| File name: | Firefox Installer.exe |
| Full analysis: | https://app.any.run/tasks/a99d9d59-45a4-49c3-aa2c-642c75911168 |
| Verdict: | Malicious activity |
| Analysis date: | December 12, 2024, 20:59:27 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections |
| MD5: | E9A5C9824FC42F6926E45450EFD2E532 |
| SHA1: | 32F4665D49BDE0F3FBB871F313F99285D91772B5 |
| SHA256: | EEC38AEB92C57C36D89CFA7A9E4C145F4FB446CCB74A17F9A5AD91F5DA4AE58E |
| SSDEEP: | 12288:qSvvp2jRWmtab28hO13iuz/T4R+bLZ6t6FllrkHXSQXD7TgtBDZjC:qSHp2jQmAS0O13Dz/kR+bYt6Fllrk3Sa |
| .exe | | | UPX compressed Win32 Executable (64.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.6) |
| .exe | | | Win32 Executable (generic) (10.6) |
| .exe | | | Generic Win/DOS Executable (4.7) |
| .exe | | | DOS Executable Generic (4.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:08:30 22:18:33+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 69632 |
| InitializedDataSize: | 65536 |
| UninitializedDataSize: | 147456 |
| EntryPoint: | 0x34fa0 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 18.5.0.0 |
| ProductVersionNumber: | 18.5.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Mozilla |
| FileDescription: | Firefox |
| FileVersion: | 18.05 |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Mozilla |
| OriginalFileName: | 7zS.sfx.exe |
| ProductName: | Firefox |
| ProductVersion: | 18.05 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1540 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3472 -prefsLen 24916 -prefMapHandle 3476 -prefMapSize 263491 -jsInitHandle 3480 -jsInitLen 234660 -parentBuildID 20241209150345 -ipcHandle 3488 -initialChannelId {02b51de1-c3d8-457c-b4cd-0b66f0bac87e} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 133.0.3 Modules
| |||||||||||||||
| 2076 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6652 -prefsLen 34583 -prefMapHandle 6656 -prefMapSize 263491 -jsInitHandle 6660 -jsInitLen 234660 -parentBuildID 20241209150345 -ipcHandle 3528 -initialChannelId {6e8a71d2-e749-4356-9ce1-86d0dc648dd5} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 11 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 133.0.3 Modules
| |||||||||||||||
| 2152 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20241209150345 -sandboxingKind 1 -prefsHandle 6824 -prefsLen 36717 -prefMapHandle 6852 -prefMapSize 263491 -ipcHandle 7068 -initialChannelId {d6e050c5-d255-4559-a446-e45395bebf9b} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 13 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 133.0.3 | |||||||||||||||
| 2804 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20241209150345 -prefsHandle 2192 -prefsLen 23174 -prefMapHandle 2196 -prefMapSize 263491 -ipcHandle 2160 -initialChannelId {c1dc2ba7-01e8-4a19-97f3-e7c427e13336} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 133.0.3 Modules
| |||||||||||||||
| 3060 | "C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\download.exe" /LaunchedFromStub /INI=C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\config.ini | C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\download.exe | setup-stub.exe | ||||||||||||
User: admin Company: Mozilla Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 18.05 Modules
| |||||||||||||||
| 3612 | "C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe" | C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe | setup.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Mozilla Maintenance Service Installer Exit code: 0 Version: 133.0.3 Modules
| |||||||||||||||
| 3640 | "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe" install | C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe | maintenanceservice_installer.exe | ||||||||||||
User: admin Company: Mozilla Foundation Integrity Level: HIGH Exit code: 0 Version: 133.0.3 Modules
| |||||||||||||||
| 3732 | "C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent register-task 308046B0AF4A39CB | C:\Program Files\Mozilla Firefox\firefox.exe | — | default-browser-agent.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 133.0.3 Modules
| |||||||||||||||
| 3792 | .\setup.exe /LaunchedFromStub /INI=C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\config.ini | C:\Users\admin\AppData\Local\Temp\7zS4FB5B283\setup.exe | download.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Installer Exit code: 0 Version: 133.0.3 Modules
| |||||||||||||||
| 3832 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20241209150345 -prefsHandle 1860 -prefsLen 23174 -prefMapHandle 1864 -prefMapSize 263491 -ipcHandle 1924 -initialChannelId {f993f01e-be9e-4e72-858d-5da84b12fb9a} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 133.0.3 Modules
| |||||||||||||||
| (PID) Process: | (6424) setup-stub.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox |
Value: 308046B0AF4A39CB | |||
| (PID) Process: | (6424) setup-stub.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6424) setup-stub.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6424) setup-stub.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6424) setup-stub.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFavoritesInitialSelection |
Value: | |||
| (PID) Process: | (6424) setup-stub.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFeedsInitialSelection |
Value: | |||
| (PID) Process: | (3792) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox |
Value: 308046B0AF4A39CB | |||
| (PID) Process: | (5576) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\InProcServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (3792) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB |
| Operation: | write | Name: | FriendlyTypeName |
Value: Firefox HTML Document | |||
| (PID) Process: | (3792) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\shell\open\ddeexec |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6220 | Firefox Installer.exe | C:\Users\admin\AppData\Local\Temp\7zSC4836733\setup-stub.exe | executable | |
MD5:BA47AB922394C48413752A9EDDE809DF | SHA256:2E7B17A429734D791C29B4CCA7355FD0076BBA9DC03D4F6F9E28B2F1CFD4CE14 | |||
| 6264 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsb5A88.tmp\System.dll | executable | |
MD5:B361682FA5E6A1906E754CFA08AA8D90 | SHA256:B711C4F17690421C9DC8DDB9ED5A9DDC539B3A28F11E19C851E25DCFC7701C04 | |||
| 6424 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\installing_page.css | text | |
MD5:6582E207592B60A995B4510CF959EB03 | SHA256:43C38801C1746880625F97EEE3FE37FE94D1300ADF812BFE26E47B094B87523B | |||
| 6264 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsb5A88.tmp\UAC.dll | executable | |
MD5:D23B256E9C12FE37D984BAE5017C5F8C | SHA256:EC6A56D981892BF251DF1439BEA425A5F6C7E1C7312D44BEDD5E2957F270338C | |||
| 6424 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\UAC.dll | executable | |
MD5:D23B256E9C12FE37D984BAE5017C5F8C | SHA256:EC6A56D981892BF251DF1439BEA425A5F6C7E1C7312D44BEDD5E2957F270338C | |||
| 6424 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\UserInfo.dll | executable | |
MD5:610AD03DEC634768CD91C7ED79672D67 | SHA256:C6C413108539F141BEA3F679E0E2EF705898C51EC7C2607F478A865FC5E2E2DF | |||
| 6424 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\stub_common.css | text | |
MD5:544B51F11AD19DF720669478D28F129D | SHA256:4D9495B6F0E18331659993B79440E414A6E607FCDAEACBC7477E0683CC0FA98B | |||
| 6424 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\CityHash.dll | executable | |
MD5:2021ACC65FA998DAA98131E20C4605BE | SHA256:C299A0A71BF57EB241868158B4FCFE839D15D5BA607E1BDC5499FDF67B334A14 | |||
| 6424 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\installing.html | html | |
MD5:167904D9F340244FBB3A303F50E7DD04 | SHA256:4D1F52B24E1E460E3B2AEF617B3A68B4AAD062C016CB5D6FBD9660813F3FCA91 | |||
| 6424 | setup-stub.exe | C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\download.exe | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6424 | setup-stub.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAMS6Jl19zCc5X6GAIL92CA%3D | unknown | — | — | whitelisted |
6424 | setup-stub.exe | GET | 200 | 23.53.40.154:80 | http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgO%2BA6ENR5cTe4xwD%2FhhTCYdJQ%3D%3D | unknown | — | — | whitelisted |
6424 | setup-stub.exe | GET | 200 | 18.66.145.213:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D | unknown | — | — | unknown |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6424 | setup-stub.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAc3sNDc3KuNeNL0DLEi%2BT8%3D | unknown | — | — | whitelisted |
3092 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6424 | setup-stub.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAo1CNVcKSsBffitZcAP9%2BQ%3D | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.147:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
716 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3296 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5064 | SearchApp.exe | 104.126.37.145:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1076 | svchost.exe | 23.213.166.81:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
6424 | setup-stub.exe | 108.138.26.56:443 | product-details.mozilla.org | AMAZON-02 | US | shared |
6424 | setup-stub.exe | 18.66.145.213:80 | ocsp.rootca1.amazontrust.com | AMAZON-02 | US | shared |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
product-details.mozilla.org |
| shared |
ocsp.rootca1.amazontrust.com |
| shared |
login.live.com |
| whitelisted |
download.mozilla.org |
| whitelisted |
download-installer.cdn.mozilla.net |
| whitelisted |