download:

Feature.jpg

Full analysis: https://app.any.run/tasks/a2647e80-2811-43ed-9170-b2d6bd4fcbbd
Verdict: Malicious activity
Analysis date: July 18, 2018, 18:35:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/x-php
File info: PHP script, ASCII text, with very long lines
MD5:

B2E1643489DDBDCA5E1A4AE06E581CAD

SHA1:

E680B58926609FCF0A2AFA73BA1BF3A6AC61C414

SHA256:

D33993B55ED2B9DE8790C228344C40D5CC824D8951E342FAE0D47D823AC67801

SSDEEP:

1536:cV79v+o+exg7lZVpGEvd8LGzjSvWNEtj2:09v+DeCOjL+ZIa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • maintenanceservice_tmp.exe (PID: 1932)
      • firefox.exe (PID: 3616)
      • firefox.exe (PID: 2404)
      • updater.exe (PID: 2164)
      • helper.exe (PID: 3904)
      • updater.exe (PID: 1580)
      • firefox.exe (PID: 3320)
    • Loads dropped or rewritten executable

      • firefox.exe (PID: 2404)
      • helper.exe (PID: 3904)
      • firefox.exe (PID: 3616)
  • SUSPICIOUS

    • Application launched itself

      • updater.exe (PID: 1580)
    • Creates a software uninstall entry

      • maintenanceservice_tmp.exe (PID: 1932)
      • helper.exe (PID: 3904)
    • Executable content was dropped or overwritten

      • updater.exe (PID: 2164)
    • Creates files in the program directory

      • maintenanceservice_tmp.exe (PID: 1932)
      • updater.exe (PID: 2164)
      • helper.exe (PID: 3904)
    • Modifies the open verb of a shell class

      • helper.exe (PID: 3904)
    • Creates COM task schedule object

      • helper.exe (PID: 3904)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 3616)
    • Dropped object may contain URL's

      • firefox.exe (PID: 3616)
      • updater.exe (PID: 2164)
    • Dropped object may contain Bitcoin addresses

      • updater.exe (PID: 2164)
    • Creates files in the user directory

      • firefox.exe (PID: 3616)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.php | PHP source (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start rundll32.exe no specs firefox.exe no specs updater.exe no specs updater.exe helper.exe no specs maintenanceservice_tmp.exe no specs firefox.exe firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1336"C:\Windows\System32\rundll32.exe" "C:\Program Files\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen C:\Users\admin\AppData\Local\Temp\Feature.jpgC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1580"C:\Program Files\Mozilla Firefox\updater.exe" C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox" 3320 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\updater.exefirefox.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
MEDIUM
Description:
Firefox Software Updater
Exit code:
0
Version:
55.0.3
Modules
Images
c:\program files\mozilla firefox\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1932dummyparam.exe upgradeC:\Program Files\Mozilla Maintenance Service\maintenanceservice_tmp.exeupdater.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
HIGH
Exit code:
0
Version:
56.0
Modules
Images
c:\program files\mozilla maintenance service\maintenanceservice_tmp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2164"C:\Program Files\Mozilla Firefox\updater.exe" C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox" 3320 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\updater.exe
updater.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
HIGH
Description:
Firefox Software Updater
Exit code:
0
Version:
55.0.3
Modules
Images
c:\program files\mozilla firefox\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2404"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3616.0.2056446622\208432476" -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" 3616 "\\.\pipe\gecko-crash-server-pipe.3616" gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
56.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
3320"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
55.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
3616"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
updater.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
56.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
3904argv0ignored /PostUpdateC:\Program Files\Mozilla Firefox\uninstall\helper.exeupdater.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox Helper
Exit code:
2
Version:
56.0
Modules
Images
c:\program files\mozilla firefox\uninstall\helper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
525
Read events
405
Write events
107
Delete events
13

Modification events

(PID) Process:(1336) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
rundll32.exe
(PID) Process:(1336) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows Photo Viewer\Viewer
Operation:writeName:MainWndPos
Value:
6000000034000000A00400008002000000000000
(PID) Process:(1580) updater.exeKey:HKEY_CLASSES_ROOT\Applications\updater.exe
Operation:writeName:IsHostApp
Value:
(PID) Process:(1580) updater.exeKey:HKEY_CLASSES_ROOT\Applications\updater.exe
Operation:writeName:NoOpenWith
Value:
(PID) Process:(1580) updater.exeKey:HKEY_CLASSES_ROOT\Applications\updater.exe
Operation:writeName:NoStartPage
Value:
(PID) Process:(1580) updater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1580) updater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2164) updater.exeKey:HKEY_CLASSES_ROOT\Applications\updater.exe
Operation:writeName:IsHostApp
Value:
(PID) Process:(2164) updater.exeKey:HKEY_CLASSES_ROOT\Applications\updater.exe
Operation:writeName:NoOpenWith
Value:
(PID) Process:(2164) updater.exeKey:HKEY_CLASSES_ROOT\Applications\updater.exe
Operation:writeName:NoStartPage
Value:
Executable files
65
Suspicious files
16
Text files
16
Unknown types
18

Dropped files

PID
Process
Filename
Type
1580updater.exeC:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0\sta5F05.tmp
MD5:
SHA256:
2164updater.exeC:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0\sta7731.tmp
MD5:
SHA256:
2164updater.exeC:\Program Files\Mozilla Firefox\updating\update.manifest
MD5:
SHA256:
2164updater.exeC:\Program Files\Mozilla Firefox\xul.dll.moz-backup
MD5:
SHA256:
2164updater.exeC:\Program Files\Mozilla Firefox\xul.dll
MD5:
SHA256:
2164updater.exeC:\Program Files\Mozilla Firefox\updating\0.patch
MD5:
SHA256:
2164updater.exeC:\Program Files\Mozilla Firefox\updating\1.patch
MD5:
SHA256:
2164updater.exeC:\Program Files\Mozilla Firefox\updating\2.patch
MD5:
SHA256:
2164updater.exeC:\Program Files\Mozilla Firefox\updating\3.patch
MD5:
SHA256:
2164updater.exeC:\Program Files\Mozilla Firefox\updating\4.patch
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3616
firefox.exe
54.148.90.131:443
services.addons.mozilla.org
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
services.addons.mozilla.org
  • 54.148.90.131
  • 52.11.89.53
  • 52.43.178.180
  • 52.11.92.87
  • 52.25.12.144
  • 35.161.145.213
whitelisted
olympia.prod.mozaws.net
  • 35.161.145.213
  • 52.25.12.144
  • 52.11.92.87
  • 52.43.178.180
  • 52.11.89.53
  • 54.148.90.131
whitelisted

Threats

No threats detected
No debug info