| download: | /fwlink/ |
| Full analysis: | https://app.any.run/tasks/c5babde6-a377-4f34-83c9-cd295255b9a0 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | May 30, 2025, 08:18:30 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections |
| MD5: | 0E20D50B6AD6229520911B203DEEEF36 |
| SHA1: | 80959E47D83691E8427AD51E6923478B397AC649 |
| SHA256: | C8582A16F4647365E0BE04826442A77DE257B9BB26BAC610FC1FB74319A2548B |
| SSDEEP: | 12288:sJdmWCYoUcs8guodIYFt7l7KuouMWuxu3zHAusN6kADKIV:sJEhIalhWuxu3TAusN6ko5V |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2011:04:11 18:12:40+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 376320 |
| InitializedDataSize: | 272896 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xfc06 |
| OSVersion: | 6 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.5.89.0 |
| ProductVersionNumber: | 3.5.89.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft® Games for Windows® - LIVE Game Setup |
| FileVersion: | 3.5.0089.0 (WGX_XLIVE_V3.05_RTM(panblder).110411-1052) |
| InternalName: | Setup.exe |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| OriginalFileName: | Setup.exe |
| ProductName: | Microsoft® Games for Windows® - LIVE |
| ProductVersion: | 3.5.0089.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1040 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5028 -childID 4 -isForBrowser -prefsHandle 5032 -prefMapHandle 5040 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1372 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e1982bf4-e1f3-4844-814d-d9eaec76a911} 8124 "\\.\pipe\gecko-crash-server-pipe.8124" 1e14b449d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1096 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5004 -childID 3 -isForBrowser -prefsHandle 4992 -prefMapHandle 4988 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1372 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c0544ff9-608c-4867-962f-60c3641653b0} 8124 "\\.\pipe\gecko-crash-server-pipe.8124" 1e145008d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2552 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5152 -childID 5 -isForBrowser -prefsHandle 5232 -prefMapHandle 5228 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1372 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3bfc98ed-bba9-4755-bf0f-e5a70055e9cf} 8124 "\\.\pipe\gecko-crash-server-pipe.8124" 1e14b449f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2852 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2148 -parentBuildID 20240213221259 -prefsHandle 2140 -prefMapHandle 2128 -prefsLen 31031 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {12cf5733-a32d-4d35-bbd7-69047db9644a} 8124 "\\.\pipe\gecko-crash-server-pipe.8124" 1e133c82d10 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 4400 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4368 -childID 2 -isForBrowser -prefsHandle 4360 -prefMapHandle 4356 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1372 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b4829842-b0cb-4fa0-8310-e8385dfc75f4} 8124 "\\.\pipe\gecko-crash-server-pipe.8124" 1e147f1e850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 5072 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1896 -parentBuildID 20240213221259 -prefsHandle 1824 -prefMapHandle 1812 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {513ab0a3-3036-4086-ba83-fec02d40f3af} 8124 "\\.\pipe\gecko-crash-server-pipe.8124" 1e140bed110 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| 6676 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4848 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4760 -prefMapHandle 4748 -prefsLen 38088 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {728d6314-8c26-4f2a-b80b-dd688278bd91} 8124 "\\.\pipe\gecko-crash-server-pipe.8124" 1e149fc5b10 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| 7172 | "C:\Users\admin\AppData\Local\Temp\fwlink.exe" | C:\Users\admin\AppData\Local\Temp\fwlink.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Games for Windows® - LIVE Game Setup Exit code: 2148270088 Version: 3.5.0089.0 (WGX_XLIVE_V3.05_RTM(panblder).110411-1052) Modules
| |||||||||||||||
| 7408 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2772 -childID 1 -isForBrowser -prefsHandle 2764 -prefMapHandle 2760 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1372 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d469329c-df42-4038-b438-a668211ad280} 8124 "\\.\pipe\gecko-crash-server-pipe.8124" 1e145842f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 7420 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (7172) fwlink.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7172) fwlink.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7172) fwlink.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (8124) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7172 | fwlink.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\xliveredist[1].msi | — | |
MD5:— | SHA256:— | |||
| 7172 | fwlink.exe | C:\Users\admin\AppData\Local\Microsoft\GFWLive\Downloads\xliveredist.msi | — | |
MD5:— | SHA256:— | |||
| 8124 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 7172 | fwlink.exe | C:\Users\admin\AppData\Local\Microsoft\GFWLive\Downloads\gfwlivesetup_17712.ver | text | |
MD5:324E62F95F29C170BF0CA2CD7A707954 | SHA256:7CCAD7E88A62DDB3F14145D697673C61954BC5AD56E5373DCB3ACF3105B4E6F5 | |||
| 7172 | fwlink.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\gfwlivesetup[1].txt | text | |
MD5:324E62F95F29C170BF0CA2CD7A707954 | SHA256:7CCAD7E88A62DDB3F14145D697673C61954BC5AD56E5373DCB3ACF3105B4E6F5 | |||
| 7172 | fwlink.exe | C:\Users\admin\AppData\Local\Microsoft\GFWLive\Downloads\gfwlclient.msi | executable | |
MD5:022B4C5E408F0F5C95968195F3126F97 | SHA256:3E266881582884E59029397E1FC0EB3BF93185D60CCB5B9F1D484CD475A076E6 | |||
| 8124 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 8124 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 8124 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 8124 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.32.238.112:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7172 | fwlink.exe | GET | 302 | 95.100.186.9:80 | http://go.microsoft.com/fwlink/?LinkID=201133 | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7172 | fwlink.exe | GET | 302 | 95.100.186.9:80 | http://go.microsoft.com/fwlink/?LinkID=194359&clcid=0x409 | unknown | — | — | whitelisted |
7172 | fwlink.exe | GET | 200 | 2.16.168.106:80 | http://download.gfwl.xboxlive.com/content/gfwl-public/redists/production/gfwlivesetup.txt | unknown | — | — | whitelisted |
7172 | fwlink.exe | GET | 200 | 2.16.168.106:80 | http://download.gfwl.xboxlive.com/content/gfwl-public/redists/production/xliveredist.msi | unknown | — | — | whitelisted |
7172 | fwlink.exe | GET | 302 | 95.100.186.9:80 | http://go.microsoft.com/fwlink/?LinkID=194360&clcid=0x409 | unknown | — | — | whitelisted |
7172 | fwlink.exe | GET | 200 | 2.16.168.106:80 | http://download.gfwl.xboxlive.com/content/gfwl-public/redists/production/gfwlclient.msi | unknown | — | — | whitelisted |
7172 | fwlink.exe | GET | 302 | 95.100.186.9:80 | http://go.microsoft.com/fwlink/?LinkId=201788 | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4180 | RUXIMICS.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 23.32.238.112:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 2.23.181.156:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
7172 | fwlink.exe | 95.100.186.9:80 | go.microsoft.com | AKAMAI-AS | FR | whitelisted |
7172 | fwlink.exe | 2.16.168.106:80 | download.gfwl.xboxlive.com | Akamai International B.V. | RU | whitelisted |
2112 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
download.gfwl.xboxlive.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
download.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |