URL:

https://files2.freedownloadmanager.org/6/latest/fdm_x64_setup.exe

Full analysis: https://app.any.run/tasks/75bc7f78-ee90-4da0-927e-423dfd93c1c7
Verdict: Malicious activity
Analysis date: July 27, 2024, 22:09:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

1F3278F30AC64DA44A79BC7F0CB1B437

SHA1:

0055192ABD106A15C2114152D2E06ECE61442EF8

SHA256:

10EFBD6CAF539B189BC4CC966A26E6EE37BB96BE58D9001B94E0FF9E958374B7

SSDEEP:

3:N8QbzKVELUXoCKGJNnqWP4A:2QbvwXiGbntP4A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • fdm_x64_setup.exe (PID: 6336)
      • fdm_x64_setup.exe (PID: 8152)
      • fdm_x64_setup.tmp (PID: 1996)
    • Uses Task Scheduler to run other applications

      • fdm_x64_setup.tmp (PID: 1996)
    • Changes the autorun value in the registry

      • fdm.exe (PID: 5808)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • fdm_x64_setup.tmp (PID: 8124)
    • Reads security settings of Internet Explorer

      • fdm_x64_setup.tmp (PID: 8124)
    • Executable content was dropped or overwritten

      • fdm_x64_setup.exe (PID: 8152)
      • fdm_x64_setup.exe (PID: 6336)
      • fdm_x64_setup.tmp (PID: 1996)
    • The process drops C-runtime libraries

      • fdm_x64_setup.tmp (PID: 1996)
    • Process drops legitimate windows executable

      • fdm_x64_setup.tmp (PID: 1996)
    • The process executes via Task Scheduler

      • helperservice.exe (PID: 6860)
    • Add new program in existing scheduled task

      • schtasks.exe (PID: 1952)
    • Changes Internet Explorer settings (feature browser emulation)

      • fdm_x64_setup.tmp (PID: 1996)
    • The process checks if it is being run in the virtual environment

      • fdm.exe (PID: 5808)
      • importwizard.exe (PID: 5732)
      • importwizard.exe (PID: 7548)
      • fdm.exe (PID: 5608)
    • Reads the Windows owner or organization settings

      • fdm_x64_setup.tmp (PID: 1996)
    • Searches for installed software

      • fdm5rhwin.exe (PID: 1120)
      • fdm5rhwin.exe (PID: 7888)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • fdm_x64_setup.tmp (PID: 1996)
    • Detected use of alternative data streams (AltDS)

      • fdm.exe (PID: 5608)
  • INFO

    • Checks proxy server information

      • slui.exe (PID: 6668)
      • slui.exe (PID: 1912)
      • fdm.exe (PID: 5608)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 4548)
      • msedge.exe (PID: 7900)
      • msedge.exe (PID: 7876)
      • firefox.exe (PID: 6112)
    • Create files in a temporary directory

      • fdm_x64_setup.exe (PID: 8152)
      • fdm_x64_setup.exe (PID: 6336)
      • fdm_x64_setup.tmp (PID: 1996)
    • The process uses the downloaded file

      • firefox.exe (PID: 4548)
    • Checks supported languages

      • fdm_x64_setup.exe (PID: 8152)
      • fdm_x64_setup.tmp (PID: 1996)
      • fdm_x64_setup.tmp (PID: 8124)
      • fdm_x64_setup.exe (PID: 6336)
      • fdm.exe (PID: 5808)
      • helperservice.exe (PID: 6860)
      • importwizard.exe (PID: 5732)
      • fdm5rhwin.exe (PID: 7888)
      • fdm5rhwin.exe (PID: 1120)
      • identity_helper.exe (PID: 1388)
      • importwizard.exe (PID: 7548)
      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Application launched itself

      • firefox.exe (PID: 1176)
      • firefox.exe (PID: 4548)
      • msedge.exe (PID: 7876)
      • msedge.exe (PID: 7900)
      • firefox.exe (PID: 3600)
      • firefox.exe (PID: 6112)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 4548)
    • Reads the computer name

      • fdm_x64_setup.tmp (PID: 1996)
      • fdm_x64_setup.tmp (PID: 8124)
      • fdm.exe (PID: 5808)
      • fdm.exe (PID: 5608)
      • identity_helper.exe (PID: 1388)
      • fdm.exe (PID: 3840)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 4548)
    • Reads the software policy settings

      • slui.exe (PID: 6668)
      • slui.exe (PID: 1912)
    • Process checks computer location settings

      • fdm_x64_setup.tmp (PID: 8124)
      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Creates files in the program directory

      • fdm_x64_setup.tmp (PID: 1996)
    • Dropped object may contain TOR URL's

      • fdm_x64_setup.tmp (PID: 1996)
    • Creates a software uninstall entry

      • fdm_x64_setup.tmp (PID: 1996)
    • Reads the machine GUID from the registry

      • fdm.exe (PID: 5808)
      • importwizard.exe (PID: 5732)
      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Creates files or folders in the user directory

      • fdm.exe (PID: 5808)
      • importwizard.exe (PID: 5732)
      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Reads the time zone

      • fdm.exe (PID: 5608)
      • fdm.exe (PID: 3840)
    • Manual execution by a user

      • fdm.exe (PID: 3840)
      • firefox.exe (PID: 3600)
    • Reads Environment values

      • identity_helper.exe (PID: 1388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
245
Monitored processes
95
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe slui.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe fdm_x64_setup.exe fdm_x64_setup.tmp no specs fdm_x64_setup.exe fdm_x64_setup.tmp schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs helperservice.exe no specs fdm.exe conhost.exe no specs importwizard.exe no specs conhost.exe no specs msedge.exe fdm5rhwin.exe no specs conhost.exe no specs fdm5rhwin.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs netsh.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs fdm.exe importwizard.exe no specs conhost.exe no specs fdm.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
456"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2240 -parentBuildID 20240213221259 -prefsHandle 2236 -prefMapHandle 2224 -prefsLen 29501 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {52b01114-7a97-4e56-a502-abb936436c87} 6112 "\\.\pipe\gecko-crash-server-pipe.6112" 271ea282310 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
704"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x1e0,0x294,0x298,0x1e8,0x2a0,0x7ffefffe5fd8,0x7ffefffe5fe4,0x7ffefffe5ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1120"C:\Program Files\Softdeluxe\Free Download Manager\fdm5rhwin.exe" 21907CB0205CFF989F82C03684A01B86 phase2C:\Program Files\Softdeluxe\Free Download Manager\fdm5rhwin.exefdm_x64_setup.tmp
User:
admin
Company:
Softdeluxe
Integrity Level:
HIGH
Description:
Free Download Manager
Exit code:
1
Version:
6.24.0.5818
Modules
Images
c:\program files\softdeluxe\free download manager\fdm5rhwin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1176"C:\Program Files\Mozilla Firefox\firefox.exe" "https://files2.freedownloadmanager.org/6/latest/fdm_x64_setup.exe"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
1388"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=4268 --field-trial-handle=2228,i,11547966192194126884,17442087347149915557,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
1432"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5020 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5224 -prefMapHandle 4960 -prefsLen 35334 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4a3a9b27-8178-4d62-9240-2dcd0ece5808} 6112 "\\.\pipe\gecko-crash-server-pipe.6112" 2720048c510 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1716"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5456 --field-trial-handle=2380,i,11263693557521522708,162908331872350934,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1912C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1952"schtasks.exe" /change /tn FreeDownloadManagerHelperService /tr "\"C:\Program Files\Softdeluxe\Free Download Manager\helperservice.exe"\"C:\Windows\System32\schtasks.exefdm_x64_setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1964\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
52 083
Read events
51 917
Write events
162
Delete events
4

Modification events

(PID) Process:(1176) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
6D9F958701000000
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
AEF6978701000000
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
0
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
1
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Installer\308046B0AF4A39CB
Operation:delete valueName:installer.taskbarpin.win10.enabled
Value:
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(4548) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
Executable files
357
Suspicious files
1 085
Text files
1 060
Unknown types
16

Dropped files

PID
Process
Filename
Type
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:2B75D45275133A2A65DB8BDCB4754B48
SHA256:690AC23F47C208944175EED497B4530A6B896BD58F61058335494812B226CC69
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:2B75D45275133A2A65DB8BDCB4754B48
SHA256:690AC23F47C208944175EED497B4530A6B896BD58F61058335494812B226CC69
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4548firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:297E88D7CEB26E549254EC875649F4EB
SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
4548firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
62
TCP/UDP connections
204
DNS requests
287
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4548
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4548
firefox.exe
POST
200
142.250.186.35:80
http://o.pki.goog/wr2
unknown
unknown
4548
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
4548
firefox.exe
POST
200
95.100.146.41:80
http://r3.o.lencr.org/
unknown
unknown
4548
firefox.exe
POST
200
95.100.146.66:80
http://r10.o.lencr.org/
unknown
unknown
4548
firefox.exe
POST
200
95.100.146.41:80
http://r11.o.lencr.org/
unknown
unknown
4548
firefox.exe
POST
200
95.100.146.41:80
http://r11.o.lencr.org/
unknown
unknown
4548
firefox.exe
POST
200
95.100.146.66:80
http://r10.o.lencr.org/
unknown
unknown
4548
firefox.exe
POST
200
104.18.38.233:80
http://ocsp.sectigo.com/
unknown
unknown
4548
firefox.exe
POST
200
95.100.146.66:80
http://r10.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
996
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5368
SearchApp.exe
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6932
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6012
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5368
SearchApp.exe
95.100.146.32:443
www.bing.com
Akamai International B.V.
CZ
unknown
456
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
6284
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6668
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 95.100.146.32
  • 95.100.146.34
  • 95.100.146.8
  • 95.100.146.16
  • 2.23.209.182
  • 2.23.209.179
  • 2.23.209.133
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.185
  • 2.23.209.130
  • 95.100.146.33
whitelisted
google.com
  • 142.250.184.238
whitelisted
files2.freedownloadmanager.org
  • 208.88.224.211
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
example.org
  • 93.184.215.14
whitelisted

Threats

PID
Process
Class
Message
4788
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
4788
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
Process
Message
fdm.exe
qrc:/qml_ui/desktop/Dialogs/TuneDialogElements/DownloadsList.qml:178:21: QML BusyIndicator: Possible anchor loop detected on horizontal anchor.
fdm.exe
qrc:/qml_ui/desktop/main.qml:969:5: QML DownloadExpiredDialog: Binding loop detected for property "implicitHeight"
fdm.exe
qrc:/qml_ui/common/Tools/UiSettingsTools.qml:16:5: QML Settings: The Settings type from Qt.labs.settings is deprecated and will be removed in a future release. Please use the one from QtCore instead.
fdm.exe
qrc:/qml_ui/common/WindowStateSaver.qml:14:5: QML Settings: The Settings type from Qt.labs.settings is deprecated and will be removed in a future release. Please use the one from QtCore instead.
fdm.exe
qrc:/qml_ui/desktop/main.qml:369: TypeError: Cannot call method 'open' of null