File name:

downloader.exe

Full analysis: https://app.any.run/tasks/9f7b503a-6881-474e-ae29-a09f355883a6
Verdict: Malicious activity
Analysis date: January 28, 2025, 00:06:21
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
discord
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

A09723171BA6D58CBDC4D2E3B0290E30

SHA1:

09C246F586437FA1EE0B0EB8A89B014160959C8D

SHA256:

5B81767CCA659CFDC321DE444E20CF54E3E965FBD56BBD95E07DFE014E3EA449

SSDEEP:

98304:nDrQcjepueG9bQ0y3gWOfvIsGRr5KOr+DEGriR5VSsFTcuaBeF3RAPXJIy6Fi8v4:DH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 3124)
    • The DLL Hijacking

      • msedgewebview2.exe (PID: 4604)
    • Scans artifacts that could help determine the target

      • msedgewebview2.exe (PID: 1576)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • downloader.exe (PID: 5488)
      • downloader.exe (PID: 7128)
    • Process drops legitimate windows executable

      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 488)
      • MicrosoftEdgeUpdate.exe (PID: 3124)
      • MicrosoftEdgeWebview_X64_132.0.2957.127.exe (PID: 5568)
      • setup.exe (PID: 7088)
      • downloader.exe (PID: 7128)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 3124)
    • Executable content was dropped or overwritten

      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 488)
      • MicrosoftEdgeUpdate.exe (PID: 3124)
      • MicrosoftEdgeWebview_X64_132.0.2957.127.exe (PID: 5568)
      • setup.exe (PID: 7088)
      • downloader.exe (PID: 7128)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6280)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5872)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6328)
      • MicrosoftEdgeUpdate.exe (PID: 6656)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 3124)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 3124)
      • MicrosoftEdgeUpdate.exe (PID: 308)
      • msedgewebview2.exe (PID: 1576)
      • downloader.exe (PID: 7128)
    • Application launched itself

      • setup.exe (PID: 7088)
      • MicrosoftEdgeUpdate.exe (PID: 308)
      • msedgewebview2.exe (PID: 1576)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 308)
    • Searches for installed software

      • setup.exe (PID: 7088)
      • msedgewebview2.exe (PID: 1576)
    • Creates a software uninstall entry

      • setup.exe (PID: 7088)
  • INFO

    • Reads the computer name

      • downloader.exe (PID: 5488)
      • MicrosoftEdgeUpdate.exe (PID: 6656)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6280)
      • MicrosoftEdgeUpdate.exe (PID: 3124)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5872)
      • MicrosoftEdgeUpdate.exe (PID: 5788)
      • MicrosoftEdgeUpdate.exe (PID: 5912)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6328)
      • MicrosoftEdgeUpdate.exe (PID: 308)
      • MicrosoftEdgeWebview_X64_132.0.2957.127.exe (PID: 5568)
      • setup.exe (PID: 7088)
      • MicrosoftEdgeUpdate.exe (PID: 4952)
      • downloader.exe (PID: 7128)
      • msedgewebview2.exe (PID: 1576)
      • msedgewebview2.exe (PID: 4604)
      • msedgewebview2.exe (PID: 5888)
    • Checks supported languages

      • downloader.exe (PID: 5488)
      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 488)
      • MicrosoftEdgeUpdate.exe (PID: 6656)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6280)
      • MicrosoftEdgeUpdate.exe (PID: 3124)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5872)
      • MicrosoftEdgeUpdate.exe (PID: 5788)
      • MicrosoftEdgeUpdate.exe (PID: 5912)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6328)
      • MicrosoftEdgeWebview_X64_132.0.2957.127.exe (PID: 5568)
      • setup.exe (PID: 7088)
      • setup.exe (PID: 6984)
      • MicrosoftEdgeUpdate.exe (PID: 308)
      • MicrosoftEdgeUpdate.exe (PID: 4952)
      • msedgewebview2.exe (PID: 1576)
      • msedgewebview2.exe (PID: 3296)
      • downloader.exe (PID: 7128)
      • msedgewebview2.exe (PID: 4604)
      • msedgewebview2.exe (PID: 5888)
      • msedgewebview2.exe (PID: 5916)
      • msedgewebview2.exe (PID: 5588)
    • Manual execution by a user

