| URL: | https://www.mumuplayer.com/ |
| Full analysis: | https://app.any.run/tasks/08548b2d-f4a1-4dc1-b96b-5ba465df3633 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | March 07, 2026, 10:26:19 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 757B751DD93CF08A1D2D64EC68F85ECA |
| SHA1: | 5BBEAEF09566243215DF1E512D1011047E9FA4E2 |
| SHA256: | 69472ED958C699507A3A5D72CE1C1D57E528AA87D6DD30EB709281DC52995CC8 |
| SSDEEP: | 3:N8DSL7VSLR:2OLiR |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 676 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | sc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 752 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5180 -prefsLen 39330 -prefMapHandle 5184 -prefMapSize 272981 -jsInitHandle 5188 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5196 -initialChannelId {6ced30dd-2188-43dd-bb47-50e7a6c1d4c8} -parentPid 8508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 9 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 1600 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3924 -prefsLen 45111 -prefMapHandle 3928 -prefMapSize 272981 -jsInitHandle 3932 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3940 -initialChannelId {a052b82d-35da-4b78-9876-b35d7a6ee675} -parentPid 8508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 1656 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | HyperVChecker.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2248 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3396 -prefsLen 37207 -prefMapHandle 3400 -prefMapSize 272981 -ipcHandle 3408 -initialChannelId {19eacfbd-f804-4fd3-9093-3685d11383fe} -parentPid 8508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8508" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 136.0 Modules
| |||||||||||||||
| 2788 | "C:\Users\admin\Downloads\MuMu_5.0.11_ECMBjdC.exe" | C:\Users\admin\Downloads\MuMu_5.0.11_ECMBjdC.exe | explorer.exe | ||||||||||||
User: admin Company: NetEase, Inc. Integrity Level: HIGH Description: MuMuPlayer Version: 2022 Modules
| |||||||||||||||
| 3700 | "C:\Users\admin\AppData\Local\Temp\7zF6B70AE4\HyperVChecker.exe" | C:\Users\admin\AppData\Local\Temp\7zF6B70AE4\HyperVChecker.exe | — | nemu-downloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3796 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5316 -prefsLen 45319 -prefMapHandle 5320 -prefMapSize 272981 -jsInitHandle 5092 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4980 -initialChannelId {5b8cdabe-359e-4ae8-89f3-e7ab41071ed4} -parentPid 8508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 4812 | "C:\Users\admin\Downloads\MuMu_5.0.11_ECMBjdC.exe" | C:\Users\admin\Downloads\MuMu_5.0.11_ECMBjdC.exe | — | explorer.exe | |||||||||||
User: admin Company: NetEase, Inc. Integrity Level: MEDIUM Description: MuMuPlayer Exit code: 3221226540 Version: 2022 Modules
| |||||||||||||||
| 5608 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3280 -prefsLen 31275 -prefMapHandle 3284 -prefMapSize 272981 -jsInitHandle 3288 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3296 -initialChannelId {7180d46b-e4a1-44c7-9624-0011373234e8} -parentPid 8508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| (PID) Process: | (5996) nemu-downloader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NemuServer |
| Operation: | write | Name: | uuid |
Value: 1224eb26-b0f7-483a-96d2-de0e4f9b5523 | |||
| (PID) Process: | (5996) nemu-downloader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NemuServer |
| Operation: | write | Name: | channel |
Value: gw-overseas12 | |||
| (PID) Process: | (5996) nemu-downloader.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NemuServer |
| Operation: | write | Name: | package |
Value: mumu | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 8508 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 8508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.bin | binary | |
MD5:A32698B29732B4520D98BEB933986C31 | SHA256:CC6759C4C6C29B3A2A7BF042365763B638B23C9D036496254C2CCAE60A5FAF90 | |||
| 8508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 8508 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:3134ED3F12E4F4F8643DB90043B0FD7B | SHA256:26E4F122034D7A03F6DA0E707799B09CBEEBDAF8D7A3133A1F7BD894AC72EEA1 | |||
| 8508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.js | text | |
MD5:37A7DC3A6FDE8830666710855BCBC7B9 | SHA256:83397F633A749037D44E35B9F41297F41E990FD564EC93F5B5BF324945C19D8F | |||
| 8508 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\activity-stream.contile.json | text | |
MD5:D38F884CC9E6A6F7A171C01E086E9B49 | SHA256:CF66BC607D582971B874A90CBEDBA813D88AF14E58B2BBF590A906E8EECFB833 | |||
| 8508 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\activity-stream.contile.json.tmp | text | |
MD5:D38F884CC9E6A6F7A171C01E086E9B49 | SHA256:CF66BC607D582971B874A90CBEDBA813D88AF14E58B2BBF590A906E8EECFB833 | |||
| 8508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 8508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:37A7DC3A6FDE8830666710855BCBC7B9 | SHA256:83397F633A749037D44E35B9F41297F41E990FD564EC93F5B5BF324945C19D8F | |||
| 8508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D | US | binary | 959 b | whitelisted |
8508 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | US | text | 90 b | whitelisted |
8508 | firefox.exe | GET | 200 | 151.101.193.91:443 | https://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?collection=url-parser-default-unknown-schemes-interventions&bucket=main&_expected=0 | US | text | 274 b | whitelisted |
8508 | firefox.exe | GET | 200 | 151.101.193.91:443 | https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/url-parser-default-unknown-schemes-interventions/changeset?_expected=1743513175300&_since=%221726769128879%22 | US | text | 1.76 Kb | whitelisted |
8508 | firefox.exe | GET | 200 | 151.101.193.91:443 | https://firefox.settings.services.mozilla.com/v1/ | US | text | 1.20 Kb | whitelisted |
8508 | firefox.exe | GET | 200 | 151.101.193.91:443 | https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/hijack-blocklists?_expected=1605801189258 | US | text | 1.68 Kb | whitelisted |
8508 | firefox.exe | GET | 200 | 151.101.193.91:443 | https://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?collection=hijack-blocklists&bucket=main&_expected=0 | US | text | 243 b | whitelisted |
8508 | firefox.exe | POST | 200 | 216.58.206.67:80 | http://o.pki.goog/we2 | US | binary | 278 b | whitelisted |
8508 | firefox.exe | POST | — | 216.58.206.67:80 | http://o.pki.goog/we2 | US | — | — | whitelisted |
8508 | firefox.exe | GET | 200 | 151.101.1.91:443 | https://contile.services.mozilla.com/v1/tiles | US | text | 5.16 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2600 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
6608 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5568 | SearchApp.exe | 2.23.227.215:443 | www.bing.com | AKAMAI-ASN1 | NL | whitelisted |
— | — | 172.66.2.5:80 | ocsp.digicert.com | CLOUDFLARENET | US | whitelisted |
— | — | 204.79.197.203:80 | oneocsp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
— | — | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8508 | firefox.exe | 151.101.193.91:443 | firefox.settings.services.mozilla.com | FASTLY | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
oneocsp.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
mozilla.map.fastly.net |
| whitelisted |
www.mumuplayer.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2600 | svchost.exe | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
8508 | firefox.exe | Potentially Bad Traffic | ET INFO PE EXE or DLL Windows file download HTTP |
8508 | firefox.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
7716 | MuMuDownloader.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7716 | MuMuDownloader.exe | Potentially Bad Traffic | ET INFO PE EXE or DLL Windows file download HTTP |
7716 | MuMuDownloader.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7716 | MuMuDownloader.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |