URL:

Tlauncher.org

Full analysis: https://app.any.run/tasks/11351a45-9a7c-4f3a-8bb9-6863afd6399e
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 06, 2025, 00:58:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
lua
upx
loader
java
arch-doc
arch-scr
arch-html
Indicators:
MD5:

C0D7E255D3C625FCB9CE03C566F1A46E

SHA1:

2E18886D8F4698CC6DFE4FD9EAF6299386D94182

SHA256:

0ACA835844FDD62F9AB41A4CDA63FCEEA83BEEF9F099B39E44097A4EA4AE1389

SSDEEP:

3:BySuS:gS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • irsetup.exe (PID: 2968)
      • 360TS_Setup.exe (PID: 1924)
      • csrss.exe (PID: 388)
    • Executing a file with an untrusted certificate

      • javaw.exe (PID: 2760)
    • Changes the autorun value in the registry

      • 360TS_Setup.exe (PID: 1924)
  • SUSPICIOUS

    • Loads DLL from Mozilla Firefox

      • csrss.exe (PID: 388)
    • Executable content was dropped or overwritten

      • TLauncher-Installer-1.6.8.exe (PID: 3044)
      • irsetup.exe (PID: 2968)
      • BrowserInstaller.exe (PID: 1180)
      • irsetup.exe (PID: 3072)
      • 360-installer-bro.exe (PID: 3888)
      • 360TS_Setup.exe (PID: 2076)
      • 360TS_Setup.exe (PID: 1924)
      • javaw.exe (PID: 2300)
      • javaw.exe (PID: 2760)
    • Reads the Internet Settings

      • TLauncher-Installer-1.6.8.exe (PID: 3044)
      • irsetup.exe (PID: 2968)
      • BrowserInstaller.exe (PID: 1180)
      • irsetup.exe (PID: 3072)
      • 360-installer-bro.exe (PID: 3888)
      • WMIC.exe (PID: 3700)
      • WMIC.exe (PID: 2120)
      • 360TS_Setup.exe (PID: 1924)
      • WMIC.exe (PID: 3036)
      • WMIC.exe (PID: 1380)
    • Reads security settings of Internet Explorer

      • TLauncher-Installer-1.6.8.exe (PID: 3044)
      • irsetup.exe (PID: 2968)
      • BrowserInstaller.exe (PID: 1180)
      • irsetup.exe (PID: 3072)
      • 360-installer-bro.exe (PID: 3888)
      • 360TS_Setup.exe (PID: 1924)
    • Adds/modifies Windows certificates

      • irsetup.exe (PID: 2968)
      • irsetup.exe (PID: 3072)
    • Reads settings of System Certificates

      • irsetup.exe (PID: 2968)
      • irsetup.exe (PID: 3072)
      • dxdiag.exe (PID: 2940)
      • 360TS_Setup.exe (PID: 1924)
    • Reads Microsoft Outlook installation path

      • irsetup.exe (PID: 2968)
    • Reads the Windows owner or organization settings

      • irsetup.exe (PID: 2968)
      • irsetup.exe (PID: 3072)
    • Checks for Java to be installed

      • irsetup.exe (PID: 2968)
      • TLauncher.exe (PID: 3884)
    • Potential Corporate Privacy Violation

      • 360-installer-bro.exe (PID: 3888)
    • Process requests binary or script from the Internet

      • 360-installer-bro.exe (PID: 3888)
      • javaw.exe (PID: 2300)
      • javaw.exe (PID: 2760)
    • Reads Internet Explorer settings

      • irsetup.exe (PID: 2968)
    • Creates a software uninstall entry

      • irsetup.exe (PID: 2968)
    • Starts CMD.EXE for commands execution

      • javaw.exe (PID: 2300)
      • javaw.exe (PID: 2760)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3492)
      • cmd.exe (PID: 1576)
      • cmd.exe (PID: 2616)
      • cmd.exe (PID: 3348)
      • cmd.exe (PID: 3400)
      • cmd.exe (PID: 3120)
      • cmd.exe (PID: 780)
    • Uses WMIC.EXE to obtain operating system information

      • cmd.exe (PID: 3492)
      • cmd.exe (PID: 1576)
    • There is functionality for taking screenshot (YARA)

      • javaw.exe (PID: 2300)
      • 360TS_Setup.exe (PID: 2076)
      • 360TS_Setup.exe (PID: 1924)
      • javaw.exe (PID: 2760)
    • Starts itself from another location

      • 360TS_Setup.exe (PID: 2076)
    • Creates file in the systems drive root

      • 360TS_Setup.exe (PID: 1924)
    • Process drops legitimate windows executable

      • javaw.exe (PID: 2300)
      • 360TS_Setup.exe (PID: 1924)
      • javaw.exe (PID: 2760)
    • The process drops C-runtime libraries

      • javaw.exe (PID: 2300)
      • javaw.exe (PID: 2760)
    • Uses ICACLS.EXE to modify access control lists

      • javaw.exe (PID: 2760)
    • Uses SYSTEMINFO.EXE to read the environment

      • cmd.exe (PID: 3348)
    • Uses WMIC.EXE to obtain CPU information

      • cmd.exe (PID: 2616)
    • Creates/Modifies COM task schedule object

      • dxdiag.exe (PID: 2940)
    • Uses WMIC.EXE to obtain quick Fix Engineering (patches) data

      • cmd.exe (PID: 780)
    • Creates or modifies Windows services

      • 360TS_Setup.exe (PID: 1924)
    • Creates files in the driver directory

      • 360TS_Setup.exe (PID: 1924)
    • Drops a system driver (possible attempt to evade defenses)

      • 360TS_Setup.exe (PID: 1924)
    • The process verifies whether the antivirus software is installed

      • 360TS_Setup.exe (PID: 1924)
    • Drops 7-zip archiver for unpacking

      • 360TS_Setup.exe (PID: 1924)
  • INFO

    • The sample compiled with english language support

      • firefox.exe (PID: 2452)
      • TLauncher-Installer-1.6.8.exe (PID: 3044)
      • irsetup.exe (PID: 2968)
      • BrowserInstaller.exe (PID: 1180)
      • 360-installer-bro.exe (PID: 3888)
      • irsetup.exe (PID: 3072)
      • javaw.exe (PID: 2300)
      • 360TS_Setup.exe (PID: 1924)
      • javaw.exe (PID: 2760)
    • Application launched itself

      • firefox.exe (PID: 2060)
      • firefox.exe (PID: 2452)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 2452)
    • Checks supported languages

      • TLauncher-Installer-1.6.8.exe (PID: 3044)
      • irsetup.exe (PID: 2968)
      • irsetup.exe (PID: 3072)
      • BrowserInstaller.exe (PID: 1180)
      • 360-installer-bro.exe (PID: 3888)
      • TLauncher.exe (PID: 3884)
      • javaw.exe (PID: 2300)
      • chcp.com (PID: 3624)
      • chcp.com (PID: 4056)
      • 360TS_Setup.exe (PID: 1924)
      • 360TS_Setup.exe (PID: 2076)
      • javaw.exe (PID: 2760)
      • chcp.com (PID: 3956)
      • chcp.com (PID: 3868)
      • chcp.com (PID: 2784)
      • chcp.com (PID: 4028)
      • chcp.com (PID: 532)
    • Create files in a temporary directory

      • TLauncher-Installer-1.6.8.exe (PID: 3044)
      • irsetup.exe (PID: 2968)
      • irsetup.exe (PID: 3072)
      • BrowserInstaller.exe (PID: 1180)
      • 360-installer-bro.exe (PID: 3888)
      • javaw.exe (PID: 2300)
      • 360TS_Setup.exe (PID: 2076)
      • 360TS_Setup.exe (PID: 1924)
      • javaw.exe (PID: 2760)
    • Reads the computer name

      • TLauncher-Installer-1.6.8.exe (PID: 3044)
      • irsetup.exe (PID: 2968)
      • BrowserInstaller.exe (PID: 1180)
      • irsetup.exe (PID: 3072)
      • 360-installer-bro.exe (PID: 3888)
      • javaw.exe (PID: 2300)
      • 360TS_Setup.exe (PID: 2076)
      • 360TS_Setup.exe (PID: 1924)
      • javaw.exe (PID: 2760)
    • Checks proxy server information

      • irsetup.exe (PID: 2968)
      • irsetup.exe (PID: 3072)
      • 360-installer-bro.exe (PID: 3888)
      • 360TS_Setup.exe (PID: 1924)
    • Reads the machine GUID from the registry

      • irsetup.exe (PID: 2968)
      • irsetup.exe (PID: 3072)
      • 360-installer-bro.exe (PID: 3888)
      • javaw.exe (PID: 2300)
      • 360TS_Setup.exe (PID: 1924)
      • javaw.exe (PID: 2760)
    • Reads the software policy settings

      • irsetup.exe (PID: 2968)
      • irsetup.exe (PID: 3072)
      • dxdiag.exe (PID: 2940)
      • 360TS_Setup.exe (PID: 1924)
    • UPX packer has been detected

      • irsetup.exe (PID: 2968)
      • irsetup.exe (PID: 3072)
    • The process uses Lua

      • irsetup.exe (PID: 2968)
      • irsetup.exe (PID: 3072)
    • Creates files or folders in the user directory

      • irsetup.exe (PID: 3072)
      • 360-installer-bro.exe (PID: 3888)
      • irsetup.exe (PID: 2968)
      • javaw.exe (PID: 2300)
      • 360TS_Setup.exe (PID: 1924)
      • javaw.exe (PID: 2760)
    • Disables trace logs

      • 360-installer-bro.exe (PID: 3888)
    • Creates files in the program directory

      • irsetup.exe (PID: 2968)
      • javaw.exe (PID: 2300)
      • 360TS_Setup.exe (PID: 2076)
      • 360TS_Setup.exe (PID: 1924)
      • javaw.exe (PID: 2760)
    • Application based on Java

      • javaw.exe (PID: 2300)
    • Changes the display of characters in the console

      • cmd.exe (PID: 3492)
      • cmd.exe (PID: 1576)
      • cmd.exe (PID: 2616)
      • cmd.exe (PID: 3348)
      • cmd.exe (PID: 3400)
      • cmd.exe (PID: 3120)
      • cmd.exe (PID: 780)
    • The sample compiled with chinese language support

      • 360TS_Setup.exe (PID: 2076)
      • 360TS_Setup.exe (PID: 1924)
    • Process checks computer location settings

      • 360TS_Setup.exe (PID: 1924)
    • The sample compiled with turkish language support

      • 360TS_Setup.exe (PID: 1924)
    • Reads security settings of Internet Explorer

      • dxdiag.exe (PID: 2940)
    • The sample compiled with russian language support

      • 360TS_Setup.exe (PID: 1924)
    • Reads Microsoft Office registry keys

      • 360TS_Setup.exe (PID: 1924)
    • Reads CPU info

      • 360TS_Setup.exe (PID: 1924)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
101
Monitored processes
47
Malicious processes
14
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
388%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16C:\Windows\System32\csrss.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Client Server Runtime Process
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\csrss.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\csrsrv.dll
c:\windows\system32\basesrv.dll
c:\windows\system32\winsrv.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
532chcp 437 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
692"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2452.10.1668992144\1644486106" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 7804 -prefMapHandle 7844 -prefsLen 37089 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {655b73bd-62e4-4124-bdc4-6b3f11f0605d} 2452 "\\.\pipe\gecko-crash-server-pipe.2452" 7784 1c6f19d0 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
780cmd.exe /C chcp 437 & wmic qfe get HotFixIDC:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1180"C:\Users\admin\AppData\Local\Temp\BrowserInstaller.exe" /NOINIT /S:C:\Users\admin\AppData\Local\Temp\setuparguments.iniC:\Users\admin\AppData\Local\Temp\BrowserInstaller.exe
irsetup.exe
User:
admin
Company:
TLauncher Inc.
Integrity Level:
HIGH
Description:
Installer of Browser Offers in TLauncher
Exit code:
0
Version:
4.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\browserinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1224C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ntmarta.dll
1380wmic qfe get HotFixIDC:\Windows\System32\wbem\WMIC.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1500systeminfoC:\Windows\System32\systeminfo.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Displays system information
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\systeminfo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1576cmd.exe /C chcp 437 & wmic os get osarchitectureC:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1592"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2452.9.669464512\1951480811" -parentBuildID 20230710165010 -prefsHandle 7852 -prefMapHandle 7828 -prefsLen 37089 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {69a56246-4030-46ce-a6ab-9b0c91fcd7ab} 2452 "\\.\pipe\gecko-crash-server-pipe.2452" 7808 125452e0 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
47 304
Read events
46 693
Write events
533
Delete events
78

