Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | May 3, 2025, 4:35 p.m. | May 3, 2025, 4:38 p.m. |
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2128 -
taskkill.exe taskkill /F /IM chrome.exe /T
2284 -
taskkill.exe taskkill /F /IM msedge.exe /T
2368 -
taskkill.exe taskkill /F /IM opera.exe /T
2448 -
taskkill.exe taskkill /F /IM brave.exe /T
2528 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
2608-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
2652
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2820 -
taskkill.exe taskkill /F /IM chrome.exe /T
2144 -
taskkill.exe taskkill /F /IM msedge.exe /T
2188 -
taskkill.exe taskkill /F /IM opera.exe /T
2344 -
taskkill.exe taskkill /F /IM brave.exe /T
2468 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
2556-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
2620
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2896 -
taskkill.exe taskkill /F /IM chrome.exe /T
2796 -
taskkill.exe taskkill /F /IM msedge.exe /T
2176 -
taskkill.exe taskkill /F /IM opera.exe /T
2348 -
taskkill.exe taskkill /F /IM brave.exe /T
2340 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
2596-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
2696
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2884 -
taskkill.exe taskkill /F /IM chrome.exe /T
516 -
taskkill.exe taskkill /F /IM msedge.exe /T
1156 -
taskkill.exe taskkill /F /IM opera.exe /T
2460 -
taskkill.exe taskkill /F /IM brave.exe /T
2744 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
2920-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
2200
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2504 -
taskkill.exe taskkill /F /IM chrome.exe /T
1284 -
taskkill.exe taskkill /F /IM msedge.exe /T
288 -
taskkill.exe taskkill /F /IM opera.exe /T
2408 -
taskkill.exe taskkill /F /IM brave.exe /T
2680 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
2740-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
2912
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2124 -
taskkill.exe taskkill /F /IM chrome.exe /T
2280 -
taskkill.exe taskkill /F /IM msedge.exe /T
2948 -
taskkill.exe taskkill /F /IM opera.exe /T
2792 -
taskkill.exe taskkill /F /IM brave.exe /T
2888 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
2720-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
2276
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2716 -
taskkill.exe taskkill /F /IM chrome.exe /T
792 -
taskkill.exe taskkill /F /IM msedge.exe /T
2928 -
taskkill.exe taskkill /F /IM opera.exe /T
2516 -
taskkill.exe taskkill /F /IM brave.exe /T
1076 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
1868-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
2540
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2400 -
taskkill.exe taskkill /F /IM chrome.exe /T
3036 -
taskkill.exe taskkill /F /IM msedge.exe /T
2024 -
taskkill.exe taskkill /F /IM opera.exe /T
916 -
taskkill.exe taskkill /F /IM brave.exe /T
1340 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
3088-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3132
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
3220 -
taskkill.exe taskkill /F /IM chrome.exe /T
3304 -
taskkill.exe taskkill /F /IM msedge.exe /T
3396 -
taskkill.exe taskkill /F /IM opera.exe /T
3476 -
taskkill.exe taskkill /F /IM brave.exe /T
3556 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
3636-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3680
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
3816 -
taskkill.exe taskkill /F /IM chrome.exe /T
3900 -
taskkill.exe taskkill /F /IM msedge.exe /T
3980 -
taskkill.exe taskkill /F /IM opera.exe /T
4060 -
taskkill.exe taskkill /F /IM brave.exe /T
3116 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
2168-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3200
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
3324 -
taskkill.exe taskkill /F /IM chrome.exe /T
3460
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Program Files\Mozilla Firefox\api-ms-win-crt-multibyte-l1-1-0.dll |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process |
section | {u'size_of_data': u'0x00017000', u'virtual_address': u'0x000d4000', u'entropy': 7.2108141687092955, u'name': u'.rsrc', u'virtual_size': u'0x00016fb0'} | entropy | 7.21081416871 | description | A section with a high entropy has been found |
url | https://aus5.mozilla.org/update/6/%PRODUCT%/%VERSION%/%BUILD_ID%/%BUILD_TARGET%/%LOCALE%/%CHANNEL%/%OS_VERSION%/%SYSTEM_CAPABILITIES%/%DISTRIBUTION%/%DISTRIBUTION_VERSION%/update.xml |
url | https://crash-reports.mozilla.com/submit?id= |
url | https://hg.mozilla.org/releases/mozilla-release/rev/92187d03adde4b31daef292087a266f10121379c |
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active |
cmdline | taskkill /F /IM opera.exe /T |
cmdline | taskkill /F /IM chrome.exe /T |
cmdline | taskkill /F /IM msedge.exe /T |
cmdline | taskkill /F /IM firefox.exe /T |
cmdline | taskkill /F /IM brave.exe /T |
process: potential browser injection target | firefox.exe |
parent_process | firefox.exe | martian_process | "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking | ||||||
parent_process | firefox.exe | martian_process | "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking | ||||||
parent_process | firefox.exe | martian_process | "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking | ||||||
parent_process | firefox.exe | martian_process | "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking | ||||||
parent_process | firefox.exe | martian_process | "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking | ||||||
parent_process | firefox.exe | martian_process | "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking | ||||||
parent_process | firefox.exe | martian_process | "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking | ||||||
parent_process | firefox.exe | martian_process | "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking | ||||||
parent_process | firefox.exe | martian_process | "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking | ||||||
parent_process | firefox.exe | martian_process | "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking |
file | C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\parent.lock |
file | C:\Users\test22\AppData\Local\Temp\firefox\parent.lock |
Cynet | Malicious (score: 99) |
Skyhigh | BehavesLike.Win32.Formbook.dh |
Cylance | Unsafe |
Sangfor | Virus.Win32.Save.a |
CrowdStrike | win/malicious_confidence_70% (W) |
VirIT | Trojan.Win32.AutoIt_Heur.L |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/HackTool.Silentall.N potentially unsafe |
Kaspersky | HEUR:Trojan.Script.Agent.gen |
Rising | HackTool.Silentall/Autoit!1.106C3 (CLASSIC) |
F-Secure | Trojan.TR/ATRAPS.Gen |
DrWeb | Trojan.Siggen30.19657 |
McAfeeD | ti!C75595A1EEF5 |
Avira | TR/ATRAPS.Gen |
Microsoft | Program:Win32/Wacapew.C!ml |
Malwarebytes | Malware.AI.3317982698 |
Ikarus | PUA.HackTool.Silentall |
Tencent | Unk.Win32.Script.404958 |
huorong | TrojanDownloader/AutoIT.Agent.d |
Fortinet | Riskware/Silentall |