URL:

https://dl.dropbox.com/scl/fi/crfl2mifthwzgmu4iuei8/em_iaN2TRar_installer_Win7-Win11_x86_x64.msi?rlkey=e8ubeknbw6np28ozey9y108md&dl=0

Full analysis: https://app.any.run/tasks/4045277e-168b-4176-bbc9-d10fe4cf28b5
Verdict: Malicious activity
Analysis date: February 07, 2024, 08:49:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
python
Indicators:
MD5:

5C637FD9BCEEDD7375D16CFD2177B0EB

SHA1:

B4A2ED75AA421CA39B612C2F59E6B252EA50A673

SHA256:

A4C0F129B86BC6A987C150204EC2D100C0732537A4118C1157ED0BC6A1756257

SSDEEP:

3:N8RdNkG6VdskXnLVOXZJPKUn2TR71cY6ku9dpx1V:27NktxnLVOXZlPo71cYRu/pxf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 1232)
      • ITSMService.exe (PID: 2712)
      • RmmService.exe (PID: 980)
    • Loads Python modules

      • RmmService.exe (PID: 980)
      • RmmService.exe (PID: 3440)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 1264)
      • firefox.exe (PID: 752)
    • Manual execution by a user

      • msiexec.exe (PID: 1832)
      • wmpnscfg.exe (PID: 1880)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 1832)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1880)
      • ITSMAgent.exe (PID: 2492)
      • ITSMService.exe (PID: 2712)
      • ITSMAgent.exe (PID: 2184)
      • ITSMAgent.exe (PID: 2788)
      • RmmService.exe (PID: 980)
      • RmmService.exe (PID: 3440)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1880)
      • ITSMAgent.exe (PID: 2492)
      • ITSMService.exe (PID: 2712)
      • ITSMAgent.exe (PID: 2184)
      • ITSMAgent.exe (PID: 2788)
      • RmmService.exe (PID: 980)
      • RmmService.exe (PID: 3440)
    • The process uses the downloaded file

      • firefox.exe (PID: 752)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 752)
    • Reads the machine GUID from the registry

      • ITSMService.exe (PID: 2712)
      • RmmService.exe (PID: 980)
      • ITSMAgent.exe (PID: 2184)
      • ITSMAgent.exe (PID: 2492)
    • Creates files in the program directory

      • ITSMService.exe (PID: 2712)
      • RmmService.exe (PID: 980)
      • RmmService.exe (PID: 3440)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 752)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
20
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msiexec.exe no specs vssvc.exe no specs wmpnscfg.exe no specs cmd.exe no specs itsmservice.exe itsmagent.exe itsmagent.exe itsmagent.exe rmmservice.exe no specs rmmservice.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
324"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="752.0.38082739\150868849" -parentBuildID 20230710165010 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {eadd62e8-3524-450c-8615-b1cb249f4f29} 752 "\\.\pipe\gecko-crash-server-pipe.752" 1180 d1a8350 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
752"C:\Program Files\Mozilla Firefox\firefox.exe" https://dl.dropbox.com/scl/fi/crfl2mifthwzgmu4iuei8/em_iaN2TRar_installer_Win7-Win11_x86_x64.msi?rlkey=e8ubeknbw6np28ozey9y108md&dl=0C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
980"C:\Program Files\ITarian\Endpoint Manager\RmmService.exe"C:\Program Files\ITarian\Endpoint Manager\RmmService.exeservices.exe
User:
SYSTEM
Company:
ITarian
Integrity Level:
SYSTEM
Description:
Endpoint Manager RMM Service
Exit code:
0
Modules
Images
c:\program files\itarian\endpoint manager\rmmservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\itarian\endpoint manager\python27.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1232C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1264"C:\Program Files\Mozilla Firefox\firefox.exe" "https://dl.dropbox.com/scl/fi/crfl2mifthwzgmu4iuei8/em_iaN2TRar_installer_Win7-Win11_x86_x64.msi?rlkey=e8ubeknbw6np28ozey9y108md&dl=0"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1832"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Downloads\em_iaN2TRar_installer_Win7-Win11_x86_x64.msi" C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1880"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2160"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="752.5.1472402225\1338011095" -childID 4 -isForBrowser -prefsHandle 3868 -prefMapHandle 3776 -prefsLen 29102 -prefMapSize 244195 -jsInitHandle 912 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {3557d32a-ec82-4391-ae22-b54fcbb34177} 752 "\\.\pipe\gecko-crash-server-pipe.752" 3856 17de4f70 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2184"C:\Program Files\ITarian\Endpoint Manager\ITSMAgent.exe"C:\Program Files\ITarian\Endpoint Manager\ITSMAgent.exe
ITSMService.exe
User:
admin
Company:
ITarian
Integrity Level:
MEDIUM
Description:
Endpoint Manager Tray Application
Exit code:
0
Version:
8.3.47427.23090
Modules
Images
c:\program files\itarian\endpoint manager\itsmagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2492"C:\Program Files\ITarian\Endpoint Manager\ITSMAgent.exe"C:\Program Files\ITarian\Endpoint Manager\ITSMAgent.exe
ITSMService.exe
User:
admin
Company:
ITarian
Integrity Level:
MEDIUM
Description:
Endpoint Manager Tray Application
Exit code:
0
Version:
8.3.47427.23090
Modules
Images
c:\program files\itarian\endpoint manager\itsmagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
20 856
Read events
20 480
Write events
376
Delete events
0

Modification events

(PID) Process:(1264) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
2166C0A101000000
(PID) Process:(752) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
044CC1A101000000
(PID) Process:(752) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(752) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(752) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(752) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(752) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(752) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(752) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(752) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
D14E5F3C23B0D901
Executable files
4
Suspicious files
408
Text files
46
Unknown types
0

Dropped files

PID
Process
Filename
Type
752firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
752firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
752firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:B7A3C61D0C144CC5E166B1E769CA8F8C
SHA256:7FADCB77FFACA6B9E9F15C6F1CD3AAD4C20DCD90FA92429A627A3A7110CA2644
752firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.dbbinary
MD5:BAD76827355267B81083EB83F904460E
SHA256:7FA0BAD7C5EBE6089E95B0A81E2FFB344D8041462C43B4E97F51FBBFD2BBE7FE
752firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journalbinary
MD5:956F455D2FF2BA0D1BAD99CED9DA723E
SHA256:1AE5E4E02F01CFCE2BE344D17AF2A895C6109857E28AF690631ABFC194269F28
752firefox.exeC:\Users\admin\Downloads\kavdHJER.msi.partbinary
MD5:5D5909A57CD57DFD54A6D1373A98045F
SHA256:E2AE9815B621138BC05C062E341EE60BA720445ED24C0EC6792F1B74BE3246D4
752firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\activity-stream.discovery_stream.jsonbinary
MD5:06B7E0A8C1B21B6CF04E4789B605C872
SHA256:2E2106575D90C9C24B3CEEAEDBF9FE51538B9FF24749D4529992A98052CF1DCF
752firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
752firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
752firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
65
DNS requests
138
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
752
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
752
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
752
firefox.exe
POST
200
142.250.186.67:80
http://ocsp.pki.goog/gts1c3
unknown
binary
471 b
unknown
752
firefox.exe
POST
200
95.101.54.145:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
752
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
471 b
unknown
752
firefox.exe
POST
200
142.250.186.67:80
http://ocsp.pki.goog/gts1c3
unknown
binary
471 b
unknown
752
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
471 b
unknown
752
firefox.exe
POST
200
95.101.54.145:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
752
firefox.exe
POST
200
95.101.54.145:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
752
firefox.exe
POST
200
95.101.54.145:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
752
firefox.exe
142.250.186.170:443
safebrowsing.googleapis.com
whitelisted
752
firefox.exe
162.125.66.15:443
dl.dropbox.com
DROPBOX
DE
malicious
752
firefox.exe
34.49.99.171:443
spocs.getpocket.com
unknown
752
firefox.exe
142.250.186.67:80
ocsp.pki.goog
GOOGLE
US
whitelisted
752
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
752
firefox.exe
34.107.243.93:443
push.services.mozilla.com
unknown
752
firefox.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
whitelisted
dl.dropbox.com
  • 162.125.66.15
shared
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
edge-block-www-env.dropbox-dns.com
  • 162.125.66.15
  • 2620:100:6021:15::a27d:410f
unknown
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
spocs.getpocket.com
  • 34.49.99.171
shared
ocsp.digicert.com
  • 192.229.221.95
whitelisted
fp2e7a.wpc.phicdn.net
  • 192.229.221.95
whitelisted

Threats

PID
Process
Class
Message
752
firefox.exe
Misc activity
ET INFO DropBox User Content Download Access over SSL M2
752
firefox.exe
Misc activity
ET INFO DropBox User Content Download Access over SSL M2
752
firefox.exe
Misc activity
ET INFO DropBox User Content Domain (dl .dropboxusercontent .com in TLS SNI)
752
firefox.exe
Misc activity
ET INFO DropBox User Content Download Access over SSL M2
Process
Message
ITSMService.exe
QCoreApplication::applicationDirPath: Please instantiate the QApplication object first
ITSMService.exe
Try to find oem.strings in "C:/Program Files/ITarian/Endpoint Manager/oem.strings"
ITSMService.exe
OEM strings file does not exists! "C:/Program Files/ITarian/Endpoint Manager/oem.strings"
ITSMService.exe
Log dir is 'C:/ProgramData/ITarian/Endpoint Manager'
ITSMAgent.exe
Try to find oem.strings in "C:/Program Files/ITarian/Endpoint Manager/oem.strings"
ITSMAgent.exe
OEM strings file does not exists! "C:/Program Files/ITarian/Endpoint Manager/oem.strings"
ITSMAgent.exe
Log dir is 'C:/ProgramData/ITarian/Endpoint Manager'
ITSMAgent.exe
Try to open ipc connection
ITSMAgent.exe
QWindowsEGLStaticContext::create: Could not initialize EGL display: error 0x3001
ITSMAgent.exe
QWindowsEGLStaticContext::create: When using ANGLE, check if d3dcompiler_4x.dll is available