URL:

https://u47119789.ct.sendgrid.net/ls/click?upn=u001.qh9tzjnjFPui3eL-2BXET55q04T1zwpHTT390iJjWR0O4RXjQmUkc-2BqMtRDHpXAF0dROYDyDz9I1LjOTesBApOKKeiuFPlDClDUDaLI47QZvY-3D2lc1_xX4LCGi0Acy-2F76tnSRLU63J6y73nt71Z2SgfrX8HFVoVK1FoaEemQpoPbj9m8Eugk-2B-2FvIieOzUWo2h54ixiDoGXR3H5OMEJKIDygnff4hPDo6KmEqluYDgFqh4rJO-2BjDgGhfPR-2FPIau-2Fb-2BhgfSU3qD5z8D84giu9FJfa9xybOnnRWNpZP-2F1Q6EmCbbe125-2Bg-2FOt5-2FRerp5pSNBlYlkpGSQxRTrHS3LTaItNIefT9vDkuCe1ChmWz87lLjBYzupvMo6fK82BVaYMXTW7r5FVwMCPU3AVqyT-2F82bMPP6LT0Hm1b78Ow7XuNnTY-2BlYoNkBLz27ZIqZO6eX-2B1pMcja-2F-2FaDxmjjJW113EOY-2FESsdjjd31meLH19BJL3I-2BcWcbQ4v0tXzStFQq5ujEVlmjJ3RDkqTT7Rs2snzk7xqcIPLPWxJFVXVXQdzVkizRmKA21d5CZZ7iUSGz62mgRjkif0tHZ795DoH0wiuFXHTZoCX9O9TV9zk5EP4BRflVhbMEQO76cAkm7Yc66mHtuKXKU0fwmj31XjyizeLv0rjZYwVhyERAk1YrLqTWPoY-2BKtnGfSRchAzxp0Onfqhu-2FWLndMB9asAtZGqUJ752qUOwpKp1G6bCGT00n-2BQqNYXd530I-2Br4QlsPZjosEaSxZjv5kf1q1dDSznDqM-2FMB-2FE5tG2oPJsg97K59Gg3nivE2WkNMGVW68w1076g04iccEFKLj8SJIIuuTbUYTS1u1aWpFxvuZajxKxbjXbKoWmD3GNcYok-2Fs9Rzcqhg5-2FnSEyj5-2FjeUHHheGwVYo-2BR-2FM-2FEUtdIs0bE1KYM5winhZ0Jnl-2Fuc5-2Buj1YmIFXlGVSoUVkFXLrChYDhL9fVdjxenLQHrq904RA-2FxitPIP-2B-2B5oGRUGSXqgaByPlXFtfWeOp9dSs1ARF2CAFcw-3D-3D

Full analysis: https://app.any.run/tasks/45fcdbea-bfb7-44d5-84f5-e877e2611f6e
Verdict: Malicious activity
Analysis date: September 23, 2024, 18:50:07
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
possible-phishing
phishing
evasion
Indicators:
MD5:

37B80E882B5129AE4ABBCB6F468ACD9D

SHA1:

167AEEEDBDFBA820907CCE42FC5849A71709D3E5

SHA256:

ABA4090F7D91520F0D655EDE501321B76654094F930F9A23BEB2043BFF95E6F8

SSDEEP:

24:2EsBMoiE1DCGX2dTOtI0QdMSG3QwRFmU3xnohNT81kCnVLfp:8Df1+GGd6tI0QdMSgIU5ohNT81hnV1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • PHISHING has been detected (SURICATA)

      • firefox.exe (PID: 6864)
      • svchost.exe (PID: 2256)
  • SUSPICIOUS

    • Checks for external IP

      • svchost.exe (PID: 2256)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 6864)
      • firefox.exe (PID: 6164)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 6864)
    • Possible Social Engineering Attempted

      • svchost.exe (PID: 2256)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
15
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs #PHISHING firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs #PHISHING svchost.exe firefox.exe no specs sppextcomobj.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1568"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1804 -parentBuildID 20240213221259 -prefsHandle 1728 -prefMapHandle 1716 -prefsLen 30537 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {39af455b-ece9-4082-a1ef-ef0a831d9c82} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 2767dfca110 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2256C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2536"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5800 -childID 6 -isForBrowser -prefsHandle 5876 -prefMapHandle 6036 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f36b489b-893c-4d38-aacb-c1fecf8dc1fe} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 2760b6daa10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3004"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5372 -childID 3 -isForBrowser -prefsHandle 5368 -prefMapHandle 5364 -prefsLen 36339 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {0d932dc8-4df4-4b9f-830f-a3b23c2e4c23} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 2760b146bd0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3164"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5908 -childID 5 -isForBrowser -prefsHandle 5900 -prefMapHandle 5896 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {df423a79-0dcf-4ac9-a67d-f28d27e35594} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 2760b6da850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3904"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2864 -childID 1 -isForBrowser -prefsHandle 2888 -prefMapHandle 2884 -prefsLen 26706 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a9642462-2e85-4439-b079-565b55efc3fb} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 27606b65150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4224"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4564 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5184 -prefMapHandle 5180 -prefsLen 36339 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c98631f2-78dc-4585-a8b1-6ef3c5d99932} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 27608d4fb10 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
6044"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6472 -childID 7 -isForBrowser -prefsHandle 6400 -prefMapHandle 6392 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {9dfeea0e-665e-4d87-bead-c5160914d3d6} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 27608b5ea10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
6164"C:\Program Files\Mozilla Firefox\firefox.exe" "https://u47119789.ct.sendgrid.net/ls/click?upn=u001.qh9tzjnjFPui3eL-2BXET55q04T1zwpHTT390iJjWR0O4RXjQmUkc-2BqMtRDHpXAF0dROYDyDz9I1LjOTesBApOKKeiuFPlDClDUDaLI47QZvY-3D2lc1_xX4LCGi0Acy-2F76tnSRLU63J6y73nt71Z2SgfrX8HFVoVK1FoaEemQpoPbj9m8Eugk-2B-2FvIieOzUWo2h54ixiDoGXR3H5OMEJKIDygnff4hPDo6KmEqluYDgFqh4rJO-2BjDgGhfPR-2FPIau-2Fb-2BhgfSU3qD5z8D84giu9FJfa9xybOnnRWNpZP-2F1Q6EmCbbe125-2Bg-2FOt5-2FRerp5pSNBlYlkpGSQxRTrHS3LTaItNIefT9vDkuCe1ChmWz87lLjBYzupvMo6fK82BVaYMXTW7r5FVwMCPU3AVqyT-2F82bMPP6LT0Hm1b78Ow7XuNnTY-2BlYoNkBLz27ZIqZO6eX-2B1pMcja-2F-2FaDxmjjJW113EOY-2FESsdjjd31meLH19BJL3I-2BcWcbQ4v0tXzStFQq5ujEVlmjJ3RDkqTT7Rs2snzk7xqcIPLPWxJFVXVXQdzVkizRmKA21d5CZZ7iUSGz62mgRjkif0tHZ795DoH0wiuFXHTZoCX9O9TV9zk5EP4BRflVhbMEQO76cAkm7Yc66mHtuKXKU0fwmj31XjyizeLv0rjZYwVhyERAk1YrLqTWPoY-2BKtnGfSRchAzxp0Onfqhu-2FWLndMB9asAtZGqUJ752qUOwpKp1G6bCGT00n-2BQqNYXd530I-2Br4QlsPZjosEaSxZjv5kf1q1dDSznDqM-2FMB-2FE5tG2oPJsg97K59Gg3nivE2WkNMGVW68w1076g04iccEFKLj8SJIIuuTbUYTS1u1aWpFxvuZajxKxbjXbKoWmD3GNcYok-2Fs9Rzcqhg5-2FnSEyj5-2FjeUHHheGwVYo-2BR-2FM-2FEUtdIs0bE1KYM5winhZ0Jnl-2Fuc5-2Buj1YmIFXlGVSoUVkFXLrChYDhL9fVdjxenLQHrq904RA-2FxitPIP-2B-2B5oGRUGSXqgaByPlXFtfWeOp9dSs1ARF2CAFcw-3D-3D"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\vcruntime140.dll
6304"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4444 -childID 2 -isForBrowser -prefsHandle 4436 -prefMapHandle 4432 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1204 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {bb35fc08-ff34-41a6-bcd5-74e71859c1b0} 6864 "\\.\pipe\gecko-crash-server-pipe.6864" 27606ca64d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
12 812
Read events
12 811
Write events
1
Delete events
0

