URL:

https://www.1024tera.com/spanish/sharing/link?surl=a21ISKFv795ugts6xCyWZw

Full analysis: https://app.any.run/tasks/3ffcf671-e35d-4b23-ba7e-aacc1a6eb2f0
Verdict: Malicious activity
Analysis date: May 14, 2024, 06:40:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

75AB6CF64564F203FC6E9C9276824EF7

SHA1:

3AFC466C81B5A05C3E944E0D4A0C70F2238DF2D8

SHA256:

81BF0F5797C692C58C275019188EF974C05037C369D87435A12D454451DCF8DB

SSDEEP:

3:N8DSLHSRSvWNs6HMLcKYrVUYa:2OLRis6HMcpUYa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • TeraBox.exe (PID: 2804)
    • Registers / Runs the DLL via REGSVR32.EXE

      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
    • Creates a writable file in the system directory

      • YunUtilityService.exe (PID: 2324)
    • Drops the executable file immediately after the start

      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
    • Reads the date of Windows installation

      • TeraBox.exe (PID: 2804)
    • Creates a software uninstall entry

      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3184)
      • regsvr32.exe (PID: 3504)
    • Reads the Internet Settings

      • TeraBoxWebService.exe (PID: 3924)
      • TeraBox.exe (PID: 3664)
      • AutoUpdate.exe (PID: 4056)
    • Reads security settings of Internet Explorer

      • TeraBoxWebService.exe (PID: 3924)
      • TeraBox.exe (PID: 3664)
      • AutoUpdate.exe (PID: 4056)
    • The process creates files with name similar to system file names

      • TeraBoxRender.exe (PID: 2344)
      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
    • Reads settings of System Certificates

      • TeraBox.exe (PID: 3664)
      • TeraBoxRender.exe (PID: 2668)
      • AutoUpdate.exe (PID: 4056)
    • Checks Windows Trust Settings

      • TeraBox.exe (PID: 3664)
      • YunUtilityService.exe (PID: 2324)
      • AutoUpdate.exe (PID: 4056)
    • Executes as Windows Service

      • YunUtilityService.exe (PID: 2324)
    • Adds/modifies Windows certificates

      • YunUtilityService.exe (PID: 2324)
    • Executable content was dropped or overwritten

      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
    • The process drops C-runtime libraries

      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
  • INFO

    • Manual execution by a user

      • wmpnscfg.exe (PID: 3020)
      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 316)
      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
    • Application launched itself

      • firefox.exe (PID: 3968)
      • firefox.exe (PID: 3984)
    • Creates files or folders in the user directory

      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
      • TeraBox.exe (PID: 2804)
      • TeraBox.exe (PID: 3664)
      • TeraBoxWebService.exe (PID: 3924)
      • TeraBoxHost.exe (PID: 3604)
      • TeraBoxHost.exe (PID: 2756)
      • AutoUpdate.exe (PID: 4056)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3020)
      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
      • TeraBox.exe (PID: 2804)
      • YunUtilityService.exe (PID: 3304)
      • TeraBoxWebService.exe (PID: 3924)
      • TeraBox.exe (PID: 3664)
      • TeraBoxWebService.exe (PID: 3552)
      • TeraBoxRender.exe (PID: 2344)
      • TeraBoxRender.exe (PID: 2900)
      • TeraBoxRender.exe (PID: 2668)
      • TeraBoxRender.exe (PID: 3604)
      • YunUtilityService.exe (PID: 2324)
      • TeraBoxRender.exe (PID: 3200)
      • TeraBoxHost.exe (PID: 3604)
      • TeraBoxHost.exe (PID: 2756)
      • AutoUpdate.exe (PID: 4056)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3020)
      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
      • TeraBox.exe (PID: 2804)
      • TeraBox.exe (PID: 3664)
      • YunUtilityService.exe (PID: 3304)
      • TeraBoxWebService.exe (PID: 3924)
      • TeraBoxRender.exe (PID: 2344)
      • TeraBoxRender.exe (PID: 2668)
      • TeraBoxRender.exe (PID: 3604)
      • YunUtilityService.exe (PID: 2324)
      • TeraBoxHost.exe (PID: 3604)
      • TeraBoxHost.exe (PID: 2756)
      • AutoUpdate.exe (PID: 4056)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 3984)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 3984)
    • The process uses the downloaded file

      • firefox.exe (PID: 3984)
    • Create files in a temporary directory

      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
      • TeraBox.exe (PID: 3664)
      • TeraBoxRender.exe (PID: 2668)
    • Reads the machine GUID from the registry

      • TeraBox.exe (PID: 2804)
      • TeraBoxWebService.exe (PID: 3924)
      • TeraBox.exe (PID: 3664)
      • TeraBoxRender.exe (PID: 2668)
      • TeraBoxHost.exe (PID: 3604)
      • YunUtilityService.exe (PID: 2324)
      • AutoUpdate.exe (PID: 4056)
    • Process checks computer location settings

      • TeraBox.exe (PID: 3664)
      • TeraBoxRender.exe (PID: 2900)
      • TeraBoxRender.exe (PID: 3200)
    • Checks proxy server information

      • TeraBoxWebService.exe (PID: 3924)
      • TeraBox.exe (PID: 3664)
      • AutoUpdate.exe (PID: 4056)
    • Reads the software policy settings

      • TeraBox.exe (PID: 3664)
      • TeraBoxRender.exe (PID: 2668)
      • YunUtilityService.exe (PID: 2324)
      • AutoUpdate.exe (PID: 4056)
    • Reads Environment values

      • TeraBox_sl_b_1.31.0.1(4).exe (PID: 3156)
    • Creates files in the program directory

