URL:

https://craxpro.io/threads/t33n-l34ks-5-89-gb.223624/post-2110793

Full analysis: https://app.any.run/tasks/af97f99e-9bbc-42e1-8343-aa385dec2093
Verdict: Malicious activity
Analysis date: August 04, 2023, 14:19:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

760DB2C65DC9AF07EBD5624D2F1ED4B2

SHA1:

EA36295E6A3C8A433097BF7F59CD85302D7B33BB

SHA256:

93BE097B6BF9D6E4F56C76B4A532B7554E5BA720E96BDC922450150FEDD69ABF

SSDEEP:

3:N8K5r4I0/iTBOKWYPWn:2K5ra/wBlW+Wn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • firefox.exe (PID: 2804)
      • firefox.exe (PID: 3332)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
15
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
488"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3332.1.899511524\2122072623" -parentBuildID 20230710165010 -prefsHandle 1408 -prefMapHandle 1404 -prefsLen 28102 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b55a24e9-3a65-4a77-a1d4-43f52caef44f} 3332 "\\.\pipe\gecko-crash-server-pipe.3332" 1420 f456a30 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
680"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3332.12.1042669561\303040228" -childID 11 -isForBrowser -prefsHandle 3796 -prefMapHandle 3244 -prefsLen 31177 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6278423d-0302-4ffc-adba-e9d71a09e511} 3332 "\\.\pipe\gecko-crash-server-pipe.3332" 3248 1a382560 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1004"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3332.7.2124063699\391072680" -childID 6 -isForBrowser -prefsHandle 3880 -prefMapHandle 3876 -prefsLen 33948 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1ea8a3df-21e1-4d0f-a862-62ce6cd5ea9a} 3332 "\\.\pipe\gecko-crash-server-pipe.3332" 4060 190943f0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1360"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3332.4.595807579\1162591675" -childID 3 -isForBrowser -prefsHandle 3676 -prefMapHandle 3584 -prefsLen 29011 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a2c3cedf-895e-45d1-90d0-9084e9170478} 3332 "\\.\pipe\gecko-crash-server-pipe.3332" 3644 15532840 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1424"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3332.8.1948781661\869532764" -childID 7 -isForBrowser -prefsHandle 2072 -prefMapHandle 2080 -prefsLen 29110 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {42f55d21-4865-49f7-a38d-5e71ed8c1679} 3332 "\\.\pipe\gecko-crash-server-pipe.3332" 2040 1a227b20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1644"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3332.9.751723322\1853162640" -childID 8 -isForBrowser -prefsHandle 2100 -prefMapHandle 2096 -prefsLen 29110 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4075d053-3b09-4415-965b-e321a33be13c} 3332 "\\.\pipe\gecko-crash-server-pipe.3332" 4604 1a3829b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1840"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3332.11.2094696217\1572434946" -childID 10 -isForBrowser -prefsHandle 8324 -prefMapHandle 8328 -prefsLen 29730 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e7b45e52-0d4b-420d-8f46-b9170995950d} 3332 "\\.\pipe\gecko-crash-server-pipe.3332" 8312 15532e00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2372"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3332.5.1306857848\2141191123" -childID 4 -isForBrowser -prefsHandle 3640 -prefMapHandle 3656 -prefsLen 29011 -prefMapSize 243955 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {64cce6f4-ddc3-467c-9c2f-a6219ba18a98} 3332 "\\.\pipe\gecko-crash-server-pipe.3332" 3700 17a89280 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2804"C:\Program Files\Mozilla Firefox\firefox.exe" "https://craxpro.io/threads/t33n-l34ks-5-89-gb.223624/post-2110793"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3180"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3332.0.21815797\1983820953" -parentBuildID 20230710165010 -prefsHandle 1112 -prefMapHandle 1104 -prefsLen 28025 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7694536d-9dec-4c61-8f8d-1b8447f3f989} 3332 "\\.\pipe\gecko-crash-server-pipe.3332" 1196 d8e06b0 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
18 862
Read events
18 824
Write events
38
Delete events
0

Modification events

(PID) Process:(2804) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
815441AB02000000
(PID) Process:(3332) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
B73F42AB02000000
(PID) Process:(3332) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(3332) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(3332) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(3332) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(3332) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(3332) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(3332) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(3332) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
EA362D0F13B0D901
Executable files
0
Suspicious files
165
Text files
70
Unknown types
0

Dropped files

PID
Process
Filename
Type
3332firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
3332firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.binbinary
MD5:C58234A092F9D899F0A623E28A4AB9DB
SHA256:EAEC709A98B57CD9C054A205F9BFA76C7424DB2845C077822804F31E16AC134C
3332firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.dbbinary
MD5:11ACD45191D3E46223C2E409BCBB60A2
SHA256:AFF042A95E5E2985EA3813DEA8CE40282CDFD34B802139066786C498E037B8C0
3332firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\targeting.snapshot.json.tmptext
MD5:573AC10F865976F3759FE37EE12C5ECC
SHA256:9209377640FB8BE37E09327BA18E29C1E986BF0A5AAA549A1D610909F71E3294
3332firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3332firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:33B1483937C16FDFD0FEE1AF8E9746F0
SHA256:E6280203750BB80548B14CA76986983950D872ECE01044CC936E97153F04B372
3332firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3332firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.tmpbinary
MD5:C58234A092F9D899F0A623E28A4AB9DB
SHA256:EAEC709A98B57CD9C054A205F9BFA76C7424DB2845C077822804F31E16AC134C
3332firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3332firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-new.bin
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
66
DNS requests
215
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3332
firefox.exe
POST
200
18.239.100.55:80
http://ocsp.r2m02.amazontrust.com/
US
binary
471 b
whitelisted
3332
firefox.exe
POST
2.16.149.144:80
http://r3.o.lencr.org/
NL
shared
3332
firefox.exe
POST
192.229.221.95:80
http://ocsp.digicert.com/
US
whitelisted
3332
firefox.exe
POST
200
2.16.149.144:80
http://r3.o.lencr.org/
NL
binary
503 b
shared
3332
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
US
binary
471 b
whitelisted
3332
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
US
binary
471 b
whitelisted
3332
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
text
90 b
whitelisted
3332
firefox.exe
POST
200
2.16.149.144:80
http://r3.o.lencr.org/
NL
binary
503 b
shared
3332
firefox.exe
POST
200
2.16.149.144:80
http://r3.o.lencr.org/
NL
binary
503 b
shared
3332
firefox.exe
POST
200
2.16.149.144:80
http://r3.o.lencr.org/
NL
binary
503 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2640
svchost.exe
239.255.255.250:1900
whitelisted
3332
firefox.exe
104.21.58.65:443
craxpro.io
CLOUDFLARENET
whitelisted
3332
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
suspicious
3332
firefox.exe
34.199.49.8:443
spocs.getpocket.com
AMAZON-AES
US
unknown
3332
firefox.exe
172.67.72.99:443
crax.pro
CLOUDFLARENET
US
unknown
3332
firefox.exe
2.16.149.144:80
r3.o.lencr.org
Akamai International B.V.
NL
unknown
3332
firefox.exe
34.120.115.102:443
contile-images.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3332
firefox.exe
104.17.3.184:443
challenges.cloudflare.com
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
craxpro.io
  • 104.21.58.65
  • 2606:4700:3037::6815:3a41
unknown
detectportal.firefox.com
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted
safebrowsing.googleapis.com
  • 142.250.200.42
  • 2a00:1450:4009:80b::200a
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.170
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
spocs.getpocket.com
  • 34.199.49.8
shared
ocsp.pki.goog
  • 142.250.200.3
  • 2a00:1450:4009:822::2003
whitelisted
push.services.mozilla.com
  • 34.117.65.55
whitelisted

Threats

No threats detected
No debug info