| URL: | https://eur01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.anastasiadate.com%2Fonline-ladies.html%3Ftoken%3D0dd8007c8345486d3263b7f0fac3f600%26emtr%3DV_db4VR7-ZWy3gXqim18TIIsuF8x8NS0YB71xmZT1OxLgOTnwUOY8NRRSn7MmvBttIJUCPQvbB7LvNNZ7yCRMRe6UVAjH3n5pSwEiRDOVolxYxgT5NGoiTVMoFXhxAqH_7qQ5-RQCwHle428KOk_ktbquls&data=02%7C01%7C%7Ce2770586da5c41ce84d008d7cefb5d17%7C28042244bb514cd680347776fa3703e8%7C1%7C0%7C637205451301331826&sdata=6LA5SasN3At09bFFfLY6vAFcI9V54IZlDnTFnCAq8yU%3D&reserved=0 |
| Full analysis: | https://app.any.run/tasks/82074103-9873-4193-acd2-eac7bfbb012a |
| Verdict: | Malicious activity |
| Analysis date: | March 23, 2020, 07:40:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 600927FEBA3FF6A54AD9FDB2109232C7 |
| SHA1: | 855E6F7E1E0345343BD3DA82A6716A468A1B9CA7 |
| SHA256: | 87D44E23209E294141BEDE9B1815A0D52E4281A775D8F218375E2CAEE7B36BB9 |
| SSDEEP: | 12:2U9qVsS9poPXvLgoamMOTZHDrSV1KFT3rgtLZjYEj1d0/:2U9qlpoPraOTZHDrS/GrgtpYKu |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 256 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://eur01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.anastasiadate.com%2Fonline-ladies.html%3Ftoken%3D0dd8007c8345486d3263b7f0fac3f600%26emtr%3DV_db4VR7-ZWy3gXqim18TIIsuF8x8NS0YB71xmZT1OxLgOTnwUOY8NRRSn7MmvBttIJUCPQvbB7LvNNZ7yCRMRe6UVAjH3n5pSwEiRDOVolxYxgT5NGoiTVMoFXhxAqH_7qQ5-RQCwHle428KOk_ktbquls&data=02%7C01%7C%7Ce2770586da5c41ce84d008d7cefb5d17%7C28042244bb514cd680347776fa3703e8%7C1%7C0%7C637205451301331826&sdata=6LA5SasN3At09bFFfLY6vAFcI9V54IZlDnTFnCAq8yU%3D&reserved=0 | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 1692 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="256.13.1641941694\370028539" -childID 2 -isForBrowser -prefsHandle 2912 -prefMapHandle 2916 -prefsLen 5996 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 256 "\\.\pipe\gecko-crash-server-pipe.256" 2928 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2532 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="256.20.318969737\1879815816" -childID 3 -isForBrowser -prefsHandle 3772 -prefMapHandle 3776 -prefsLen 7129 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 256 "\\.\pipe\gecko-crash-server-pipe.256" 3788 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 3284 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="256.0.1341437325\876402343" -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 256 "\\.\pipe\gecko-crash-server-pipe.256" 1208 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 3928 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="256.3.702834255\710548357" -childID 1 -isForBrowser -prefsHandle 1396 -prefMapHandle 1392 -prefsLen 1 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 256 "\\.\pipe\gecko-crash-server-pipe.256" 1752 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 3952 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://eur01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.anastasiadate.com%2Fonline-ladies.html%3Ftoken%3D0dd8007c8345486d3263b7f0fac3f600%26emtr%3DV_db4VR7-ZWy3gXqim18TIIsuF8x8NS0YB71xmZT1OxLgOTnwUOY8NRRSn7MmvBttIJUCPQvbB7LvNNZ7yCRMRe6UVAjH3n5pSwEiRDOVolxYxgT5NGoiTVMoFXhxAqH_7qQ5-RQCwHle428KOk_ktbquls&data=02%7C01%7C%7Ce2770586da5c41ce84d008d7cefb5d17%7C28042244bb514cd680347776fa3703e8%7C1%7C0%7C637205451301331826&sdata=6LA5SasN3At09bFFfLY6vAFcI9V54IZlDnTFnCAq8yU%3D&reserved=0" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| (PID) Process: | (3952) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 42C3C0ED08000000 | |||
| (PID) Process: | (256) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: B2C1C3ED08000000 | |||
| (PID) Process: | (256) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (256) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (256) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 256 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 256 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
| 256 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
| 256 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp | — | |
MD5:— | SHA256:— | |||
| 256 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.bin | binary | |
MD5:— | SHA256:— | |||
| 256 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:— | SHA256:— | |||
| 256 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4 | jsonlz4 | |
MD5:— | SHA256:— | |||
| 256 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 256 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flash-digest256.pset | cdxl | |
MD5:076933FF9904D1110D896E2C525E39E5 | SHA256:4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0 | |||
| 256 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flashsubdoc-digest256.pset | cdxl | |
MD5:076933FF9904D1110D896E2C525E39E5 | SHA256:4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
256 | firefox.exe | GET | 200 | 104.111.237.98:80 | http://www.anastasiadate.com/Pages/Search/OnlineLadies.aspx?emtr=V_db4VR7-ZWy3gXqim18TIIsuF8x8NS0YB71xmZT1OxLgOTnwUOY8NRRSn7MmvBttIJUCPQvbB7LvNNZ7yCRMRe6UVAjH3n5pSwEiRDOVolxYxgT5NGoiTVMoFXhxAqH_7qQ5-RQCwHle428KOk_ktbquls | NL | html | 49.3 Kb | suspicious |
256 | firefox.exe | GET | 200 | 104.111.237.98:80 | http://49ad.itocd.net/www/styles/inner.css?v9731-1&features=ad|like|purchase-form-v3|reduce-main-menu | NL | text | 71.3 Kb | whitelisted |
256 | firefox.exe | GET | 200 | 104.111.237.98:80 | http://4ad.itocd.net/www/images/girl/1893601-1893800/38541be9-5f3a-4ddf-8454-a754f1048340.jpg | NL | image | 9.78 Kb | suspicious |
256 | firefox.exe | GET | 200 | 104.111.237.98:80 | http://61ad.itocd.net/www/styles/notifications.css?v9731-1&features=ad|like|purchase-form-v3|reduce-main-menu | NL | text | 2.65 Kb | whitelisted |
256 | firefox.exe | GET | 302 | 104.111.237.98:80 | http://www.anastasiadate.com/online-ladies.html?token=0dd8007c8345486d3263b7f0fac3f600&emtr=V_db4VR7-ZWy3gXqim18TIIsuF8x8NS0YB71xmZT1OxLgOTnwUOY8NRRSn7MmvBttIJUCPQvbB7LvNNZ7yCRMRe6UVAjH3n5pSwEiRDOVolxYxgT5NGoiTVMoFXhxAqH_7qQ5-RQCwHle428KOk_ktbquls | NL | html | 309 b | suspicious |
256 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://ocsp.pki.goog/gts1o1 | US | der | 472 b | whitelisted |
256 | firefox.exe | GET | 200 | 104.111.237.98:80 | http://9ad.itocd.net/www/images/girl/1859601-1859800/dc4c0037-61b0-4600-ae6e-fbc7e8b9d1e3.jpg | NL | image | 23.1 Kb | suspicious |
256 | firefox.exe | GET | 200 | 104.111.237.98:80 | http://7ad.itocd.net/www/images/girl/1671801-1672000/520b5490-eea0-4612-a510-dc2897e6cb7f.jpg | NL | image | 13.0 Kb | suspicious |
256 | firefox.exe | GET | 200 | 104.111.237.98:80 | http://36ad.itocd.net/www/images/girl/1793201-1793400/ba2b5008-08bd-48bb-90f4-6f6026689d91.jpg | NL | image | 8.61 Kb | suspicious |
256 | firefox.exe | GET | 200 | 104.111.237.98:80 | http://18ad.itocd.net/www/images/girl/2043001-2043200/0da1d726-80c7-4807-b525-448376eb5f04.jpg | NL | image | 10.1 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
256 | firefox.exe | 95.101.72.209:80 | detectportal.firefox.com | Akamai International B.V. | — | whitelisted |
256 | firefox.exe | 104.47.1.28:443 | eur01.safelinks.protection.outlook.com | Microsoft Corporation | AT | whitelisted |
256 | firefox.exe | 52.38.153.3:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
256 | firefox.exe | 104.111.237.98:80 | www.anastasiadate.com | Akamai International B.V. | NL | whitelisted |
256 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
256 | firefox.exe | 172.217.23.106:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
256 | firefox.exe | 172.217.16.195:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
256 | firefox.exe | 143.204.201.70:443 | firefox.settings.services.mozilla.com | — | US | suspicious |
256 | firefox.exe | 54.191.143.31:443 | push.services.mozilla.com | Amazon.com, Inc. | US | unknown |
256 | firefox.exe | 104.111.237.98:443 | www.anastasiadate.com | Akamai International B.V. | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
eur01.safelinks.protection.outlook.com |
| whitelisted |
a1089.dscd.akamai.net |
| whitelisted |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
snippets.cdn.mozilla.net |
| whitelisted |
d228z91au11ukj.cloudfront.net |
| whitelisted |
www.anastasiadate.com |
| suspicious |
PID | Process | Class | Message |
|---|---|---|---|
1052 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
1052 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
1052 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
1052 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |