| URL: | https://www.Aol.com/story/life/tv/2018/10/2=%202/dancing-stars-fairy-tale-showmance-brews-disney-night/1734997002/pl=%2034u6z0-j498-le1-1ke-9nf8ukx14qpe |
| Full analysis: | https://app.any.run/tasks/62b831ec-903c-4223-9e83-287ff412c9cc |
| Verdict: | Malicious activity |
| Analysis date: | March 02, 2024, 19:31:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 8A68D26407DC009E257BDF01926C2415 |
| SHA1: | 20EE4F602CEBA01AE62BB61D5758F08AE29E7694 |
| SHA256: | 1B9EBAA172AE1FBCF5F5C6241E40EC43AC8E61D70867A5C9B9588615BD27A7E9 |
| SSDEEP: | 3:N8DSLQTNRM7CDAKS9taMCIXlXPFEARSPBbA541ycciXOHFWoCcdYFDdbWBn:2OLgNRMem/7CIXluCSPu5M7OPo5+n |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 764 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.18.226747404\552963075" -childID 15 -isForBrowser -prefsHandle 7328 -prefMapHandle 7336 -prefsLen 31203 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {bcb2f699-38e2-4931-93ca-6475d49e1c19} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 7424 1b887c90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 908 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.10.2100280967\1809539872" -childID 9 -isForBrowser -prefsHandle 2348 -prefMapHandle 4272 -prefsLen 31122 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {216d85dc-0a53-435b-9b04-6e28b126d13d} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 4164 16865c90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 984 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.6.1056143139\434959985" -childID 5 -isForBrowser -prefsHandle 2096 -prefMapHandle 2092 -prefsLen 29313 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8630da85-5f30-43e0-a47b-951b6e764548} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 2160 1a5b93f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1316 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.9.973664813\1143179457" -childID 8 -isForBrowser -prefsHandle 2928 -prefMapHandle 3024 -prefsLen 31122 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fd7f1bdf-20ae-4add-b7df-007dd3cf11e9} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 3060 17fec110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1864 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.13.1420312950\1595868066" -childID 12 -isForBrowser -prefsHandle 7860 -prefMapHandle 7856 -prefsLen 31122 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {65f86fe6-eec7-4de8-a34e-44038070a8ed} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 7880 1ad3f560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1892 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.5.1535016351\2108618891" -childID 4 -isForBrowser -prefsHandle 3756 -prefMapHandle 3716 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7fc5e3ad-bbfb-410c-a30f-5236a31d36ba} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 3764 17fec280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2376 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.7.197510401\1516692851" -childID 6 -isForBrowser -prefsHandle 4196 -prefMapHandle 4200 -prefsLen 29313 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0024eb55-9001-4d6c-9f20-a36ba3a546c5} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 4188 1a5b9f70 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2384 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.4.1866866410\816323129" -childID 3 -isForBrowser -prefsHandle 2912 -prefMapHandle 3728 -prefsLen 29102 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {aed998e2-384d-4977-84c8-92fbf8e9ca7b} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 3736 17fec110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2632 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.15.1879229775\2117258305" -parentBuildID 20230710165010 -prefsHandle 7932 -prefMapHandle 7928 -prefsLen 36592 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f3243c32-d4d9-4c9c-88ab-5be9a89ca176} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 7940 1bf4e4a0 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2640 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4052.8.341330340\1657625050" -childID 7 -isForBrowser -prefsHandle 4364 -prefMapHandle 2388 -prefsLen 29313 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4fd781b6-53e5-479e-9635-a83855520460} 4052 "\\.\pipe\gecko-crash-server-pipe.4052" 4352 18b849b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (3864) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 24FFDA4E01000000 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: F6CDDC4E01000000 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB |
| Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (4052) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal | binary | |
MD5:98E2A7027A4EBFBB32F411CF5AA1D0B8 | SHA256:7F8096314F45AB6D951A62A6FB90CC062B94F328DA4D1E13020FA24AA66601CF | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db | binary | |
MD5:29771CEA0074CFAECEA05D61A0D7A8FB | SHA256:9EAED554E8C90B9BB610D0F48A33F2E80386FF4E33F635871B5469697691A015 | |||
| 4052 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4052 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
4052 | firefox.exe | POST | 200 | 142.250.185.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
4052 | firefox.exe | POST | 200 | 23.219.155.48:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
4052 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
4052 | firefox.exe | POST | 200 | 23.219.155.48:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
4052 | firefox.exe | POST | 200 | 142.250.185.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
4052 | firefox.exe | POST | 200 | 23.219.155.48:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
4052 | firefox.exe | POST | — | 23.219.155.48:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
4052 | firefox.exe | POST | — | 23.219.155.48:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
4052 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4052 | firefox.exe | 212.82.100.163:443 | www.aol.com | Yahoo! UK Services Limited | IE | unknown |
4052 | firefox.exe | 142.250.186.74:443 | safebrowsing.googleapis.com | — | — | whitelisted |
4052 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | unknown |
4052 | firefox.exe | 142.250.185.227:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
4052 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
4052 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | GOOGLE | US | unknown |
4052 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.aol.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
media-router-aol1.prod.g03.yahoodns.net |
| malicious |
contile.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
spocs.getpocket.com |
| shared |
gkegw.prod.ads.prod.webservices.mozgcp.net |
| unknown |
r3.o.lencr.org |
| shared |