| URL: | https://www.wps.com/blog/es-microsoft-office-crack-download-free/ |
| Full analysis: | https://app.any.run/tasks/0f305ad5-9042-48c2-a0e7-a105448cd4e8 |
| Verdict: | Malicious activity |
| Analysis date: | December 06, 2023, 17:55:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | D26E6B5326256827ED5297B4DE996426 |
| SHA1: | 0E2DAD04BB9E25EC909DA5C6F9891B18EF349C29 |
| SHA256: | 82EED146C4B3C6A1C8A5BFD91C0F87450E9A6C38A00C63AD17B64E428B68D884 |
| SSDEEP: | 3:N8DSLh2crbhRuuH0XvOskDQv:2OL/bhRuuH0XWuv |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 244 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2832.2.930707789\1316654887" -childID 1 -isForBrowser -prefsHandle 2072 -prefMapHandle 2068 -prefsLen 25524 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {bde97f23-7c36-4564-a8bd-cca62ffd5082} 2832 "\\.\pipe\gecko-crash-server-pipe.2832" 2084 1924c158 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 588 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2832.1.294960846\2028839073" -parentBuildID 20230710165010 -prefsHandle 1416 -prefMapHandle 1412 -prefsLen 29857 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {3e8ed7b0-4e9e-4157-8de8-7b7c45e7228e} 2832 "\\.\pipe\gecko-crash-server-pipe.2832" 1428 42d3258 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1628 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2832.3.2032955046\1459568438" -childID 2 -isForBrowser -prefsHandle 3012 -prefMapHandle 3008 -prefsLen 35454 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7a47bae4-782d-4102-8b18-c8311cf24bf0} 2832 "\\.\pipe\gecko-crash-server-pipe.2832" 3024 1e4f0258 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1692 | "C:\Users\admin\Downloads\cached\wps_download\09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe" -installCallByOnlineSetup -defaultOpen -defaultOpenPdf -createIcons -curlangofinstalledproduct=en_US -notElevateAndDirectlyInstall -D="C:\Users\admin\AppData\Local\Kingsoft\WPS Office" -notautostartwps | C:\Users\admin\Downloads\cached\wps_download\09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | wps_wid.cid-1960927767.1701885326.exe | ||||||||||||
User: admin Company: Zhuhai Kingsoft Office Software Co.,Ltd Integrity Level: MEDIUM Description: WPS Install Application Exit code: 0 Version: 12,2,0,13266 Modules
| |||||||||||||||
| 1936 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2832.0.1137560229\1195781131" -parentBuildID 20230710165010 -prefsHandle 1116 -prefMapHandle 1108 -prefsLen 29780 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {edb72660-5cc2-4c1a-abbe-cfc1291bb327} 2832 "\\.\pipe\gecko-crash-server-pipe.2832" 1200 42d1458 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2028 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2832.6.1916904656\2081292453" -childID 5 -isForBrowser -prefsHandle 4068 -prefMapHandle 4064 -prefsLen 35557 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f79b4761-7b04-4206-9d80-224585d54ea5} 2832 "\\.\pipe\gecko-crash-server-pipe.2832" 3880 23688b58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2228 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2832.4.253876148\1559589325" -childID 3 -isForBrowser -prefsHandle 3792 -prefMapHandle 3804 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b6db775c-944f-46ff-9b5c-317cb5350151} 2832 "\\.\pipe\gecko-crash-server-pipe.2832" 3808 230df558 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2708 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2832.5.1016780133\115518964" -childID 4 -isForBrowser -prefsHandle 4056 -prefMapHandle 4052 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ec782f6c-75e1-4538-aa91-10c7750017b0} 2832 "\\.\pipe\gecko-crash-server-pipe.2832" 4084 230dec58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2832 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://www.wps.com/blog/es-microsoft-office-crack-download-free/" | C:\Program Files\Mozilla Firefox\firefox.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3208 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2832.7.1414432537\1141057202" -childID 6 -isForBrowser -prefsHandle 4032 -prefMapHandle 4036 -prefsLen 30357 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8217d83d-57e2-4c5e-8a8e-9d57fdbbcf2c} 2832 "\\.\pipe\gecko-crash-server-pipe.2832" 4012 230dc858 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (2832) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0000000000000000 | |||
| (PID) Process: | (2832) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (2832) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (2832) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (2832) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (2832) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 0 | |||
| (PID) Process: | (2832) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (2832) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (2832) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: F8B731ACA1C5D901 | |||
| (PID) Process: | (2832) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2832 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\doomed\21349 | compressed | |
MD5:58BF90C279D403DC2DFB9B9DF37D9B81 | SHA256:4A922FE9DF274368DBD30EC32F033BC5404E868AE1F512F6CFB291D7A4D781C5 | |||
| 2832 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2832 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2832 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\datareporting\glean\pending_pings\8874cf50-3b4f-483e-840e-255bb2e98352 | text | |
MD5:62ECEA500D053B33C97FDD1D5C67AD4B | SHA256:98EE959A42123FE04467C6CD9F33EAA6921BA973FFC95D42D7CE796047451E0D | |||
| 2832 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:5A4915726F478E3CDA51138C6A93CC23 | SHA256:58E854E4F553A12A3EB3ABEAE51BB881B9813DDD7A31DA7DDFED937D8B4B0E2C | |||
| 2832 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs.js | text | |
MD5:F42921723A3596D2FA57BE1279C18862 | SHA256:5D6A78D6523693521C6D337C72269B0320B0C5A82D699D74FF2490813574C652 | |||
| 2832 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.bin | binary | |
MD5:4DF9B77C7650AF87B264E535779AE2A4 | SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58 | |||
| 2832 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2832 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2832 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\datareporting\glean\tmp\584051ae-b8c3-42bd-be1b-3cc457110dee | text | |
MD5:5758A48D44BB510AE4DF92E7EFFE716F | SHA256:90A13DBA0939015DADAEEA546908F8CF4C27842159BED44FA2CCA10356B6F680 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2832 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
2832 | firefox.exe | POST | 200 | 184.24.77.61:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2832 | firefox.exe | POST | 200 | 184.24.77.61:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2832 | firefox.exe | POST | 200 | 184.24.77.61:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2832 | firefox.exe | POST | 200 | 18.245.65.219:80 | http://ocsp.r2m02.amazontrust.com/ | unknown | binary | 471 b | unknown |
2832 | firefox.exe | POST | 200 | 216.58.212.131:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | unknown |
2832 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 471 b | unknown |
2832 | firefox.exe | POST | 200 | 216.58.212.131:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
2832 | firefox.exe | POST | 200 | 216.58.212.131:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
2832 | firefox.exe | POST | 200 | 184.24.77.61:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2832 | firefox.exe | 217.198.191.102:443 | www.wps.com | ZEN-ECN | SG | unknown |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2832 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
2832 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2832 | firefox.exe | 44.216.137.107:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
2832 | firefox.exe | 184.24.77.61:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
2832 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
www.wps.com |
| unknown |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
sz-special-overseas.volcgtm.com |
| unknown |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
ocsp.dcocsp.cn |
| whitelisted |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
Process | Message |
|---|---|
09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | [kscreen] isElide:0 switchRec:0 switchRecElide:1 |
09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | QLayout: Attempting to add QLayout "" to QWidget "", which already has a layout
|
09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | QLayout: Attempting to add QLayout "" to QWidget "m_BrandAreaWidget", which already has a layout
|
09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
|
09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
|
09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
|
09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
|
09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
|
09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
|
09db699b58b0ad591392bc08cea3cab3-13_setup_XA_mui_Free.exe.600.1021.exe | QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
|