| URL: | https://github.com/Profthm/Freevps64/blob/main/rustdesk-1.2.3-x86_64.exe |
| Full analysis: | https://app.any.run/tasks/2ba3dc03-6558-42d8-a0b6-65958f295c37 |
| Verdict: | Malicious activity |
| Analysis date: | July 08, 2025, 15:53:42 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| MD5: | B263A8336BC9FECA6E628A58F463230E |
| SHA1: | 9BB97F53EC1FC8A654D43C768DE9AE7DB5D40786 |
| SHA256: | 82100ECE6B0E6158C17687390691FB3909CBA2FB886856A734226A86A9C4F5CB |
| SSDEEP: | 3:N8tEdOrIalOskHTERAzLXJRO:2uYIalITs0L5RO |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1100 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3384 -prefsLen 36996 -prefMapHandle 3380 -prefMapSize 272997 -ipcHandle 3396 -initialChannelId {132b861f-c217-475e-9673-3da0883171d6} -parentPid 6208 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6208" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 1300 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4180 -prefsLen 44823 -prefMapHandle 4184 -prefMapSize 272997 -jsInitHandle 4188 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4196 -initialChannelId {6f8162c3-bb32-4e91-9f9e-d0f31e12709e} -parentPid 6208 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6208" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 1440 | C:\Windows\System32\RuntimeBroker.exe -Embedding | C:\Windows\System32\RuntimeBroker.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Runtime Broker Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1660 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3376 -prefsLen 31090 -prefMapHandle 3380 -prefMapSize 272997 -jsInitHandle 3384 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3392 -initialChannelId {fa6b4143-35ee-43f3-88cf-ae82c71b6f35} -parentPid 6208 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6208" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 1944 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://github.com/Profthm/Freevps64/blob/main/rustdesk-1.2.3-x86_64.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 2200 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2520 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6756 -prefsLen 39438 -prefMapHandle 6792 -prefMapSize 272997 -jsInitHandle 6796 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6804 -initialChannelId {3ed82a86-fca8-4578-8e29-2d4ec65e25d6} -parentPid 6208 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6208" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 12 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 2528 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 1908 -prefsLen 36520 -prefMapHandle 1912 -prefMapSize 272997 -ipcHandle 1280 -initialChannelId {2a011e16-7a0e-473c-9387-5c153e7379e1} -parentPid 6208 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6208" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 3028 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 0 -prefsHandle 4620 -prefsLen 44979 -prefMapHandle 4624 -prefMapSize 272997 -ipcHandle 4632 -initialChannelId {67ee687f-c12a-4682-93a9-1f4407eb29a5} -parentPid 6208 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6208" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 6 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 3740 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4840 -prefsLen 44957 -prefMapHandle 4836 -prefMapSize 272997 -jsInitHandle 4832 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4828 -initialChannelId {c0af7e2b-32b2-407b-b05c-77cc59af065a} -parentPid 6208 -crashReporter "\\.\pipe\gecko-crash-server-pipe.6208" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| (PID) Process: | (6208) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (6208) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (1440) RuntimeBroker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{4B0964E4-58F1-47F4-A552-E2E1FC56DCD7} |
