| URL: | https://u47119789.ct.sendgrid.net/ls/click?upn=u001.qh9tzjnjFPui3eL-2BXET55q04T1zwpHTT390iJjWR0O4RXjQmUkc-2BqMtRDHpXAF0dROYDyDz9I1LjOTesBApOKKeiuFPlDClDUDaLI47QZvY-3D2lc1_xX4LCGi0Acy-2F76tnSRLU63J6y73nt71Z2SgfrX8HFVoVK1FoaEemQpoPbj9m8Eugk-2B-2FvIieOzUWo2h54ixiDoGXR3H5OMEJKIDygnff4hPDo6KmEqluYDgFqh4rJO-2BjDgGhfPR-2FPIau-2Fb-2BhgfSU3qD5z8D84giu9FJfa9xybOnnRWNpZP-2F1Q6EmCbbe125-2Bg-2FOt5-2FRerp5pSNBlYlkpGSQxRTrHS3LTaItNIefT9vDkuCe1ChmWz87lLjBYzupvMo6fK82BVaYMXTW7r5FVwMCPU3AVqyT-2F82bMPP6LT0Hm1b78Ow7XuNnTY-2BlYoNkBLz27ZIqZO6eX-2B1pMcja-2F-2FaDxmjjJW113EOY-2FESsdjjd31meLH19BJL3I-2BcWcbQ4v0tXzStFQq5ujEVlmjJ3RDkqTT7Rs2snzk7xqcIPLPWxJFVXVXQdzVkizRmKA21d5CZZ7iUSGz62mgRjkif0tHZ795DoH0wiuFXHTZoCX9O9TV9zk5EP4BRflVhbMEQO76cAkm7Yc66mHtuKXKU0fwmj31XjyizeLv0rjZYwVhyERAk1YrLqTWPoY-2BKtnGfSRchAzxp0Onfqhu-2FWLndMB9asAtZGqUJ752qUOwpKp1G6bCGT00n-2BQqNYXd530I-2Br4QlsPZjosEaSxZjv5kf1q1dDSznDqM-2FMB-2FE5tG2oPJsg97K59Gg3nivE2WkNMGVW68w1076g04iccEFKLj8SJIIuuTbUYTS1u1aWpFxvuZajxKxbjXbKoWmD3GNcYok-2Fs9Rzcqhg5-2FnSEyj5-2FjeUHHheGwVYo-2BR-2FM-2FEUtdIs0bE1KYM5winhZ0Jnl-2Fuc5-2Buj1YmIFXlGVSoUVkFXLrChYDhL9fVdjxenLQHrq904RA-2FxitPIP-2B-2B5oGRUGSXqgaByPlXFtfWeOp9dSs1ARF2CAFcw-3D-3D |
| Full analysis: | https://app.any.run/tasks/45fcdbea-bfb7-44d5-84f5-e877e2611f6e |
| Verdict: | Malicious activity |
| Analysis date: | September 23, 2024, 18:50:07 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 37B80E882B5129AE4ABBCB6F468ACD9D |
| SHA1: | 167AEEEDBDFBA820907CCE42FC5849A71709D3E5 |
| SHA256: | ABA4090F7D91520F0D655EDE501321B76654094F930F9A23BEB2043BFF95E6F8 |
| SSDEEP: | 24:2EsBMoiE1DCGX2dTOtI0QdMSG3QwRFmU3xnohNT81kCnVLfp:8Df1+GGd6tI0QdMSgIU5ohNT81hnV1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1568 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1804 -parentBuildID 20240213221259 -prefsHandle 1728 -prefMapHandle 1716 -prefsLen 30537 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {39af455b-ece9-4082-a1ef-ef0a831d9c82} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 2767dfca110 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 2256 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2536 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5800 -childID 6 -isForBrowser -prefsHandle 5876 -prefMapHandle 6036 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f36b489b-893c-4d38-aacb-c1fecf8dc1fe} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 2760b6daa10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 3004 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5372 -childID 3 -isForBrowser -prefsHandle 5368 -prefMapHandle 5364 -prefsLen 36339 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {0d932dc8-4df4-4b9f-830f-a3b23c2e4c23} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 2760b146bd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 3164 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5908 -childID 5 -isForBrowser -prefsHandle 5900 -prefMapHandle 5896 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {df423a79-0dcf-4ac9-a67d-f28d27e35594} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 2760b6da850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 3904 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2864 -childID 1 -isForBrowser -prefsHandle 2888 -prefMapHandle 2884 -prefsLen 26706 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a9642462-2e85-4439-b079-565b55efc3fb} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 27606b65150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 4224 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4564 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5184 -prefMapHandle 5180 -prefsLen 36339 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c98631f2-78dc-4585-a8b1-6ef3c5d99932} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 27608d4fb10 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 6044 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6472 -childID 7 -isForBrowser -prefsHandle 6400 -prefMapHandle 6392 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {9dfeea0e-665e-4d87-bead-c5160914d3d6} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 27608b5ea10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 6164 