| download: | Feature.jpg |
| Full analysis: | https://app.any.run/tasks/a2647e80-2811-43ed-9170-b2d6bd4fcbbd |
| Verdict: | Malicious activity |
| Analysis date: | July 18, 2018, 18:35:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/x-php |
| File info: | PHP script, ASCII text, with very long lines |
| MD5: | B2E1643489DDBDCA5E1A4AE06E581CAD |
| SHA1: | E680B58926609FCF0A2AFA73BA1BF3A6AC61C414 |
| SHA256: | D33993B55ED2B9DE8790C228344C40D5CC824D8951E342FAE0D47D823AC67801 |
| SSDEEP: | 1536:cV79v+o+exg7lZVpGEvd8LGzjSvWNEtj2:09v+DeCOjL+ZIa |
| .php | | | PHP source (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1336 | "C:\Windows\System32\rundll32.exe" "C:\Program Files\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen C:\Users\admin\AppData\Local\Temp\Feature.jpg | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1580 | "C:\Program Files\Mozilla Firefox\updater.exe" C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox" 3320 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\updater.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Foundation Integrity Level: MEDIUM Description: Firefox Software Updater Exit code: 0 Version: 55.0.3 Modules
| |||||||||||||||
| 1932 | dummyparam.exe upgrade | C:\Program Files\Mozilla Maintenance Service\maintenanceservice_tmp.exe | — | updater.exe | |||||||||||
User: admin Company: Mozilla Foundation Integrity Level: HIGH Exit code: 0 Version: 56.0 Modules
| |||||||||||||||
| 2164 | "C:\Program Files\Mozilla Firefox\updater.exe" C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox" 3320 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\updater.exe | updater.exe | ||||||||||||
User: admin Company: Mozilla Foundation Integrity Level: HIGH Description: Firefox Software Updater Exit code: 0 Version: 55.0.3 Modules
| |||||||||||||||
| 2404 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3616.0.2056446622\208432476" -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" 3616 "\\.\pipe\gecko-crash-server-pipe.3616" gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 56.0 Modules
| |||||||||||||||
| 3320 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 55.0.3 Modules
| |||||||||||||||
| 3616 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | updater.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 56.0 Modules
| |||||||||||||||
| 3904 | argv0ignored /PostUpdate | C:\Program Files\Mozilla Firefox\uninstall\helper.exe | — | updater.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Helper Exit code: 2 Version: 56.0 Modules
| |||||||||||||||
| (PID) Process: | (1336) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: rundll32.exe | |||
| (PID) Process: | (1336) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows Photo Viewer\Viewer |
| Operation: | write | Name: | MainWndPos |
Value: 6000000034000000A00400008002000000000000 | |||
| (PID) Process: | (1580) updater.exe | Key: | HKEY_CLASSES_ROOT\Applications\updater.exe |
| Operation: | write | Name: | IsHostApp |
Value: | |||
| (PID) Process: | (1580) updater.exe | Key: | HKEY_CLASSES_ROOT\Applications\updater.exe |
| Operation: | write | Name: | NoOpenWith |
Value: | |||
| (PID) Process: | (1580) updater.exe | Key: | HKEY_CLASSES_ROOT\Applications\updater.exe |
| Operation: | write | Name: | NoStartPage |
Value: | |||
| (PID) Process: | (1580) updater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1580) updater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2164) updater.exe | Key: | HKEY_CLASSES_ROOT\Applications\updater.exe |
| Operation: | write | Name: | IsHostApp |
Value: | |||
| (PID) Process: | (2164) updater.exe | Key: | HKEY_CLASSES_ROOT\Applications\updater.exe |
| Operation: | write | Name: | NoOpenWith |
Value: | |||
| (PID) Process: | (2164) updater.exe | Key: | HKEY_CLASSES_ROOT\Applications\updater.exe |
| Operation: | write | Name: | NoStartPage |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1580 | updater.exe | C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0\sta5F05.tmp | — | |
MD5:— | SHA256:— | |||
| 2164 | updater.exe | C:\Users\admin\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates\0\sta7731.tmp | — | |
MD5:— | SHA256:— | |||
| 2164 | updater.exe | C:\Program Files\Mozilla Firefox\updating\update.manifest | — | |
MD5:— | SHA256:— | |||
| 2164 | updater.exe | C:\Program Files\Mozilla Firefox\xul.dll.moz-backup | — | |
MD5:— | SHA256:— | |||
| 2164 | updater.exe | C:\Program Files\Mozilla Firefox\xul.dll | — | |
MD5:— | SHA256:— | |||
| 2164 | updater.exe | C:\Program Files\Mozilla Firefox\updating\0.patch | — | |
MD5:— | SHA256:— | |||
| 2164 | updater.exe | C:\Program Files\Mozilla Firefox\updating\1.patch | — | |
MD5:— | SHA256:— | |||
| 2164 | updater.exe | C:\Program Files\Mozilla Firefox\updating\2.patch | — | |
MD5:— | SHA256:— | |||
| 2164 | updater.exe | C:\Program Files\Mozilla Firefox\updating\3.patch | — | |
MD5:— | SHA256:— | |||
| 2164 | updater.exe | C:\Program Files\Mozilla Firefox\updating\4.patch | — | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3616 | firefox.exe | 54.148.90.131:443 | services.addons.mozilla.org | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
services.addons.mozilla.org |
| whitelisted |
olympia.prod.mozaws.net |
| whitelisted |