| URL: | https://malwarebytes.com |
| Full analysis: | https://app.any.run/tasks/ed612f8d-7cfd-4bda-9a92-00337ff508a2 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | October 22, 2023, 11:50:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 45325956ABBA8D049F4161DFA2661C64 |
| SHA1: | 474DF96ED31D74AC57FF4523EA65265401EE7EE4 |
| SHA256: | 5F4E8AE839F5E043A5268684DC98B482342C873E69B28F46FB4F17E89D330549 |
| SSDEEP: | 3:N8nzyT:2nGT |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 592 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://malwarebytes.com | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 604 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.6.1834680012\1913868419" -childID 5 -isForBrowser -prefsHandle 4144 -prefMapHandle 4156 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c7f613f6-9d55-434f-ad71-2366df731675} 592 "\\.\pipe\gecko-crash-server-pipe.592" 4064 198d8110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 760 | "C:\Users\admin\Downloads\MBSetup.exe" | C:\Users\admin\Downloads\MBSetup.exe | explorer.exe | ||||||||||||
User: admin Company: Malwarebytes Integrity Level: HIGH Description: Malwarebytes Setup Exit code: 1 Version: 4.6.0.352 Modules
| |||||||||||||||
| 852 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.4.481525566\1392199420" -childID 3 -isForBrowser -prefsHandle 3560 -prefMapHandle 3732 -prefsLen 34332 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2e4c0378-a246-4c73-935d-ba241ef2c5d9} 592 "\\.\pipe\gecko-crash-server-pipe.592" 3564 135f59b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 948 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.9.205545885\1952482477" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 4536 -prefMapHandle 4540 -prefsLen 34499 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {98eb9b4e-19c8-477c-9c02-a7727a1c7fd9} 592 "\\.\pipe\gecko-crash-server-pipe.592" 4620 18d49bc0 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 1 Version: 115.0.2 Modules
| |||||||||||||||
| 2128 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.3.1948410886\732144727" -childID 2 -isForBrowser -prefsHandle 2860 -prefMapHandle 2856 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c5d78ec6-f5e3-4354-97e0-1f908279a930} 592 "\\.\pipe\gecko-crash-server-pipe.592" 2876 16651e00 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2200 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.8.1356595037\1004478411" -parentBuildID 20230710165010 -prefsHandle 4548 -prefMapHandle 4556 -prefsLen 34499 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8e2e622c-ffdd-4dc1-8271-2212108305ca} 592 "\\.\pipe\gecko-crash-server-pipe.592" 4532 1aa4bba0 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 1 Version: 115.0.2 Modules
| |||||||||||||||
| 2460 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.2.1922628499\1077684472" -childID 1 -isForBrowser -prefsHandle 2052 -prefMapHandle 2044 -prefsLen 24491 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7363a917-ddc4-4745-9f92-d8d463f01a77} 592 "\\.\pipe\gecko-crash-server-pipe.592" 2064 10c71840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2820 | "C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe" | C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe | services.exe | ||||||||||||
User: SYSTEM Company: Malwarebytes Integrity Level: SYSTEM Description: Malwarebytes Installer Service Exit code: 0 Version: 4.0.0.538 Modules
| |||||||||||||||
| 2936 | "C:\Users\admin\Downloads\MBSetup.exe" | C:\Users\admin\Downloads\MBSetup.exe | explorer.exe | ||||||||||||
User: admin Company: Malwarebytes Integrity Level: HIGH Description: Malwarebytes Setup Exit code: 0 Version: 4.6.0.352 Modules
| |||||||||||||||
| (PID) Process: | (3820) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 2166C0A101000000 | |||
| (PID) Process: | (592) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 044CC1A101000000 | |||
| (PID) Process: | (592) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (592) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (592) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (592) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (592) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (592) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (592) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (592) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: D14E5F3C23B0D901 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-wal | binary | |
MD5:BA99A79627F03A2D5B5B9D97A12F9411 | SHA256:1994C300C2AAA8EF7B5A92D9B7098200E0BBDB65BB9B4651F9796E7816014A30 | |||
| 592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db | binary | |
MD5:11CF2BB29260EC5870F466C674A9FD7A | SHA256:48C86F58C6CACBC1983820509DBB91D53EF08D8AF6E6EDA05DA9A166916B123E | |||
| 592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal | binary | |
MD5:F4C02692EE8331409551A78EB696E39F | SHA256:A818EFD8FADB61372E816B4C9D44FBDCE2F2ECFD9BD5827496B7ABB3951BC30C | |||
| 592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
592 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
592 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
592 | firefox.exe | POST | 200 | 142.250.185.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
592 | firefox.exe | POST | 200 | 2.16.202.115:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
592 | firefox.exe | POST | 200 | 142.250.185.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
592 | firefox.exe | POST | 200 | 2.16.202.115:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
592 | firefox.exe | POST | 200 | 2.16.202.115:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
592 | firefox.exe | POST | 200 | 2.16.202.115:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
592 | firefox.exe | POST | 200 | 13.224.191.223:80 | http://ocsp.r2m02.amazontrust.com/ | unknown | binary | 471 b | unknown |
592 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
592 | firefox.exe | 52.222.214.121:443 | malwarebytes.com | AMAZON-02 | US | unknown |
592 | firefox.exe | 172.217.16.202:443 | safebrowsing.googleapis.com | — | — | whitelisted |
592 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
592 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
592 | firefox.exe | 34.117.65.55:443 | push.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
592 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
592 | firefox.exe | 107.20.123.120:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
592 | firefox.exe | 142.250.185.227:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
592 | firefox.exe | 2.16.202.115:80 | r3.o.lencr.org | Akamai International B.V. | NL | unknown |
592 | firefox.exe | 18.66.97.80:443 | www.malwarebytes.com | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
malwarebytes.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
r3.o.lencr.org |
| shared |
Process | Message |
|---|---|
mbamtray.exe | QAxBase::setControl: requested control {F36AD0D0-B5F0-4C69-AF08-603D177FEF0E} could not be instantiated
|
mbamtray.exe | void __thiscall _MBScanControllerSlots::OnControllerException(int,const class QString &,const class QString &,const class QString &) Controller error, code: -2147467259 source: "" description: "" help: ""
|