Modification events

(PID) Process:(6864) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
Executable files
2
Suspicious files
144
Text files
34
Unknown types
4

Dropped files

PID
Process
Filename
Type
6864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
6864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
6864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:CA885C61A7F59BB07DB83A5EF0FD68B1
SHA256:017B29186E3F8C7AA7144EA79972AE2D954AD0240D7311529A36BAF609CB7624
6864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:811954755E27247C95447A45B752E1B6
SHA256:C060E1283F61BFE150041041BCEB79E10C910D96BEFB794E9B6BFEC3070FD2E5
6864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.binbinary
MD5:3A077074D35CD00015443A840B0C34A1
SHA256:BD09D18ACBBC0F11869E9208D7ADE91F4358C85A47C97242244B86A03ADB4835
6864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
97
DNS requests
154
Threats
35

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6864
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
6864
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
6864
firefox.exe
POST
200
2.16.168.7:80
http://r10.o.lencr.org/
unknown
unknown
6864
firefox.exe
POST
200
2.16.168.7:80
http://r10.o.lencr.org/
unknown
unknown
6864
firefox.exe
POST
200
216.58.206.35:80
http://o.pki.goog/s/wr3/XjA
unknown
unknown
6864
firefox.exe
POST
200
192.124.249.22:80
http://ocsp.godaddy.com/
unknown
unknown
6864
firefox.exe
POST
200
2.16.168.7:80
http://r10.o.lencr.org/
unknown
unknown
6864
firefox.exe
POST
200
2.16.168.7:80
http://r10.o.lencr.org/
unknown
unknown
6864
firefox.exe
POST
200
216.58.206.35:80
http://o.pki.goog/wr2
unknown
unknown
6864
firefox.exe
POST
200
2.16.202.128:80
http://r11.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
6032
svchost.exe
52.183.220.149:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
whitelisted
1776
RUXIMICS.exe
52.183.220.149:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2120
MoUsoCoreWorker.exe
52.183.220.149:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
20.50.201.200:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4
System
192.168.100.255:138
whitelisted
6864
firefox.exe
142.250.185.106:443
safebrowsing.googleapis.com
whitelisted
6864
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
6864
firefox.exe
167.89.115.54:443
u47119789.ct.sendgrid.net
SENDGRID
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 52.183.220.149
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.78
whitelisted
u47119789.ct.sendgrid.net
  • 167.89.115.54
  • 167.89.118.35
  • 167.89.118.118
  • 167.89.115.147
  • 167.89.118.28
  • 167.89.118.106
  • 167.89.118.74
  • 167.89.115.26
  • 167.89.115.35
  • 167.89.118.126
  • 167.89.115.121
  • 167.89.115.58
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
example.org
  • 93.184.215.14
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
whitelisted
prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
unknown

Threats

PID
Process
Class
Message
2256
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] CloudFlare Public R2.dev Bucket
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] CloudFlare Public R2.dev Bucket
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] CloudFlare Public R2.dev Bucket
2256
svchost.exe
Misc activity
SUSPICIOUS [ANY.RUN] Abuse Public R2.dev Bucket
2256
svchost.exe
Misc activity
SUSPICIOUS [ANY.RUN] Abuse Public R2.dev Bucket
2256
svchost.exe
Misc activity
SUSPICIOUS [ANY.RUN] Abuse Public R2.dev Bucket
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msauth .net)
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
No debug info