| URL: | https://cdn.discordapp.com/attachments/1172994496879935552/1172994549975625809/Install.rar?ex=6562574d&is=654fe24d&hm=22010ab84184409f71ff95362d54cc4ac021707efd8060eb00c52db882648d20& |
| Full analysis: | https://app.any.run/tasks/4fb9746a-14b7-4bbe-9b38-3dfda9d83fb4 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | November 12, 2023, 22:34:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| SHA1: | 2170B5189B7BA77CBCAAE1A960067EEC44C703C9 |
| SHA256: | 9C5738C0F4272EE78866C6DF2D925814C8DA9538B2A6F8ED4A77E1A2E1CF7972 |
| SSDEEP: | 3:N8cCWdy6//NSXcFRSZQCPgVQXRirKaiARR1NIY1F9ydwf/GGiCXUSdLizVdLVDn:2cry6XNSXczYtY6XtaiARRHIEF4dwGGg |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 308 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.1.419357371\458963473" -parentBuildID 20230710165010 -prefsHandle 1404 -prefMapHandle 1400 -prefsLen 29857 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1559b424-a6cd-4401-8665-21d2d358c2aa} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 1416 f9d3858 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 460 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.7.306662710\783622735" -childID 6 -isForBrowser -prefsHandle 3988 -prefMapHandle 3992 -prefsLen 35561 -prefMapSize 244187 -jsInitHandle 848 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {71cabe67-c1e2-4390-a843-196784e27d45} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 3980 2345e558 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1164 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.6.535281084\1968945430" -childID 5 -isForBrowser -prefsHandle 3836 -prefMapHandle 3756 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 848 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c0ba983a-1698-464d-b6c8-bc68d61489f0} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 3840 1fc84e58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1416 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.5.83439166\1168635926" -childID 4 -isForBrowser -prefsHandle 3652 -prefMapHandle 3584 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 848 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {db0eeb8b-68d5-443e-a5ca-ba8e28e5ca87} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 3672 1fc83958 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1644 | 7z.exe e extracted/file_8.zip -oextracted | C:\Users\admin\AppData\Local\Temp\main\7z.exe | — | cmd.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Console Exit code: 0 Version: 19.00 Modules
| |||||||||||||||
| 1696 | 7z.exe e extracted/file_9.zip -oextracted | C:\Users\admin\AppData\Local\Temp\main\7z.exe | — | cmd.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Console Exit code: 0 Version: 19.00 Modules
| |||||||||||||||
| 2220 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.2.965310401\2110894171" -childID 1 -isForBrowser -prefsHandle 2044 -prefMapHandle 2040 -prefsLen 25524 -prefMapSize 244187 -jsInitHandle 848 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {440b3bfa-491a-4093-ac51-5ea27a0ccd62} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 2060 1994c758 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2228 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.0.1155360764\2135018522" -parentBuildID 20230710165010 -prefsHandle 1104 -prefMapHandle 1096 -prefsLen 29780 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6de6160e-56e8-43ac-b81e-79eae6d9d4b3} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 1196 f9d2058 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2280 | 7z.exe e extracted/file_3.zip -oextracted | C:\Users\admin\AppData\Local\Temp\main\7z.exe | — | cmd.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Console Exit code: 0 Version: 19.00 Modules
| |||||||||||||||
| 2412 | 7z.exe e extracted/file_5.zip -oextracted | C:\Users\admin\AppData\Local\Temp\main\7z.exe | — | cmd.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Console Exit code: 0 Version: 19.00 Modules
| |||||||||||||||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0000000000000000 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 0 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: F8B731ACA1C5D901 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2700 | firefox.exe | C:\Users\admin\Downloads\Install.E_CPdMLK.rar.part | — | |
MD5:— | SHA256:— | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs-1.js | text | |
MD5:F42921723A3596D2FA57BE1279C18862 | SHA256:5D6A78D6523693521C6D337C72269B0320B0C5A82D699D74FF2490813574C652 | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs.js | text | |
MD5:F42921723A3596D2FA57BE1279C18862 | SHA256:5D6A78D6523693521C6D337C72269B0320B0C5A82D699D74FF2490813574C652 | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\doomed\3971 | compressed | |
MD5:58BF90C279D403DC2DFB9B9DF37D9B81 | SHA256:4A922FE9DF274368DBD30EC32F033BC5404E868AE1F512F6CFB291D7A4D781C5 | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.bin | binary | |
MD5:4DF9B77C7650AF87B264E535779AE2A4 | SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58 | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2700 | firefox.exe | GET | 304 | 23.53.40.129:80 | http://ciscobinary.openh264.org/openh264-win64-31c4d2e4a037526fd30d4e5c39f60885986cf865.zip | unknown | — | — | unknown |
2700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
2700 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
2700 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2700 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2700 | firefox.exe | POST | 200 | 13.249.8.192:80 | http://ocsp.r2m02.amazontrust.com/ | unknown | binary | 471 b | unknown |
2700 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2700 | firefox.exe | POST | 200 | 216.58.206.35:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
2700 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2700 | firefox.exe | 162.159.133.233:443 | cdn.discordapp.com | CLOUDFLARENET | — | shared |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2700 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
2700 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2700 | firefox.exe | 35.168.31.31:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
2700 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | unknown |
2700 | firefox.exe | 2.16.202.121:80 | r3.o.lencr.org | Akamai International B.V. | NL | unknown |
2700 | firefox.exe | 13.249.8.192:80 | ocsp.r2m02.amazontrust.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
cdn.discordapp.com |
| shared |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
content-signature-2.cdn.mozilla.net |
| whitelisted |
r3.o.lencr.org |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
324 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discordapp .com) |
324 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discordapp .com) |
324 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discordapp .com) |
2700 | firefox.exe | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
324 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.pw domain - Likely Hostile |
3848 | Install.exe | Misc activity | ET INFO HTTP Request to a *.pw domain |
3848 | Install.exe | Malware Command and Control Activity Detected | ET MALWARE [ANY.RUN] Win32/Lumma Stealer Check-In |
3848 | Install.exe | Malware Command and Control Activity Detected | STEALER [ANY.RUN] Win32/Lumma Stealer Check-In |
3848 | Install.exe | Misc activity | ET INFO HTTP Request to a *.pw domain |
3848 | Install.exe | Malware Command and Control Activity Detected | ET MALWARE [ANY.RUN] Win32/Lumma Stealer Exfiltration |