731093\620902528" -childID 3 -isForBrowser -prefsHandle 3360 -prefMapHandle 3344 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2732 "\\.\pipe\gecko-crash-server-pipe.2732" 3508 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
1416"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2732.27.53060376\1875678458" -childID 4 -isForBrowser -prefsHandle 3344 -prefMapHandle 3360 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2732 "\\.\pipe\gecko-crash-server-pipe.2732" 3648 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
996"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2732.34.799697885\356366355" -childID 5 -isForBrowser -prefsHandle 2312 -prefMapHandle 3948 -prefsLen 9703 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2732 "\\.\pipe\gecko-crash-server-pipe.2732" 3772 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
2072"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2732.41.2101429983\464431007" -parentBuildID 20201112153044 -prefsHandle 1012 -prefMapHandle 8100 -prefsLen 9703 -prefMapSize 238726 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2732 "\\.\pipe\gecko-crash-server-pipe.2732" 3244 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Total events
11 852
Read events
11 830
Write events
0
Delete events
0

Modification events

No data
Executable files
4
Suspicious files
126
Text files
59
Unknown types
35

Dropped files

PID
Process
Filename
Type
2732firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
2732firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
2732firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:1F62A46CB75FAA4EA7835E0F2D31A957
SHA256:FE615B0F6034D79896C0FB3A466039926CB9AC6CCAF44093998A961C237E511B
2732firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2732firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:1F62A46CB75FAA4EA7835E0F2D31A957
SHA256:FE615B0F6034D79896C0FB3A466039926CB9AC6CCAF44093998A961C237E511B
2732firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-walsqlite-wal
MD5:CB956460A00468B799B24F898BC7BB02
SHA256:B153DA623C097272F33F961D78B1C20FA446A8EBAABD56F85392DE8633E031D8
2732firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journalbinary
MD5:8DF14AE6118595E9B99D28870DAE00B0
SHA256:DBFC81DA3D1F350AC3DEF3440CD91B5F0089C06F013B24A45FF1FC3DA365396E
2732firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsontext
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
2732firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2732firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
45
TCP/UDP connections
83
DNS requests
141
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2732
firefox.exe
GET
200
172.217.16.132:80
http://www.google.com/adsense/domains/caf.js
US
text
59.4 Kb
whitelisted
2732
firefox.exe
GET
200
199.59.242.153:80
http://ww1.divertigames.net/
US
html
3.99 Kb
malicious
2732
firefox.exe
GET
200
199.59.242.155:80
http://tracking.bodis.com/tlpv?d=eyJkb21haW5fbmFtZSI6ImRpdmVydGlnYW1lcy5uZXQiLCJzZXJ2ZXIiOjE1OSwidGVybXMiOltdLCJVUkwiOiJodHRwOlwvXC93dzEuZGl2ZXJ0aWdhbWVzLm5ldFwvIiwicmVmZXJyZXIiOiIiLCJkdyI6MTI4MCwiZGgiOjYxOCwicnciOjEyODAsInJoIjo3MjB9&t=1619707768&abp=0
US
whitelisted
2732
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2732
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2732
firefox.exe
GET
200
199.59.242.153:80
http://ww1.divertigames.net/public/legacy/10355/resources/arrows-bg.jpg
US
image
93.6 Kb
malicious
2732
firefox.exe
POST
200
142.250.186.35:80
http://ocsp.pki.goog/gts1o1core
US
der
471 b
whitelisted
2732
firefox.exe
GET
200
199.59.242.153:80
http://ww1.divertigames.net/public/legacy/10355/resources/arrows-bg-ext.png
US
image
1.12 Kb
malicious
2732
firefox.exe
POST
200
142.250.186.35:80
http://ocsp.pki.goog/gts1o1core
US
der
472 b
whitelisted
2732
firefox.exe
GET
302
172.98.192.35:80
http://www.divertigames.net/gioco-v-728x90/index.html
US
text
11 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2732
firefox.exe
34.107.221.82:80
detectportal.firefox.com
US
whitelisted
2732
firefox.exe
142.250.184.202:443
safebrowsing.googleapis.com
Google Inc.
US
whitelisted
2732
firefox.exe
172.98.192.35:80
www.divertigames.net
Centrilogic, Inc.
US
malicious
2732
firefox.exe
52.10.171.58:443
location.services.mozilla.com
Amazon.com, Inc.
US
unknown
2732
firefox.exe
143.204.202.83:443
content-signature-2.cdn.mozilla.net
US
suspicious
2732
firefox.exe
143.204.202.18:443
firefox.settings.services.mozilla.com
US
unknown
2732
firefox.exe
34.211.62.63:443
push.services.mozilla.com
Amazon.com, Inc.
US
unknown
2732
firefox.exe
143.204.202.101:443
firefox-settings-attachments.cdn.mozilla.net
US
suspicious
143.204.202.83:443
content-signature-2.cdn.mozilla.net
US
suspicious
2732
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
whitelisted
www.divertigames.net
  • 172.98.192.35
suspicious
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
whitelisted
firefox.settings.services.mozilla.com
  • 143.204.202.18
  • 143.204.202.115
  • 143.204.202.6
  • 143.204.202.9
whitelisted
location.services.mozilla.com
  • 52.10.171.58
  • 34.210.121.31
  • 52.34.254.9
  • 44.237.173.75
  • 34.216.198.143
  • 44.236.127.247
whitelisted
locprod2-elb-us-west-2.prod.mozaws.net
  • 44.236.127.247
  • 34.216.198.143
  • 44.237.173.75
  • 52.34.254.9
  • 34.210.121.31
  • 52.10.171.58
whitelisted
content-signature-2.cdn.mozilla.net
  • 143.204.202.83
  • 143.204.202.18
  • 143.204.202.13
  • 143.204.202.80
whitelisted
d2nxq2uap88usk.cloudfront.net
  • 143.204.202.80
  • 143.204.202.13
  • 143.204.202.18
  • 143.204.202.83
shared
safebrowsing.googleapis.com
  • 142.250.184.202
whitelisted
push.services.mozilla.com
  • 34.211.62.63
whitelisted

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET INFO Observed DNS Query to .cloud TLD
Potentially Bad Traffic
ET INFO Observed DNS Query to .cloud TLD
No debug info