| URL: | https://fumacrom.com/R7zM |
| Full analysis: | https://app.any.run/tasks/7010fa46-74f4-4bdd-8a9f-e495c0e3aa74 |
| Verdict: | Malicious activity |
| Analysis date: | September 28, 2021, 06:52:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 72319A79306A81D1D9A6A1AA3AE15BBC |
| SHA1: | CFCC001EBC23C1084C34768A54D4A1BAA80FB4AE |
| SHA256: | 6E15071929A18A31DA8CC554726531AE106776D60DBBFCDCCDDD8D0372FE1CEA |
| SSDEEP: | 3:N8TXTLf:2L |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1844 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2132.3.1686041655\2114914742" -childID 2 -isForBrowser -prefsHandle 2824 -prefMapHandle 2808 -prefsLen 5260 -prefMapSize 246031 -jsInit 916 285716 -parentBuildID 20210804193234 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2132 "\\.\pipe\gecko-crash-server-pipe.2132" 2844 1fe103a8 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 2036 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2132.5.312785512\49732583" -childID 3 -isForBrowser -prefsHandle 3512 -prefMapHandle 3552 -prefsLen 5920 -prefMapSize 246031 -jsInit 916 285716 -parentBuildID 20210804193234 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2132 "\\.\pipe\gecko-crash-server-pipe.2132" 3536 219833a8 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 2132 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://fumacrom.com/R7zM | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 2508 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2132.0.1213149681\1693828007" -parentBuildID 20210804193234 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 1 -prefMapSize 246031 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2132 "\\.\pipe\gecko-crash-server-pipe.2132" 1180 d594758 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 2776 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2132.1.1285634141\244720349" -childID 1 -isForBrowser -prefsHandle 1900 -prefMapHandle 1896 -prefsLen 218 -prefMapSize 246031 -jsInit 916 285716 -parentBuildID 20210804193234 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2132 "\\.\pipe\gecko-crash-server-pipe.2132" 1912 1afb43a8 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 2788 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2132.7.918609021\1395731227" -childID 4 -isForBrowser -prefsHandle 3780 -prefMapHandle 3772 -prefsLen 5920 -prefMapSize 246031 -jsInit 916 285716 -parentBuildID 20210804193234 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2132 "\\.\pipe\gecko-crash-server-pipe.2132" 3800 21983f78 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| 3528 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://fumacrom.com/R7zM" | C:\Program Files\Mozilla Firefox\firefox.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 91.0 Modules
| |||||||||||||||
| (PID) Process: | (3528) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 24B6265620000000 | |||
| (PID) Process: | (2132) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: F7BD265620000000 | |||
| (PID) Process: | (2132) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (2132) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (2132) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (2132) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (2132) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (2132) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (2132) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|ServicesSettingsServer |
Value: https://firefox.settings.services.mozilla.com/v1 | |||
| (PID) Process: | (2132) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash |
Value: 97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2132 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 2132 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:— | SHA256:— | |||
| 2132 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 2132 | firefox.exe | C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\update-config.json | text | |
MD5:— | SHA256:— | |||
| 2132 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QLDYZ5~1.DEF\cert9.db | sqlite | |
MD5:— | SHA256:— | |||
| 2132 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QLDYZ5~1.DEF\cert9.db-journal | binary | |
MD5:— | SHA256:— | |||
| 2132 | firefox.exe | C:\Users\admin\AppData\Local\Temp\mz_etilqs_IZdjNO470F84FXb | binary | |
MD5:— | SHA256:— | |||
| 2132 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journal | binary | |
MD5:— | SHA256:— | |||
| 2132 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | text | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2132 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2132 | firefox.exe | GET | 200 | 172.67.159.248:80 | http://hurirk.net/-89918HOAU/R7zM?rndad=3224007696-1632811965 | US | html | 5.11 Kb | malicious |
2132 | firefox.exe | POST | 200 | 142.251.36.35:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
2132 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2132 | firefox.exe | GET | 200 | 172.67.159.248:80 | http://hurirk.net/.well-known/http-opportunistic | US | text | 41 b | malicious |
2132 | firefox.exe | GET | 200 | 172.67.159.248:80 | http://cdn.hurirk.net/static/js/main.js | US | compressed | 667 b | malicious |
2132 | firefox.exe | GET | 200 | 172.67.159.248:80 | http://cdn.hurirk.net/static/js/view117_bidshow.js | US | compressed | 3.93 Kb | malicious |
2132 | firefox.exe | GET | 200 | 172.67.159.248:80 | http://cdn.hurirk.net/.well-known/http-opportunistic | US | text | 45 b | malicious |
2132 | firefox.exe | GET | 200 | 172.67.159.248:80 | http://cdn.hurirk.net/static/js/amvn.js | US | compressed | 80.6 Kb | malicious |
2132 | firefox.exe | GET | 200 | 172.67.152.78:80 | http://aswemaching.xyz/QVVCVzUgNyE6CiBoIHFAMzl/cgcHcHARUXMgcDtDcz10IgR5LCF5Vi06NzNTMzosIxsvMDZyBwcSJjtnBgYaOGMOLCUhZxAcex5bExsQOgRzMwcvZBE/FzpzAA8yE2QEPw0uBTQzOxZZBAIDbnQDHzIzB3kCBC1aKTEEIGEOPBRnZnAUcx5cNR0TOXw4GhACUSAGB2FyNhR7GnYEMAYTBCYFACN5DgYpLXA5OnYdBzkcDxBzLjAUbnAbEnZyBwMQOjBCCgF2HWBzD3AdQnQBGDlvZGcEAXAlLSYGQScHBQYFEWR7EXMZbHYBcBtsG2RBChAWElkIPRQDbyZ4AGBmKjEpM1spHhBkc3EwECBTCzwPIXMQYDozdHgREGRFczc1bnlnPzE4WzFoCR9sDCwqYW8SEA | US | compressed | 1.14 Kb | malicious |
2132 | firefox.exe | POST | 200 | 142.251.36.35:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2132 | firefox.exe | 13.227.219.45:443 | firefox.settings.services.mozilla.com | — | US | suspicious |
2132 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | — | US | whitelisted |
2132 | firefox.exe | 104.21.94.98:443 | fumacrom.com | Cloudflare Inc | US | suspicious |
2132 | firefox.exe | 216.58.208.106:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
2132 | firefox.exe | 65.9.73.22:443 | content-signature-2.cdn.mozilla.net | AT&T Services, Inc. | US | unknown |
2132 | firefox.exe | 142.251.36.35:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
2132 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2132 | firefox.exe | 172.67.159.248:80 | hurirk.net | — | US | malicious |
2132 | firefox.exe | 172.67.159.248:443 | hurirk.net | — | US | malicious |
2132 | firefox.exe | 142.251.36.42:443 | ajax.googleapis.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
firefox.settings.services.mozilla.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
fumacrom.com |
| unknown |
safebrowsing.googleapis.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
content-signature-2.cdn.mozilla.net |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
hurirk.net |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
2132 | firefox.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2132 | firefox.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2132 | firefox.exe | Generic Protocol Command Decode | SURICATA Applayer Mismatch protocol both directions |
2132 | firefox.exe | Generic Protocol Command Decode | SURICATA Applayer Mismatch protocol both directions |
2132 | firefox.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2132 | firefox.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2132 | firefox.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2132 | firefox.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2132 | firefox.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2132 | firefox.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |