File name:

upsupx3.exe

Full analysis: https://app.any.run/tasks/416420b6-6dd4-4131-9371-f85ce2da9f35
Verdict: Malicious activity
Analysis date: March 28, 2024, 17:50:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed
MD5:

219AD549C4D74BAAF85871C1EB484B2F

SHA1:

37BC156EF7C53E371314D020A551FD4AE1EDC041

SHA256:

6C33432C658BE9C33E8475CDF8C771AD96DEF493D7F8EFCB69BA8D251CCD4332

SSDEEP:

12288:j2xLBCxeU+rnJevdbt7VVVVVVVVVVVVVVVVVVVlVVVVVVVVVVVVVVVVVVV:KbCxeU+rnJevdx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • upsupx3.exe (PID: 4008)
      • Ninite 7Zip Installer.exe (PID: 3308)
      • target.exe (PID: 3412)
      • Ninite.exe (PID: 2096)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Ninite.exe (PID: 880)
      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 2096)
    • Reads security settings of Internet Explorer

      • Ninite.exe (PID: 880)
      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 2096)
    • Application launched itself

      • Ninite.exe (PID: 880)
    • Reads settings of System Certificates

      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 2096)
    • Checks Windows Trust Settings

      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 2096)
    • Adds/modifies Windows certificates

      • Ninite.exe (PID: 2096)
    • Drops 7-zip archiver for unpacking

      • Ninite.exe (PID: 2096)
      • target.exe (PID: 3412)
    • Searches for installed software

      • Ninite.exe (PID: 2096)
    • Cleans NTFS data stream (Zone Identifier)

      • Ninite.exe (PID: 2096)
    • Creates/Modifies COM task schedule object

      • target.exe (PID: 3412)
    • Creates a software uninstall entry

      • target.exe (PID: 3412)
    • Checks for Java to be installed

      • Ninite.exe (PID: 2096)
  • INFO

    • Checks supported languages

      • upsupx3.exe (PID: 4008)
      • wmpnscfg.exe (PID: 2756)
      • Ninite.exe (PID: 880)
      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 2096)
      • target.exe (PID: 3412)
      • 7zFM.exe (PID: 2732)
    • Manual execution by a user

      • notepad++.exe (PID: 116)
      • firefox.exe (PID: 1596)
      • explorer.exe (PID: 1928)
      • wmpnscfg.exe (PID: 2756)
      • WinRAR.exe (PID: 2632)
      • 7zFM.exe (PID: 2732)
    • Reads the computer name

      • upsupx3.exe (PID: 4008)
      • wmpnscfg.exe (PID: 2756)
      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 880)
      • Ninite.exe (PID: 2096)
      • target.exe (PID: 3412)
      • 7zFM.exe (PID: 2732)
    • The process uses the downloaded file

      • firefox.exe (PID: 3444)
      • Ninite.exe (PID: 2096)
    • Application launched itself

      • firefox.exe (PID: 1596)
      • firefox.exe (PID: 3444)
    • Checks proxy server information

      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 2096)
    • Reads the machine GUID from the registry

      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 2096)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 3444)
    • Reads the software policy settings

      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 2096)
    • Creates files or folders in the user directory

      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 2096)
    • Create files in a temporary directory

      • Ninite 7Zip Installer.exe (PID: 3308)
      • Ninite.exe (PID: 2096)
    • Creates files in the program directory

      • target.exe (PID: 3412)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (39.3)
.exe | Win32 EXE Yoda's Crypter (38.6)
.dll | Win32 Dynamic Link Library (generic) (9.5)
.exe | Win32 Executable (generic) (6.5)
.exe | Generic Win/DOS Executable (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:01:14 17:24:35+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 196608
InitializedDataSize: 49152
UninitializedDataSize: 315392
EntryPoint: 0x7d4a0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows command line
FileVersionNumber: 1.0.1.4
ProductVersionNumber: 1.0.1.4
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft compilation
FileDescription: Microsoft compilation
FileVersion: 1.0.1.4
InternalName: ce.exe
LegalCopyright: Copyright (C) 2023
OriginalFileName: ce.exe
ProductName: compilation
ProductVersion: 1.0.1.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
69
Monitored processes
22
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start upsupx3.exe no specs notepad++.exe wmpnscfg.exe no specs explorer.exe no specs winrar.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs ninite 7zip installer.exe ninite.exe no specs ninite.exe target.exe no specs 7zfm.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\Notepad++\notepad++.exe" "C:\Users\admin\Desktop\upsupx3.exe"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
552"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3444.0.735234950\533467010" -parentBuildID 20230710165010 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {bc3a2456-f528-4e4e-9c23-58847cbd675e} 3444 "\\.\pipe\gecko-crash-server-pipe.3444" 1180 d9a71a0 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
880Ninite.exe "f8c65629377b6fe2b110bd1868f87d36b5c80bb6" /fullpath "C:\Users\admin\Downloads\Ninite 7Zip Installer.exe"C:\Users\admin\AppData\Local\Temp\18e1945e-ed2c-11ee-ae0a-12a9866c77de\Ninite.exeNinite 7Zip Installer.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
MEDIUM
Description:
Ninite
Exit code:
0
Version:
0,1,1,1461
Modules
Images
c:\users\admin\appdata\local\temp\18e1945e-ed2c-11ee-ae0a-12a9866c77de\ninite.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1196"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3444.6.1733714616\1618329376" -childID 5 -isForBrowser -prefsHandle 3888 -prefMapHandle 3896 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 912 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {24473359-2d41-41e7-aa58-7616ed9daee7} 3444 "\\.\pipe\gecko-crash-server-pipe.3444" 3840 21a803f0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1596"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1928"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2096"C:\Users\admin\AppData\Local\Temp\18e1945e-ed2c-11ee-ae0a-12a9866c77de\Ninite.exe" "f8c65629377b6fe2b110bd1868f87d36b5c80bb6" /fullpath "C:\Users\admin\Downloads\Ninite 7Zip Installer.exe" /relaunchC:\Users\admin\AppData\Local\Temp\18e1945e-ed2c-11ee-ae0a-12a9866c77de\Ninite.exe
Ninite.exe
User:
admin
Company:
Secure By Design Inc.
Integrity Level:
HIGH
Description:
Ninite
Exit code:
0
Version:
0,1,1,1461
Modules
Images
c:\users\admin\appdata\local\temp\18e1945e-ed2c-11ee-ae0a-12a9866c77de\ninite.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2208"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3444.9.567080689\386894663" -childID 8 -isForBrowser -prefsHandle 4600 -prefMapHandle 4604 -prefsLen 31135 -prefMapSize 244195 -jsInitHandle 912 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {71348a61-98c3-4360-bde0-be38e17550e4} 3444 "\\.\pipe\gecko-crash-server-pipe.3444" 4588 16a529b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2632"C:\Program Files\WinRAR\WinRAR.exe" C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2640"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3444.1.956176411\1759816254" -parentBuildID 20230710165010 -prefsHandle 1404 -prefMapHandle 1400 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0db55b6c-17ea-4270-8bf8-753c604f971d} 3444 "\\.\pipe\gecko-crash-server-pipe.3444" 1416 d927520 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
42 066
Read events
41 825
Write events
215
Delete events
26

Modification events

(PID) Process:(116) notepad++.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2632) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Viewer
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF1600000016000000D60300000B020000
(PID) Process:(1596) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
E9AD256C01000000
(PID) Process:(3444) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
0731276C01000000
(PID) Process:(3444) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB
Operation:delete valueName:installer.taskbarpin.win10.enabled
Value:
(PID) Process:(3444) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(3444) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
Executable files
17
Suspicious files
42
Text files
131
Unknown types
121

Dropped files

PID
Process
Filename
Type
116notepad++.exeC:\Users\admin\AppData\Roaming\Notepad++\config.xmlxml
MD5:
SHA256:
116notepad++.exeC:\Users\admin\AppData\Roaming\Notepad++\session.xmltext
MD5:
SHA256:
3444firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:
SHA256:
3444firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:
SHA256:
3444firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:
SHA256:
3444firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsonbinary
MD5:
SHA256:
3444firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:
SHA256:
3444firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:
SHA256:
3444firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:
SHA256:
3444firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
84
DNS requests
156
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3444
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
unknown
3444
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
unknown
3444
firefox.exe
POST
200
2.22.242.122:80
http://r3.o.lencr.org/
unknown
unknown
3444
firefox.exe
POST
200
2.22.242.122:80
http://r3.o.lencr.org/
unknown
unknown
3444
firefox.exe
POST
200
2.22.242.122:80
http://r3.o.lencr.org/
unknown
unknown
3444
firefox.exe
POST
200
142.250.185.67:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
3444
firefox.exe
POST
200
2.22.242.122:80
http://r3.o.lencr.org/
unknown
unknown
3444
firefox.exe
POST
200
2.22.242.122:80
http://r3.o.lencr.org/
unknown
unknown
3444
firefox.exe
POST
2.22.242.122:80
http://r3.o.lencr.org/
unknown
unknown
3444
firefox.exe
POST
200
2.22.242.122:80
http://r3.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3444
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
3444
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3444
firefox.exe
34.117.188.166:443
spocs.getpocket.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3444
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
unknown
3444
firefox.exe
2.22.242.122:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
3444
firefox.exe
142.250.185.234:443
safebrowsing.googleapis.com
GOOGLE
US
whitelisted
3444
firefox.exe
34.107.243.93:443
push.services.mozilla.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
spocs.getpocket.com
  • 34.117.188.166
shared
prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
unknown
r3.o.lencr.org
  • 2.22.242.122
  • 2.22.242.107
  • 2.22.242.96
  • 2.22.242.99
  • 2.16.202.112
  • 95.101.54.99
  • 2.16.202.115
  • 95.101.54.203
  • 95.101.54.211
  • 2.16.202.121
  • 95.101.54.130
shared
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted
a1887.dscq.akamai.net
  • 2.22.242.122
  • 2.22.242.107
  • 2.22.242.96
  • 2.22.242.99
  • 2a02:26f0:3500:e::1732:8356
  • 2a02:26f0:3500:e::1732:834a
  • 2a02:26f0:3500:e::1732:8346
  • 2a02:26f0:3500:e::1732:835c
  • 95.101.54.130
  • 95.101.54.203
  • 95.101.54.211
  • 95.101.54.99
  • 2.16.202.115
  • 2.16.202.112
  • 2.16.202.121
  • 2a02:26f0:480:e::210:f10f
  • 2a02:26f0:480:e::210:f108
whitelisted

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3