Modification events

(PID) Process:(2452) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
A22DA35001000000
(PID) Process:(2060) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
A2E9A05001000000
(PID) Process:(2452) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB
Operation:delete valueName:installer.taskbarpin.win10.enabled
Value:
(PID) Process:(2452) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(2452) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(2452) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(2452) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(2452) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(2452) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(2452) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
Executable files
1 632
Suspicious files
3 389
Text files
1 481
Unknown types
0

Dropped files

PID
Process
Filename
Type
2452firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2452firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2452firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:10838BA4D091CD29EB56089222ECB443
SHA256:934225516EF688A07796A04C2358410D6F7238FD8056C261780E20B098F1189C
2452firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite-journalbinary
MD5:F7B5946BE77E0A7CB04BD24F5A2CC36E
SHA256:4BD76F8DC297AD9739E44CB9EAC2861C0D3AEBA3AA495467F89AC844DF388755
2452firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.initext
MD5:5A14BC3397EA072906B63D69FC704FEA
SHA256:03F45724EA1FE89E753AA76B40DE9078BFC9160AA1065ED9D4D98DA04B7FB3E7
2452firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
2452firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2452firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2452firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:10838BA4D091CD29EB56089222ECB443
SHA256:934225516EF688A07796A04C2358410D6F7238FD8056C261780E20B098F1189C
2452firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
76
TCP/UDP connections
220
DNS requests
206
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2452
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
text
90 b
whitelisted
2452
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/we2
US
binary
280 b
whitelisted
2452
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
2452
firefox.exe
POST
200
2.16.206.143:80
http://r10.o.lencr.org/
DE
binary
504 b
whitelisted
2452
firefox.exe
POST
2.16.206.143:80
http://r11.o.lencr.org/
DE
whitelisted
2452
firefox.exe
POST
200
2.16.206.143:80
http://r11.o.lencr.org/
DE
binary
504 b
whitelisted
2452
firefox.exe
POST
200
2.16.206.143:80
http://r10.o.lencr.org/
DE
binary
504 b
whitelisted
2452
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/we2
US
binary
279 b
whitelisted
2452
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/we2
US
binary
278 b
whitelisted
2452
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/s/wr3/UTA
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
2452
firefox.exe
104.20.36.13:80
tlauncher.org
CLOUDFLARENET
whitelisted
2452
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
2452
firefox.exe
34.117.188.166:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
2452
firefox.exe
142.250.184.195:80
o.pki.goog
GOOGLE
US
whitelisted
2452
firefox.exe
216.58.206.74:443
safebrowsing.googleapis.com
whitelisted
2452
firefox.exe
34.107.243.93:443
push.services.mozilla.com
GOOGLE
US
whitelisted
2452
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
tlauncher.org
  • 104.20.36.13
  • 104.20.37.13
  • 2606:4700:10::6814:250d
  • 2606:4700:10::6814:240d
unknown
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 23.215.0.132
  • 96.7.128.186
  • 96.7.128.192
  • 23.215.0.133
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
whitelisted
prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
whitelisted
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
3888
360-installer-bro.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
3888
360-installer-bro.exe
Misc activity
ET INFO Packed Executable Download
2300
javaw.exe
Potentially Bad Traffic
ET INFO Vulnerable Java Version 1.8.x Detected
2300
javaw.exe
Potentially Bad Traffic
ET INFO Vulnerable Java Version 1.8.x Detected
No debug info