File name:

Firefox Installer.exe

Full analysis: https://app.any.run/tasks/a99d9d59-45a4-49c3-aa2c-642c75911168
Verdict: Malicious activity
Analysis date: December 12, 2024, 20:59:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

E9A5C9824FC42F6926E45450EFD2E532

SHA1:

32F4665D49BDE0F3FBB871F313F99285D91772B5

SHA256:

EEC38AEB92C57C36D89CFA7A9E4C145F4FB446CCB74A17F9A5AD91F5DA4AE58E

SSDEEP:

12288:qSvvp2jRWmtab28hO13iuz/T4R+bLZ6t6FllrkHXSQXD7TgtBDZjC:qSHp2jQmAS0O13Dz/kR+bYt6Fllrk3Sa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.exe (PID: 3792)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Firefox Installer.exe (PID: 6220)
      • setup-stub.exe (PID: 6264)
      • setup-stub.exe (PID: 6424)
      • setup.exe (PID: 3792)
      • download.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 3612)
      • maintenanceservice_tmp.exe (PID: 3640)
    • Application launched itself

      • setup-stub.exe (PID: 6264)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • setup-stub.exe (PID: 6264)
      • setup-stub.exe (PID: 6424)
      • setup.exe (PID: 3792)
      • maintenanceservice_installer.exe (PID: 3612)
    • Reads security settings of Internet Explorer

      • setup-stub.exe (PID: 6424)
      • setup-stub.exe (PID: 6264)
      • maintenanceservice_installer.exe (PID: 3612)
    • Reads Internet Explorer settings

      • setup-stub.exe (PID: 6424)
    • Process drops legitimate windows executable

      • download.exe (PID: 3060)
      • setup.exe (PID: 3792)
    • Checks Windows Trust Settings

      • setup-stub.exe (PID: 6424)
    • The process drops Mozilla's DLL files

      • setup.exe (PID: 3792)
      • download.exe (PID: 3060)
    • The process drops C-runtime libraries

      • download.exe (PID: 3060)
      • setup.exe (PID: 3792)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 5576)
    • Loads DLL from Mozilla Firefox

      • regsvr32.exe (PID: 5576)
      • default-browser-agent.exe (PID: 5036)
    • Searches for installed software

      • setup.exe (PID: 3792)
    • Creates a software uninstall entry

      • setup.exe (PID: 3792)
    • The process creates files with name similar to system file names

      • maintenanceservice_installer.exe (PID: 3612)
  • INFO

    • The sample compiled with english language support

      • Firefox Installer.exe (PID: 6220)
      • download.exe (PID: 3060)
      • setup.exe (PID: 3792)
      • maintenanceservice_installer.exe (PID: 3612)
      • firefox.exe (PID: 7060)
    • Create files in a temporary directory

      • Firefox Installer.exe (PID: 6220)
      • setup-stub.exe (PID: 6424)
      • download.exe (PID: 3060)
      • maintenanceservice_installer.exe (PID: 3612)
      • setup.exe (PID: 3792)
    • Reads the computer name

      • setup-stub.exe (PID: 6264)
      • Firefox Installer.exe (PID: 6220)
      • setup-stub.exe (PID: 6424)
      • setup.exe (PID: 3792)
      • maintenanceservice_tmp.exe (PID: 3640)
      • maintenanceservice_installer.exe (PID: 3612)
    • Checks supported languages

      • Firefox Installer.exe (PID: 6220)
      • setup-stub.exe (PID: 6264)
      • setup-stub.exe (PID: 6424)
      • setup.exe (PID: 3792)
      • maintenanceservice_installer.exe (PID: 3612)
      • maintenanceservice_tmp.exe (PID: 3640)
    • Process checks computer location settings

      • setup-stub.exe (PID: 6264)
    • Checks proxy server information

      • setup-stub.exe (PID: 6424)
    • Process checks whether UAC notifications are on

      • setup-stub.exe (PID: 6264)
    • Reads the machine GUID from the registry

      • setup-stub.exe (PID: 6424)
      • setup.exe (PID: 3792)
    • Creates files or folders in the user directory

      • setup-stub.exe (PID: 6424)
    • The process uses the downloaded file

      • setup-stub.exe (PID: 6424)
    • Reads the software policy settings

      • setup-stub.exe (PID: 6424)
    • Creates files in the program directory

      • setup.exe (PID: 3792)
      • maintenanceservice_installer.exe (PID: 3612)
      • setup-stub.exe (PID: 6424)
    • Application launched itself

      • firefox.exe (PID: 6548)
      • firefox.exe (PID: 3732)
      • firefox.exe (PID: 7060)
      • firefox.exe (PID: 4708)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 7060)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 7060)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (64.2)
.dll | Win32 Dynamic Link Library (generic) (15.6)
.exe | Win32 Executable (generic) (10.6)
.exe | Generic Win/DOS Executable (4.7)
.exe | DOS Executable Generic (4.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:08:30 22:18:33+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 69632
InitializedDataSize: 65536
UninitializedDataSize: 147456
EntryPoint: 0x34fa0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 18.5.0.0
ProductVersionNumber: 18.5.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Mozilla
FileDescription: Firefox
FileVersion: 18.05
InternalName: 7zS.sfx
LegalCopyright: Mozilla
OriginalFileName: 7zS.sfx.exe
ProductName: Firefox
ProductVersion: 18.05
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
158
Monitored processes
28
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start firefox installer.exe setup-stub.exe setup-stub.exe download.exe setup.exe regsvr32.exe no specs maintenanceservice_installer.exe maintenanceservice_tmp.exe default-browser-agent.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1540"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3472 -prefsLen 24916 -prefMapHandle 3476 -prefMapSize 263491 -jsInitHandle 3480 -jsInitLen 234660 -parentBuildID 20241209150345 -ipcHandle 3488 -initialChannelId {02b51de1-c3d8-457c-b4cd-0b66f0bac87e} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
2076"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6652 -prefsLen 34583 -prefMapHandle 6656 -prefMapSize 263491 -jsInitHandle 6660 -jsInitLen 234660 -parentBuildID 20241209150345 -ipcHandle 3528 -initialChannelId {6e8a71d2-e749-4356-9ce1-86d0dc648dd5} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 11 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
2152"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20241209150345 -sandboxingKind 1 -prefsHandle 6824 -prefsLen 36717 -prefMapHandle 6852 -prefMapSize 263491 -ipcHandle 7068 -initialChannelId {d6e050c5-d255-4559-a446-e45395bebf9b} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 13 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
133.0.3
2804"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20241209150345 -prefsHandle 2192 -prefsLen 23174 -prefMapHandle 2196 -prefMapSize 263491 -ipcHandle 2160 -initialChannelId {c1dc2ba7-01e8-4a19-97f3-e7c427e13336} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 2 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
3060"C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\download.exe" /LaunchedFromStub /INI=C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\config.iniC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\download.exe
setup-stub.exe
User:
admin
Company:
Mozilla
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
18.05
Modules
Images
c:\users\admin\appdata\local\temp\nsn5fa8.tmp\download.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3612"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe
setup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Mozilla Maintenance Service Installer
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\maintenanceservice_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3640"C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe" installC:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe
maintenanceservice_installer.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
HIGH
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files (x86)\mozilla maintenance service\maintenanceservice_tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3732"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent register-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exedefault-browser-agent.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
3792.\setup.exe /LaunchedFromStub /INI=C:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\config.iniC:\Users\admin\AppData\Local\Temp\7zS4FB5B283\setup.exe
download.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox Installer
Exit code:
0
Version:
133.0.3
Modules
Images
c:\users\admin\appdata\local\temp\7zs4fb5b283\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
3832"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20241209150345 -prefsHandle 1860 -prefsLen 23174 -prefMapHandle 1864 -prefMapSize 263491 -ipcHandle 1924 -initialChannelId {f993f01e-be9e-4e72-858d-5da84b12fb9a} -parentPid 7060 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7060" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
133.0.3
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
Total events
20 692
Read events
20 596
Write events
66
Delete events
30

Modification events

(PID) Process:(6424) setup-stub.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs
Operation:writeName:C:\Program Files\Mozilla Firefox
Value:
308046B0AF4A39CB
(PID) Process:(6424) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6424) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6424) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6424) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(6424) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
(PID) Process:(3792) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs
Operation:writeName:C:\Program Files\Mozilla Firefox
Value:
308046B0AF4A39CB
(PID) Process:(5576) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(3792) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB
Operation:writeName:FriendlyTypeName
Value:
Firefox HTML Document
(PID) Process:(3792) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FirefoxHTML-308046B0AF4A39CB\shell\open\ddeexec
Operation:delete keyName:(default)
Value:
Executable files
94
Suspicious files
297
Text files
144
Unknown types
10

