palemoon.exe

Pale Moon

Moonchild Productions

Publisher:
Moonchild Productions

Product:
Pale Moon

Description:
Pale Moon web browser

Version:
24.0

MD5:
b560e9db72f7a6c55c09d6dd60282da0

SHA-1:
6b60f36d0f4db680e9a1a19feb5f5827eb2fa6cd

SHA-256:
b86b959e9f56c75222dd299420bed880f9552713c47a938b9259d9eeeee09504

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 7:47:56 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Stranfom
1.3.0.4246

File size:
271.5 KB (278,016 bytes)

Product version:
24.0.1

Copyright:
©Pale Moon, Firefox and Mozilla Developers, available under the MPL 2.0.

Trademarks:
The Pale Moon logo and project names are the property of Moonchild Productions.

Original file name:
palemoon.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\core\palemoon.exe

File PE Metadata
Compilation timestamp:
9/17/2013 3:02:23 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:h9giUqozIxdHFPhzv+9giUqozIxdHFP8N:8igzIxVF5igzIxVFK

Entry address:
0x2EA3

Entry point:
E8, B9, 02, 00, 00, E9, 91, FE, FF, FF, 55, 8B, EC, 5D, E9, FC, 00, 00, 00, 83, 3D, B4, 64, 40, 00, 00, 74, 03, 33, C0, C3, 56, 6A, 04, 6A, 20, FF, 15, D0, 40, 40, 00, 59, 59, 8B, F0, 56, FF, 15, 50, 40, 40, 00, A3, B4, 64, 40, 00, A3, B0, 64, 40, 00, 85, F6, 75, 05, 6A, 18, 58, 5E, C3, 83, 26, 00, 33, C0, 5E, C3, 6A, 14, 68, A8, 48, 40, 00, E8, 72, 03, 00, 00, FF, 35, B4, 64, 40, 00, 8B, 35, 4C, 40, 40, 00, FF, D6, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, D8, 40, 40, 00, 59, EB, 65, 6A, 08, E8...
 
[+]

Code size:
9.5 KB (9,728 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to muc03s01-in-f10.1e100.net  (173.194.35.138:443)

TCP (HTTP SSL):
Connects to lhr08s02-in-f25.1e100.net  (173.194.41.121:443)

TCP (HTTP SSL):
Connects to fa-in-f95.1e100.net  (173.194.70.95:443)

TCP (HTTP SSL):
Connects to fa-in-f84.1e100.net  (173.194.70.84:443)

TCP (HTTP SSL):
Connects to ee-in-f84.1e100.net  (173.194.65.84:443)

TCP (HTTP SSL):
Connects to edge-star-shv-10-fra2.facebook.com  (31.13.81.144:443)

TCP (HTTP SSL):
Connects to edge-star-shv-04-mxp1.facebook.com  (31.13.86.49:443)

TCP (HTTP SSL):
Connects to edge-star-shv-01-ash5.facebook.com  (173.252.101.48:443)

TCP (HTTP SSL):
Connects to channelproxy-shv-06-frc1.facebook.com  (69.171.248.16:443)

TCP (HTTP SSL):
Connects to bud02s04-in-f30.1e100.net  (173.194.39.190:443)

TCP (HTTP SSL):
Connects to bud02s02-in-f7.1e100.net  (173.194.39.103:443)

TCP (HTTP SSL):
Connects to a77.109.170-97.deploy.akamaitechnologies.com  (77.109.170.97:443)

TCP (HTTP SSL):
Connects to a23-62-2-121.deploy.static.akamaitechnologies.com  (23.62.2.121:443)

TCP (HTTP):
Connects to 173.192.82.194-static.reverse.softlayer.com  (173.192.82.194:80)

Scan palemoon.exe - Powered by Reason Core Security