URL:

https://doxbin.com/upload/DANIELMORAESBITTARPEDOFILOBYMLP&usg=AOvVaw008gB7CtENNVS7FTXFYJLN&opi=89978449

Full analysis: https://app.any.run/tasks/40af8fad-7e9a-4d70-8770-755fcea39135
Verdict: Malicious activity
Analysis date: July 14, 2023, 22:06:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

9AC2A4717D1EB416264C5CFC61949B0A

SHA1:

0B43F4E75E3159153CFAAC3752E9BB95997CE01D

SHA256:

51CD019972D97D7FDB88EA307727E284AEB9064247BEF184FC5C7046A383ED95

SSDEEP:

3:N8S9Kg2irsJlzYhk8obrQS/A7upn8vKdca:2SV2IsJlzMk8WQS/02n+Kdca

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • firefox.exe (PID: 3420)
      • firefox.exe (PID: 3696)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 3696)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
14
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1344"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3696.7.104177228\997768423" -childID 5 -isForBrowser -prefsHandle 2160 -prefMapHandle 1588 -prefsLen 29657 -prefMapSize 243323 -jsInitHandle 884 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b36760bf-36dc-4f7a-a91e-89096d23c8c3} 3696 "\\.\pipe\gecko-crash-server-pipe.3696" 3976 16fd39b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
1568"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3696.4.194444665\562446357" -childID 3 -isForBrowser -prefsHandle 2664 -prefMapHandle 2668 -prefsLen 24580 -prefMapSize 243323 -jsInitHandle 884 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fc57ddf7-f8db-4bb2-9b5b-3ee77a055f45} 3696 "\\.\pipe\gecko-crash-server-pipe.3696" 2652 15b5bf70 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
2032"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3696.10.95727460\669481931" -childID 8 -isForBrowser -prefsHandle 8300 -prefMapHandle 8304 -prefsLen 31910 -prefMapSize 243323 -jsInitHandle 884 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {890896af-abe6-479f-b2f0-b33c3550cffa} 3696 "\\.\pipe\gecko-crash-server-pipe.3696" 8288 1d2973f0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
2412"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3696.6.1294580233\624627666" -childID 4 -isForBrowser -prefsHandle 2172 -prefMapHandle 2128 -prefsLen 29553 -prefMapSize 243323 -jsInitHandle 884 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {3f46f10b-9e35-405b-8607-90d2478ea527} 3696 "\\.\pipe\gecko-crash-server-pipe.3696" 2424 e9f6b20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2664"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3696.1.1988104762\2024729527" -parentBuildID 20230710165010 -prefsHandle 1404 -prefMapHandle 1400 -prefsLen 25929 -prefMapSize 243323 -appDir "C:\Program Files\Mozilla Firefox\browser" - {510248c0-0c4c-4e70-ac36-f784b6940d2b} 3696 "\\.\pipe\gecko-crash-server-pipe.3696" 1416 e9bcee0 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3296"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3696.2.1796908071\1135685126" -childID 1 -isForBrowser -prefsHandle 2156 -prefMapHandle 2152 -prefsLen 24503 -prefMapSize 243323 -jsInitHandle 884 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d2f7e1b0-f54b-4248-bd3d-284c61783e89} 3696 "\\.\pipe\gecko-crash-server-pipe.3696" 2168 e9f6b20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3420"C:\Program Files\Mozilla Firefox\firefox.exe" "https://doxbin.com/upload/DANIELMORAESBITTARPEDOFILOBYMLP&usg=AOvVaw008gB7CtENNVS7FTXFYJLN&opi=89978449"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3652"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3696.5.1552386489\1112696510" -parentBuildID 20230710165010 -prefsHandle 3064 -prefMapHandle 3060 -prefsLen 27916 -prefMapSize 243323 -appDir "C:\Program Files\Mozilla Firefox\browser" - {34b6c7bd-e3b8-4c9c-98c5-c51f2d233c0e} 3696 "\\.\pipe\gecko-crash-server-pipe.3696" 3076 16216d60 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
3660"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3696.9.1739007469\205823754" -childID 7 -isForBrowser -prefsHandle 4144 -prefMapHandle 4120 -prefsLen 32990 -prefMapSize 243323 -jsInitHandle 884 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4e95440f-30e0-41a9-a480-5846c54d229e} 3696 "\\.\pipe\gecko-crash-server-pipe.3696" 4200 1acd5e00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
3688"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3696.8.244312264\2017194838" -childID 6 -isForBrowser -prefsHandle 4000 -prefMapHandle 3960 -prefsLen 29657 -prefMapSize 243323 -jsInitHandle 884 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {31ebdc69-3cba-4b2b-8c91-e903c9540044} 3696 "\\.\pipe\gecko-crash-server-pipe.3696" 4004 1acd53f0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
13 890
Read events
13 855
Write events
33
Delete events
2

Modification events

(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:delete valueName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
09611C1E1E000000
(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:delete valueName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
AD681C1E1E000000
(PID) Process:(3696) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(3696) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(3696) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(3696) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(3696) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3696) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000040010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3696) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|ScreenX
Value:
0
(PID) Process:(3696) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|ScreenY
Value:
43
Executable files
4
Suspicious files
184
Text files
82
Unknown types
0

Dropped files

PID
Process
Filename
Type
3696firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite-wal
MD5:
SHA256:
3696firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3696firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite-journalbinary
MD5:D248DFA921AFA17B8BD06978B6868A2D
SHA256:53FF1345F97ADA5217455D8262CBC75806AA896BA8617CBCD4FBB12D70F05CEA
3696firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.iniini
MD5:5A14BC3397EA072906B63D69FC704FEA
SHA256:03F45724EA1FE89E753AA76B40DE9078BFC9160AA1065ED9D4D98DA04B7FB3E7
3696firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:F406826E92F37E8DD190306ADCA35EAC
SHA256:0743F6032B5CA89E917F1679E36A67B13564005729AB0903E8D71D850C646C08
3696firefox.exeC:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates.xmlxml
MD5:D9BC3A7CCB24B554BE35C97FA3D7C7D3
SHA256:EF3711EB7E08CF646A50CCD66CB11DD88C7750BC1908CA09F5219269FEE3B348
3696firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20230710165010text
MD5:95CA1174E0AC03E11C26BFCE80157CBE
SHA256:239AD654746E98B50D4FC24A07DA4B2419A32DF9A2D43DB6F2944FCCA8E95576
3696firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite-shmbinary
MD5:6C7BA28367B300402B7D004F1349DCE0
SHA256:3CEDCEED86944D8C0BC451DEA6D7870F0977C56C773B5B22FE3CF313FE78F766
3696firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
3696firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:F406826E92F37E8DD190306ADCA35EAC
SHA256:0743F6032B5CA89E917F1679E36A67B13564005729AB0903E8D71D850C646C08
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
92
DNS requests
179
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3696
firefox.exe
POST
200
142.250.186.99:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
3696
firefox.exe
POST
200
184.24.77.48:80
http://r3.o.lencr.org/
US
der
503 b
shared
3696
firefox.exe
POST
200
184.24.77.48:80
http://r3.o.lencr.org/
US
binary
503 b
shared
3696
firefox.exe
POST
200
184.24.77.48:80
http://r3.o.lencr.org/
US
der
503 b
shared
3696
firefox.exe
POST
200
184.24.77.48:80
http://r3.o.lencr.org/
US
der
503 b
shared
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
3696
firefox.exe
POST
200
184.24.77.48:80
http://r3.o.lencr.org/
US
binary
503 b
shared
3696
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
text
90 b
whitelisted
3696
firefox.exe
POST
200
142.250.186.99:80
http://ocsp.pki.goog/gts1c3
US
binary
471 b
whitelisted
3696
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2640
svchost.exe
239.255.255.250:1900
whitelisted
3696
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
3696
firefox.exe
190.115.31.91:443
doxbin.com
DDOS-GUARD CORP.
BZ
suspicious
3696
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
suspicious
3696
firefox.exe
184.24.77.48:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
3696
firefox.exe
3.229.85.40:443
spocs.getpocket.com
AMAZON-AES
US
unknown
3696
firefox.exe
35.201.103.21:443
normandy.cdn.mozilla.net
GOOGLE
US
unknown
3696
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
suspicious

DNS requests

Domain
IP
Reputation
doxbin.com
  • 190.115.31.91
malicious
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
spocs.getpocket.com
  • 3.229.85.40
  • 3.229.237.11
  • 52.55.246.60
  • 54.88.103.11
shared
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 54.88.103.11
  • 52.55.246.60
  • 3.229.237.11
  • 3.229.85.40
shared
r3.o.lencr.org
  • 184.24.77.48
  • 184.24.77.81
  • 184.24.77.69
  • 184.24.77.47
  • 184.24.77.73
  • 184.24.77.53
  • 184.24.77.83
  • 184.24.77.45
  • 184.24.77.52
  • 184.24.77.67
  • 184.24.77.61
  • 184.24.77.55
  • 184.24.77.46
  • 184.24.77.56
  • 184.24.77.57
  • 184.24.77.44
  • 184.24.77.82
shared
a1887.dscq.akamai.net
  • 184.24.77.52
  • 184.24.77.45
  • 184.24.77.83
  • 184.24.77.53
  • 184.24.77.73
  • 184.24.77.47
  • 184.24.77.69
  • 184.24.77.81
  • 184.24.77.48
  • 2a02:26f0:1700:f::1737:a194
  • 2a02:26f0:1700:f::1737:a1a4
  • 184.24.77.56
  • 184.24.77.46
  • 184.24.77.55
  • 184.24.77.61
  • 184.24.77.67
  • 184.24.77.82
  • 184.24.77.44
  • 184.24.77.57
whitelisted

Threats

PID
Process
Class
Message
3696
firefox.exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
1 ETPRO signatures available at the full report
No debug info