URL:

https://gofile.io/d/znhEB0

Full analysis: https://app.any.run/tasks/eefef26f-ed8f-4958-b6b0-b65afda4ec9a
Verdict: Malicious activity
Threats:

Rhadamanthys is a C++ information-stealing malware that extracts sensitive data from infiltrated machines. Its layered operational chain and advanced evasion tactics make it a major risk in cybersecurity landscapes.

Analysis date: October 03, 2025, 17:00:46
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
fileshare
autoit
anti-evasion
stealer
rhadamanthys
Indicators:
MD5:

9DB28735383DD2877627A2960BDC3C4B

SHA1:

79C96683D07517FFD3B6C55B95DD45738470264C

SHA256:

0792571BEC6D971D59FCE63378C732B62499933491A041CC15591DA871BAB6A6

SSDEEP:

3:N8rxL1xgnVn:2ZEV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • TradingView Premium Desktop.exe (PID: 2188)
    • Loads dropped or rewritten executable

      • tasklist.exe (PID: 9476)
      • Corresponding.scr (PID: 9816)
    • Actions looks like stealing of personal data

      • OOBE-Maintenance.exe (PID: 8648)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 9392)
      • WinRAR.exe (PID: 8188)
      • msedge.exe (PID: 8000)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 8188)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 8188)
    • Application launched itself

      • WinRAR.exe (PID: 9392)
      • cmd.exe (PID: 4644)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 8188)
    • Reads command from file

      • cmd.exe (PID: 4644)
    • Executable content was dropped or overwritten

      • TradingView Premium Desktop.exe (PID: 2188)
    • Starts CMD.EXE for commands execution

      • TradingView Premium Desktop.exe (PID: 2188)
      • cmd.exe (PID: 4644)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 9448)
    • Get information on the list of running processes

      • cmd.exe (PID: 9448)
    • The executable file from the user directory is run by the CMD process

      • Corresponding.scr (PID: 9816)
    • Starts the AutoIt3 executable file

      • cmd.exe (PID: 9448)
    • Starts application with an unusual extension

      • cmd.exe (PID: 9448)
    • There is functionality for taking screenshot (YARA)

      • TradingView Premium Desktop.exe (PID: 2188)
      • Corresponding.scr (PID: 9816)
    • The process checks if it is being run in the virtual environment

      • Corresponding.scr (PID: 9816)
    • Executes application which crashes

      • Corresponding.scr (PID: 9816)
    • Connects to unusual port

      • Corresponding.scr (PID: 9816)
      • OOBE-Maintenance.exe (PID: 8648)
      • wmpshare.exe (PID: 9316)
    • Loads DLL from Mozilla Firefox

      • OOBE-Maintenance.exe (PID: 8648)
    • Searches for installed software

      • OOBE-Maintenance.exe (PID: 8648)
    • Reads Mozilla Firefox installation path

      • msedge.exe (PID: 8000)
  • INFO

    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 9352)
      • BackgroundTransferHost.exe (PID: 9592)
      • BackgroundTransferHost.exe (PID: 9916)
      • BackgroundTransferHost.exe (PID: 9360)
      • BackgroundTransferHost.exe (PID: 10164)
    • Application launched itself

      • firefox.exe (PID: 4212)
      • firefox.exe (PID: 1136)
      • chrome.exe (PID: 8536)
      • msedge.exe (PID: 8000)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 9592)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 9592)
      • slui.exe (PID: 6136)
      • chrome.exe (PID: 8536)
      • msedge.exe (PID: 8000)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 9592)
      • slui.exe (PID: 6136)
    • Manual execution by a user

      • WinRAR.exe (PID: 9392)
      • OOBE-Maintenance.exe (PID: 8648)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 8188)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with arabic language support

      • WinRAR.exe (PID: 8188)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 4212)
    • The sample compiled with bulgarian language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with russian language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with french language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with Italian language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with polish language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with korean language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with german language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with spanish language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with chinese language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with japanese language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with portuguese language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with slovak language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with turkish language support

