File name:

Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe

Full analysis: https://app.any.run/tasks/18c3b318-6d91-419a-b766-554b45269227
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: December 27, 2024, 18:05:45
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

3EE0D0A7731C6690F05BD464C445CCDD

SHA1:

76CA249B923AF396DC1DFC99A4DF9C6C0CDE1A6B

SHA256:

88FAABF5436296AA5322AD612CF310A6C0EF7526112B9BB2CEC7405867B5EA53

SSDEEP:

12288:XLVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzEO:bVP60BM2pMUN9keo+c+zEO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.exe (PID: 3060)
    • Actions looks like stealing of personal data

      • target.exe (PID: 2756)
      • target.exe (PID: 5388)
      • assistant_installer.exe (PID: 4228)
      • assistant_installer.exe (PID: 6352)
      • target.exe (PID: 4648)
    • Steals credentials from Web Browsers

      • target.exe (PID: 5388)
      • target.exe (PID: 2756)
      • target.exe (PID: 4648)
      • assistant_installer.exe (PID: 4228)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • maintenanceservice_tmp.exe (PID: 6316)
      • Ninite.exe (PID: 6192)
      • target.exe (PID: 2756)
      • target.exe (PID: 5388)
      • target.exe (PID: 5464)
      • target.exe (PID: 5916)
      • assistant_package_sfx.exe (PID: 6176)
      • target.exe (PID: 4648)
    • Reads security settings of Internet Explorer

      • Ninite.exe (PID: 7036)
      • Ninite.exe (PID: 6192)
      • maintenanceservice_installer.exe (PID: 1576)
      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 2756)
    • Application launched itself

      • Ninite.exe (PID: 7036)
      • target.exe (PID: 2756)
      • target.exe (PID: 5464)
      • assistant_installer.exe (PID: 6352)
    • Searches for installed software

      • Ninite.exe (PID: 6192)
      • setup.exe (PID: 3060)
    • Process drops legitimate windows executable

      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
      • assistant_package_sfx.exe (PID: 6176)
    • The process drops C-runtime libraries

      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
    • The process drops Mozilla's DLL files

      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
    • Checks Windows Trust Settings

      • Ninite.exe (PID: 6192)
      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 2756)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 6356)
    • Loads DLL from Mozilla Firefox

      • regsvr32.exe (PID: 6356)
      • default-browser-agent.exe (PID: 6704)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
    • Creates a software uninstall entry

      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
    • Starts itself from another location

      • target.exe (PID: 2756)
  • INFO

    • Create files in a temporary directory

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 6192)
      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • target.exe (PID: 2756)
      • target.exe (PID: 5388)
      • target.exe (PID: 5916)
      • target.exe (PID: 5464)
      • assistant_package_sfx.exe (PID: 6176)
    • The sample compiled with english language support

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • target.exe (PID: 5388)
      • target.exe (PID: 2756)
      • target.exe (PID: 5916)
      • target.exe (PID: 5464)
      • assistant_package_sfx.exe (PID: 6176)
      • target.exe (PID: 4648)
    • Checks supported languages

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 7036)
      • Ninite.exe (PID: 6192)
      • target.exe (PID: 3260)
      • setup.exe (PID: 3060)
      • maintenanceservice_tmp.exe (PID: 6316)
      • maintenanceservice_installer.exe (PID: 1576)
      • target.exe (PID: 2756)
      • default-browser-agent.exe (PID: 6704)
      • target.exe (PID: 5388)
      • target.exe (PID: 5464)
      • assistant_installer.exe (PID: 4228)
    • The process uses the downloaded file

      • Ninite.exe (PID: 7036)
      • Ninite.exe (PID: 6192)
    • Creates files or folders in the user directory

      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • Ninite.exe (PID: 6192)
      • target.exe (PID: 2756)
      • target.exe (PID: 5388)
    • Reads the computer name

      • Ninite.exe (PID: 6192)
      • Ninite.exe (PID: 7036)
      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • maintenanceservice_tmp.exe (PID: 6316)
      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 2756)
      • target.exe (PID: 5464)
    • Process checks computer location settings

      • Ninite.exe (PID: 7036)
    • Checks proxy server information

      • Ninite.exe (PID: 6192)
      • setup.exe (PID: 3060)
      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 2756)
    • Reads the machine GUID from the registry

      • Ninite.exe (PID: 6192)
      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 2756)
    • Reads the software policy settings

      • Ninite.exe (PID: 6192)
      • Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe (PID: 6484)
      • target.exe (PID: 2756)
    • Creates files in the program directory

      • setup.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 1576)
      • target.exe (PID: 5464)
    • Application launched itself

      • firefox.exe (PID: 6960)
      • firefox.exe (PID: 4548)
    • Sends debugging messages

      • assistant_installer.exe (PID: 6352)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:04:12 00:19:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 233472
InitializedDataSize: 182272
UninitializedDataSize: -
EntryPoint: 0x1a53a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.1.1.1183
ProductVersionNumber: 0.1.1.1183
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Secure By Design Inc.
FileDescription: Ninite
FileVersion: 0,1,1,1183
InternalName: Ninite
LegalCopyright: Copyright (C) 2009 Secure By Design Inc
OriginalFileName: -
ProductName: Ninite
ProductVersion: 0,1,1,1183
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
21
Malicious processes
12
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ninite 7zip chrome firefox keepass 2 notepad installer.exe ninite.exe no specs ninite.exe target.exe setup.exe regsvr32.exe no specs maintenanceservice_installer.exe maintenanceservice_tmp.exe default-browser-agent.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs target.exe target.exe target.exe target.exe target.exe assistant_package_sfx.exe assistant_installer.exe assistant_installer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1576"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe
setup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Mozilla Maintenance Service Installer
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\maintenanceservice_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2756"C:\Users\admin\AppData\Local\Temp\3EF47D~1\target.exe" /install /install /silent /launchopera=0 /desktopshortcut=1 /quicklaunchshortcut=0 /setdefaultbrowser=0 /all_users=1 --setdefaultbrowser=0 --allusers=1C:\Users\admin\AppData\Local\Temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
Ninite.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Version:
115.0.5322.119
Modules
Images
c:\users\admin\appdata\local\temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3060.\setup.exe -msC:\Users\admin\AppData\Local\Temp\7zSCBC1E393\setup.exe
target.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox Installer
Exit code:
0
Version:
133.0.3
Modules
Images
c:\users\admin\appdata\local\temp\7zscbc1e393\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
3260"C:\Users\admin\AppData\Local\Temp\352C98~1\target.exe" -msC:\Users\admin\AppData\Local\Temp\352c9878-c47d-11ef-b4ea-18f7786f96ee\target.exe
Ninite.exe
User:
admin
Company:
Mozilla
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
18.05
Modules
Images
c:\users\admin\appdata\local\temp\352c9878-c47d-11ef-b4ea-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4228"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202412271806401\assistant\assistant_installer.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x230,0x234,0x238,0x20c,0x23c,0x7ff6999d9618,0x7ff6999d9624,0x7ff6999d9630C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202412271806401\assistant\assistant_installer.exe
assistant_installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Browser Assistant Installer
Exit code:
0
Version:
115.0.5322.119
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\opera_package_202412271806401\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4548"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask installC:\Program Files\Mozilla Firefox\firefox.exesetup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\vcruntime140.dll
4648C:\Users\admin\AppData\Local\Temp\3EF47D~1\target.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x280,0x284,0x294,0x25c,0x298,0x7ff820564e20,0x7ff820564e2c,0x7ff820564e38C:\Users\admin\AppData\Local\Temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
target.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Version:
115.0.5322.119
Modules
Images
c:\users\admin\appdata\local\temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5040"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask installC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
5388C:\Users\admin\AppData\Local\Temp\3EF47D~1\target.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x288,0x28c,0x290,0x264,0x294,0x7ff8211a4e20,0x7ff8211a4e2c,0x7ff8211a4e38C:\Users\admin\AppData\Local\Temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
target.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Version:
115.0.5322.119
Modules
Images
c:\users\admin\appdata\local\temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5464"C:\Users\admin\AppData\Local\Temp\3EF47D~1\target.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=0 --general-interests=0 --general-location=0 --personalized-content=0 --personalized-ads=0 --launchopera=0 --showunbox=0 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=1 --setdefaultbrowser=0 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --show-intro-overlay --server-tracking-data=server_tracking_data --initial-pid=2756 --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20241227180640" --session-guid=b6baa4c6-4307-44cc-bce6-e54be0519720 --server-tracking-blob="NjFkODk4ZWJjMmNmNGQ1YjllMzkyYmJlMjJiYmQ5MDY3ZjdhY2U0Y2Y1NWMzYTQwM2Q2Zjk0N2YzZTU1NDA1Yzp7InByb2R1Y3QiOnsibmFtZSI6Ik9wZXJhIn0sInN5c3RlbSI6eyJwbGF0Zm9ybSI6eyJhcmNoIjoieDg2XzY0Iiwib3BzeXMiOiJXaW5kb3dzIiwib3BzeXMtdmVyc2lvbiI6IjEwIiwicGFja2FnZSI6IkVYRSJ9fX0= " --silent --desktopshortcut=1 --wait-for-package --initial-proc-handle=4C05000000000000C:\Users\admin\AppData\Local\Temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
target.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Version:
115.0.5322.119
Modules
Images
c:\users\admin\appdata\local\temp\3ef47d32-c47d-11ef-b4ea-18f7786f96ee\target.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
17 374
Read events
17 280
Write events
68
Delete events
26

Modification events

(PID) Process:(6356) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs
Operation:writeName:C:\Program Files\Mozilla Firefox
Value:
308046B0AF4A39CB
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 133.0.3 (x64 en-US)
Operation:writeName:EstimatedSize
Value:
257624
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB
Operation:writeName:FriendlyTypeName
Value:
Firefox HTML Document
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\shell\open\ddeexec
Operation:delete keyName:(default)
Value:
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxPDF-308046B0AF4A39CB
Operation:writeName:FriendlyTypeName
Value:
Firefox PDF Document
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxPDF-308046B0AF4A39CB\shell\open\ddeexec
Operation:delete keyName:(default)
Value:
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxURL-308046B0AF4A39CB\shell\open\ddeexec
Operation:delete keyName:(default)
Value:
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\InstallInfo
Operation:writeName:HideIconsCommand
Value:
"C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts
(PID) Process:(3060) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Firefox-308046B0AF4A39CB\InstallInfo
Operation:writeName:ShowIconsCommand
Value:
"C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts
Executable files
95
Suspicious files
72
Text files
46
Unknown types
7

Dropped files

PID
Process
Filename
Type
6192Ninite.exeC:\Users\admin\AppData\Local\Temp\352c9878-c47d-11ef-b4ea-18f7786f96ee\target.exe_352c987a-c47d-11ef-b4ea-18f7786f96ee
MD5:
SHA256:
6192Ninite.exeC:\Users\admin\AppData\Local\Temp\352c9878-c47d-11ef-b4ea-18f7786f96ee\target.exe
MD5:
SHA256:
6484Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275Fder
MD5:1715487539A5FE41E6F592A8A1728142
SHA256:CB20D073A7FADB8252E243138450AC4BE3A4626180359A9FA8BC45FE37A89567
6192Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_ADE4E4D3A3BCBCA5C39C54D362D88565binary
MD5:A8B47769E606E6902A9171EE9AC34B2F
SHA256:4BC7A2E683B91D883066D40D6F7DE299300881A36D17FA87BED7229129DE02F9
6192Ninite.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5D0124FE434029F621924FE1DF99D7C7binary
MD5:878FAE523D85C620C12D8B04EF7ED2F3
SHA256:F7811D69A9E582D397E8831C154221666E3469F9E23D0C57FFB412BBF6DB7AD0
6484Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41Cbinary
MD5:D1AD71C4385980797259AD339D32D7FC
SHA256:926F9F595BE150A28DD9C7CA4764433D5D3007FB7961DE93D3081090D09CE6E6
6484Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:8B4E28719EF88E81782F10B8946CEC3D
SHA256:ACEDD4537A487C6F9E311F9FE39D2F50EBE713741B09D5396B4133BE16BF2645
6484Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9CB4373A4252DE8D2212929836304EC5_A784AE3E993E9BBF7162E8F9F9758D3Dder
MD5:01441B25795958D856EF2A7078A1830D
SHA256:FDABC00AD8C0B56700BE874EEBC41ECD9AE7F734B8BA57CE463D9006467ACEEF
3260target.exeC:\Users\admin\AppData\Local\Temp\7zSCBC1E393\core\browser\omni.ja
MD5:
SHA256:
6484Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_A784AE3E993E9BBF7162E8F9F9758D3Dbinary
MD5:D6653C404659E4CA5726923D104DAAD1
SHA256:D8256387AF7E76F2A7787A3DEAC69FBE0058935A454CA6EB4365941A00AB4717
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
60
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6484
Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
unknown
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6484
Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe
GET
200
151.101.2.133:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
whitelisted
6484
Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe
GET
200
151.101.2.133:80
http://ocsp.globalsign.com/codesigningrootr45/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEQCBTkIXoSl%2F7VrM1Bf4ka11
unknown
whitelisted
6484
Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe
GET
200
151.101.2.133:80
http://ocsp.globalsign.com/gsgccr45codesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLuA3ygnKW%2F7xuSx%2F09F%2BhHVuEUQQU2rONwCSQo2t30wygWd0hZ2R2C3gCDGPUxoqhhiZifL455A%3D%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.136:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
6484
Ninite 7Zip Chrome Firefox KeePass 2 Notepad Installer.exe
65.9.66.56:443
ninite.com
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.193
  • 23.48.23.143
  • 23.48.23.190
  • 23.48.23.145
  • 23.48.23.141
  • 23.48.23.158
  • 23.48.23.147
  • 23.48.23.159
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.184.238
whitelisted
www.bing.com
  • 104.126.37.136
  • 104.126.37.129
  • 104.126.37.177
  • 104.126.37.154
  • 104.126.37.137
  • 104.126.37.185
  • 104.126.37.153
  • 104.126.37.139
  • 104.126.37.186
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ninite.com
  • 65.9.66.56
  • 65.9.66.14
  • 65.9.66.107
  • 65.9.66.60
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.38.41
shared
login.live.com
  • 40.126.32.134
  • 20.190.160.22
  • 40.126.32.68
  • 40.126.32.76
  • 40.126.32.140
  • 40.126.32.133
  • 40.126.32.72
  • 40.126.32.138
unknown
ocsp.globalsign.com
  • 151.101.2.133
  • 151.101.194.133
  • 151.101.66.133
  • 151.101.130.133
whitelisted

Threats

No threats detected
No debug info