analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://www.wahh-app.com

Full analysis: https://app.any.run/tasks/bea37773-acb2-454d-a141-33b8de96ec3e
Verdict: Malicious activity
Analysis date: March 14, 2019, 21:45:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

2DDEC79F7A5267322C1F5B9A7B4EC34B

SHA1:

920189D1EA20DE069AD0097B3F21B811B759F789

SHA256:

788CF4DBF386C57F65EF9E059CE4B8BDAD0A129A2F5FC680263F7B05B016703B

SSDEEP:

3:N1KJS4Q8g:Cc4c

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • firefox.exe (PID: 2800)
  • INFO

    • Reads CPU info

      • firefox.exe (PID: 2800)
      • firefox.exe (PID: 2264)
      • firefox.exe (PID: 2524)
      • firefox.exe (PID: 3216)
    • Application launched itself

      • firefox.exe (PID: 2800)
    • Creates files in the user directory

      • firefox.exe (PID: 2800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
4
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe firefox.exe firefox.exe firefox.exe

Process information

PID
CMD
Path
Indicators
Parent process
2800"C:\Program Files\Mozilla Firefox\firefox.exe" http://www.wahh-app.comC:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
61.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2264"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2800.0.225485574\371004064" -childID 1 -isForBrowser -prefsHandle 1364 -prefsLen 8310 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2800 "\\.\pipe\gecko-crash-server-pipe.2800" 1484 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
61.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2524"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2800.6.717442892\315336976" -childID 2 -isForBrowser -prefsHandle 2444 -prefsLen 11442 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2800 "\\.\pipe\gecko-crash-server-pipe.2800" 2268 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
61.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3216"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2800.12.764734604\698285912" -childID 3 -isForBrowser -prefsHandle 3072 -prefsLen 12017 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2800 "\\.\pipe\gecko-crash-server-pipe.2800" 3084 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
61.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
451
Read events
449
Write events
2
Delete events
0

Modification events

(PID) Process:(2800) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2800) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
Executable files
1
Suspicious files
61
Text files
16
Unknown types
34

