URL:

http://irp-cdn.multiscreensite.com/2c11e5c7/files/uploaded/20352994798.pdf

Full analysis: https://app.any.run/tasks/04767ce1-6487-4f1f-8bde-5fac2c018512
Verdict: Malicious activity
Analysis date: July 27, 2023, 16:09:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

6D3BD9EA8E29943A594DAC9BAB5BEF7E

SHA1:

DC13E1CBBA2C55644FA760EE1D732EFB1EC89362

SHA256:

2353EA451C74197899688A4B27E51070BB1602AF4991A109FA033420F6A357F5

SSDEEP:

3:N1KXVpIQfMPmy9KcANAEDoMXsT:CFptfwmy2Ts

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • firefox.exe (PID: 1588)
      • firefox.exe (PID: 3100)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
77
Monitored processes
43
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3100.19.1679114132\1832582589" -childID 17 -isForBrowser -prefsHandle 3092 -prefMapHandle 3156 -prefsLen 32054 -prefMapSize 243323 -jsInitHandle 940 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d6714e12-5ccb-4ba8-b26c-e22fc305b800} 3100 "\\.\pipe\gecko-crash-server-pipe.3100" 3340 121e1b20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
128"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3100.26.420005283\97132759" -childID 22 -isForBrowser -prefsHandle 8220 -prefMapHandle 8136 -prefsLen 32054 -prefMapSize 243323 -jsInitHandle 940 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7f427757-3633-4e67-a791-71a8eadd66e3} 3100 "\\.\pipe\gecko-crash-server-pipe.3100" 8224 121e19b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
148"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3100.25.1237905404\1549128827" -childID 21 -isForBrowser -prefsHandle 7784 -prefMapHandle 3348 -prefsLen 32054 -prefMapSize 243323 -jsInitHandle 940 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8dd2450a-59f7-4433-a18b-9457e599bcbb} 3100 "\\.\pipe\gecko-crash-server-pipe.3100" 4184 1cbe0e00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
148"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3100.40.849258789\1560356559" -childID 36 -isForBrowser -prefsHandle 7628 -prefMapHandle 7624 -prefsLen 32054 -prefMapSize 243323 -jsInitHandle 940 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {96ec9120-a036-47f7-94ce-5ba0bfccacf4} 3100 "\\.\pipe\gecko-crash-server-pipe.3100" 7640 1cdf4110 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
580"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3100.35.727939742\1336459329" -childID 31 -isForBrowser -prefsHandle 8504 -prefMapHandle 2320 -prefsLen 32054 -prefMapSize 243323 -jsInitHandle 940 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7573dd91-e521-48a5-9570-b6628fb711f0} 3100 "\\.\pipe\gecko-crash-server-pipe.3100" 8440 19fe16d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
1036"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3100.28.1531437609\1052321644" -childID 24 -isForBrowser -prefsHandle 7792 -prefMapHandle 8224 -prefsLen 32054 -prefMapSize 243323 -jsInitHandle 940 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {dcacde88-dffb-4030-af58-f9b4811b20e9} 3100 "\\.\pipe\gecko-crash-server-pipe.3100" 3892 121e19b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1052"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3100.7.1333573616\948217798" -childID 5 -isForBrowser -prefsHandle 3788 -prefMapHandle 3956 -prefsLen 29711 -prefMapSize 243323 -jsInitHandle 940 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {085d6d13-58aa-4ef5-8741-aaefde143461} 3100 "\\.\pipe\gecko-crash-server-pipe.3100" 4004 1a575e00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1052"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3100.38.872285724\1312990397" -childID 34 -isForBrowser -prefsHandle 8156 -prefMapHandle 3744 -prefsLen 32054 -prefMapSize 243323 -jsInitHandle 940 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c58154b2-121a-4cce-96f2-bdbef2520d20} 3100 "\\.\pipe\gecko-crash-server-pipe.3100" 7824 1cc10f70 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
1208"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3100.3.1547178918\155929503" -childID 2 -isForBrowser -prefsHandle 1612 -prefMapHandle 1624 -prefsLen 27566 -prefMapSize 243323 -jsInitHandle 940 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8332277a-b037-4bd9-9f5b-bbd3e646f5de} 3100 "\\.\pipe\gecko-crash-server-pipe.3100" 2280 15441f70 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1244"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3100.16.1978031827\429256189" -childID 14 -isForBrowser -prefsHandle 8124 -prefMapHandle 8112 -prefsLen 32054 -prefMapSize 243323 -jsInitHandle 940 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {23b33f97-f093-4eec-afee-28c6f0eaf82a} 3100 "\\.\pipe\gecko-crash-server-pipe.3100" 8100 121e16d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
43 157
Read events
43 132
Write events
23
Delete events
2

Modification events

(PID) Process:(1588) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:delete valueName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
09611C1E1E000000
(PID) Process:(1588) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:delete valueName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
AD681C1E1E000000
(PID) Process:(3100) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(3100) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(3100) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(3100) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(3100) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3100) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000049010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3100) firefox.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
1
Suspicious files
272
Text files
85
Unknown types
9

