analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://anonfiles.com/zaH2t8i0y3/GodsEye_zip

Full analysis: https://app.any.run/tasks/ab636df2-a097-494b-8943-7ce99817d750
Verdict: Malicious activity
Analysis date: May 20, 2022, 21:40:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

3438BF5213CC5FD6C9DC91FF2BC0C42E

SHA1:

B51DA5D725E3DADC07BF748ABB8A6F5FCEF9143E

SHA256:

1B6C50621B0D54195242D854A54A925A6410107A3C406405B9B2318265F92CA0

SSDEEP:

3:N8M2EJ5Kg+0MV:2M2oUglMV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2840)
      • firefox.exe (PID: 3252)
      • chrome.exe (PID: 2652)
    • Application was dropped or rewritten from another process

      • GodsEye.exe (PID: 3864)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3612)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2840)
      • GodsEye.exe (PID: 3864)
    • Reads the computer name

      • WinRAR.exe (PID: 2840)
      • GodsEye.exe (PID: 3864)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2840)
      • firefox.exe (PID: 3252)
      • chrome.exe (PID: 2652)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2840)
      • firefox.exe (PID: 3252)
      • chrome.exe (PID: 2652)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 3892)
  • INFO

    • Checks supported languages

      • firefox.exe (PID: 2836)
      • firefox.exe (PID: 3252)
      • firefox.exe (PID: 1544)
      • firefox.exe (PID: 1048)
      • firefox.exe (PID: 3448)
      • firefox.exe (PID: 2428)
      • firefox.exe (PID: 2616)
      • firefox.exe (PID: 3300)
      • firefox.exe (PID: 3360)
      • SearchProtocolHost.exe (PID: 3612)
      • chrome.exe (PID: 3892)
      • chrome.exe (PID: 916)
      • chrome.exe (PID: 3708)
      • chrome.exe (PID: 3928)
      • chrome.exe (PID: 3220)
      • chrome.exe (PID: 3576)
      • chrome.exe (PID: 3116)
      • chrome.exe (PID: 1828)
      • chrome.exe (PID: 3820)
      • chrome.exe (PID: 672)
      • firefox.exe (PID: 2264)
      • chrome.exe (PID: 3624)
      • chrome.exe (PID: 2696)
      • chrome.exe (PID: 3204)
      • chrome.exe (PID: 2488)
      • chrome.exe (PID: 2644)
      • chrome.exe (PID: 2032)
      • chrome.exe (PID: 2680)
      • chrome.exe (PID: 2988)
      • chrome.exe (PID: 2164)
      • chrome.exe (PID: 2652)
      • chrome.exe (PID: 852)
    • Reads CPU info

      • firefox.exe (PID: 3252)
    • Reads the computer name

      • firefox.exe (PID: 3252)
      • firefox.exe (PID: 1544)
      • firefox.exe (PID: 1048)
      • firefox.exe (PID: 3448)
      • firefox.exe (PID: 3300)
      • firefox.exe (PID: 2428)
      • firefox.exe (PID: 3360)
      • firefox.exe (PID: 2616)
      • SearchProtocolHost.exe (PID: 3612)
      • chrome.exe (PID: 3892)
      • chrome.exe (PID: 3576)
      • chrome.exe (PID: 3708)
      • chrome.exe (PID: 1828)
      • firefox.exe (PID: 2264)
      • chrome.exe (PID: 2696)
      • chrome.exe (PID: 2032)
      • chrome.exe (PID: 2680)
      • chrome.exe (PID: 2164)
    • Application launched itself

      • firefox.exe (PID: 2836)
      • firefox.exe (PID: 3252)
      • chrome.exe (PID: 3892)
    • Creates files in the program directory

      • firefox.exe (PID: 3252)
    • Checks Windows Trust Settings

      • firefox.exe (PID: 3252)
    • Reads the date of Windows installation

      • firefox.exe (PID: 3252)
      • chrome.exe (PID: 2680)
    • Manual execution by user

      • WinRAR.exe (PID: 2840)
      • GodsEye.exe (PID: 3864)
      • chrome.exe (PID: 3892)
    • Creates files in the user directory

      • firefox.exe (PID: 3252)
    • Reads the hosts file

      • chrome.exe (PID: 3892)
      • chrome.exe (PID: 3576)
    • Reads settings of System Certificates