      • WinRAR.exe (PID: 8188)
    • The sample compiled with swedish language support

      • WinRAR.exe (PID: 8188)
    • Checks supported languages

      • TradingView Premium Desktop.exe (PID: 2188)
      • extrac32.exe (PID: 9432)
      • Corresponding.scr (PID: 9816)
      • chrome.exe (PID: 8536)
      • msedge.exe (PID: 8000)
      • wmpshare.exe (PID: 9316)
    • The sample compiled with czech language support

      • WinRAR.exe (PID: 8188)
    • Loads dropped or rewritten executable

      • TradingView Premium Desktop.exe (PID: 2188)
    • Create files in a temporary directory

      • TradingView Premium Desktop.exe (PID: 2188)
      • extrac32.exe (PID: 9432)
      • chrome.exe (PID: 8536)
      • OOBE-Maintenance.exe (PID: 8648)
      • msedge.exe (PID: 8000)
    • Reads the computer name

      • TradingView Premium Desktop.exe (PID: 2188)
      • extrac32.exe (PID: 9432)
      • Corresponding.scr (PID: 9816)
      • chrome.exe (PID: 8536)
      • msedge.exe (PID: 8000)
    • Reads mouse settings

      • Corresponding.scr (PID: 9816)
    • Reads the machine GUID from the registry

      • Corresponding.scr (PID: 9816)
      • chrome.exe (PID: 8536)
      • msedge.exe (PID: 8000)
      • wmpshare.exe (PID: 9316)
    • Reads Environment values

      • chrome.exe (PID: 8536)
      • msedge.exe (PID: 8000)
    • Process checks computer location settings

      • chrome.exe (PID: 8536)
      • msedge.exe (PID: 8000)
    • Process checks whether UAC notifications are on

      • msedge.exe (PID: 8000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
249
Monitored processes
73
Malicious processes
4
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1136"C:\Program Files\Mozilla Firefox\firefox.exe" "https://gofile.io/d/znhEB0"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\vcruntime140.dll
1516"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=10 --always-read-main-dll --field-trial-handle=4420,i,5677442372833529353,8143086290865791087,262144 --variations-seed-version --mojo-platform-channel-handle=4344 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
2188"C:\Users\admin\AppData\Local\Temp\Rar$EXb8188.2300\TradingView Premium Desktop.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb8188.2300\TradingView Premium Desktop.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb8188.2300\tradingview premium desktop.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2504"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Local\Temp\chr4BF0.tmp /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\Temp\chr4BF0.tmp\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x298,0x29c,0x2a0,0x294,0x2a8,0x7ffba5e3f208,0x7ffba5e3f214,0x7ffba5e3f220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2600"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --string-annotations --always-read-main-dll --field-trial-handle=6716,i,5677442372833529353,8143086290865791087,262144 --variations-seed-version --mojo-platform-channel-handle=3940 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3116"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 1904 -prefsLen 36580 -prefMapHandle 1932 -prefMapSize 273045 -ipcHandle 2004 -initialChannelId {ca06b2d7-6a9f-4e78-b615-df2e9ded9768} -parentPid 4212 -crashReporter "\\.\pipe\gecko-crash-server-pipe.4212" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
4212"C:\Program Files\Mozilla Firefox\firefox.exe" https://gofile.io/d/znhEB0C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4308"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=16 --always-read-main-dll --field-trial-handle=4968,i,5677442372833529353,8143086290865791087,262144 --variations-seed-version --mojo-platform-channel-handle=5020 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4644cmd.exe /c cmd < Trinity.accdtC:\Windows\SysWOW64\cmd.exeTradingView Premium Desktop.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
27 987
Read events
27 915
Write events
70
Delete events
2

Modification events

(PID) Process:(1136) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
A0413F4201000000
(PID) Process:(4212) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
B012404201000000
(PID) Process:(4212) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
0
(PID) Process:(4212) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
1
(PID) Process:(4212) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Installer\308046B0AF4A39CB
Operation:delete valueName:installer.taskbarpin.win10.enabled
Value:
(PID) Process:(4212) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(4212) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(4212) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(4212) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(4212) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
Executable files
961
Suspicious files
1 363
Text files
644
Unknown types
0

