File name:

Endermanch@WinlockerVB6Blacksod.exe

Full analysis: https://app.any.run/tasks/f033355c-3188-405c-b428-a41ac1b6e577
Verdict: Malicious activity
Analysis date: January 15, 2021, 21:54:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

DBFBF254CFB84D991AC3860105D66FC6

SHA1:

893110D8C8451565CAA591DDFCCF92869F96C242

SHA256:

68B0E1932F3B4439865BE848C2D592D5174DBDBAAB8F66104A0E5B28C928EE0C

SSDEEP:

49152:6kAG2QGTC5xvMdgpdb1KRHGepUu2cGbqPs9+q2HRPTnFVSLE:6kAjQGTCnvMmpYQqPNRPTnF4Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2076)
    • Loads the Task Scheduler DLL interface

      • MsiExec.exe (PID: 2780)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2076)
    • Changes the login/logoff helper path in the registry

      • msiexec.exe (PID: 1708)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2076)
      • msiexec.exe (PID: 1708)
    • Creates files in the user directory

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2076)
      • MsiExec.exe (PID: 2616)
    • Reads Environment values

      • MsiExec.exe (PID: 2616)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2076)
    • Starts Microsoft Installer

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2076)
    • Creates files in the Windows directory

      • MsiExec.exe (PID: 2780)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 1708)
    • Drops a file that was compiled in debug mode

      • msiexec.exe (PID: 1708)
    • Executed via COM

      • explorer.exe (PID: 3212)
      • DllHost.exe (PID: 3440)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 1708)
      • iexplore.exe (PID: 2532)
      • firefox.exe (PID: 1520)
      • firefox.exe (PID: 2188)
    • Creates files in the program directory

      • msiexec.exe (PID: 1708)
      • firefox.exe (PID: 1520)
    • Manual execution by user

      • iexplore.exe (PID: 2532)
      • explorer.exe (PID: 2540)
      • firefox.exe (PID: 2188)
    • Changes internet zones settings

      • iexplore.exe (PID: 2532)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1120)
    • Reads CPU info

      • firefox.exe (PID: 1520)
    • Creates files in the user directory

      • firefox.exe (PID: 1520)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (78.5)
.exe | Win32 Executable (generic) (11.3)
.exe | Generic Win/DOS Executable (5)
.exe | DOS Executable Generic (5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:09:23 15:36:22+02:00
PEType: PE32
LinkerVersion: 9
CodeSize: 1034240
InitializedDataSize: 428544
UninitializedDataSize: -
EntryPoint: 0xc684c
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: Debug
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Windows
FileDescription: This installer database contains the logic and data required to install Error file remover.
FileVersion: 1.0.0.0
InternalName: Error file remover
LegalCopyright: Copyright (C) 2016 Windows
OriginalFileName: Error file remover.exe
ProductName: Error file remover
ProductVersion: 1.0.0.0

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 23-Sep-2015 13:36:22
Detected languages:
  • English - United States
Debug artifacts:
  • C:\Users\victor\Desktop\BRANCH\win\Release\stubs\x86\ExternalUi.pdb
CompanyName: Windows
FileDescription: This installer database contains the logic and data required to install Error file remover.
FileVersion: 1.0.0.0
InternalName: Error file remover
LegalCopyright: Copyright (C) 2016 Windows
OriginalFileName: Error file remover.exe
ProductName: Error file remover
ProductVersion: 1.0.0.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000E8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 23-Sep-2015 13:36:22
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x000FC61C
0x000FC800
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.62583
.rdata
0x000FE000
0x0003BA7A
0x0003BC00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.42392
.data
0x0013A000
0x00009D08
0x00003000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.36397
.rsrc
0x00144000
0x00011AC8
0x00011C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.48512
.reloc
0x00156000
0x00018032
0x00018200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
5.23129

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.221
1915
Latin 1 / Western European
English - United States
RT_MANIFEST
2
3.1591
9640
Latin 1 / Western European
English - United States
RT_ICON
3
3.46873
4264
Latin 1 / Western European
English - United States
RT_ICON
4
3.54157
2440
Latin 1 / Western European
English - United States
RT_ICON
5
4.01317
1128
Latin 1 / Western European
English - United States
RT_ICON
9
3.37783
1116
Latin 1 / Western European
English - United States
RT_STRING
10
3.35254
1888
Latin 1 / Western European
English - United States
RT_STRING
11
3.31743
760
Latin 1 / Western European
English - United States
RT_STRING
12
3.23118
1432
Latin 1 / Western European
English - United States
RT_STRING
13
3.34086
996
Latin 1 / Western European
English - United States
RT_STRING

Imports

ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
KERNEL32.dll
MPR.dll
MSIMG32.dll
OLEAUT32.dll
SHELL32.dll
SHLWAPI.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
16
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start endermanch@winlockervb6blacksod.exe msiexec.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs iexplore.exe iexplore.exe no specs explorer.exe no specs explorer.exe no specs PhotoViewer.dll no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe

Process information

PID
CMD
Path
Indicators
Parent process
1120"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2532 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1328"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1520.20.1222993846\1815648604" -childID 3 -isForBrowser -prefsHandle 3672 -prefMapHandle 3688 -prefsLen 7632 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1520 "\\.\pipe\gecko-crash-server-pipe.1520" 3704 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
1520"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
1708C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2076"C:\Users\admin\AppData\Local\Temp\Endermanch@WinlockerVB6Blacksod.exe" C:\Users\admin\AppData\Local\Temp\Endermanch@WinlockerVB6Blacksod.exe
explorer.exe
User:
admin
Company:
Windows
Integrity Level:
MEDIUM
Description:
This installer database contains the logic and data required to install Error file remover.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\endermanch@winlockervb6blacksod.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2188"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
2532"C:\Program Files\Internet Explorer\iexplore.exe" C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2540"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2552"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1520.3.509127440\1939689789" -childID 1 -isForBrowser -prefsHandle 1728 -prefMapHandle 1724 -prefsLen 1 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1520 "\\.\pipe\gecko-crash-server-pipe.1520" 1748 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
2616C:\Windows\system32\MsiExec.exe -Embedding D032B6C95903A8CE43DD22D0DF24CF85C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 789
Read events
2 439
Write events
338
Delete events
12

Modification events

(PID) Process:(1708) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
AC060000BA6BF80789EBD601
(PID) Process:(1708) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
8713A8AA246C25BBD7DD4B8CD56964C44AAE61B3DD6561A7A36B5879A8FC6765
(PID) Process:(1708) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1708) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
Operation:writeName:(default)
Value:
C:\Windows\Installer\144825.ipi
(PID) Process:(1708) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(1708) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\144826.rbs
Value:
30862217
(PID) Process:(1708) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\144826.rbsLow
Value:
157314768
(PID) Process:(1708) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D45F152E5BE7289449F90D588F84BD5D
Operation:writeName:2E4D254C42ED6B845B3CCA2B040A6160
Value:
C:\Program Files\Windows\Error file remover\Windows Logoff Sound.wav
(PID) Process:(1708) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2ED206DB688193B489E86537451F75D7
Operation:writeName:2E4D254C42ED6B845B3CCA2B040A6160
Value:
C:\Program Files\Windows\Error file remover\fatalerror.exe
(PID) Process:(1708) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4FEC4D8CE9091D3499C19390B8C387CF
Operation:writeName:2E4D254C42ED6B845B3CCA2B040A6160
Value:
02:\Software\Caphyon\Advanced Installer\LZMA\{C452D4E2-DE24-48B6-B5C3-ACB240A01606}\1.0.0.0\AI_ExePath
Executable files
7
Suspicious files
47
Text files
39
Unknown types
39

Dropped files

PID
Process
Filename
Type
1708msiexec.exeC:\Windows\Installer\MSI4BEC.tmp
MD5:
SHA256:
1708msiexec.exeC:\Windows\Installer\MSI4CB8.tmp
MD5:
SHA256:
1708msiexec.exeC:\Windows\Installer\MSI4CC9.tmp
MD5:
SHA256:
1708msiexec.exeC:\Windows\Installer\MSI4CD9.tmp
MD5:
SHA256:
1708msiexec.exeC:\Windows\Installer\MSI4CF9.tmp
MD5:
SHA256:
1708msiexec.exeC:\Windows\Installer\MSI4D49.tmp
MD5:
SHA256:
1708msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFD7A4ECCAC44BF427.TMP
MD5:
SHA256:
1708msiexec.exeC:\Windows\Installer\MSI4D99.tmp
MD5:
SHA256:
1708msiexec.exeC:\Windows\Installer\MSI4DB9.tmp
MD5:
SHA256:
1708msiexec.exeC:\Windows\Installer\MSI4DCA.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
16
DNS requests
53
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1520
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2616
MsiExec.exe
POST
402
3.227.220.164:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
1520
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2616
MsiExec.exe
POST
402
3.227.220.164:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
2616
MsiExec.exe
POST
402
3.227.220.164:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
2616
MsiExec.exe
POST
402
3.227.220.164:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
2616
MsiExec.exe
POST
402
3.227.220.164:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
2616
MsiExec.exe
POST
402
3.227.220.164:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
2532
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
2616
MsiExec.exe
POST
402
3.227.220.164:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1520
firefox.exe
34.107.221.82:80
detectportal.firefox.com
US
whitelisted
1520
firefox.exe
35.162.52.193:443
push.services.mozilla.com
Amazon.com, Inc.
US
unknown
1520
firefox.exe
65.9.58.32:443
snippets.cdn.mozilla.net
AT&T Services, Inc.
US
suspicious
65.9.58.32:443
snippets.cdn.mozilla.net
AT&T Services, Inc.
US
suspicious
1520
firefox.exe
65.9.58.73:443
content-signature-2.cdn.mozilla.net
AT&T Services, Inc.
US
suspicious
1520
firefox.exe
65.9.58.62:443
firefox.settings.services.mozilla.com
AT&T Services, Inc.
US
unknown
1520
firefox.exe
34.216.80.151:443
shavar.services.mozilla.com
Amazon.com, Inc.
US
unknown
1520
firefox.exe
34.213.158.239:443
search.services.mozilla.com
Amazon.com, Inc.
US
unknown
2532
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2616
MsiExec.exe
3.227.220.164:80
collect.installeranalytics.com
US
malicious

DNS requests

Domain
IP
Reputation
collect.installeranalytics.com
  • 3.227.220.164
  • 35.171.222.234
malicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
whitelisted
search.services.mozilla.com
  • 34.213.158.239
  • 52.38.202.57
  • 35.167.169.250
whitelisted
search.r53-2.services.mozilla.com
  • 35.167.169.250
  • 52.38.202.57
  • 34.213.158.239
whitelisted
push.services.mozilla.com
  • 35.162.52.193
whitelisted
autopush.prod.mozaws.net
  • 35.162.52.193
whitelisted
snippets.cdn.mozilla.net
  • 65.9.58.32
  • 65.9.58.34
  • 65.9.58.51
  • 65.9.58.121
whitelisted

Threats

PID
Process
Class
Message
1052
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .cloud TLD
1052
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .cloud TLD
No debug info