| URL: | http://r.srvtrck.com/v1/redirect?yk_tag=dcc_400_df_234f9&site_id=01c4acc04f4d45969e998e808e70d93b&api_key=abbc5236946676eae219a734c0a1c5e8&url=https%3A%2F%2Fwww.lowes.com&source=http://worldsave.net&type=url |
| Full analysis: | https://app.any.run/tasks/948eb45e-33a4-4806-a7a0-e3573d691c67 |
| Verdict: | Malicious activity |
| Analysis date: | August 09, 2023, 13:11:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 192BA123461037E2C4B734D513340B98 |
| SHA1: | A9ACF7BA2F57A200A8E466A74B08A173B59FB187 |
| SHA256: | AC66FD6677A581A168134EE05FD8181CA93B54D0C0D5896E4E0082555A1AD8F1 |
| SSDEEP: | 3:N1KMLQVZLKpKXt46scu45eH7QfdlBh6CHnXW4gW9jEUGQ4WWDRVHWCXjZHAIKKZ9:CMLYKpG4Cu45eqzBsEnVizR3zZHJ3/rD |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 740 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1004.12.1426492873\1268844949" -childID 11 -isForBrowser -prefsHandle 4164 -prefMapHandle 4160 -prefsLen 31775 -prefMapSize 243955 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {da7bffd7-2d15-492f-8535-d71406b5157b} 1004 "\\.\pipe\gecko-crash-server-pipe.1004" 3364 1e4556d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 772 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1004.8.1440645704\1845409398" -childID 7 -isForBrowser -prefsHandle 2124 -prefMapHandle 2136 -prefsLen 29065 -prefMapSize 243955 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {edc0edad-1157-462d-9d3c-3f58f491b11a} 1004 "\\.\pipe\gecko-crash-server-pipe.1004" 2120 19fcc3f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1004 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://r.srvtrck.com/v1/redirect?yk_tag=dcc_400_df_234f9&site_id=01c4acc04f4d45969e998e808e70d93b&api_key=abbc5236946676eae219a734c0a1c5e8&url=https%3A%2F%2Fwww.lowes.com&source=http://worldsave.net&type=url | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1172 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1004.2.684453049\1096993612" -childID 1 -isForBrowser -prefsHandle 2036 -prefMapHandle 2032 -prefsLen 24255 -prefMapSize 243955 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0a2399ac-f7a1-4e4c-acee-b0491c85ae00} 1004 "\\.\pipe\gecko-crash-server-pipe.1004" 2052 12f919b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1400 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1004.1.832703466\252863441" -parentBuildID 20230710165010 -prefsHandle 1412 -prefMapHandle 1408 -prefsLen 28102 -prefMapSize 243955 -appDir "C:\Program Files\Mozilla Firefox\browser" - {671519f8-7177-42c6-8859-123b2af88173} 1004 "\\.\pipe\gecko-crash-server-pipe.1004" 1424 da1e8a0 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1816 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1004.3.1912379337\211586943" -childID 2 -isForBrowser -prefsHandle 2820 -prefMapHandle 2816 -prefsLen 33872 -prefMapSize 243955 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {42fc77a3-06ce-4e56-9580-33dc2f6bd243} 1004 "\\.\pipe\gecko-crash-server-pipe.1004" 2832 169f4c90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2028 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1004.6.1680948774\45426235" -childID 5 -isForBrowser -prefsHandle 3768 -prefMapHandle 3764 -prefsLen 33948 -prefMapSize 243955 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d40f569d-437d-4a92-9eb1-56d946e2ab12} 1004 "\\.\pipe\gecko-crash-server-pipe.1004" 3672 190acc90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2564 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1004.4.969455524\1215837435" -childID 3 -isForBrowser -prefsHandle 3496 -prefMapHandle 3448 -prefsLen 29011 -prefMapSize 243955 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6053dbeb-5c2f-4bfa-b5fc-66310cd215fe} 1004 "\\.\pipe\gecko-crash-server-pipe.1004" 3528 1852d110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2672 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1004.5.241655182\830806139" -childID 4 -isForBrowser -prefsHandle 3636 -prefMapHandle 3520 -prefsLen 29011 -prefMapSize 243955 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4e9273cc-1afa-435e-9f14-5ebb73cda32b} 1004 "\\.\pipe\gecko-crash-server-pipe.1004" 3668 1852dc90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2716 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1004.11.951623003\7090518" -childID 10 -isForBrowser -prefsHandle 2088 -prefMapHandle 2240 -prefsLen 31682 -prefMapSize 243955 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {78181e5f-ddab-4d1e-acff-4ed01187f14d} 1004 "\\.\pipe\gecko-crash-server-pipe.1004" 2260 19fccc90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (3504) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 815441AB02000000 | |||