      • chrome.exe (PID: 3576)
    • Dropped object may contain Bitcoin addresses

      • chrome.exe (PID: 3892)
      • firefox.exe (PID: 3252)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
34
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winrar.exe searchprotocolhost.exe no specs godseye.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs firefox.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2836"C:\Program Files\Mozilla Firefox\firefox.exe" "https://anonfiles.com/zaH2t8i0y3/GodsEye_zip"C:\Program Files\Mozilla Firefox\firefox.exeExplorer.EXE
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
3252"C:\Program Files\Mozilla Firefox\firefox.exe" https://anonfiles.com/zaH2t8i0y3/GodsEye_zipC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1544"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3252.0.112218128\102496956" -parentBuildID 20201112153044 -prefsHandle 1096 -prefMapHandle 828 -prefsLen 1 -prefMapSize 238726 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3252 "\\.\pipe\gecko-crash-server-pipe.3252" 1188 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msasn1.dll
1048"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3252.6.634708620\1403583253" -childID 1 -isForBrowser -prefsHandle 3068 -prefMapHandle 3064 -prefsLen 245 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3252 "\\.\pipe\gecko-crash-server-pipe.3252" 3080 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
3448"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3252.13.2092980902\1338428693" -childID 2 -isForBrowser -prefsHandle 2032 -prefMapHandle 2680 -prefsLen 6644 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3252 "\\.\pipe\gecko-crash-server-pipe.3252" 2740 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msasn1.dll
3300"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3252.20.643294744\1584106913" -childID 3 -isForBrowser -prefsHandle 2408 -prefMapHandle 3408 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3252 "\\.\pipe\gecko-crash-server-pipe.3252" 3504 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
2428"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3252.21.949830431\2101443856" -childID 4 -isForBrowser -prefsHandle 3524 -prefMapHandle 3520 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3252 "\\.\pipe\gecko-crash-server-pipe.3252" 3556 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
2616"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3252.34.1386923269\1935557031" -childID 5 -isForBrowser -prefsHandle 3736 -prefMapHandle 3732 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3252 "\\.\pipe\gecko-crash-server-pipe.3252" 3748 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\rpcrt4.dll
3360"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3252.41.1063477370\144671573" -childID 6 -isForBrowser -prefsHandle 7772 -prefMapHandle 7776 -prefsLen 7673 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3252 "\\.\pipe\gecko-crash-server-pipe.3252" 7760 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\crypt32.dll
2840"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\GodsEye.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
Total events
27 850
Read events
27 665
Write events
178
Delete events
7

Modification events

(PID) Process:(2836) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
FFFB05DE5C000000
(PID) Process:(3252) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
A40506DE5C000000
(PID) Process:(3252) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(3252) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(3252) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(3252) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(3252) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|ServicesSettingsServer
Value:
https://firefox.settings.services.mozilla.com/v1
(PID) Process:(3252) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash
Value:
97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E
(PID) Process:(3252) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3252) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
9
Suspicious files
337
Text files
177
Unknown types
58

Dropped files

PID
Process
Filename
Type
3252firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
3252firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
3252firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache.binbinary
MD5:CC6662648E5B47063417268BE0F31DED
SHA256:FA6FF49A970984D3409C16CBD12647533754BE59901CF544A1491B7A0F99DD73
3252firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4jsonlz4
MD5:CB0706E6CB718756AE3CBCD1D122585E
SHA256:A4722B9C89E0C52075D5FEEC009502B9FE19653C140A4EE3E01131B30189B177
3252firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-new.bin
MD5:
SHA256:
3252firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache.bin
MD5:
SHA256:
3252firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-walbinary
MD5:DC3CDC76F2D5EF0DFF517B5A41D1C7A9
SHA256:0CDD75FBDA3200F8E0829096926BA60630F88F2438C310FDEFB0DB810CCA5FBC
3252firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
3252firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
MD5:
SHA256:
3252firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4.tmpjsonlz4
MD5:CB0706E6CB718756AE3CBCD1D122585E
SHA256:A4722B9C89E0C52075D5FEEC009502B9FE19653C140A4EE3E01131B30189B177
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
43
TCP/UDP connections
105
DNS requests
179
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3252
firefox.exe
GET
301
172.64.153.88:80
http://hybrid-analysis.com/
US
whitelisted
3252
firefox.exe
POST
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
3252
firefox.exe
POST
200
92.123.195.35:80
http://r3.o.lencr.org/
unknown
der
503 b
shared
3252
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3252
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt
US
text
8 b
whitelisted
3252
firefox.exe
GET
302
216.239.32.21:80
http://virustotal.com/
US
whitelisted
3576
chrome.exe
GET
302
216.239.38.21:80
http://virustotal.com/
US
whitelisted
3252
firefox.exe
POST
200
92.123.195.35:80
http://r3.o.lencr.org/
unknown
der
503 b
shared
3252
firefox.exe
POST
200
142.250.186.131:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
3252
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3252
firefox.exe
52.222.214.116:443
firefox.settings.services.mozilla.com
Amazon.com, Inc.
US
suspicious
3252
firefox.exe
34.107.221.82:80
detectportal.firefox.com
US
whitelisted
3252
firefox.exe
18.66.139.97:443
content-signature-2.cdn.mozilla.net
Massachusetts Institute of Technology
US
unknown
3252
firefox.exe
35.83.182.199:443
location.services.mozilla.com
Merit Network Inc.
US
unknown
3252
firefox.exe
142.250.186.74:443
safebrowsing.googleapis.com
Google Inc.
US
whitelisted
3252
firefox.exe
45.154.253.150:443
anonfiles.com
suspicious
3252
firefox.exe
45.154.253.152:443
anonfiles.com
suspicious
3252
firefox.exe
92.123.195.35:80
r3.o.lencr.org
Akamai International B.V.
whitelisted
3252
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3252
firefox.exe
142.250.186.131:80
ocsp.pki.goog
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
anonfiles.com
  • 45.154.253.150
  • 45.154.253.151
  • 45.154.253.152
  • 2001:678:b30:4::d
  • 2001:678:b30:4::e
  • 2001:678:b30:4::c
shared
firefox.settings.services.mozilla.com
  • 52.222.214.116
  • 52.222.214.84
  • 52.222.214.96
  • 52.222.214.105
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
content-signature-2.cdn.mozilla.net
  • 18.66.139.97
  • 18.66.139.67
  • 18.66.139.17
  • 18.66.139.125
  • 18.66.248.112
  • 18.66.248.5
  • 18.66.248.105
  • 18.66.248.40
whitelisted
d2nxq2uap88usk.cloudfront.net
  • 18.66.139.125
  • 18.66.139.17
  • 18.66.139.67
  • 18.66.139.97
  • 2600:9000:225e:7a00:a:da5e:7900:93a1
  • 2600:9000:225e:3a00:a:da5e:7900:93a1
  • 2600:9000:225e:a200:a:da5e:7900:93a1
  • 2600:9000:225e:5000:a:da5e:7900:93a1
  • 2600:9000:225e:6400:a:da5e:7900:93a1
  • 2600:9000:225e:e200:a:da5e:7900:93a1
  • 2600:9000:225e:8a00:a:da5e:7900:93a1
  • 2600:9000:225e:7000:a:da5e:7900:93a1
  • 18.66.248.40
  • 18.66.248.105
  • 18.66.248.5
  • 18.66.248.112
  • 2600:9000:224a:ca00:a:da5e:7900:93a1
  • 2600:9000:224a:5000:a:da5e:7900:93a1
  • 2600:9000:224a:4a00:a:da5e:7900:93a1
  • 2600:9000:224a:a00:a:da5e:7900:93a1
  • 2600:9000:224a:d600:a:da5e:7900:93a1
  • 2600:9000:224a:be00:a:da5e:7900:93a1
  • 2600:9000:224a:1600:a:da5e:7900:93a1
  • 2600:9000:224a:9600:a:da5e:7900:93a1
shared
location.services.mozilla.com
  • 35.83.182.199
  • 34.218.94.83
  • 35.161.134.161
  • 54.149.42.12
  • 35.82.180.24
  • 35.160.240.234
whitelisted
locprod2-elb-us-west-2.prod.mozaws.net
  • 35.160.240.234
  • 35.83.182.199
  • 34.218.94.83
  • 35.161.134.161
  • 54.149.42.12
  • 35.82.180.24
whitelisted

Threats

PID
Process
Class
Message
3252
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
3252
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
3252
firefox.exe
Potentially Bad Traffic
ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.xyz)
3252
firefox.exe
Potentially Bad Traffic
ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.xyz)
3252
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
3252
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
No debug info