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://u47119789.ct.sendgrid.net/ls/click?upn=u001.qh9tzjnjFPui3eL-2BXET55q04T1zwpHTT390iJjWR0O4RXjQmUkc-2BqMtRDHpXAF0dROYDyDz9I1LjOTesBApOKKeiuFPlDClDUDaLI47QZvY-3D2lc1_xX4LCGi0Acy-2F76tnSRLU63J6y73nt71Z2SgfrX8HFVoVK1FoaEemQpoPbj9m8Eugk-2B-2FvIieOzUWo2h54ixiDoGXR3H5OMEJKIDygnff4hPDo6KmEqluYDgFqh4rJO-2BjDgGhfPR-2FPIau-2Fb-2BhgfSU3qD5z8D84giu9FJfa9xybOnnRWNpZP-2F1Q6EmCbbe125-2Bg-2FOt5-2FRerp5pSNBlYlkpGSQxRTrHS3LTaItNIefT9vDkuCe1ChmWz87lLjBYzupvMo6fK82BVaYMXTW7r5FVwMCPU3AVqyT-2F82bMPP6LT0Hm1b78Ow7XuNnTY-2BlYoNkBLz27ZIqZO6eX-2B1pMcja-2F-2FaDxmjjJW113EOY-2FESsdjjd31meLH19BJL3I-2BcWcbQ4v0tXzStFQq5ujEVlmjJ3RDkqTT7Rs2snzk7xqcIPLPWxJFVXVXQdzVkizRmKA21d5CZZ7iUSGz62mgRjkif0tHZ795DoH0wiuFXHTZoCX9O9TV9zk5EP4BRflVhbMEQO76cAkm7Yc66mHtuKXKU0fwmj31XjyizeLv0rjZYwVhyERAk1YrLqTWPoY-2BKtnGfSRchAzxp0Onfqhu-2FWLndMB9asAtZGqUJ752qUOwpKp1G6bCGT00n-2BQqNYXd530I-2Br4QlsPZjosEaSxZjv5kf1q1dDSznDqM-2FMB-2FE5tG2oPJsg97K59Gg3nivE2WkNMGVW68w1076g04iccEFKLj8SJIIuuTbUYTS1u1aWpFxvuZajxKxbjXbKoWmD3GNcYok-2Fs9Rzcqhg5-2FnSEyj5-2FjeUHHheGwVYo-2BR-2FM-2FEUtdIs0bE1KYM5winhZ0Jnl-2Fuc5-2Buj1YmIFXlGVSoUVkFXLrChYDhL9fVdjxenLQHrq904RA-2FxitPIP-2B-2B5oGRUGSXqgaByPlXFtfWeOp9dSs1ARF2CAFcw-3D-3D" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 6304 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4444 -childID 2 -isForBrowser -prefsHandle 4436 -prefMapHandle 4432 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {bb35fc08-ff34-41a6-bcd5-74e71859c1b0} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 27606ca64d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (6864) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6864 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6864 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 6864 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6864 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6864 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6864 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6864 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.bin | binary | |
MD5:CA885C61A7F59BB07DB83A5EF0FD68B1 | SHA256:017B29186E3F8C7AA7144EA79972AE2D954AD0240D7311529A36BAF609CB7624 | |||
| 6864 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:811954755E27247C95447A45B752E1B6 | SHA256:C060E1283F61BFE150041041BCEB79E10C910D96BEFB794E9B6BFEC3070FD2E5 | |||
| 6864 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.bin | binary | |
MD5:3A077074D35CD00015443A840B0C34A1 | SHA256:BD09D18ACBBC0F11869E9208D7ADE91F4358C85A47C97242244B86A03ADB4835 | |||
| 6864 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6864 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
6864 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6864 | firefox.exe | POST | 200 | 2.16.168.7:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6864 | firefox.exe | POST | 200 | 2.16.168.7:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6864 | firefox.exe | POST | 200 | 216.58.206.35:80 | http://o.pki.goog/s/wr3/XjA | unknown | — | — | unknown |
6864 | firefox.exe | POST | 200 | 192.124.249.22:80 | http://ocsp.godaddy.com/ | unknown | — | — | unknown |
6864 | firefox.exe | POST | 200 | 2.16.168.7:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6864 | firefox.exe | POST | 200 | 2.16.168.7:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6864 | firefox.exe | POST | 200 | 216.58.206.35:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
6864 | firefox.exe | POST | 200 | 2.16.202.128:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
6032 | svchost.exe | 52.183.220.149:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1776 | RUXIMICS.exe | 52.183.220.149:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2120 | MoUsoCoreWorker.exe | 52.183.220.149:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 20.50.201.200:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6864 | firefox.exe | 142.250.185.106:443 | safebrowsing.googleapis.com | — | — | whitelisted |
6864 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
6864 | firefox.exe | 167.89.115.54:443 | u47119789.ct.sendgrid.net | SENDGRID | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
u47119789.ct.sendgrid.net |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
ipv4only.arpa |
| whitelisted |
example.org |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
prod.ads.prod.webservices.mozgcp.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2256 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
2256 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] CloudFlare Public R2.dev Bucket |
2256 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] CloudFlare Public R2.dev Bucket |
2256 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] CloudFlare Public R2.dev Bucket |
2256 | svchost.exe | Misc activity | SUSPICIOUS [ANY.RUN] Abuse Public R2.dev Bucket |
2256 | svchost.exe | Misc activity | SUSPICIOUS [ANY.RUN] Abuse Public R2.dev Bucket |
2256 | svchost.exe | Misc activity | SUSPICIOUS [ANY.RUN] Abuse Public R2.dev Bucket |
2256 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |
2256 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net) |
2256 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com) |