URL:

https://www.fosshub.com/qBittorrent.html

Full analysis: https://app.any.run/tasks/4666e551-bf47-4eba-aac4-1d4a3c8d4fac
Verdict: Malicious activity
Analysis date: September 29, 2024, 16:50:18
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

1AF734AED77CAA29BC62521ADA93E89B

SHA1:

512DEAEAFC9793B960A805FF1EF324A68762C282

SHA256:

4964BD0E6C51FAC410CAD7AAEB237354B191E6E377A284B64BA3DB10C11674DC

SSDEEP:

3:N8DSLWWKSmnMRRKXOLQ:2OLWWzmnMRRKXOLQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • qbittorrent_4.6.7_x64_setup.exe (PID: 3276)
      • qbittorrent_4.6.7_x64_setup.exe (PID: 8144)
    • Application launched itself

      • qbittorrent_4.6.7_x64_setup.exe (PID: 8144)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • qbittorrent_4.6.7_x64_setup.exe (PID: 3276)
    • Potential Corporate Privacy Violation

      • svchost.exe (PID: 2256)
      • qbittorrent.exe (PID: 6412)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 6292)
      • firefox.exe (PID: 2436)
    • Manual execution by a user

      • qbittorrent_4.6.7_x64_setup.exe (PID: 8144)
      • qbittorrent.exe (PID: 2396)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 2436)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
165
Monitored processes
41
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs svchost.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs qbittorrent_4.6.7_x64_setup.exe qbittorrent_4.6.7_x64_setup.exe qbittorrent.exe qbittorrent.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
940"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4472 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5108 -prefMapHandle 5208 -prefsLen 36339 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {04869e35-2056-4a7c-9f13-ee694af8dcbe} 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 23ddb01ad10 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2256C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2384"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4504 -childID 2 -isForBrowser -prefsHandle 4496 -prefMapHandle 4492 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1452 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {cee25b57-25c2-46c3-9688-cf6df7db64a5} 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 23dd8753850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2396"C:\Program Files\qBittorrent\qbittorrent.exe" "magnet:?xt=urn:btih:3b322ec276abb43d9bd29bedb360bb226118cefb&dn=Agatha.All.Along.S01E04.1080p.HEVC.x265-MeGusta.mkv"C:\Program Files\qBittorrent\qbittorrent.exeexplorer.exe
User:
admin
Company:
The qBittorrent Project
Integrity Level:
MEDIUM
Description:
qBittorrent - A Bittorrent Client
Exit code:
0
Version:
v4.6.7
Modules
Images
c:\program files\qbittorrent\qbittorrent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2436"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.fosshub.com/qBittorrent.htmlC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2480"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6184 -childID 6 -isForBrowser -prefsHandle 6192 -prefMapHandle 6196 -prefsLen 31108 -prefMapSize 244343 -jsInitHandle 1452 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {92c15157-02b4-4e12-9d99-405866ceb435} 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 23ddbbebf50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2632"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7136 -childID 8 -isForBrowser -prefsHandle 7164 -prefMapHandle 7144 -prefsLen 31169 -prefMapSize 244343 -jsInitHandle 1452 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ddbefffe-89f2-4f54-a741-c02b4b890ba8} 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 23dda117d90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2820"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=3000 -childID 1 -isForBrowser -prefsHandle 2992 -prefMapHandle 2988 -prefsLen 26641 -prefMapSize 244343 -jsInitHandle 1452 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4baf6d9f-407d-410e-bcc1-c0ccad86253d} 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 23dd7944150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3276"C:\Users\admin\Downloads\qbittorrent_4.6.7_x64_setup.exe" /UAC:C0216 /NCRC C:\Users\admin\Downloads\qbittorrent_4.6.7_x64_setup.exe
qbittorrent_4.6.7_x64_setup.exe
User:
admin
Company:
The qBittorrent project
Integrity Level:
HIGH
Description:
qBittorrent - A Bittorrent Client
Exit code:
0
Version:
4.6.7
Modules
Images
c:\users\admin\downloads\qbittorrent_4.6.7_x64_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3584"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7592 -childID 10 -isForBrowser -prefsHandle 7584 -prefMapHandle 7580 -prefsLen 31169 -prefMapSize 244343 -jsInitHandle 1452 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4f16701a-ef4a-489b-a48c-86be757ac52e} 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 23ddcf4a850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
41 429
Read events
41 407
Write events
22
Delete events
0

