top title background image
flash

http://104.239.170.93/bins/UnHAnaAW.x86

Status: finished
Submission Time: 2020-05-24 19:28:22 +02:00
Malicious

Comments

Tags

Details

  • Analysis ID:
    232671
  • API (Web) ID:
    361583
  • Analysis Started:
    2020-05-24 19:28:23 +02:00
  • Analysis Finished:
    2020-05-24 19:32:51 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 60
System: Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 88.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171)

Third Party Analysis Engines

malicious
Score: 34/61
malicious
Score: 28/48
malicious

IPs

IP Country Detection
13.35.43.53
United States
34.211.106.52
United States
104.239.170.93
United States
Click to see the 2 hidden entries
52.18.228.24
United States
52.88.148.130
United States

Domains

Name IP Detection
search.r53-2.services.mozilla.com
34.211.106.52
pipeline-incoming-prod-elb-149169523.us-west-2.elb.amazonaws.com
52.88.148.130
locprod1-elb-eu-west-1.prod.mozaws.net
52.18.228.24
Click to see the 1 hidden entries
balrog-cloudfront.prod.mozaws.net
13.35.43.53

URLs

Name Detection
http://104.239.170.93/bins/UnHAnaAW.x86
http://104.239.170.93/bins/UnHAnaAW.x86necko:classified1strongly-framed1request-methodGETrequest-Use
https://support.mozilla.org/kb/reset-firefox-easily-fix-most-problems
Click to see the 26 hidden entries
https://normandy.cdn.mozilla.net/api/v1O
https://discovery.addons.allizom.orgQhttps://discovery.addons-dev.allizom.org
https://discovery.addons.mozilla.org
https://support.mozilla.org/kb/flash-protected-mode-autodisabled
https://developer.mozilla.org/en-US/docs/JavaScript_OS.File/OS.File.Info#Cross-platform_Attributes/
http://www.openh264.org/
https://developer.mozilla.org/docs/JavaScript_OS.File
https://bugzilla.mozilla.org/show_bug.cgi?id=1100294
https://bugzilla.mozilla.org/show_bug.cgi?id=1243643
https://bugzilla.mozilla.org/show_bug.cgi?id=1238180
http://mozilla.org/MPL/2.0/.
http://104.239.170.93/
https://discovery.addons-dev.allizom.org
http://104.239.170.93/zyxel.sh;
https://developer.mozilla.org/en-US/docs/JavaScript_OS.File/OS.File.Info#Cross-platform_Attributes/_
https://support.mozilla.org/kb/warning-unresponsive-script#w_other-causes
https://www.widevine.com/
http://schemas.xmlsoap.org/soap/envelope/
https://hg.mozilla.org/releases/mozilla-release/rev/c61f5f5ead48c78a80c80db5c489bdc7cfaf8175
https://screenshots.firefox.com/
http://schemas.xmlsoap.org/soap/encoding/
http://104.239.170.93/bins/x86
http://104.239.170.93/predictor::seen1
https://normandy.cdn.mozilla.net/api/v1Oextensions.shield-recipe-client.api_urlQextensions.shield-re
http://www.apache.org/licenses/LICENSE-2.0
https://discovery.addons.allizom.orgQ

Dropped files

Name File Type Hashes Detection
/tmp/mozilla_user0/y3EpDsgD.bin.part
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/cache2/entries/736A8C595DC4B84C52B69F02E33465069AE8803F
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-trackwhite-simple.pset
data
#
Click to see the 63 hidden entries
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/startupCache/urlCache-new.bin
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/startupCache/startupCache.8.little
Zip archive data, at least v2.0 to extract
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/startupCache/scriptCache-new.bin
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/startupCache/scriptCache-child-new.bin
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-unwanted-simple.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-unwanted-simple.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-unwanted-simple-1.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-trackwhite-simple.sbstore
data
#
/home/user/.mozilla/firefox/v9nzj3nw.default/crashes/store.json.mozlz4.tmp
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-trackwhite-simple-1.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-track-simple.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-track-simple.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-track-simple-1.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-phish-simple.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-phish-simple.pset
data
#
/home/user/.mozilla/firefox/v9nzj3nw.default/cookies.sqlite-shm
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-phish-simple-1.sbstore
data
#
/home/user/.mozilla/firefox/v9nzj3nw.default/datareporting/aborted-session-ping.tmp
ASCII text, with very long lines, with no line terminators
#
/home/user/.mozilla/firefox/v9nzj3nw.default/datareporting/session-state.json.tmp
ASCII text, with no line terminators
#
/home/user/.mozilla/firefox/v9nzj3nw.default/favicons.sqlite-shm
data
#
/home/user/.mozilla/firefox/v9nzj3nw.default/gmp-gmpopenh264/1.7.1/gmpopenh264.info.tmp
ASCII text
#
/home/user/.mozilla/firefox/v9nzj3nw.default/gmp-gmpopenh264/1.7.1/libgmpopenh264.so.tmp
ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a6f7711a0f3110c0daf8b925630d2ba49053bb97, not stripped
#
/home/user/.mozilla/firefox/v9nzj3nw.default/places.sqlite-shm
data
#
/home/user/.mozilla/firefox/v9nzj3nw.default/prefs-1.js
ASCII text, with very long lines
#
/home/user/.mozilla/firefox/v9nzj3nw.default/search.json.mozlz4.tmp
data
#
/home/user/.mozilla/firefox/v9nzj3nw.default/sessionCheckpoints.json.tmp
ASCII text, with no line terminators
#
/home/user/.mozilla/firefox/v9nzj3nw.default/storage/permanent/chrome/idb/2918063365piupsah.sqlite-shm
data
#
/home/user/.mozilla/firefox/v9nzj3nw.default/storage/permanent/chrome/idb/3561288849sdhlie.sqlite-shm
data
#
/home/user/.mozilla/firefox/v9nzj3nw.default/webappsstore.sqlite-shm
data
#
/home/user/.mozilla/firefox/v9nzj3nw.default/xulstore.json.tmp
ASCII text, with no line terminators
#
/tmp/tmpaddon
Zip archive data, at least v2.0 to extract
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/except-flashallow-digest256.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/activity-stream.tippytop.json.tmp
ASCII text, with very long lines, with no line terminators
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/cache2/entries/20D862992F39CB72DDA198C7938367CD9283E540
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/cache2/entries/7D0DF88A5F52C22C222EA72EA1AC18B62CF57B56
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/cache2/entries/E293DE1609300BB1B8A8CA45B3A45EB3CB38903B
Zip archive data, at least v2.0 to extract
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/allow-flashallow-digest256.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/allow-flashallow-digest256.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/base-track-digest256.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/base-track-digest256.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/block-flash-digest256.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/block-flash-digest256.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/block-flashsubdoc-digest256.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/block-flashsubdoc-digest256.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/except-flash-digest256.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/except-flash-digest256.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/except-flashallow-digest256.pset
data
#
/home/user/.cache/dconf/user
very short file (no magic)
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/except-flashsubdoc-digest256.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/except-flashsubdoc-digest256.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/mozplugin-block-digest256.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/mozplugin-block-digest256.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/mozstd-trackwhite-digest256.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/mozstd-trackwhite-digest256.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-block-simple-1.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-block-simple.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-block-simple.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-harmful-simple-1.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-harmful-simple.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-harmful-simple.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-malware-simple-1.sbstore
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-malware-simple.pset
data
#
/home/user/.cache/mozilla/firefox/v9nzj3nw.default/safebrowsing-updating/test-malware-simple.sbstore
data
#