| URL: | https://www.reddit.com/r/EXPERTTUTORIALVIDEO/comments/1280zck/tutorial_video/ |
| Full analysis: | https://app.any.run/tasks/059487ee-7201-4717-a5a9-29d77b2abffa |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | April 01, 2023, 12:20:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 0874DD04EF80B6F1A057DAF034749612 |
| SHA1: | 7B2ED477F9FC2560048C921FA3C9C6F29F383D46 |
| SHA256: | 5AE03C781B5975CF748A395FEBD22602C9C93379A30A22FF4DDAD46617E18854 |
| SSDEEP: | 3:N8DSLQuM4gB2xq3o6AL/OF2FqlRn:2OLQuML2sq/bUR |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 580 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="976.41.1772509852\710245796" -childID 6 -isForBrowser -prefsHandle 4124 -prefMapHandle 4128 -prefsLen 9214 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 976 "\\.\pipe\gecko-crash-server-pipe.976" 4140 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 908 | "C:\Users\admin\AppData\Roaming\551EzJ0a.exe" | C:\Users\admin\AppData\Roaming\551EzJ0a.exe | — | PC-Set-UP_SOFT.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: GUI_MODERNISTA Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 976 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://www.reddit.com/r/EXPERTTUTORIALVIDEO/comments/1280zck/tutorial_video/ | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 1272 | "C:\Users\admin\AppData\Roaming\telemetry\svcservice.exe" | C:\Users\admin\AppData\Roaming\telemetry\svcservice.exe | 47K34vB4.exe | ||||||||||||
User: admin Company: iTop Inc. Integrity Level: MEDIUM Description: Capture Exit code: 0 Version: 3.3.0.39 Modules
| |||||||||||||||
| 1488 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3904.18625\PC-Files_Expert-2O23\PC-Set-UP_SOFT.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3904.18625\PC-Files_Expert-2O23\PC-Set-UP_SOFT.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1620 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="976.20.2067000243\312749220" -childID 3 -isForBrowser -prefsHandle 2500 -prefMapHandle 2552 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 976 "\\.\pipe\gecko-crash-server-pipe.976" 2484 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 2384 | "C:\Users\admin\AppData\Roaming\47K34vB4.exe" | C:\Users\admin\AppData\Roaming\47K34vB4.exe | — | PC-Set-UP_SOFT.exe | |||||||||||
User: admin Company: iTop Inc. Integrity Level: MEDIUM Description: Capture Exit code: 0 Version: 3.3.0.39 Modules
| |||||||||||||||
| 2436 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="976.55.1413864798\450815490" -childID 8 -isForBrowser -prefsHandle 8152 -prefMapHandle 7856 -prefsLen 9682 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 976 "\\.\pipe\gecko-crash-server-pipe.976" 7820 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 2444 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="976.6.1928243316\1726087761" -childID 1 -isForBrowser -prefsHandle 3544 -prefMapHandle 3540 -prefsLen 181 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 976 "\\.\pipe\gecko-crash-server-pipe.976" 3556 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 2464 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="976.13.1321745540\1772930871" -childID 2 -isForBrowser -prefsHandle 2220 -prefMapHandle 2288 -prefsLen 6644 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 976 "\\.\pipe\gecko-crash-server-pipe.976" 2160 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| (PID) Process: | (2656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 09611C1E1E000000 | |||
| (PID) Process: | (976) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: AD681C1E1E000000 | |||
| (PID) Process: | (976) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (976) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (976) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (976) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (976) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|ServicesSettingsServer |
Value: https://firefox.settings.services.mozilla.com/v1 | |||
| (PID) Process: | (976) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash |
Value: 97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E | |||
| (PID) Process: | (976) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (976) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 976 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 976 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 976 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-wal | sqlite-wal | |
MD5:— | SHA256:— | |||
| 976 | firefox.exe | C:\Users\admin\AppData\Local\Temp\mz_etilqs_XMg61VOTqrQgtgh | binary | |
MD5:— | SHA256:— | |||
| 976 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QLDYZ5~1.DEF\cert9.db-journal | binary | |
MD5:— | SHA256:— | |||
| 976 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 976 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QLDYZ5~1.DEF\cert9.db | sqlite | |
MD5:— | SHA256:— | |||
| 976 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:— | SHA256:— | |||
| 976 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journal | binary | |
MD5:— | SHA256:— | |||
| 976 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
976 | firefox.exe | POST | 200 | 2.16.186.80:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
976 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
976 | firefox.exe | POST | 200 | 104.18.32.68:80 | http://ocsp.usertrust.com/ | US | der | 471 b | whitelisted |
976 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 471 b | whitelisted |
976 | firefox.exe | POST | 200 | 2.16.186.80:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
976 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 471 b | whitelisted |
976 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | US | text | 8 b | whitelisted |
976 | firefox.exe | POST | 200 | 2.16.186.80:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
976 | firefox.exe | POST | 200 | 172.64.155.188:80 | http://ocsp.sectigo.com/ | US | der | 472 b | whitelisted |
976 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
976 | firefox.exe | 151.101.1.140:443 | www.reddit.com | FASTLY | US | suspicious |
976 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
976 | firefox.exe | 35.241.9.150:443 | firefox.settings.services.mozilla.com | GOOGLE | US | suspicious |
976 | firefox.exe | 2.16.186.80:80 | r3.o.lencr.org | Akamai International B.V. | DE | whitelisted |
976 | firefox.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
976 | firefox.exe | 142.250.186.138:443 | safebrowsing.googleapis.com | GOOGLE | US | whitelisted |
976 | firefox.exe | 142.250.186.131:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
976 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | suspicious |
976 | firefox.exe | 54.163.121.204:443 | gql-realtime.reddit.com | AMAZON-AES | US | unknown |
976 | firefox.exe | 142.250.185.138:443 | fonts.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
www.reddit.com |
| whitelisted |
location.services.mozilla.com |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
reddit.map.fastly.net |
| whitelisted |
locprod2-elb-us-west-2.prod.mozaws.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
r3.o.lencr.org |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
— | — | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
— | — | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
— | — | Potentially Bad Traffic | ET INFO Commonly Abused Content Delivery Network Domain in DNS Lookup (btloader .com) |
— | — | Potentially Bad Traffic | ET INFO Commonly Abused Content Delivery Network Domain in DNS Lookup (btloader .com) |
— | — | Potentially Bad Traffic | ET INFO Commonly Abused Content Delivery Network Domain in DNS Lookup (btloader .com) |
976 | firefox.exe | Potentially Bad Traffic | ET INFO Observed Abused Content Delivery Network Domain (btloader .com in TLS SNI) |
— | — | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
— | — | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
— | — | Potentially Bad Traffic | ET INFO Commonly Abused Content Delivery Network Domain in DNS Lookup (btloader .com) |