      • firefox.exe (PID: 6744)
      • downloader.exe (PID: 7128)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 6764)
    • Application launched itself

      • firefox.exe (PID: 6764)
      • firefox.exe (PID: 6744)
    • Create files in a temporary directory

      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 488)
      • MicrosoftEdgeUpdate.exe (PID: 3124)
      • msedgewebview2.exe (PID: 1576)
    • The sample compiled with english language support

      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 488)
      • MicrosoftEdgeUpdate.exe (PID: 3124)
      • MicrosoftEdgeWebview_X64_132.0.2957.127.exe (PID: 5568)
      • setup.exe (PID: 7088)
      • downloader.exe (PID: 7128)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 3124)
      • MicrosoftEdgeWebview_X64_132.0.2957.127.exe (PID: 5568)
      • setup.exe (PID: 6984)
      • setup.exe (PID: 7088)
      • MicrosoftEdgeUpdate.exe (PID: 308)
      • msedgewebview2.exe (PID: 1576)
      • msedgewebview2.exe (PID: 5888)
      • msedgewebview2.exe (PID: 3296)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 5788)
      • MicrosoftEdgeUpdate.exe (PID: 4952)
      • msedgewebview2.exe (PID: 1576)
      • downloader.exe (PID: 7128)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 5788)
      • MicrosoftEdgeUpdate.exe (PID: 4952)
      • msedgewebview2.exe (PID: 1576)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 3124)
      • setup.exe (PID: 7088)
      • msedgewebview2.exe (PID: 5588)
      • msedgewebview2.exe (PID: 1576)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 5788)
      • MicrosoftEdgeUpdate.exe (PID: 308)
      • MicrosoftEdgeUpdate.exe (PID: 4952)
      • downloader.exe (PID: 7128)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 308)
      • msedgewebview2.exe (PID: 1576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (57.6)
.exe | Win64 Executable (generic) (36.9)
.exe | Generic Win/DOS Executable (2.6)
.exe | DOS Executable Generic (2.6)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:01:08 20:06:46+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.41
CodeSize: 5515776
InitializedDataSize: 1814528
UninitializedDataSize: -
EntryPoint: 0x523d68
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.1.0.0
ProductVersionNumber: 0.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
ProductVersion: 1.1.3
ProductName: cirno-downloader
FileDescription: cirno-downloader
FileVersion: 1.1.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
167
Monitored processes
34
Malicious processes
9
Suspicious processes
2

