File name:

Firefox Installer.exe

Full analysis: https://app.any.run/tasks/a99d9d59-45a4-49c3-aa2c-642c75911168
Verdict: Malicious activity
Analysis date: December 12, 2024, 20:59:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

E9A5C9824FC42F6926E45450EFD2E532

SHA1:

32F4665D49BDE0F3FBB871F313F99285D91772B5

SHA256:

EEC38AEB92C57C36D89CFA7A9E4C145F4FB446CCB74A17F9A5AD91F5DA4AE58E

SSDEEP:

12288:qSvvp2jRWmtab28hO13iuz/T4R+bLZ6t6FllrkHXSQXD7TgtBDZjC:qSHp2jQmAS0O13Dz/kR+bYt6Fllrk3Sa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.exe (PID: 3792)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Firefox Installer.exe (PID: 6220)
      • setup-stub.exe (PID: 6264)
      • setup-stub.exe (PID: 6424)
      • download.exe (PID: 3060)
      • setup.exe (PID: 3792)
      • maintenanceservice_installer.exe (PID: 3612)
      • maintenanceservice_tmp.exe (PID: 3640)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • setup-stub.exe (PID: 6264)
      • setup-stub.exe (PID: 6424)
      • setup.exe (PID: 3792)
      • maintenanceservice_installer.exe (PID: 3612)
    • Reads security settings of Internet Explorer

      • setup-stub.exe (PID: 6264)
      • setup-stub.exe (PID: 6424)
      • maintenanceservice_installer.exe (PID: 3612)
    • Application launched itself

      • setup-stub.exe (PID: 6264)
    • Reads Internet Explorer settings

      • setup-stub.exe (PID: 6424)
    • Process drops legitimate windows executable

      • download.exe (PID: 3060)
      • setup.exe (PID: 3792)
    • Checks Windows Trust Settings

      • setup-stub.exe (PID: 6424)
    • The process drops Mozilla's DLL files

      • download.exe (PID: 3060)
      • setup.exe (PID: 3792)
    • The process drops C-runtime libraries

      • download.exe (PID: 3060)
      • setup.exe (PID: 3792)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 5576)
    • Loads DLL from Mozilla Firefox

      • regsvr32.exe (PID: 5576)
      • default-browser-agent.exe (PID: 5036)
    • Searches for installed software

      • setup.exe (PID: 3792)
    • Creates a software uninstall entry

      • setup.exe (PID: 3792)
    • The process creates files with name similar to system file names

      • maintenanceservice_installer.exe (PID: 3612)
  • INFO

    • The sample compiled with english language support

      • Firefox Installer.exe (PID: 6220)
      • download.exe (PID: 3060)
      • setup.exe (PID: 3792)
      • maintenanceservice_installer.exe (PID: 3612)
      • firefox.exe (PID: 7060)
    • Checks supported languages

      • Firefox Installer.exe (PID: 6220)
      • setup-stub.exe (PID: 6424)
      • setup-stub.exe (PID: 6264)
      • setup.exe (PID: 3792)
      • maintenanceservice_installer.exe (PID: 3612)
      • maintenanceservice_tmp.exe (PID: 3640)
    • Reads the computer name

      • Firefox Installer.exe (PID: 6220)
      • setup-stub.exe (PID: 6264)
      • setup-stub.exe (PID: 6424)
      • setup.exe (PID: 3792)
      • maintenanceservice_installer.exe (PID: 3612)
      • maintenanceservice_tmp.exe (PID: 3640)
    • Create files in a temporary directory

      • Firefox Installer.exe (PID: 6220)
      • download.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 3612)
      • setup.exe (PID: 3792)
      • setup-stub.exe (PID: 6424)
    • Process checks computer location settings

      • setup-stub.exe (PID: 6264)
    • Process checks whether UAC notifications are on

      • setup-stub.exe (PID: 6264)
    • Checks proxy server information

      • setup-stub.exe (PID: 6424)
    • The process uses the downloaded file

      • setup-stub.exe (PID: 6424)
    • Reads the software policy settings

      • setup-stub.exe (PID: 6424)
    • Creates files or folders in the user directory

      • setup-stub.exe (PID: 6424)
    • Creates files in the program directory

      • setup.exe (PID: 3792)
      • maintenanceservice_installer.exe (PID: 3612)
      • setup-stub.exe (PID: 6424)
    • Reads the machine GUID from the registry

