| URL: | http://d23iz4esrwkib6.cloudfront.net/lu/depot/ess/lda/logioptionsplus/0/logioptionsplus_files_uipak_and_echo_1.0/046d-uipak_x32.exe?/lu/depot/ess/lda/logioptionsplus/0/logioptionsplus_files_uipak_and_echo_1.0/046d-uipak_x32.exe%3f& |
| Full analysis: | https://app.any.run/tasks/72a8a316-0a7a-4ca6-88c5-ee02b43e21ce |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | March 12, 2024, 10:59:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | D3D278F893FEC0A0AC395211545C356F |
| SHA1: | FAEBE3CE38AAAAD92A6BCFAB8BCCF768AAF928A3 |
| SHA256: | 68FC9414E91BFAAF4A1F38AD8CFF134195BEB42F5376C927B1BE05DE190C299B |
| SSDEEP: | 3:N1KaXL5Wx7l/0jbWyAymPq0QOWw6iB6AM9VRNtMbN/f6WyAymPq0QOWw6iB6AM9t:CaXL5gmj2WZAW7s5bWZAW7s9C |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1352 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.3.191432188\1556394731" -childID 2 -isForBrowser -prefsHandle 2760 -prefMapHandle 2752 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 844 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ca998708-7aa2-481c-9b10-727c7fb0bcaf} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 2772 1658a840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1604 | "C:\Users\admin\Downloads\046d-uipak_x32.exe" | C:\Users\admin\Downloads\046d-uipak_x32.exe | firefox.exe | ||||||||||||
User: admin Company: Logitech Integrity Level: MEDIUM Exit code: 0 Version: 2.00 Modules
| |||||||||||||||
| 2128 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.5.392725849\31963820" -childID 4 -isForBrowser -prefsHandle 4244 -prefMapHandle 4248 -prefsLen 29208 -prefMapSize 244195 -jsInitHandle 844 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {5f2b9440-aac0-410e-9b32-9b54ef153851} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 4236 19de8280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2620 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.6.2036817305\720317292" -childID 5 -isForBrowser -prefsHandle 4228 -prefMapHandle 4232 -prefsLen 34335 -prefMapSize 244195 -jsInitHandle 844 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7f87ebdb-c738-4144-9b0c-80a375b0646f} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 3936 19de8e00 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2960 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.2.1226637491\138283366" -childID 1 -isForBrowser -prefsHandle 1900 -prefMapHandle 2008 -prefsLen 24491 -prefMapSize 244195 -jsInitHandle 844 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {54a8a611-b5b5-4df8-bdd3-719d1152a86c} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 1872 112643f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3000 | "C:\Users\admin\Downloads\046d-uipak_x32.exe" | C:\Users\admin\Downloads\046d-uipak_x32.exe | explorer.exe | ||||||||||||
User: admin Company: Logitech Integrity Level: MEDIUM Exit code: 0 Version: 2.00 Modules
| |||||||||||||||
| 3228 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.0.427012714\24213238" -parentBuildID 20230710165010 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ca116f6e-6e40-4876-ac17-e97afba15c23} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 1192 d6a76b0 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3460 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.1.1852132928\579868534" -parentBuildID 20230710165010 -prefsHandle 1404 -prefMapHandle 1400 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {aa3c40cf-5bee-4470-9170-9c59960d21c5} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 1416 d612a90 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3616 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3700.4.1253213177\955566672" -childID 3 -isForBrowser -prefsHandle 4056 -prefMapHandle 3876 -prefsLen 29208 -prefMapSize 244195 -jsInitHandle 844 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {92520476-184d-440e-9eff-90c629b175f1} 3700 "\\.\pipe\gecko-crash-server-pipe.3700" 4048 18f83560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3672 | "C:\Program Files\Mozilla Firefox\firefox.exe" "http://d23iz4esrwkib6.cloudfront.net/lu/depot/ess/lda/logioptionsplus/0/logioptionsplus_files_uipak_and_echo_1.0/046d-uipak_x32.exe?/lu/depot/ess/lda/logioptionsplus/0/logioptionsplus_files_uipak_and_echo_1.0/046d-uipak_x32.exe%3f&" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (3672) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: A9043C4F01000000 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 9FC23D4F01000000 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB |
| Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (3700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3700 | firefox.exe | C:\Users\admin\Downloads\046d-uipak_x32.ioycyVrg.exe.part | executable | |
MD5:677396BC34969DF36B6E321A2783D208 | SHA256:2F5F4F59E86E2C3B8577CD67DBD96A563AAA9C8F6057D4A8AB696A0362E7DAAD | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal | binary | |
MD5:6CF0B132127AE5423701994822399295 | SHA256:FB921AD301347043C132CCCACD08AEE1B46BB05461138ECBFBC1316A015744A0 | |||
| 3700 | firefox.exe | C:\Users\admin\Downloads\27PbgJUp.exe.part | executable | |
MD5:677396BC34969DF36B6E321A2783D208 | SHA256:2F5F4F59E86E2C3B8577CD67DBD96A563AAA9C8F6057D4A8AB696A0362E7DAAD | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3700 | firefox.exe | GET | 200 | 18.155.139.26:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/ess/lda/logioptionsplus/0/logioptionsplus_files_uipak_and_echo_1.0/046d-uipak_x32.exe?/lu/depot/ess/lda/logioptionsplus/0/logioptionsplus_files_uipak_and_echo_1.0/046d-uipak_x32.exe%3f& | unknown | executable | 312 Kb | unknown |
3700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
3700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
3700 | firefox.exe | POST | 200 | 216.58.206.67:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | unknown |
3700 | firefox.exe | POST | 200 | 184.24.77.76:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3700 | firefox.exe | POST | 200 | 184.24.77.76:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3700 | firefox.exe | POST | 200 | 184.24.77.76:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3700 | firefox.exe | POST | 200 | 216.58.206.67:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | unknown |
3700 | firefox.exe | POST | 200 | 184.24.77.76:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3700 | firefox.exe | POST | 200 | 216.58.206.67:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3700 | firefox.exe | 18.155.139.26:80 | d23iz4esrwkib6.cloudfront.net | AMAZON-02 | US | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3700 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
3700 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
3700 | firefox.exe | 34.117.188.166:443 | spocs.getpocket.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
3700 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
3700 | firefox.exe | 184.24.77.76:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
d23iz4esrwkib6.cloudfront.net |
| shared |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
firefox.settings.services.mozilla.com |
| whitelisted |
prod.ads.prod.webservices.mozgcp.net |
| unknown |
prod.remote-settings.prod.webservices.mozgcp.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3700 | firefox.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
3700 | firefox.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |