| URL: | http://www.vstmenia.com/iobit-software-updater-pro-crack/ |
| Full analysis: | https://app.any.run/tasks/b6c57a1f-9500-45b1-859d-39878a68507e |
| Verdict: | Malicious activity |
| Analysis date: | April 30, 2023, 14:33:36 |
| OS: | Windows 11 Professional (build: 22000, 64 bit) |
| Indicators: | |
| MD5: | 315E001F010A0E23362382DF6E7CE06F |
| SHA1: | 6470F19E3F0CFBDDA3E07F7632ED2ABE32C435C3 |
| SHA256: | B04578C1DDE4084EC3E07E17D39BC322C4411867765DBC251859B9A36C643CA7 |
| SSDEEP: | 3:N1KJS4auALoZYcVy3K7l:Cc4aPLo6cVy6R |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 700 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2360.1.1601615930\904823396" -parentBuildID 20230321111920 -prefsHandle 2220 -prefMapHandle 2216 -prefsLen 22972 -prefMapSize 236587 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ec6ab9a3-4e74-41a9-ba7f-e3ffdddc2220} 2360 "\\.\pipe\gecko-crash-server-pipe.2360" 2228 231656e2258 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 111.0.1 Modules
| |||||||||||||||
| 2360 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://www.vstmenia.com/iobit-software-updater-pro-crack/ | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 111.0.1 Modules
| |||||||||||||||
| 3760 | "C:\Program Files\Mozilla Firefox\firefox.exe" "http://www.vstmenia.com/iobit-software-updater-pro-crack/" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 111.0.1 Modules
| |||||||||||||||
| 4524 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2360.2.9670793\1276992244" -childID 1 -isForBrowser -prefsHandle 3076 -prefMapHandle 3064 -prefsLen 21754 -prefMapSize 236587 -jsInitHandle 1424 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f65253a0-4a0d-44ad-8666-641ad4144abc} 2360 "\\.\pipe\gecko-crash-server-pipe.2360" 3088 2316b522358 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 111.0.1 Modules
| |||||||||||||||
| 6284 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2360.0.2011272930\254264761" -parentBuildID 20230321111920 -prefsHandle 1712 -prefMapHandle 1704 -prefsLen 22972 -prefMapSize 236587 -appDir "C:\Program Files\Mozilla Firefox\browser" - {40c3f7b8-17e7-496a-8eaf-a0c1b81a06fd} 2360 "\\.\pipe\gecko-crash-server-pipe.2360" 1788 23164f98758 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 111.0.1 Modules
| |||||||||||||||
| 6384 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2360.12.1370847282\1833117104" -childID 9 -isForBrowser -prefsHandle 8784 -prefMapHandle 9128 -prefsLen 26804 -prefMapSize 236587 -jsInitHandle 1424 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3621d92f-7fbd-40df-bfec-3b8880229334} 2360 "\\.\pipe\gecko-crash-server-pipe.2360" 8588 2315887c158 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 111.0.1 Modules
| |||||||||||||||
| 6836 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2360.4.619873992\103239382" -childID 3 -isForBrowser -prefsHandle 3640 -prefMapHandle 3644 -prefsLen 21977 -prefMapSize 236587 -jsInitHandle 1424 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d8927541-84c3-4273-89bc-665374d46825} 2360 "\\.\pipe\gecko-crash-server-pipe.2360" 3696 2316c016358 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 111.0.1 Modules
| |||||||||||||||
| 6924 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2360.3.1172110051\35436440" -childID 2 -isForBrowser -prefsHandle 3424 -prefMapHandle 3420 -prefsLen 24142 -prefMapSize 236587 -jsInitHandle 1424 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {bd2e86ea-55e9-4f89-af22-9d2bca2bd5b1} 2360 "\\.\pipe\gecko-crash-server-pipe.2360" 3436 2316b705c58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 111.0.1 Modules
| |||||||||||||||
| 7408 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2360.11.1380134896\1449726946" -childID 8 -isForBrowser -prefsHandle 8268 -prefMapHandle 8272 -prefsLen 26723 -prefMapSize 236587 -jsInitHandle 1424 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {33fd6843-b37a-4991-be74-083c8991c8d0} 2360 "\\.\pipe\gecko-crash-server-pipe.2360" 9320 231728be758 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 111.0.1 Modules
| |||||||||||||||
| 7436 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2360.13.517335707\464286637" -childID 10 -isForBrowser -prefsHandle 5376 -prefMapHandle 5276 -prefsLen 26928 -prefMapSize 236587 -jsInitHandle 1424 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b5c47983-1176-46ed-ab42-bf9fe2acce47} 2360 "\\.\pipe\gecko-crash-server-pipe.2360" 3708 2316dd8d458 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 111.0.1 Modules
| |||||||||||||||
| (PID) Process: | (3760) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | delete value | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: BBE1C37401000000 | |||
| (PID) Process: | (3760) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | delete value | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 96E9C47401000000 | |||
| (PID) Process: | (2360) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Progress |
Value: 1 | |||
| (PID) Process: | (2360) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Progress |
Value: 0 | |||
| (PID) Process: | (2360) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (2360) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (2360) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (2360) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 0 | |||
| (PID) Process: | (2360) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (2360) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2360 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\8o2qovza.default-release\compatibility.ini | text | |
MD5:DEBA18A64D02347AC44475F260DA8294 | SHA256:31CC635079DBD141E22E7A5ABF23B339B8FE923258FDBEFACE9511CFA809142C | |||
| 2360 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\8o2qovza.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2360 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\8o2qovza.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2360 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\8o2qovza.default-release\storage.sqlite-journal | binary | |
MD5:D875FB3B880B7CF74197CA6EB2B5C2E8 | SHA256:CA58A9E228A9AC9513C997639673160E89AC41BBB36E4581D5C58A67A21F39D4 | |||
| 2360 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20230321111920 | text | |
MD5:9595DA0B17A7F143A4DA9A8BF63C9B1B | SHA256:281AC6644B4602CE3DD2DFEC51AF01D9C2F4AEF99ED0DAE07831523DC29BE594 | |||
| 2360 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\8o2qovza.default-release\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2360 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\8o2qovza.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2360 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\8o2qovza.default-release\extensions.json.tmp | text | |
MD5:FBEADD857445C3D00C258396149D75E8 | SHA256:ADD813AF5E305BC9DB1214165B37C1806DDD96C91B63140F687503BFE41AE05D | |||
| 2360 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\8o2qovza.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2360 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\8o2qovza.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | binary | |
MD5:B7E8A7B765A8D3796639FB49C7891BF7 | SHA256:EE3FE2CDA725BE41F90B7B3EE434BDF322D51866EB4A97D5B68FB446808673C4 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4000 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8e555dfb3f8a59e6 | US | — | — | whitelisted |
2360 | firefox.exe | GET | 200 | 68.178.247.250:80 | http://www.vstmenia.com/wp-content/plugins/click-to-top/assets/css/hover.css?ver=1.0 | US | text | 7.33 Kb | suspicious |
2360 | firefox.exe | GET | 200 | 68.178.247.250:80 | http://www.vstmenia.com/wp-content/plugins/click-to-top/assets/js/jquery.easing.js?ver=1.0 | US | text | 1.94 Kb | suspicious |
2360 | firefox.exe | GET | 200 | 68.178.247.250:80 | http://www.vstmenia.com/iobit-software-updater-pro-crack/ | US | html | 15.7 Kb | suspicious |
2360 | firefox.exe | GET | 200 | 68.178.247.250:80 | http://www.vstmenia.com/wp-content/fonts/6c03258347cd08d9a022dbcf33977603.css?ver=20201110 | US | text | 771 b | suspicious |
2360 | firefox.exe | GET | 200 | 68.178.247.250:80 | http://www.vstmenia.com/wp-content/plugins/click-to-top/assets/css/font-awesome.min.css?ver=4.5 | US | text | 6.10 Kb | suspicious |
2360 | firefox.exe | GET | 200 | 68.178.247.250:80 | http://www.vstmenia.com/wp-content/plugins/click-to-top/assets/css/click-top-style.css?ver=1.7 | US | text | 12.2 Kb | suspicious |
2360 | firefox.exe | GET | 200 | 68.178.247.250:80 | http://www.vstmenia.com/wp-content/themes/donovan/style.css?ver=1.9 | US | compressed | 12.5 Kb | suspicious |
4000 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | der | 471 b | whitelisted |
2360 | firefox.exe | POST | 200 | 13.32.113.9:80 | http://ocsp.r2m02.amazontrust.com/ | US | binary | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2164 | svchost.exe | 2.19.229.151:443 | fs.microsoft.com | AKAMAI-AS | FR | suspicious |
2360 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
2360 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | suspicious |
2360 | firefox.exe | 35.241.9.150:443 | firefox.settings.services.mozilla.com | GOOGLE | US | suspicious |
2360 | firefox.exe | 50.16.121.128:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
2360 | firefox.exe | 68.178.247.250:80 | www.vstmenia.com | GO-DADDY-COM-LLC | US | suspicious |
2360 | firefox.exe | 2.16.241.15:80 | r3.o.lencr.org | Akamai International B.V. | DE | suspicious |
2360 | firefox.exe | 54.148.4.3:443 | shavar.services.mozilla.com | AMAZON-02 | US | unknown |
4000 | svchost.exe | 20.190.159.0:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | suspicious |
2360 | firefox.exe | 13.32.113.9:80 | ocsp.r2m02.amazontrust.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
fs.microsoft.com |
| whitelisted |
www.vstmenia.com |
| unknown |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
firefox.settings.services.mozilla.com |
| whitelisted |
vstmenia.com |
| unknown |
r3.o.lencr.org |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
1480 | svchost.exe | Misc activity | ET INFO Microsoft Connection Test |