Dropped files

PID
Process
Filename
Type
4212firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
4212firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:0AABD9E5E3E5521E0A1ED35F1D62DB75
SHA256:260A86BA84F58B68CA4113660DC26BE98851EF7222D1B05C635599447ADA2447
4212firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:C4ABC596A5E728E91E215A22CE63A3DA
SHA256:137AA84417F6294C0B9B9491A53E1DEAA07F92B1B9BEF80DBD528128D629DF20
4212firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
4212firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
4212firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4212firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4212firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:B30329D7D2CF4258C22F500CBEA218FF
SHA256:C5E20431B116E1DABD383C6855A36E6DAF13E1CC125B83D59EF68B4BCEFB02E6
4212firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4212firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:C4ABC596A5E728E91E215A22CE63A3DA
SHA256:137AA84417F6294C0B9B9491A53E1DEAA07F92B1B9BEF80DBD528128D629DF20
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
138
DNS requests
138
Threats
24

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4212
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
text
90 b
whitelisted
4212
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
4212
firefox.exe
POST
200
142.250.186.99:80
http://o.pki.goog/we2
US
binary
279 b
whitelisted
4212
firefox.exe
POST
200
142.250.186.99:80
http://o.pki.goog/s/wr3/W6c
US
binary
471 b
whitelisted
4212
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
5320
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
4212
firefox.exe
POST
200
142.250.186.99:80
http://o.pki.goog/s/wr3/vbw
US
binary
472 b
whitelisted
4212
firefox.exe
POST
200
142.250.186.99:80
http://o.pki.goog/s/wr3/W6c
US
binary
471 b
whitelisted
4212
firefox.exe
POST
200
142.250.186.99:80
http://o.pki.goog/s/wr3/W6c
US
binary
471 b
whitelisted
5320
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6016
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
764
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5224
SearchApp.exe
2.16.204.151:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4212
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
whitelisted
4212
firefox.exe
51.75.242.210:443
gofile.io
OVH SAS
FR
whitelisted
4212
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
4212
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
4212
firefox.exe
151.101.193.91:443
firefox.settings.services.mozilla.com
FASTLY
US
whitelisted
4212
firefox.exe
142.250.186.99:80
o.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
www.bing.com
  • 2.16.204.151
  • 2.16.204.146
  • 2.16.204.139
  • 2.16.204.141
  • 2.16.204.148
  • 2.16.204.145
  • 2.16.204.156
  • 2.16.204.150
  • 2.16.204.152
  • 2.16.204.143
  • 2.16.204.144
  • 2.16.204.142
  • 2.16.204.147
  • 23.3.89.113
  • 23.3.89.112
  • 95.100.158.122
  • 23.11.206.99
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted
content-signature-chains.prod.autograph.services.mozaws.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted
gofile.io
  • 51.75.242.210
  • 45.112.123.126
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.36.137.203
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted

Threats

PID
Process
Class
Message
2428
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING Online File Storage Domain in DNS Lookup (gofile .io)
4212
firefox.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in TLS SNI (gofile .io)
4212
firefox.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in TLS SNI (gofile .io)
2428
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING Online File Storage Domain in DNS Lookup (gofile .io)
2428
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING Online File Storage Domain in DNS Lookup (gofile .io)
4212
firefox.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in TLS SNI (gofile .io)
4212
firefox.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in TLS SNI (gofile .io)
2428
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING Online File Storage Domain in DNS Lookup (gofile .io)
2428
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING Online File Storage Domain in DNS Lookup (gofile .io)
2428
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING Online File Storage Domain in DNS Lookup (gofile .io)
Process
Message
chrome.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\Temp\chr3FD9.tmp directory exists )
msedge.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\Temp\chr4BF0.tmp directory exists )