Dropped files

PID
Process
Filename
Type
3100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite-wal
MD5:
SHA256:
3100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20230710165010text
MD5:5956316906CE782099C605DA7276923E
SHA256:B4A860365D2F56B54F5B1670BBDBD47CCD6FBC170B091BAF61AE039AD240C166
3100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:2C74ED9BB496B4DBC6CC6BA2C24021BD
SHA256:D486EAF6DDBDCEB04B5FE1469400354C24DEEE90B1A499D4E1DBEF45F5E198C4
3100firefox.exeC:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\profile_count_308046B0AF4A39CB.jsonbinary
MD5:58728D2E9D553BB2369BDB4A618ACAE5
SHA256:7EBC652A4B5B43608F61AC1057C51EC2EC1C8E33BBEB130794E15AF72BEB42E8
3100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite-journalbinary
MD5:D071D4F624B88F1CF2400863F427FA37
SHA256:5CB82474338DBE492F80A55FDEF0EAA0C0FB3AB29F39BF5BD5C77B6683F92C51
3100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\ls-archive-tmp.sqlitebinary
MD5:446FBAA8B14B3C86BFCEF8BE65EE7D80
SHA256:47DBD4AF1EF0E76FD0FC756D4F3A397C251F63CB1B71B1B4405FCA69C1DED6E0
3100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:2C74ED9BB496B4DBC6CC6BA2C24021BD
SHA256:D486EAF6DDBDCEB04B5FE1469400354C24DEEE90B1A499D4E1DBEF45F5E198C4
3100firefox.exeC:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\update-config.jsonbinary
MD5:E812E56D0B6EDF84B4A0B959F53E239F
SHA256:D55B72651CD0C5B834EAA29BA778BE7EDC357C16163A77AE778DCD61E85C3582
3100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\ls-archive-tmp.sqlite-journalbinary
MD5:E8FCC216ECC101E7539A45E49EB5575C
SHA256:FA166ED4A87328206DFB73AE3B670483167610222DCC9F73D90D794BB9675DE1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
209
DNS requests
312
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3100
firefox.exe
GET
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
whitelisted
3100
firefox.exe
GET
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
whitelisted
3100
firefox.exe
POST
2.16.202.121:80
http://r3.o.lencr.org/
NL
shared
3100
firefox.exe
GET
200
13.32.99.71:80
http://irp-cdn.multiscreensite.com/2c11e5c7/files/uploaded/20352994798.pdf
US
pdf
162 Kb
whitelisted
3100
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
US
binary
471 b
whitelisted
3100
firefox.exe
GET
403
13.32.99.71:80
http://irp-cdn.multiscreensite.com/favicon.ico
US
xml
255 b
whitelisted
3100
firefox.exe
POST
142.250.186.67:80
http://ocsp.pki.goog/gts1c3
US
whitelisted
3100
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
DE
binary
503 b
shared
3100
firefox.exe
POST
2.16.202.121:80
http://r3.o.lencr.org/
NL
shared
3100
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1084
svchost.exe
224.0.0.252:5355
unknown
3100
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
2720
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
3100
firefox.exe
13.32.99.71:80
irp-cdn.multiscreensite.com
AMAZON-02
US
suspicious
3100
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
suspicious
3100
firefox.exe
35.201.103.21:443
normandy.cdn.mozilla.net
GOOGLE
US
unknown
3100
firefox.exe
172.217.18.10:443
safebrowsing.googleapis.com
GOOGLE
US
whitelisted
3100
firefox.exe
2.16.202.121:80
r3.o.lencr.org
Akamai International B.V.
NL
suspicious

DNS requests

Domain
IP
Reputation
irp-cdn.multiscreensite.com
  • 13.32.99.71
  • 13.32.99.60
  • 13.32.99.94
  • 13.32.99.102
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
da7otfopzteok.cloudfront.net
  • 13.32.99.102
  • 13.32.99.94
  • 13.32.99.60
  • 13.32.99.71
malicious
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
spocs.getpocket.com
  • 3.229.237.11
  • 3.229.85.40
  • 54.88.103.11
  • 34.193.43.112
shared
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 34.193.43.112
  • 54.88.103.11
  • 3.229.85.40
  • 3.229.237.11
shared
r3.o.lencr.org
  • 2.16.202.121
  • 95.101.54.131
  • 184.24.77.62
  • 184.24.77.53
  • 184.24.77.54
  • 184.24.77.74
  • 184.24.77.71
  • 184.24.77.56
  • 184.24.77.52
  • 184.24.77.75
  • 184.24.77.59
  • 2.16.241.15
  • 2.16.241.8
shared
a1887.dscq.akamai.net
  • 95.101.54.131
  • 2.16.202.121
  • 2a02:26f0:780::210:ca79
  • 2a02:26f0:780::5f65:3683
  • 184.24.77.59
  • 184.24.77.75
  • 184.24.77.52
  • 184.24.77.56
  • 184.24.77.71
  • 184.24.77.74
  • 184.24.77.54
  • 184.24.77.53
  • 184.24.77.62
  • 2a02:26f0:1700:f::1737:a1a4
  • 2a02:26f0:1700:f::1737:a194
  • 2a02:26f0:3500:e::1732:835c
  • 2a02:26f0:3500:e::1732:8353
  • 2.16.241.8
  • 2.16.241.15
  • 2a02:26f0:480:e::210:f108
  • 2a02:26f0:480:e::210:f10f
whitelisted
normandy.cdn.mozilla.net
  • 35.201.103.21
whitelisted

Threats

PID
Process
Class
Message
1084
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
1084
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
No debug info