      • TeraBoxHost.exe (PID: 3604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
77
Monitored processes
34
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs wmpnscfg.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs terabox_sl_b_1.31.0.1(4).exe no specs terabox_sl_b_1.31.0.1(4).exe terabox.exe regsvr32.exe no specs regsvr32.exe no specs yunutilityservice.exe no specs teraboxwebservice.exe no specs terabox.exe teraboxwebservice.exe teraboxrender.exe no specs teraboxrender.exe teraboxrender.exe no specs teraboxrender.exe no specs teraboxrender.exe no specs yunutilityservice.exe teraboxhost.exe teraboxhost.exe autoupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3984.1.1934869933\26544248" -parentBuildID 20230710165010 -prefsHandle 1440 -prefMapHandle 1436 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {591fa58d-073c-4ec5-9c4c-827c70c3ee61} 3984 "\\.\pipe\gecko-crash-server-pipe.3984" 1452 d8220d0 socketC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
316"C:\Users\admin\Downloads\TeraBox_sl_b_1.31.0.1(4).exe" C:\Users\admin\Downloads\TeraBox_sl_b_1.31.0.1(4).exeexplorer.exe
User:
admin
Company:
Flextech
Integrity Level:
MEDIUM
Description:
TeraBox Installer
Exit code:
3221226540
Version:
1.31.0.1
Modules
Images
c:\users\admin\downloads\terabox_sl_b_1.31.0.1(4).exe
c:\windows\system32\ntdll.dll
928"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3984.0.1610809843\137441533" -parentBuildID 20230710165010 -prefsHandle 1120 -prefMapHandle 1112 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ad1f33a4-8621-4362-aaf5-4721635550a0} 3984 "\\.\pipe\gecko-crash-server-pipe.3984" 1192 d8aaca0 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1008"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3984.7.1675492575\989330738" -childID 6 -isForBrowser -prefsHandle 3944 -prefMapHandle 3940 -prefsLen 34425 -prefMapSize 244195 -jsInitHandle 920 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c7105817-3495-420e-aa24-8bfdafb009e1} 3984 "\\.\pipe\gecko-crash-server-pipe.3984" 3904 17a31b20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1592"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3984.2.821024578\1623700771" -childID 1 -isForBrowser -prefsHandle 2060 -prefMapHandle 1904 -prefsLen 24491 -prefMapSize 244195 -jsInitHandle 920 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {13ccc04f-034b-4c08-bd8a-b71ac62dc680} 3984 "\\.\pipe\gecko-crash-server-pipe.3984" 1940 12dc2560 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1612"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3984.6.2136809063\1677400470" -childID 5 -isForBrowser -prefsHandle 3812 -prefMapHandle 3808 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 920 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6408cabb-3fc7-45b8-8ab2-5cbe51ef596b} 3984 "\\.\pipe\gecko-crash-server-pipe.3984" 3920 17a31f70 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2260"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3984.3.1337206941\584066144" -childID 2 -isForBrowser -prefsHandle 2852 -prefMapHandle 2848 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 920 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1a84a29a-379c-43ff-9fbb-47c8a8aff632} 3984 "\\.\pipe\gecko-crash-server-pipe.3984" 2864 161deb20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2324C:\Users\admin\AppData\Roaming\TeraBox\YunUtilityService.exeC:\Users\admin\AppData\Roaming\TeraBox\YunUtilityService.exe
services.exe
User:
SYSTEM
Company:
Flextech Inc.
Integrity Level:
SYSTEM
Description:
TeraBox Service Used to Quickly Apply For Disk Space
Exit code:
0
Version:
1.31.0.1
Modules
Images
c:\users\admin\appdata\roaming\terabox\yunutilityservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\userenv.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
2344"C:\Users\admin\AppData\Roaming\TeraBox\TeraBoxRender.exe" --type=gpu-process --field-trial-handle=2016,6959819072871851436,11714733104476260096,131072 --enable-features=CastMediaRouteProvider --no-sandbox --locales-dir-path="C:\Users\admin\AppData\Roaming\TeraBox\browserres\locales" --log-file="C:\Users\admin\AppData\Roaming\TeraBox\debug.log" --log-severity=disable --resources-dir-path="C:\Users\admin\AppData\Roaming\TeraBox\browserres" --user-agent="Mozilla/5.0; (Windows NT 6.1); AppleWebKit/537.36; (KHTML, like Gecko); Chrome/86.0.4240.198; Safari/537.36; terabox;1.31.0.1;PC;PC-Windows;6.1.7601;WindowsTeraBox" --lang=en-US --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --log-file="C:\Users\admin\AppData\Roaming\TeraBox\debug.log" --mojo-platform-channel-handle=2008 /prefetch:2C:\Users\admin\AppData\Roaming\TeraBox\TeraBoxRender.exeTeraBox.exe
User:
admin
Company:
Flextech Inc.
Integrity Level:
MEDIUM
Description:
TeraBoxRender
Exit code:
0
Version:
2.0.1.1
Modules
Images
c:\users\admin\appdata\roaming\terabox\teraboxrender.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\terabox\libcef.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
2456"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3984.4.2036035395\2079595685" -childID 3 -isForBrowser -prefsHandle 3720 -prefMapHandle 3004 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 920 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a900629f-46d0-4566-85ac-1c002cbdae62} 3984 "\\.\pipe\gecko-crash-server-pipe.3984" 3704 1394eb20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
60 863
Read events
60 391
Write events
434
Delete events
38

Modification events

(PID) Process:(3968) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
4C8D7CE300000000
(PID) Process:(3984) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
6CD27EE300000000
(PID) Process:(3984) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB
Operation:delete valueName:installer.taskbarpin.win10.enabled
Value:
(PID) Process:(3984) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(3984) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(3984) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(3984) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(3984) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(3984) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(3984) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
Executable files
89
Suspicious files
284
Text files
43
Unknown types
7

Dropped files

PID
Process
Filename
Type
3984firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
3984firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\activity-stream.discovery_stream.json
MD5:
SHA256:
3984firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3984firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:04BADC0A17F546BBD91CC2404D2776D9
SHA256:54CD83D3031D15EA1F5B1C5D73416C0B2F9151F93E130DD525DDA488A8EB9110
3984firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3984firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3984firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\targeting.snapshot.json
MD5:
SHA256:
3984firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:A4C0253717519EB0B07D5D8DD14F5D02
SHA256:115B88AA451EA9D5CD010C60DB4B97759E55ECE806CF6C4EBA737C6290C0D044
3984firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
3984firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:A4C0253717519EB0B07D5D8DD14F5D02
SHA256:115B88AA451EA9D5CD010C60DB4B97759E55ECE806CF6C4EBA737C6290C0D044
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
70
TCP/UDP connections
182
DNS requests
261
Threats
30

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3984
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
unknown
3984
firefox.exe
POST
200
192.229.221.95:80
http://status.rapidssl.com/
unknown
unknown
3984
firefox.exe
POST
200
192.229.221.95:80
http://status.rapidssl.com/
unknown
unknown
3984
firefox.exe
POST
200
23.216.154.115:80
http://r3.o.lencr.org/
unknown
unknown
3984
firefox.exe
POST
200
23.216.154.115:80
http://r3.o.lencr.org/
unknown
unknown
3984
firefox.exe
POST
200
216.58.212.131:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
3984
firefox.exe
POST
200
216.58.212.131:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
3984
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
unknown
3984
firefox.exe
POST
200
23.216.154.115:80
http://r3.o.lencr.org/
unknown
unknown
3984
firefox.exe
POST
200
23.216.154.115:80
http://r3.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
unknown
3984
firefox.exe
34.117.188.166:443
contile.services.mozilla.com
unknown
3984
firefox.exe
210.148.85.59:443
www.1024tera.com
Internet Initiative Japan Inc.
JP
unknown
3984
firefox.exe
142.250.185.74:443
safebrowsing.googleapis.com
whitelisted
3984
firefox.exe
216.58.212.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
3984
firefox.exe
34.107.243.93:443
push.services.mozilla.com
unknown
3984
firefox.exe
192.229.221.95:80
status.rapidssl.com
EDGECAST
US
whitelisted
3984
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
whitelisted
www.1024tera.com
  • 210.148.85.59
unknown
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.215.14
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
shared
prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
unknown
r3.o.lencr.org
  • 23.216.154.115
  • 23.216.154.169
  • 23.55.163.48
  • 23.55.163.58
shared
a1887.dscq.akamai.net
  • 23.216.154.115
  • 23.216.154.169
  • 2a02:26f0:3500:e::1732:8356
  • 2a02:26f0:3500:e::1732:834a
  • 2a02:26f0:3500:e::1732:8345
  • 2a02:26f0:3500:e::1732:8346
  • 2a02:26f0:3500:e::1732:8353
  • 23.55.163.48
  • 23.55.163.58
  • 2a02:26f0:480:e::210:f112
  • 2a02:26f0:480:e::210:f10f
whitelisted

Threats

PID
Process
Class
Message
1088
svchost.exe
Misc activity
ET INFO DNS Query to File Sharing Domain (terabox .com)
1088
svchost.exe
Misc activity
ET INFO DNS Query to File Sharing Domain (terabox .com)
1088
svchost.exe
Misc activity
ET INFO DNS Query to File Sharing Domain (terabox .com)
3984
firefox.exe
Misc activity
ET INFO Observed File Sharing Domain (terabox .com in TLS SNI)
3984
firefox.exe
Misc activity
ET INFO Observed File Sharing Domain (terabox .com in TLS SNI)
1088
svchost.exe
Misc activity
ET INFO DNS Query to File Sharing Domain (terabox .com)
1088
svchost.exe
Misc activity
ET INFO DNS Query to File Sharing Domain (terabox .com)
1088
svchost.exe
Misc activity
ET INFO DNS Query to File Sharing Domain (terabox .com)
3984
firefox.exe
Misc activity
ET INFO Observed File Sharing Domain (terabox .com in TLS SNI)
124
firefox.exe
Misc activity
ET INFO Session Traversal Utilities for NAT (STUN Binding Request)
Process
Message
TeraBoxHost.exe
vast_media--[2024-05-14 07:43:26:644] Initialized sdl_video_render_driver=software
TeraBoxHost.exe
vast_media--[2024-05-14 07:43:26:644] Initialized sdl_audio_play_driver=directsound
TeraBoxHost.exe
vast_media--[2024-05-14 07:43:26:644] Initialized hardware_type=3001