URL:

https://files2.freedownloadmanager.org/6/latest/fdm_x64_setup.exe

Full analysis: https://app.any.run/tasks/75bc7f78-ee90-4da0-927e-423dfd93c1c7
Verdict: Malicious activity
Analysis date: July 27, 2024, 22:09:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

1F3278F30AC64DA44A79BC7F0CB1B437

SHA1:

0055192ABD106A15C2114152D2E06ECE61442EF8

SHA256:

10EFBD6CAF539B189BC4CC966A26E6EE37BB96BE58D9001B94E0FF9E958374B7

SSDEEP:

3:N8QbzKVELUXoCKGJNnqWP4A:2QbvwXiGbntP4A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • fdm_x64_setup.exe (PID: 8152)
      • fdm_x64_setup.exe (PID: 6336)
      • fdm_x64_setup.tmp (PID: 1996)
    • Uses Task Scheduler to run other applications

      • fdm_x64_setup.tmp (PID: 1996)
    • Changes the autorun value in the registry

      • fdm.exe (PID: 5808)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • fdm_x64_setup.exe (PID: 8152)
      • fdm_x64_setup.tmp (PID: 1996)
      • fdm_x64_setup.exe (PID: 6336)
    • Reads security settings of Internet Explorer

      • fdm_x64_setup.tmp (PID: 8124)
    • Reads the date of Windows installation

      • fdm_x64_setup.tmp (PID: 8124)
    • Reads the Windows owner or organization settings

      • fdm_x64_setup.tmp (PID: 1996)
    • Process drops legitimate windows executable

      • fdm_x64_setup.tmp (PID: 1996)
    • The process drops C-runtime libraries

      • fdm_x64_setup.tmp (PID: 1996)
    • Changes Internet Explorer settings (feature browser emulation)

      • fdm_x64_setup.tmp (PID: 1996)
    • Add new program in existing scheduled task

      • schtasks.exe (PID: 1952)
    • The process checks if it is being run in the virtual environment

      • fdm.exe (PID: 5808)
      • importwizard.exe (PID: 5732)
      • fdm.exe (PID: 5608)
      • importwizard.exe (PID: 7548)
    • The process executes via Task Scheduler

      • helperservice.exe (PID: 6860)
    • Searches for installed software

      • fdm5rhwin.exe (PID: 1120)
      • fdm5rhwin.exe (PID: 7888)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • fdm_x64_setup.tmp (PID: 1996)
    • Detected use of alternative data streams (AltDS)

      • fdm.exe (PID: 5608)
  • INFO

    • Checks proxy server information

      • slui.exe (PID: 6668)
      • slui.exe (PID: 1912)
      • fdm.exe (PID: 5608)
    • Application launched itself

      • firefox.exe (PID: 1176)
      • firefox.exe (PID: 4548)
      • msedge.exe (PID: 7900)
      • msedge.exe (PID: 7876)
      • firefox.exe (PID: 3600)
      • firefox.exe (PID: 6112)
    • Reads the software policy settings

      • slui.exe (PID: 6668)
      • slui.exe (PID: 1912)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 4548)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 4548)
      • msedge.exe (PID: 7900)
      • msedge.exe (PID: 7876)
      • firefox.exe (PID: 6112)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 4548)
    • The process uses the downloaded file

      • firefox.exe (PID: 4548)
    • Create files in a temporary directory

      • fdm_x64_setup.exe (PID: 8152)
      • fdm_x64_setup.exe (PID: 6336)
      • fdm_x64_setup.tmp (PID: 1996)
    • Checks supported languages

      • fdm_x64_setup.tmp (PID: 8124)
      • fdm_x64_setup.exe (PID: 8152)
      • fdm_x64_setup.exe (PID: 6336)
      • fdm_x64_setup.tmp (PID: 1996)
      • fdm.exe (PID: 5808)
      • helperservice.exe (PID: 6860)
      • importwizard.exe (PID: 5732)
      • fdm5rhwin.exe (PID: 7888)
      • fdm5rhwin.exe (PID: 1120)
      • identity_helper.exe (PID: 1388)
      • importwizard.exe (PID: 7548)
      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Reads the computer name

      • fdm_x64_setup.tmp (PID: 8124)
      • fdm_x64_setup.tmp (PID: 1996)
      • fdm.exe (PID: 5808)
      • identity_helper.exe (PID: 1388)
      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Process checks computer location settings

      • fdm_x64_setup.tmp (PID: 8124)
      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Creates files in the program directory

      • fdm_x64_setup.tmp (PID: 1996)
    • Dropped object may contain TOR URL's

      • fdm_x64_setup.tmp (PID: 1996)
    • Creates a software uninstall entry

      • fdm_x64_setup.tmp (PID: 1996)
    • Reads the machine GUID from the registry

      • fdm.exe (PID: 5808)
      • importwizard.exe (PID: 5732)
      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Creates files or folders in the user directory

      • fdm.exe (PID: 5808)
      • importwizard.exe (PID: 5732)
      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Reads Environment values

