analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Firefox Installer.exe

Full analysis: https://app.any.run/tasks/4754fcf6-8c77-4c29-b7f0-29d85c570cdc
Verdict: Malicious activity
Analysis date: November 29, 2020, 10:50:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

C22C2248F41A9034B112FA994C229089

SHA1:

30A7E05AE8B0295A6799DDA5487C05C3E4D3EDA2

SHA256:

8164560A044D6624AE0C273C5E0B779BCEEC3B9C27DC778EA4005B77C341529E

SSDEEP:

6144:OaVWdyzOxeA1DfdwX3MmIO5+vlXeFEyQSFooCNHpSWEB5bdSmeUxy2Lpr6Co+BBu:OMROxdDfOnMmX5+vw2yQirC1pb0b4HUw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • setup-stub.exe (PID: 3756)
      • Firefox Installer.exe (PID: 2836)
      • setup-stub.exe (PID: 3716)
    • Loads dropped or rewritten executable

      • setup-stub.exe (PID: 3756)
      • setup-stub.exe (PID: 3716)
    • Application was dropped or rewritten from another process

      • setup-stub.exe (PID: 3716)
      • setup-stub.exe (PID: 3756)
    • Actions looks like stealing of personal data

      • setup-stub.exe (PID: 3716)
    • Changes settings of System certificates

      • setup-stub.exe (PID: 3716)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Firefox Installer.exe (PID: 2836)
      • setup-stub.exe (PID: 3756)
      • setup-stub.exe (PID: 3716)
    • Drops a file with too old compile date

      • setup-stub.exe (PID: 3756)
      • setup-stub.exe (PID: 3716)
    • Application launched itself

      • setup-stub.exe (PID: 3756)
    • Creates files in the program directory

      • setup-stub.exe (PID: 3716)
    • Reads internet explorer settings

      • setup-stub.exe (PID: 3716)
    • Creates a directory in Program Files

      • setup-stub.exe (PID: 3716)
    • Adds / modifies Windows certificates

      • setup-stub.exe (PID: 3716)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (64.2)
.dll | Win32 Dynamic Link Library (generic) (15.6)
.exe | Win32 Executable (generic) (10.6)
.exe | Generic Win/DOS Executable (4.7)
.exe | DOS Executable Generic (4.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:08:31 00:18:33+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 69632
InitializedDataSize: 65536
UninitializedDataSize: 147456
EntryPoint: 0x34fa0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 18.5.0.0
ProductVersionNumber: 18.5.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Mozilla
FileDescription: Firefox
FileVersion: 18.05
InternalName: 7zS.sfx
LegalCopyright: Mozilla
OriginalFileName: 7zS.sfx.exe
ProductName: Firefox
ProductVersion: 18.05

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 30-Aug-2018 22:18:33
Detected languages:
  • English - United States
CompanyName: Mozilla
FileDescription: Firefox
FileVersion: 18.05
InternalName: 7zS.sfx
LegalCopyright: Mozilla
OriginalFilename: 7zS.sfx.exe
ProductName: Firefox
ProductVersion: 18.05

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 30-Aug-2018 22:18:33
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
UPX0
0x00001000
0x00024000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
UPX1
0x00025000
0x00011000
0x00010200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.87799
.rsrc
0x00036000
0x00010000
0x0000FC00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.52725

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.38843
1365
UNKNOWN
UNKNOWN
RT_MANIFEST
2
5.52861
5160
UNKNOWN
English - United States
RT_ICON
3
5.45625
11560
UNKNOWN
English - United States
RT_ICON
4
7.98617
43467
UNKNOWN
English - United States
RT_ICON
5
6.34937
136
UNKNOWN
English - United States
RT_STRING
97
6.74142
184
UNKNOWN
English - United States
RT_DIALOG
188
6.07381
84
UNKNOWN
English - United States
RT_STRING
207
5.37823
52
UNKNOWN
English - United States
RT_STRING

Imports

KERNEL32.DLL
MSVCRT.dll
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start firefox installer.exe setup-stub.exe setup-stub.exe

Process information

PID
CMD
Path
Indicators
Parent process
2836"C:\Users\admin\AppData\Local\Temp\Firefox Installer.exe" C:\Users\admin\AppData\Local\Temp\Firefox Installer.exe
explorer.exe
User:
admin
Company:
Mozilla
Integrity Level:
MEDIUM
Description:
Firefox
Version:
18.05
3756.\setup-stub.exeC:\Users\admin\AppData\Local\Temp\7zS41BF7EF8\setup-stub.exe
Firefox Installer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox Installer
Version:
81.0.1
3716"C:\Users\admin\AppData\Local\Temp\7zS41BF7EF8\setup-stub.exe" /UAC:4012E /NCRCC:\Users\admin\AppData\Local\Temp\7zS41BF7EF8\setup-stub.exe
setup-stub.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox Installer
Version:
81.0.1
Total events
767
Read events
744
Write events
0
Delete events
0

Modification events

No data
Executable files
9
Suspicious files
4
Text files
7
Unknown types
2

Dropped files

PID
Process
Filename
Type
3716setup-stub.exeC:\Users\admin\AppData\Local\Temp\CabD969.tmp
MD5:
SHA256:
3716setup-stub.exeC:\Users\admin\AppData\Local\Temp\TarD96A.tmp
MD5:
SHA256:
2836Firefox Installer.exeC:\Users\admin\AppData\Local\Temp\7zS41BF7EF8\setup-stub.exeexecutable
MD5:C3A5078709A35B8B730688BF20BCE092
SHA256:DBA10F95C26FE4E824519A542C89EC4FFB7A5B462D60B84D1C8D6AE4B4444A53
3716setup-stub.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1E11E75149C17A93653DA7DC0B8CF53F_0CE58C7814E604EF410B4A46E10F97A5binary
MD5:2EF99F45D0AEEF6B9AC1103A32B19824
SHA256:2644F2CD4B39351BF9F484E178DA9640CF1007F46D7E920C9DA42CCD706A93F9
2836Firefox Installer.exeC:\Users\admin\AppData\Local\Temp\7zS41BF7EF8\postSigningDatatext
MD5:FACE2AB5E7A7CD2B22EEF1AF52EEB5FC
SHA256:89FAD1E8F3BD1FA3890A9C684F32EF028C6BC1E57F3CC3677804DD5BF519FB06
3716setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsuD667.tmp\CityHash.dllexecutable
MD5:737379945745BB94F8A0DADCC18CAD8D
SHA256:D3D7B3D7A7941D66C7F75257BE90B12AC76F787AF42CD58F019CE0280972598A
3716setup-stub.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6binary
MD5:1FF55F5D5A87B44FB8D0A868B79829B7
SHA256:4B19F1939CD7F4D4DBF9EF4F056EC370A2D3719605F639940FEDE1C18D743078
3716setup-stub.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6der
MD5:F35594720BDB12D02C777B50A40996C7
SHA256:7C7C3BB58FDF08A0BF4C74CAF57034C7F8DCF3CC4D587E3F90A38B17ECDDB9EB
3716setup-stub.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1E11E75149C17A93653DA7DC0B8CF53F_0CE58C7814E604EF410B4A46E10F97A5der
MD5:090489EFAFDE588C144D5001A52C9D14
SHA256:DB925AE148C1B83CFF0845B5EAE793A9FF4FAA734CABD5CA44342ACE76EBF95E
3716setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsuD667.tmp\stub_common.csstext
MD5:544B51F11AD19DF720669478D28F129D
SHA256:4D9495B6F0E18331659993B79440E414A6E607FCDAEACBC7477E0683CC0FA98B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3716
setup-stub.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAqFR8NrFFUItcKTf94Y2FE%3D
US
der
471 b
whitelisted
3716
setup-stub.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3716
setup-stub.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3716
setup-stub.exe
143.204.215.113:443
product-details.mozilla.org
US
suspicious

DNS requests

Domain
IP
Reputation
product-details.mozilla.org
  • 143.204.215.113
  • 143.204.215.17
  • 143.204.215.124
  • 143.204.215.67
shared
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
No debug info