| URL: | https://www.torproject.org/dist/torbrowser/13.5.1/tor-browser-windows-x86_64-portable-13.5.1.exe |
| Full analysis: | https://app.any.run/tasks/d0c80885-4488-454a-8662-33f82e0aa5d6 |
| Verdict: | Malicious activity |
| Analysis date: | August 03, 2024, 09:38:35 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MD5: | FCC2519E7AA2030B1A4E8EB1B867756B |
| SHA1: | 5125E5E31255A275A8E9C1D85CB3A0CECC80F05E |
| SHA256: | E88FBA9E2E8BBF93560C3AF39A582EA0373A1AC6947B2D994B68D934E79A3D79 |
| SSDEEP: | 3:N8DSL2VXZG+XJcSWy+KKYHalAXSBKSUkcgkA:2OLyXZGrSrKqalAiBKSZcFA |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1076 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="6204.3.992028281\2009917209" -childID 3 -isForBrowser -prefsHandle 3728 -prefMapHandle 3724 -prefsLen 20641 -prefMapSize 241916 -jsInitHandle 1288 -jsInitLen 240916 -parentBuildID 20240708120000 -win32kLockedDown -appDir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - {9fc6fa4b-761e-4ad3-917d-5f3135767da8} 6204 tab | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Tor Browser Exit code: 0 Version: 115.13.0 Modules
| |||||||||||||||
| 1716 | "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Tor\tor.exe" -f "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\torrc" DataDirectory "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor" ClientOnionAuthDir "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\onion-auth" --defaults-torrc "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\torrc-defaults" GeoIPFile "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\geoip" GeoIPv6File "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\geoip6" +__ControlPort 127.0.0.1:9151 HashedControlPassword 16:dc3f83baf013a29a6077277ee3d0246a03e57b4308db2ca4644ca8fec3 +__SocksPort "127.0.0.1:9150 ExtendedErrors IPv6Traffic PreferIPv6 KeepAliveIsolateSOCKSAuth" __OwningControllerProcess 6204 DisableNetwork 1 | C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Tor\tor.exe | — | firefox.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2928 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="3268.9.71350400\331513649" -childID 8 -isForBrowser -prefsHandle 2688 -prefMapHandle 4808 -prefsLen 22712 -prefMapSize 240456 -jsInitHandle 1256 -jsInitLen 240916 -parentBuildID 20240708120000 -win32kLockedDown -appDir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - {ae43119b-7909-4a75-b82e-d18842d3c8d1} 3268 tab | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Tor Browser Exit code: 0 Version: 115.13.0 Modules
| |||||||||||||||
| 3076 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoABAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=5808 --field-trial-handle=1904,i,9545027208310983167,2505339765450578858,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 3076 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | tor.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3268 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Tor Browser Exit code: 0 Version: 115.13.0 Modules
| |||||||||||||||
| 3684 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="3268.7.412320073\602583193" -childID 6 -isForBrowser -prefsHandle 3888 -prefMapHandle 3996 -prefsLen 22491 -prefMapSize 240456 -jsInitHandle 1256 -jsInitLen 240916 -parentBuildID 20240708120000 -win32kLockedDown -appDir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - {f0e19c0c-46f1-4df4-a550-fe2ff1546842} 3268 tab | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Tor Browser Exit code: 0 Version: 115.13.0 Modules
| |||||||||||||||
| 4192 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="6204.0.911964958\361980265" -parentBuildID 20240708120000 -prefsHandle 1896 -prefMapHandle 1888 -prefsLen 21579 -prefMapSize 241916 -appDir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - {05a6be18-6365-424e-bd09-15bc763f6682} 6204 gpu | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Tor Browser Exit code: 1 Version: 115.13.0 Modules
| |||||||||||||||
| 4316 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="3268.4.1076626867\2080844385" -parentBuildID 20240708120000 -prefsHandle 2824 -prefMapHandle 2984 -prefsLen 21219 -prefMapSize 240456 -appDir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - {459895f2-7b13-41e0-9065-313a4da1e36e} 3268 rdd | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Tor Browser Exit code: 0 Version: 115.13.0 Modules
| |||||||||||||||
| 4436 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | tor-browser-windows-x86_64-portable-13.5.1.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Tor Browser Exit code: 0 Version: 115.13.0 Modules
| |||||||||||||||
| (PID) Process: | (6416) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (6416) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (6416) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (6416) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (6416) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (6416) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (6416) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (6416) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (6416) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (6416) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6416 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6416 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6416 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6416 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6416 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RFe5a9f.TMP | — | |
MD5:— | SHA256:— | |||
| 6416 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6416 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RFe5a9f.TMP | — | |
MD5:— | SHA256:— | |||
| 6416 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6416 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Variations | binary | |
MD5:961E3604F228B0D10541EBF921500C86 | SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED | |||
| 6416 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:FC81892AC822DCBB09441D3B58B47125 | SHA256:FB077C966296D02D50CCBF7F761D2A3311A206A784A7496F331C2B0D6AD205C8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1248 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1248 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6224 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7828 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/fhtuazrdjnqikxtln4pvzfahjq_20240720.656159207.14/obedbbhbpmojnkanicioggnmelmoomoc_20240720.656159207.14_all_ENUS500000_kewn2vupl47qk3g57fw5vpvpaq.crx3 | unknown | — | — | whitelisted |
6244 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7828 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/fhtuazrdjnqikxtln4pvzfahjq_20240720.656159207.14/obedbbhbpmojnkanicioggnmelmoomoc_20240720.656159207.14_all_ENUS500000_kewn2vupl47qk3g57fw5vpvpaq.crx3 | unknown | — | — | whitelisted |
7828 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/fhtuazrdjnqikxtln4pvzfahjq_20240720.656159207.14/obedbbhbpmojnkanicioggnmelmoomoc_20240720.656159207.14_all_ENUS500000_kewn2vupl47qk3g57fw5vpvpaq.crx3 | unknown | — | — | whitelisted |
7828 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/fhtuazrdjnqikxtln4pvzfahjq_20240720.656159207.14/obedbbhbpmojnkanicioggnmelmoomoc_20240720.656159207.14_all_ENUS500000_kewn2vupl47qk3g57fw5vpvpaq.crx3 | unknown | — | — | whitelisted |
7828 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/fhtuazrdjnqikxtln4pvzfahjq_20240720.656159207.14/obedbbhbpmojnkanicioggnmelmoomoc_20240720.656159207.14_all_ENUS500000_kewn2vupl47qk3g57fw5vpvpaq.crx3 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
876 | RUXIMICS.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1108 | svchost.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6416 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
6692 | chrome.exe | 116.202.120.165:443 | www.torproject.org | Hetzner Online GmbH | DE | unknown |
6692 | chrome.exe | 74.125.128.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6416 | chrome.exe | 224.0.0.251:5353 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
www.torproject.org |
| shared |
accounts.google.com |
| whitelisted |
dist.torproject.org |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
www.google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7748 | tor.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 3 |
7748 | tor.exe | Misc Attack | ET TOR Known Tor Exit Node Traffic group 3 |
7748 | tor.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 848 |
7748 | tor.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 307 |
7748 | tor.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 779 |