plugin-container.exe

Firefox

Mengmeng Wang

The application plugin-container.exe, “Plugin Container for Firefox” by Mengmeng Wang has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address 6a.ae.a86c.ip4.static.sl-reverse.com on port 843.
Publisher:
Mozilla Corporation  (signed by Mengmeng Wang)

Product:
Firefox

Description:
Plugin Container for Firefox

Version:
50.1.0

MD5:
c6bb98bab2ed2e68e687194a94de9f8b

SHA-1:
b6070ba292901ad7ba60bd5736461452ab8f65ae

SHA-256:
e4e115d4dd1325e1bf561a0e51ef09caf47c11f1485ebbad731fb2133cdb5593

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 4:16:20 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Elex.MW (M)
17.1.18.14

File size:
158.2 KB (161,976 bytes)

Product version:
50.1.0

Copyright:
License: MPL 2

Trademarks:
Mozilla

Original file name:
plugin-container.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\firefox\plugin-container.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
10/14/2016 2:00:00 AM

Valid to:
10/14/2017 1:59:59 AM

Subject:
CN=Mengmeng Wang, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
57FCDAB4B0C6202BC89A0DDD4A742960

File PE Metadata
Compilation timestamp:
1/18/2017 8:06:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0xF021

Entry point:
E8, 88, 08, 00, 00, E9, 87, FE, FF, FF, 3B, 0D, 58, 50, 42, 00, F2, 75, 02, F2, C3, F2, E9, AE, 0B, 00, 00, CC, CC, CC, CC, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 56, 8B, 44, 24, 14, 0B, C0, 75, 28, 8B, 4C, 24, 10, 8B, 44, 24, 0C, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 08, F7, F1, 8B, F0, 8B, C3...
 
[+]

Code size:
60 KB (61,440 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to server-54-192-83-11.mia50.r.cloudfront.net  (54.192.83.11:443)

TCP:
Connects to server.28z.biz  (162.220.166.241:24005)

TCP:
Connects to REDCRUCIBLEWEB3  (68.168.223.144:27102)

TCP (HTTP):
Connects to dcs-188-64-85-87.redcdn.pl  (188.64.85.87:80)

TCP (HTTP):
Connects to dcs-188-64-85-30.redcdn.pl  (188.64.85.30:80)

TCP (HTTP):
Connects to dcs-188-64-84-53.redcdn.pl  (188.64.84.53:80)

TCP (HTTP):
Connects to dcs-188-64-84-31.redcdn.pl  (188.64.84.31:80)

TCP (HTTP):
Connects to dcs-188-64-84-16.redcdn.pl  (188.64.84.16:80)

TCP (HTTP):
Connects to dcs-188-64-84-12.redcdn.pl  (188.64.84.12:80)

TCP:
Connects to 6a.ae.a86c.ip4.static.sl-reverse.com  (108.168.174.106:843)

Remove plugin-container.exe - Powered by Reason Core Security