URL:

https://archive.org/download/vbcable-cd-pack-setup-v-2152/VBCable_CD_PackSetup_v2152.zip/VBCable_CD_PackSetup.exe

Full analysis: https://app.any.run/tasks/aee39ac3-9452-4dbd-b1a2-50f0212a9a08
Verdict: Malicious activity
Analysis date: July 24, 2024, 19:11:07
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

FB84D30D99184A12CBADB53396414992

SHA1:

20D875727DB00A6524159EF4497AB98B9E9C8C05

SHA256:

0B56309B3AA1AC089311817DCE33B8873FD4BBAFDD0E87CCA334EFC57113B031

SSDEEP:

3:N8MFXJ2mUHRQVuqssGZAy4XUCyuJsGZAykA:2MFXmQVuqs+y4ErG+ykA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • VBCable_CD_PackSetup.exe (PID: 7860)
      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • drvinst.exe (PID: 8032)
      • drvinst.exe (PID: 4040)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
      • drvinst.exe (PID: 7220)
      • drvinst.exe (PID: 7528)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • VBCable_CD_PackSetup.exe (PID: 7860)
      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • drvinst.exe (PID: 8032)
      • drvinst.exe (PID: 4040)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
      • drvinst.exe (PID: 7220)
      • drvinst.exe (PID: 7528)
    • Drops a system driver (possible attempt to evade defenses)

      • VBCable_CD_PackSetup.exe (PID: 7860)
      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • drvinst.exe (PID: 8032)
      • drvinst.exe (PID: 4040)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
      • drvinst.exe (PID: 7220)
      • drvinst.exe (PID: 7528)
    • Reads security settings of Internet Explorer

      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
      • VBCable_CD_PackSetup.exe (PID: 7860)
      • ShellExperienceHost.exe (PID: 7552)
    • Checks Windows Trust Settings

      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • drvinst.exe (PID: 8032)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
      • drvinst.exe (PID: 7220)
    • Creates files in the driver directory

      • drvinst.exe (PID: 8032)
      • drvinst.exe (PID: 4040)
      • drvinst.exe (PID: 7220)
      • drvinst.exe (PID: 7528)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 4040)
      • drvinst.exe (PID: 7528)
    • Creates a software uninstall entry

      • VBCable_CD_PackSetup.exe (PID: 7860)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 4840)
      • firefox.exe (PID: 5684)
      • msedge.exe (PID: 6340)
      • msedge.exe (PID: 7868)
    • The process uses the downloaded file

      • firefox.exe (PID: 4840)
      • VBCable_CD_PackSetup.exe (PID: 7860)
    • Creates files in the program directory

      • VBCable_CD_PackSetup.exe (PID: 7860)
      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
    • Reads the computer name

      • VBCable_CD_PackSetup.exe (PID: 7860)
      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
      • drvinst.exe (PID: 8032)
      • drvinst.exe (PID: 4040)
      • drvinst.exe (PID: 7220)
      • drvinst.exe (PID: 7528)
      • TextInputHost.exe (PID: 8900)
      • identity_helper.exe (PID: 8324)
      • ShellExperienceHost.exe (PID: 7552)
    • Checks supported languages

      • VBCable_CD_PackSetup.exe (PID: 7860)
      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • drvinst.exe (PID: 8032)
      • drvinst.exe (PID: 4040)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
      • drvinst.exe (PID: 7528)
      • drvinst.exe (PID: 7220)
      • TextInputHost.exe (PID: 8900)
      • identity_helper.exe (PID: 8324)
      • ShellExperienceHost.exe (PID: 7552)
    • Reads the software policy settings

      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • drvinst.exe (PID: 8032)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
      • drvinst.exe (PID: 7220)
      • slui.exe (PID: 7904)
    • Reads the machine GUID from the registry

      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • drvinst.exe (PID: 8032)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
      • drvinst.exe (PID: 7220)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 4840)
      • VBCable_CD_PackSetup.exe (PID: 7860)
      • msedge.exe (PID: 6340)
      • msedge.exe (PID: 7868)
    • Create files in a temporary directory

      • VBCABLE_C_Setup_x64.exe (PID: 7944)
      • VBCABLE_D_Setup_x64.exe (PID: 8156)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 4840)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 4840)
    • Creates files or folders in the user directory

      • VBCable_CD_PackSetup.exe (PID: 7860)
    • Manual execution by a user

      • msedge.exe (PID: 7868)
      • rundll32.exe (PID: 7600)
    • Reads Environment values

      • identity_helper.exe (PID: 8324)
    • Checks proxy server information

      • slui.exe (PID: 7904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
207
Monitored processes
59
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe vbcable_cd_packsetup.exe no specs vbcable_cd_packsetup.exe vbcable_c_setup_x64.exe drvinst.exe drvinst.exe vbcable_d_setup_x64.exe drvinst.exe drvinst.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs textinputhost.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe no specs shellexperiencehost.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2216 -parentBuildID 20240213221259 -prefsHandle 2208 -prefMapHandle 2204 -prefsLen 30537 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b39c2a5c-24e8-4a78-8802-0639bd70e357} 4840 "\\.\pipe\gecko-crash-server-pipe.4840" 23b87883d10 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1148"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5760 -childID 4 -isForBrowser -prefsHandle 5776 -prefMapHandle 5784 -prefsLen 31207 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {232a72ba-fe7d-4525-b52f-dafd77301d31} 4840 "\\.\pipe\gecko-crash-server-pipe.4840" 23b9d38a850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1320"C:\Users\admin\Downloads\VBCable_CD_PackSetup.exe" C:\Users\admin\Downloads\VBCable_CD_PackSetup.exefirefox.exe
User:
admin
Company:
VB-AUDIO Software
Integrity Level:
MEDIUM
Description:
VB-AUDIO CABLE C+D Installer
Exit code:
3221226540
Version:
2, 1, 5, 2
Modules
Images
c:\users\admin\downloads\vbcable_cd_packsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1772"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1796 -parentBuildID 20240213221259 -prefsHandle 1736 -prefMapHandle 1716 -prefsLen 30537 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a62266b7-294b-4a05-9bd2-ea126c9d07b9} 4840 "\\.\pipe\gecko-crash-server-pipe.4840" 23b936c3010 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2228"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6096 -childID 6 -isForBrowser -prefsHandle 6104 -prefMapHandle 6108 -prefsLen 31207 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {182d4a5f-a5cb-4e8c-9f56-efb746eeb524} 4840 "\\.\pipe\gecko-crash-server-pipe.4840" 23b9d38ad90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3472"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3680 --field-trial-handle=2304,i,9148612453680373201,8775173206808340754,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3484"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2372 --field-trial-handle=2376,i,2278261248393160149,1816172580105695025,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3652"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4400 -childID 2 -isForBrowser -prefsHandle 4392 -prefMapHandle 4388 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {062883b8-85e4-49d3-b5bb-355b5ade5d40} 4840 "\\.\pipe\gecko-crash-server-pipe.4840" 23b9895d4d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3704"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4148 --field-trial-handle=2304,i,9148612453680373201,8775173206808340754,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4040DrvInst.exe "2" "211" "ROOT\MEDIA\0000" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:3beb73af0c48fa1f:VBCableInst:2.1.5.0:vbaudio101wdmcablec," "466fcbd9b" "00000000000001D8"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
Total events
46 366
Read events
44 992
Write events
1 358
Delete events
16

Modification events

(PID) Process:(5684) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
39D608C400000000
(PID) Process:(4840) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
5F170AC400000000
(PID) Process:(4840) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
0
(PID) Process:(4840) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
1
(PID) Process:(4840) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Installer\308046B0AF4A39CB
Operation:delete valueName:installer.taskbarpin.win10.enabled
Value:
(PID) Process:(4840) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(4840) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(4840) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(4840) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(4840) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
Executable files
45
Suspicious files
249
Text files
129
Unknown types
50

Dropped files

PID
Process
Filename
Type
4840firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4840firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
4840firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4840firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
4840firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4840firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.binbinary
MD5:04376FDEB670785966CFF083BA15A3B2
SHA256:6731D5A6ACFC9BD49C22D8DE2246EBDFBE21888B01AD2EDA5C88B3EA743C53DB
4840firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4840firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:DB6FF84E344D74420F318F3FB87C0301
SHA256:0010CAA8838077871C70C71DC25B55827A98F1E24824B5A88B76EF9452C1AA56
4840firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4840firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
137
DNS requests
180
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4840
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4840
firefox.exe
POST
200
184.24.77.44:80
http://r11.o.lencr.org/
unknown
unknown
4840
firefox.exe
POST
200
184.24.77.44:80
http://r11.o.lencr.org/
unknown
unknown
4840
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
4840
firefox.exe
POST
200
184.24.77.52:80
http://r3.o.lencr.org/
unknown
unknown
4840
firefox.exe
POST
200
184.24.77.61:80
http://r10.o.lencr.org/
unknown
unknown
4840
firefox.exe
POST
200
184.24.77.61:80
http://r10.o.lencr.org/
unknown
unknown
4840
firefox.exe
POST
200
184.24.77.44:80
http://r10.o.lencr.org/
unknown
unknown
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
unknown
4840
firefox.exe
POST
200
184.24.77.52:80
http://r3.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
6012
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1552
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3656
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4204
svchost.exe
4.209.32.67:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4840
firefox.exe
172.217.18.106:443
safebrowsing.googleapis.com
whitelisted
4840
firefox.exe
34.107.243.93:443
push.services.mozilla.com
unknown
4840
firefox.exe
34.117.188.166:443
contile.services.mozilla.com
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 216.58.206.78
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
archive.org
  • 207.241.224.2
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.215.14
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
whitelisted
prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
unknown

Threats

No threats detected
No debug info