| Operation: | write | Name: | DeviceTicket |
Value: 0100000001000000D08C9DDF0115D1118C7A00C04FC297EB010000009E69BE108EA91E4C8C201A9BADDCBE4300000000020000000000106600000001000020000000C725C88AD13C9F2C69B68DA5130CB4170982E7BAB0A15FCE8E642BFAEFEEAFDA000000000E800000000200002000000000E3AD2365C16666D63C15115BDCED261591B68C6F9703F61C518336F262DB10B00A0000BD12A060EE588F1C637916F403588236739E2B4E6F2C306FC4ADBB6D73E0AD58C3853B0379A1BDD964AAFA6A1CD0560D3AABC0BF123B0E40EBE99D041853525D22613A554545CA9F1169E5258C20DCC510BAD2F60FD60F0FF9B5E306EAE4AF9908D0A8AD92878135D266AE0EB7F068DBCBA840CC9244405047CCA9CD578A4DC4C168E934738EA1E8F1E8933866254C48070A89B2C200C0578E1E21B40CFDD318780374EB1A69E34E7A2E31E98A853F7D613F5FDBFDCEC2765E8CA6FB11A99DFB87E8A4AD428D554F8AEE8FC4CF6798077A8EBEABDA0D45B42DEE7F12351B72E20CA26BDF7A9522FE3C6958B77A12204EB45EC2116B83657ADB62A6F2C3DEA1763CF6EE7EC7144F262F4474B5741E49486FA8172CE2345810730247A90EAEB27B897D0CFCD5E764B6B4F445E94CFA511FA303188D3B5538555E89C71DB3E07366D148DC36E96DE0FCF286DC6100D0BC5F7283D8FBAC4144A380C99D557C708A0F0BC6AA43C05E64F2ED0C9E5A953D7B98DBFCACCD1E91B7D85CDD25EFE70735081B41A11B4DDF65BEA49C46C710D85E12E4076C5C750B8192B9B883D72A9FE26DD418BB3487DABA8A37291850868E938B87BD750F484DBA11B7A16D3529F0A0AA6773AFEF6673AF09765D65B08F0FB7C7C3F0CA7D3CA2D7AB8DD2D9AE4B9D1ED4B8362A7181ED8669665D04B789D3D1C2799242407B041D766A2A4F4505624F571555A159081493C2E5749AA6A0AC3B6BC644C0676C207E6FDF759B70503044738F72D9C7E6AE752948D00DF4F935CB44CF2289BD3448CE8C0F1F3335FCA713C7592FC67D6BAF89E2FF46405B62593A6E28208F8E241B198F8F06D6405AE149189A5DE49D63BF1423DCB39DA66715349EC5F93C3806AF2B075374FA201E16D1ABA274063047D9D954E109356BFD68E2EF4FED237E8C97A8287212BB872FC73A98A00BEEF0AD8E388CD3B8F40436FDFE2A94B0D45D257032B07916269046F4C9AF15DDE9022EDF750AC9FCE5032EB79EAB1A3A31E3E204FE824EC1CC276EF0A5AAF92B32F3C4B9CEC601474A94F59F4055AADC8221ECF404C225AE12A496870A0FF5F88398C93652C053864184624BC58ED307AF2199F529E7FDF8E53176E548F9562CD57672E6F25A8ABF6A3B62107DAEE714DC5B5D3D54AC2703B41ED40E9429217C127714077B077C69C61A47530F065C26276D86DDD573001CAE6F5B51AC5005B911CAD7C248F16DF3233CA801D39B49E12BFD65B11F154E6C86E62B6920DD3F6A230667DF359B3D173E5E2B527AA320CCE88F119F65B6A5D8644D5E3F2A1D9BE26C583283DC727DC3FF3EA284BBCC62A469427FA66D96FA0A99C7F6337678AAA0A70E57E60026626C564C9E439A830686A12E1F859DDFA60BF92C6D4CE7CE359FCB10A87D3962DE7D2077B6970F894AE9F26A63267D21EB537F1A541E6F87F63C41828C451A2702E131E54CB42B7EC1E95231AC2F51D7DA6079D58872A742EE22219D4259F66039909CD93E4565A8284708AC191F8C9EBBD4EA56E86F4FE0E2C578985C4E973ACC9E6ED769FF21D1642356D8C2511BA9646D708D767C0B178D7FE31ECB7B8AE66C6A1761BC163BA3B27F1BB93792AD178B8DED9DBD285B25AA360E2C6E8C4C77B282EE6DE1BBCDE0AD0A925F931F61CAA4C538B966ABE52B8AC2CA1548427CEC60DCF5A0C42CB0FF3B94133DFE7B8058087895959A5949EA3BE715A1F74DEC4A822B89AF1C89794A07EED7051AC7C461C179C1DA977585A5F2134AA33EEFD5C9BE442FD6F1C3365B47E6EB47028DBECF3219F65B2778DC526BE4F080AFE27F15833F53CFD2911858222C30A0879D8121675C5A1E799EE