| (PID) Process: | (1004) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: B73F42AB02000000 | |||
| (PID) Process: | (1004) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (1004) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (1004) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (1004) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (1004) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (1004) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (1004) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (1004) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: EA362D0F13B0D901 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1004 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal | — | |
MD5:— | SHA256:— | |||
| 1004 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-new.bin | — | |
MD5:— | SHA256:— | |||
| 1004 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache.bin | — | |
MD5:— | SHA256:— | |||
| 1004 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\targeting.snapshot.json.tmp | text | |
MD5:AE7C2AF2A172AE3B09A34346BE256343 | SHA256:BFA16C4AFEB7642ECC25F598567B2332BA83A884AF250581F1308AB26DCF34B6 | |||
| 1004 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\targeting.snapshot.json | text | |
MD5:AE7C2AF2A172AE3B09A34346BE256343 | SHA256:BFA16C4AFEB7642ECC25F598567B2332BA83A884AF250581F1308AB26DCF34B6 | |||
| 1004 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite-journal | binary | |
MD5:0C61390C853ECBDB9301E06B6FFE5634 | SHA256:E3242F00558EC94E2F94F618E0988A936938946910D7F077E2FDFB8C055412BE | |||
| 1004 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:EE7CE93E27CAEB88D7F3C4296CBA48AB | SHA256:7B873BB8A51F55DFF6EAE517B562717D3F597D69973E3CA9FDDEE89EC39C6A21 | |||
| 1004 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-wal | — | |
MD5:— | SHA256:— | |||
| 1004 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db | binary | |
MD5:BD188E6BFB6330B6AB76E90FB1196D69 | SHA256:63D94CF3B58870AB1465E0BA2FD4B0FE0E0744F76F4B3386D10D98E998E19128 | |||
| 1004 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1004 | firefox.exe | GET | — | 23.55.161.211:80 | http://ciscobinary.openh264.org/openh264-win32-2e1774ab6dc6c43debb0b5b628bdf122a391d521.zip | US | — | — | whitelisted |
1004 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | US | text | 8 b | whitelisted |
1004 | firefox.exe | POST | — | 142.250.186.163:80 | http://ocsp.pki.goog/gts1c3 | US | — | — | whitelisted |
1004 | firefox.exe | POST | — | 142.250.186.163:80 | http://ocsp.pki.goog/s/gts1d4/O-GmpPOKBKI | US | — | — | whitelisted |
1004 | firefox.exe | POST | 200 | 184.24.77.75:80 | http://r3.o.lencr.org/ | US | binary | 503 b | shared |
1004 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | US | text | 90 b | whitelisted |
1004 | firefox.exe | POST | — | 192.124.249.24:80 | http://ocsp.godaddy.com/ | US | — | — | whitelisted |
1004 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | US | text | 8 b | whitelisted |
1004 | firefox.exe | GET | — | 104.18.206.219:80 | http://r.srvtrck.com/v1/redirect?yk_tag=dcc_400_df_234f9&site_id=01c4acc04f4d45969e998e808e70d93b&api_key=abbc5236946676eae219a734c0a1c5e8&url=https%3A%2F%2Fwww.lowes.com&source=http://worldsave.net&type=url | unknown | — | — | suspicious |
1004 | firefox.exe | POST | 200 | 192.124.249.24:80 | http://ocsp.godaddy.com/ | US | binary | 2.06 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1004 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | suspicious |
1004 | firefox.exe | 104.18.206.219:443 | r.srvtrck.com | CLOUDFLARENET | — | whitelisted |
1004 | firefox.exe | 35.172.161.7:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
1004 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | suspicious |
1004 | firefox.exe | 18.205.42.100:443 | 905trk.com | AMAZON-AES | US | unknown |
1004 | firefox.exe | 3.209.177.37:443 | lg.provenpixel.com | AMAZON-AES | US | unknown |
1004 | firefox.exe | 192.124.249.24:80 | ocsp.godaddy.com | SUCURI-SEC | US | suspicious |
1004 | firefox.exe | 34.192.219.139:443 | lg.provenpixel.com | AMAZON-AES | US | unknown |
1004 | firefox.exe | 35.244.181.201:443 | aus5.mozilla.org | GOOGLE | US | suspicious |
1004 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
r.srvtrck.com |
| suspicious |
detectportal.firefox.com |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
firefox.settings.services.mozilla.com |
| whitelisted |
prod.remote-settings.prod.webservices.mozgcp.net |
| whitelisted |
safebrowsing.googleapis.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |