| File name: | Firefox Installer.exe |
| Full analysis: | https://app.any.run/tasks/553a65b7-5437-4cea-b056-be00743947ea |
| Verdict: | Malicious activity |
| Analysis date: | January 08, 2025, 16:13:22 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections |
| MD5: | 04C3E1B7EB4DD63317EB54B3E5089675 |
| SHA1: | 0BE38E5D8C5268F0A297A351650B7EAE11B9255F |
| SHA256: | 8F25D5220EE8E2305575FCA71A6D229F1EF2FD7E5CA5780D7E899BFF4AEC4219 |
| SSDEEP: | 12288:sSvvp2jRWmtab28hx/vKv2D9irEEcwyvawvS5SggO0t5vkg:sSHp2jQmAS0x/vKvs9eERfSwvX1Nt5vF |
| .exe | | | UPX compressed Win32 Executable (64.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.6) |
| .exe | | | Win32 Executable (generic) (10.6) |
| .exe | | | Generic Win/DOS Executable (4.7) |
| .exe | | | DOS Executable Generic (4.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:08:30 22:18:33+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 69632 |
| InitializedDataSize: | 65536 |
| UninitializedDataSize: | 147456 |
| EntryPoint: | 0x34fa0 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 18.5.0.0 |
| ProductVersionNumber: | 18.5.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Mozilla |
| FileDescription: | Firefox |
| FileVersion: | 18.05 |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Mozilla |
| OriginalFileName: | 7zS.sfx.exe |
| ProductName: | Firefox |
| ProductVersion: | 18.05 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1828 | "C:\Users\admin\AppData\Local\Temp\Firefox Installer.exe" | C:\Users\admin\AppData\Local\Temp\Firefox Installer.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 18.05 Modules
| |||||||||||||||
| 2088 | "C:\Program Files\Mozilla Firefox\default-browser-agent.exe" register-task 308046B0AF4A39CB | C:\Program Files\Mozilla Firefox\default-browser-agent.exe | — | setup.exe | |||||||||||
User: admin Company: Mozilla Foundation Integrity Level: HIGH Exit code: 0 Version: 134.0 Modules
| |||||||||||||||
| 2212 | "C:\Users\admin\AppData\Local\Temp\nse613F.tmp\download.exe" /LaunchedFromStub /INI=C:\Users\admin\AppData\Local\Temp\nse613F.tmp\config.ini | C:\Users\admin\AppData\Local\Temp\nse613F.tmp\download.exe | setup-stub.exe | ||||||||||||
User: admin Company: Mozilla Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 18.05 Modules
| |||||||||||||||
| 2452 | "C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe" | C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe | setup.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Mozilla Maintenance Service Installer Exit code: 0 Version: 134.0 Modules
| |||||||||||||||
| 2756 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 134.0 Modules
| |||||||||||||||
| 3576 | "C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent register-task 308046B0AF4A39CB | C:\Program Files\Mozilla Firefox\firefox.exe | — | default-browser-agent.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 134.0 Modules
| |||||||||||||||
| 3680 | "C:\Users\admin\AppData\Local\Temp\7zS4271B603\setup-stub.exe" /UAC:702C8 /NCRC | C:\Users\admin\AppData\Local\Temp\7zS4271B603\setup-stub.exe | setup-stub.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Installer Exit code: 0 Version: 134.0 Modules
| |||||||||||||||
| 3840 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4652 -prefsLen 27596 -prefMapHandle 4456 -prefMapSize 265037 -jsInitHandle 4452 -jsInitLen 254356 -parentBuildID 20241230151726 -ipcHandle 4444 -initialChannelId {24c5f2e8-773c-485b-9e67-84b1a7723d8c} -parentPid 6496 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6496" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 9 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 134.0 Modules
| |||||||||||||||
| 3848 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20241230151726 -prefsHandle 2148 -prefsLen 23417 -prefMapHandle 2152 -prefMapSize 265037 -ipcHandle 2104 -initialChannelId {195b95c6-439a-4c49-8bb4-ae92740f7a4f} -parentPid 2756 -crashReporter "\\.\pipe\gecko-crash-server-pipe.2756" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 134.0 | |||||||||||||||
| 4160 | .\setup-stub.exe | C:\Users\admin\AppData\Local\Temp\7zS4271B603\setup-stub.exe | Firefox Installer.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Installer Exit code: 0 Version: 134.0 Modules
| |||||||||||||||
| (PID) Process: | (3680) setup-stub.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox |
Value: 308046B0AF4A39CB | |||
| (PID) Process: | (3680) setup-stub.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3680) setup-stub.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3680) setup-stub.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3680) setup-stub.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFavoritesInitialSelection |
Value: | |||
| (PID) Process: | (3680) setup-stub.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFeedsInitialSelection |
Value: | |||
