| download: | /vir/Email-Worm.Win32.Tanatos.b |
| Full analysis: | https://app.any.run/tasks/b17fe635-c899-4e05-8567-f968092b4193 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | November 29, 2024, 19:44:23 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections |
| MD5: | C559245877A6211E15D2D7EECBB97F14 |
| SHA1: | 469C4FBBE25560B1E29185B0B9249F93A5DC87CD |
| SHA256: | AD11A78AE6DA616C878F2190C2DE3F2011D16B605F6691CD14B149699830FF4E |
| SSDEEP: | 3072:OZGkcXIZ9wwF0nLr+fXbbqd79HOf6wB1dH4csCm:S5U8ILr+fXbbqd79A6w54csn |
| .exe | | | UPX compressed Win32 Executable (39.3) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (38.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (9.5) |
| .exe | | | Win32 Executable (generic) (6.5) |
| .exe | | | Generic Win/DOS Executable (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2097:03:26 09:25:25+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 73728 |
| InitializedDataSize: | 4096 |
| UninitializedDataSize: | 450560 |
| EntryPoint: | 0x80120 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="580.0.177426381\485510765" -parentBuildID 20230710165010 -prefsHandle 1096 -prefMapHandle 1088 -prefsLen 28739 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {29a8fade-bca4-41cb-ae3f-90bf22a52326} 580 "\\.\pipe\gecko-crash-server-pipe.580" 1168 d57b1a0 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 580 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 600 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="580.3.129650050\429353775" -childID 2 -isForBrowser -prefsHandle 2692 -prefMapHandle 2688 -prefsLen 34441 -prefMapSize 244371 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b1ad76e0-1f86-4b81-9c8b-9c857def2018} 580 "\\.\pipe\gecko-crash-server-pipe.580" 2704 17dd1110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1004 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1332 | "C:\Windows\System32\runas.exe" /user:administrator C:\Users\admin\Desktop\Email-Worm.Win32.Tanatos.b.exe | C:\Windows\System32\runas.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Run As Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1500 | _72 _72=C:\USERS\ADMIN\DESKTOP\EMAIL-WORM.WIN32.TANATOS.B.EXE | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BIIQ.EXE | Email-Worm.Win32.Tanatos.b.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Modules
| |||||||||||||||
| 1740 | C:\Users\admin\Desktop\Email-Worm.Win32.Tanatos.b.exe | C:\Users\admin\Desktop\Email-Worm.Win32.Tanatos.b.exe | runas.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2604 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2648 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="580.1.168421846\1331282781" -parentBuildID 20230710165010 -prefsHandle 1320 -prefMapHandle 1316 -prefsLen 28816 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {af52ecbb-4126-4f74-bc8f-7ff2f204475a} 580 "\\.\pipe\gecko-crash-server-pipe.580" 1332 f165a90 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 3408 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="580.2.690066123\183217289" -childID 1 -isForBrowser -prefsHandle 1856 -prefMapHandle 1852 -prefsLen 28928 -prefMapSize 244371 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {52ea662b-bfc7-4cca-bfd5-46ffd3c5399e} 580 "\\.\pipe\gecko-crash-server-pipe.580" 1960 1285ec90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (2604) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 0685CBFB00000000 | |||
| (PID) Process: | (580) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: F53FCDFB00000000 | |||
| (PID) Process: | (580) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB |
| Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
| (PID) Process: | (580) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (580) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (580) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (580) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (580) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (580) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (580) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 580 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini | text | |
MD5:5A14BC3397EA072906B63D69FC704FEA | SHA256:03F45724EA1FE89E753AA76B40DE9078BFC9160AA1065ED9D4D98DA04B7FB3E7 | |||
| 1500 | BIIQ.EXE | C:\Users\Administrator\AppData\Local\Temp\sphqghum.tmp | text | |
MD5:CA4F0A28EB6DC9CA21A7227FA060C5AD | SHA256:ADEE06381F046F52D79BB0E4E29FC8F0E8540FBFB51E29C72EEC5FD7A96EEF7F | |||
| 1500 | BIIQ.EXE | C:\Windows\System32\okkqqck.dll | binary | |
MD5:8A16A13AEE0EE6D896BDE34D04E8EF15 | SHA256:4BB1617D0A336770FDA1F3ACC1CB3B20D5F69AE2301A7C4C45367CDB0758B85E | |||
| 1740 | Email-Worm.Win32.Tanatos.b.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BIIQ.EXE | executable | |
MD5:C559245877A6211E15D2D7EECBB97F14 | SHA256:AD11A78AE6DA616C878F2190C2DE3F2011D16B605F6691CD14B149699830FF4E | |||
| 580 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 580 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1500 | BIIQ.EXE | C:\Windows\System32\fttqqi.dll | binary | |
MD5:BF7A8C5BF5F213BD78813719583D8F39 | SHA256:D422918DE76776BE22921D79546F45ABFBA72EEE7762B7FDFE9122AC1FB05CFF | |||
| 580 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 580 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 580 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:10838BA4D091CD29EB56089222ECB443 | SHA256:934225516EF688A07796A04C2358410D6F7238FD8056C261780E20B098F1189C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
580 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
580 | firefox.exe | POST | 200 | 142.250.186.67:80 | http://o.pki.goog/wr2 | unknown | — | — | whitelisted |
580 | firefox.exe | POST | 200 | 2.16.206.148:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
580 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
580 | firefox.exe | POST | 200 | 142.250.186.67:80 | http://o.pki.goog/s/wr3/yvU | unknown | — | — | whitelisted |
580 | firefox.exe | POST | 200 | 2.16.206.148:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
580 | firefox.exe | POST | 200 | 2.16.206.148:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
580 | firefox.exe | POST | 200 | 2.16.206.148:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
1108 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
580 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
580 | firefox.exe | 34.117.188.166:443 | contile.services.mozilla.com | — | — | whitelisted |
580 | firefox.exe | 142.250.186.67:80 | o.pki.goog | GOOGLE | US | whitelisted |
580 | firefox.exe | 216.58.212.138:443 | safebrowsing.googleapis.com | — | — | whitelisted |
580 | firefox.exe | 34.36.165.17:443 | tiles-cdn.prod.ads.prod.webservices.mozgcp.net | GOOGLE-CLOUD-PLATFORM | US | unknown |
580 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
prod.ads.prod.webservices.mozgcp.net |
| unknown |
firefox.settings.services.mozilla.com |
| whitelisted |
prod.remote-settings.prod.webservices.mozgcp.net |
| whitelisted |