File name:

FishSol-1.9.6-HOTFIX2.zip

Full analysis: https://app.any.run/tasks/1bad43b5-76dc-4035-9335-c1be8ad59d7a
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: April 06, 2026, 11:32:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
ahk
loader
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

23FC33CA126128526BCCE25F3E1EF1B9

SHA1:

A41560B031998622C1633842372CA906A189C236

SHA256:

ED8051497DC23B56A880698387FE54E980C9D63073C9D2D86DEE933E2CCB8163

SSDEEP:

98304:nYKEbwCpduDrNpIckGQzWpTpEck97PWDMe/AU4VZCKzAkh9WD7BlLJh1y2VO3LSf:nmlQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
    • AHK has been detected (YARA)

      • AutoHotkeyU64.exe (PID: 5672)
      • AutoHotkeyU64.exe (PID: 8300)
  • SUSPICIOUS

    • Adds/modifies Windows certificates

      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
    • Application launched itself

      • AutoHotkey_2.0.23_setup.exe (PID: 9008)
      • AutoHotkeyUX.exe (PID: 8932)
      • AutoHotkeyUX.exe (PID: 3048)
    • Executable content was dropped or overwritten

      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
      • AutoHotkeyUX.exe (PID: 9024)
    • Reads the date of Windows installation

      • AutoHotkeyUX.exe (PID: 3048)
    • Checks for external IP

      • AutoHotkeyUX.exe (PID: 8932)
  • INFO

    • Manual execution by a user

      • firefox.exe (PID: 6084)
      • AutoHotkeyUX.exe (PID: 7404)
    • Checks supported languages

      • AutoHotkey_2.0.23_setup.exe (PID: 9008)
      • AutoHotkeyUX.exe (PID: 2792)
      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
      • AutoHotkeyUX.exe (PID: 8932)
      • AutoHotkeyUX.exe (PID: 7404)
      • AutoHotkeyUX.exe (PID: 3048)
      • AutoHotkeyUX.exe (PID: 9024)
      • AutoHotkeyUX.exe (PID: 7844)
      • AutoHotkeyU64.exe (PID: 8300)
      • AutoHotkeyUX.exe (PID: 1772)
      • AutoHotkeyU64.exe (PID: 5672)
    • Application launched itself

      • firefox.exe (PID: 6084)
      • firefox.exe (PID: 7660)
    • Launching a file from the Downloads directory

      • firefox.exe (PID: 7660)
    • AutoHotkey executable

      • firefox.exe (PID: 7660)
      • AutoHotkey_2.0.23_setup.exe (PID: 9008)
      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
      • AutoHotkeyUX.exe (PID: 8932)
      • WinRAR.exe (PID: 7224)
      • AutoHotkeyUX.exe (PID: 3048)
      • AutoHotkeyUX.exe (PID: 7844)
      • AutoHotkeyUX.exe (PID: 1772)
    • Reads the computer name

      • AutoHotkey_2.0.23_setup.exe (PID: 9008)
      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
      • AutoHotkeyUX.exe (PID: 8932)
      • AutoHotkeyUX.exe (PID: 3048)
      • AutoHotkeyUX.exe (PID: 7404)
      • AutoHotkeyUX.exe (PID: 9024)
      • AutoHotkeyU64.exe (PID: 8300)
      • AutoHotkeyU64.exe (PID: 5672)
    • The sample compiled with english language support

      • firefox.exe (PID: 7660)
      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
      • AutoHotkeyUX.exe (PID: 9024)
    • Reads security settings of Internet Explorer

      • AutoHotkey_2.0.23_setup.exe (PID: 9008)
      • WinRAR.exe (PID: 7224)
      • AutoHotkeyUX.exe (PID: 8932)
      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
      • AutoHotkeyUX.exe (PID: 3048)
      • AutoHotkeyUX.exe (PID: 9024)
      • AutoHotkeyU64.exe (PID: 8300)
      • AutoHotkeyU64.exe (PID: 5672)
    • Process checks computer location settings

      • AutoHotkey_2.0.23_setup.exe (PID: 9008)
      • AutoHotkeyUX.exe (PID: 3048)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 7660)
    • Reads the machine GUID from the registry

      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
      • AutoHotkeyUX.exe (PID: 8932)
      • AutoHotkeyU64.exe (PID: 8300)
      • AutoHotkeyUX.exe (PID: 9024)
      • AutoHotkeyU64.exe (PID: 5672)
    • Creates files or folders in the user directory