      • setup-stub.exe (PID: 6424)
      • setup.exe (PID: 3792)
    • Application launched itself

      • firefox.exe (PID: 4708)
      • firefox.exe (PID: 7060)
      • firefox.exe (PID: 3732)
      • firefox.exe (PID: 6548)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 7060)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 7060)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (64.2)
.dll | Win32 Dynamic Link Library (generic) (15.6)
.exe | Win32 Executable (generic) (10.6)
.exe | Generic Win/DOS Executable (4.7)
.exe | DOS Executable Generic (4.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:08:30 22:18:33+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 69632
InitializedDataSize: 65536
UninitializedDataSize: 147456
EntryPoint: 0x34fa0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 18.5.0.0
ProductVersionNumber: 18.5.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Mozilla
FileDescription: Firefox
FileVersion: 18.05
InternalName: 7zS.sfx
LegalCopyright: Mozilla
OriginalFileName: 7zS.sfx.exe
ProductName: Firefox
ProductVersion: 18.05
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
158
Monitored processes
28
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start firefox installer.exe setup-stub.exe setup-stub.exe download.exe setup.exe regsvr32.exe no specs maintenanceservice_installer.exe maintenanceservice_tmp.exe default-browser-agent.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1540"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3472 -prefsLen 24916 -prefMapHandle 3476 -prefMapSize 263491 -jsInitHandle 3480 -jsInitLen 234660 -parentBuildID 20241209150345 -ipcHandle 3488 -initialChannelId {02b51de1-c3d8-457c-b4cd-0b66f0bac87e} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
2076"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6652 -prefsLen 34583 -prefMapHandle 6656 -prefMapSize 263491 -jsInitHandle 6660 -jsInitLen 234660 -parentBuildID 20241209150345 -ipcHandle 3528 -initialChannelId {6e8a71d2-e749-4356-9ce1-86d0dc648dd5} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 11 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
2152"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20241209150345 -sandboxingKind 1 -prefsHandle 6824 -prefsLen 36717 -prefMapHandle 6852 -prefMapSize 263491 -ipcHandle 7068 -initialChannelId {d6e050c5-d255-4559-a446-e45395bebf9b} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 13 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
133.0.3
2804"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20241209150345 -prefsHandle 2192 -prefsLen 23174 -prefMapHandle 2196 -prefMapSize 263491 -ipcHandle 2160 -initialChannelId {c1dc2ba7-01e8-4a19-97f3-e7c427e13336} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
3060"C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\download.exe" /LaunchedFromStub /INI=C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\config.iniC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\download.exe
setup-stub.exe
User:
admin
Company:
Mozilla
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
18.05
Modules
Images
c:\users\admin\appdata\local\temp\nsn5fa8.tmp\download.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3612"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe
setup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Mozilla Maintenance Service Installer
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\maintenanceservice_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3640"C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe" installC:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe
maintenanceservice_installer.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
HIGH
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files (x86)\mozilla maintenance service\maintenanceservice_tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3732"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent register-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exedefault-browser-agent.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
3792.\setup.exe /LaunchedFromStub /INI=C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\config.iniC:\Users\admin\AppData\Local\Temp\7zS4FB5B283\setup.exe
download.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox Installer
Exit code:
0
Version:
133.0.3
Modules
Images
c:\users\admin\appdata\local\temp\7zs4fb5b283\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
3832"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20241209150345 -prefsHandle 1860 -prefsLen 23174 -prefMapHandle 1864 -prefMapSize 263491 -ipcHandle 1924 -initialChannelId {f993f01e-be9e-4e72-858d-5da84b12fb9a} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
Total events
20 692
Read events
20 596
Write events
66
Delete events
30

Modification events

(PID) Process:(6424) setup-stub.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs
Operation:writeName:C:\Program Files\Mozilla Firefox
Value:
308046B0AF4A39CB
(PID) Process:(6424) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6424) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6424) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6424) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(6424) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
(PID) Process:(3792) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs
Operation:writeName:C:\Program Files\Mozilla Firefox
Value:
308046B0AF4A39CB
(PID) Process:(5576) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(3792) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB
Operation:writeName:FriendlyTypeName
Value:
Firefox HTML Document
(PID) Process:(3792) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\shell\open\ddeexec
Operation:delete keyName:(default)
Value:
Executable files
94
Suspicious files
297
Text files
144
Unknown types
10