Modification events

(PID) Process:(2436) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(3276) qbittorrent_4.6.7_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\qBittorrent
Operation:writeName:InstallLocation
Value:
C:\Program Files\qBittorrent
(PID) Process:(3276) qbittorrent_4.6.7_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:DisplayName
Value:
qBittorrent
(PID) Process:(3276) qbittorrent_4.6.7_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:UninstallString
Value:
"C:\Program Files\qBittorrent\uninst.exe"
(PID) Process:(3276) qbittorrent_4.6.7_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:DisplayIcon
Value:
"C:\Program Files\qBittorrent\qbittorrent.exe",0
(PID) Process:(3276) qbittorrent_4.6.7_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:Publisher
Value:
The qBittorrent project
(PID) Process:(3276) qbittorrent_4.6.7_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:URLInfoAbout
Value:
https://www.qbittorrent.org
(PID) Process:(3276) qbittorrent_4.6.7_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:DisplayVersion
Value:
4.6.7
(PID) Process:(3276) qbittorrent_4.6.7_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:NoModify
Value:
1
(PID) Process:(3276) qbittorrent_4.6.7_x64_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent
Operation:writeName:NoRepair
Value:
1
Executable files
18
Suspicious files
256
Text files
66
Unknown types
0

Dropped files

PID
Process
Filename
Type
2436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
2436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:69A2317E1CE95726018AFAE20240C18C
SHA256:369DC82DD1AC305BFB7132809F4BDF04AC677A2319F481E905490319E87CD0CC
2436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
2436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:69A2317E1CE95726018AFAE20240C18C
SHA256:369DC82DD1AC305BFB7132809F4BDF04AC677A2319F481E905490319E87CD0CC
2436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:E22CF79A5D56C74F97F72B7F3D1F494A
SHA256:E70D8E2CBD59898BD357C7712305F8665211A87E428A47A063FDF29832001BE8
2436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.binbinary
MD5:536826A46AB5A4ABC46FD591989D6AD5
SHA256:8347973573F3F5FCB473F63A3D2EB6A04A553A4EA4CD92F40E0531DFD0C1B0DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
94
TCP/UDP connections
400
DNS requests
569
Threats
41

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2808
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2436
firefox.exe
POST
200
142.251.36.3:80
http://o.pki.goog/wr2
unknown
whitelisted
2436
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
2436
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
2436
firefox.exe
POST
200
2.16.2.75:80
http://r10.o.lencr.org/
unknown
whitelisted
2436
firefox.exe
POST
200
2.16.2.75:80
http://r10.o.lencr.org/
unknown
whitelisted
2436
firefox.exe
POST
200
2.16.2.75:80
http://r10.o.lencr.org/
unknown
whitelisted
2436
firefox.exe
POST
200
142.251.36.3:80
http://o.pki.goog/s/wr3/XjA
unknown
whitelisted
2436
firefox.exe
POST
200
2.16.2.75:80
http://r10.o.lencr.org/
unknown
whitelisted
2436
firefox.exe
POST
200
142.251.36.3:80
http://o.pki.goog/wr2
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2808
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2808
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2572
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4324
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2436
firefox.exe
104.20.226.61:443
www.fosshub.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.251.39.110
whitelisted
www.fosshub.com
  • 104.20.226.61
  • 2606:4700:10::6814:e23d
unknown
detectportal.firefox.com
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted
push.services.mozilla.com
  • 34.107.243.93
whitelisted
safebrowsing.googleapis.com
  • 172.217.23.202
  • 2a00:1450:400e:805::200a
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Potential Corporate Privacy Violation
ET POLICY DNS Query for TOR Hidden Domain .onion Accessible Via TOR
2256
svchost.exe
Potential Corporate Privacy Violation
ET POLICY DNS Query for TOR Hidden Domain .onion Accessible Via TOR
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2256
svchost.exe
Potential Corporate Privacy Violation
ET POLICY DNS Query for TOR Hidden Domain .onion Accessible Via TOR
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
2256
svchost.exe
Potential Corporate Privacy Violation
ET POLICY DNS Query for TOR Hidden Domain .onion Accessible Via TOR
No debug info