| URL: | http://1000098.kefu.helps.live/ |
| Full analysis: | https://app.any.run/tasks/bc6fed10-2a72-42a7-90a0-46049fcdfdb0 |
| Verdict: | Malicious activity |
| Analysis date: | December 19, 2025, 18:29:44 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | DF4E3A768F5ADA030B5D4A23B287AC46 |
| SHA1: | 411CBEB6F58CC903DCC12F2BBF01008E433EDC95 |
| SHA256: | 3FE5248230E2A81A8DA66F57C452283ADE8C42825FE74587F255871B5CE4DC0C |
| SSDEEP: | 3:N1Ktd1eJCML:C/8JCm |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 792 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2900 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5124 -prefsLen 45168 -prefMapHandle 5128 -prefMapSize 273045 -jsInitHandle 5132 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5140 -initialChannelId {8f0d4a55-cecf-4f18-af30-8027eb9a1824} -parentPid 7664 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7664" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 5152 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4852 -prefsLen 45116 -prefMapHandle 4920 -prefMapSize 273045 -ipcHandle 4840 -initialChannelId {3ec1ca3b-a01c-4dfb-b904-bd3a6669c71e} -parentPid 7664 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7664" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 6392 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4140 -prefsLen 44960 -prefMapHandle 4144 -prefMapSize 273045 -jsInitHandle 4148 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4108 -initialChannelId {3dbeb3f0-9624-4bcf-a836-c57a63e27cae} -parentPid 7664 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7664" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 6940 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5568 -prefsLen 39120 -prefMapHandle 5616 -prefMapSize 273045 -jsInitHandle 5620 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5628 -initialChannelId {c2f9f324-c04b-4d2e-8e41-1175ca56801d} -parentPid 7664 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7664" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 7196 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5360 -prefsLen 39120 -prefMapHandle 2804 -prefMapSize 273045 -jsInitHandle 5356 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5464 -initialChannelId {127b14fb-2869-4439-83a9-81439231dfca} -parentPid 7664 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7664" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 7272 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5524 -prefsLen 39120 -prefMapHandle 5528 -prefMapSize 273045 -jsInitHandle 5532 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5480 -initialChannelId {c9ddd960-facd-45b7-af6a-679c8babfe57} -parentPid 7664 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7664" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 9 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 7572 | "C:\Program Files\Mozilla Firefox\firefox.exe" "http://1000098.kefu.helps.live/" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 7664 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://1000098.kefu.helps.live/ | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 7820 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 1928 -prefsLen 36580 -prefMapHandle 1932 -prefMapSize 273045 -ipcHandle 1992 -initialChannelId {082fab36-1f79-4409-b74f-02d156ccf93e} -parentPid 7664 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7664" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7664 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 7664 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 7664 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 7664 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.bin | binary | |
MD5:5152D8F49F1AD4219D935611EFE18437 | SHA256:9A6E50715E3C49A43E3D622EDE7E37ECF0767342B3039B8B0AE25BBE4FF6F66E | |||
| 7664 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 7664 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | text | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 7664 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 7664 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | text | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 7664 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:B30329D7D2CF4258C22F500CBEA218FF | SHA256:C5E20431B116E1DABD383C6855A36E6DAF13E1CC125B83D59EF68B4BCEFB02E6 | |||
| 7664 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7664 | firefox.exe | GET | 101 | 34.107.243.93:443 | https://push.services.mozilla.com/ | unknown | — | — | unknown |
7664 | firefox.exe | GET | 200 | 34.160.144.191:443 | https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2025-11-08-08-20-52.chain | unknown | — | 5.18 Kb | unknown |
7664 | firefox.exe | GET | 200 | 34.160.144.191:443 | https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2025-11-08-08-20-52.chain | unknown | — | 5.18 Kb | unknown |
7664 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | unknown |
7664 | firefox.exe | GET | 200 | 34.36.137.203:443 | https://contile.services.mozilla.com/v1/tiles | unknown | text | 5.17 Kb | unknown |
7664 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | unknown |
7664 | firefox.exe | GET | 200 | 151.101.129.91:443 | https://firefox.settings.services.mozilla.com/v1/ | unknown | — | 1.20 Kb | unknown |
7664 | firefox.exe | GET | 200 | 151.101.129.91:443 | https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/ms-language-packs/records/cfr-v1-en-US | unknown | — | 330 b | unknown |
7664 | firefox.exe | POST | 200 | 142.251.143.35:80 | http://o.pki.goog/s/wr3/peI | unknown | — | — | whitelisted |
7664 | firefox.exe | POST | 200 | 142.251.143.35:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6244 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
6768 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4472 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
7664 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
7664 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
7664 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
7664 | firefox.exe | 151.101.129.91:443 | firefox.settings.services.mozilla.com | FASTLY | US | whitelisted |
7664 | firefox.exe | 142.251.208.10:443 | safebrowsing.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
content-signature-2.cdn.mozilla.net |
| whitelisted |
1000098.kefu.helps.live |
| unknown |
detectportal.firefox.com |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
safebrowsing.googleapis.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7664 | firefox.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspicious unencrypted POST request sending an email address |
7664 | firefox.exe | Potential Corporate Privacy Violation | ET INFO HTTP POST contains pass= in cleartext |
7664 | firefox.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspicious unencrypted POST request sending an email address |
7664 | firefox.exe | Potential Corporate Privacy Violation | ET INFO HTTP POST contains pass= in cleartext |