| URL: | https://www.torrentdownloads.pro/torrent/1664848545/Zoo-%282017%29-720p-WEB-DL-x264-ESubs---MkvHub-Com |
| Full analysis: | https://app.any.run/tasks/47630ab9-0293-4357-8ebc-5d5fe47ea72b |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | March 16, 2022, 10:04:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 16C65BF93572486C868ADF2AA9FD6DA9 |
| SHA1: | 8620DB257796085370D1EED444A4E427FB7E513C |
| SHA256: | 9CC3D4941B9CC09076D4AE55E0DB3C2FFE014566A0E213B1F7B165600AE66228 |
| SSDEEP: | 3:N8DSL2XeBz4L8XOKUTd6G4+YIkPjSyQHVhiT:2OLweBzMx6G4jSD+T |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1032 | "C:\Windows\system32\cmd.exe" /C ""C:\Users\admin\AppData\Local\Temp\GenericSetup.exe_1647425142\Carrier.exe" /S" | C:\Windows\system32\cmd.exe | — | GenericSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1056 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4016.6.3089490\740757383" -childID 1 -isForBrowser -prefsHandle 2800 -prefMapHandle 2796 -prefsLen 181 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4016 "\\.\pipe\gecko-crash-server-pipe.4016" 2812 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 1244 | C:\Users\admin\AppData\Local\Temp\GenericSetup.exe_1647425142\Carrier.exe | C:\Users\admin\AppData\Local\Temp\GenericSetup.exe_1647425142\Carrier.exe | — | GenericSetup.exe | |||||||||||
User: admin Company: BitTorrent, Inc. Integrity Level: HIGH Description: uTorrent Web Exit code: 0 Version: 1.2.7.4186 Modules
| |||||||||||||||
| 1256 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4016.13.940882669\957418216" -childID 2 -isForBrowser -prefsHandle 3008 -prefMapHandle 3004 -prefsLen 6644 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4016 "\\.\pipe\gecko-crash-server-pipe.4016" 3020 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 1296 | "C:\Users\admin\Downloads\utweb_installer.exe" | C:\Users\admin\Downloads\utweb_installer.exe | — | firefox.exe | |||||||||||
User: admin Company: BitTorrent, Inc. Integrity Level: MEDIUM Description: uTorrent Web Exit code: 3221226540 Version: 1.2.7.4186 Modules
| |||||||||||||||
| 1664 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4016.41.246495516\923523589" -childID 6 -isForBrowser -prefsHandle 3768 -prefMapHandle 3468 -prefsLen 9214 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4016 "\\.\pipe\gecko-crash-server-pipe.4016" 2668 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 1800 | "C:\Users\admin\AppData\Local\Temp\GenericSetup.exe_1647425142\Carrier.exe" /S | C:\Users\admin\AppData\Local\Temp\GenericSetup.exe_1647425142\Carrier.exe | cmd.exe | ||||||||||||
User: admin Company: BitTorrent, Inc. Integrity Level: HIGH Description: uTorrent Web Exit code: 0 Version: 1.2.7.4186 Modules
| |||||||||||||||
| 2068 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4016.20.843070094\1144247893" -childID 3 -isForBrowser -prefsHandle 3752 -prefMapHandle 3748 -prefsLen 7378 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4016 "\\.\pipe\gecko-crash-server-pipe.4016" 3764 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 2132 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2460 | "C:\Program Files\Internet Explorer\iexplore.exe" https://utweb.trontv.com/gui/index.html?v=1.2.7.4186&localauth=localapi167a75fe7e0ae29f: | C:\Program Files\Internet Explorer\iexplore.exe | utweb.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3536) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: A898CC23BB000000 | |||
| (PID) Process: | (4016) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 46A0CC23BB000000 | |||
| (PID) Process: | (4016) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (4016) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (4016) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (4016) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (4016) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|ServicesSettingsServer |
Value: https://firefox.settings.services.mozilla.com/v1 | |||
| (PID) Process: | (4016) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash |
Value: 97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E | |||
| (PID) Process: | (4016) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (4016) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4016 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 4016 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 4016 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journal | binary | |
MD5:— | SHA256:— | |||
| 4016 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:— | SHA256:— | |||
| 4016 | firefox.exe | C:\Users\admin\AppData\Local\Temp\mz_etilqs_EN7sRsayK4IYUyP | binary | |
MD5:— | SHA256:— | |||
| 4016 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\settings\main\ms-language-packs\asrouter.ftl | text | |
MD5:— | SHA256:— | |||
| 4016 | firefox.exe | C:\Users\admin\AppData\Local\Temp\mz_etilqs_2ORy0XV23APMh3S | binary | |
MD5:— | SHA256:— | |||
| 4016 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 4016 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 4016 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:299A2B747C11E4BDA194E563FEA4A699 | SHA256:94EE461F62E8B4A0A65471A41E10C8C56722B73C0A019D76ACA7F5BAF109813E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4016 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 471 b | whitelisted |
4016 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
4016 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
4016 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
4016 | firefox.exe | POST | 200 | 2.16.186.16:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
4016 | firefox.exe | POST | 200 | 2.16.186.16:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
4016 | firefox.exe | POST | 200 | 192.124.249.24:80 | http://ocsp.godaddy.com/ | US | der | 1.74 Kb | whitelisted |
4016 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
4016 | firefox.exe | POST | 200 | 108.156.253.141:80 | http://ocsp.sca1b.amazontrust.com/ | US | der | 471 b | whitelisted |
4016 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt | US | text | 8 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4016 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | — | US | whitelisted |
4016 | firefox.exe | 104.26.13.134:443 | www.torrentdownloads.pro | Cloudflare Inc | US | unknown |
4016 | firefox.exe | 13.32.22.10:443 | content-signature-2.cdn.mozilla.net | Amazon.com, Inc. | US | unknown |
4016 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
4016 | firefox.exe | 142.250.184.234:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
4016 | firefox.exe | 142.250.185.234:443 | ajax.googleapis.com | Google Inc. | US | whitelisted |
4016 | firefox.exe | 104.16.95.65:443 | static.cloudflareinsights.com | Cloudflare Inc | US | shared |
4016 | firefox.exe | 143.204.214.4:443 | d1clmik8la8v65.cloudfront.net | — | US | suspicious |
4016 | firefox.exe | 23.109.82.15:443 | abasgimental.com | — | NL | unknown |
4016 | firefox.exe | 34.213.133.213:443 | push.services.mozilla.com | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
www.torrentdownloads.pro |
| suspicious |
firefox.settings.services.mozilla.com |
| whitelisted |
location.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
locprod2-elb-us-west-2.prod.mozaws.net |
| whitelisted |
e1.o.lencr.org |
| whitelisted |
a1887.dscq.akamai.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
4016 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
4016 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
4016 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
4016 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
1800 | Carrier.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
1800 | Carrier.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
— | — | Potential Corporate Privacy Violation | ET POLICY DNS Query For XXX Adult Site Top Level Domain |
— | — | Potential Corporate Privacy Violation | ET POLICY DNS Query For XXX Adult Site Top Level Domain |
— | — | Potential Corporate Privacy Violation | ET P2P BitTorrent DHT ping request |
— | — | Potentially Bad Traffic | ET DNS Query for .to TLD |
Process | Message |
|---|---|
GenericSetup.exe | Error: File not found - genericsetup.wrappers.sciter:console.tis
|
GenericSetup.exe | at sciter:init-script.tis
|
GenericSetup.exe | |
GenericSetup.exe | |
GenericSetup.exe | file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
|
GenericSetup.exe | Error: File not found - genericsetup.wrappers.sciter:console.tis
|
GenericSetup.exe | at sciter:init-script.tis
|
GenericSetup.exe | |
GenericSetup.exe | |
GenericSetup.exe | file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
|