URL:

https://poce-my.sharepoint.com/:o:/g/personal/adrien_sandray

Full analysis: https://app.any.run/tasks/a0cc6370-5ad7-4c56-9920-18af839a7cfa
Verdict: Malicious activity
Analysis date: February 28, 2023, 16:01:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

D0F7067CD03A978BD766B1BE0E8C5F7D

SHA1:

887D564EFCF2ACABA352D89AD575BCBD5E0FB90F

SHA256:

A113D0F4784EAFB1390DDFF52CC51FA14E7022F2F40AE9097C83714AD38666E4

SSDEEP:

3:N8Ol6K+ArL5+KVFSE/6Ccn:2Ol6K+AfNan

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Manual execution by a user

      • firefox.exe (PID: 3240)
    • Application launched itself

      • firefox.exe (PID: 3240)
      • firefox.exe (PID: 3348)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 3348)
    • Drops a file that was compiled in debug mode

      • firefox.exe (PID: 3348)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 3348)
    • Create files in a temporary directory

      • firefox.exe (PID: 3348)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
9
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start opera.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1016"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3348.0.669452259\735847996" -parentBuildID 20201112153044 -prefsHandle 1128 -prefMapHandle 1120 -prefsLen 1 -prefMapSize 238726 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3348 "\\.\pipe\gecko-crash-server-pipe.3348" 1204 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1240"C:\Program Files\Opera\opera.exe" "https://poce-my.sharepoint.com/:o:/g/personal/adrien_sandray"C:\Program Files\Opera\opera.exe
Explorer.EXE
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
1748
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\opera.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
1636"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3348.21.1762068250\108403668" -childID 4 -isForBrowser -prefsHandle 1748 -prefMapHandle 4224 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3348 "\\.\pipe\gecko-crash-server-pipe.3348" 4108 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1872"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3348.13.322624786\1935994192" -childID 2 -isForBrowser -prefsHandle 2960 -prefMapHandle 2872 -prefsLen 6644 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3348 "\\.\pipe\gecko-crash-server-pipe.3348" 2916 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
2280"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3348.20.567171586\1031462788" -childID 3 -isForBrowser -prefsHandle 1840 -prefMapHandle 1776 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3348 "\\.\pipe\gecko-crash-server-pipe.3348" 4192 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
2996"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3348.34.2074430290\1192806642" -childID 5 -isForBrowser -prefsHandle 3820 -prefMapHandle 3836 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3348 "\\.\pipe\gecko-crash-server-pipe.3348" 3948 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
3240"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeExplorer.EXE
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
3348"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
3468"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3348.6.1476616816\548403111" -childID 1 -isForBrowser -prefsHandle 4372 -prefMapHandle 4368 -prefsLen 181 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3348 "\\.\pipe\gecko-crash-server-pipe.3348" 4384 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
Total events
19 046
Read events
18 880
Write events
166
Delete events
0

Modification events

(PID) Process:(1240) opera.exeKey:HKEY_CURRENT_USER\Software\Opera Software
Operation:writeName:Last CommandLine v2
Value:
C:\Program Files\Opera\opera.exe "https://poce-my.sharepoint.com/:o:/g/personal/adrien_sandray"
(PID) Process:(1240) opera.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3240) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
EE3F38B00E000000
(PID) Process:(3348) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
C28F39B00E000000
(PID) Process:(3348) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(3348) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(3348) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(3348) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(3348) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|ServicesSettingsServer
Value:
https://firefox.settings.services.mozilla.com/v1
(PID) Process:(3348) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash
Value:
97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E
Executable files
8
Suspicious files
96
Text files
94
Unknown types
36

Dropped files

PID
Process
Filename
Type
3348firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
1240opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr2C2A.tmptext
MD5:
SHA256:
1240opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.initext
MD5:
SHA256:
1240opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr2C98.tmpxml
MD5:
SHA256:
1240opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr9A0A.tmptext
MD5:
SHA256:
1240opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xmlxml
MD5:
SHA256:
1240opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.wintext
MD5:0100E3D2A29941CEEF4E37312A7FA332
SHA256:0C42C7737A5ABA75C8E2EA967E2A994542B2C641D0A370EDC41BC4D70A7CAC70
1240opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr8AC6.tmptext
MD5:
SHA256:
1240opera.exeC:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00003.tmphtml
MD5:
SHA256:
1240opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dattext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
54
DNS requests
98
Threats
38

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1240
opera.exe
GET
216.58.207.228:80
http://www.google.com/search?q=https%3A%2F%2Fpoce-my.sharepoint.com%2F%3Ao%3A%2Fg%2Fpersonal%2Fadrien_sandray&sourceid=opera&ie=utf-8&oe=utf-8&channel=suggest
US
malicious
3348
firefox.exe
POST
200
216.58.207.195:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
3348
firefox.exe
POST
200
216.58.207.195:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
3348
firefox.exe
POST
200
216.58.207.195:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
3348
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt
US
text
8 b
whitelisted
1240
opera.exe
GET
200
185.26.182.110:80
http://redir.opera.com/favicons/google/favicon.ico
unknown
image
5.30 Kb
whitelisted
3348
firefox.exe
POST
200
23.33.119.27:80
http://r3.o.lencr.org/
NO
der
503 b
shared
3348
firefox.exe
POST
200
23.33.119.27:80
http://r3.o.lencr.org/
NO
der
503 b
shared
3348
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3348
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1240
opera.exe
13.107.136.8:443
poce-my.sharepoint.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
suspicious
3348
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
suspicious
3348
firefox.exe
34.111.73.144:443
firefox-settings-attachments.cdn.mozilla.net
GOOGLE
US
unknown
3348
firefox.exe
35.244.181.201:443
aus5.mozilla.org
GOOGLE
US
suspicious
1240
opera.exe
185.26.182.94:443
certs.opera.com
Opera Software AS
whitelisted
1240
opera.exe
82.145.216.15:443
sitecheck2.opera.com
Opera Software AS
NO
suspicious
1240
opera.exe
185.26.182.110:80
redir.opera.com
Opera Software AS
unknown
3348
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
3348
firefox.exe
35.241.9.150:443
firefox.settings.services.mozilla.com
GOOGLE
US
suspicious
3348
firefox.exe
35.164.234.103:443
location.services.mozilla.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
poce-my.sharepoint.com
  • 13.107.136.8
suspicious
certs.opera.com
  • 185.26.182.94
whitelisted
sitecheck2.opera.com
  • 82.145.216.15
whitelisted
redir.opera.com
  • 185.26.182.110
whitelisted
www.google.com
  • 216.58.207.228
malicious
detectportal.firefox.com
  • 34.107.221.82
whitelisted
firefox.settings.services.mozilla.com
  • 35.241.9.150
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.171
whitelisted
location.services.mozilla.com
  • 35.164.234.103
whitelisted

Threats

PID
Process
Class
Message
1240
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
1240
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
1240
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
1240
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
1240
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
1240
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
1240
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
1240
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
1240
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
1240
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
No debug info