URL:

https://www.torproject.org/download/languages/

Full analysis: https://app.any.run/tasks/d3b92227-412a-47da-b9f7-af85d1becd7f
Verdict: Malicious activity
Analysis date: December 22, 2019, 18:58:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

697F35CB4A53AF75C63399FDD5682152

SHA1:

1663C0D783A067BBC02727CDC3C0D70B9288ABF7

SHA256:

A1DCF4F9EDC3FB20EE4315921E24FB909B59B3A4E16679DA5D0B75643544E497

SSDEEP:

3:N8DSL2VXZG+XQUzK:2OLyXZGN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3476)
      • torbrowser-install-9.0.2_en-US.exe (PID: 2772)
      • csrss.exe (PID: 404)
      • firefox.exe (PID: 2124)
      • firefox.exe (PID: 2560)
      • firefox.exe (PID: 4092)
      • firefox.exe (PID: 3092)
      • firefox.exe (PID: 656)
      • firefox.exe (PID: 716)
      • firefox.exe (PID: 4048)
      • tor.exe (PID: 2152)
    • Application was dropped or rewritten from another process

      • firefox.exe (PID: 4092)
      • firefox.exe (PID: 2124)
      • firefox.exe (PID: 2560)
      • tor.exe (PID: 2152)
      • firefox.exe (PID: 3092)
      • firefox.exe (PID: 716)
      • firefox.exe (PID: 656)
      • firefox.exe (PID: 4048)
  • SUSPICIOUS

    • Creates files in the user directory

      • torbrowser-install-9.0.2_en-US.exe (PID: 2772)
    • Executable content was dropped or overwritten

      • torbrowser-install-9.0.2_en-US.exe (PID: 2772)
    • Application launched itself

      • firefox.exe (PID: 4092)
      • firefox.exe (PID: 2560)
    • Reads CPU info

      • firefox.exe (PID: 2560)
    • Connects to unusual port

      • tor.exe (PID: 2152)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2752)
    • Changes internet zones settings

      • iexplore.exe (PID: 2752)
    • Dropped object may contain TOR URL's

      • iexplore.exe (PID: 1784)
      • torbrowser-install-9.0.2_en-US.exe (PID: 2772)
    • Dropped object may contain URL to Tor Browser

      • iexplore.exe (PID: 1784)
      • iexplore.exe (PID: 2752)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1784)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 1784)
      • iexplore.exe (PID: 2752)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2752)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2752)
    • Manual execution by user

      • torbrowser-install-9.0.2_en-US.exe (PID: 2772)
      • explorer.exe (PID: 2884)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2752)
    • Dropped object may contain Bitcoin addresses

      • torbrowser-install-9.0.2_en-US.exe (PID: 2772)
      • tor.exe (PID: 2152)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
14
Malicious processes
8
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start iexplore.exe iexplore.exe explorer.exe no specs torbrowser-install-9.0.2_en-us.exe searchprotocolhost.exe no specs csrss.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs tor.exe firefox.exe firefox.exe firefox.exe firefox.exe