83266AAE077C2EB8A2DD86DD1BA2E9AB43244561425130F740CE1B8F655C102D462D9F264BF73C32978C7CFD9907DECAB202E4D36A7A72981E50C3F57430C49D6F56C4202D7217545D0E5B02A4F359B126DD9C5CF7BC77512F3AD04D0AC90D79FEEB3DBC82063AAB3CE80C147B529FFD97C9EF274100983F8BEB3373B19F5A80E51E01CA61B5B61C978D79CDB867B671B814A9871C519987928D35362B0B02B5976007194BB3D5D0AF92EDF31F91E10B991490A8BC2A9E402039FCBA6D5289F41622DEF1ABB597DFF3646C1D6470BCB65CC0420F329597BFF00123D58143CC0721B03C0DC052D7BD2A5C2DDB7191D43AE70B6A454A8346FE33F7C912696E43D28438EDBF11715C2D1C46EF21D8D997549EF2CE0C5817563E7A841C8E6418E6CBD00FC9CE7F790329A3548A1ADF62BF754B706F2D3A976A7B3868274BCAD594D895E34F9A807251F9C82E0A1859E90A1C8F91F03319AFFD0E09179EA0DBD90106004CD7DB1E9C35A1153FB26C888B9325B08DD8A187001D1320060852A9D024889A150695B3CF137CD4FD95CF0EF8CDBD91786898FF9B8B9F885653684339CF835368AB0554744D339801CCD343B4AF5F0BBD2CBC5AEAFE19AC7A5545DC596C7C5C3203090DA6831A3ED6FBBDB89A815BAF9195B629A5A7BF7C1B5FB349DD951ABC32B2C818F38F6C6796C1E0BC005A6FBB2F82DC3B2F55496059F78F28919D2BE8804C1D48A417E8C5D6A16A4736D9B86DCC3A9896D9A412DA1E5651AE31C7DCDE99325CE7E0E9D3FBA2A91A4FB18B6FEF92293F38789AD78A3EA7A3F8DB7EA3508A15C68A78F51D7E4C57F0F5B4FB8D9082277639D8A51D267F0F49CBCB24E989F873233C53679E9B0EDFC88C3E79E961C53F3D0EAA2C432D6E973D0ADDC5D7328ABB726045A17D456BF20EF60F02AA634ED7818F486A65A2FDE23E1A34E1A167F2CA0CC33FDD6747B258A89A5466FC673BC188FE934B58A9E7E63A22569FCAFF8DD30F936C5903C31947766BF6E4485F5D59571968DC895755B2CB5BA32E4150A4E04E9B227A1B1A0FD545B765A1A3460CA2D0D0E2E5803CF54D70DB23521139EB9C2F185BFACCC3CAFA97A8DE24D829316542C6795EC93CFBE830F0EF72D0D8AA65FCDA25FF8B99BAA4F9D2A99FDB26714F2549E1108D84C612DC25B0C2C30ABF4DCD12763CDAB6DADD32B824B54249DAC46AC55B7118CE8EC78B76FED8289427E6D3649C4A3A7759DE20BFE87384D8224599B5F63E00C82F33C0E4DE2EB6C5AE50F7C3E88C24A386B6BCE3AD0A21F80BBDE55B1F90025A741E5FEB20852E8A9148ED2D98C3A02576E97FA3CBCDAA276CCC6D57388AC544FC1349711C6C557865CE5ED09D8D221F9051990CFFBB38A9224D0D9041F528EB228130546E3C3F20869BE087B94C22513018A4472075C65FE4A448D95C0BAF14E0444D89E1100763BB7A6463010A1C9E15A078DBC8EE24BFD4D654A9BDED1E74CFD1CE0FF6A171D435B3C0A0AA2A7D222F25A9FDC1B92850251B32786C3FE6F4E23F1551D65C90232FC26ADCDE858013ADA1F81F2B2F62C7D47A5DD633084941623FD0F5180FD5680632048731932F7E9A09DA3DE59CFDFD8EB11702DCDA5F3D989FE28AD08B1B86E4A9FDF8F6E392A344AC34E257A28C4CBFA3F27437F6328D7CF3A170F03725BD117D82DB5E60935CAA9A2AB0EBF7601E52EF16D5672F9D370FB3FBFA563FE690EC9BA36780FB40A0F864D95997015717EE4E412DEF569DCD2526A2A350B15206B8FEA86C081D18A3F12C87669FAC7CBCF3E1D05D2F96686153894767F397891484DDF4B8BD261F510FF031AD33900E517D61994657584D625164AC9A50FBCDB01D18998E075E8C971330D32AE788C597E8ED3DE3767606B4739364E132A75FC7F22FF132AC7F7FF8B3CF7195C991D749D5592D8447FBB1567C86D83F18DD6E1125B77C25FB8747A567F3C589E336FBD31BEF5F2577F9A77FF1EF69AA7D19FC5C4C732B538D0F192F4157BC6C4BFC111CA4000000035FA77746BB4EEE7EE7A41CAD3869E4805B76ECC2751F25F48C13322FC6411E8A2474499E76898A2A63F37AC66A369A7094480CD3F3F7A8696D2675F852092F9 | |||
| (PID) Process: | (1440) RuntimeBroker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{4B0964E4-58F1-47F4-A552-E2E1FC56DCD7} |
| Operation: | write | Name: | DeviceId |
Value: 0018401373B97A62 | |||
| (PID) Process: | (1440) RuntimeBroker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{4B0964E4-58F1-47F4-A552-E2E1FC56DCD7} |
| Operation: | write | Name: | ApplicationFlags |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6208 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 6208 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:3134ED3F12E4F4F8643DB90043B0FD7B | SHA256:26E4F122034D7A03F6DA0E707799B09CBEEBDAF8D7A3133A1F7BD894AC72EEA1 | |||
| 6208 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6208 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:400B8A933193D28899F8307CDE971634 | SHA256:800DDF4307DBBE0BEC4A9CF750D82A0AD2FD8FCEE6159A2940FFBFB74FB6C321 | |||
| 6208 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6208 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6208 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6208 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\activity-stream.contile.json | binary | |
MD5:84F8E3E190371FCEF50A1D5FBA49F5C8 | SHA256:1931D16A007DFA06DFA13E05E8B481DBAF42B2E907C4F3496ACD79FE0AE7652D | |||
| 6208 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6208 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:FC1AA2CDFE51C6B3A806C98FC75B9EDF | SHA256:AF80CC40ED4A3F0EFC4F71BE899928C22F13B0D76217895D63A2C9D89EECADF2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6208 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
6208 | firefox.exe | POST | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/ | unknown | — | — | whitelisted |
6208 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6208 | firefox.exe | POST | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/ | unknown | — | — | whitelisted |
6208 | firefox.exe | POST | 200 | 216.58.206.67:80 | http://o.pki.goog/s/wr3/k58 | unknown | — | — | whitelisted |
6208 | firefox.exe | POST | 200 | 216.58.206.67:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
6208 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6208 | firefox.exe | POST | 200 | 216.58.206.67:80 | http://o.pki.goog/s/wr3/azY | unknown | — | — | whitelisted |
6208 | firefox.exe | POST | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/ | unknown | — | — | whitelisted |
6208 | firefox.exe | POST | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5944 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4916 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6208 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | whitelisted |
6208 | firefox.exe | 185.199.108.133:443 | user-images.githubusercontent.com | FASTLY | US | whitelisted |
6208 | firefox.exe | 185.199.109.154:443 | github.githubassets.com | FASTLY | US | whitelisted |
6208 | firefox.exe | 140.82.121.3:443 | github.com | GITHUB | US | whitelisted |
6208 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
content-signature-2.cdn.mozilla.net |
| whitelisted |
content-signature-chains.prod.autograph.services.mozaws.net |
| whitelisted |
github.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
mc.prod.ads.prod.webservices.mozgcp.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2200 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
2200 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
2200 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
2200 | svchost.exe | Misc activity | ET INFO RustDesk Domain in DNS Lookup |
2200 | svchost.exe | Misc activity | ET INFO RustDesk Relay Domain in DNS Lookup |
7768 | rustdesk.exe | Misc activity | ET INFO RustDesk Register Public Key |
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
— | — | Potentially Bad Traffic | ET INFO Possible Firefox Plugin install |