URL:

https://telegra.ph/Soft-06-29-2

Full analysis: https://app.any.run/tasks/1c473603-1c64-445f-8e95-5dedbf3b2347
Verdict: Malicious activity
Threats:

Arkei is a stealer type malware capable of collecting passwords, autosaved forms, cryptocurrency wallet credentials, and files.

Analysis date: August 17, 2023, 16:42:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
arkei
stealer
vidar
trojan
Indicators:
MD5:

0B7C833C2F8DFECCCC51C12779D8A2C5

SHA1:

6C21C4390417E002DE46F95E4DA3A553267D87A0

SHA256:

8987399903CAF046E44D6878C7011F76B754957CD2B0C68F31A8B29E4C82AD8A

SSDEEP:

3:N8INN5X:2IT5X

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials

      • Setup.exe (PID: 3992)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 3992)
    • Steals credentials from Web Browsers

      • Setup.exe (PID: 3992)
      • 53155427428605771938.exe (PID: 2136)
    • ARKEI detected by memory dumps

      • Setup.exe (PID: 2788)
      • Setup.exe (PID: 812)
      • Setup.exe (PID: 3992)
    • Connects to the CnC server

      • Setup.exe (PID: 3992)
    • VIDAR was detected

      • Setup.exe (PID: 3992)
    • ARKEI was detected

      • Setup.exe (PID: 3992)
    • Application was dropped or rewritten from another process

      • 53155427428605771938.exe (PID: 2136)
    • Actions looks like stealing of personal data

      • 53155427428605771938.exe (PID: 2136)
      • Setup.exe (PID: 3992)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 3992)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 3992)
    • Reads the Internet Settings

      • Setup.exe (PID: 3992)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 3992)
    • Reads settings of System Certificates

      • Setup.exe (PID: 3992)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • Setup.exe (PID: 3992)
    • Searches for installed software

      • Setup.exe (PID: 3992)
    • Starts CMD.EXE for commands execution

      • 53155427428605771938.exe (PID: 2136)
    • Connects to the server without a host name

      • Setup.exe (PID: 3992)
    • Process requests binary or script from the Internet

      • Setup.exe (PID: 3992)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 2344)
    • Manual execution by a user

      • Setup.exe (PID: 3992)
      • Setup.exe (PID: 812)
      • WinRAR.exe (PID: 3112)
      • Setup.exe (PID: 2788)
    • Reads the computer name

      • Setup.exe (PID: 3992)
      • Setup.exe (PID: 812)
      • Setup.exe (PID: 2788)
      • 53155427428605771938.exe (PID: 2136)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 3112)
      • firefox.exe (PID: 2344)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 3992)
      • Setup.exe (PID: 812)
      • Setup.exe (PID: 2788)
    • Checks proxy server information

      • Setup.exe (PID: 3992)
    • Checks supported languages

      • Setup.exe (PID: 3992)
      • Setup.exe (PID: 812)
      • Setup.exe (PID: 2788)
      • 53155427428605771938.exe (PID: 2136)
    • Creates files in the program directory

      • Setup.exe (PID: 3992)
    • Creates files or folders in the user directory

      • Setup.exe (PID: 3992)
      • 53155427428605771938.exe (PID: 2136)
    • Reads product name

      • Setup.exe (PID: 3992)
    • Reads Environment values

      • Setup.exe (PID: 3992)
    • Reads CPU info

      • Setup.exe (PID: 3992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
19
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winrar.exe no specs #ARKEI setup.exe #ARKEI setup.exe no specs #ARKEI setup.exe no specs 53155427428605771938.exe cmd.exe no specs choice.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
732"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2344.8.1991345886\792231822" -childID 7 -isForBrowser -prefsHandle 8428 -prefMapHandle 2920 -prefsLen 30211 -prefMapSize 244147 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {3dc0c221-db00-4e12-b540-73bf31ffdd5c} 2344 "\\.\pipe\gecko-crash-server-pipe.2344" 8424 2146e658 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
812"C:\Users\admin\Desktop\Setup.exe" C:\Users\admin\Desktop\Setup.exe
explorer.exe
User:
admin
Company:
Redth
Integrity Level:
MEDIUM
Description:
PushSharp.Core
Exit code:
0
Version:
2.1.2.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\gdi32.dll
868"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2344.3.506857069\1277873455" -childID 2 -isForBrowser -prefsHandle 2808 -prefMapHandle 2804 -prefsLen 35203 -prefMapSize 244147 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {85acf592-002e-4ef9-85c4-7f90c4f0fa36} 2344 "\\.\pipe\gecko-crash-server-pipe.2344" 2820 1e4bb558 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1176choice /C Y /N /D Y /T 0 C:\Windows\System32\choice.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Offers the user a choice
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\choice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
1356"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2344.2.866938396\84371524" -childID 1 -isForBrowser -prefsHandle 2016 -prefMapHandle 2012 -prefsLen 25361 -prefMapSize 244147 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c0f68c5f-0be0-402c-a351-cc1936448916} 2344 "\\.\pipe\gecko-crash-server-pipe.2344" 2028 e41d58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
1452"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2344.7.581605125\1261538818" -childID 6 -isForBrowser -prefsHandle 3944 -prefMapHandle 4004 -prefsLen 35478 -prefMapSize 244147 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a98318e3-07ee-469a-ab24-f5f7a87a97bc} 2344 "\\.\pipe\gecko-crash-server-pipe.2344" 4112 e43258 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1996"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2344.1.1447123548\1589387931" -parentBuildID 20230710165010 -prefsHandle 1408 -prefMapHandle 1404 -prefsLen 29601 -prefMapSize 244147 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f664b9fb-3245-47d2-b510-a6468167e05e} 2344 "\\.\pipe\gecko-crash-server-pipe.2344" 1420 43c7558 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2136"C:\ProgramData\53155427428605771938.exe" C:\ProgramData\53155427428605771938.exe
Setup.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\53155427428605771938.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\winmm.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2344"C:\Program Files\Mozilla Firefox\firefox.exe" "https://telegra.ph/Soft-06-29-2"C:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\vcruntime140.dll
2364"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2344.9.1853415694\595797322" -childID 8 -isForBrowser -prefsHandle 4012 -prefMapHandle 8084 -prefsLen 30211 -prefMapSize 244147 -jsInitHandle 840 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fe3feaa3-bafb-422b-9dbb-bfccdfeb5295} 2344 "\\.\pipe\gecko-crash-server-pipe.2344" 7920 18628458 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
Total events
18 314
Read events
18 184
Write events
130
Delete events
0

Modification events

(PID) Process:(2344) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
0000000000000000
(PID) Process:(2344) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(2344) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(2344) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(2344) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(2344) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
0
(PID) Process:(2344) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(2344) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(2344) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
CA0A97189BC5D901
(PID) Process:(2344) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
8
Suspicious files
882
Text files
260
Unknown types
290

Dropped files

PID
Process
Filename
Type
2344firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cert9.dbsqlite
MD5:426CCA0470AF9E07BDFB879EFB8E26C6
SHA256:4BF78262668CB79634AE188DB85F6F19C36C0E75FD343597AB02431C5AACA8C6
2344firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs-1.jstext
MD5:64B08303762D0E419DDAC925656D5406
SHA256:76801B6FDC9750BB12DECD4DC589FCE4805C8E43725489131CAF75E08525BF58
2344firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2344firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.binbinary
MD5:4DF9B77C7650AF87B264E535779AE2A4
SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58
2344firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\6D89348819C8881868053197CA0754F36784BF5Fcompressed
MD5:E77013A5A7B245C487C9370255301CA1
SHA256:947B76501CD6B68A27FC6BCDE244A8467302119A9C43B9BAEDA8BE4053978286
2344firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2344firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2344firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs.jstext
MD5:64B08303762D0E419DDAC925656D5406
SHA256:76801B6FDC9750BB12DECD4DC589FCE4805C8E43725489131CAF75E08525BF58
2344firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage.sqlite-journalbinary
MD5:1D0D504512027B01091D55E633E31562
SHA256:A6FD2492686A7E1E86A0EB7B2E3BFB3D4C789E001B64F2A85050612CF0B17E4E
2344firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\ED9826654AE8BD972BDE17A9E0A449D3F881E430cer
MD5:9FF146C13234EA4AEBDAD7AE6455D2A5
SHA256:EC07A23B9B81ABC22BCB344EDE672F93EE3C2021D9D9FC152302B9AE8F20B416
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
44
TCP/UDP connections
140
DNS requests
279
Threats
24

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2344
firefox.exe
POST
142.250.185.163:80
http://ocsp.pki.goog/gts1c3
US
whitelisted
2344
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
text
90 b
whitelisted
POST
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
2344
firefox.exe
POST
142.250.185.163:80
http://ocsp.pki.goog/gts1c3
US
whitelisted
2344
firefox.exe
POST
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3
US
der
471 b
whitelisted
2344
firefox.exe
POST
184.24.77.67:80
http://r3.o.lencr.org/
US
shared
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
2344
firefox.exe
POST
192.124.249.23:80
http://ocsp.godaddy.com/
US
whitelisted
POST
200
104.18.14.101:80
http://ocsp.comodoca.com/
US
der
472 b
whitelisted
2344
firefox.exe
POST
52.222.226.205:80
http://ocsp.r2m01.amazontrust.com/
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2344
firefox.exe
172.217.23.106:443
safebrowsing.googleapis.com
whitelisted
2344
firefox.exe
34.117.65.55:443
push.services.mozilla.com
suspicious
2344
firefox.exe
35.168.157.224:443
spocs.getpocket.com
AMAZON-AES
US
unknown
2344
firefox.exe
142.250.185.163:80
ocsp.pki.goog
GOOGLE
US
whitelisted
4
System
192.168.100.255:137
whitelisted
2344
firefox.exe
172.67.203.7:443
www.ezojs.com
suspicious
1208
svchost.exe
239.255.255.250:1900
whitelisted
2344
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
2344
firefox.exe
172.67.144.62:443
the.gatekeeperconsent.com
unknown
2344
firefox.exe
104.16.53.48:443
www.mediafire.com
CLOUDFLARENET
suspicious

DNS requests

Domain
IP
Reputation
telegra.ph
  • 149.154.164.13
malicious
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
example.org
  • 93.184.216.34
whitelisted
spocs.getpocket.com
  • 35.168.157.224
  • 107.21.3.27
  • 54.86.197.167
  • 52.1.169.109
shared
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 52.1.169.109
  • 54.86.197.167
  • 107.21.3.27
  • 35.168.157.224
shared
ocsp.godaddy.com
  • 192.124.249.23
  • 192.124.249.36
  • 192.124.249.22
  • 192.124.249.24
  • 192.124.249.41
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted

Threats

PID
Process
Class
Message
2344
firefox.exe
Misc activity
ET INFO Observed Telegram Domain (t .me in TLS SNI)
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
2 ETPRO signatures available at the full report
No debug info