URL:

https://www.keikotomanabu.net/cgi-bin/step_out_location.cgi?URL=https://polished-pond-609a.sharepoint00aws-s3-amazonaws-com.workers.dev//ku.sharepoint.com/:x:/s/Shopify/EcPeluUel81HmbP4mlhNLZABK3ajgZLx_hA?e=Ms4VV6#constantinos.chrysikopoulos@ku.ac.ae

Full analysis: https://app.any.run/tasks/f412a033-cd40-415d-a95d-0100a3e52641
Verdict: Malicious activity
Analysis date: October 31, 2024, 05:06:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
phishing
possible-phishing
Indicators:
MD5:

77FCFBEE1DE73AACC268DD8BEC7DDCC4

SHA1:

7659E6772371F5DD8C83A4BC311291C2D3538744

SHA256:

3E636C3487751B8D96E2F4B5C3C467326C11FFB03465CDC4D41BD8B13EF93F8A

SSDEEP:

6:2OLa8Wwqc6MaX0mATBV7ZHSPHflcko3CuWmJ7GODoQz1:2v8vEX2VdyPHtcfCu9KINp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Phishing has been detected

      • firefox.exe (PID: 608)
      • firefox.exe (PID: 6668)
  • SUSPICIOUS

    • Possibly a phishing URL contains email has been detected

      • firefox.exe (PID: 608)
      • firefox.exe (PID: 6668)
    • Access to SharePoint Content

      • firefox.exe (PID: 608)
      • firefox.exe (PID: 6668)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 608)
      • firefox.exe (PID: 7412)
      • firefox.exe (PID: 7496)
      • firefox.exe (PID: 6668)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 7496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
28
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #POSSIBLE-PHISHING firefox.exe no specs #POSSIBLE-PHISHING firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1808 -parentBuildID 20240213221259 -prefsHandle 1716 -prefMapHandle 1744 -prefsLen 30705 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {cb98ed4f-ecca-43f7-94ad-8fade2f8389c} 6668 "\\.\pipe\gecko-crash-server-pipe.6668" 1d34dbb1010 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
608"C:\Program Files\Mozilla Firefox\firefox.exe" "https://www.keikotomanabu.net/cgi-bin/step_out_location.cgi?URL=https://polished-pond-609a.sharepoint00aws-s3-amazonaws-com.workers.dev//ku.sharepoint.com/:x:/s/Shopify/EcPeluUel81HmbP4mlhNLZABK3ajgZLx_hA?e=Ms4VV6#constantinos.chrysikopoulos@ku.ac.ae"C:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
2632"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=3036 -childID 1 -isForBrowser -prefsHandle 2924 -prefMapHandle 2956 -prefsLen 26798 -prefMapSize 244343 -jsInitHandle 1284 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {37d6b7b4-389a-4dc9-8328-1000c95b9cb1} 6668 "\\.\pipe\gecko-crash-server-pipe.6668" 1d353992150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3000"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1752 -parentBuildID 20240213221259 -prefsHandle 1680 -prefMapHandle 1672 -prefsLen 19989 -prefMapSize 240426 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a9a36b6d-65ba-4b85-aa45-cbfdaefa38ad} 7496 "\\.\pipe\gecko-crash-server-pipe.7496" 22a6d1ac910 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3772"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2192 -parentBuildID 20240213221259 -prefsHandle 2184 -prefMapHandle 2172 -prefsLen 30705 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8b53d48c-d4b5-4cd6-a13c-a66120e1d556} 6668 "\\.\pipe\gecko-crash-server-pipe.6668" 1d341e7fb10 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4448"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6656 -childID 7 -isForBrowser -prefsHandle 6700 -prefMapHandle 6652 -prefsLen 29293 -prefMapSize 240426 -jsInitHandle 1176 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {75d6b7ee-9103-4a12-b7db-c6b8a14fca75} 7496 "\\.\pipe\gecko-crash-server-pipe.7496" 22a77091d90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
6028"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7468 -childID 9 -isForBrowser -prefsHandle 7460 -prefMapHandle 7456 -prefsLen 29293 -prefMapSize 240426 -jsInitHandle 1176 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {be67e462-25fb-4338-9ee0-dd1d35fb00d3} 7496 "\\.\pipe\gecko-crash-server-pipe.7496" 22a71ad8690 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
6284"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6876 -parentBuildID 20240213221259 -sandboxingKind 1 -prefsHandle 6860 -prefMapHandle 6864 -prefsLen 31443 -prefMapSize 240426 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a06a9145-df10-44de-a6bf-96880e0a2430} 7496 "\\.\pipe\gecko-crash-server-pipe.7496" 22a73c6d710 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
6292"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4176 -childID 2 -isForBrowser -prefsHandle 4172 -prefMapHandle 4168 -prefsLen 22416 -prefMapSize 240426 -jsInitHandle 1176 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d92c4bb7-5524-4572-bdcf-3441027cde92} 7496 "\\.\pipe\gecko-crash-server-pipe.7496" 22a73cb7150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
6668"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.keikotomanabu.net/cgi-bin/step_out_location.cgi?URL=https://polished-pond-609a.sharepoint00aws-s3-amazonaws-com.workers.dev//ku.sharepoint.com/:x:/s/Shopify/EcPeluUel81HmbP4mlhNLZABK3ajgZLx_hA?e=Ms4VV6#constantinos.chrysikopoulos@ku.ac.aeC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
27 988
Read events
27 986
Write events
2
Delete events
0

