| download: | /download/netscape-9-0-beta-1-netscape-navigator-9.0b1/netscape-9-0-beta-1-netscape-navigator-9.0b1.exe |
| Full analysis: | https://app.any.run/tasks/f3e2530f-dc58-473e-b55f-1cd3c3ab3552 |
| Verdict: | Malicious activity |
| Analysis date: | December 17, 2023, 15:16:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | C00A3FE37D0F7334122A6EE11CC1B79B |
| SHA1: | 5FFED4378033A17A9C3CE35A0AD5DDBED7361AFE |
| SHA256: | E8BA1FF03EFE1B27E5898399A27D11C359137F70D0504B4A6F4C0F713D7D8DE8 |
| SSDEEP: | 98304:crc8d7xE2p9UbJ1fPpBc4gO0wexBJfBJDab42b3+vykpDpkmCS4EN4fVyKCcvibU:9WXyF8Goj6uPC3 |
| .exe | | | Win64 Executable (generic) (28.6) |
|---|---|---|
| .exe | | | UPX compressed Win32 Executable (28) |
| .exe | | | Win32 EXE Yoda's Crypter (27.5) |
| .dll | | | Win32 Dynamic Link Library (generic) (6.8) |
| .exe | | | Win32 Executable (generic) (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2006:08:16 00:27:50+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 40960 |
| InitializedDataSize: | 28672 |
| UninitializedDataSize: | 94208 |
| EntryPoint: | 0x21cf0 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.42.0.0 |
| ProductVersionNumber: | 4.42.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Mozilla |
| FileDescription: | Firefox |
| FileVersion: | 4.42 |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Mozilla |
| OriginalFileName: | 7zS.sfx.exe |
| ProductName: | Firefox |
| ProductVersion: | 4.42 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Users\admin\Desktop\netscape-9-0-beta-1-netscape-navigator-9.0b1.exe" | C:\Users\admin\Desktop\netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Integrity Level: MEDIUM Description: Firefox Exit code: 3221226540 Version: 4.42 Modules
| |||||||||||||||
| 480 | .\setup.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\setup.exe | — | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | |||||||||||
User: admin Company: Netscape Integrity Level: HIGH Description: Navigator Installer Exit code: 0 Version: 9.0 Modules
| |||||||||||||||
| 1624 | "C:\Program Files\Netscape\Navigator 9\navigator.exe" | C:\Program Files\Netscape\Navigator 9\navigator.exe | — | setup.exe | |||||||||||
User: admin Company: Netscape Integrity Level: HIGH Description: Navigator Exit code: 0 Version: Personal Modules
| |||||||||||||||
| 1808 | "C:\Program Files\Netscape\Navigator 9\navigator.exe" | C:\Program Files\Netscape\Navigator 9\navigator.exe | — | navigator.exe | |||||||||||
User: admin Company: Netscape Integrity Level: HIGH Description: Navigator Exit code: 0 Version: Personal Modules
| |||||||||||||||
| 2080 | "C:\Users\admin\Desktop\netscape-9-0-beta-1-netscape-navigator-9.0b1.exe" | C:\Users\admin\Desktop\netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 4.42 Modules
| |||||||||||||||
| 2300 | "C:\Program Files\Netscape\Navigator 9\navigator.exe" | C:\Program Files\Netscape\Navigator 9\navigator.exe | navigator.exe | ||||||||||||
User: admin Company: Netscape Integrity Level: MEDIUM Description: Navigator Exit code: 0 Version: Personal Modules
| |||||||||||||||
| (PID) Process: | (480) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\InstallerTest |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (480) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 115 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2080 | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\nonlocalized\LICENSE | text | |
MD5:48FF35A6E75247E702019CDDD0EACC21 | SHA256:C2AA7D58CEBD24CB877BBF11D6B13A4BB7CD08B9D7DB5D3037CA06C46BF4CFD8 | |||
| 2080 | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\nonlocalized\res\forms.css | text | |
MD5:43C717453B00DBA083428B8E3583B588 | SHA256:6DE94BF45EE501DFFD9FCFF3F4FCDFD85E2452CDBCE630813381BFFF77F777D5 | |||
| 2080 | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\nonlocalized\res\EditorOverride.css | text | |
MD5:4B3B5AD0B17C566819A88D54026B52FD | SHA256:4ECA3B7360E2D917B9C6C626F9BF5AAFDD5EEC1D296146BAAB32D1F3B00D7A53 | |||
| 2080 | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\nonlocalized\res\svg.css | text | |
MD5:0386ADBF839E5E72336F780838965ED4 | SHA256:3AC1F6E45E7F599EBAC6F6658053231F2769DA73360405D5BFEAA0317C1AC319 | |||
| 2080 | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\nonlocalized\res\quirk.css | text | |
MD5:79959B19373EFB260456C42E0D176068 | SHA256:EBD1A3BA548D222825D6500879A656F125E71084382C9067D1322FBAD4D57467 | |||
| 2080 | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\nonlocalized\res\mathml.css | text | |
MD5:3FA9013A72E4119B37D01FDDC304B503 | SHA256:9A113001B65BD4F0AC3C4D22158E34F0DC393F28BFC1E5FBB2AC0EAEEBCB8582 | |||
| 2080 | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\nonlocalized\res\ua.css | text | |
MD5:E95E78329871E4A902A97641C8B43E25 | SHA256:EB98804CBE3BBB242A301049B0268278CA94BAB7C15AC95AB969B87B3981332B | |||
| 2080 | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\nonlocalized\js3250.dll | executable | |
MD5:4DC1EDC90D78E8E9C7FB4B6EBE2F324C | SHA256:A863A6C1A100ECCE347526CBF179FF8022A4EB6227266E86CB097AE19AB8798B | |||
| 2080 | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\localized\defaults\profile\chrome\userContent-example.css | text | |
MD5:D3765C7D2DE5626529195007F4B7144A | SHA256:10CD5C7D7FB1F6F1123893530099888822C6CB8A4A41584534C2D2EBA38F5BA9 | |||
| 2080 | netscape-9-0-beta-1-netscape-navigator-9.0b1.exe | C:\Users\admin\AppData\Local\Temp\7zSC7.tmp\localized\defaults\profile\chrome\userChrome-example.css | text | |
MD5:4788FDAA51B0A238CB21F5C2877EF06D | SHA256:BBAA6DE3247C9D5C9991F8D14B9022491578E603A6B2E2838E760A87C658A719 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2300 | navigator.exe | GET | 404 | 13.50.184.192:80 | http://browser.netscape.com/firstrun/9.0b1/ | unknown | html | 4.69 Kb | unknown |
2300 | navigator.exe | GET | 301 | 13.49.212.207:80 | http://www.netscape.com/ | unknown | html | 4.31 Kb | unknown |
2300 | navigator.exe | GET | 301 | 13.49.212.207:80 | http://www.netscape.com/api/storystatus-b64/aHR0cDovL2Jyb3dzZXIubmV0c2NhcGUuY29tL2ZpcnN0cnVuLzkuMGIxLw== | unknown | html | 4.39 Kb | unknown |
2300 | navigator.exe | GET | 404 | 13.50.184.192:80 | http://browser.netscape.com/firstrun/%VERSION%/ | unknown | html | 4.70 Kb | unknown |
2300 | navigator.exe | GET | — | 13.49.212.207:80 | http://www.netscape.com/api/sitemail/ | unknown | — | — | unknown |
2300 | navigator.exe | GET | — | 13.49.212.207:80 | http://www.netscape.com/api/feeds/ | unknown | — | — | unknown |
2300 | navigator.exe | GET | 404 | 13.50.184.192:80 | http://browser.netscape.com/favicon.ico | unknown | html | 4.69 Kb | unknown |
2300 | navigator.exe | GET | 404 | 142.250.185.238:80 | http://sb.google.com/safebrowsing/update?client=Navigator&appver=9.0b1&version=goog-white-domain:1:-1,goog-white-url:1:-1,goog-black-url:1:-1,goog-black-enchash:1:-1 | unknown | html | 1.54 Kb | unknown |
2300 | navigator.exe | GET | 301 | 109.234.111.119:80 | http://mjd.yt/ | unknown | — | — | unknown |
2300 | navigator.exe | GET | 404 | 142.250.185.238:80 | http://sb.google.com/safebrowsing/update?client=Navigator&appver=9.0b1&version=goog-white-domain:1:-1,goog-white-url:1:-1,goog-black-url:1:-1,goog-black-enchash:1:-1 | unknown | html | 1.54 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2300 | navigator.exe | 13.50.184.192:80 | browser.netscape.com | AMAZON-02 | SE | unknown |
2300 | navigator.exe | 13.49.212.207:80 | browser.netscape.com | AMAZON-02 | SE | unknown |
2300 | navigator.exe | 212.82.100.163:443 | www.aol.com | Yahoo! UK Services Limited | IE | unknown |
2300 | navigator.exe | 87.248.119.252:443 | s.yimg.com | Yahoo! UK Services Limited | GB | unknown |
2300 | navigator.exe | 188.125.72.139:80 | geo.yahoo.com | Yahoo! UK Services Limited | IE | unknown |
2300 | navigator.exe | 54.74.75.43:80 | bcn.fp.yahoo.com | AMAZON-02 | IE | unknown |
2300 | navigator.exe | 142.250.185.238:80 | sb.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
browser.netscape.com |
| whitelisted |
www.netscape.com |
| unknown |
www.aol.com |
| whitelisted |
s.yimg.com |
| shared |
geo.yahoo.com |
| whitelisted |
bcn.fp.yahoo.com |
| unknown |
sb.google.com |
| whitelisted |
mjd.yt |
| unknown |
youtube.com |
| whitelisted |
www.youtube.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2300 | navigator.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake FireFox Version 2. |
2300 | navigator.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake FireFox Version 2. |
2300 | navigator.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake FireFox Version 2. |
2300 | navigator.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake FireFox Version 2. |
2300 | navigator.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake FireFox Version 2. |
2300 | navigator.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake FireFox Version 2. |
2300 | navigator.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake FireFox Version 2. |