File name:

LightBurn_Loader.exe

Full analysis: https://app.any.run/tasks/04f3e12a-4aaf-4103-8197-dd9dfb5e1bf8
Verdict: Malicious activity
Analysis date: January 05, 2026, 23:09:46
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
qrcode
inno
installer
delphi
github
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 3 sections
MD5:

7D5ADF8FD2E851C25E130342ADD26DCE

SHA1:

86AC2E764AEDC47F609333E6584E7AE1666D7C2A

SHA256:

D33BD9CA0B05A225479F5EF310DDCD2A9BFE93A5D8CE7BAAD2183AEE016E4C10

SSDEEP:

1536:K7noK4n3OXXf2Dyxmf8hizBrOKRMP28uFKff2HnTn:Io3eXQMUlOP28uFKn2Hb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • vcredist_2010_x64.exe (PID: 3692)
      • Setup.exe (PID: 6508)
    • Changes the autorun value in the registry

      • VC_redist.x64.exe (PID: 2228)
    • Registers / Runs the DLL via REGSVR32.EXE

      • LightBurn-v2.0.03.tmp (PID: 5600)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • LightBurn-v2.0.03.exe (PID: 7392)
      • LightBurn-v2.0.03.exe (PID: 8820)
      • LightBurn-v2.0.03.tmp (PID: 5600)
      • vcredist_2010_x64.exe (PID: 3692)
      • vcredist_2015-2022_x64.exe (PID: 1348)
      • vcredist_2015-2022_x64.exe (PID: 5736)
      • VC_redist.x64.exe (PID: 2228)
      • VC_redist.x64.exe (PID: 9120)
      • VC_redist.x64.exe (PID: 8620)
      • dllhost.exe (PID: 9108)
      • VC_redist.x64.exe (PID: 6000)
    • Reads security settings of Internet Explorer

      • LightBurn-v2.0.03.tmp (PID: 7504)
      • Setup.exe (PID: 6508)
      • vcredist_2015-2022_x64.exe (PID: 5736)
      • VC_redist.x64.exe (PID: 9120)
    • Reads the Windows owner or organization settings

      • LightBurn-v2.0.03.tmp (PID: 5600)
      • msiexec.exe (PID: 1296)
      • msiexec.exe (PID: 1204)
    • Starts a Microsoft application from unusual location

      • vcredist_2010_x64.exe (PID: 3692)
      • vcredist_2015-2022_x64.exe (PID: 1348)
      • vcredist_2015-2022_x64.exe (PID: 5736)
      • VC_redist.x64.exe (PID: 2228)
    • Process drops legitimate windows executable

      • LightBurn-v2.0.03.tmp (PID: 5600)
      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
      • vcredist_2015-2022_x64.exe (PID: 1348)
      • vcredist_2015-2022_x64.exe (PID: 5736)
      • VC_redist.x64.exe (PID: 2228)
      • msiexec.exe (PID: 1204)
      • VC_redist.x64.exe (PID: 8620)
    • Using the short paths format

      • vcredist_2010_x64.exe (PID: 3692)
    • Creates file in the systems drive root

      • vcredist_2010_x64.exe (PID: 3692)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 1296)
      • msiexec.exe (PID: 1204)
    • Searches for installed software

      • vcredist_2015-2022_x64.exe (PID: 5736)
      • VC_redist.x64.exe (PID: 2228)
      • dllhost.exe (PID: 5180)
      • VC_redist.x64.exe (PID: 9120)
      • VC_redist.x64.exe (PID: 8620)
      • VC_redist.x64.exe (PID: 3172)
      • VC_redist.x64.exe (PID: 6000)
    • Starts itself from another location

      • vcredist_2015-2022_x64.exe (PID: 5736)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1524)
    • Application launched itself

      • VC_redist.x64.exe (PID: 2992)
      • VC_redist.x64.exe (PID: 9120)
      • VC_redist.x64.exe (PID: 3172)
      • VC_redist.x64.exe (PID: 6512)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 8420)
    • There is functionality for taking screenshot (YARA)

