File name:

ex4 to mq4 4.0.509.5.exe

Full analysis: https://app.any.run/tasks/8ad4d997-ef32-4700-87f5-5276fa289420
Verdict: Malicious activity
Analysis date: July 14, 2025, 19:25:21
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
delphi
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed, 3 sections
MD5:

96BDCB87A3B8CE80EEEBB18D7AF08BED

SHA1:

C33CA9F37784691EDE198F1809CA5AF63B47E05B

SHA256:

3FCBE92DE0D0A94DC76C5A14A8A59510D4BF9D1865B4158E99D35662C005E60B

SSDEEP:

24576:blAX7cD8isaJp1jThCYUsdxxrOPVuLtRPls2W42E:bqXyBTCbsdDxRPQ42E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • ex4 to mq4 4.0.509.5.exe (PID: 7080)
    • The process executes via Task Scheduler

      • updater.exe (PID: 7872)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 4048)
      • ex4 to mq4 4.0.509.5.exe (PID: 7080)
      • mt5setup.exe (PID: 4160)
      • mt5setup.exe (PID: 3860)
    • Reads the BIOS version

      • mt5setup.exe (PID: 3860)
      • mt5setup.exe (PID: 4160)
      • terminal64.exe (PID: 6840)
      • terminal64.exe (PID: 5988)
    • Application launched itself

      • updater.exe (PID: 7872)
      • mt5setup.exe (PID: 3860)
    • Reads the date of Windows installation

      • mt5setup.exe (PID: 3860)
      • mt5setup.exe (PID: 4160)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 6760)
    • Reads Internet Explorer settings

      • mt5setup.exe (PID: 4160)
    • Creates a software uninstall entry

      • mt5setup.exe (PID: 4160)
    • Executable content was dropped or overwritten

      • mt5setup.exe (PID: 4160)
  • INFO

    • Checks supported languages

      • ex4 to mq4 4.0.509.5.exe (PID: 7080)
      • updater.exe (PID: 7872)
      • updater.exe (PID: 7908)
      • mt5setup.exe (PID: 3860)
      • mt5setup.exe (PID: 4160)
      • terminal64.exe (PID: 5988)
      • terminal64.exe (PID: 6840)
      • identity_helper.exe (PID: 4100)
    • The sample compiled with english language support

      • ex4 to mq4 4.0.509.5.exe (PID: 7080)
    • Reads the computer name

      • ex4 to mq4 4.0.509.5.exe (PID: 7080)
      • updater.exe (PID: 7872)
      • mt5setup.exe (PID: 3860)
      • mt5setup.exe (PID: 4160)
      • terminal64.exe (PID: 6840)
      • terminal64.exe (PID: 5988)
      • identity_helper.exe (PID: 4100)
    • Manual execution by a user

      • firefox.exe (PID: 5616)
      • WinRAR.exe (PID: 4048)
      • msedge.exe (PID: 7860)
    • Application launched itself

      • firefox.exe (PID: 5616)
      • firefox.exe (PID: 416)
      • msedge.exe (PID: 2304)
      • msedge.exe (PID: 7860)
      • msedge.exe (PID: 7352)
      • msedge.exe (PID: 1740)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 416)
    • UPX packer has been detected

      • ex4 to mq4 4.0.509.5.exe (PID: 7080)
    • Compiled with Borland Delphi (YARA)

      • ex4 to mq4 4.0.509.5.exe (PID: 7080)
      • slui.exe (PID: 5924)
      • mt5setup.exe (PID: 4160)
      • terminal64.exe (PID: 5988)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 416)
    • Checks proxy server information

      • mt5setup.exe (PID: 3860)
      • slui.exe (PID: 5924)
      • mt5setup.exe (PID: 4160)
      • terminal64.exe (PID: 6840)
      • terminal64.exe (PID: 5988)
    • Reads Windows Product ID

      • mt5setup.exe (PID: 3860)
      • mt5setup.exe (PID: 4160)
      • terminal64.exe (PID: 6840)
      • terminal64.exe (PID: 5988)
    • Process checks whether UAC notifications are on

      • mt5setup.exe (PID: 3860)
      • updater.exe (PID: 7872)
      • terminal64.exe (PID: 6840)
      • terminal64.exe (PID: 5988)
    • Reads the software policy settings

      • slui.exe (PID: 5924)
      • mt5setup.exe (PID: 4160)
    • Creates files in the program directory

      • mt5setup.exe (PID: 4160)
    • Reads the machine GUID from the registry

      • mt5setup.exe (PID: 4160)
    • Reads CPU info

      • mt5setup.exe (PID: 4160)
    • Process checks computer location settings

      • mt5setup.exe (PID: 3860)
      • mt5setup.exe (PID: 4160)
    • Creates files or folders in the user directory

      • mt5setup.exe (PID: 3860)
      • terminal64.exe (PID: 6840)
      • mt5setup.exe (PID: 4160)
      • terminal64.exe (PID: 5988)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 7260)
    • Reads Environment values

      • identity_helper.exe (PID: 4100)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.scr | Windows screen saver (60.5)
.exe | Win32 Executable (generic) (20.8)
.exe | Generic Win/DOS Executable (9.2)
.exe | DOS Executable Generic (9.2)
.vxd | VXD Driver (0.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:03:11 21:24:43+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 5
CodeSize: 1081344
InitializedDataSize: 12288
UninitializedDataSize: 5267456
EntryPoint: 0x60e100
OSVersion: 4
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 4.0.509.5
ProductVersionNumber: 4.0.509.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: MetaQuotes Software Corp
FileDescription: EX4-TO-MQ4 Decompiler Free
FileVersion: 4.0.509.5
LegalCopyright: Copyright (C) 2007-2014 MetaQuotes Software Corp
OriginalFileName: ex4_to_mq4_freeware.exe
ProductName: EX4-TO-MQ4 Decompiler Free
ProductVersion: 4.0.509.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
203
Monitored processes
56
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ex4 to mq4 4.0.509.5.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs updater.exe no specs updater.exe no specs svchost.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe firefox.exe no specs firefox.exe no specs rundll32.exe no specs winrar.exe no specs firefox.exe no specs firefox.exe no specs mt5setup.exe mt5setup.exe terminal64.exe msedge.exe no specs explorer.exe no specs msedge.exe no specs explorer.exe no specs terminal64.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
416"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
856"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4244 -prefsLen 44823 -prefMapHandle 4248 -prefMapSize 272997 -jsInitHandle 4252 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4260 -initialChannelId {25b3a74f-dd28-49a4-aebe-f05a90f32675} -parentPid 416 -crashReporter "\\.\pipe\gecko-crash-server-pipe.416" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1300"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3292 -prefsLen 36996 -prefMapHandle 3296 -prefMapSize 272997 -jsInitHandle 3300 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3308 -initialChannelId {2cf93d5b-6150-4bda-853a-9af98f88ae3e} -parentPid 416 -crashReporter "\\.\pipe\gecko-crash-server-pipe.416" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
1740"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-windowC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2200C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2276"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5108 -prefsLen 39015 -prefMapHandle 5112 -prefMapSize 272997 -jsInitHandle 5116 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4928 -initialChannelId {e5aba5ca-1cf3-49b8-bedf-502aa59fb623} -parentPid 416 -crashReporter "\\.\pipe\gecko-crash-server-pipe.416" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2304"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.mql5.com/?utm_campaign=mql5.welcome.open&utm_medium=special&utm_source=web.installer&&utm_codepage=1033&utm_uniq=5189418734217907311&utm_link=74BAB33E0E66E858F995CF8800B3C38CC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemt5setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2996"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6212 -prefsLen 39561 -prefMapHandle 6188 -prefMapSize 272997 -jsInitHandle 6164 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5520 -initialChannelId {a4bf6e05-17d9-49af-b82c-559cc1172e29} -parentPid 416 -crashReporter "\\.\pipe\gecko-crash-server-pipe.416" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 16 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3092"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5484 -prefsLen 39427 -prefMapHandle 5760 -prefMapSize 272997 -jsInitHandle 5756 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5720 -initialChannelId {348c5f50-697b-459d-a7f7-7fc71ecb6068} -parentPid 416 -crashReporter "\\.\pipe\gecko-crash-server-pipe.416" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 14 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3388"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2164,i,10767479198624047559,10832925058454850485,262144 --variations-seed-version --mojo-platform-channel-handle=2576 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
47 774
Read events
47 531
Write events
234
Delete events
9

Modification events

(PID) Process:(416) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(4048) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4048) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\ForexCracked.com-AlphaFlow-EA.zip
(PID) Process:(4048) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4048) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4048) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4048) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4048) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(4048) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(4048) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
Executable files
3
Suspicious files
270
Text files
1 588
Unknown types
175

Dropped files

PID
Process
Filename
Type
416firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
416firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
416firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:3134ED3F12E4F4F8643DB90043B0FD7B
SHA256:26E4F122034D7A03F6DA0E707799B09CBEEBDAF8D7A3133A1F7BD894AC72EEA1
416firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
416firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\bounce-tracking-protection.sqlite-journalbinary
MD5:05E88CC499CEA66FCA75A580980D1D43
SHA256:03CA80E1F2B4728339F58F0E5F99F912963595AB9D92C1990939AFFC3A958F56
416firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
416firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
416firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:AF5FF21D33011DB779300A39AB66C4C1
SHA256:B98C8B35E69F140133E1D713FB1333543CA4EEBC7DC73897A1470146C9175BD2
416firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
416firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-walbinary
MD5:C0E0DEE97AB381B04C45DBD3C810C460
SHA256:17C5B5C1EE6A1F85B68C1021A7B8CDAF787BCF09636D90941C8E3389D6333B75
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
57
TCP/UDP connections
213
DNS requests
269
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
416
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
text
90 b
whitelisted
1268
svchost.exe
GET
200
23.55.110.193:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
416
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
416
firefox.exe
POST
200
172.217.16.131:80
http://o.pki.goog/s/wr3/k58
US
binary
472 b
whitelisted
416
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
416
firefox.exe
POST
200
172.217.16.131:80
http://o.pki.goog/we2
US
binary
280 b
whitelisted
5444
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
416
firefox.exe
POST
200
172.217.16.131:80
http://o.pki.goog/we2
US
binary
280 b
whitelisted
416
firefox.exe
POST
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr3ovtlsca2024
unknown
binary
1.40 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4312
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
416
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
whitelisted
1268
svchost.exe
23.55.110.193:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
416
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
416
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 40.127.240.158
whitelisted
google.com
  • 142.250.184.238
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted
content-signature-chains.prod.autograph.services.mozaws.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted
crl.microsoft.com
  • 23.55.110.193
  • 23.55.110.211
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.36.137.203
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted
mc.prod.ads.prod.webservices.mozgcp.net
  • 34.36.137.203
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2200
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
No debug info