URL:

https://www.softwarecrackguru.com/2022/11/umtv2umtpro-qcfire-v84-xiaomi-sideload.html

Full analysis: https://app.any.run/tasks/e556ea41-d2eb-4625-953d-629cfcc0a9e2
Verdict: Malicious activity
Analysis date: October 02, 2024, 23:21:25
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

D120C357353417D91DD82C5AA2FE1D86

SHA1:

609BF908AE8317D3EF12473452D4DFD435E04A23

SHA256:

A139AFC601C618003C6255F1516F66F6533C4D650E8C82C32017E48878398F8F

SSDEEP:

3:N8DSLnDtTZ1sLsbdOpiITTIrTMfp5G:2OLnDpPEsxiTKAfp5G

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • UMTv2_UMTPro_QcFire_v8.4_Setup.exe (PID: 7124)
      • vc_redist.x64.exe (PID: 2212)
      • UMTv2_UMTPro_QcFire_v8.4_Setup.exe (PID: 7384)
      • UMTv2_UMTPro_QcFire_v8.4_Setup.tmp (PID: 7560)
    • Process drops legitimate windows executable

      • UMTv2_UMTPro_QcFire_v8.4_Setup.tmp (PID: 7560)
      • vc_redist.x64.exe (PID: 2212)
    • There is functionality for communication over UDP network (YARA)

      • QcFire.exe (PID: 7888)
    • Application launched itself

      • WinRAR.exe (PID: 8024)
      • vc_redist.x64.exe (PID: 7380)
    • The process drops C-runtime libraries

      • UMTv2_UMTPro_QcFire_v8.4_Setup.tmp (PID: 7560)
    • Drops a system driver (possible attempt to evade defenses)

      • UMTv2_UMTPro_QcFire_v8.4_Setup.tmp (PID: 7560)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 6364)
      • firefox.exe (PID: 3988)
    • Manual execution by a user

      • WinRAR.exe (PID: 8024)
      • UMTv2_UMTPro_QcFire_v8.4_Setup.exe (PID: 7124)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 3988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
174
Monitored processes
32
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs svchost.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs Copy/Move/Rename/Delete/Link Object no specs winrar.exe no specs winrar.exe umtv2_umtpro_qcfire_v8.4_setup.exe umtv2_umtpro_qcfire_v8.4_setup.tmp no specs umtv2_umtpro_qcfire_v8.4_setup.exe umtv2_umtpro_qcfire_v8.4_setup.tmp vc_redist.x64.exe no specs vc_redist.x64.exe qcfire.exe no specs THREAT qcfire.exe

Process information

PID
CMD
Path
Indicators
Parent process
1504"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2792 -childID 3 -isForBrowser -prefsHandle 5200 -prefMapHandle 5028 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1376 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8a134f95-6257-4a67-94f9-3e7e03633a6f} 3988 "\\.\pipe\gecko-crash-server-pipe.3988" 16b1c2d7850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1804"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5176 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5212 -prefMapHandle 5208 -prefsLen 34713 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {1d170b16-40a2-4af8-b878-95d3087192f6} 3988 "\\.\pipe\gecko-crash-server-pipe.3988" 16b1e653910 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2060"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5544 -childID 5 -isForBrowser -prefsHandle 5536 -prefMapHandle 5532 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1376 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a2e48193-c5e2-47ad-b014-02581ab6c063} 3988 "\\.\pipe\gecko-crash-server-pipe.3988" 16b1c2d7a10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2212"C:\UMTool\QcFire\data\vc_redist\vc_redist.x64.exe" -burn.unelevated BurnPipe.{1C30445E-292A-46EE-80D7-E4AB0099BD72} {AE0210E9-D0CA-4ED9-B148-1538D82ECAD3} 7380C:\UMTool\QcFire\data\vc_redist\vc_redist.x64.exe
vc_redist.x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026
Exit code:
1602
Version:
14.0.23026.0
Modules
Images
c:\umtool\qcfire\data\vc_redist\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2256C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3212"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5528 -childID 4 -isForBrowser -prefsHandle 5516 -prefMapHandle 5424 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1376 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {0f6f68ee-3c2a-4fa0-a957-0f53672d9224} 3988 "\\.\pipe\gecko-crash-server-pipe.3988" 16b1c2d7f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3296"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1828 -parentBuildID 20240213221259 -prefsHandle 1752 -prefMapHandle 1712 -prefsLen 30537 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ebfc7d86-f0db-48e0-abaf-b356ca4904c5} 3988 "\\.\pipe\gecko-crash-server-pipe.3988" 16b14be5710 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3688"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4468 -childID 2 -isForBrowser -prefsHandle 4464 -prefMapHandle 4460 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1376 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {af77e5b8-21f7-4f73-8caa-ac7255c4eb17} 3988 "\\.\pipe\gecko-crash-server-pipe.3988" 16b1b851850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3988"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.softwarecrackguru.com/2022/11/umtv2umtpro-qcfire-v84-xiaomi-sideload.htmlC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4648"C:\Program Files\WinRAR\WinRAR.exe" -elevate8024C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
24 282
Read events
24 249
Write events
33
Delete events
0

Modification events

(PID) Process:(3988) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(8024) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(8024) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(8024) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(8024) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4648) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4648) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4648) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4648) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7560) UMTv2_UMTPro_QcFire_v8.4_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EBA4E667-E6F7-47A0-A62B-A51D60136B26}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.0
Executable files
146
Suspicious files
461
Text files
174
Unknown types
9

Dropped files

PID
Process
Filename
Type
3988firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:297E88D7CEB26E549254EC875649F4EB
SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702
3988firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
3988firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:7A97B8DBC4F98D175F958C00F463A52A
SHA256:92074D2ED1AA1FD621287E35DB9EF1AE3DC04777EFAE5F09E7A3B4534C201548
3988firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3988firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\protections.sqlite-journalbinary
MD5:CDB9D33AF2F6547A4328194D8394FE2B
SHA256:8E8A4347E3E4CAB6F4945A5C15353AA5A10F8C623C78A43CAD8B9EA3B08E8F0A
3988firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3988firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-walbinary
MD5:05980D556A566E8F0849884216CAD930
SHA256:5C3783EC4F87995D6A3D253113F5AAEFE8FF6F5589CE470705F5011E1D74B366
3988firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3988firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:7A97B8DBC4F98D175F958C00F463A52A
SHA256:92074D2ED1AA1FD621287E35DB9EF1AE3DC04777EFAE5F09E7A3B4534C201548
3988firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.binbinary
MD5:8EF02F2253D2E46935DA266A8EE13FCD
SHA256:84835D20BCB79D4D052FAA5BB15858E2305ACB25DBB353EAE2AD7E55AD480937
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
72
TCP/UDP connections
232
DNS requests
260
Threats
48

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3988
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
3988
firefox.exe
POST
200
142.250.184.227:80
http://o.pki.goog/s/wr3/8FE
unknown
whitelisted
3988
firefox.exe
POST
200
184.24.77.80:80
http://r10.o.lencr.org/
unknown
whitelisted
3988
firefox.exe
POST
200
184.24.77.80:80
http://r10.o.lencr.org/
unknown
whitelisted
3988
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
3988
firefox.exe
POST
200
142.250.184.227:80
http://o.pki.goog/s/wr3/XjA
unknown
whitelisted
3988
firefox.exe
POST
200
142.250.184.227:80
http://o.pki.goog/s/wr3/8FE
unknown
whitelisted
3988
firefox.exe
POST
200
142.250.184.227:80
http://o.pki.goog/wr2
unknown
whitelisted
3988
firefox.exe
POST
200
184.24.77.80:80
http://r10.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2952
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
3988
firefox.exe
34.117.188.166:443
contile.services.mozilla.com
whitelisted
3988
firefox.exe
172.217.16.211:443
www.softwarecrackguru.com
GOOGLE
US
whitelisted
3988
firefox.exe
172.217.18.10:443
safebrowsing.googleapis.com
whitelisted
3988
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
  • 40.127.240.158
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
google.com
  • 142.250.184.206
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
www.softwarecrackguru.com
  • 172.217.16.211
malicious
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
ghs.google.com
  • 172.217.16.211
  • 2a00:1450:4001:806::2013
whitelisted
example.org
  • 93.184.215.14
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
No debug info