Dropped files

PID
Process
Filename
Type
2800firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
MD5:
SHA256:
2800firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
MD5:
SHA256:
2800firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
MD5:
SHA256:
2800firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
MD5:
SHA256:
2800firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm
MD5:
SHA256:
2800firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:707C12070C52E55C2A996AC15E219B95
SHA256:6C5410C655C8EFC48D123ABE708C8940A4218072C0DAF85E03AB45DA6D2CE6B9
2800firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\FBEC81BC3D9C763EFF00DE82D35A2A11B88F158Eder
MD5:760E7296E79015B433B937975C70954B
SHA256:5F80B41431FB7FB8DF33DF4458001448257CD4A7D849FA7B9BA5C39110011B5D
2800firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:84DCA4994FB755BA9254EB782FCBC2C6
SHA256:214F13B2A140F5E696D188DB2C8F4E44D13FA82CAB7F779876C4B62557F012DF
2800firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstorebinary
MD5:CD82F4495EAFE523B9B6B938C828611B
SHA256:576A0D2C3AD8D66BB202439B18F9FD563F92D9DDD9582A3C4CCE0ECAFD4F0908
2800firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.sbstorebinary
MD5:0E8FE60CCD7E9B4C32589A5743A95302
SHA256:2B124D4026850A3CFFD28DBACB58AEC28F7DCD4D40BC14E52BBE96D60CE4E749
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
32
DNS requests
60
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2800
firefox.exe
GET
200
172.217.18.100:80
http://www.google.com/adsense/domains/caf.js
US
text
57.6 Kb
whitelisted
2800
firefox.exe
GET
200
172.217.18.99:80
http://fonts.gstatic.com/s/boogaloo/v10/kmK-Zq45GAvOdnaW6y1C9ys.woff2
US
woff2
10.0 Kb
whitelisted
2800
firefox.exe
GET
200
172.217.22.10:80
http://fonts.googleapis.com/css?family=Boogaloo
US
text
289 b
whitelisted
2800
firefox.exe
GET
200
172.217.22.10:80
http://fonts.googleapis.com/css?family=Libre+Baskerville:400,700
US
text
432 b
whitelisted
2800
firefox.exe
GET
200
52.222.146.200:80
http://d1lxhc4jvstzrp.cloudfront.net/themes/assets/style.css
US
text
343 b
shared
2800
firefox.exe
GET
200
172.217.18.100:80
http://www.google.com/afs/ads/i/iframe.html
US
html
601 b
whitelisted
2800
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2800
firefox.exe
GET
200
172.217.18.100:80
http://www.google.com/dp/ads?max_radlink_len=40&r=m&client=dp-teaminternet06_3ph&channel=bucket030%2Cbucket049&hl=no&adtest=off&type=3&pcsa=false&optimize_terms=on&swp=as-drid-2719855883814808&uiopt=true&oe=UTF-8&ie=UTF-8&fexp=21404&format=r5%7Cs&num=0&output=afd_ads&domain_name=ww1.wahh-app.com&v=3&adext=as1%2Csr1&bsl=8&u_his=1&u_tz=0&dt=1552599952807&u_w=1280&u_h=720&biw=1264&bih=585&psw=1264&psh=585&frm=0&uio=ff2sa16fa2sl1sr1-wi666st22sa14lt33-&cont=tc%7Csearchbox&jsv=52476&rurl=http%3A%2F%2Fww1.wahh-app.com%2F%3Fsubid1%3D896f9160-46a2-11e9-bb1b-b722f3c58af9
US
html
6.39 Kb
whitelisted
2800
firefox.exe
GET
200
52.222.146.200:80
http://d1lxhc4jvstzrp.cloudfront.net/scripts/js3caf.js
US
text
6.17 Kb
shared
2800
firefox.exe
GET
200
185.53.179.29:80
http://ww1.wahh-app.com/?subid1=896f9160-46a2-11e9-bb1b-b722f3c58af9
DE
html
3.50 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2800
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2800
firefox.exe
216.58.208.35:80
www.gstatic.com
Google Inc.
US
whitelisted
2800
firefox.exe
52.222.146.200:80
d1lxhc4jvstzrp.cloudfront.net
Amazon.com, Inc.
US
whitelisted
2800
firefox.exe
37.48.65.153:80
www.wahh-app.com
LeaseWeb Netherlands B.V.
NL
malicious
2800
firefox.exe
185.53.179.29:80
ww1.wahh-app.com
Team Internet AG
DE
malicious
2800
firefox.exe
35.160.41.125:443
tiles.services.mozilla.com
Amazon.com, Inc.
US
unknown
2800
firefox.exe
2.16.186.50:80
detectportal.firefox.com
Akamai International B.V.
whitelisted
2800
firefox.exe
172.217.18.100:80
www.google.com
Google Inc.
US
whitelisted
2800
firefox.exe
172.217.18.99:80
fonts.gstatic.com
Google Inc.
US
whitelisted
2800
firefox.exe
172.217.22.10:80
fonts.googleapis.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 2.16.186.50
  • 2.16.186.112
whitelisted
www.wahh-app.com
  • 37.48.65.153
malicious
a1089.dscd.akamai.net
  • 2.16.186.112
  • 2.16.186.50
whitelisted
search.services.mozilla.com
  • 35.166.112.39
  • 34.213.175.109
  • 52.88.150.81
whitelisted
search.r53-2.services.mozilla.com
  • 52.88.150.81
  • 34.213.175.109
  • 35.166.112.39
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
tiles.services.mozilla.com
  • 35.160.41.125
  • 34.218.217.119
  • 34.216.156.21
  • 34.214.20.242
  • 34.208.7.98
  • 35.164.130.113
  • 35.164.197.9
  • 54.149.115.79
whitelisted
tiles.r53-2.services.mozilla.com
  • 54.149.115.79
  • 35.164.197.9
  • 35.164.130.113
  • 34.208.7.98
  • 34.214.20.242
  • 34.216.156.21
  • 34.218.217.119
  • 35.160.41.125
whitelisted
cs9.wac.phicdn.net
  • 93.184.220.29
whitelisted
ww1.wahh-app.com
  • 185.53.179.29
malicious

Threats

No threats detected
No debug info