| URL: | http://cdn09.foxitsoftware.com/pub/foxit/reader/desktop/win/9.x/9.3/en_us/FoxitReader93_Setup_Prom_IS.exe |
| Full analysis: | https://app.any.run/tasks/b459fd6f-baa8-42b2-ba47-403122a174e2 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | December 18, 2018, 21:54:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 595C5DD1512214506064F876F2F29A58 |
| SHA1: | 00E55FA992E70EA0A1745FA8A6D5E8AD91D92F03 |
| SHA256: | 86B8DA7690284B17174331567E20FA63BACB07320EF586407D783B9655FD112E |
| SSDEEP: | 3:N1KdBLiGDKNElQHYbRMJIsVKSMRTD4bRwEm5IH0:CXzDEHYbRMT+newp5M0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 480 | "C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader\Shell Extensions\FoxitPreviewhost.exe" /regserver | C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader\Shell Extensions\FoxitPreviewhost.exe | — | FoxitReader93_enu_Setup_Prom.tmp | |||||||||||
User: admin Company: Foxit Corporation Integrity Level: HIGH Description: Foxit PDF Preview Handler Host Exit code: 0 Version: 1.0.6.411 Modules
| |||||||||||||||
| 1196 | C:\Windows\System32\spoolsv.exe | C:\Windows\System32\spoolsv.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Spooler SubSystem App Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1432 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader\plugins\Creator\x86\FPC_WordAddin_x86.dll" | C:\Windows\system32\regsvr32.exe | — | FoxitReader93_enu_Setup_Prom.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2252 | "C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader\FoxitReader.exe" /FirstRun | C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader\FoxitReader.exe | — | FoxitReader93_enu_Setup_Prom.tmp | |||||||||||
User: admin Company: Foxit Software Inc. Integrity Level: HIGH Description: Foxit Reader 9.3 Exit code: 0 Version: 9.3.0.10826 Modules
| |||||||||||||||
| 2324 | "C:\Windows\System32\regsvr32.exe" -s "C:\\Program Files\\Foxit Software\\Foxit Reader\\Foxit Reader\\Shell Extensions\\FoxitThumbnailHndlr_x86.dll" | C:\Windows\System32\regsvr32.exe | — | FoxitReader.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2536 | "C:\Windows\System32\regsvr32.exe" -s "C:\\Program Files\\Foxit Software\\Foxit Reader\\Foxit Reader\\Shell Extensions\\FoxitPrevHndlr.dll" | C:\Windows\System32\regsvr32.exe | — | FoxitReader.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2608 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2980.0.281993157\1447491283" -childID 1 -isForBrowser -prefsHandle 1444 -prefsLen 8310 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2980 "\\.\pipe\gecko-crash-server-pipe.2980" 1492 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 61.0.2 Modules
| |||||||||||||||
| 2716 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2980.12.1710068662\1665470738" -childID 3 -isForBrowser -prefsHandle 3052 -prefsLen 12017 -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2980 "\\.\pipe\gecko-crash-server-pipe.2980" 3064 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 61.0.2 Modules
| |||||||||||||||
| 2808 | "C:\Users\admin\AppData\Roaming\Foxit Software\Addon\Foxit Reader\FoxitReaderUpdater.exe" -updater -type "Auto Updater" -hwnd 327988 -readerpath "C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader\" -regpath "HKEY_CURRENT_USER\Software\Foxit Software\Foxit Reader 9.0" -version "9.3.0.10826" -readerlang "en-US" | C:\Users\admin\AppData\Roaming\Foxit Software\Addon\Foxit Reader\FoxitReaderUpdater.exe | FoxitReader.exe | ||||||||||||
User: admin Company: Foxit Corporation Integrity Level: HIGH Description: Foxit Updater Exit code: 0 Version: 9.3.0.9928 Modules
| |||||||||||||||
| 2816 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader\plugins\FoxitReaderBrowserAx.dll" | C:\Windows\system32\regsvr32.exe | — | FoxitReader93_enu_Setup_Prom.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2980) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2980) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2980) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2980) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2980) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3832) FoxitReader93_Setup_Prom_IS.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3832) FoxitReader93_Setup_Prom_IS.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3832) FoxitReader93_Setup_Prom_IS.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FoxitReader93_Setup_Prom_IS_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3832) FoxitReader93_Setup_Prom_IS.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FoxitReader93_Setup_Prom_IS_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3832) FoxitReader93_Setup_Prom_IS.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FoxitReader93_Setup_Prom_IS_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2980 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 2980 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