Process information

PID
CMD
Path
Indicators
Parent process
404%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16C:\Windows\System32\csrss.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Client Server Runtime Process
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\csrss.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\csrsrv.dll
c:\windows\system32\basesrv.dll
c:\windows\system32\winsrv.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
656"C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="2560.13.32736009\350402553" -childID 2 -isForBrowser -prefsHandle 1480 -prefMapHandle 1984 -prefsLen 1863 -prefMapSize 190076 -parentBuildID 20190402030101 -greomni "C:\Users\admin\Desktop\Tor Browser\Browser\omni.ja" -appomni "C:\Users\admin\Desktop\Tor Browser\Browser\browser\omni.ja" -appdir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - 2560 tabC:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Tor Browser
Exit code:
0
Version:
68.3.0
Modules
Images
c:\users\admin\desktop\tor browser\browser\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\tor browser\browser\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
716"C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="2560.20.185817187\1300720564" -childID 3 -isForBrowser -prefsHandle 3036 -prefMapHandle 3032 -prefsLen 6146 -prefMapSize 190076 -parentBuildID 20190402030101 -greomni "C:\Users\admin\Desktop\Tor Browser\Browser\omni.ja" -appomni "C:\Users\admin\Desktop\Tor Browser\Browser\browser\omni.ja" -appdir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - 2560 tabC:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Tor Browser
Exit code:
0
Version:
68.3.0
Modules
Images
c:\users\admin\desktop\tor browser\browser\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\tor browser\browser\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
1784"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2752 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2124"C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="2560.0.115686030\272940378" -parentBuildID 20190402030101 -greomni "C:\Users\admin\Desktop\Tor Browser\Browser\omni.ja" -appomni "C:\Users\admin\Desktop\Tor Browser\Browser\browser\omni.ja" -appdir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - 2560 gpuC:\Users\admin\Desktop\Tor Browser\Browser\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Tor Browser
Exit code:
0
Version:
68.3.0
Modules
Images
c:\users\admin\desktop\tor browser\browser\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\tor browser\browser\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
2152"C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Tor\tor.exe" --defaults-torrc "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\torrc-defaults" -f "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\torrc" DataDirectory "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor" GeoIPFile "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\geoip" GeoIPv6File "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\geoip6" HashedControlPassword 16:ee5b27272f1a053760d4fd40629f9f7333825329117e18b8ee0faf2fc6 +__ControlPort 9151 +__SocksPort "127.0.0.1:9150 IPv6Traffic PreferIPv6 KeepAliveIsolateSOCKSAuth" __OwningControllerProcess 2560 DisableNetwork 1C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Tor\tor.exe
firefox.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\tor browser\browser\torbrowser\tor\tor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\tor browser\browser\torbrowser\tor\zlib1.dll
c:\users\admin\desktop\tor browser\browser\torbrowser\tor\libssp-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2560"C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe"C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Tor Browser
Exit code:
0
Version:
68.3.0
Modules
Images
c:\users\admin\desktop\tor browser\browser\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\tor browser\browser\mozglue.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
2752"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2772"C:\Users\admin\Downloads\torbrowser-install-9.0.2_en-US.exe" C:\Users\admin\Downloads\torbrowser-install-9.0.2_en-US.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\downloads\torbrowser-install-9.0.2_en-us.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2884"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 514
Read events
2 155
Write events
354
Delete events
5

Modification events

(PID) Process:(2752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{0D61C305-24ED-11EA-AB41-5254004A04AF}
Value:
0
(PID) Process:(2752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(2752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E3070C000000160012003A0023000801
Executable files
34
Suspicious files
17
Text files
101
Unknown types
34

Dropped files

PID
Process
Filename
Type
2752iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
2752iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
1784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:
SHA256:
1784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GYZFQTD\languages[1].htmhtml
MD5:
SHA256:
1784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:
SHA256:
1784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IN21C0N0\bootstrap[1].csstext
MD5:
SHA256:
1784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IN21C0N0\jquery-3.2.1.min[1].jstext
MD5:C9F5AEECA3AD37BF2AA006139B935F0A
SHA256:87083882CC6015984EB0411A99D3981817F5DC5C90BA24F0940420C5548D82DE
1784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\EDBHKSWP\SourceSansPro-Regular[1].ttfttf
MD5:5182DA425F811908BED9F5B8C72FA44F
SHA256:71D10A86B4C54A5A9C0C8B467E53AC67D79EDB96C956E4E9F65A7074DFB9992A
1784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IN21C0N0\all.min[1].csstext
MD5:B8085BF2C839791244BD95F56FB93C01
SHA256:453893F7DAA3D8FE9716F8C6D0F36F8ADE8CACFC0093E164F4F998B46427959E
1784iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\EDBHKSWP\SourceSerifPro-Regular[1].ttfttf
MD5:BCAE00EDEB14F3BDEC0FDFCF97CD6B8C
SHA256:86E691C18816E380F7AB798AFF931E016A280DD2753A19F30058ED0C1EE31B12
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
15
DNS requests
3
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2752
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2752
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
1784
iexplore.exe
116.202.120.165:443
www.torproject.org
334,Udyog Vihar
IN
suspicious
2152
tor.exe
91.143.91.91:9001
ISPpro Internet KG
DE
suspicious
2152
tor.exe
69.164.222.151:9001
Linode, LLC
US
suspicious
2752
iexplore.exe
116.202.120.165:443
www.torproject.org
334,Udyog Vihar
IN
suspicious
2152
tor.exe
91.200.102.209:443
suspicious
2152
tor.exe
199.249.230.64:443
Quintex Alliance Consulting
US
suspicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.torproject.org
  • 116.202.120.165
  • 95.216.163.36
shared
dist.torproject.org
  • 116.202.120.165
  • 94.130.28.204
  • 82.195.75.101
  • 38.229.72.19
whitelisted

Threats

PID
Process
Class
Message
2152
tor.exe
Misc Attack
ET TOR Known Tor Exit Node Traffic group 61
2152
tor.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 61
2152
tor.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] TOR SSL connection
2152
tor.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 689
2152
tor.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 688
2152
tor.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 577
2152
tor.exe
Misc activity
ET POLICY TLS possible TOR SSL traffic
No debug info