| File name: | ezgif-3-78bc232eb2e8.gif |
| Full analysis: | https://app.any.run/tasks/56f09823-583d-49a4-adf2-33314a43badf |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | November 06, 2020, 18:15:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | image/gif |
| File info: | GIF image data, version 89a, 360 x 201 |
| MD5: | 766F359297085CE6923CAB5CCC5CC4A1 |
| SHA1: | 12EFFC6F4017F0FED7EE6ACE61AB6C564EC04867 |
| SHA256: | 78AE5291FDEEA850E185D1ABB3F7C85EBD0A074195EE924B7E2DE51B28CEB56B |
| SSDEEP: | 12288:Shv0FD37GNPrAZ29d71duFrmMfz4s00lQlqRGxp7FTFIjy/uxex:e0FDr8ncrmML4Q+MRGr5JIzxex |
| .gif | | | GIF animated bitmap (59.1) |
|---|---|---|
| .gif | | | GIF89a bitmap (24.4) |
| .gif | | | GIF bitmap (generic) (12.2) |
| .bs/bin | | | PrintFox (C64) bitmap (4) |
| GIFVersion: | 89a |
|---|---|
| ImageWidth: | 360 |
| ImageHeight: | 201 |
| HasColorMap: | Yes |
| ColorResolutionDepth: | 8 |
| BitsPerPixel: | 7 |
| BackgroundColor: | - |
| AnimationIterations: | Infinite |
| FrameCount: | 78 |
| Duration: | 3.90 s |
| ImageSize: | 360x201 |
|---|---|
| Megapixels: | 0.072 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 404 | "C:\Program Files\McAfee\WebAdvisor\UIHost.exe" | C:\Program Files\McAfee\WebAdvisor\UIHost.exe | ServiceHost.exe | ||||||||||||
User: admin Company: McAfee, LLC Integrity Level: MEDIUM Description: McAfee WebAdvisor Exit code: 0 Version: 4,1,1,163 Modules
| |||||||||||||||
| 772 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1592.13.56720637\243823573" -childID 2 -isForBrowser -prefsHandle 2940 -prefMapHandle 2944 -prefsLen 5996 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1592 "\\.\pipe\gecko-crash-server-pipe.1592" 2952 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 836 | "C:\Program Files\McAfee\WebAdvisor\updater.exe" | C:\Program Files\McAfee\WebAdvisor\updater.exe | ServiceHost.exe | ||||||||||||
User: SYSTEM Company: McAfee, LLC Integrity Level: SYSTEM Description: McAfee WebAdvisor Exit code: 0 Version: 4,1,1,163 Modules
| |||||||||||||||
| 896 | regsvr32.exe /s "C:\Program Files\McAfee\WebAdvisor\win32\WSSDep.dll" | C:\Windows\system32\regsvr32.exe | — | installer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 936 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3092.20.1359999005\1397357459" -childID 3 -isForBrowser -prefsHandle 3752 -prefMapHandle 3736 -prefsLen 6719 -prefMapSize 191902 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3092 "\\.\pipe\gecko-crash-server-pipe.3092" 3800 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 964 | "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\ezgif-3-78bc232eb2e8.gif | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 1396 | "C:\Windows\Temp\asw.63373adf44f8cb97\avast_free_antivirus_setup_online.exe" /silent /psh:Gh3IDl5G7QpXQppwWEPodlxCmARJB8hHUkacAV9FnQNZRZQCV0ecCl5HilwJEslBUjX6cjwgilAdF58BUkWYA1hGlAZcQ5j+RwAAAG90rDM= /ws /ga_clientid:3bb9ac6c-6f47-4284-b137-881b2951b71d /edat_dir:C:\Windows\Temp\asw.63373adf44f8cb97 | C:\Windows\Temp\asw.63373adf44f8cb97\avast_free_antivirus_setup_online.exe | mmm_irs_ppi_002_451_m.exe | ||||||||||||
User: admin Company: AVAST Software Integrity Level: HIGH Description: Avast Antivirus Exit code: 0 Version: 20.8.5684.0 Modules
| |||||||||||||||
| 1576 | "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/84b394ae-4a66-4a06-81b7-a852c5a99b4d/main/Firefox/68.0.1/release/20190717172542?v=4 C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\84b394ae-4a66-4a06-81b7-a852c5a99b4d | C:\Program Files\Mozilla Firefox\pingsender.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Foundation Integrity Level: MEDIUM Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 1592 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 1684 | "C:\Windows\explorer.exe" /select, "C:\Users\admin\Downloads\memz-trojan.zip" | C:\Windows\explorer.exe | — | memz-trojan_2161627974.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (964) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 4249775716 | |||
| (PID) Process: | (964) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30848104 | |||
| (PID) Process: | (964) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (964) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (964) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (964) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (964) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (964) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (964) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (964) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 964 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 964 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFD3B8DAE4F5AC9403.TMP | — | |
