| URL: | https://download.honeygain.com/windows-app/Honeygain_install.exe |
| Full analysis: | https://app.any.run/tasks/54f45290-3595-4bcf-bfcc-a6293eb8bc27 |
| Verdict: | Malicious activity |
| Analysis date: | February 22, 2024, 20:36:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 6ED974C409AF6CA73BD58837DB68B5FD |
| SHA1: | 529B2BE5DC24D14BBB613F1D7D11122AB33A8376 |
| SHA256: | E290459B4F7D7D477B6E47C5A3399E5A284DA1329EC6AEB7F91561C4DEE66B42 |
| SSDEEP: | 3:N8SEloFMM2QAzcKWEJFN:2SKoFQIkn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1124 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.7.1842306828\352001230" -childID 6 -isForBrowser -prefsHandle 4292 -prefMapHandle 4296 -prefsLen 29406 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ea835a1b-4521-4c34-8d82-02cee7a237e6} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 4308 193456d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1392 | "C:\Program Files\Honeygain\Honeygain.exe" | C:\Program Files\Honeygain\Honeygain.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Honeygain Exit code: 0 Version: 1.4.0.0 Modules
| |||||||||||||||
| 1484 | "C:\Users\admin\AppData\Local\Temp\MSI3B34.tmp" /HideWindow REG ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "Honeygain" /d "\"C:\Program Files\Honeygain\Honeygain.exe\" -silent" /f | C:\Users\admin\AppData\Local\Temp\MSI3B34.tmp | — | Honeygain_install.exe | |||||||||||
User: admin Company: Caphyon LTD Integrity Level: MEDIUM Description: File that launches another file Exit code: 0 Version: 19.8.1.0 Modules
| |||||||||||||||
| 1784 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.6.722214303\540541663" -childID 5 -isForBrowser -prefsHandle 3832 -prefMapHandle 3828 -prefsLen 33514 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {36a3a2f2-ff2c-4e2f-8ba7-85dae52c4da0} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 3848 19345280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1928 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.2.1335891920\1420338705" -childID 1 -isForBrowser -prefsHandle 1664 -prefMapHandle 2092 -prefsLen 24491 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {dd55162a-6046-4a27-9662-0a5a98593563} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 2004 128923f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2324 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.5.416904803\20876467" -childID 4 -isForBrowser -prefsHandle 3736 -prefMapHandle 3656 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {93b75967-5de1-414a-a242-20a0927a0985} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 3720 17df9110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2620 | "C:\Windows\System32\reg.exe" ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "Honeygain" /d "\"C:\Program Files\Honeygain\Honeygain.exe\" -silent" /f | C:\Windows\System32\reg.exe | MSI3B34.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2632 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.4.929339498\474049077" -childID 3 -isForBrowser -prefsHandle 3032 -prefMapHandle 3616 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f89303e4-e84b-4890-ab8d-6bc7105013c1} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 3636 18f26b20 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2744 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.3.853020415\1137057229" -childID 2 -isForBrowser -prefsHandle 2884 -prefMapHandle 2880 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0d883908-f774-4678-a4b3-ac1e3d616ba1} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 2896 1648f840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2820 | "C:\Users\admin\Downloads\Honeygain_install.exe" /i "C:\Users\admin\AppData\Roaming\Honeygain\Honeygain 1.4.0.0\install\Honeygain_install.msi" AI_EUIMSI=1 SHORTCUTDIR="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Honeygain" APPDIR="C:\Program Files\Honeygain" SECONDSEQUENCE="1" CLIENTPROCESSID="3988" CHAINERUIPROCESSID="3988Chainer" ACTION="INSTALL" EXECUTEACTION="INSTALL" CLIENTUILEVEL="0" ADDLOCAL="Core,Updater" CHECKBOX_1_PROP="checked" PRIMARYFOLDER="APPDIR" ROOTDRIVE="C:\" AI_FOUND_PREREQS=".NET Framework 4.7.2 (web installer)" AI_SETUPEXEPATH="C:\Users\admin\Downloads\Honeygain_install.exe" SETUPEXEDIR="C:\Users\admin\Downloads\" EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1708632636 " AI_SETUPEXEPATH_ORIGINAL="C:\Users\admin\Downloads\Honeygain_install.exe" HG_DETECTED_DOTNET_VERSION="#528049" TARGETDIR="C:\" AI_INSTALL="1" | C:\Users\admin\Downloads\Honeygain_install.exe | Honeygain_install.exe | ||||||||||||
User: admin Company: Honeygain Integrity Level: HIGH Description: Honeygain Installer Exit code: 0 Version: 1.4.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3864) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 8F6F214F01000000 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: D0B2234F01000000 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB |
| Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal | binary | |
MD5:094A6C411E12EE7D31AD963985C84518 | SHA256:887F29E0835383C457C39D870E85B120C1975669E35E6445A1422847D1BB29AD | |||
| 4052 | firefox.exe | C:\Users\admin\Downloads\AIN7xk3A.exe.part | executable | |
MD5:C810E46F33F8D012E7FCFA08065DF092 | SHA256:0BA8CE2112E8F30943D7F57E71B0B1C5D691C58B122119C576DFCAEDC60345D5 | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4052 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
4052 | firefox.exe | POST | 200 | 142.250.185.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
4052 | firefox.exe | POST | 200 | 23.32.238.49:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
4052 | firefox.exe | POST | 200 | 23.32.238.49:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
4052 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
4052 | firefox.exe | POST | 200 | 23.32.238.49:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
4052 | firefox.exe | POST | 200 | 142.250.185.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
4052 | firefox.exe | POST | 200 | 23.32.238.56:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
4052 | firefox.exe | POST | 200 | 23.32.238.49:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
4052 | firefox.exe | POST | 200 | 23.32.238.49:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4052 | firefox.exe | 172.67.71.104:443 | download.honeygain.com | CLOUDFLARENET | US | unknown |
4052 | firefox.exe | 142.250.185.170:443 | safebrowsing.googleapis.com | GOOGLE | US | whitelisted |
4052 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
4052 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | GOOGLE | US | unknown |
4052 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
4052 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | unknown |
4052 | firefox.exe | 142.250.185.227:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
download.honeygain.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
gkegw.prod.ads.prod.webservices.mozgcp.net |
| unknown |
r3.o.lencr.org |
| shared |
a1887.dscq.akamai.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3988 | Honeygain_install.exe | Domain Observed Used for C2 Detected | ET ADWARE_PUP Observed PUA SSL/TLS Certificate (HoneyGain) |
2968 | rundll32.exe | Domain Observed Used for C2 Detected | ET ADWARE_PUP Observed PUA SSL/TLS Certificate (HoneyGain) |
1572 | rundll32.exe | Domain Observed Used for C2 Detected | ET ADWARE_PUP Observed PUA SSL/TLS Certificate (HoneyGain) |
4080 | Honeygain.exe | Domain Observed Used for C2 Detected | ET ADWARE_PUP Observed PUA SSL/TLS Certificate (HoneyGain) |
4080 | Honeygain.exe | Domain Observed Used for C2 Detected | ET ADWARE_PUP Observed PUA SSL/TLS Certificate (HoneyGain) |
4080 | Honeygain.exe | Domain Observed Used for C2 Detected | ET ADWARE_PUP Observed PUA SSL/TLS Certificate (HoneyGain) |
4080 | Honeygain.exe | Domain Observed Used for C2 Detected | ET ADWARE_PUP Observed PUA SSL/TLS Certificate (HoneyGain) |
4080 | Honeygain.exe | Domain Observed Used for C2 Detected | ET ADWARE_PUP Observed Honeygain Domain (api .honeygain .com in TLS SNI) |
4080 | Honeygain.exe | Domain Observed Used for C2 Detected | ET ADWARE_PUP Observed PUA SSL/TLS Certificate (HoneyGain) |
4080 | Honeygain.exe | Domain Observed Used for C2 Detected | ET ADWARE_PUP Observed PUA SSL/TLS Certificate (HoneyGain) |
Process | Message |
|---|---|
Honeygain.exe | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|
Honeygain.exe | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|
Honeygain.exe | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|
Honeygain.exe | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|