URL:

https://malwarebytes.com

Full analysis: https://app.any.run/tasks/ed612f8d-7cfd-4bda-9a92-00337ff508a2
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: October 22, 2023, 11:50:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
antivirus
malwarebytes
falsenegative
Indicators:
MD5:

45325956ABBA8D049F4161DFA2661C64

SHA1:

474DF96ED31D74AC57FF4523EA65265401EE7EE4

SHA256:

5F4E8AE839F5E043A5268684DC98B482342C873E69B28F46FB4F17E89D330549

SSDEEP:

3:N8nzyT:2nGT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MBSetup.exe (PID: 2936)
      • MBSetup.exe (PID: 3712)
      • MBSetup.exe (PID: 760)
      • MBSetup.exe (PID: 3064)
      • MBAMInstallerService.exe (PID: 2820)
      • MBAMService.exe (PID: 3664)
      • MBAMService.exe (PID: 3520)
      • mbamtray.exe (PID: 3232)
    • Creates a writable file the system directory

      • MBSetup.exe (PID: 2936)
      • MBAMInstallerService.exe (PID: 2820)
      • MBAMService.exe (PID: 3520)
    • Actions looks like stealing of personal data

      • MBSetup.exe (PID: 2936)
      • MBAMService.exe (PID: 3520)
    • Drops the executable file immediately after the start

      • MBSetup.exe (PID: 2936)
      • MBAMService.exe (PID: 3520)
      • MBAMInstallerService.exe (PID: 2820)
    • Loads dropped or rewritten executable

      • MBAMInstallerService.exe (PID: 2820)
      • mbamtray.exe (PID: 3232)
      • MBAMService.exe (PID: 3520)
    • Steals credentials

      • MBAMService.exe (PID: 3520)
  • SUSPICIOUS

    • Reads the BIOS version

      • MBSetup.exe (PID: 2936)
      • MBAMService.exe (PID: 3520)
    • Searches for installed software

      • MBSetup.exe (PID: 2936)
      • MBAMInstallerService.exe (PID: 2820)
    • Creates files in the driver directory

      • MBSetup.exe (PID: 2936)
      • MBAMInstallerService.exe (PID: 2820)
      • MBAMService.exe (PID: 3520)
    • Reads settings of System Certificates

      • MBSetup.exe (PID: 2936)
      • mbamtray.exe (PID: 3232)
    • Reads the Internet Settings

      • MBSetup.exe (PID: 2936)
      • mbamtray.exe (PID: 3232)
    • The process verifies whether the antivirus software is installed

      • MBSetup.exe (PID: 2936)
      • MBAMService.exe (PID: 3664)
      • MBAMInstallerService.exe (PID: 2820)
      • mbamtray.exe (PID: 3232)
      • MBAMService.exe (PID: 3520)
    • Executes as Windows Service

      • MBAMInstallerService.exe (PID: 2820)
      • MBAMService.exe (PID: 3520)
    • Drops 7-zip archiver for unpacking

      • MBAMInstallerService.exe (PID: 2820)
    • Drops a system driver (possible attempt to evade defenses)

      • MBAMInstallerService.exe (PID: 2820)
      • MBAMService.exe (PID: 3520)
    • Process drops legitimate windows executable

      • MBAMInstallerService.exe (PID: 2820)
    • The process drops C-runtime libraries

      • MBAMInstallerService.exe (PID: 2820)
    • Changes Internet Explorer settings (feature browser emulation)

      • MBAMService.exe (PID: 3520)
    • Creates or modifies Windows services

      • MBAMService.exe (PID: 3520)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 3820)
      • firefox.exe (PID: 592)
    • The process uses the downloaded file

      • firefox.exe (PID: 592)
      • MBAMInstallerService.exe (PID: 2820)
    • Create files in a temporary directory

      • MBSetup.exe (PID: 2936)
    • Reads the machine GUID from the registry

      • MBSetup.exe (PID: 2936)
      • MBAMInstallerService.exe (PID: 2820)
      • MBAMService.exe (PID: 3520)
      • mbamtray.exe (PID: 3232)
    • Manual execution by a user

      • MBSetup.exe (PID: 3712)
      • MBSetup.exe (PID: 3064)
      • MBSetup.exe (PID: 2936)
      • MBSetup.exe (PID: 760)
    • Reads the computer name

