URL:

http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDEonU3suH%2FUK8T3g5g%3D%3D

Full analysis: https://app.any.run/tasks/35caac34-8682-4aae-9130-151f163a9ddd
Verdict: Malicious activity
Analysis date: April 29, 2024, 05:05:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

E11CB9FA2F6EB026CAEA1946D7747F10

SHA1:

C24785BBA3953AD575152EE702619DAD8D159888

SHA256:

1DB363AD31D56897C3C0A7F2A30B56DA9E4E22639A8D03E683DA7E9083E5A32D

SSDEEP:

3:N1KRGWVmJ2LZyWGCHprVCR3XGzXnUsyX+BVaRjNRuCPwRQEjOCQKWmn:CgWVmJsZyDCJrVCxYUzEaFNRuCIRFjtr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • rundll32.exe (PID: 1876)
      • rundll32.exe (PID: 660)
      • wmplayer.exe (PID: 3856)
      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3944)
    • Uses RUNDLL32.EXE to load library

      • iexplore.exe (PID: 3980)
    • Reads security settings of Internet Explorer

      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3856)
      • wmplayer.exe (PID: 3944)
    • Process requests binary or script from the Internet

      • wmplayer.exe (PID: 3944)
  • INFO

    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3980)
    • Application launched itself

      • iexplore.exe (PID: 3980)
      • firefox.exe (PID: 1856)
      • firefox.exe (PID: 588)
    • The process uses the downloaded file

      • rundll32.exe (PID: 1876)
      • iexplore.exe (PID: 4044)
      • iexplore.exe (PID: 3980)
      • rundll32.exe (PID: 660)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 1876)
      • rundll32.exe (PID: 660)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3256)
      • wmplayer.exe (PID: 3856)
      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3944)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3256)
      • wmplayer.exe (PID: 3856)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3256)
      • wmplayer.exe (PID: 3856)
      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3944)
    • Reads Environment values

      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3944)
    • Process checks computer location settings

      • setup_wm.exe (PID: 3564)
    • Reads the machine GUID from the registry

      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3944)
    • Checks proxy server information

      • setup_wm.exe (PID: 3564)
    • Create files in a temporary directory

      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3944)
    • Creates files or folders in the user directory

      • wmplayer.exe (PID: 3944)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 588)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 588)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
21
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe rundll32.exe no specs iexplore.exe no specs rundll32.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs wmpnscfg.exe no specs wmplayer.exe no specs setup_wm.exe unregmp2.exe no specs unregmp2.exe no specs wmplayer.exe

Process information

PID
CMD
Path
Indicators
Parent process
588"C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT+anRD3C1tW3nsrKeuXC7DPwQU+O9_8s14Z6jeb48kjYjxhwMCs+sCDEonU3suH_UK8T3g5g=="C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
660"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT+anRD3C1tW3nsrKeuXC7DPwQU+O9_8s14Z6jeb48kjYjxhwMCs+sCDEonU3suH_UK8T3g5g==C:\Windows\System32\rundll32.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1292"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT+anRD3C1tW3nsrKeuXC7DPwQU+O9_8s14Z6jeb48kjYjxhwMCs+sCDEonU3suH_UK8T3g5g==C:\Program Files\Internet Explorer\iexplore.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1844"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="588.0.1952513294\2017248232" -parentBuildID 20230710165010 -prefsHandle 1116 -prefMapHandle 1108 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6bb031e3-030c-49f2-a2ca-f492d88a7f1f} 588 "\\.\pipe\gecko-crash-server-pipe.588" 1204 d6a9f20 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1856"C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT+anRD3C1tW3nsrKeuXC7DPwQU+O9_8s14Z6jeb48kjYjxhwMCs+sCDEonU3suH_UK8T3g5g=="C:\Program Files\Mozilla Firefox\firefox.exerundll32.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1876"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT+anRD3C1tW3nsrKeuXC7DPwQU+O9_8s14Z6jeb48kjYjxhwMCs+sCDEonU3suH_UK8T3g5g==C:\Windows\System32\rundll32.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2320"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="588.3.48569911\1060369666" -childID 2 -isForBrowser -prefsHandle 2896 -prefMapHandle 1908 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 928 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8cc35c1d-5459-4e9d-8d79-ab4c0c0cf374} 588 "\\.\pipe\gecko-crash-server-pipe.588" 2908 16273e00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2364"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="588.1.1598435752\1302416550" -parentBuildID 20230710165010 -prefsHandle 1428 -prefMapHandle 1424 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {83b6255e-8b41-4b7f-83e4-1760b3e22f00} 588 "\\.\pipe\gecko-crash-server-pipe.588" 1440 f01c260 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2480"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="588.2.1512915567\856268629" -childID 1 -isForBrowser -prefsHandle 1644 -prefMapHandle 1640 -prefsLen 29565 -prefMapSize 244195 -jsInitHandle 928 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0c95dedc-6050-4fe9-b667-697d2a2ad076} 588 "\\.\pipe\gecko-crash-server-pipe.588" 2140 125fd6d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2536"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="588.7.1329630261\1503492636" -childID 6 -isForBrowser -prefsHandle 4292 -prefMapHandle 4296 -prefsLen 34364 -prefMapSize 244195 -jsInitHandle 928 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {73c5dce5-0bb6-4441-a703-f9419440f616} 588 "\\.\pipe\gecko-crash-server-pipe.588" 4280 197e4f70 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
39 992
Read events
39 299
Write events
584
Delete events
109

Modification events

(PID) Process:(3980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31103474
(PID) Process:(3980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31103474
(PID) Process:(3980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
4
Suspicious files
93
Text files
42
Unknown types
42

Dropped files

PID
Process
Filename
Type
588firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
4044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT+anRD3C1tW3nsrKeuXC7DPwQU+O9_8s14Z6jeb48kjYjxhwMCs+sCDEonU3suH_UK8T3g5g==[1]der
MD5:0ADCC3BE570E9BCF2CADDFF229A167A1
SHA256:91A352F0DE74B494AB6A14B666C3E817EA512E3A4DA9AFA3ECC8BF84CC47CC13
3980iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF40548D8C30EDBE21.TMPgmc
MD5:F621C0D8A57D4F9CAF10AAEFA0080306
SHA256:0D57DD1A3AD3D0D43ED1668B5D5E0075E201CD750688D09B2BCF063C17308FB9
3980iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{1E0FFE1D-05E6-11EF-9E36-12A9866C77DE}.datbinary
MD5:21DF2AC5D8F9E58612AC68AD8BD73DFF
SHA256:B89AC3E6B75202F19ED1B3CDE4A379D21FF95BFBD301EE134C2A932255729E3A
588firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\activity-stream.discovery_stream.json
MD5:
SHA256:
3980iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT+anRD3C1tW3nsrKeuXC7DPwQU+O9_8s14Z6jeb48kjYjxhwMCs+sCDEonU3suH_UK8T3g5g==der
MD5:0ADCC3BE570E9BCF2CADDFF229A167A1
SHA256:91A352F0DE74B494AB6A14B666C3E817EA512E3A4DA9AFA3ECC8BF84CC47CC13
4044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT+anRD3C1tW3nsrKeuXC7DPwQU+O9_8s14Z6jeb48kjYjxhwMCs+sCDEonU3suH_UK8T3g5g==.h4f34w3.partialder
MD5:0ADCC3BE570E9BCF2CADDFF229A167A1
SHA256:91A352F0DE74B494AB6A14B666C3E817EA512E3A4DA9AFA3ECC8BF84CC47CC13
3980iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT+anRD3C1tW3nsrKeuXC7DPwQU+O9_8s14Z6jeb48kjYjxhwMCs+sCDEonU3suH_UK8T3g5g==.h4f34w3.partial:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
588firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3980iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{253BD0CF-05E6-11EF-9E36-12A9866C77DE}.datbinary
MD5:52EFE03371C921AB6765A59748D446F5
SHA256:2738E5D9FFF3B32802CB0AF3A7878ED08975BE82B08081427B7231BF5D035210
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
74
DNS requests
135
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
588
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
unknown
4044
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDEonU3suH%2FUK8T3g5g%3D%3D
unknown
unknown
588
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
unknown
588
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
unknown
3980
iexplore.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5ae977de40ce3b21
unknown
unknown
588
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
unknown
3980
iexplore.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?71672cd0900ed23e
unknown
unknown
3980
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
588
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
unknown
588
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
4044
iexplore.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
588
firefox.exe
34.117.188.166:443
contile.services.mozilla.com
unknown
588
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
588
firefox.exe
142.250.185.106:443
safebrowsing.googleapis.com
whitelisted
588
firefox.exe
142.250.186.67:80
ocsp.pki.goog
GOOGLE
US
whitelisted
588
firefox.exe
34.107.243.93:443
push.services.mozilla.com
unknown
588
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.215.14
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
shared
prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
unknown
r3.o.lencr.org
  • 95.101.54.131
  • 95.101.54.107
shared
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted

Threats

PID
Process
Class
Message
3944
wmplayer.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info