| URL: | http://a.directfiledl.com/getfile?id=52162532&s=B820050 |
| Full analysis: | https://app.any.run/tasks/c5156086-d2d0-4213-bd03-a5a54054d956 |
| Verdict: | Malicious activity |
| Analysis date: | February 21, 2024, 13:31:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | C94E771F5E311FC395196427395AAC15 |
| SHA1: | 6CDDED9EE47ED2611F0495BB6DCAFDAA783F6D78 |
| SHA256: | 081BF446F26E6F4D5F17AD8B185356C385A414DDFE2A1D333303EE3A08856BF7 |
| SSDEEP: | 3:N1Kf1MXKcd3CARQJAOQBWX7m:C9MF3C0QcJ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 840 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.4.2087339583\1712738732" -childID 3 -isForBrowser -prefsHandle 3668 -prefMapHandle 3664 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {36909601-0a0b-4e28-bb82-faa15732b5ad} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 3660 18275280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1072 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Vega X Dev Mode.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1352 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.3.1192443194\1218971741" -childID 2 -isForBrowser -prefsHandle 2980 -prefMapHandle 2976 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c5dc7c72-5176-45e2-94f0-d6b7d5024434} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 2992 1657dc90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1484 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.7.1360084779\1935599655" -childID 6 -isForBrowser -prefsHandle 3952 -prefMapHandle 3948 -prefsLen 34332 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {cf0731cf-2a19-4648-a1c0-bae918d413b2} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 3316 192f0110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1496 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.2.1335891920\1420338705" -childID 1 -isForBrowser -prefsHandle 1976 -prefMapHandle 1924 -prefsLen 24491 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {dd55162a-6046-4a27-9662-0a5a98593563} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 1824 1278f280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1540 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.5.1498032314\1743602157" -childID 4 -isForBrowser -prefsHandle 3480 -prefMapHandle 2476 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1a3813d6-aca4-4222-b512-68599b5d5fe3} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 3460 1925e560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2992 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.6.987582955\16879003" -childID 5 -isForBrowser -prefsHandle 3816 -prefMapHandle 3824 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {24590b46-95ef-4e10-8c68-12494e88f117} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 3324 1925e6d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3656 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://a.directfiledl.com/getfile?id=52162532&s=B820050 | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3876 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1072.29859\Vega X Dev Mode\Vega X.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1072.29859\Vega X Dev Mode\Vega X.exe | WinRAR.exe | ||||||||||||
User: admin Company: https://vegax.gg Integrity Level: MEDIUM Description: Vega X Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3932 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.1.1373502737\708591823" -parentBuildID 20230710165010 -prefsHandle 1400 -prefMapHandle 1396 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6c8e80cb-a3fd-4cd4-9d27-8fd4d1700fa3} 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 1412 d11b840 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 412BED4E01000000 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 81C7EE4E01000000 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB |
| Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (3656) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3656 | firefox.exe | C:\Users\admin\Downloads\zR3GQ1HG.zip.part | compressed | |
MD5:001FF484746E9253F0A3BB0F9642DA06 | SHA256:F2C705AF59DE24152851CC5AF148DC8BEEF681F029CC7CBF91C3406D046AE555 | |||
| 3656 | firefox.exe | C:\Users\admin\Downloads\Vega X Dev Mode._w7YstmJ.zip.part | compressed | |
MD5:001FF484746E9253F0A3BB0F9642DA06 | SHA256:F2C705AF59DE24152851CC5AF148DC8BEEF681F029CC7CBF91C3406D046AE555 | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:B7A3C61D0C144CC5E166B1E769CA8F8C | SHA256:7FADCB77FFACA6B9E9F15C6F1CD3AAD4C20DCD90FA92429A627A3A7110CA2644 | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.bin | dbf | |
MD5:63B1BB87284EFE954E1C3AE390E7EE44 | SHA256:B017EE25A7F5C09EB4BF359CA721D67E6E9D9F95F8CE6F741D47F33BDE6EF73A | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal | binary | |
MD5:7A5BF5AF7FCC54A43C76BCA4FBB0DCA4 | SHA256:67F278BA6944FFCC65F4E1F2877C878789B25D9B31A9CB9A954F359AF08B8D73 | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3656 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3656 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
3656 | firefox.exe | GET | 200 | 167.235.218.62:80 | http://a.directfiledl.com/getfile?id=52162532&s=B820050 | unknown | compressed | 42.9 Mb | unknown |
3656 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
3656 | firefox.exe | POST | 200 | 95.101.54.130:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3656 | firefox.exe | POST | 200 | 95.101.54.130:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3656 | firefox.exe | POST | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
3656 | firefox.exe | POST | 200 | 95.101.54.130:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3656 | firefox.exe | POST | 200 | 95.101.54.130:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3656 | firefox.exe | POST | 200 | 95.101.54.130:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3656 | firefox.exe | POST | 200 | 142.250.185.99:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3656 | firefox.exe | 167.235.218.62:80 | a.directfiledl.com | Hetzner Online GmbH | DE | unknown |
3656 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
3656 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
3656 | firefox.exe | 34.117.188.166:443 | spocs.getpocket.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
3656 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
3656 | firefox.exe | 95.101.54.130:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
3656 | firefox.exe | 142.250.185.234:443 | safebrowsing.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
a.directfiledl.com |
| unknown |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
gkegw.prod.ads.prod.webservices.mozgcp.net |
| unknown |
r3.o.lencr.org |
| shared |
firefox.settings.services.mozilla.com |
| whitelisted |