      • MBSetup.exe (PID: 2936)
      • MBAMInstallerService.exe (PID: 2820)
      • MBAMService.exe (PID: 3664)
      • MBAMService.exe (PID: 3520)
      • mbamtray.exe (PID: 3232)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 592)
    • Checks supported languages

      • MBSetup.exe (PID: 2936)
      • MBSetup.exe (PID: 760)
      • MBAMInstallerService.exe (PID: 2820)
      • MBAMService.exe (PID: 3664)
      • MBAMService.exe (PID: 3520)
      • mbamtray.exe (PID: 3232)
    • Creates files in the program directory

      • MBSetup.exe (PID: 2936)
      • MBAMInstallerService.exe (PID: 2820)
      • MBAMService.exe (PID: 3520)
    • Reads Environment values

      • MBAMService.exe (PID: 3520)
    • Reads the time zone

      • MBAMService.exe (PID: 3520)
    • Reads CPU info

      • MBAMService.exe (PID: 3520)
    • Checks proxy server information

      • mbamtray.exe (PID: 3232)
    • Creates files or folders in the user directory

      • mbamtray.exe (PID: 3232)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
67
Monitored processes
21
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs mbsetup.exe no specs mbsetup.exe mbsetup.exe no specs mbsetup.exe mbaminstallerservice.exe mbamservice.exe no specs mbamservice.exe mbamtray.exe

Process information

PID
CMD
Path
Indicators
Parent process
592"C:\Program Files\Mozilla Firefox\firefox.exe" https://malwarebytes.comC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
604"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.6.1834680012\1913868419" -childID 5 -isForBrowser -prefsHandle 4144 -prefMapHandle 4156 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c7f613f6-9d55-434f-ad71-2366df731675} 592 "\\.\pipe\gecko-crash-server-pipe.592" 4064 198d8110 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
760"C:\Users\admin\Downloads\MBSetup.exe" C:\Users\admin\Downloads\MBSetup.exe
explorer.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
HIGH
Description:
Malwarebytes Setup
Exit code:
1
Version:
4.6.0.352
Modules
Images
c:\users\admin\downloads\mbsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
852"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.4.481525566\1392199420" -childID 3 -isForBrowser -prefsHandle 3560 -prefMapHandle 3732 -prefsLen 34332 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2e4c0378-a246-4c73-935d-ba241ef2c5d9} 592 "\\.\pipe\gecko-crash-server-pipe.592" 3564 135f59b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
948"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.9.205545885\1952482477" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 4536 -prefMapHandle 4540 -prefsLen 34499 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {98eb9b4e-19c8-477c-9c02-a7727a1c7fd9} 592 "\\.\pipe\gecko-crash-server-pipe.592" 4620 18d49bc0 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
1
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
2128"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.3.1948410886\732144727" -childID 2 -isForBrowser -prefsHandle 2860 -prefMapHandle 2856 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c5d78ec6-f5e3-4354-97e0-1f908279a930} 592 "\\.\pipe\gecko-crash-server-pipe.592" 2876 16651e00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2200"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.8.1356595037\1004478411" -parentBuildID 20230710165010 -prefsHandle 4548 -prefMapHandle 4556 -prefsLen 34499 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8e2e622c-ffdd-4dc1-8271-2212108305ca} 592 "\\.\pipe\gecko-crash-server-pipe.592" 4532 1aa4bba0 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
1
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2460"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="592.2.1922628499\1077684472" -childID 1 -isForBrowser -prefsHandle 2052 -prefMapHandle 2044 -prefsLen 24491 -prefMapSize 244195 -jsInitHandle 852 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7363a917-ddc4-4745-9f92-d8d463f01a77} 592 "\\.\pipe\gecko-crash-server-pipe.592" 2064 10c71840 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2820"C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe"C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe
services.exe
User:
SYSTEM
Company:
Malwarebytes
Integrity Level:
SYSTEM
Description:
Malwarebytes Installer Service
Exit code:
0
Version:
4.0.0.538
Modules
Images
c:\program files\malwarebytes\anti-malware\mbaminstallerservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\authz.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
2936"C:\Users\admin\Downloads\MBSetup.exe" C:\Users\admin\Downloads\MBSetup.exe
explorer.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
HIGH
Description:
Malwarebytes Setup
Exit code:
0
Version:
4.6.0.352
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\downloads\mbsetup.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
136 128
Read events
135 939
Write events
181
Delete events
8