      • LightBurn.exe (PID: 7248)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 4336)
      • firefox.exe (PID: 7816)
      • LightBurn-v2.0.03.exe (PID: 7392)
      • LightBurn_Loader.exe (PID: 8524)
      • LightBurn_Loader.exe (PID: 7228)
      • LightBurn_Loader.exe (PID: 6648)
      • LightBurn_Loader.exe (PID: 7296)
      • msedge.exe (PID: 7880)
      • notepad.exe (PID: 7076)
      • VC_redist.x64.exe (PID: 3172)
    • Checks supported languages

      • TextInputHost.exe (PID: 4472)
      • LightBurn_Loader.exe (PID: 7736)
      • LightBurn-v2.0.03.exe (PID: 7392)
      • LightBurn-v2.0.03.tmp (PID: 7504)
      • LightBurn-v2.0.03.exe (PID: 8820)
      • LightBurn-v2.0.03.tmp (PID: 5600)
      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
      • Setup.exe (PID: 6508)
      • vcredist_2015-2022_x64.exe (PID: 1348)
      • vcredist_2015-2022_x64.exe (PID: 5736)
      • VC_redist.x64.exe (PID: 2228)
      • msiexec.exe (PID: 1204)
      • VC_redist.x64.exe (PID: 2992)
      • VC_redist.x64.exe (PID: 9120)
      • VC_redist.x64.exe (PID: 8620)
      • DoCheckLightBurn.exe (PID: 6532)
      • LightBurn.exe (PID: 7248)
      • LightBurn_Loader.exe (PID: 7228)
      • LightBurn_Loader.exe (PID: 7296)
      • VC_redist.x64.exe (PID: 3172)
      • VC_redist.x64.exe (PID: 6512)
      • VC_redist.x64.exe (PID: 6000)
      • identity_helper.exe (PID: 9120)
    • Reads the computer name

      • TextInputHost.exe (PID: 4472)
      • LightBurn_Loader.exe (PID: 7736)
      • LightBurn-v2.0.03.tmp (PID: 7504)
      • LightBurn-v2.0.03.exe (PID: 8820)
      • LightBurn-v2.0.03.tmp (PID: 5600)
      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
      • Setup.exe (PID: 6508)
      • vcredist_2015-2022_x64.exe (PID: 5736)
      • VC_redist.x64.exe (PID: 2228)
      • msiexec.exe (PID: 1204)
      • VC_redist.x64.exe (PID: 9120)
      • VC_redist.x64.exe (PID: 8620)
      • DoCheckLightBurn.exe (PID: 6532)
      • LightBurn_Loader.exe (PID: 7228)
      • LightBurn.exe (PID: 7248)
      • LightBurn_Loader.exe (PID: 7296)
      • VC_redist.x64.exe (PID: 6000)
      • identity_helper.exe (PID: 9120)
    • Application launched itself

      • firefox.exe (PID: 7816)
      • firefox.exe (PID: 7836)
      • msedge.exe (PID: 7880)
    • Create files in a temporary directory

      • LightBurn-v2.0.03.exe (PID: 7392)
      • LightBurn-v2.0.03.exe (PID: 8820)
      • LightBurn-v2.0.03.tmp (PID: 5600)
      • Setup.exe (PID: 6508)
      • vcredist_2015-2022_x64.exe (PID: 5736)
      • VC_redist.x64.exe (PID: 2228)
      • VC_redist.x64.exe (PID: 9120)
      • VC_redist.x64.exe (PID: 6000)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4336)
      • msiexec.exe (PID: 1296)
      • msiexec.exe (PID: 1204)
    • Process checks computer location settings

      • LightBurn-v2.0.03.tmp (PID: 7504)
      • vcredist_2015-2022_x64.exe (PID: 5736)
      • VC_redist.x64.exe (PID: 9120)
      • LightBurn.exe (PID: 7248)
    • The sample compiled with english language support

      • LightBurn-v2.0.03.tmp (PID: 5600)
      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
      • vcredist_2015-2022_x64.exe (PID: 1348)
      • vcredist_2015-2022_x64.exe (PID: 5736)
      • VC_redist.x64.exe (PID: 2228)
      • msiexec.exe (PID: 1204)
      • VC_redist.x64.exe (PID: 9120)
      • VC_redist.x64.exe (PID: 8620)
      • VC_redist.x64.exe (PID: 6000)
    • The sample compiled with Italian language support

      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
    • Reads the machine GUID from the registry

