| URL: | https://bam.nr-data.net/ |
| Full analysis: | https://app.any.run/tasks/98f80315-0d73-4661-a99b-323403db532a |
| Verdict: | Malicious activity |
| Analysis date: | September 19, 2023, 21:02:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 86EF37AE8668FE30DB8778E180F152A8 |
| SHA1: | B4A4C2ED5BCBABD02BD05A8E4A641268F5361F57 |
| SHA256: | 0B77CF4E24CFF91777DE6ABA9034CE31B6060F4D75B915C05A4215220107EEA9 |
| SSDEEP: | 3:N84EHs:2JHs |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 596 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.2.384145226\455439516" -childID 1 -isForBrowser -prefsHandle 1792 -prefMapHandle 2028 -prefsLen 24320 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1e560532-6a95-4a46-b491-92926a619ec2} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 2044 11b5d560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1000 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://bam.nr-data.net/ | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1700 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.3.613954573\1369985234" -childID 2 -isForBrowser -prefsHandle 2856 -prefMapHandle 2852 -prefsLen 33872 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {34d124de-58df-4f7c-a3bc-6196328e816f} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 2868 1f9ec280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1800 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.0.1173435387\1920998556" -parentBuildID 20230710165010 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 28025 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {960c729a-b724-44b2-91e3-91244c3c8660} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 1180 dae2870 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2412 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.1.465863403\1301930459" -parentBuildID 20230710165010 -prefsHandle 1392 -prefMapHandle 1384 -prefsLen 28102 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {39db6516-9002-41fc-af75-9c3d64e3f653} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 1412 da241a0 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3296 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.6.2071058400\1440093846" -childID 5 -isForBrowser -prefsHandle 3896 -prefMapHandle 3900 -prefsLen 29011 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b69f691a-79a7-4877-9684-6d4b497e4900} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 3884 20ee5f70 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3556 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.7.1794065712\259833837" -childID 6 -isForBrowser -prefsHandle 4032 -prefMapHandle 4016 -prefsLen 33948 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8c9a5e39-c7c9-49dc-a2bc-29fa86382e7e} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 3716 22044110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3648 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://bam.nr-data.net/" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3680 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.5.2120427529\1400694815" -childID 4 -isForBrowser -prefsHandle 3564 -prefMapHandle 3612 -prefsLen 29011 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {505e9f8a-22b1-4f61-8db8-30bc73135383} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 3736 20ee5e00 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 4036 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.4.213780302\408908987" -childID 3 -isForBrowser -prefsHandle 3556 -prefMapHandle 2976 -prefsLen 29011 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {990e37ae-ca7f-4b8e-9b9f-6360272638e9} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 3560 15829b20 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (3648) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 815441AB02000000 | |||
| (PID) Process: | (1000) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: B73F42AB02000000 | |||
| (PID) Process: | (1000) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (1000) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (1000) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (1000) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (1000) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (1000) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (1000) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (1000) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: EA362D0F13B0D901 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1000 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 1000 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite-journal | binary | |
MD5:32DA5BA82EF21B8C7B7D9D4557FB85E2 | SHA256:350B20426A57515D0D0F3B8EE54EE1452A69A417ACF15AFC418208C9DD8EDDB3 | |||
| 1000 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.tmp | binary | |
MD5:63B1BB87284EFE954E1C3AE390E7EE44 | SHA256:B017EE25A7F5C09EB4BF359CA721D67E6E9D9F95F8CE6F741D47F33BDE6EF73A | |||
| 1000 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.bin | binary | |
MD5:63B1BB87284EFE954E1C3AE390E7EE44 | SHA256:B017EE25A7F5C09EB4BF359CA721D67E6E9D9F95F8CE6F741D47F33BDE6EF73A | |||
| 1000 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journal | binary | |
MD5:FBCC689B1A7BD3D737F2DC47927198D0 | SHA256:1B9EDCA6E2DD6746B8061FE0DD740194A156FC0C77A3597C9153B2EB649492FF | |||
| 1000 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.tmp | binary | |
MD5:0CD476A42E8DA7EE64F4889578AB6D87 | SHA256:6DDB22517E018A2434CE8AF6CE0A0FBE4A2A449637746101893EF6AC2049682D | |||
| 1000 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1000 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1000 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal | — | |
MD5:— | SHA256:— | |||
| 1000 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1000 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
1000 | firefox.exe | POST | 200 | 184.24.77.203:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | unknown |
1000 | firefox.exe | POST | 200 | 184.24.77.203:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | unknown |
1000 | firefox.exe | POST | 200 | 216.58.212.35:80 | http://ocsp.pki.goog/gts1c3 | unknown | der | 471 b | unknown |
1000 | firefox.exe | GET | 200 | 23.200.86.251:80 | http://ciscobinary.openh264.org/openh264-win32-31c4d2e4a037526fd30d4e5c39f60885986cf865.zip | unknown | compressed | 461 Kb | unknown |
1000 | firefox.exe | POST | 200 | 184.24.77.203:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | unknown |
1000 | firefox.exe | POST | 200 | 216.58.212.35:80 | http://ocsp.pki.goog/gts1c3 | unknown | der | 471 b | unknown |
1000 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | der | 471 b | unknown |
1000 | firefox.exe | POST | 200 | 184.24.77.203:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | unknown |
1000 | firefox.exe | POST | 200 | 184.24.77.203:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1000 | firefox.exe | 162.247.241.14:443 | bam.nr-data.net | NEWRELIC-AS-1 | US | unknown |
1000 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
1000 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1000 | firefox.exe | 44.214.229.86:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
1000 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
1000 | firefox.exe | 216.58.206.42:443 | safebrowsing.googleapis.com | GOOGLE | US | whitelisted |
1000 | firefox.exe | 34.117.65.55:443 | push.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
1000 | firefox.exe | 184.24.77.203:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
bam.nr-data.net |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
bam.nr-data.net.cdn.cloudflare.net |
| unknown |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
example.org |
| whitelisted |
ipv4only.arpa |
| unknown |
firefox.settings.services.mozilla.com |
| whitelisted |