Modification events

(PID) Process:(3820) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
2166C0A101000000
(PID) Process:(592) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
044CC1A101000000
(PID) Process:(592) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(592) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(592) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(592) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(592) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(592) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(592) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(592) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
D14E5F3C23B0D901
Executable files
334
Suspicious files
290
Text files
1 145
Unknown types
0

Dropped files

PID
Process
Filename
Type
592firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
592firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-walbinary
MD5:BA99A79627F03A2D5B5B9D97A12F9411
SHA256:1994C300C2AAA8EF7B5A92D9B7098200E0BBDB65BB9B4651F9796E7816014A30
592firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
592firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
592firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:60E0DE9E05EC76C749D80F0D15A81B21
SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48
592firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
592firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.dbbinary
MD5:11CF2BB29260EC5870F466C674A9FD7A
SHA256:48C86F58C6CACBC1983820509DBB91D53EF08D8AF6E6EDA05DA9A166916B123E
592firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
592firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journalbinary
MD5:F4C02692EE8331409551A78EB696E39F
SHA256:A818EFD8FADB61372E816B4C9D44FBDCE2F2ECFD9BD5827496B7ABB3951BC30C
592firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:60E0DE9E05EC76C749D80F0D15A81B21
SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
115
DNS requests
240
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
592
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
592
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
592
firefox.exe
POST
200
142.250.185.227:80
http://ocsp.pki.goog/gts1c3
unknown
binary
472 b
unknown
592
firefox.exe
POST
200
2.16.202.115:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
592
firefox.exe
POST
200
142.250.185.227:80
http://ocsp.pki.goog/gts1c3
unknown
binary
472 b
unknown
592
firefox.exe
POST
200
2.16.202.115:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
592
firefox.exe
POST
200
2.16.202.115:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
592
firefox.exe
POST
200
2.16.202.115:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
592
firefox.exe
POST
200
13.224.191.223:80
http://ocsp.r2m02.amazontrust.com/
unknown
binary
471 b
unknown
592
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
592
firefox.exe
52.222.214.121:443
malwarebytes.com
AMAZON-02
US
unknown
592
firefox.exe
172.217.16.202:443
safebrowsing.googleapis.com
whitelisted
592
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
unknown
592
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
592
firefox.exe
34.117.65.55:443
push.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
592
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
592
firefox.exe
107.20.123.120:443
spocs.getpocket.com
AMAZON-AES
US
unknown
592
firefox.exe
142.250.185.227:80
ocsp.pki.goog
GOOGLE
US
whitelisted
592
firefox.exe
2.16.202.115:80
r3.o.lencr.org
Akamai International B.V.
NL
unknown
592
firefox.exe
18.66.97.80:443
www.malwarebytes.com
US
unknown

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
whitelisted
malwarebytes.com
  • 52.222.214.121
  • 52.222.214.43
  • 52.222.214.90
  • 52.222.214.71
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
spocs.getpocket.com
  • 107.20.123.120
  • 54.88.171.25
  • 52.1.244.253
  • 54.88.170.35
shared
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 54.88.171.25
  • 107.20.123.120
  • 52.1.244.253
  • 54.88.170.35
shared
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted
r3.o.lencr.org
  • 2.16.202.115
  • 95.101.54.107
  • 95.101.54.130
  • 95.101.54.106
  • 95.101.54.203
  • 95.101.54.114
  • 95.101.54.211
  • 95.101.54.131
  • 95.101.54.195
  • 95.101.54.123
  • 95.101.54.200
  • 2.16.202.112
shared

Threats

No threats detected
Process
Message
mbamtray.exe
QAxBase::setControl: requested control {F36AD0D0-B5F0-4C69-AF08-603D177FEF0E} could not be instantiated
mbamtray.exe
void __thiscall _MBScanControllerSlots::OnControllerException(int,const class QString &,const class QString &,const class QString &) Controller error, code: -2147467259 source: "" description: "" help: ""