      • vcredist_2010_x64.exe (PID: 3692)
      • Setup.exe (PID: 6508)
      • msiexec.exe (PID: 1296)
      • VC_redist.x64.exe (PID: 2228)
      • msiexec.exe (PID: 1204)
      • LightBurn.exe (PID: 7248)
    • The sample compiled with japanese language support

      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
    • The sample compiled with chinese language support

      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
      • LightBurn-v2.0.03.tmp (PID: 5600)
    • The sample compiled with korean language support

      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
    • The sample compiled with french language support

      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
    • The sample compiled with spanish language support

      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
    • The sample compiled with german language support

      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
    • The sample compiled with russian language support

      • vcredist_2010_x64.exe (PID: 3692)
      • msiexec.exe (PID: 1296)
    • Reads CPU info

      • Setup.exe (PID: 6508)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 1296)
      • msiexec.exe (PID: 1204)
      • LightBurn.exe (PID: 7248)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1296)
      • VC_redist.x64.exe (PID: 2228)
      • msiexec.exe (PID: 1204)
      • LightBurn-v2.0.03.tmp (PID: 5600)
    • Detects InnoSetup installer (YARA)

      • LightBurn-v2.0.03.exe (PID: 7392)
      • LightBurn-v2.0.03.tmp (PID: 7504)
      • LightBurn-v2.0.03.exe (PID: 8820)
      • LightBurn-v2.0.03.tmp (PID: 5600)
    • Compiled with Borland Delphi (YARA)

      • LightBurn-v2.0.03.exe (PID: 7392)
      • LightBurn-v2.0.03.tmp (PID: 7504)
      • LightBurn-v2.0.03.exe (PID: 8820)
      • LightBurn-v2.0.03.tmp (PID: 5600)
    • Checks proxy server information

      • slui.exe (PID: 9140)
      • LightBurn.exe (PID: 7248)
    • Creates files in the program directory

      • VC_redist.x64.exe (PID: 2228)
      • LightBurn-v2.0.03.tmp (PID: 5600)
    • Manages system restore points

      • SrTasks.exe (PID: 7764)
    • Launching a file from a Registry key

      • VC_redist.x64.exe (PID: 2228)
    • The sample compiled with arabic language support

      • LightBurn-v2.0.03.tmp (PID: 5600)
    • Reads security settings of Internet Explorer

      • dllhost.exe (PID: 9108)
      • notepad.exe (PID: 7076)
    • Reads the time zone

      • LightBurn.exe (PID: 7248)
    • Reads Environment values

      • identity_helper.exe (PID: 9120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (87)
.exe | Generic Win/DOS Executable (6.4)
.exe | DOS Executable Generic (6.4)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2016:01:01 20:32:49+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 8
CodeSize: 36864
InitializedDataSize: 20480
UninitializedDataSize: 151552
EntryPoint: 0x2e7f0
OSVersion: 5.2
ImageVersion: 5.2
SubsystemVersion: 5.2
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
230
Monitored processes
65
Malicious processes
4
Suspicious processes
5