| 2980 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
| 2980 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 2980 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 2980 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 2980 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 2980 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 2980 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\55F3A8141B0F01292545EBF09A1E053D6C64205B | binary | |
MD5:— | SHA256:— | |||
| 2980 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.sbstore | binary | |
MD5:0E8FE60CCD7E9B4C32589A5743A95302 | SHA256:2B124D4026850A3CFFD28DBACB58AEC28F7DCD4D40BC14E52BBE96D60CE4E749 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2980 | firefox.exe | GET | 200 | 185.59.220.21:80 | http://cdn09.foxitsoftware.com/pub/foxit/reader/desktop/win/9.x/9.3/en_us/FoxitReader93_Setup_Prom_IS.exe | DE | executable | 66.1 Mb | suspicious |
2980 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2980 | firefox.exe | POST | 200 | 172.217.16.206:80 | http://ocsp.pki.goog/GTSGIAG3 | US | der | 463 b | whitelisted |
2980 | firefox.exe | POST | 200 | 172.217.16.206:80 | http://ocsp.pki.goog/GTSGIAG3 | US | der | 463 b | whitelisted |
2980 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3832 | FoxitReader93_Setup_Prom_IS.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
2980 | firefox.exe | GET | 200 | 2.16.186.112:80 | http://detectportal.firefox.com/success.txt | unknown | text | 8 b | whitelisted |
3020 | FoxitReader.exe | GET | 200 | 157.22.19.177:80 | http://ad.foxitsoftware.com/banners_gb.19bbea1a53e751ded94b5df166bec3b1-55E78D8CC8A20022E0AF3C404E2803454AE87C32.zip | US | compressed | 194 Kb | malicious |
3020 | FoxitReader.exe | POST | 200 | 157.22.19.177:80 | http://ad.foxitsoftware.com/adserve.php | US | text | 9.75 Kb | malicious |
3832 | FoxitReader93_Setup_Prom_IS.exe | GET | 200 | 54.192.94.2:80 | http://x.ss2.us/x.cer | US | der | 1.27 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2980 | firefox.exe | 2.16.186.112:80 | detectportal.firefox.com | Akamai International B.V. | — | whitelisted |
2980 | firefox.exe | 185.59.220.21:80 | cdn09.foxitsoftware.com | Datacamp Limited | DE | suspicious |
2980 | firefox.exe | 34.216.89.123:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
2980 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2980 | firefox.exe | 172.217.16.202:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
2980 | firefox.exe | 52.41.60.30:443 | tiles.services.mozilla.com | Amazon.com, Inc. | US | unknown |
2980 | firefox.exe | 172.217.16.206:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
2980 | firefox.exe | 54.187.176.55:443 | shavar.services.mozilla.com | Amazon.com, Inc. | US | unknown |
2980 | firefox.exe | 54.230.95.61:443 | tracking-protection.cdn.mozilla.net | Amazon.com, Inc. | US | unknown |
2980 | firefox.exe | 172.217.22.78:443 | sb-ssl.google.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
cdn09.foxitsoftware.com |
| suspicious |
detectportal.firefox.com |
| whitelisted |
a1089.dscd.akamai.net |
| whitelisted |
1809278276.rsc.cdn77.org |
| suspicious |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
cs9.wac.phicdn.net |
| whitelisted |
tiles.services.mozilla.com |
| whitelisted |
tiles.r53-2.services.mozilla.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2980 | firefox.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2980 | firefox.exe | unknown | SURICATA TCPv4 invalid checksum |
2980 | firefox.exe | unknown | SURICATA IPv4 invalid checksum |
Process | Message |
|---|---|
FoxitReader.exe | StopRequest |
FoxitReader.exe | StopRequest |