URL:

https://bam.nr-data.net/

Full analysis: https://app.any.run/tasks/98f80315-0d73-4661-a99b-323403db532a
Verdict: Malicious activity
Analysis date: September 19, 2023, 21:02:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

86EF37AE8668FE30DB8778E180F152A8

SHA1:

B4A4C2ED5BCBABD02BD05A8E4A641268F5361F57

SHA256:

0B77CF4E24CFF91777DE6ABA9034CE31B6060F4D75B915C05A4215220107EEA9

SSDEEP:

3:N84EHs:2JHs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • firefox.exe (PID: 3648)
      • firefox.exe (PID: 1000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
10
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
596"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.2.384145226\455439516" -childID 1 -isForBrowser -prefsHandle 1792 -prefMapHandle 2028 -prefsLen 24320 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1e560532-6a95-4a46-b491-92926a619ec2} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 2044 11b5d560 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1000"C:\Program Files\Mozilla Firefox\firefox.exe" https://bam.nr-data.net/C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\msvcrt.dll
1700"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.3.613954573\1369985234" -childID 2 -isForBrowser -prefsHandle 2856 -prefMapHandle 2852 -prefsLen 33872 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {34d124de-58df-4f7c-a3bc-6196328e816f} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 2868 1f9ec280 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\vcruntime140.dll
1800"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.0.1173435387\1920998556" -parentBuildID 20230710165010 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 28025 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {960c729a-b724-44b2-91e3-91244c3c8660} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 1180 dae2870 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2412"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.1.465863403\1301930459" -parentBuildID 20230710165010 -prefsHandle 1392 -prefMapHandle 1384 -prefsLen 28102 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {39db6516-9002-41fc-af75-9c3d64e3f653} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 1412 da241a0 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\vcruntime140.dll
3296"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.6.2071058400\1440093846" -childID 5 -isForBrowser -prefsHandle 3896 -prefMapHandle 3900 -prefsLen 29011 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b69f691a-79a7-4877-9684-6d4b497e4900} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 3884 20ee5f70 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3556"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.7.1794065712\259833837" -childID 6 -isForBrowser -prefsHandle 4032 -prefMapHandle 4016 -prefsLen 33948 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8c9a5e39-c7c9-49dc-a2bc-29fa86382e7e} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 3716 22044110 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3648"C:\Program Files\Mozilla Firefox\firefox.exe" "https://bam.nr-data.net/"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3680"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.5.2120427529\1400694815" -childID 4 -isForBrowser -prefsHandle 3564 -prefMapHandle 3612 -prefsLen 29011 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {505e9f8a-22b1-4f61-8db8-30bc73135383} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 3736 20ee5e00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
4036"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.4.213780302\408908987" -childID 3 -isForBrowser -prefsHandle 3556 -prefMapHandle 2976 -prefsLen 29011 -prefMapSize 243955 -jsInitHandle 872 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {990e37ae-ca7f-4b8e-9b9f-6360272638e9} 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 3560 15829b20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
9 553
Read events
9 517
Write events
36
Delete events
0

Modification events

(PID) Process:(3648) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
815441AB02000000
(PID) Process:(1000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
B73F42AB02000000
(PID) Process:(1000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(1000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(1000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(1000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(1000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(1000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(1000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(1000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
EA362D0F13B0D901
Executable files
2
Suspicious files
108
Text files
68
Unknown types
0

Dropped files

PID
Process
Filename
Type
1000firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
1000firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite-journalbinary
MD5:32DA5BA82EF21B8C7B7D9D4557FB85E2
SHA256:350B20426A57515D0D0F3B8EE54EE1452A69A417ACF15AFC418208C9DD8EDDB3
1000firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.tmpbinary
MD5:63B1BB87284EFE954E1C3AE390E7EE44
SHA256:B017EE25A7F5C09EB4BF359CA721D67E6E9D9F95F8CE6F741D47F33BDE6EF73A
1000firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.binbinary
MD5:63B1BB87284EFE954E1C3AE390E7EE44
SHA256:B017EE25A7F5C09EB4BF359CA721D67E6E9D9F95F8CE6F741D47F33BDE6EF73A
1000firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journalbinary
MD5:FBCC689B1A7BD3D737F2DC47927198D0
SHA256:1B9EDCA6E2DD6746B8061FE0DD740194A156FC0C77A3597C9153B2EB649492FF
1000firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.tmpbinary
MD5:0CD476A42E8DA7EE64F4889578AB6D87
SHA256:6DDB22517E018A2434CE8AF6CE0A0FBE4A2A449637746101893EF6AC2049682D
1000firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
1000firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
1000firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
MD5:
SHA256:
1000firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
52
DNS requests
112
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1000
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
1000
firefox.exe
POST
200
184.24.77.203:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
1000
firefox.exe
POST
200
184.24.77.203:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
1000
firefox.exe
POST
200
216.58.212.35:80
http://ocsp.pki.goog/gts1c3
unknown
der
471 b
unknown
1000
firefox.exe
GET
200
23.200.86.251:80
http://ciscobinary.openh264.org/openh264-win32-31c4d2e4a037526fd30d4e5c39f60885986cf865.zip
unknown
compressed
461 Kb
unknown
1000
firefox.exe
POST
200
184.24.77.203:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
1000
firefox.exe
POST
200
216.58.212.35:80
http://ocsp.pki.goog/gts1c3
unknown
der
471 b
unknown
1000
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
der
471 b
unknown
1000
firefox.exe
POST
200
184.24.77.203:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
1000
firefox.exe
POST
200
184.24.77.203:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1000
firefox.exe
162.247.241.14:443
bam.nr-data.net
NEWRELIC-AS-1
US
unknown
1000
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
1000
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
4
System
192.168.100.255:138
whitelisted
1000
firefox.exe
44.214.229.86:443
spocs.getpocket.com
AMAZON-AES
US
unknown
1000
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
unknown
1000
firefox.exe
216.58.206.42:443
safebrowsing.googleapis.com
GOOGLE
US
whitelisted
1000
firefox.exe
34.117.65.55:443
push.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
1000
firefox.exe
184.24.77.203:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
bam.nr-data.net
  • 162.247.241.14
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
bam.nr-data.net.cdn.cloudflare.net
  • 162.247.241.14
unknown
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
spocs.getpocket.com
  • 44.214.229.86
  • 184.72.95.230
  • 34.197.137.200
  • 18.215.75.185
shared
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 18.215.75.185
  • 34.197.137.200
  • 184.72.95.230
  • 44.214.229.86
shared
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
unknown
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted

Threats

No threats detected
No debug info