Behavior graph

Click at the process to see the details
start downloader.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs microsoftedgewebview2runtimeinstallerx64.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgewebview_x64_132.0.2957.127.exe setup.exe setup.exe no specs microsoftedgeupdate.exe downloader.exe msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
308"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.43
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
488"C:\Users\admin\Downloads\MicrosoftEdgeWebView2RuntimeInstallerX64.exe" C:\Users\admin\Downloads\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
firefox.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.195.43
Modules
Images
c:\users\admin\downloads\microsoftedgewebview2runtimeinstallerx64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1576"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\132.0.2957.127\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=downloader.exe --webview-exe-version=1.1.3 --user-data-dir="C:\Users\admin\AppData\Local\andreh.downloader.app\EBWebView" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --autoplay-policy=no-user-gesture-required --disable-features=msWebOOUI,msPdfOOUI,msSmartScreenProtection --lang=en-US --mojo-named-platform-channel-pipe=7128.3032.6939030428279415697C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\132.0.2957.127\msedgewebview2.exe
downloader.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Version:
132.0.2957.127
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\132.0.2957.127\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\132.0.2957.127\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2956"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6352 -childID 8 -isForBrowser -prefsHandle 6384 -prefMapHandle 6436 -prefsLen 32060 -prefMapSize 244583 -jsInitHandle 1396 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4d72a915-e8ca-431d-b872-c12bd2e45a1f} 6764 "\\.\pipe\gecko-crash-server-pipe.6764" 22b880bff50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
3124C:\Users\admin\AppData\Local\Temp\EU2593.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=Prefers"C:\Users\admin\AppData\Local\Temp\EU2593.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebView2RuntimeInstallerX64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.43
Modules
Images
c:\users\admin\appdata\local\temp\eu2593.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
3288"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4340 -childID 2 -isForBrowser -prefsHandle 4332 -prefMapHandle 4328 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1396 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a0a70fb6-e502-4ea7-84a0-75c61c09cc37} 6764 "\\.\pipe\gecko-crash-server-pipe.6764" 22b8b052850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3296C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\132.0.2957.127\msedgewebview2.exe --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Local\andreh.downloader.app\EBWebView /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\andreh.downloader.app\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=132.0.6834.111 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\132.0.2957.127\msedgewebview2.exe --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=132.0.2957.127 --initial-client-data=0x184,0x188,0x18c,0x160,0x194,0x7ff821f6b078,0x7ff821f6b084,0x7ff821f6b090C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\132.0.2957.127\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Version:
132.0.2957.127
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\132.0.2957.127\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\132.0.2957.127\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4604"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\132.0.2957.127\msedgewebview2.exe" --type=gpu-process --string-annotations --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\andreh.downloader.app\EBWebView" --webview-exe-name=downloader.exe --webview-exe-version=1.1.3 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=1800,i,7211913981184410430,493769639842672744,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=1784 /prefetch:2C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\132.0.2957.127\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Version:
132.0.2957.127
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\132.0.2957.127\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\132.0.2957.127\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4952"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuNDMiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuNDMiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7Nzk0NzY2OTQtRUZGMi00OEU2LUJERDUtRDY0MkFBRUZCQjNGfSIgdXNlcmlkPSJ7NTRFMDlGNzktNjMwQi00Nzc1LUE4RDgtQzk3NzBFMUFENUJFfSIgaW5zdGFsbHNvdXJjZT0ib2ZmbGluZSIgcmVxdWVzdGlkPSJ7NTU3Q0ExNjItNTI1Ni00NkI3LUFCRDEtOUY0MDdEOUQzMzQzfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBsb2dpY2FsX2NwdXM9IjQiIHBoeXNtZW1vcnk9IjQiIGRpc2tfdHlwZT0iMiIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iMTAuMC4xOTA0NS40MDQ2IiBzcD0iIiBhcmNoPSJ4NjQiIHByb2R1Y3RfdHlwZT0iNDgiIGlzX3dpcD0iMCIgaXNfaW5fbG9ja2Rvd25fbW9kZT0iMCIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9IkRFTEwiIHByb2R1Y3RfbmFtZT0iREVMTCIvPjxleHAgZXRhZz0iJnF1b3Q7cjQ1MnQxK2syVGdxL0hYemp2Rk5CUmhvcEJXUjlzYmpYeHFlVURIOXVYMD0mcXVvdDsiLz48YXBwIGFwcGlkPSJ7RjMwMTcyMjYtRkUyQS00Mjk1LThCREYtMDBDM0E5QTdFNEM1fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMTMyLjAuMjk1Ny4xMjciIGxhbmc9ImVuIiBicmFuZD0iIiBjbGllbnQ9IiIgZXhwZXJpbWVudHM9ImNvbnNlbnQ9ZmFsc2UiIGluc3RhbGxhZ2U9Ii0xIiBpbnN0YWxsZGF0ZT0iLTEiPjx1cGRhdGVjaGVjay8-PGV2ZW50IGV2ZW50dHlwZT0iOSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTQxMDQ3NTgxNzciIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSIxNDEwNDkwOTkyOCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxldmVudCBldmVudHR5cGU9IjEiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjE0MTE2NDczNTA3IiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iNiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTQxMzQxMzA5MDQiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIxOTY3NTciIHN5c3RlbV91cHRpbWVfdGlja3M9IjE0NTU4MzI5NzYyIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIiBkb3dubG9hZGVkPSIxNzcwNzgzNTIiIHRvdGFsPSIxNzcwNzgzNTIiIHBhY2thZ2VfY2FjaGVfcmVzdWx0PSIxIiBpbnN0YWxsX3RpbWVfbXM9IjQyNDIwIi8-PC9hcHA-PC9yZXF1ZXN0PgC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.43
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
5128"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4728 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4928 -prefMapHandle 4812 -prefsLen 36588 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d822eb12-d076-493d-841b-e5e379af698f} 6764 "\\.\pipe\gecko-crash-server-pipe.6764" 22b8d099110 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
Total events
32 251
Read events
30 661
Write events
1 520
Delete events
70

Modification events

(PID) Process:(6764) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(6764) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(3124) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(3124) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(3124) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(3124) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.43
(PID) Process:(3124) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(3124) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.43
(PID) Process:(3124) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Edge Update
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.43\MicrosoftEdgeUpdateCore.exe"
(PID) Process:(3124) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:edgeupdate_task_name_c
Value:
MicrosoftEdgeUpdateTaskUserS-1-5-21-1693682860-607145093-2874071422-1001Core{E6BFB298-3F54-412B-8370-7235012D8A80}
Executable files
215
Suspicious files
395
Text files
76
Unknown types
3

Dropped files

PID
Process
Filename
Type
6764firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
6764firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.tmpbinary
MD5:F759EB25271E6A6F0A3500520813E5FE
SHA256:015E515D432DD64FDC9502ABE9C723EEF544E7AF11C36BDFE8B38412597CA1EC
6764firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\protections.sqlite-journalbinary
MD5:55D173DF47EDF1A14905D8BC8A5E19B8
SHA256:40428616D91D37DE55953CE5E824796B0AAD961576A033E4889F54D83FF43914
5488downloader.exeC:\Users\admin\Desktop\dbbinary
MD5:91DB85C6C189D3076FDF10B68284E1BB
SHA256:0AA6A400D8372BB2E3010B4813196C5D04849FDC433CB9945896536BA71716B5
6764firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.binbinary
MD5:C95DDC2B1A525D1A243E4C294DA2F326
SHA256:3A5919E086BFB31E36110CF636D2D5109EB51F2C410B107F126126AB25D67363
6764firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
6764firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
6764firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6764firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6764firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:5C9C9C36654DC4C46EE7EA803B349FD0
SHA256:953FB085C01C5AB250F1773568B782E7E325815F2FD5224BEA956CC9E8B1A72C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
195
TCP/UDP connections
180
DNS requests
179
Threats
17

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
312 b
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
6764
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
6764
firefox.exe
POST
200
2.16.241.15:80
http://r10.o.lencr.org/
DE
binary
504 b
whitelisted
6764
firefox.exe
POST
200
142.250.185.67:80
http://o.pki.goog/wr2
US
binary
472 b
whitelisted
6764
firefox.exe
POST
200
2.16.241.15:80
http://r11.o.lencr.org/
DE
binary
504 b
whitelisted
6764
firefox.exe
POST
200
2.16.241.15:80
http://r11.o.lencr.org/
DE
binary
504 b
whitelisted
6764
firefox.exe
POST
200
142.250.185.67:80
http://o.pki.goog/s/wr3/jLM
US
binary
472 b
whitelisted
6764
firefox.exe
POST
200
2.16.241.15:80
http://r10.o.lencr.org/
DE
binary
504 b
whitelisted
6764
firefox.exe
POST
200
142.250.185.67:80
http://o.pki.goog/s/wr3/3cs
US
binary
472 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
2.21.65.132:443
www.bing.com
Akamai International B.V.
NL
whitelisted
1176
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
2.23.242.9:443
go.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
6764
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.21.65.132
  • 2.21.65.154
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.68
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.0
  • 20.190.159.2
  • 20.190.159.4
  • 20.190.159.73
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
  • 184.30.131.245
whitelisted
go.microsoft.com
  • 2.23.242.9
  • 184.28.89.167
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
whitelisted
example.org
  • 96.7.128.192
  • 23.215.0.133
  • 23.215.0.132
  • 96.7.128.186
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted

Threats

PID
Process
Class
Message
6764
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
6764
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
6764
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
6764
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
6764
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
6764
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
6764
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
5888
msedgewebview2.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
5888
msedgewebview2.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
5888
msedgewebview2.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
Process
Message
downloader.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
downloader.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\andreh.downloader.app directory exists )
downloader.exe
Warning: AddWebResourceRequestedFilter without SourceKind parameter is deprecated! It does not behave as expected for iframes.Please use AddWebResourceRequestedFilterWithRequestSourceKinds instead. For more information, please see https://go.microsoft.com/fwlink/?linkid=2286319
downloader.exe
Warning: AddWebResourceRequestedFilter without SourceKind parameter is deprecated! It does not behave as expected for iframes.Please use AddWebResourceRequestedFilterWithRequestSourceKinds instead. For more information, please see https://go.microsoft.com/fwlink/?linkid=2286319