| URL: | cdn.tophd.xxx |
| Full analysis: | https://app.any.run/tasks/aa67b859-d38e-46ef-968a-2bd95e25482a |
| Verdict: | Malicious activity |
| Analysis date: | September 16, 2024, 08:38:20 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MD5: | EB57152A1412B0F30874EE968788A8B5 |
| SHA1: | D2B781693A2DA882C7A62EF300BB811299A138AE |
| SHA256: | 4C13CE7E11F820C1DD5CD6F5B351AA6021D7EA4A2F6552ECD6D114C9BA85579B |
| SSDEEP: | 3:Xx:Xx |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 508 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=3572 -childID 1 -isForBrowser -prefsHandle 3524 -prefMapHandle 3520 -prefsLen 21575 -prefMapSize 240426 -jsInitHandle 1272 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b625f029-9ab7-4917-880f-658fcc40db18} 6816 "\\.\pipe\gecko-crash-server-pipe.6816" 25295d83bd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 788 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5868 -childID 5 -isForBrowser -prefsHandle 5788 -prefMapHandle 5840 -prefsLen 31169 -prefMapSize 244343 -jsInitHandle 1240 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4f7113a1-4389-4f84-b387-e3eb31a506e5} 6556 "\\.\pipe\gecko-crash-server-pipe.6556" 1fe29ed7310 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1436 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1640 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4504 -childID 2 -isForBrowser -prefsHandle 4500 -prefMapHandle 4496 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1240 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7ef1f4e7-c077-4251-80e1-e45f2a4147ee} 6556 "\\.\pipe\gecko-crash-server-pipe.6556" 1fe249d0850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2256 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2268 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2864 -childID 1 -isForBrowser -prefsHandle 2856 -prefMapHandle 2840 -prefsLen 26706 -prefMapSize 244343 -jsInitHandle 1240 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {cd9639d9-fabe-42fc-9a3f-bf46f25b1ba9} 6556 "\\.\pipe\gecko-crash-server-pipe.6556" 1fe24869150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2576 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5416 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5348 -prefMapHandle 5420 -prefsLen 30985 -prefMapSize 240426 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {542accfe-0d74-4759-a731-bdc3d987cbaf} 6816 "\\.\pipe\gecko-crash-server-pipe.6816" 2529cba6510 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| 3292 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5380 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5248 -prefMapHandle 5356 -prefsLen 36393 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e2188ba4-6e85-4ba6-81e9-c7297b479323} 6556 "\\.\pipe\gecko-crash-server-pipe.6556" 1fe28924d10 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| 3448 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5500 -childID 3 -isForBrowser -prefsHandle 5396 -prefMapHandle 5408 -prefsLen 31169 -prefMapSize 244343 -jsInitHandle 1240 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {09221edc-77d5-486d-96c4-351647e19d12} 6556 "\\.\pipe\gecko-crash-server-pipe.6556" 1fe2902d150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 3980 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1764 -parentBuildID 20240213221259 -prefsHandle 1704 -prefMapHandle 1696 -prefsLen 19989 -prefMapSize 240426 -appDir "C:\Program Files\Mozilla Firefox\browser" - {51fd6696-8196-4100-bd76-42747992e687} 6816 "\\.\pipe\gecko-crash-server-pipe.6816" 25291fac610 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (6556) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (6816) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.db | sqlite | |
MD5:DCD493BAE88344DF0B76EEDB1FAD8964 | SHA256:BAC57D5971A555ED438C9B889C12A986F782A06E9EF81A0FE24113F7367E80A2 | |||
| 6556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.db-journal | binary | |
MD5:AE7ABE4B1D363930B58877C9070E59A6 | SHA256:8BC3B6D719B574CC781D1FF9A48333AF3F1051C1B44B685EFED6F19BC702139B | |||
| 6556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 6556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.tmp | dbf | |
MD5:F759EB25271E6A6F0A3500520813E5FE | SHA256:015E515D432DD64FDC9502ABE9C723EEF544E7AF11C36BDFE8B38412597CA1EC | |||
| 6556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage.sqlite-journal | binary | |
MD5:F02F5C379A82CE36D0F65A54BDDEF53E | SHA256:FEEFB42B82308DD9819E6ACB53E7FA978A87C6B421EFFF86CA04CEF27C2E2BE6 | |||
| 6556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6556 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:297E88D7CEB26E549254EC875649F4EB | SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702 | |||
| 6556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\protections.sqlite-journal | binary | |
MD5:664809EA5E7D45AD6E8DBDEEE6D8CB59 | SHA256:8E5B57F44F843A819A3ABC5C06EB86C7C07048BA3F5F27B555A2D981E4356E24 | |||
| 6556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6556 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6556 | firefox.exe | POST | 200 | 142.250.185.67:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
6556 | firefox.exe | GET | — | 104.21.49.31:80 | http://cdn.tophd.xxx/favicon.ico | unknown | — | — | whitelisted |
6556 | firefox.exe | POST | 200 | 2.16.202.115:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6556 | firefox.exe | POST | 200 | 2.16.202.115:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6556 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
6816 | firefox.exe | POST | 200 | 195.138.255.19:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6816 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6816 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2120 | MoUsoCoreWorker.exe | 52.185.211.133:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
— | — | 52.185.211.133:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4132 | svchost.exe | 52.185.211.133:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
— | — | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6556 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
6556 | firefox.exe | 104.21.49.31:80 | cdn.tophd.xxx | CLOUDFLARENET | — | whitelisted |
6556 | firefox.exe | 34.117.188.166:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
6556 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | GOOGLE | US | whitelisted |
6556 | firefox.exe | 142.250.186.42:443 | safebrowsing.googleapis.com | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
cdn.tophd.xxx |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
ipv4only.arpa |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
prod.ads.prod.webservices.mozgcp.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2256 | svchost.exe | Potential Corporate Privacy Violation | ET POLICY DNS Query For XXX Adult Site Top Level Domain |
2256 | svchost.exe | Potential Corporate Privacy Violation | ET POLICY DNS Query For XXX Adult Site Top Level Domain |
2256 | svchost.exe | Potential Corporate Privacy Violation | ET POLICY DNS Query For XXX Adult Site Top Level Domain |
6556 | firefox.exe | Potential Corporate Privacy Violation | ET POLICY request to .xxx TLD |
6556 | firefox.exe | Potential Corporate Privacy Violation | ET POLICY request to .xxx TLD |