File name:

Firebird-2.1.1.17910-0_Win32.exe

Full analysis: https://app.any.run/tasks/b47042ad-a6ef-472d-8bfe-8d669abe1ed3
Verdict: Malicious activity
Analysis date: February 14, 2025, 11:57:35
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

C7F4EF2DE86DBCCB65DDFC3A105C7C96

SHA1:

95125D187B50369C0A03BA0D7D3EADBA862319BA

SHA256:

4D52A328AD8F75A2C63B37218ADD1C617746D2293CB2ADFB130F68EA03BFD255

SSDEEP:

98304:5tr7OGHeyHU7GYCMG6Mo4LsF5dBOs3Fu1wngQ8vhL70mgPllFdiyc7XAAZAMsQMK:wUqqWerbp/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Firebird-2.1.1.17910-0_Win32.exe (PID: 6428)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
      • Firebird-2.1.1.17910-0_Win32.exe (PID: 6640)
      • TiWorker.exe (PID: 6488)
      • instclient.exe (PID: 5268)
    • Reads security settings of Internet Explorer

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6464)
    • Reads the Windows owner or organization settings

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
      • msiexec.exe (PID: 3188)
    • Process drops legitimate windows executable

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
      • msiexec.exe (PID: 3188)
      • TiWorker.exe (PID: 6488)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 3188)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
      • TiWorker.exe (PID: 6488)
    • Executes as Windows Service

      • fbguard.exe (PID: 4668)
      • fbserver.exe (PID: 4684)
  • INFO

    • Checks supported languages

      • Firebird-2.1.1.17910-0_Win32.exe (PID: 6428)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6464)
      • Firebird-2.1.1.17910-0_Win32.exe (PID: 6640)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
      • msiexec.exe (PID: 3188)
      • msiexec.exe (PID: 6252)
      • instclient.exe (PID: 5268)
      • instreg.exe (PID: 6456)
      • instsvc.exe (PID: 3092)
      • instsvc.exe (PID: 4704)
      • instsvc.exe (PID: 4596)
      • fbguard.exe (PID: 4668)
      • fbserver.exe (PID: 4684)
      • identity_helper.exe (PID: 7192)
    • Create files in a temporary directory

      • Firebird-2.1.1.17910-0_Win32.exe (PID: 6428)
      • Firebird-2.1.1.17910-0_Win32.exe (PID: 6640)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
      • msiexec.exe (PID: 3836)
    • Reads the computer name

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6464)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
      • msiexec.exe (PID: 3188)
      • msiexec.exe (PID: 6252)
      • instsvc.exe (PID: 3092)
      • instsvc.exe (PID: 4704)
      • instsvc.exe (PID: 4596)
      • fbserver.exe (PID: 4684)
      • identity_helper.exe (PID: 7192)
      • fbguard.exe (PID: 4668)
    • Process checks computer location settings

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6464)
    • Detects InnoSetup installer (YARA)

      • Firebird-2.1.1.17910-0_Win32.exe (PID: 6428)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6464)
      • Firebird-2.1.1.17910-0_Win32.exe (PID: 6640)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
    • The sample compiled with english language support

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
      • msiexec.exe (PID: 3188)
      • TiWorker.exe (PID: 6488)
      • instclient.exe (PID: 5268)
    • Creates a software uninstall entry

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
      • msiexec.exe (PID: 3188)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3188)
    • Creates files in the program directory

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
      • fbguard.exe (PID: 4668)
    • Application launched itself

      • msedge.exe (PID: 4500)
    • Reads Environment values

      • identity_helper.exe (PID: 7192)
    • Compiled with Borland Delphi (YARA)

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6464)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 6684)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37376
InitializedDataSize: 17408
UninitializedDataSize: -
EntryPoint: 0x9a58
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Firebird Project
FileDescription: Firebird Setup
FileVersion:
LegalCopyright:
ProductName: Firebird
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
180
Monitored processes
52
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start firebird-2.1.1.17910-0_win32.exe firebird-2.1.1.17910-0_win32.tmp no specs firebird-2.1.1.17910-0_win32.exe firebird-2.1.1.17910-0_win32.tmp msiexec.exe no specs msiexec.exe msiexec.exe no specs tiworker.exe instreg.exe no specs conhost.exe no specs instclient.exe conhost.exe no specs instsvc.exe no specs conhost.exe no specs instsvc.exe no specs conhost.exe no specs instsvc.exe no specs conhost.exe no specs fbguard.exe no specs fbserver.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
628\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeinstclient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
736"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3528 --field-trial-handle=2420,i,8169824279173495160,5439601270071399293,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
876"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2768 --field-trial-handle=2420,i,8169824279173495160,5439601270071399293,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2008"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x31c,0x320,0x324,0x314,0x32c,0x7ff81f735fd8,0x7ff81f735fe4,0x7ff81f735ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3536 --field-trial-handle=2420,i,8169824279173495160,5439601270071399293,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2956"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2612 --field-trial-handle=2420,i,8169824279173495160,5439601270071399293,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2972\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeinstsvc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3092"C:\Program Files (x86)\Firebird\Firebird_2_1\bin\instsvc.exe" remove C:\Program Files (x86)\Firebird\Firebird_2_1\bin\instsvc.exeFirebird-2.1.1.17910-0_Win32.tmp
User:
admin
Company:
Firebird Project
Integrity Level:
HIGH
Description:
Firebird SQL Server
Exit code:
1
Version:
WI-V2.1.1.17910
Modules
Images
c:\program files (x86)\firebird\firebird_2_1\bin\instsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3172"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=5596 --field-trial-handle=2420,i,8169824279173495160,5439601270071399293,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3188C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
6 523
Read events
6 295
Write events
200
Delete events
28

Modification events

(PID) Process:(6684) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\Firebird\Firebird_2_1\bin\gbak.exe
Value:
1
(PID) Process:(6684) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\Firebird\Firebird_2_1\bin\gfix.exe
Value:
1
(PID) Process:(6684) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\Firebird\Firebird_2_1\bin\gsec.exe
Value:
1
(PID) Process:(6684) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\Firebird\Firebird_2_1\bin\gsplit.exe
Value:
1
(PID) Process:(6684) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\Firebird\Firebird_2_1\bin\fbguard.exe
Value:
1
(PID) Process:(6684) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\Firebird\Firebird_2_1\bin\fbserver.exe
Value:
1
(PID) Process:(6684) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\Firebird\Firebird_2_1\bin\fb_lock_print.exe
Value:
1
(PID) Process:(6684) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\Firebird\Firebird_2_1\bin\instreg.exe
Value:
1
(PID) Process:(6684) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\Firebird\Firebird_2_1\bin\instsvc.exe
Value:
1
(PID) Process:(6684) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\Firebird\Firebird_2_1\bin\fbclient.dll
Value:
1
Executable files
83
Suspicious files
464
Text files
377
Unknown types
0

Dropped files

PID
Process
Filename
Type
6684Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files (x86)\Firebird\Firebird_2_1\is-OLN1S.tmpexecutable
MD5:6B940AFF068B86A6B1D3B1FAA08C5D24
SHA256:D65204C9BDACA1F052834B70EF3C90E1817B498871665EECF18357BDCAF7A290
6640Firebird-2.1.1.17910-0_Win32.exeC:\Users\admin\AppData\Local\Temp\is-I9GMQ.tmp\Firebird-2.1.1.17910-0_Win32.tmpexecutable
MD5:52950AC9E2B481453082F096120E355A
SHA256:25FBC88C7C967266F041AE4D47C2EAE0B96086F9E440CCA10729103AEE7EF6CD
6684Firebird-2.1.1.17910-0_Win32.tmpC:\Users\admin\AppData\Local\Temp\is-US4Q0.tmp\_isetup\_RegDLL.tmpexecutable
MD5:C594B792B9C556EA62A30DE541D2FB03
SHA256:5DCC1E0A197922907BCA2C4369F778BD07EE4B1BBBDF633E987A028A314D548E
6684Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files (x86)\Firebird\Firebird_2_1\IPLicense.txttext
MD5:29418614945D275B7AA89EA63C01DFCD
SHA256:FECE7C16035E212CCA352512A46791F090FF33E99B2DD7208E8F04F5323106B7
6428Firebird-2.1.1.17910-0_Win32.exeC:\Users\admin\AppData\Local\Temp\is-H3J6C.tmp\Firebird-2.1.1.17910-0_Win32.tmpexecutable
MD5:52950AC9E2B481453082F096120E355A
SHA256:25FBC88C7C967266F041AE4D47C2EAE0B96086F9E440CCA10729103AEE7EF6CD
6684Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files (x86)\Firebird\Firebird_2_1\is-VH58S.tmptext
MD5:4F7696F9F8CB776E35922A2B9715A6B7
SHA256:A32B842BD833FBF127EF67267383901D0DA8F430006030B8CD931221A11E9D56
6684Firebird-2.1.1.17910-0_Win32.tmpC:\Users\admin\AppData\Local\Temp\is-US4Q0.tmp\_isetup\_setup64.tmpexecutable
MD5:B4604F8CD050D7933012AE4AA98E1796
SHA256:B50B7AC03EC6DA865BF4504C7AC1E52D9F5B67C7BCB3EC0DB59FAB24F1B471C5
6684Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files (x86)\Firebird\Firebird_2_1\IDPLicense.txttext
MD5:4F7696F9F8CB776E35922A2B9715A6B7
SHA256:A32B842BD833FBF127EF67267383901D0DA8F430006030B8CD931221A11E9D56
6684Firebird-2.1.1.17910-0_Win32.tmpC:\Users\admin\AppData\Local\Temp\is-US4Q0.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
6684Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files (x86)\Firebird\Firebird_2_1\is-IPIHG.tmptext
MD5:29418614945D275B7AA89EA63C01DFCD
SHA256:FECE7C16035E212CCA352512A46791F090FF33E99B2DD7208E8F04F5323106B7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
74
DNS requests
81
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6784
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4136
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4136
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
440
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
244
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
2.18.97.227:443
go.microsoft.com
Akamai International B.V.
FR
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
  • 2.19.122.42
  • 2.19.122.41
  • 2.19.122.44
  • 2.19.122.40
  • 2.19.122.39
  • 2.19.122.47
  • 2.19.122.38
  • 2.19.122.45
  • 2.19.122.49
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
login.live.com
  • 20.190.159.75
  • 20.190.159.128
  • 40.126.31.0
  • 20.190.159.73
  • 40.126.31.1
  • 40.126.31.2
  • 40.126.31.67
  • 40.126.31.71
whitelisted
go.microsoft.com
  • 2.18.97.227
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 23.209.214.100
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted

Threats

No threats detected
No debug info