      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
      • AutoHotkeyUX.exe (PID: 8932)
      • AutoHotkeyU64.exe (PID: 8300)
    • Creates a software uninstall entry

      • AutoHotkey_2.0.23_setup.exe (PID: 9092)
    • Detects AutoHotkey samples (YARA)

      • AutoHotkeyUX.exe (PID: 7404)
      • AutoHotkeyU64.exe (PID: 8300)
      • AutoHotkeyUX.exe (PID: 1772)
      • AutoHotkeyU64.exe (PID: 5672)
      • AutoHotkeyUX.exe (PID: 7844)
    • There is functionality for taking screenshot (YARA)

      • AutoHotkeyUX.exe (PID: 7404)
      • AutoHotkeyU64.exe (PID: 8300)
      • AutoHotkeyUX.exe (PID: 1772)
      • AutoHotkeyUX.exe (PID: 7844)
      • AutoHotkeyU64.exe (PID: 5672)
    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 7224)
    • Create files in a temporary directory

      • AutoHotkeyU64.exe (PID: 5672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0008
ZipCompression: Deflated
ZipModifyDate: 2026:04:02 09:07:44
ZipCRC: 0x0ff54f0b
ZipCompressedSize: 579
ZipUncompressedSize: 2206
ZipFileName: settings.ini
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
168
Monitored processes
25
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs autohotkey_2.0.23_setup.exe no specs autohotkey_2.0.23_setup.exe autohotkeyux.exe no specs autohotkeyux.exe no specs autohotkeyux.exe autohotkeyux.exe no specs autohotkeyux.exe autohotkeyux.exe no specs #AHK autohotkeyu64.exe autohotkeyux.exe no specs #AHK autohotkeyu64.exe

Process information

PID
CMD
Path
Indicators
Parent process
1176"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 2260 -prefsLen 36580 -prefMapHandle 2264 -prefMapSize 273045 -ipcHandle 2212 -initialChannelId {efd72756-f432-4578-b163-5553cdff2698} -parentPid 7660 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7660" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\vcruntime140.dll
1772"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" "C:\Program Files\AutoHotkey\UX\launcher.ahk" "C:\Users\admin\AppData\Local\Temp\Rar$DIa7224.38974\FishSol-1.9.6-HOTFIX2.ahk" C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exeWinRAR.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey 64-bit
Version:
2.0.23
Modules
Images
c:\program files\autohotkey\ux\autohotkeyux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2220"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4884 -prefsLen 39429 -prefMapHandle 4888 -prefMapSize 273045 -jsInitHandle 4892 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4904 -initialChannelId {3251b751-1130-428d-a141-79fc68a8c7b7} -parentPid 7660 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7660" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\msvcp140.dll
2308"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4952 -prefsLen 39429 -prefMapHandle 4948 -prefMapSize 273045 -jsInitHandle 4936 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4908 -initialChannelId {75a01b04-6c15-47a7-8b2c-f6a279f0c0df} -parentPid 7660 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7660" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2724"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4840 -prefsLen 45425 -prefMapHandle 4844 -prefMapSize 273045 -ipcHandle 4776 -initialChannelId {b59bcc4c-5c22-409c-968a-4bcbbf84f924} -parentPid 7660 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7660" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
2792"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" "C:\Program Files\AutoHotkey\UX\reset-assoc.ahk" /checkC:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exeAutoHotkey_2.0.23_setup.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
HIGH
Description:
AutoHotkey 64-bit
Exit code:
0
Version:
2.0.23
Modules
Images
c:\program files\autohotkey\ux\autohotkeyux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
3048"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" /script "C:\Program Files\AutoHotkey\UX\install-version.ahk" "1.1.37.02"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exeAutoHotkeyUX.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey 64-bit
Exit code:
0
Version:
2.0.23
Modules
Images
c:\program files\autohotkey\ux\autohotkeyux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\winmm.dll
3552"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3144 -prefsLen 37299 -prefMapHandle 3152 -prefMapSize 273045 -jsInitHandle 3156 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3168 -initialChannelId {d387abbf-52eb-4b19-a424-aaca7acb8ab7} -parentPid 7660 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7660" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
5672"C:\Program Files\AutoHotkey\v1.1.37.02\AutoHotkeyU64.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa7224.38974\FishSol-1.9.6-HOTFIX2.ahk"C:\Program Files\AutoHotkey\v1.1.37.02\AutoHotkeyU64.exe
AutoHotkeyUX.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 64-bit
Version:
1.1.37.02
Modules
Images
c:\program files\autohotkey\v1.1.37.02\autohotkeyu64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6084"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\bcrypt.dll
Total events
25 287
Read events
25 235
Write events
45
Delete events
7

Modification events

(PID) Process:(7224) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7224) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7224) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(7224) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\FishSol-1.9.6-HOTFIX2.zip
(PID) Process:(7224) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7224) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7224) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7224) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7224) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(7224) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
41
Suspicious files
229
Text files
133
Unknown types
0

Dropped files

PID
Process
Filename
Type
7660firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
7660firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\activity-stream.discovery_stream.jsontext
MD5:021E7F43700F144943706E811705AECC
SHA256:C8E39CB281FF94CC317EDCB1FC528C01B13B69AA3AD4AA428FD50ABE5DC1BA03
7660firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
7660firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:BA5435221D5B4EBD2DAE6E8B3B0AD559
SHA256:6E2643118192563AB74C2ABDEC953215210B208A4EF576AD9AEA3A17FA36D39D
7660firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\activity-stream.contile.jsontext
MD5:9BBE09CF9240FB5D3EFE7EBF1B1ACE58
SHA256:A6A0C47F7FA8F08A31C20AA4412230CBA11BD7604B321BA854C3E8E80337897F
7660firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7660firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7660firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\extensions\trash\addon@example.com.xpicompressed
MD5:8D9AFAC42BC67132A3FFB3520C6B57A7
SHA256:116FDE2E4201D9545542FA9DEBC8054B12BBE874240A48BB5AE848B1BCBC2BA0
7660firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.binbinary
MD5:73A2E89AF4D3D52D0167E7B3805E20E5
SHA256:AB2871B600E4E7A13DF4552B1172DA5EEA32C9BA8E3D2153F1987FE2B124CFC4
7660firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\extensions\addon@example.com.xpicompressed
MD5:1C6752C0C855D40F73C80D9EB2E29989
SHA256:365BE5C9BE5E58BCB2E40006B80D777C59D7BFA22015CA9309A13B7ABBAF58F9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
260
TCP/UDP connections
96
DNS requests
132
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
US
binary
313 b
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
959 b
whitelisted
8140
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
8140
svchost.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
8140
svchost.exe
GET
200
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.74 Kb
whitelisted
7660
firefox.exe
GET
200
151.101.129.91:443
https://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?collection=url-parser-default-unknown-schemes-interventions&bucket=main&_expected=0
US
text
274 b
whitelisted
7660
firefox.exe
GET
200
151.101.129.91:443
https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/url-parser-default-unknown-schemes-interventions/changeset?_expected=1743513175300&_since=%221726769128879%22
US
text
1.76 Kb
whitelisted
7660
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
text
90 b
whitelisted
7660
firefox.exe
GET
101
34.107.243.93:443
https://push.services.mozilla.com/
US
whitelisted
7660
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
8140
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
2.16.204.156:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
162.159.142.9:80
ocsp.digicert.com
CLOUDFLARENET
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5264
slui.exe
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
8140
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 4.231.128.59
  • 51.104.136.2
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
www.bing.com
  • 2.16.204.156
  • 2.16.204.138
  • 2.16.204.153
  • 2.16.204.135
  • 2.16.204.157
  • 2.16.204.146
  • 2.16.204.155
  • 2.16.204.148
  • 2.16.204.141
whitelisted
ocsp.digicert.com
  • 162.159.142.9
  • 172.66.2.5
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 142.251.110.139
  • 142.251.110.113
  • 142.251.110.100
  • 142.251.110.101
  • 142.251.110.138
  • 142.251.110.102
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.59.18.102
  • 23.52.181.212
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.250
whitelisted
firefox.settings.services.mozilla.com
  • 151.101.129.91
  • 151.101.1.91
  • 151.101.65.91
  • 151.101.193.91
whitelisted

Threats

PID
Process
Class
Message
8140
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
7660
firefox.exe
Misc activity
ET INFO EXE - Served Attached HTTP
8932
AutoHotkeyUX.exe
Misc activity
ET INFO Observed UA-CPU Header
9024
AutoHotkeyUX.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (AutoHotkey)
2232
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
8300
AutoHotkeyU64.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (AutoHotkey)
8932
AutoHotkeyUX.exe
Device Retrieving External IP Address Detected
SUSPICIOUS [ANY.RUN] An IP address was received from the server as a result of an HTTP request
No debug info