MD5:— | SHA256:— | |||
| 964 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFF27A65E1FC7D47C1.TMP | — | |
MD5:— | SHA256:— | |||
| 964 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF1DB5D4EFA1E3760D.TMP | — | |
MD5:— | SHA256:— | |||
| 964 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFA73AC19CE07017CC.TMP | — | |
MD5:— | SHA256:— | |||
| 1592 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 1592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
| 1592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
| 1592 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp | — | |
MD5:— | SHA256:— | |||
| 1592 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1592 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
964 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.47 Kb | whitelisted |
1592 | firefox.exe | POST | 200 | 216.58.212.163:80 | http://ocsp.pki.goog/gts1o1core | US | der | 472 b | whitelisted |
1592 | firefox.exe | POST | 200 | 216.58.212.163:80 | http://ocsp.pki.goog/gts1o1core | US | der | 471 b | whitelisted |
1592 | firefox.exe | POST | 200 | 216.58.212.163:80 | http://ocsp.pki.goog/gts1o1core | US | der | 471 b | whitelisted |
1592 | firefox.exe | POST | 200 | 216.58.212.163:80 | http://ocsp.pki.goog/gts1o1core | US | der | 472 b | whitelisted |
1592 | firefox.exe | POST | 200 | 216.58.212.163:80 | http://ocsp.pki.goog/gts1o1core | US | der | 471 b | whitelisted |
964 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.47 Kb | whitelisted |
1592 | firefox.exe | POST | 200 | 216.58.212.163:80 | http://ocsp.pki.goog/gts1o1core | US | der | 472 b | whitelisted |
1592 | firefox.exe | POST | 200 | 216.58.212.163:80 | http://ocsp.pki.goog/gts1o1core | US | der | 472 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1592 | firefox.exe | 143.204.215.65:443 | snippets.cdn.mozilla.net | — | US | suspicious |
1592 | firefox.exe | 143.204.215.37:443 | firefox.settings.services.mozilla.com | — | US | malicious |
1592 | firefox.exe | 216.58.212.163:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
964 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
1592 | firefox.exe | 172.217.22.68:443 | www.google.com | Google Inc. | US | whitelisted |
1592 | firefox.exe | 54.186.24.65:443 | shavar.services.mozilla.com | Amazon.com, Inc. | US | unknown |
1592 | firefox.exe | 216.58.207.67:443 | www.gstatic.com | Google Inc. | US | whitelisted |
1592 | firefox.exe | 52.41.198.156:443 | push.services.mozilla.com | Amazon.com, Inc. | US | unknown |
1592 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
964 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
snippets.cdn.mozilla.net |
| whitelisted |
d228z91au11ukj.cloudfront.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1060 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
1060 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
3332 | memz-trojan_2161627974.exe | A Network Trojan was detected | ADWARE [PTsecurity] InstallCore |
3332 | memz-trojan_2161627974.exe | A Network Trojan was detected | AV TROJAN EXPERIMENTAL Suspicious CIS Downloaded over HTTP |
3332 | memz-trojan_2161627974.exe | A Network Trojan was detected | AV TROJAN EXPERIMENTAL Suspicious CIS Downloaded over HTTP |
2312 | mmm_irs_ppi_002_451_m.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1060 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
Process | Message |
|---|---|
saBSI.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory |
saBSI.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory |
saBSI.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\in43A9003C\023EA0DC_stp\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\in43A9003C\023EA0DC_stp\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
saBSI.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\in43A9003C\023EA0DC_stp\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\in43A9003C\023EA0DC_stp\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
saBSI.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\in43A9003C\023EA0DC_stp\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\in43A9003C\023EA0DC_stp\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
saBSI.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory |
installer.exe | NotComDllGetInterface: C:\Program Files\McAfee\Temp1942447361\installer.exe loading C:\Program Files\McAfee\Temp1942447361\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
installer.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory |
installer.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory |
installer.exe | NotComDllGetInterface: C:\Program Files\McAfee\Temp1942447361\installer.exe loading C:\Program Files\McAfee\Temp1942447361\mfeaaca.dll, WinVerifyTrust failed with 80092003
|