URL: | https://defgyma.com/dl/buildz.exe |
Full analysis: | https://app.any.run/tasks/fc6f2ed0-5884-47b6-85d2-4667e5029fee |
Verdict: | Malicious activity |
Threats: | Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying. |
Analysis date: | June 20, 2024, 01:18:52 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MD5: | 7C4E8D265A2D04F347C94931815E9210 |
SHA1: | B522D93B05B6A968E09816621F4C291A0E6A33A5 |
SHA256: | 4A555B50980C406271738BF98B7EF5863F52547BF7C57DC93D6F3D922C885473 |
SSDEEP: | 3:N8YD7/a0dAn:2YykAn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3416 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://defgyma.com/dl/buildz.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
3700 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://defgyma.com/dl/buildz.exe | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2300 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.0.185035456\1747542983" -parentBuildID 20230710165010 -prefsHandle 1112 -prefMapHandle 1104 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1f4ba286-0d53-495e-a6bd-21acf4782e3c} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 1200 d1ab6c0 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 1 Version: 115.0.2 Modules
| |||||||||||||||
2100 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.1.990139524\1636656802" -parentBuildID 20230710165010 -prefsHandle 1408 -prefMapHandle 1404 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fd8b56de-d19d-4580-970b-1cfc199a2514} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 1420 eb6aee0 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
3364 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.2.1582339515\1872883783" -childID 1 -isForBrowser -prefsHandle 2064 -prefMapHandle 2060 -prefsLen 24556 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {372db1a8-21f8-4e69-a0c1-e9c5c92d420f} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 2076 129753f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
312 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.3.82416029\38582668" -childID 2 -isForBrowser -prefsHandle 2812 -prefMapHandle 2808 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {bd69fed5-0d00-43f9-b82c-8e89e5efdc70} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 2824 1eea2840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
1144 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.4.1703102974\847846194" -childID 3 -isForBrowser -prefsHandle 2940 -prefMapHandle 3768 -prefsLen 34449 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {56a04bfb-6457-4d55-9c0b-2d88a6621a95} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 3788 21d37560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
3140 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.5.278005094\505948818" -childID 4 -isForBrowser -prefsHandle 3932 -prefMapHandle 3980 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {100ce387-3312-47bc-aea3-a413263885db} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 2940 227d7840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2276 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.6.300063699\2050951440" -childID 5 -isForBrowser -prefsHandle 4128 -prefMapHandle 4132 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ecda27f5-daf6-4844-aef7-114411953ef7} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 4116 227d7280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
1648 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.7.203528552\1477572616" -childID 6 -isForBrowser -prefsHandle 4292 -prefMapHandle 4296 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7a6714db-5c92-49b1-9230-5eb6c92c108d} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 4280 21df7c90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
|
(PID) Process: | (3416) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 57ECC94300000000 | |||
(PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: E761CB4300000000 | |||
(PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB |
Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
(PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
(PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
(PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
(PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
(PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
(PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
(PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3700 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db | binary | |
MD5:B3CD47BB452B639D99D5A985AD0F07E7 | SHA256:BCDF9FF8596EDD49AB352D4F693B37D0A5CA75D7C6726E77BBC5E1EAD1FA6B4E | |||
3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
3700 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\activity-stream.discovery_stream.json.tmp | binary | |
MD5:20564DB63236613BB0BD7356CC253F29 | SHA256:3CA2B3717B65E1ECB311E15D73472517D06CA8B8044D14E4EEF2B92E2372DA33 | |||
3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 184.24.77.54:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | unknown |
3700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 184.24.77.54:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | — | 184.24.77.48:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
3700 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1372 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3700 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
3700 | firefox.exe | 142.250.184.234:443 | safebrowsing.googleapis.com | — | — | whitelisted |
3700 | firefox.exe | 34.117.188.166:443 | contile.services.mozilla.com | — | — | unknown |
3700 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | — | — | unknown |
3700 | firefox.exe | 34.36.165.17:443 | tiles-cdn.prod.ads.prod.webservices.mozgcp.net | GOOGLE-CLOUD-PLATFORM | US | unknown |
3700 | firefox.exe | 190.220.21.28:443 | defgyma.com | AMX Argentina S.A. | AR | unknown |
3700 | firefox.exe | 184.24.77.48:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
3700 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
Domain | IP | Reputation |
---|---|---|
defgyma.com |
| unknown |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
prod.ads.prod.webservices.mozgcp.net |
| unknown |
firefox.settings.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
prod.remote-settings.prod.webservices.mozgcp.net |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
3016 | buildz.exe | Potentially Bad Traffic | ET INFO Observed External IP Lookup Domain (api .2ip .ua in TLS SNI) |
1060 | svchost.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Address Lookup DNS Query (2ip .ua) |
2252 | buildz.exe | Potentially Bad Traffic | ET INFO Observed External IP Lookup Domain (api .2ip .ua in TLS SNI) |
2252 | buildz.exe | A Network Trojan was detected | ET USER_AGENTS Suspicious User Agent (Microsoft Internet Explorer) |
2252 | buildz.exe | A Network Trojan was detected | ET MALWARE Win32/Filecoder.STOP Variant Request for Public Key |
2252 | buildz.exe | A Network Trojan was detected | ET MALWARE Win32/Filecoder.STOP Variant Public Key Download |