Dropped files

PID
Process
Filename
Type
6220Firefox Installer.exeC:\Users\admin\AppData\Local\Temp\7zSC4836733\setup-stub.exeexecutable
MD5:BA47AB922394C48413752A9EDDE809DF
SHA256:2E7B17A429734D791C29B4CCA7355FD0076BBA9DC03D4F6F9E28B2F1CFD4CE14
6264setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsb5A88.tmp\System.dllexecutable
MD5:B361682FA5E6A1906E754CFA08AA8D90
SHA256:B711C4F17690421C9DC8DDB9ED5A9DDC539B3A28F11E19C851E25DCFC7701C04
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\installing_page.csstext
MD5:6582E207592B60A995B4510CF959EB03
SHA256:43C38801C1746880625F97EEE3FE37FE94D1300ADF812BFE26E47B094B87523B
6264setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsb5A88.tmp\UAC.dllexecutable
MD5:D23B256E9C12FE37D984BAE5017C5F8C
SHA256:EC6A56D981892BF251DF1439BEA425A5F6C7E1C7312D44BEDD5E2957F270338C
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\UAC.dllexecutable
MD5:D23B256E9C12FE37D984BAE5017C5F8C
SHA256:EC6A56D981892BF251DF1439BEA425A5F6C7E1C7312D44BEDD5E2957F270338C
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\UserInfo.dllexecutable
MD5:610AD03DEC634768CD91C7ED79672D67
SHA256:C6C413108539F141BEA3F679E0E2EF705898C51EC7C2607F478A865FC5E2E2DF
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\stub_common.csstext
MD5:544B51F11AD19DF720669478D28F129D
SHA256:4D9495B6F0E18331659993B79440E414A6E607FCDAEACBC7477E0683CC0FA98B
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\CityHash.dllexecutable
MD5:2021ACC65FA998DAA98131E20C4605BE
SHA256:C299A0A71BF57EB241868158B4FCFE839D15D5BA607E1BDC5499FDF67B334A14
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\installing.htmlhtml
MD5:167904D9F340244FBB3A303F50E7DD04
SHA256:4D1F52B24E1E460E3B2AEF617B3A68B4AAD062C016CB5D6FBD9660813F3FCA91
6424setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsn5FA8.tmp\download.exe
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
50
TCP/UDP connections
98
DNS requests
112
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6424
setup-stub.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAMS6Jl19zCc5X6GAIL92CA%3D
unknown
whitelisted
6424
setup-stub.exe
GET
200
23.53.40.154:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgO%2BA6ENR5cTe4xwD%2FhhTCYdJQ%3D%3D
unknown
whitelisted
6424
setup-stub.exe
GET
200
18.66.145.213:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
unknown
unknown
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6424
setup-stub.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAc3sNDc3KuNeNL0DLEi%2BT8%3D
unknown
whitelisted
3092
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6424
setup-stub.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAo1CNVcKSsBffitZcAP9%2BQ%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.147:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
716
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3296
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
104.126.37.145:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
6424
setup-stub.exe
108.138.26.56:443
product-details.mozilla.org
AMAZON-02
US
shared
6424
setup-stub.exe
18.66.145.213:80
ocsp.rootca1.amazontrust.com
AMAZON-02
US
shared

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 216.58.206.78
whitelisted
www.bing.com
  • 104.126.37.145
  • 104.126.37.137
  • 104.126.37.185
  • 104.126.37.123
  • 104.126.37.131
  • 104.126.37.162
  • 104.126.37.139
  • 104.126.37.170
  • 104.126.37.146
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
product-details.mozilla.org
  • 108.138.26.56
  • 108.138.26.53
  • 108.138.26.105
  • 108.138.26.118
shared
ocsp.rootca1.amazontrust.com
  • 18.66.145.213
shared
login.live.com
  • 40.126.31.71
  • 20.190.159.71
  • 40.126.31.69
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.23
whitelisted
download.mozilla.org
  • 107.23.187.47
  • 3.213.198.252
  • 3.210.232.56
whitelisted
download-installer.cdn.mozilla.net
  • 34.117.35.28
whitelisted

Threats

No threats detected
No debug info