File name:

Firebird-2.1.1.17910-0_Win32.exe

Full analysis: https://app.any.run/tasks/72e8d83a-aaa5-4038-a0ed-9a9e21755ba3
Verdict: Malicious activity
Analysis date: May 29, 2024, 11:42:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C7F4EF2DE86DBCCB65DDFC3A105C7C96

SHA1:

95125D187B50369C0A03BA0D7D3EADBA862319BA

SHA256:

4D52A328AD8F75A2C63B37218ADD1C617746D2293CB2ADFB130F68EA03BFD255

SSDEEP:

98304:5tr7OGHeyHU7GYCMG6Mo4LsF5dBOs3Fu1wngQ8vhL70mgPllFdiyc7XAAZAMsQMK:wUqqWerbp/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Firebird-2.1.1.17910-0_Win32.exe (PID: 3976)
      • Firebird-2.1.1.17910-0_Win32.exe (PID: 2104)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • msiexec.exe (PID: 1872)
      • instclient.exe (PID: 1588)
    • Creates a writable file in the system directory

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • instclient.exe (PID: 1588)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Firebird-2.1.1.17910-0_Win32.exe (PID: 3976)
      • Firebird-2.1.1.17910-0_Win32.exe (PID: 2104)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • instclient.exe (PID: 1588)
    • Process drops legitimate windows executable

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • msiexec.exe (PID: 1872)
    • Reads the Windows owner or organization settings

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • msiexec.exe (PID: 1872)
    • The process drops C-runtime libraries

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • msiexec.exe (PID: 1872)
    • Executes as Windows Service

      • fbguard.exe (PID: 2364)
      • fbserver.exe (PID: 2232)
    • Reads the Internet Settings

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 3992)
  • INFO

    • Checks supported languages

      • Firebird-2.1.1.17910-0_Win32.exe (PID: 2104)
      • Firebird-2.1.1.17910-0_Win32.exe (PID: 3976)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 3992)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • msiexec.exe (PID: 2136)
      • instreg.exe (PID: 1664)
      • instclient.exe (PID: 1588)
      • msiexec.exe (PID: 1872)
      • instsvc.exe (PID: 1800)
      • instsvc.exe (PID: 580)
      • fbguard.exe (PID: 2364)
      • fbserver.exe (PID: 2232)
      • wmpnscfg.exe (PID: 1644)
      • instsvc.exe (PID: 1988)
    • Reads the computer name

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 3992)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • msiexec.exe (PID: 1872)
      • msiexec.exe (PID: 2136)
      • instsvc.exe (PID: 1988)
      • instsvc.exe (PID: 1800)
      • fbguard.exe (PID: 2364)
      • instsvc.exe (PID: 580)
      • fbserver.exe (PID: 2232)
      • wmpnscfg.exe (PID: 1644)
    • Create files in a temporary directory

      • Firebird-2.1.1.17910-0_Win32.exe (PID: 3976)
      • Firebird-2.1.1.17910-0_Win32.exe (PID: 2104)
      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • msiexec.exe (PID: 1872)
      • msiexec.exe (PID: 2116)
    • Creates files in the program directory

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • fbguard.exe (PID: 2364)
    • Creates a software uninstall entry

      • Firebird-2.1.1.17910-0_Win32.tmp (PID: 2108)
      • msiexec.exe (PID: 1872)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1872)
      • msiexec.exe (PID: 2136)
    • Application launched itself

      • msiexec.exe (PID: 1872)
      • msedge.exe (PID: 1804)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1872)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37376
InitializedDataSize: 17408
UninitializedDataSize: -
EntryPoint: 0x9a58
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Firebird Project
FileDescription: Firebird Setup
FileVersion:
LegalCopyright:
ProductName: Firebird
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
29
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start firebird-2.1.1.17910-0_win32.exe firebird-2.1.1.17910-0_win32.tmp no specs firebird-2.1.1.17910-0_win32.exe firebird-2.1.1.17910-0_win32.tmp msiexec.exe no specs msiexec.exe msiexec.exe no specs instreg.exe no specs instclient.exe instsvc.exe no specs instsvc.exe no specs instsvc.exe no specs fbguard.exe no specs fbserver.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
580"C:\Program Files\Firebird\Firebird_2_1\bin\instsvc.exe" start -n DefaultInstance C:\Program Files\Firebird\Firebird_2_1\bin\instsvc.exeFirebird-2.1.1.17910-0_Win32.tmp
User:
admin
Company:
Firebird Project
Integrity Level:
HIGH
Description:
Firebird SQL Server
Exit code:
0
Version:
WI-V2.1.1.17910
Modules
Images
c:\program files\firebird\firebird_2_1\bin\instsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1012"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1412 --field-trial-handle=1308,i,15232011365455749608,1856832425225134838,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1588"C:\Program Files\Firebird\Firebird_2_1\bin\instclient.exe" install gds32C:\Program Files\Firebird\Firebird_2_1\bin\instclient.exe
Firebird-2.1.1.17910-0_Win32.tmp
User:
admin
Company:
Firebird Project
Integrity Level:
HIGH
Description:
Firebird SQL Server
Exit code:
0
Version:
WI-V2.1.1.17910
Modules
Images
c:\program files\firebird\firebird_2_1\bin\instclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1612"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1648 --field-trial-handle=1308,i,15232011365455749608,1856832425225134838,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1644"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1664"C:\Program Files\Firebird\Firebird_2_1\bin\instreg.exe" install C:\Program Files\Firebird\Firebird_2_1\bin\instreg.exeFirebird-2.1.1.17910-0_Win32.tmp
User:
admin
Company:
Firebird Project
Integrity Level:
HIGH
Description:
Firebird SQL Server
Exit code:
0
Version:
WI-V2.1.1.17910
Modules
Images
c:\program files\firebird\firebird_2_1\bin\instreg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1800"C:\Program Files\Firebird\Firebird_2_1\bin\instsvc.exe" install -auto -superserver -guardian -n DefaultInstance C:\Program Files\Firebird\Firebird_2_1\bin\instsvc.exeFirebird-2.1.1.17910-0_Win32.tmp
User:
admin
Company:
Firebird Project
Integrity Level:
HIGH
Description:
Firebird SQL Server
Exit code:
0
Version:
WI-V2.1.1.17910
Modules
Images
c:\program files\firebird\firebird_2_1\bin\instsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1804"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.firebirdsql.org//afterinstallC:\Program Files\Microsoft\Edge\Application\msedge.exe
Firebird-2.1.1.17910-0_Win32.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1820"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6c07f598,0x6c07f5a8,0x6c07f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1872C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
10 959
Read events
10 774
Write events
168
Delete events
17

Modification events

(PID) Process:(2108) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Firebird\Firebird_2_1\IPLicense.txt
Value:
1
(PID) Process:(2108) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Firebird\Firebird_2_1\IDPLicense.txt
Value:
1
(PID) Process:(2108) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Firebird\Firebird_2_1\doc\After_Installation.url
Value:
1
(PID) Process:(2108) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Firebird\Firebird_2_1\doc\firebirdsql.org.url
Value:
1
(PID) Process:(2108) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Firebird\Firebird_2_1\firebird.msg
Value:
1
(PID) Process:(2108) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Firebird\Firebird_2_1\bin\gbak.exe
Value:
1
(PID) Process:(2108) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Firebird\Firebird_2_1\bin\gfix.exe
Value:
1
(PID) Process:(2108) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Firebird\Firebird_2_1\bin\gsec.exe
Value:
1
(PID) Process:(2108) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Firebird\Firebird_2_1\bin\gsplit.exe
Value:
1
(PID) Process:(2108) Firebird-2.1.1.17910-0_Win32.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Firebird\Firebird_2_1\bin\gstat.exe
Value:
1
Executable files
71
Suspicious files
275
Text files
377
Unknown types
10

Dropped files

PID
Process
Filename
Type
3976Firebird-2.1.1.17910-0_Win32.exeC:\Users\admin\AppData\Local\Temp\is-U94GK.tmp\Firebird-2.1.1.17910-0_Win32.tmpexecutable
MD5:52950AC9E2B481453082F096120E355A
SHA256:25FBC88C7C967266F041AE4D47C2EAE0B96086F9E440CCA10729103AEE7EF6CD
2108Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files\Firebird\Firebird_2_1\doc\is-AJUQL.tmpurl
MD5:9752F59E52A25912D39D50043CBFA232
SHA256:0AF69EC81E56D5E8BA22E368A41E7AFF5E72747F7C4C8EA225F77A9DAEFA2DA1
2108Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files\Firebird\Firebird_2_1\unins000.exeexecutable
MD5:6B940AFF068B86A6B1D3B1FAA08C5D24
SHA256:D65204C9BDACA1F052834B70EF3C90E1817B498871665EECF18357BDCAF7A290
2108Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files\Firebird\Firebird_2_1\IPLicense.txttext
MD5:29418614945D275B7AA89EA63C01DFCD
SHA256:FECE7C16035E212CCA352512A46791F090FF33E99B2DD7208E8F04F5323106B7
2108Firebird-2.1.1.17910-0_Win32.tmpC:\Users\admin\AppData\Local\Temp\is-QC27Q.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2108Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files\Firebird\Firebird_2_1\is-1SUSQ.tmpexecutable
MD5:6B940AFF068B86A6B1D3B1FAA08C5D24
SHA256:D65204C9BDACA1F052834B70EF3C90E1817B498871665EECF18357BDCAF7A290
2108Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files\Firebird\Firebird_2_1\is-HIRAA.tmptext
MD5:4F7696F9F8CB776E35922A2B9715A6B7
SHA256:A32B842BD833FBF127EF67267383901D0DA8F430006030B8CD931221A11E9D56
2108Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files\Firebird\Firebird_2_1\is-61P51.tmptext
MD5:29418614945D275B7AA89EA63C01DFCD
SHA256:FECE7C16035E212CCA352512A46791F090FF33E99B2DD7208E8F04F5323106B7
2108Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files\Firebird\Firebird_2_1\doc\is-S98I0.tmpurl
MD5:89C80A903264535AC6BF32728B5E2C0B
SHA256:7669EDE935CBDE28B806A319942D2D49074650A827CD9C1A16C0D9668CB03FC4
2108Firebird-2.1.1.17910-0_Win32.tmpC:\Program Files\Firebird\Firebird_2_1\doc\firebirdsql.org.urlurl
MD5:9752F59E52A25912D39D50043CBFA232
SHA256:0AF69EC81E56D5E8BA22E368A41E7AFF5E72747F7C4C8EA225F77A9DAEFA2DA1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
35
DNS requests
42
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1012
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1012
msedge.exe
172.67.146.203:443
www.firebirdsql.org
unknown
1804
msedge.exe
239.255.255.250:1900
unknown
1012
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1012
msedge.exe
172.217.16.202:443
fonts.googleapis.com
GOOGLE
US
whitelisted
1012
msedge.exe
142.250.185.67:443
fonts.gstatic.com
GOOGLE
US
whitelisted
1012
msedge.exe
172.64.154.11:443
firebirdfoundation.substack.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.firebirdsql.org
  • 172.67.146.203
  • 104.21.10.218
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
fonts.googleapis.com
  • 172.217.16.202
whitelisted
fonts.gstatic.com
  • 142.250.185.67
whitelisted
firebirdfoundation.substack.com
  • 172.64.154.11
  • 104.18.33.245
unknown
www.googletagmanager.com
  • 172.217.16.200
whitelisted
cdn.sendpulse.com
  • 156.146.33.141
  • 156.146.33.14
  • 212.102.56.182
  • 195.181.175.40
  • 212.102.56.179
  • 156.146.33.138
  • 195.181.175.15
whitelisted
connect.facebook.net
  • 157.240.251.9
whitelisted
ssl.google-analytics.com
  • 172.217.16.136
whitelisted

Threats

No threats detected
No debug info