File name:

Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe

Full analysis: https://app.any.run/tasks/18c3b318-6d91-419a-b766-554b45269227
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: December 27, 2024, 18:05:45
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

3EE0D0A7731C6690F05BD464C445CCDD

SHA1:

76CA249B923AF396DC1DFC99A4DF9C6C0CDE1A6B

SHA256:

88FAABF5436296AA5322AD612CF310A6C0EF7526112B9BB2CEC7405867B5EA53

SSDEEP:

12288:XLVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzEO:bVP60BM2pMUN9keo+c+zEO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.exe (PID: 3060)
    • Steals credentials from Web Browsers

      • target.exe (PID: 5388)
      • target.exe (PID: 2756)
      • target.exe (PID: 4648)
      • assistant_installer.exe (PID: 4228)
    • Actions looks like stealing of personal data

      • target.exe (PID: 5388)
      • target.exe (PID: 2756)
      • assistant_installer.exe (PID: 4228)
      • assistant_installer.exe (PID: 6352)
      • target.exe (PID: 4648)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 7036)
      • Ninite.exe (PID: 6192)
      • maintenanceservice_installer.exe (PID: 1576)
      • target.exe (PID: 2756)
    • Executable content was dropped or overwritten

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • maintenanceservice_tmp.exe (PID: 6316)
      • Ninite.exe (PID: 6192)
      • target.exe (PID: 2756)
      • target.exe (PID: 5388)
      • target.exe (PID: 5916)
      • target.exe (PID: 5464)
      • assistant_package_sfx.exe (PID: 6176)
      • target.exe (PID: 4648)
    • Checks Windows Trust Settings

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 6192)
      • target.exe (PID: 2756)
    • Searches for installed software

      • Ninite.exe (PID: 6192)
      • setup.exe (PID: 3060)
    • Application launched itself

      • Ninite.exe (PID: 7036)
      • target.exe (PID: 2756)
      • target.exe (PID: 5464)
      • assistant_installer.exe (PID: 6352)
    • The process drops Mozilla's DLL files

      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
    • The process drops C-runtime libraries

      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
    • Process drops legitimate windows executable

      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
      • assistant_package_sfx.exe (PID: 6176)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
    • Loads DLL from Mozilla Firefox

      • regsvr32.exe (PID: 6356)
      • default-browser-agent.exe (PID: 6704)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 6356)
    • Creates a software uninstall entry

      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
    • Starts itself from another location

      • target.exe (PID: 2756)
  • INFO

    • The sample compiled with english language support

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • target.exe (PID: 5388)
      • target.exe (PID: 2756)
      • target.exe (PID: 5464)
      • target.exe (PID: 5916)
      • assistant_package_sfx.exe (PID: 6176)
      • target.exe (PID: 4648)
    • Checks supported languages

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 7036)
      • target.exe (PID: 3260)
      • Ninite.exe (PID: 6192)
      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • maintenanceservice_tmp.exe (PID: 6316)
      • default-browser-agent.exe (PID: 6704)
      • target.exe (PID: 5388)
      • target.exe (PID: 2756)
      • target.exe (PID: 5464)
      • assistant_installer.exe (PID: 4228)
    • Checks proxy server information

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 6192)
      • setup.exe (PID: 3060)
      • target.exe (PID: 2756)
    • Reads the computer name

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 7036)
      • Ninite.exe (PID: 6192)
      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • maintenanceservice_tmp.exe (PID: 6316)
      • target.exe (PID: 2756)
      • target.exe (PID: 5464)
    • Create files in a temporary directory

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 6192)
      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • target.exe (PID: 2756)
      • target.exe (PID: 5388)
      • target.exe (PID: 5464)
      • target.exe (PID: 5916)
      • assistant_package_sfx.exe (PID: 6176)
    • Reads the machine GUID from the registry

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 6192)
      • target.exe (PID: 2756)
    • Creates files or folders in the user directory

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 5388)
      • target.exe (PID: 2756)
      • Ninite.exe (PID: 6192)
    • Reads the software policy settings

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 6192)
      • target.exe (PID: 2756)
    • The process uses the downloaded file

      • Ninite.exe (PID: 7036)
      • Ninite.exe (PID: 6192)
    • Process checks computer location settings

      • Ninite.exe (PID: 7036)
    • Creates files in the program directory

      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • target.exe (PID: 5464)
    • Application launched itself

      • firefox.exe (PID: 6960)
      • firefox.exe (PID: 4548)
    • Sends debugging messages

      • assistant_installer.exe (PID: 6352)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:04:12 00:19:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 233472
InitializedDataSize: 182272
UninitializedDataSize: -
EntryPoint: 0x1a53a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.1.1.1183
ProductVersionNumber: 0.1.1.1183
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Secure By Design Inc.
FileDescription: Ninite
FileVersion: 0,1,1,1183
InternalName: Ninite
LegalCopyright: Copyright (C) 2009 Secure By Design Inc
OriginalFileName: -
ProductName: Ninite
ProductVersion: 0,1,1,1183
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
21
Malicious processes
12
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ninite 7zip chrome firefox keepass 2 notepad installer.exe ninite.exe no specs ninite.exe target.exe setup.exe regsvr32.exe no specs maintenanceservice_installer.exe maintenanceservice_tmp.exe default-browser-agent.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs target.exe target.exe target.exe target.exe target.exe assistant_package_sfx.exe assistant_installer.exe assistant_installer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1576"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe
setup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Mozilla Maintenance Service Installer
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\maintenanceservice_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2756"C:\Users\admin\AppData\Local\Temp\3EF47D~1\target.exe" /install /install /silent /launchopera=0 /desktopshortcut=1 /quicklaunchshortcut=0 /setdefaultbrowser=0 /all_users=1 --setdefaultbrowser=0 --allusers=1C:\Users\admin\AppData\Local\Temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
Ninite.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Version:
115.0.5322.119
Modules
Images
c:\users\admin\appdata\local\temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3060.\setup.exe -msC:\Users\admin\AppData\Local\Temp\7zSCBC1E393\setup.exe
target.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox Installer
Exit code:
0
Version:
133.0.3
Modules
Images
c:\users\admin\appdata\local\temp\7zscbc1e393\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
3260"C:\Users\admin\AppData\Local\Temp\352C98~1\target.exe" -msC:\Users\admin\AppData\Local\Temp\352c9878-c47d-11ef-b4ea-18f7786f96ee\target.exe
Ninite.exe
User:
admin
Company:
Mozilla
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
18.05
Modules
Images
c:\users\admin\appdata\local\temp\352c9878-c47d-11ef-b4ea-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4228"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202412271806401\assistant\assistant_installer.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x230,0x234,0x238,0x20c,0x23c,0x7ff6999d9618,0x7ff6999d9624,0x7ff6999d9630C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202412271806401\assistant\assistant_installer.exe
assistant_installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Browser Assistant Installer
Exit code:
0
Version:
115.0.5322.119
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\opera_package_202412271806401\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4548"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask installC:\Program Files\Mozilla Firefox\firefox.exesetup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\vcruntime140.dll
4648C:\Users\admin\AppData\Local\Temp\3EF47D~1\target.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x280,0x284,0x294,0x25c,0x298,0x7ff820564e20,0x7ff820564e2c,0x7ff820564e38C:\Users\admin\AppData\Local\Temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
target.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Version:
115.0.5322.119
Modules
Images
c:\users\admin\appdata\local\temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5040"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask installC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
5388C:\Users\admin\AppData\Local\Temp\3EF47D~1\target.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x288,0x28c,0x290,0x264,0x294,0x7ff8211a4e20,0x7ff8211a4e2c,0x7ff8211a4e38C:\Users\admin\AppData\Local\Temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
target.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Version:
115.0.5322.119
Modules
Images
c:\users\admin\appdata\local\temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5464"C:\Users\admin\AppData\Local\Temp\3EF47D~1\target.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=0 --general-interests=0 --general-location=0 --personalized-content=0 --personalized-ads=0 --launchopera=0 --showunbox=0 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=1 --setdefaultbrowser=0 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --show-intro-overlay --server-tracking-data=server_tracking_data --initial-pid=2756 --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20241227180640" --session-guid=b6baa4c6-4307-44cc-bce6-e54be0519720 --server-tracking-blob="NjFkODk4ZWJjMmNmNGQ1YjllMzkyYmJlMjJiYmQ5MDY3ZjdhY2U0Y2Y1NWMzYTQwM2Q2Zjk0N2YzZTU1NDA1Yzp7InByb2R1Y3QiOnsibmFtZSI6Ik9wZXJhIn0sInN5c3RlbSI6eyJwbGF0Zm9ybSI6eyJhcmNoIjoieDg2XzY0Iiwib3BzeXMiOiJXaW5kb3dzIiwib3BzeXMtdmVyc2lvbiI6IjEwIiwicGFja2FnZSI6IkVYRSJ9fX0= " --silent --desktopshortcut=1 --wait-for-package --initial-proc-handle=4C05000000000000C:\Users\admin\AppData\Local\Temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
target.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Version:
115.0.5322.119
Modules
Images
c:\users\admin\appdata\local\temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
17 374
Read events
17 280
Write events
68
Delete events
26

Modification events

(PID) Process:(6356) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs
Operation:writeName:C:\Program Files\Mozilla Firefox
Value:
308046B0AF4A39CB
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 133.0.3 (x64 en-US)
Operation:writeName:EstimatedSize
Value:
257624
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB
Operation:writeName:FriendlyTypeName
Value:
Firefox HTML Document
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\shell\open\ddeexec
Operation:delete keyName:(default)
Value:
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxPDF-308046B0AF4A39CB
Operation:writeName:FriendlyTypeName
Value:
Firefox PDF Document
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxPDF-308046B0AF4A39CB\shell\open\ddeexec
Operation:delete keyName:(default)
Value:
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxURL-308046B0AF4A39CB\shell\open\ddeexec
Operation:delete keyName:(default)
Value:
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\InstallInfo
Operation:writeName:HideIconsCommand
Value:
"C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\InstallInfo
Operation:writeName:ShowIconsCommand
Value:
"C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts
Executable files
95
Suspicious files
72
Text files
46
Unknown types
7

Dropped files

PID
Process
Filename
Type
6192Ninite.exeC:\Users\admin\AppData\Local\Temp\352c9878-c47d-11ef-b4ea-18f7786f96ee\target.exe_352c987a-c47d-11ef-b4ea-18f7786f96ee
MD5:
SHA256:
6192Ninite.exeC:\Users\admin\AppData\Local\Temp\352c9878-c47d-11ef-b4ea-18f7786f96ee\target.exe
MD5:
SHA256:
6484Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517der
MD5:0DE8E564661932A00EB1D768264C89A2
SHA256:459907BABFCF4CD10A27DDF004B1BA356FF6697E893EA598A3A76C8776955D25
6484Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:8B4E28719EF88E81782F10B8946CEC3D
SHA256:ACEDD4537A487C6F9E311F9FE39D2F50EBE713741B09D5396B4133BE16BF2645
3260target.exeC:\Users\admin\AppData\Local\Temp\7zSCBC1E393\core\browser\VisualElements\VisualElements_150.pngimage
MD5:8E058139E0576B4AD8D424BB21071063
SHA256:E86EE493E89F5DFCE2CE8817AC5D1C04D8BA2B07A06FF0F967C0167562510DF7
6192Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5D0124FE434029F621924FE1DF99D7C7binary
MD5:2CA502DF0146F7C4F2E86231D58E3ACF
SHA256:509212F4CA53ED2224498FFD54ACA3F03015E625B9B3F0ECEB1EE1B619A4BA45
6484Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exeC:\Users\admin\AppData\Local\Temp\3399a132-c47d-11ef-b4ea-18f7786f96ee\Ninite.exeexecutable
MD5:AECEA03AB75EA848DC8BB0511A3DFD83
SHA256:168C0280421EC2CEA8ADCF34A22056839F32DF0AC3575B08F98001A10AD587C9
3260target.exeC:\Users\admin\AppData\Local\Temp\7zSCBC1E393\core\browser\VisualElements\PrivateBrowsing_70.pngimage
MD5:C9AE03C43B67A4E4986518FE3FE29756
SHA256:ADF41380B5ED3F73B8E5FB51F7F33B722F4DB4600791CDF92033267C9971C4D5
3260target.exeC:\Users\admin\AppData\Local\Temp\7zSCBC1E393\core\browser\omni.ja
MD5:
SHA256:
6484Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275Fbinary
MD5:F436E2D35C9A1388316F4EE072F8AC84
SHA256:3EF058D2BDD4734522ABACC9B23410EC15EE43F49E8652170CC390BE00731F32
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
60
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6484
Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
unknown
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6484
Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe
GET
200
151.101.2.133:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
whitelisted
6484
Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe
GET
200
151.101.2.133:80
http://ocsp.globalsign.com/codesigningrootr45/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEQCBTkIXoSl%2F7VrM1Bf4ka11
unknown
whitelisted
6484
Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe
GET
200
151.101.2.133:80
http://ocsp.globalsign.com/gsgccr45codesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLuA3ygnKW%2F7xuSx%2F09F%2BhHVuEUQQU2rONwCSQo2t30wygWd0hZ2R2C3gCDGPUxoqhhiZifL455A%3D%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.136:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
6484
Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe
65.9.66.56:443
ninite.com
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.193
  • 23.48.23.143
  • 23.48.23.190
  • 23.48.23.145
  • 23.48.23.141
  • 23.48.23.158
  • 23.48.23.147
  • 23.48.23.159
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.184.238
whitelisted
www.bing.com
  • 104.126.37.136
  • 104.126.37.129
  • 104.126.37.177
  • 104.126.37.154
  • 104.126.37.137
  • 104.126.37.185
  • 104.126.37.153
  • 104.126.37.139
  • 104.126.37.186
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ninite.com
  • 65.9.66.56
  • 65.9.66.14
  • 65.9.66.107
  • 65.9.66.60
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.38.41
shared
login.live.com
  • 40.126.32.134
  • 20.190.160.22
  • 40.126.32.68
  • 40.126.32.76
  • 40.126.32.140
  • 40.126.32.133
  • 40.126.32.72
  • 40.126.32.138
unknown
ocsp.globalsign.com
  • 151.101.2.133
  • 151.101.194.133
  • 151.101.66.133
  • 151.101.130.133
whitelisted

Threats

No threats detected
No debug info