Modification events

(PID) Process:(6668) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(7496) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
Executable files
2
Suspicious files
456
Text files
62
Unknown types
11

Dropped files

PID
Process
Filename
Type
6668firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
6668firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6668firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:C09FF302D57C404B61E6A89B0B9F36E7
SHA256:6A5B4F82595799346D0E501FE6CC8629E0FD6ED27B74D0E6CB5073DDB2E3C40B
6668firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6668firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
6668firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
6668firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.db-journalbinary
MD5:13EF4FE66B36CD0B385CC08A6FE95FCC
SHA256:8F1AF339A8D3E8B369165A110B02754A72A3ECD69CFA3FBB0FE64ADF4F4460E6
6668firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6668firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.binbinary
MD5:EDF1533423C1FC648999D5A0755A4B3A
SHA256:412FB53D62BB8CFA7568C9970D68657C2B25E36433925A911B9EC1182865D892
6668firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.bindbf
MD5:3B156E12141F8CBCE9D60CDCE2077617
SHA256:E6287E44B44ABEA20E1B2E3F415D22B9E5E5FBBC155AD9DADBABA63951B2AF6F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
51
TCP/UDP connections
156
DNS requests
169
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6668
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
6668
firefox.exe
POST
200
95.101.54.114:80
http://r11.o.lencr.org/
unknown
whitelisted
6668
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
6668
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/wr2
unknown
whitelisted
6668
firefox.exe
POST
200
95.101.54.131:80
http://r10.o.lencr.org/
unknown
whitelisted
6668
firefox.exe
POST
200
95.101.54.131:80
http://r10.o.lencr.org/
unknown
whitelisted
6668
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/s/wr3/yvU
unknown
whitelisted
6668
firefox.exe
POST
200
95.101.54.114:80
http://r11.o.lencr.org/
unknown
whitelisted
6668
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/wr2
unknown
whitelisted
6668
firefox.exe
POST
200
95.101.54.114:80
http://r11.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4360
SearchApp.exe
104.126.37.160:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1584
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6668
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
6668
firefox.exe
34.117.188.166:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
6668
firefox.exe
34.107.243.93:443
push.services.mozilla.com
GOOGLE
US
whitelisted
6668
firefox.exe
142.250.181.234:443
safebrowsing.googleapis.com
whitelisted
6668
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 51.124.78.146
whitelisted
www.bing.com
  • 104.126.37.160
  • 104.126.37.131
  • 104.126.37.128
  • 104.126.37.139
  • 104.126.37.153
  • 104.126.37.155
  • 104.126.37.130
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.177
  • 2.23.209.182
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.185
  • 2.23.209.176
  • 2.23.209.179
  • 2.23.209.130
  • 2.23.209.133
whitelisted
google.com
  • 142.250.185.78
whitelisted
www.keikotomanabu.net
  • 160.17.10.1
unknown
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.215.14
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
whitelisted

Threats

PID
Process
Class
Message
2172
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] DNS Query to Cloudflare Worker App
2172
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] DNS Query to Cloudflare Worker App
2172
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] DNS Query to Cloudflare Worker App
6668
firefox.exe
Misc activity
ET INFO Observed Cloudflare workers.dev Domain in TLS SNI
2172
svchost.exe
Misc activity
ET INFO Observed DNS Query to Cloudflare workers.dev Domain
2172
svchost.exe
Misc activity
ET INFO Observed DNS Query to Cloudflare workers.dev Domain
2172
svchost.exe
Misc activity
ET INFO Observed DNS Query to Cloudflare workers.dev Domain
No debug info