download:

Thunderbird%20Setup%2060.2.1.exe

Full analysis: https://app.any.run/tasks/2958638c-1912-4191-8423-0c692ab3ac73
Verdict: Malicious activity
Analysis date: October 31, 2018, 21:06:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

486CFB8EA09192AC6F87E8AA1AF31F03

SHA1:

65AD6D5A7717F4288C88FEAD5FB73417D2BBB7C1

SHA256:

C06D5A4F7CB2C7686AE158119B57AB30D661E1658B5C27E14F64CFF22F388ECE

SSDEEP:

786432:d15s0AxrReQXiPKGJLvzTXlI6i1zVa8SJvmGmc1d:d1C0AhRjiCsLvzTXlI6i1zVpvc1d

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • setup.exe (PID: 3872)
      • setup.exe (PID: 236)
      • maintenanceservice_installer.exe (PID: 4012)
      • ns44BA.tmp (PID: 3064)
      • maintenanceservice.exe (PID: 1728)
      • thunderbird.exe (PID: 1412)
    • Loads dropped or rewritten executable

      • setup.exe (PID: 236)
      • setup.exe (PID: 3872)
      • maintenanceservice_installer.exe (PID: 4012)
      • thunderbird.exe (PID: 1412)
  • SUSPICIOUS

    • Application launched itself

      • setup.exe (PID: 3872)
    • Creates a software uninstall entry

      • setup.exe (PID: 236)
      • maintenanceservice_installer.exe (PID: 4012)
    • Starts application with an unusual extension

      • setup.exe (PID: 236)
    • Executable content was dropped or overwritten

      • maintenanceservice_installer.exe (PID: 4012)
      • 21fa2ebf-a67f-4fd8-a827-d02a93a14051.exe (PID: 2216)
      • setup.exe (PID: 236)
      • setup.exe (PID: 3872)
    • Modifies the open verb of a shell class

      • setup.exe (PID: 236)
    • Creates files in the program directory

      • maintenanceservice_installer.exe (PID: 4012)
      • maintenanceservice.exe (PID: 1728)
      • setup.exe (PID: 236)
    • Creates COM task schedule object

      • setup.exe (PID: 236)
    • Reads CPU info

      • thunderbird.exe (PID: 1412)
    • Creates files in the user directory

      • thunderbird.exe (PID: 1412)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • thunderbird.exe (PID: 1412)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (43.7)
.exe | UPX compressed Win32 Executable (42.8)
.exe | Win32 Executable (generic) (7.1)
.exe | Generic Win/DOS Executable (3.1)
.exe | DOS Executable Generic (3.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:08:31 00:18:33+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 65536
InitializedDataSize: 53248
UninitializedDataSize: 135168
EntryPoint: 0x31300
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 18.5.0.0
ProductVersionNumber: 18.5.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Mozilla
FileDescription: Thunderbird
FileVersion: 18.05
InternalName: 7zS.sfx
LegalCopyright: Mozilla
OriginalFileName: 7zS.sfx.exe
ProductName: Thunderbird
ProductVersion: 18.05

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 30-Aug-2018 22:18:33
Detected languages:
  • English - United States
CompanyName: Mozilla
FileDescription: Thunderbird
FileVersion: 18.05
InternalName: 7zS.sfx
LegalCopyright: Mozilla
OriginalFilename: 7zS.sfx.exe
ProductName: Thunderbird
ProductVersion: 18.05

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 30-Aug-2018 22:18:33
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
UPX0
0x00001000
0x00021000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
UPX1
0x00022000
0x00010000
0x0000F600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.89684
.rsrc
0x00032000
0x0000D000
0x0000C800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.48054

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.38843
1365
UNKNOWN
UNKNOWN
RT_MANIFEST
2
5.6365
4264
UNKNOWN
English - United States
RT_ICON
3
5.94806
9640
UNKNOWN
English - United States
RT_ICON
4
7.90767
32797
UNKNOWN
English - United States
RT_ICON
5
6.45677
136
UNKNOWN
English - United States
RT_STRING
97
6.87063
184
UNKNOWN
English - United States
RT_DIALOG
188
6.1066
84
UNKNOWN
English - United States
RT_STRING
207
4.94064
52
UNKNOWN
English - United States
RT_STRING

Imports

KERNEL32.DLL
MSVCRT.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
7
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start 21fa2ebf-a67f-4fd8-a827-d02a93a14051.exe setup.exe setup.exe ns44ba.tmp no specs maintenanceservice_installer.exe maintenanceservice.exe no specs thunderbird.exe

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Users\admin\AppData\Local\Temp\7zS8A896CFC\setup.exe" /UAC:90550 /NCRCC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\setup.exe
setup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Thunderbird Installer
Exit code:
0
Version:
60.2.1
Modules
Images
c:\users\admin\appdata\local\temp\7zs8a896cfc\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1412"C:\Program Files\Mozilla Thunderbird\thunderbird.exe"C:\Program Files\Mozilla Thunderbird\thunderbird.exe
setup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Thunderbird
Exit code:
0
Version:
60.2.1
Modules
Images
c:\program files\mozilla thunderbird\thunderbird.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla thunderbird\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
1728"C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" installC:\Program Files\Mozilla Maintenance Service\maintenanceservice.exemaintenanceservice_installer.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
HIGH
Exit code:
0
Version:
60.2.1
Modules
Images
c:\program files\mozilla maintenance service\maintenanceservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2216"C:\Users\admin\Desktop\21fa2ebf-a67f-4fd8-a827-d02a93a14051.exe" C:\Users\admin\Desktop\21fa2ebf-a67f-4fd8-a827-d02a93a14051.exe
explorer.exe
User:
admin
Company:
Mozilla
Integrity Level:
MEDIUM
Description:
Thunderbird
Exit code:
0
Version:
18.05
Modules
Images
c:\users\admin\desktop\21fa2ebf-a67f-4fd8-a827-d02a93a14051.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3064"C:\Users\admin\AppData\Local\Temp\nsyEBF7.tmp\ns44BA.tmp" "C:\Program Files\Mozilla Thunderbird\maintenanceservice_installer.exe"C:\Users\admin\AppData\Local\Temp\nsyEBF7.tmp\ns44BA.tmpsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsyebf7.tmp\ns44ba.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3872.\setup.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\setup.exe
21fa2ebf-a67f-4fd8-a827-d02a93a14051.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Thunderbird Installer
Exit code:
0
Version:
60.2.1
Modules
Images
c:\users\admin\appdata\local\temp\7zs8a896cfc\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
4012"C:\Program Files\Mozilla Thunderbird\maintenanceservice_installer.exe"C:\Program Files\Mozilla Thunderbird\maintenanceservice_installer.exe
ns44BA.tmp
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Mozilla Maintenance Service Installer
Exit code:
0
Version:
60.2.1
Modules
Images
c:\program files\mozilla thunderbird\maintenanceservice_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
992
Read events
797
Write events
191
Delete events
4

Modification events

(PID) Process:(236) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
Operation:writeName:ThunderbirdInstallerTest
Value:
Write Test
(PID) Process:(236) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
Operation:delete valueName:ThunderbirdInstallerTest
Value:
Write Test
(PID) Process:(236) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Thunderbird\TaskBarIDs
Operation:writeName:C:\Program Files\Mozilla Thunderbird
Value:
D78BF5DD33499EC2
(PID) Process:(236) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\InProcServer32
Operation:writeName:
Value:
C:\Program Files\Mozilla Thunderbird\AccessibleMarshal.dll
(PID) Process:(236) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(236) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}
Operation:writeName:
Value:
PSFactoryBuffer
(PID) Process:(236) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D68D6D0-D93D-4D08-A30D-F00DD1F45B24}\ProxyStubClsid32
Operation:writeName:
Value:
{1814CEEB-49E2-407F-AF99-FA755A7D2607}
(PID) Process:(236) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D68D6D0-D93D-4D08-A30D-F00DD1F45B24}
Operation:writeName:
Value:
ISimpleDOMDocument
(PID) Process:(236) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D68D6D0-D93D-4D08-A30D-F00DD1F45B24}\NumMethods
Operation:writeName:
Value:
9
(PID) Process:(236) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E747BE5-2052-4265-8AF0-8ECAD7AAD1C0}\ProxyStubClsid32
Operation:writeName:
Value:
{1814CEEB-49E2-407F-AF99-FA755A7D2607}
Executable files
167
Suspicious files
32
Text files
216
Unknown types
17

Dropped files

PID
Process
Filename
Type
221621fa2ebf-a67f-4fd8-a827-d02a93a14051.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\core\AccessibleMarshal.dllexecutable
MD5:
SHA256:
221621fa2ebf-a67f-4fd8-a827-d02a93a14051.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\core\AccessibleHandler.dllexecutable
MD5:
SHA256:
221621fa2ebf-a67f-4fd8-a827-d02a93a14051.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\core\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:6D778E83F74A4C7FE4C077DC279F6867
SHA256:A97DCCA76CDB12E985DFF71040815F28508C655AB2B073512E386DD63F4DA325
221621fa2ebf-a67f-4fd8-a827-d02a93a14051.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\core\api-ms-win-core-handle-l1-1-0.dllexecutable
MD5:6DB54065B33861967B491DD1C8FD8595
SHA256:945CC64EE04B1964C1F9FCDC3124DD83973D332F5CFB696CDF128CA5C4CBD0E5
221621fa2ebf-a67f-4fd8-a827-d02a93a14051.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\core\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:88FF191FD8648099592ED28EE6C442A5
SHA256:C310CC91464C9431AB0902A561AF947FA5C973925FF70482D3DE017ED3F73B7D
221621fa2ebf-a67f-4fd8-a827-d02a93a14051.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\core\api-ms-win-core-processthreads-l1-1-0.dllexecutable
MD5:A2D7D7711F9C0E3E065B2929FF342666
SHA256:9DAB884071B1F7D7A167F9BEC94BA2BEE875E3365603FA29B31DE286C6A97A1D
221621fa2ebf-a67f-4fd8-a827-d02a93a14051.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\core\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:E2F648AE40D234A3892E1455B4DBBE05
SHA256:C8C499B012D0D63B7AFC8B4CA42D6D996B2FCF2E8B5F94CACFBEC9E6F33E8A03
221621fa2ebf-a67f-4fd8-a827-d02a93a14051.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\core\Accessible.tlbtlb
MD5:EE105B897DBD5A5B75E6A91B9FAFA8BD
SHA256:C5F6E85A679A98BA0FCD45F50464B6D6EBB2F0B76B4506388E9086E5FA6F93BB
221621fa2ebf-a67f-4fd8-a827-d02a93a14051.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\core\api-ms-win-core-heap-l1-1-0.dllexecutable
MD5:2EA3901D7B50BF6071EC8732371B821C
SHA256:44F6DF4280C8ECC9C6E609B1A4BFEE041332D337D84679CFE0D6678CE8F2998A
221621fa2ebf-a67f-4fd8-a827-d02a93a14051.exeC:\Users\admin\AppData\Local\Temp\7zS8A896CFC\core\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:502263C56F931DF8440D7FD2FA7B7C00
SHA256:94A5DF1227818EDBFD0D5091C6A48F86B4117C38550343F780C604EEE1CD6231
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
2
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1412
thunderbird.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1412
thunderbird.exe
52.215.245.12:443
location.services.mozilla.com
Amazon.com, Inc.
IE
unknown
1412
thunderbird.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
location.services.mozilla.com
  • 52.215.245.12
  • 34.252.164.43
  • 54.229.18.107
whitelisted
locprod1-elb-eu-west-1.prod.mozaws.net
  • 54.229.18.107
  • 34.252.164.43
  • 52.215.245.12
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
cs9.wac.phicdn.net
  • 93.184.220.29
whitelisted

Threats

No threats detected
No debug info