Dropped files

PID
Process
Filename
Type
6220Firefox Installer.exeC:\Users\admin\AppData\Local\Temp\7zSC4836733\setup-stub.exeexecutable
MD5:BA47AB922394C48413752A9EDDE809DF
SHA256:2E7B17A429734D791C29B4CCA7355FD0076BBA9DC03D4F6F9E28B2F1CFD4CE14
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\profile_cleanup_page.csstext
MD5:A19F25578E4C90A1EBDBB65F05848C2A
SHA256:AF2642060A29B6402F9AA8DBE691F685EFE2B592B17520B1DA36A559547DC944
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\bgstub.jpgimage
MD5:C55F15CEEDC724D6C6E15D1DAF96B698
SHA256:4B7E441D51B790EE1C0BAFF19E4E968392A937877DFA8B84E74464F5BA7A4CF4
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\InetBgDL.dllexecutable
MD5:AF9E2D138CF17B8FF4D4B8DF7FDDAEFA
SHA256:3921DEC014FADD1DE7F3A36606AC95882A17CB96DF38A5424E58531A169F825B
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\stub_common.jstext
MD5:EFCE3DCE0165B3F6551DB47E5C0AC8D6
SHA256:DAB39CBAE31848CCE0B5C43FDDD2674FEF4DEA5B7A3DACDAABDC78A8A931817E
6264setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsb5A88.tmp\UAC.dllexecutable
MD5:D23B256E9C12FE37D984BAE5017C5F8C
SHA256:EC6A56D981892BF251DF1439BEA425A5F6C7E1C7312D44BEDD5E2957F270338C
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\profile_cleanup.jstext
MD5:D845E8F4C0EDB3CAB17E6A30090AC5B8
SHA256:1ADCFDD9768242C6C639B10E4F0BCDA24F6A957A169C1DEDE265E40336ECBD4F
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\profile_cleanup.htmlhtml
MD5:1CB97B5F8C5F2728B26742D1D0669899
SHA256:DEC82E9CAA154300E1AA44F550C16B455A2025BE4FB1C3155CB75FE04A6B6611
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\System.dllexecutable
MD5:B361682FA5E6A1906E754CFA08AA8D90
SHA256:B711C4F17690421C9DC8DDB9ED5A9DDC539B3A28F11E19C851E25DCFC7701C04
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\download.exe
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
50
TCP/UDP connections
98
DNS requests
112
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6424
setup-stub.exe
GET
200
18.66.145.213:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
unknown
unknown
6424
setup-stub.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAo1CNVcKSsBffitZcAP9%2BQ%3D
unknown
whitelisted
6424
setup-stub.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAMS6Jl19zCc5X6GAIL92CA%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6424
setup-stub.exe
GET
200
23.53.40.154:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgO%2BA6ENR5cTe4xwD%2FhhTCYdJQ%3D%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.147:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6424
setup-stub.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAEkCvseOAuKFvFLcZ3008A%3D
unknown
whitelisted
3092
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
3092
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
716
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3296
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
104.126.37.145:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
6424
setup-stub.exe
108.138.26.56:443
product-details.mozilla.org
AMAZON-02
US
shared
6424
setup-stub.exe
18.66.145.213:80
ocsp.rootca1.amazontrust.com
AMAZON-02
US
shared

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 216.58.206.78
whitelisted
www.bing.com
  • 104.126.37.145
  • 104.126.37.137
  • 104.126.37.185
  • 104.126.37.123
  • 104.126.37.131
  • 104.126.37.162
  • 104.126.37.139
  • 104.126.37.170
  • 104.126.37.146
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
product-details.mozilla.org
  • 108.138.26.56
  • 108.138.26.53
  • 108.138.26.105
  • 108.138.26.118
shared
ocsp.rootca1.amazontrust.com
  • 18.66.145.213
shared
login.live.com
  • 40.126.31.71
  • 20.190.159.71
  • 40.126.31.69
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.23
whitelisted
download.mozilla.org
  • 107.23.187.47
  • 3.213.198.252
  • 3.210.232.56
whitelisted
download-installer.cdn.mozilla.net
  • 34.117.35.28
whitelisted

Threats

No threats detected
No debug info