File name:

Firefox Installer.exe

Full analysis: https://app.any.run/tasks/96259ca1-9553-4241-9b46-4b8149e04776
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: August 15, 2024, 16:54:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

F86D2027E0E347DEE0B7962C46659B3D

SHA1:

D4ACC39D628F86BB6267ABD6ED02DD66A733FE32

SHA256:

FDC794F0D5A8FC07FC3FC78750D4D0006B2A221150547C634131BEF3DC7C5CA0

SSDEEP:

12288:eSvvp2jRWmtab28hVkzqP0Pu4GtflXCQ2Zp3NgYmp:eSHp2jQmAS0VkWP0PFGJlSQ2f3NgYmp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • setup-stub.exe (PID: 7088)
    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.exe (PID: 6544)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • Firefox Installer.exe (PID: 6836)
      • setup-stub.exe (PID: 6880)
      • setup-stub.exe (PID: 7088)
      • download.exe (PID: 6580)
      • setup.exe (PID: 6544)
      • maintenanceservice_installer.exe (PID: 5112)
      • maintenanceservice_tmp.exe (PID: 4236)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • setup-stub.exe (PID: 6880)
      • setup-stub.exe (PID: 7088)
      • setup.exe (PID: 6544)
      • maintenanceservice_installer.exe (PID: 5112)
    • Executable content was dropped or overwritten

      • Firefox Installer.exe (PID: 6836)
      • setup-stub.exe (PID: 6880)
      • setup-stub.exe (PID: 7088)
      • setup.exe (PID: 6544)
      • download.exe (PID: 6580)
      • maintenanceservice_installer.exe (PID: 5112)
      • maintenanceservice_tmp.exe (PID: 4236)
    • The process creates files with name similar to system file names

      • setup-stub.exe (PID: 6880)
      • setup-stub.exe (PID: 7088)
      • setup.exe (PID: 6544)
      • maintenanceservice_installer.exe (PID: 5112)
    • Reads security settings of Internet Explorer

      • setup-stub.exe (PID: 6880)
      • setup.exe (PID: 6544)
      • maintenanceservice_installer.exe (PID: 5112)
      • setup-stub.exe (PID: 7088)
    • Reads the date of Windows installation

      • setup-stub.exe (PID: 6880)
    • Application launched itself

      • setup-stub.exe (PID: 6880)
    • Reads Microsoft Outlook installation path

      • setup-stub.exe (PID: 7088)
    • Reads Internet Explorer settings

      • setup-stub.exe (PID: 7088)
    • Process drops legitimate windows executable

      • download.exe (PID: 6580)
      • setup.exe (PID: 6544)
    • The process drops Mozilla's DLL files

      • download.exe (PID: 6580)
      • setup.exe (PID: 6544)
    • The process drops C-runtime libraries

      • download.exe (PID: 6580)
      • setup.exe (PID: 6544)
    • Checks Windows Trust Settings

      • setup-stub.exe (PID: 7088)
    • Loads DLL from Mozilla Firefox

      • regsvr32.exe (PID: 6824)
      • default-browser-agent.exe (PID: 1060)
    • Creates a software uninstall entry

      • setup.exe (PID: 6544)
      • maintenanceservice_installer.exe (PID: 5112)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 6824)
    • Searches for installed software

      • setup.exe (PID: 6544)
  • INFO

    • Reads the computer name

      • Firefox Installer.exe (PID: 6836)
      • setup-stub.exe (PID: 6880)
      • setup-stub.exe (PID: 7088)
      • setup.exe (PID: 6544)
      • maintenanceservice_installer.exe (PID: 5112)
      • maintenanceservice_tmp.exe (PID: 4236)
    • Checks supported languages

      • Firefox Installer.exe (PID: 6836)
      • setup-stub.exe (PID: 6880)
      • setup-stub.exe (PID: 7088)
      • download.exe (PID: 6580)
      • setup.exe (PID: 6544)
      • maintenanceservice_installer.exe (PID: 5112)
      • default-browser-agent.exe (PID: 1060)
      • maintenanceservice_tmp.exe (PID: 4236)
    • Create files in a temporary directory

      • Firefox Installer.exe (PID: 6836)
      • setup-stub.exe (PID: 6880)
      • setup-stub.exe (PID: 7088)
      • setup.exe (PID: 6544)
      • download.exe (PID: 6580)
      • maintenanceservice_installer.exe (PID: 5112)
    • Process checks whether UAC notifications are on

      • setup-stub.exe (PID: 6880)
    • Process checks computer location settings

      • setup-stub.exe (PID: 6880)
    • Reads the machine GUID from the registry

      • setup-stub.exe (PID: 7088)
      • setup.exe (PID: 6544)
    • Creates files in the program directory

      • setup-stub.exe (PID: 7088)
      • setup.exe (PID: 6544)
      • maintenanceservice_installer.exe (PID: 5112)
    • Creates files or folders in the user directory

      • setup-stub.exe (PID: 7088)
    • Reads the software policy settings

      • setup-stub.exe (PID: 7088)
    • Process checks Internet Explorer phishing filters

      • setup-stub.exe (PID: 7088)
    • Checks proxy server information

      • setup-stub.exe (PID: 7088)
    • UPX packer has been detected

      • Firefox Installer.exe (PID: 6836)
      • download.exe (PID: 6580)
    • Application launched itself

      • firefox.exe (PID: 6016)
      • firefox.exe (PID: 4020)
      • firefox.exe (PID: 6240)
      • firefox.exe (PID: 7148)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 7148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (64.2)
.dll | Win32 Dynamic Link Library (generic) (15.6)
.exe | Win32 Executable (generic) (10.6)
.exe | Generic Win/DOS Executable (4.7)
.exe | DOS Executable Generic (4.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:08:30 22:18:33+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 69632
InitializedDataSize: 65536
UninitializedDataSize: 147456
EntryPoint: 0x34fa0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 18.5.0.0
ProductVersionNumber: 18.5.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Mozilla
FileDescription: Firefox
FileVersion: 18.05
InternalName: 7zS.sfx
LegalCopyright: Mozilla
OriginalFileName: 7zS.sfx.exe
ProductName: Firefox
ProductVersion: 18.05
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
17
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT firefox installer.exe setup-stub.exe setup-stub.exe THREAT download.exe setup.exe regsvr32.exe no specs maintenanceservice_installer.exe maintenanceservice_tmp.exe default-browser-agent.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1060"C:\Program Files\Mozilla Firefox\default-browser-agent.exe" register-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\default-browser-agent.exesetup.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
HIGH
Exit code:
0
Version:
129.0.1
Modules
Images
c:\program files\mozilla firefox\default-browser-agent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1164"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1336 -parentBuildID 20240812083845 -prefsHandle 1760 -prefMapHandle 1752 -prefsLen 21229 -prefMapSize 256888 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e6669e9b-fdcc-4921-8278-ea2a73fd7ade} 7148 "\\.\pipe\gecko-crash-server-pipe.7148" gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
129.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
4020"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask installC:\Program Files\Mozilla Firefox\firefox.exesetup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
129.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
4236"C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe" installC:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe
maintenanceservice_installer.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
HIGH
Exit code:
0
Version:
129.0.1
Modules
Images
c:\program files (x86)\mozilla maintenance service\maintenanceservice_tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4824"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent register-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
129.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
5112"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe"C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe
setup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Mozilla Maintenance Service Installer
Exit code:
0
Version:
129.0.1
Modules
Images
c:\program files\mozilla firefox\maintenanceservice_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5140"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask installC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
129.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
5408"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2172 -parentBuildID 20240812083845 -prefsHandle 2164 -prefMapHandle 2152 -prefsLen 21229 -prefMapSize 256888 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d2d23a89-3e02-4bf3-b796-d3b5608f035f} 7148 "\\.\pipe\gecko-crash-server-pipe.7148" socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
129.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
6016"C:\Program Files\Mozilla Firefox\firefox.exe" -reset-profile -migration -first-startupC:\Program Files\Mozilla Firefox\firefox.exesetup-stub.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
129.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
6240"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent register-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exedefault-browser-agent.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
129.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
Total events
28 198
Read events
28 048
Write events
117
Delete events
33

Modification events

(PID) Process:(7088) setup-stub.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs
Operation:writeName:C:\Program Files\Mozilla Firefox
Value:
308046B0AF4A39CB
(PID) Process:(7088) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(7088) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(7088) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(7088) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(7088) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7088) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7088) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7088) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(7088) setup-stub.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
Executable files
94
Suspicious files
89
Text files
100
Unknown types
23

Dropped files

PID
Process
Filename
Type
6836Firefox Installer.exeC:\Users\admin\AppData\Local\Temp\7zS4BA0EF3E\setup-stub.exeexecutable
MD5:0BB63D7C9F50C73D7A1DC4A22C5DAE18
SHA256:F8DC75F5B3E7A15CAAB2685A193C45BFDCA55B7F59F7F85D278D5E8B5EB386D5
7088setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsr58FA.tmp\UserInfo.dllexecutable
MD5:610AD03DEC634768CD91C7ED79672D67
SHA256:C6C413108539F141BEA3F679E0E2EF705898C51EC7C2607F478A865FC5E2E2DF
7088setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsr58FA.tmp\UAC.dllexecutable
MD5:D23B256E9C12FE37D984BAE5017C5F8C
SHA256:EC6A56D981892BF251DF1439BEA425A5F6C7E1C7312D44BEDD5E2957F270338C
7088setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsr58FA.tmp\stub_common.jstext
MD5:EFCE3DCE0165B3F6551DB47E5C0AC8D6
SHA256:DAB39CBAE31848CCE0B5C43FDDD2674FEF4DEA5B7A3DACDAABDC78A8A931817E
6880setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsq563B.tmp\UAC.dllexecutable
MD5:D23B256E9C12FE37D984BAE5017C5F8C
SHA256:EC6A56D981892BF251DF1439BEA425A5F6C7E1C7312D44BEDD5E2957F270338C
7088setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsr58FA.tmp\nsJSON.dllexecutable
MD5:E832077EAEE06F3B2AC9A8D2E7264567
SHA256:705F4947FB94254C4E5084E6A962045F6A4E790DFC1ECF59CD0FC3FEB38BCBBF
6880setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsq563B.tmp\System.dllexecutable
MD5:B361682FA5E6A1906E754CFA08AA8D90
SHA256:B711C4F17690421C9DC8DDB9ED5A9DDC539B3A28F11E19C851E25DCFC7701C04
7088setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsr58FA.tmp\System.dllexecutable
MD5:B361682FA5E6A1906E754CFA08AA8D90
SHA256:B711C4F17690421C9DC8DDB9ED5A9DDC539B3A28F11E19C851E25DCFC7701C04
7088setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsr58FA.tmp\CityHash.dllexecutable
MD5:2021ACC65FA998DAA98131E20C4605BE
SHA256:C299A0A71BF57EB241868158B4FCFE839D15D5BA607E1BDC5499FDF67B334A14
7088setup-stub.exeC:\Users\admin\AppData\Local\Temp\nsr58FA.tmp\bgstub.jpgimage
MD5:C55F15CEEDC724D6C6E15D1DAF96B698
SHA256:4B7E441D51B790EE1C0BAFF19E4E968392A937877DFA8B84E74464F5BA7A4CF4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
46
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7088
setup-stub.exe
GET
200
34.120.208.123:80
http://download-stats.mozilla.org/stub/v9/release/release/en-US/1/1/10/0/19045/0/0/0/2/0/66175800/66175800/0/0/38/37/0/0/12/0/0/0/1/123.0/20240213221259/129.0.1/20240812083845/1/1/0/1/34.117.35.28/dlsource%3Dmozillaci/2/1/0/0
unknown
whitelisted
2968
svchost.exe
GET
304
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
3164
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6508
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7088
setup-stub.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAo1CNVcKSsBffitZcAP9%2BQ%3D
unknown
whitelisted
7088
setup-stub.exe
GET
200
184.24.77.73:80
http://r10.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRpD%2BQVZ%2B1vf7U0RGQGBm8JZwdxcgQUdKR2KRcYVIUxN75n5gZYwLzFBXICEgOfds7UJR2FFZdqPwx2PSesGA%3D%3D
unknown
whitelisted
7088
setup-stub.exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
unknown
unknown
7088
setup-stub.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAMS6Jl19zCc5X6GAIL92CA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2388
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3972
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5336
SearchApp.exe
104.126.37.130:443
www.bing.com
Akamai International B.V.
DE
unknown
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3164
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3164
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.206
whitelisted
www.bing.com
  • 104.126.37.130
  • 104.126.37.123
  • 104.126.37.171
  • 104.126.37.147
  • 104.126.37.170
  • 104.126.37.177
  • 104.126.37.168
  • 104.126.37.145
  • 104.126.37.152
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.138
  • 40.126.32.74
  • 20.190.160.17
  • 40.126.32.133
  • 40.126.32.68
  • 40.126.32.140
  • 20.190.160.22
  • 20.190.160.14
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
product-details.mozilla.org
  • 18.245.86.112
  • 18.245.86.113
  • 18.245.86.56
  • 18.245.86.36
shared
ocsp.rootca1.amazontrust.com
  • 18.245.39.64
shared
th.bing.com
  • 104.126.37.152
  • 104.126.37.130
  • 104.126.37.123
  • 104.126.37.171
  • 104.126.37.147
  • 104.126.37.170
  • 104.126.37.177
  • 104.126.37.168
  • 104.126.37.145
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
download.mozilla.org
  • 54.205.8.35
  • 3.84.105.199
  • 54.204.106.41
whitelisted

Threats

No threats detected
No debug info