Behavior graph

Click at the process to see the details
start lightburn_loader.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs textinputhost.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe firefox.exe no specs firefox.exe no specs winrar.exe lightburn-v2.0.03.exe lightburn-v2.0.03.tmp no specs lightburn-v2.0.03.exe lightburn-v2.0.03.tmp vcredist_2010_x64.exe setup.exe msiexec.exe vcredist_2015-2022_x64.exe vcredist_2015-2022_x64.exe vc_redist.x64.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe vc_redist.x64.exe no specs vc_redist.x64.exe vc_redist.x64.exe dochecklightburn.exe no specs conhost.exe no specs Copy/Move/Rename/Delete/Link Object regsvr32.exe no specs lightburn_loader.exe no specs lightburn_loader.exe lightburn.exe lightburn_loader.exe no specs lightburn_loader.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs notepad.exe no specs vc_redist.x64.exe no specs vc_redist.x64.exe no specs vc_redist.x64.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs lightburn_loader.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1204"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5048 -prefsLen 39120 -prefMapHandle 5052 -prefMapSize 273045 -jsInitHandle 5056 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4920 -initialChannelId {e52cf670-47c3-4fa6-a703-689e6d4a48cf} -parentPid 7836 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7836" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
1204C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1296C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1340"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5752,i,17905209877146781088,18038361710856774920,262144 --variations-seed-version --mojo-platform-channel-handle=6556 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1348"C:\Users\admin\AppData\Local\Temp\is-C8J04.tmp/vcredist_2015-2022_x64.exe"C:\Users\admin\AppData\Local\Temp\is-C8J04.tmp\vcredist_2015-2022_x64.exe
LightBurn-v2.0.03.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33810
Exit code:
3010
Version:
14.40.33810.0
Modules
Images
c:\users\admin\appdata\local\temp\is-c8j04.tmp\vcredist_2015-2022_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1492\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeDoCheckLightBurn.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1492"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6548,i,17905209877146781088,18038361710856774920,262144 --variations-seed-version --mojo-platform-channel-handle=6764 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1524C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1780"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4996 -prefsLen 39120 -prefMapHandle 5000 -prefMapSize 273045 -jsInitHandle 5004 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5012 -initialChannelId {859e95d1-93ae-472f-a3e0-fdc5ed70907c} -parentPid 7836 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7836" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140_1.dll
2124"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --disable-quic --onnx-enabled-for-ee --string-annotations --always-read-main-dll --field-trial-handle=5076,i,17905209877146781088,18038361710856774920,262144 --variations-seed-version --mojo-platform-channel-handle=5272 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
35 334
Read events
34 016
Write events
918
Delete events
400

Modification events

(PID) Process:(4336) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(4336) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
(PID) Process:(4336) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:13
Value:
(PID) Process:(4336) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:12
Value:
(PID) Process:(4336) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:11
Value:
(PID) Process:(4336) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:10
Value:
(PID) Process:(4336) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:9
Value:
(PID) Process:(4336) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:8
Value:
(PID) Process:(4336) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:7
Value:
(PID) Process:(4336) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:6
Value:
Executable files
233
Suspicious files
623
Text files
452
Unknown types
7

Dropped files

PID
Process
Filename
Type
7836firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
7836firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
7836firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7836firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7836firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.binbinary
MD5:5152D8F49F1AD4219D935611EFE18437
SHA256:9A6E50715E3C49A43E3D622EDE7E37ECF0767342B3039B8B0AE25BBE4FF6F66E
7836firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsontext
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
7836firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:B30329D7D2CF4258C22F500CBEA218FF
SHA256:C5E20431B116E1DABD383C6855A36E6DAF13E1CC125B83D59EF68B4BCEFB02E6
7836firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmptext
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
7836firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:E456B99E4F96451BED2DDF14C83E4DED
SHA256:AD322531719D94EE64E161B6E0A74B2F2D824B9D2267D4DB260E73938BB0059C
7836firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
488
TCP/UDP connections
208
DNS requests
143
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7836
firefox.exe
POST
142.250.184.195:80
http://o.pki.goog/s/wr3/dcM
US
whitelisted
6488
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
7836
firefox.exe
GET
200
151.101.1.91:443
https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/ms-language-packs/records/cfr-v1-en-US
US
text
330 b
unknown
1388
svchost.exe
GET
200
23.53.41.90:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
1388
svchost.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
7836
firefox.exe
GET
101
34.107.243.93:443
https://push.services.mozilla.com/
US
unknown
7836
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
unknown
7836
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
unknown
7836
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/we2
US
binary
280 b
whitelisted
7836
firefox.exe
GET
200
34.160.144.191:443
https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2025-11-08-08-20-52.chain
US
text
5.18 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
1388
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4992
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3412
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7836
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE-CLOUD-PLATFORM
US
whitelisted
7836
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
7836
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
7836
firefox.exe
142.250.184.195:80
o.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.184.238
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.36.137.203
whitelisted
example.org
  • 104.18.2.24
  • 104.18.3.24
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2292
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
Process
Message
Setup.exe
The operation completed successfully.
Setup.exe
The operation completed successfully.
msiexec.exe
Failed to release Service
LightBurn.exe
- Theme Layers Added
LightBurn.exe
- Theme Icons Added
LightBurn.exe
- Theme QPalette Added
LightBurn.exe
QCoreApplication::postEvent: Unexpected null receiver
LightBurn.exe
- Theme Info Added
LightBurn.exe
- Theme Layers Added
LightBurn.exe
- Theme Icons Added