| (PID) Process: | (4228) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox |
Value: 308046B0AF4A39CB | |||
| (PID) Process: | (4228) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB |
| Operation: | write | Name: | FriendlyTypeName |
Value: Firefox HTML Document | |||
| (PID) Process: | (4228) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\shell\open\ddeexec |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4228) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxPDF-308046B0AF4A39CB |
| Operation: | write | Name: | FriendlyTypeName |
Value: Firefox PDF Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1828 | Firefox Installer.exe | C:\Users\admin\AppData\Local\Temp\7zS4271B603\postSigningData | text | |
MD5:DE228A6CFD36EC7D11445447A52C09F5 | SHA256:50DEF86F44839E6FBEF8624DD5AA801F73DBC4B2064843850BECCBA8B8E5D6A3 | |||
| 4160 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsx5C8C.tmp\UAC.dll | executable | |
MD5:D23B256E9C12FE37D984BAE5017C5F8C | SHA256:EC6A56D981892BF251DF1439BEA425A5F6C7E1C7312D44BEDD5E2957F270338C | |||
| 4160 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsx5C8C.tmp\System.dll | executable | |
MD5:B361682FA5E6A1906E754CFA08AA8D90 | SHA256:B711C4F17690421C9DC8DDB9ED5A9DDC539B3A28F11E19C851E25DCFC7701C04 | |||
| 3680 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nse613F.tmp\UAC.dll | executable | |
MD5:D23B256E9C12FE37D984BAE5017C5F8C | SHA256:EC6A56D981892BF251DF1439BEA425A5F6C7E1C7312D44BEDD5E2957F270338C | |||
| 3680 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nse613F.tmp\System.dll | executable | |
MD5:B361682FA5E6A1906E754CFA08AA8D90 | SHA256:B711C4F17690421C9DC8DDB9ED5A9DDC539B3A28F11E19C851E25DCFC7701C04 | |||
| 3680 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nse613F.tmp\bgstub.jpg | image | |
MD5:C55F15CEEDC724D6C6E15D1DAF96B698 | SHA256:4B7E441D51B790EE1C0BAFF19E4E968392A937877DFA8B84E74464F5BA7A4CF4 | |||
| 3680 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nse613F.tmp\stub_common.css | text | |
MD5:544B51F11AD19DF720669478D28F129D | SHA256:4D9495B6F0E18331659993B79440E414A6E607FCDAEACBC7477E0683CC0FA98B | |||
| 3680 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nse613F.tmp\CityHash.dll | executable | |
MD5:2021ACC65FA998DAA98131E20C4605BE | SHA256:C299A0A71BF57EB241868158B4FCFE839D15D5BA607E1BDC5499FDF67B334A14 | |||
| 3680 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nse613F.tmp\InetBgDL.dll | executable | |
MD5:AF9E2D138CF17B8FF4D4B8DF7FDDAEFA | SHA256:3921DEC014FADD1DE7F3A36606AC95882A17CB96DF38A5424E58531A169F825B | |||
| 3680 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nse613F.tmp\stub_common.js | text | |
MD5:EFCE3DCE0165B3F6551DB47E5C0AC8D6 | SHA256:DAB39CBAE31848CCE0B5C43FDDD2674FEF4DEA5B7A3DACDAABDC78A8A931817E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3680 | setup-stub.exe | GET | 200 | 18.66.145.213:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D | unknown | — | — | unknown |
3680 | setup-stub.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | whitelisted |
6496 | firefox.exe | POST | 200 | 184.24.77.62:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
3680 | setup-stub.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAc3sNDc3KuNeNL0DLEi%2BT8%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6496 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
3680 | setup-stub.exe | GET | 200 | 34.120.208.123:80 | http://download-stats.mozilla.org/stub/v9/release/release/it/1/1/10/0/19045/0/0/0/2/0/68855056/68855056/0/0/16/16/0/0/12/0/0/0/1/123.0/20240213221259/134.0/20241230151726/1/1/0/1/34.117.35.28/dlsource%3Dmozillaci/2/1/0/0/4046/20241230151726 | unknown | — | — | whitelisted |
6496 | firefox.exe | POST | 200 | 184.24.77.62:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
6496 | firefox.exe | POST | 200 | 184.24.77.62:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
6496 | firefox.exe | POST | 200 | 184.24.77.62:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5864 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2452 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3680 | setup-stub.exe | 18.245.86.112:443 | product-details.mozilla.org | — | US | shared |
3680 | setup-stub.exe | 18.66.145.213:80 | ocsp.rootca1.amazontrust.com | AMAZON-02 | US | shared |
5864 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5864 | svchost.exe | 2.16.164.113:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5864 | svchost.exe | 23.209.210.103:80 | www.microsoft.com | PT. Telekomunikasi Selular | ID | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
product-details.mozilla.org |
| shared |
ocsp.rootca1.amazontrust.com |
| shared |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
download.mozilla.org |
| unknown |
ocsp.digicert.com |
| whitelisted |
download-installer.cdn.mozilla.net |
| whitelisted |
x1.c.lencr.org |
| whitelisted |