| URL: | https://firebasestorage.googleapis.com/v0/b/remasd-6c702.firebasestorage.app/o/image.jpg?alt=media&token=c16438a4-4eeb-4116-adc7-373fbf7359b0 |
| Full analysis: | https://app.any.run/tasks/502f7980-4622-4ffb-8c1d-9485504797c0 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | January 31, 2026, 12:02:42 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 5A5CBE743DF10239AF707723084775AB |
| SHA1: | 7E0B215A333710A17ECE43FE86F2612037B41554 |
| SHA256: | 9746EE0BE01B3DDD21A72A5D5C9911D7228C34288311423BFB10B8A4B105983A |
| SSDEEP: | 3:N8dHElMKKhmHEVJ/+TF+QHiZKMIU7HjRqLYPRW5KDIWMy:2FElLZH/TvC0MIOcKRW5KIo |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1116 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 2420 -prefsLen 39330 -prefMapHandle 4460 -prefMapSize 272981 -jsInitHandle 4988 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4916 -initialChannelId {42fcf681-5a22-4d5e-aeb0-85e66f615e2c} -parentPid 1984 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1984" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 1848 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3320 -prefsLen 37207 -prefMapHandle 3324 -prefMapSize 272981 -ipcHandle 3332 -initialChannelId {12b6e81c-f70d-44f6-ad41-314ccd3655d0} -parentPid 1984 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1984" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 136.0 Modules
| |||||||||||||||
| 1984 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://firebasestorage.googleapis.com/v0/b/remasd-6c702.firebasestorage.app/o/image.jpg?alt=media&token=c16438a4-4eeb-4116-adc7-373fbf7359b0 | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 2016 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4868 -prefsLen 45319 -prefMapHandle 4888 -prefMapSize 272981 -jsInitHandle 4900 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 2740 -initialChannelId {50f461e4-3fb0-4c8d-b48a-64e0b12e36c9} -parentPid 1984 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1984" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 9 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 2288 | "C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Downloads\image.jpg" | C:\Windows\System32\mspaint.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Paint Exit code: 0 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2572 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 1944 -prefsLen 36521 -prefMapHandle 1948 -prefMapSize 272981 -ipcHandle 1912 -initialChannelId {71ba935b-04b9-4148-9017-802dbaf590e8} -parentPid 1984 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1984" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 136.0 Modules
| |||||||||||||||
| 4700 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3936 -prefsLen 45165 -prefMapHandle 3940 -prefMapSize 272981 -jsInitHandle 3944 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3952 -initialChannelId {01fb51ad-9f9e-4681-83dd-227e4e49bae9} -parentPid 1984 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1984" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 5100 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3236 -prefsLen 31275 -prefMapHandle 3240 -prefMapSize 272981 -jsInitHandle 3244 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3252 -initialChannelId {4e84194f-6563-4b3a-b5ea-9be8788dff41} -parentPid 1984 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1984" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 5520 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 4 -prefsHandle 4872 -prefsLen 45400 -prefMapHandle 4876 -prefMapSize 272981 -ipcHandle 5392 -initialChannelId {e857af0a-5c68-4a6f-b3ed-e2fb86910a66} -parentPid 1984 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1984" -appDir "C:\Program Files\Mozilla Firefox\browser" - 11 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 136.0 Modules
| |||||||||||||||
| 6240 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4868 -prefsLen 39330 -prefMapHandle 4872 -prefMapSize 272981 -jsInitHandle 4876 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3796 -initialChannelId {872fe565-0123-4650-8705-0090b02fbfb4} -parentPid 1984 -crashReporter "\\.\pipe\gecko-crash-server-pipe.1984" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| (PID) Process: | (2288) mspaint.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View |
| Operation: | write | Name: | WindowPlacement |
Value: 2C00000000000000010000000000000000000000FFFFFFFFFFFFFFFF870000004C000000C7040000B2020000 | |||
| (PID) Process: | (2288) mspaint.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View |
| Operation: | write | Name: | ShowThumbnail |
Value: 0 | |||
| (PID) Process: | (2288) mspaint.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View |
| Operation: | write | Name: | BMPWidth |
Value: 0 | |||
| (PID) Process: | (2288) mspaint.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View |
| Operation: | write | Name: | BMPHeight |
Value: 0 | |||
| (PID) Process: | (2288) mspaint.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View |
| Operation: | write | Name: | ThumbXPos |
Value: 0 | |||
| (PID) Process: | (2288) mspaint.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View |
| Operation: | write | Name: | ThumbYPos |
Value: 0 | |||
| (PID) Process: | (2288) mspaint.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View |
| Operation: | write | Name: | ThumbWidth |
Value: 0 | |||
| (PID) Process: | (2288) mspaint.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View |
| Operation: | write | Name: | ThumbHeight |
Value: 0 | |||
| (PID) Process: | (2288) mspaint.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View |
| Operation: | write | Name: | UnitSetting |
Value: 0 | |||
| (PID) Process: | (2288) mspaint.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View |
| Operation: | write | Name: | ShowRulers |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1984 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 1984 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:AA67738B5778177FD33C852DE2187A82 | SHA256:CA9F8B9F4C97C66EFD4FC504F0B50C380C25788508FF8B1F6166F10F50B359B7 | |||
| 1984 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1984 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\activity-stream.discovery_stream.json | text | |
MD5:EFFB621901AE4C3C99EC4DDF2EA1635A | SHA256:357EB4C17A7C7F33BA6869E8013445582A07F437DDC8BEC9D0FD416CCBDA241A | |||
| 1984 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.bin | binary | |
MD5:5152D8F49F1AD4219D935611EFE18437 | SHA256:9A6E50715E3C49A43E3D622EDE7E37ECF0767342B3039B8B0AE25BBE4FF6F66E | |||
| 1984 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | text | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 1984 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:3134ED3F12E4F4F8643DB90043B0FD7B | SHA256:26E4F122034D7A03F6DA0E707799B09CBEEBDAF8D7A3133A1F7BD894AC72EEA1 | |||
| 1984 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1984 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1984 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | text | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1984 | firefox.exe | GET | 101 | 34.107.243.93:443 | https://push.services.mozilla.com/ | US | — | — | unknown |
1984 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | US | text | 90 b | unknown |
1984 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/we2 | US | binary | 280 b | whitelisted |
1984 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/s/wr3/peI | US | binary | 472 b | whitelisted |
1984 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/we2 | US | binary | 280 b | whitelisted |
1984 | firefox.exe | GET | 200 | 151.101.65.91:443 | https://firefox.settings.services.mozilla.com/v1/ | US | text | 1.20 Kb | unknown |
1984 | firefox.exe | GET | 200 | 151.101.65.91:443 | https://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?collection=url-parser-default-unknown-schemes-interventions&bucket=main&_expected=0 | US | text | 274 b | unknown |
1984 | firefox.exe | GET | 200 | 151.101.65.91:443 | https://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?collection=hijack-blocklists&bucket=main&_expected=0 | US | text | 243 b | unknown |
1984 | firefox.exe | GET | 200 | 151.101.65.91:443 | https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/hijack-blocklists?_expected=1605801189258 | US | text | 1.68 Kb | unknown |
1984 | firefox.exe | GET | 200 | 34.36.137.203:443 | https://contile.services.mozilla.com/v1/tiles | US | text | 4.99 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
7004 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3656 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
1984 | firefox.exe | 151.101.65.91:443 | firefox.settings.services.mozilla.com | FASTLY | US | whitelisted |
1984 | firefox.exe | 172.217.16.170:443 | firebasestorage.googleapis.com | GOOGLE | US | whitelisted |
1984 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
1984 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
1984 | firefox.exe | 172.217.16.195:80 | o.pki.goog | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
mozilla.map.fastly.net |
| whitelisted |
firebasestorage.googleapis.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1984 | firefox.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to connect to TLS FireBase Storage |
1984 | firefox.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to connect to TLS FireBase Storage |
1984 | firefox.exe | A Network Trojan was detected | ET MALWARE Base64 Encoded MZ In Image |
1984 | firefox.exe | A Network Trojan was detected | PAYLOAD [ANY.RUN] Stegocampaign Jpeg with base64 added (TA558) |
1984 | firefox.exe | A Network Trojan was detected | PAYLOAD [ANY.RUN] Base64 encoded PE EXE file inside JPEG image |
1984 | firefox.exe | A Network Trojan was detected | ET MALWARE ReverseLoader Reverse Base64 Encoded Executable In Image M2 |
7004 | svchost.exe | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
1984 | firefox.exe | A Network Trojan was detected | ET MALWARE Base64 Encoded MZ In Image |
1984 | firefox.exe | A Network Trojan was detected | PAYLOAD [ANY.RUN] Base64 encoded PE EXE file inside JPEG image |
1984 | firefox.exe | A Network Trojan was detected | PAYLOAD [ANY.RUN] Stegocampaign Jpeg with base64 added (TA558) |