      • identity_helper.exe (PID: 1388)
    • Reads the time zone

      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Manual execution by a user

      • fdm.exe (PID: 3840)
      • firefox.exe (PID: 3600)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
245
Monitored processes
95
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe slui.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe fdm_x64_setup.exe fdm_x64_setup.tmp no specs fdm_x64_setup.exe fdm_x64_setup.tmp schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs helperservice.exe no specs fdm.exe conhost.exe no specs importwizard.exe no specs conhost.exe no specs msedge.exe fdm5rhwin.exe no specs conhost.exe no specs fdm5rhwin.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs netsh.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs fdm.exe importwizard.exe no specs conhost.exe no specs fdm.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
456"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2240 -parentBuildID 20240213221259 -prefsHandle 2236 -prefMapHandle 2224 -prefsLen 29501 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {52b01114-7a97-4e56-a502-abb936436c87} 6112 "\\.\pipe\gecko-crash-server-pipe.6112" 271ea282310 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
704"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x1e0,0x294,0x298,0x1e8,0x2a0,0x7ffefffe5fd8,0x7ffefffe5fe4,0x7ffefffe5ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1120"C:\Program Files\Softdeluxe\Free Download Manager\fdm5rhwin.exe" 21907CB0205CFF989F82C03684A01B86 phase2C:\Program Files\Softdeluxe\Free Download Manager\fdm5rhwin.exefdm_x64_setup.tmp
User:
admin
Company:
Softdeluxe
Integrity Level:
HIGH
Description:
Free Download Manager
Exit code:
1
Version:
6.24.0.5818
Modules
Images
c:\program files\softdeluxe\free download manager\fdm5rhwin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1176"C:\Program Files\Mozilla Firefox\firefox.exe" "https://files2.freedownloadmanager.org/6/latest/fdm_x64_setup.exe"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
1388"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=4268 --field-trial-handle=2228,i,11547966192194126884,17442087347149915557,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
1432"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5020 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5224 -prefMapHandle 4960 -prefsLen 35334 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4a3a9b27-8178-4d62-9240-2dcd0ece5808} 6112 "\\.\pipe\gecko-crash-server-pipe.6112" 2720048c510 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1716"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5456 --field-trial-handle=2380,i,11263693557521522708,162908331872350934,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1912C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1952"schtasks.exe" /change /tn FreeDownloadManagerHelperService /tr "\"C:\Program Files\Softdeluxe\Free Download Manager\helperservice.exe"\"C:\Windows\System32\schtasks.exefdm_x64_setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1964\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
52 083
Read events
51 917
Write events
162
Delete events
4

Modification events

(PID) Process:(1176) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
6D9F958701000000
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
AEF6978701000000
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
0
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
1
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Installer\308046B0AF4A39CB
Operation:delete valueName:installer.taskbarpin.win10.enabled
Value:
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
Executable files
357
Suspicious files
1 085
Text files
1 060
Unknown types
16

Dropped files

PID
Process
Filename
Type
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:2B75D45275133A2A65DB8BDCB4754B48
SHA256:690AC23F47C208944175EED497B4530A6B896BD58F61058335494812B226CC69
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:2B75D45275133A2A65DB8BDCB4754B48
SHA256:690AC23F47C208944175EED497B4530A6B896BD58F61058335494812B226CC69
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.binbinary
MD5:10CB0C67B96E749E8231AE5D1A5B6FFC
SHA256:DA3A1FBFAD79C074C74D3DF2E94E1CCE96611D3393F59DBD01B5C8688DD1C610
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
62
TCP/UDP connections
204
DNS requests
287
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4548
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4548
firefox.exe
POST
200
142.250.186.35:80
http://o.pki.goog/wr2
unknown
4548
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
4548
firefox.exe
POST
200
95.100.146.41:80
http://r11.o.lencr.org/
unknown
4548
firefox.exe
POST
200
95.100.146.41:80
http://r11.o.lencr.org/
unknown
4548
firefox.exe
POST
200
95.100.146.41:80
http://r3.o.lencr.org/
unknown
4548
firefox.exe
POST
200
95.100.146.66:80
http://r10.o.lencr.org/
unknown
4548
firefox.exe
POST
200
95.100.146.66:80
http://r10.o.lencr.org/
unknown
4548
firefox.exe
POST
200
104.18.38.233:80
http://ocsp.sectigo.com/
unknown
4548
firefox.exe
POST
200
95.100.146.66:80
http://r10.o.lencr.org/
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
996
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5368
SearchApp.exe
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6932
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6012
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5368
SearchApp.exe
95.100.146.32:443
www.bing.com
Akamai International B.V.
CZ
unknown
456
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
6284
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6668
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 95.100.146.32
  • 95.100.146.34
  • 95.100.146.8
  • 95.100.146.16
  • 2.23.209.182
  • 2.23.209.179
  • 2.23.209.133
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.185
  • 2.23.209.130
  • 95.100.146.33
whitelisted
google.com
  • 142.250.184.238
whitelisted
files2.freedownloadmanager.org
  • 208.88.224.211
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
example.org
  • 93.184.215.14
whitelisted

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET DNS Query for .cc TLD
Potentially Bad Traffic
ET DNS Query for .cc TLD
Process
Message
fdm.exe
qrc:/qml_ui/desktop/Dialogs/TuneDialogElements/DownloadsList.qml:178:21: QML BusyIndicator: Possible anchor loop detected on horizontal anchor.
fdm.exe
qrc:/qml_ui/desktop/main.qml:969:5: QML DownloadExpiredDialog: Binding loop detected for property "implicitHeight"
fdm.exe
qrc:/qml_ui/common/Tools/UiSettingsTools.qml:16:5: QML Settings: The Settings type from Qt.labs.settings is deprecated and will be removed in a future release. Please use the one from QtCore instead.
fdm.exe
qrc:/qml_ui/common/WindowStateSaver.qml:14:5: QML Settings: The Settings type from Qt.labs.settings is deprecated and will be removed in a future release. Please use the one from QtCore instead.
fdm.exe
qrc:/qml_ui/desktop/main.qml:369: TypeError: Cannot call method 'open' of null