URL:

https://qu.ax/nmeC.mp4

Full analysis: https://app.any.run/tasks/812130c6-a881-445b-b6cc-8a94dc8ee062
Verdict: Malicious activity
Analysis date: October 05, 2023, 13:16:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
SHA1:

8D308C2CA4AFE6483192D550165DA1AB259E990F

SHA256:

9D98931C55E5074FF06AB9745FA5CA929381CFA1E753C932DBFED71168D8B998

SSDEEP:

3:N8PEvXI7:28vXM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • firefox.exe (PID: 2092)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 2092)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
11
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
584"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2092.0.2040682406\1015326729" -parentBuildID 20230710165010 -prefsHandle 1096 -prefMapHandle 1088 -prefsLen 29780 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1328ee06-0e1e-4ad4-840a-dd9c9ae68600} 2092 "\\.\pipe\gecko-crash-server-pipe.2092" 1200 f8ce458 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2008"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2092.3.1616956301\914279235" -childID 2 -isForBrowser -prefsHandle 2908 -prefMapHandle 2904 -prefsLen 35454 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {3860daec-e95b-43cf-94c4-111035f38b8f} 2092 "\\.\pipe\gecko-crash-server-pipe.2092" 2920 1e099758 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
2092"C:\Program Files\Mozilla Firefox\firefox.exe" "https://qu.ax/nmeC.mp4"C:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\msvcp140.dll
2840"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2092.1.1177387671\509920181" -parentBuildID 20230710165010 -prefsHandle 1384 -prefMapHandle 1380 -prefsLen 29857 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {5a8ddd24-917c-4308-bca7-4c92d818ce55} 2092 "\\.\pipe\gecko-crash-server-pipe.2092" 1408 f8d0e58 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
2916"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2092.2.370294317\1883021525" -childID 1 -isForBrowser -prefsHandle 2044 -prefMapHandle 2040 -prefsLen 25524 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {aaa5e66c-4447-4dd1-8cb7-16a589c7466f} 2092 "\\.\pipe\gecko-crash-server-pipe.2092" 2060 18c54e58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
2956"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2092.4.57633875\1153108520" -childID 3 -isForBrowser -prefsHandle 3724 -prefMapHandle 3736 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {056527fa-db48-4092-9904-8012e40665d5} 2092 "\\.\pipe\gecko-crash-server-pipe.2092" 3716 20d75e58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\msasn1.dll
2980"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2092.5.1864249469\885232430" -childID 4 -isForBrowser -prefsHandle 3760 -prefMapHandle 3756 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e0c615fc-13fd-41a3-aa5c-c417e0783006} 2092 "\\.\pipe\gecko-crash-server-pipe.2092" 3800 20d77f58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3488"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2092.8.568066377\442935322" -parentBuildID 20230710165010 -prefsHandle 4128 -prefMapHandle 2668 -prefsLen 35661 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {cec10959-ce98-4159-b426-1909dca96038} 2092 "\\.\pipe\gecko-crash-server-pipe.2092" 4224 23a87758 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3512"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2092.9.91289008\410236258" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 4328 -prefMapHandle 4344 -prefsLen 35661 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c080b085-e6ba-4e3a-a7c5-39b75d0d27fd} 2092 "\\.\pipe\gecko-crash-server-pipe.2092" 4176 23ddf558 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3708"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2092.6.1447200641\394882219" -childID 5 -isForBrowser -prefsHandle 4060 -prefMapHandle 4064 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {bdac7aa5-484e-4150-a7c0-459f908c8cac} 2092 "\\.\pipe\gecko-crash-server-pipe.2092" 3756 21f9ee58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
6 861
Read events
6 824
Write events
37
Delete events
0

Modification events

(PID) Process:(2092) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
0000000000000000
(PID) Process:(2092) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(2092) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(2092) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(2092) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(2092) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
0
(PID) Process:(2092) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(2092) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(2092) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
C33DEE86A0C5D901
(PID) Process:(2092) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
2
Suspicious files
374
Text files
38
Unknown types
0

Dropped files

PID
Process
Filename
Type
2092firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs.jstext
MD5:E778738F76C14C768F4B19DB33E49F67
SHA256:6B8350E96BE46ADC7CE24B1314D4A680559989415B28CF30F9617FD08E94B88D
2092firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2092firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2092firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2092firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.binbinary
MD5:4DF9B77C7650AF87B264E535779AE2A4
SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58
2092firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs-1.jstext
MD5:E778738F76C14C768F4B19DB33E49F67
SHA256:6B8350E96BE46ADC7CE24B1314D4A680559989415B28CF30F9617FD08E94B88D
2092firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
2092firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2092firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
2092firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-walbinary
MD5:2AF6052EF7CBEED491B3B5B6DF978265
SHA256:98022C29CBE272CC7AF1EB924118593C42A6FFE801F9E25444227229ED88AA6A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
29
DNS requests
74
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2092
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
2092
firefox.exe
POST
200
184.24.77.55:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
2092
firefox.exe
POST
200
184.24.77.55:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
2092
firefox.exe
POST
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3
unknown
binary
472 b
unknown
2092
firefox.exe
POST
200
184.24.77.55:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
2092
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
2092
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
471 b
unknown
2092
firefox.exe
POST
200
184.24.77.55:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
2092
firefox.exe
POST
200
184.24.77.55:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
2092
firefox.exe
POST
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3
unknown
binary
472 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2092
firefox.exe
195.15.254.190:443
qu.ax
Infomaniak Network SA
CH
unknown
2092
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
2092
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2092
firefox.exe
34.197.137.200:443
spocs.getpocket.com
AMAZON-AES
US
unknown
2092
firefox.exe
172.217.18.106:443
safebrowsing.googleapis.com
GOOGLE
US
whitelisted
2092
firefox.exe
184.24.77.55:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
2092
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
unknown
2092
firefox.exe
18.238.20.52:80
ocsp.r2m02.amazontrust.com
US
unknown

DNS requests

Domain
IP
Reputation
qu.ax
  • 195.15.254.190
  • 2001:1600:10:100::b69
unknown
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
spocs.getpocket.com
  • 34.197.137.200
  • 184.72.95.230
  • 44.214.229.86
  • 50.16.143.240
shared
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 184.72.95.230
  • 50.16.143.240
  • 44.214.229.86
  • 34.197.137.200
shared
r3.o.lencr.org
  • 184.24.77.55
  • 184.24.77.76
  • 184.24.77.53
  • 184.24.77.56
  • 184.24.77.45
  • 184.24.77.83
  • 184.24.77.79
  • 184.24.77.47
  • 184.24.77.67
shared
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted

Threats

PID
Process
Class
Message
324
svchost.exe
Misc activity
ET INFO Anonymous File Sharing Domain in DNS Lookup (qu .ax)
324
svchost.exe
Misc activity
ET INFO Anonymous File Sharing Domain in DNS Lookup (qu .ax)
324
svchost.exe
Misc activity
ET INFO Anonymous File Sharing Domain in DNS Lookup (qu .ax)
2092
firefox.exe
Misc activity
ET INFO Observed Anonymous File Sharing Service Domain (qu .ax) in TLS SNI
2092
firefox.exe
Misc activity
ET INFO Observed Anonymous File Sharing Service Domain (qu .ax) in TLS SNI
No debug info