| URL: | http://google.com |
| Full analysis: | https://app.any.run/tasks/dc9b053b-5e2d-4b0a-8476-54d1e990a666 |
| Verdict: | Malicious activity |
| Analysis date: | September 09, 2019, 10:48:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | C7B920F57E553DF2BB68272F61570210 |
| SHA1: | 234988566C9A0A9CF952CEC82B143BF9C207AC16 |
| SHA256: | AA2239C17609B21EBA034C564AF878F3EEC8CE83ED0F2768597D2BC2FD4E4DA5 |
| SSDEEP: | 3:N1KZK3uK:C03uK |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 840 | "C:\Users\admin\AppData\Local\Temp\is-A7ERN.tmp\freeFTPd.tmp" /SL5="$30168,647076,54272,C:\Users\admin\Downloads\freeFTPd.exe" | C:\Users\admin\AppData\Local\Temp\is-A7ERN.tmp\freeFTPd.tmp | — | freeFTPd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2312 | "C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp" /SECONDPHASE="C:\Program Files\freeFTPd\unins000.exe" /FIRSTPHASEWND=$2029A | C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp | unins000.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2328 | "C:\Program Files\freeFTPd\freeFTPdService.exe" /Service | C:\Program Files\freeFTPd\freeFTPdService.exe | — | freeFTPd.tmp | |||||||||||
User: admin Integrity Level: HIGH Description: freeFTPdService Module Exit code: 0 Version: 1, 0, 13, 0 Modules
| |||||||||||||||
| 2356 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2400.3.1631032610\700455295" -childID 1 -isForBrowser -prefsHandle 1748 -prefMapHandle 1744 -prefsLen 1 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2400 "\\.\pipe\gecko-crash-server-pipe.2400" 1768 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2400 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://google.com | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2436 | "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/cbf7e85a-f5da-450e-b495-50e94941c41c/main/Firefox/68.0.1/release/20190717172542?v=4 C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\cbf7e85a-f5da-450e-b495-50e94941c41c | C:\Program Files\Mozilla Firefox\pingsender.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Foundation Integrity Level: MEDIUM Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2440 | "C:\Users\admin\AppData\Local\Temp\is-RL9OB.tmp\freeFTPd.tmp" /SL5="$3017E,647076,54272,C:\Users\admin\Downloads\freeFTPd.exe" /SPAWNWND=$20180 /NOTIFYWND=$30168 | C:\Users\admin\AppData\Local\Temp\is-RL9OB.tmp\freeFTPd.tmp | freeFTPd.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2464 | "C:\Program Files\freeFTPd\freeFTPdService.exe" /RegServer | C:\Program Files\freeFTPd\freeFTPdService.exe | — | freeFTPd.tmp | |||||||||||
User: admin Integrity Level: HIGH Description: freeFTPdService Module Exit code: 0 Version: 1, 0, 13, 0 Modules
| |||||||||||||||
| 2548 | "C:\Program Files\freeFTPd\unins000.exe" | C:\Program Files\freeFTPd\unins000.exe | DllHost.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2556 | "C:\Program Files\freeFTPd\freeFTPdService.exe" /KeyGen | C:\Program Files\freeFTPd\freeFTPdService.exe | — | freeFTPd.tmp | |||||||||||
User: admin Integrity Level: HIGH Description: freeFTPdService Module Exit code: 0 Version: 1, 0, 13, 0 Modules
| |||||||||||||||
| (PID) Process: | (3516) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: AD72793601000000 | |||
| (PID) Process: | (2400) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: ADB07D3601000000 | |||
| (PID) Process: | (2400) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (2400) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2400) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2400) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2400) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2400) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2440) freeFTPd.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\70DBC326-7505-4913-A0C1-C6BD87C1859D_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.3.9 (a) | |||
| (PID) Process: | (2440) freeFTPd.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\70DBC326-7505-4913-A0C1-C6BD87C1859D_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\freeFTPd | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2400 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 2400 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
| 2400 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
| 2400 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp | — | |
MD5:— | SHA256:— | |||
| 2400 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 2400 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:— | SHA256:— | |||
| 2400 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4 | jsonlz4 | |
MD5:— | SHA256:— | |||
| 2400 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.bin | binary | |
MD5:— | SHA256:— | |||
| 2400 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2400 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2400 | firefox.exe | GET | 200 | 91.134.235.212:80 | http://www.freesshd.com/Images/Weonlydo.jpg | FR | image | 3.90 Kb | malicious |
2400 | firefox.exe | GET | 200 | 91.134.235.212:80 | http://www.freesshd.com/img/topleft.gif | FR | image | 3.32 Kb | malicious |
2400 | firefox.exe | POST | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gts1o1 | US | der | 471 b | whitelisted |
2400 | firefox.exe | POST | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gts1o1 | US | der | 472 b | whitelisted |
2400 | firefox.exe | GET | 200 | 91.134.235.212:80 | http://www.freesshd.com/Images/Wippien.jpg | FR | image | 3.04 Kb | malicious |
2400 | firefox.exe | GET | 200 | 95.100.39.17:80 | http://detectportal.firefox.com/success.txt | DE | text | 8 b | whitelisted |
2400 | firefox.exe | GET | 200 | 91.134.235.212:80 | http://www.freesshd.com/default.css | FR | text | 1.09 Kb | malicious |
2400 | firefox.exe | GET | 200 | 91.134.235.212:80 | http://www.freesshd.com/?ctt=download | FR | html | 2.07 Kb | malicious |
2400 | firefox.exe | POST | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gts1o1 | US | der | 472 b | whitelisted |
2400 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2400 | firefox.exe | 95.100.39.17:80 | detectportal.firefox.com | Akamai International B.V. | DE | whitelisted |
2400 | firefox.exe | 172.217.18.174:80 | google.com | Google Inc. | US | whitelisted |
2400 | firefox.exe | 52.36.193.139:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
2400 | firefox.exe | 52.35.21.229:443 | push.services.mozilla.com | Amazon.com, Inc. | US | unknown |
2400 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2400 | firefox.exe | 52.11.24.67:443 | tiles.services.mozilla.com | Amazon.com, Inc. | US | unknown |
2400 | firefox.exe | 172.217.18.4:80 | www.google.com | Google Inc. | US | whitelisted |
2400 | firefox.exe | 172.217.18.4:443 | www.google.com | Google Inc. | US | whitelisted |
2400 | firefox.exe | 54.230.201.96:443 | snippets.cdn.mozilla.net | Amazon.com, Inc. | US | unknown |
2400 | firefox.exe | 172.217.16.131:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
google.com |
| malicious |
a1089.dscd.akamai.net |
| whitelisted |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
snippets.cdn.mozilla.net |
| whitelisted |
d228z91au11ukj.cloudfront.net |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1060 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
1060 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
2400 | firefox.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |