URL: | https://ea.trustifi.com/#/fff0a4/330345/69c608/bc6dbf/591d41/18c362/f2cc9d/c4ea4e/e8666a/ef542d/85972d/627493/9a11d6/1f4096/1d247f/89da78/c232d4/86cff6/ecf950/224390/99dfa5/a34f0a/a30847/6f8bee/a08442/4dde74/3fd8f5/cae3a2/c2469a/da7354/dc456c/c93666/295616/ab6057/66291a/690925/6b6f41/f88c57/d6b8e3/0ca0e3/642593/927e58/bb8848/edd9e8/6a56c2/947d2b/900776/2e2ac4/0e1709/f050a9/c1722c/e9cc62/3e1691/8a1288/47acac/e6d594/0655d4/01ae7f/daa155/c53e3a/a5244a/5b7873/ffc806/50db3b/4c5714/039fd8/d2ba2f/280cb7/b2bbe9/2ba811/18d662/f0da13/7626ed/8455c9/da997f/571253/f0a912/15e860/acb8a1/e0911a/d924a2/7c5cf1/b04e88/80ed9d/1e77dd/09b1a3/7af26f/f29f95/432416/483d51/5f4cd9 |
Full analysis: | https://app.any.run/tasks/825140b0-4ae0-459a-8df7-7bee49be5d5d |
Verdict: | Malicious activity |
Analysis date: | October 19, 2023, 16:23:32 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
SHA1: | A5A32B033652171D9CAA3936D11137703AAE7576 |
SHA256: | A736CACC7EFA9D54317D5739BA901DCBBF88ABC0D54723D08C2495317AFB1D9F |
SSDEEP: | 12:2pMcGjnN57KaBB3/Pb86uSGwFTrF0W7RnacKZHeSzJJVJTKLSgk:2LGjnNlzB786uSGwFPGW1nsZtzlJTKLe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1592 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2276.9.1284069894\916236276" -childID 8 -isForBrowser -prefsHandle 8524 -prefMapHandle 8520 -prefsLen 31122 -prefMapSize 244195 -jsInitHandle 836 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c29ce182-8eb6-49c4-b636-ca7434e9fd1d} 2276 "\\.\pipe\gecko-crash-server-pipe.2276" 8536 162023f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2276 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://ea.trustifi.com/#/fff0a4/330345/69c608/bc6dbf/591d41/18c362/f2cc9d/c4ea4e/e8666a/ef542d/85972d/627493/9a11d6/1f4096/1d247f/89da78/c232d4/86cff6/ecf950/224390/99dfa5/a34f0a/a30847/6f8bee/a08442/4dde74/3fd8f5/cae3a2/c2469a/da7354/dc456c/c93666/295616/ab6057/66291a/690925/6b6f41/f88c57/d6b8e3/0ca0e3/642593/927e58/bb8848/edd9e8/6a56c2/947d2b/900776/2e2ac4/0e1709/f050a9/c1722c/e9cc62/3e1691/8a1288/47acac/e6d594/0655d4/01ae7f/daa155/c53e3a/a5244a/5b7873/ffc806/50db3b/4c5714/039fd8/d2ba2f/280cb7/b2bbe9/2ba811/18d662/f0da13/7626ed/8455c9/da997f/571253/f0a912/15e860/acb8a1/e0911a/d924a2/7c5cf1/b04e88/80ed9d/1e77dd/09b1a3/7af26f/f29f95/432416/483d51/5f4cd9 | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2748 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2276.8.937512564\577122571" -childID 7 -isForBrowser -prefsHandle 3292 -prefMapHandle 2772 -prefsLen 31122 -prefMapSize 244195 -jsInitHandle 836 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {47db2136-516a-4bbf-9c20-04cc354cab61} 2276 "\\.\pipe\gecko-crash-server-pipe.2276" 3432 16202280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2856 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2276.7.1648681107\1321949737" -childID 6 -isForBrowser -prefsHandle 4412 -prefMapHandle 4408 -prefsLen 29313 -prefMapSize 244195 -jsInitHandle 836 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2145e18d-6096-4457-a724-b84c0d36899e} 2276 "\\.\pipe\gecko-crash-server-pipe.2276" 4428 198ea3f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
3004 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2276.3.1077322245\792658652" -childID 2 -isForBrowser -prefsHandle 2876 -prefMapHandle 2872 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 836 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e0e5f2c1-453b-46a1-8d81-0e6837da5e5e} 2276 "\\.\pipe\gecko-crash-server-pipe.2276" 2888 16588f70 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
3248 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2276.5.2065503885\1845343508" -childID 4 -isForBrowser -prefsHandle 3992 -prefMapHandle 3996 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 836 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {772ad0d0-5274-469b-9644-54d91748eeb3} 2276 "\\.\pipe\gecko-crash-server-pipe.2276" 3976 196f39b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
3472 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2276.6.371764064\324570349" -childID 5 -isForBrowser -prefsHandle 4080 -prefMapHandle 4092 -prefsLen 34336 -prefMapSize 244195 -jsInitHandle 836 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d166f01f-8ad5-4f3c-9c3a-a30dba0b5f75} 2276 "\\.\pipe\gecko-crash-server-pipe.2276" 4188 196f3e00 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
3484 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2276.0.1023772669\1080111531" -parentBuildID 20230710165010 -prefsHandle 1104 -prefMapHandle 1096 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {473f2d49-5bfa-4450-bef3-ed2875cf98a0} 2276 "\\.\pipe\gecko-crash-server-pipe.2276" 1176 d2aabc0 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
3676 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2276.1.1608019694\1405435204" -parentBuildID 20230710165010 -prefsHandle 1384 -prefMapHandle 1380 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {aeadd755-9288-4d9a-b61a-d96d63b7e92c} 2276 "\\.\pipe\gecko-crash-server-pipe.2276" 1396 ee48840 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
3680 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2276.2.764995857\1082419268" -childID 1 -isForBrowser -prefsHandle 2056 -prefMapHandle 2052 -prefsLen 24491 -prefMapSize 244195 -jsInitHandle 836 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7ca28dbf-6d68-4ac2-8606-89505fac5cff} 2276 "\\.\pipe\gecko-crash-server-pipe.2276" 2068 127706d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
|
(PID) Process: | (3828) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 2166C0A101000000 | |||
(PID) Process: | (2276) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 044CC1A101000000 | |||
(PID) Process: | (2276) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
(PID) Process: | (2276) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
(PID) Process: | (2276) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
(PID) Process: | (2276) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
(PID) Process: | (2276) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
(PID) Process: | (2276) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
(PID) Process: | (2276) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
(PID) Process: | (2276) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: D14E5F3C23B0D901 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2276 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:B7A3C61D0C144CC5E166B1E769CA8F8C | SHA256:7FADCB77FFACA6B9E9F15C6F1CD3AAD4C20DCD90FA92429A627A3A7110CA2644 | |||
2276 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
2276 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
2276 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
2276 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journal | binary | |
MD5:090F9F8663536DBF5718E0C9C492CBB6 | SHA256:BD949B930761291AD5FED687E1391EDF6EB55C1E6E1802ED02FC4063B8F3A1FB | |||
2276 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
2276 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
2276 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal | binary | |
MD5:244BE91ECFD2779B7D39BF3D5C0FCAD1 | SHA256:35CE69E9F89D74F42C5170D9775BCA468D372692A85A0F890C7D54D68953D995 | |||
2276 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
2276 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2276 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | — |
2276 | firefox.exe | POST | 200 | 23.53.40.154:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
2276 | firefox.exe | POST | 200 | 23.53.40.154:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
2276 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | — |
2276 | firefox.exe | POST | 200 | 23.53.40.154:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
2276 | firefox.exe | POST | 200 | 142.250.181.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | — |
2276 | firefox.exe | POST | 200 | 142.250.181.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | — |
2276 | firefox.exe | POST | 200 | 23.53.40.154:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
2276 | firefox.exe | POST | 200 | 142.250.181.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | — |
2276 | firefox.exe | POST | 200 | 142.250.181.227:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2276 | firefox.exe | 104.26.4.170:443 | ea.trustifi.com | CLOUDFLARENET | US | unknown |
2276 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | unknown |
2276 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2276 | firefox.exe | 54.163.171.165:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
2276 | firefox.exe | 23.53.40.154:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
2276 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
2276 | firefox.exe | 142.250.185.170:443 | safebrowsing.googleapis.com | — | — | unknown |
2276 | firefox.exe | 34.117.65.55:443 | push.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2276 | firefox.exe | 216.58.206.35:443 | fonts.gstatic.com | GOOGLE | US | unknown |
2276 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | unknown |
Domain | IP | Reputation |
---|---|---|
ea.trustifi.com |
| unknown |
detectportal.firefox.com |
| unknown |
prod.detectportal.prod.cloudops.mozgcp.net |
| unknown |
contile.services.mozilla.com |
| unknown |
spocs.getpocket.com |
| unknown |
example.org |
| unknown |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| unknown |
ipv4only.arpa |
| unknown |
r3.o.lencr.org |
| unknown |
a1887.dscq.akamai.net |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |