File name:

imyfone-fixppo-9.0.3-crack-with-registration-code-2024_archive.torrent

Full analysis: https://app.any.run/tasks/e4e9f86f-5e4a-4cff-ab2d-5e426bd676ac
Verdict: Malicious activity
Analysis date: March 11, 2025, 08:52:38
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
obfuscated-js
bittorrent
Indicators:
MIME: application/x-bittorrent
File info: BitTorrent file
MD5:

AB54D744A1CD31F41EC00E1922DB4CD0

SHA1:

E422F59A7AD56614BA22537358657488BA05AC00

SHA256:

456CDA19A3E92D07701933A621F4FE320759442D3B5BE041BE77797913348589

SSDEEP:

48:H2Cx/6OEBlf5PQwY7Kpw1kJxECpUx77/u67Ib7KrwDL:rx/6OaPQwYEskJxE1x77u67Ib+kL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • BITTORRENT has been detected (SURICATA)

      • qbittorrent.exe (PID: 7720)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9240)
      • qbittorrent_5.0.4_x64_setup.exe (PID: 9616)
    • Application launched itself

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9240)
    • Creates a software uninstall entry

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9616)
    • The process creates files with name similar to system file names

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9616)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9616)
    • There is functionality for taking screenshot (YARA)

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9616)
      • qbittorrent_5.0.4_x64_setup.exe (PID: 9240)
      • qbittorrent.exe (PID: 7720)
  • INFO

    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 6668)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 6644)
      • firefox.exe (PID: 8016)
    • Application launched itself

      • firefox.exe (PID: 2140)
      • firefox.exe (PID: 6644)
      • firefox.exe (PID: 8016)
      • firefox.exe (PID: 8012)
    • The sample compiled with english language support

      • firefox.exe (PID: 6644)
      • qbittorrent_5.0.4_x64_setup.exe (PID: 9616)
    • Manual execution by a user

      • firefox.exe (PID: 2140)
      • firefox.exe (PID: 8012)
      • WinRAR.exe (PID: 728)
      • WinRAR.exe (PID: 4980)
      • notepad.exe (PID: 9656)
    • Reads the computer name

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9240)
      • qbittorrent_5.0.4_x64_setup.exe (PID: 9616)
    • Process checks computer location settings

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9240)
    • Checks supported languages

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9240)
    • Creates files in the program directory

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9616)
    • Qt framework related mutex has been found

      • qbittorrent.exe (PID: 7720)
    • Create files in a temporary directory

      • qbittorrent_5.0.4_x64_setup.exe (PID: 9240)
      • qbittorrent_5.0.4_x64_setup.exe (PID: 9616)
    • Reads the software policy settings

      • slui.exe (PID: 3268)
    • Creates files or folders in the user directory

      • qbittorrent.exe (PID: 7720)
    • Reads the machine GUID from the registry

      • qbittorrent.exe (PID: 7720)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.torrent | Torrent (trackerless) (57.6)
.torrent | Torrent (42.3)

EXIF

Torrent

Announce: http://bt1.archive.org:6969/announce
AnnounceList1: http://bt1.archive.org:6969/announce
AnnounceList2: http://bt2.archive.org:6969/announce
Comment: (Binary data 774 bytes, use -b option to extract)
Creator: ia_make_torrent
CreateDate: 2025:01:30 01:40:54+00:00
Collections1: org.archive.imyfone-fixppo-9.0.3-crack-with-registration-code-2024
Crc32_1: f0784e1f
File1Length: 9.5 kB
Md5_1: 86fba220810b1265f84a0ae3b4c9c7b0
Mtime1: 1712420337
File1Path: __ia_thumb.jpg
Sha1: 56b0fdcdcabd347ff3e1ac551d621a120b745089
Crc32_2: b3f44bbf
File2Length: 5.4 kB
Md5_2: 32e5a4995cfad8aa4f83b884fde5d366
Mtime2: 1712420307
File2Path: download-2024-01-20T224411.723.jpg
Sha2: e4faa46562af460762ba5f24ea6a192dedc162c7
Crc32_3: 483ff9e4
File3Length: 8.0 kB
Md5_3: 33e0cfb0092907c3efe67700e871d117
Mtime3: 1712420363
File3Path: download-2024-01-20T224411.723_thumb.jpg
Sha3: bc953c51b0b5d57599a73794c7843b3d6de87072
Crc32_4: 4ffcc753
File4Length: 37 kB
Md5_4: fa94dc8cc861fdc427159d18faf5a4c2
Mtime4: 1712420334
File4Path: imyfone-fixppo-9.0.3-crack-with-registration-code-2024_meta.sqlite
Sha4: af08db746796a6471a5140a3a3f9977ac832998a
Crc32_5: e3dd85ba
File5Length: 5.2 kB
Md5_5: d2b3051711a09de9e19c293bb3604daa
Mtime5: 1738134398
File5Path: imyfone-fixppo-9.0.3-crack-with-registration-code-2024_meta.xml
Sha5: 842389f8b34ce2d31f3343b98f41410bf9485f6e
Name: imyfone-fixppo-9.0.3-crack-with-registration-code-2024
PieceLength: 524288
Pieces: (Binary data 20 bytes, use -b option to extract)
Locale: en
Title: imyfone-fixppo-9.0.3-crack-with-registration-code-2024
URLList1: https://archive.org/download/
URLList2: http://ia600308.us.archive.org/1/items/
URLList3: http://ia800308.us.archive.org/1/items/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
198
Monitored processes
60
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start openwith.exe no specs sppextcomobj.exe no specs slui.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs qbittorrent_5.0.4_x64_setup.exe qbittorrent_5.0.4_x64_setup.exe slui.exe #BITTORRENT qbittorrent.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs notepad.exe no specs rundll32.exe no specs winrar.exe no specs winrar.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
728"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Downloads\KeyForgeX.zip" C:\Users\admin\Downloads\KeyForgeX\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
968"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5372 -childID 5 -isForBrowser -prefsHandle 5300 -prefMapHandle 5308 -prefsLen 31870 -prefMapSize 244679 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {43be8ade-f5e8-48be-adf1-77744a0d14ee} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 1d32f30ba10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\msvcp140.dll
1056"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1900 -parentBuildID 20240213221259 -prefsHandle 1828 -prefMapHandle 1816 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4ef0759f-b7b7-4ded-a09b-93d9c96ba155} 6644 "\\.\pipe\gecko-crash-server-pipe.6644" 264f10f1510 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
1676"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5988 -childID 11 -isForBrowser -prefsHandle 6268 -prefMapHandle 6272 -prefsLen 31366 -prefMapSize 244583 -jsInitHandle 1392 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {eb5a6f18-e2e5-4f85-8216-3bbcb74fe2d0} 6644 "\\.\pipe\gecko-crash-server-pipe.6644" 264fc58fd90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2140"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\crypt32.dll
2140"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5552 -childID 25 -isForBrowser -prefsHandle 5784 -prefMapHandle 5780 -prefsLen 32150 -prefMapSize 244583 -jsInitHandle 1392 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4ce8a483-12b7-4036-b4c0-ce3e3c96455a} 6644 "\\.\pipe\gecko-crash-server-pipe.6644" 264fc8a7d90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2852C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3268"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3676"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5680 -childID 10 -isForBrowser -prefsHandle 6176 -prefMapHandle 6140 -prefsLen 31366 -prefMapSize 244583 -jsInitHandle 1392 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c80120d3-ed3c-4289-97f9-419806179a9d} 6644 "\\.\pipe\gecko-crash-server-pipe.6644" 264fb8fd150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
57 865
Read events
57 836
Write events
29
Delete events
0

Modification events

(PID) Process:(6644) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(6644) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(9616) qbittorrent_5.0.4_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:DisplayName
Value:
qBittorrent
(PID) Process:(9616) qbittorrent_5.0.4_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:UninstallString
Value:
"C:\Program Files\qBittorrent\uninst.exe"
(PID) Process:(9616) qbittorrent_5.0.4_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:DisplayIcon
Value:
"C:\Program Files\qBittorrent\qbittorrent.exe",0
(PID) Process:(9616) qbittorrent_5.0.4_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:Publisher
Value:
The qBittorrent project
(PID) Process:(9616) qbittorrent_5.0.4_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:URLInfoAbout
Value:
https://www.qbittorrent.org
(PID) Process:(9616) qbittorrent_5.0.4_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:DisplayVersion
Value:
5.0.4
(PID) Process:(9616) qbittorrent_5.0.4_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:NoModify
Value:
1
(PID) Process:(9616) qbittorrent_5.0.4_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:NoRepair
Value:
1
Executable files
14
Suspicious files
308
Text files
55
Unknown types
0

Dropped files

PID
Process
Filename
Type
6644firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
6644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.binbinary
MD5:76AF3298C8A0225EFC7A19C2F24711D0
SHA256:EFBE7E99EF243668CDF6D6C4740DD9D514A25631451AFDB7094BB4817B3944F4
6644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
6644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
6644firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.binbinary
MD5:C95DDC2B1A525D1A243E4C294DA2F326
SHA256:3A5919E086BFB31E36110CF636D2D5109EB51F2C410B107F126126AB25D67363
6644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-walbinary
MD5:2A7E73B56803EAD4BBB84B4E6D90B0D6
SHA256:4B9EFAACD5E66B6EA659FEA204B2F0EF7B69451F8A075B7D08BC40BE950C6479
6644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6644firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
141
TCP/UDP connections
566
DNS requests
585
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6644
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/we2
unknown
whitelisted
6644
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/we2
unknown
whitelisted
6644
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/s/wr3/UTA
unknown
whitelisted
6644
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6644
firefox.exe
POST
200
23.32.238.82:80
http://r10.o.lencr.org/
unknown
whitelisted
6644
firefox.exe
POST
200
23.32.238.82:80
http://r10.o.lencr.org/
unknown
whitelisted
6644
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/we2
unknown
whitelisted
6644
firefox.exe
POST
200
184.24.77.48:80
http://r11.o.lencr.org/
unknown
whitelisted
6644
firefox.exe
POST
200
142.250.186.163:80
http://o.pki.goog/we2
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6644
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
6644
firefox.exe
34.117.188.166:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
6644
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
google.com
  • 216.58.206.78
whitelisted
client.wns.windows.com
  • 40.113.103.199
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.160.64
  • 20.190.160.65
  • 20.190.160.22
  • 40.126.32.72
  • 40.126.32.138
  • 20.190.160.67
  • 20.190.160.17
  • 20.190.160.132
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 23.51.98.7
  • 2.17.190.73
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
whitelisted
example.org
  • 96.7.128.186
  • 96.7.128.192
  • 23.215.0.133
  • 23.215.0.132
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
6644
firefox.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6644
firefox.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6644
firefox.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7720
qbittorrent.exe
Misc activity
INFO [ANY.RUN] P2P BitTorrent Protocol
No debug info