| URL: | https://spys.one/en/https-ssl-proxy/ |
| Full analysis: | https://app.any.run/tasks/f352066a-c7d1-456d-b09f-c45e6029ff08 |
| Verdict: | Malicious activity |
| Analysis date: | June 21, 2025, 18:53:35 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MD5: | FF93B891B613B57646A36F65CA25F960 |
| SHA1: | EF1F54EF0489AD9DE165CA2B58BEE69F506B7393 |
| SHA256: | 26A8EAD1879302B6556E9429874316658BA70927D0007D2C1CFC2C80049AADF2 |
| SSDEEP: | 3:N8Y+qSWWTeKn:2Y+qMTVn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2200 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2464 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6784 -prefsLen 39623 -prefMapHandle 6768 -prefMapSize 272997 -jsInitHandle 5956 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6824 -initialChannelId {cb26a915-4c4a-48e2-8487-f8f11b36fd18} -parentPid 6508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 15 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 2716 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 1904 -prefsLen 36520 -prefMapHandle 1908 -prefMapSize 272997 -ipcHandle 1968 -initialChannelId {db1194d4-d82f-41b6-b7e9-6f5e6b3987be} -parentPid 6508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6508" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 3488 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3204 -prefsLen 31090 -prefMapHandle 3208 -prefMapSize 272997 -jsInitHandle 3212 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3220 -initialChannelId {b7b10a49-6843-44a6-86be-60ba8a4a913e} -parentPid 6508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 3720 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 1 -prefsHandle 6216 -prefsLen 45524 -prefMapHandle 6204 -prefMapSize 272997 -ipcHandle 7124 -initialChannelId {639b3b67-f9ff-467f-9853-debd916315f7} -parentPid 6508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 18 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 3756 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://spys.one/en/https-ssl-proxy/" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 3832 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6836 -prefsLen 39623 -prefMapHandle 6844 -prefMapSize 272997 -jsInitHandle 5312 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5976 -initialChannelId {f01d62a0-ad1e-4095-93ae-f864360debe8} -parentPid 6508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 16 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 3888 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 2832 -prefsLen 36996 -prefMapHandle 3276 -prefMapSize 272997 -ipcHandle 3312 -initialChannelId {7e997d99-dab5-42af-a508-d484f1f85891} -parentPid 6508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6508" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 4104 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6004 -prefsLen 39149 -prefMapHandle 6052 -prefMapSize 272997 -jsInitHandle 6056 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6064 -initialChannelId {aa782d2f-698d-4b0f-b786-a9659b3b4511} -parentPid 6508 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6508" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 14 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 5900 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6508) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 6508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.js | text | |
MD5:2E109F48C8A12186ADFF199CE2C356A0 | SHA256:9D8A6E8A727FB3EDEE2C4258E82D840DAC010BB3EDAD7DB0DDBE9B3FDF16F14E | |||
| 6508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:2E109F48C8A12186ADFF199CE2C356A0 | SHA256:9D8A6E8A727FB3EDEE2C4258E82D840DAC010BB3EDAD7DB0DDBE9B3FDF16F14E | |||
| 6508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.bin | binary | |
MD5:2260ACD903B5AD29B53A2632B3BE8995 | SHA256:C4986C3DEF476F7BE7D5ECA32AA0A021308BFB9798850E9BF4B20E0B87B83EEA | |||
| 6508 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6508 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
6508 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6508 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/s/wr3/FIY | unknown | — | — | whitelisted |
6508 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6508 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
6508 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
6508 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
6508 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
6508 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
6508 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4960 | RUXIMICS.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6508 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | whitelisted |
6508 | firefox.exe | 188.114.97.3:443 | spys.one | CLOUDFLARENET | NL | unknown |
6508 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
6508 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
6508 | firefox.exe | 142.250.184.195:80 | o.pki.goog | GOOGLE | US | whitelisted |
6508 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
content-signature-2.cdn.mozilla.net |
| whitelisted |
content-signature-chains.prod.autograph.services.mozaws.net |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
spys.one |
| unknown |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
mc.prod.ads.prod.webservices.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2200 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2200 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2200 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2200 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2200 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2200 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2200 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2200 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2200 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2200 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |