URL:

goharpc.com

Full analysis: https://app.any.run/tasks/73aab193-dcac-4e66-80c4-54a9c43322fa
Verdict: Malicious activity
Threats:

Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.

Analysis date: November 23, 2023, 17:12:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
lumma
stealer
Indicators:
MD5:

AF66435A9C3B504492586FF9F84E8CD4

SHA1:

3B267594FB7E81676CCC2F5398A307D535C8348E

SHA256:

B0EE62806C79193EAD0042889D82FD0650231EF862E41A5E93DC336E2C6AF1C3

SSDEEP:

3:5LK:5LK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LUMMA has been detected (SURICATA)

      • Setup.exe (PID: 3260)
    • Connects to the CnC server

      • Setup.exe (PID: 3260)
    • LUMMA has been detected (YARA)

      • Setup.exe (PID: 3260)
    • Actions looks like stealing of personal data

      • Setup.exe (PID: 3260)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3440)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 3440)
    • Reads the Internet Settings

      • Setup.exe (PID: 3260)
    • The process drops C-runtime libraries

      • WinRAR.exe (PID: 3440)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 2700)
    • The process uses the downloaded file

      • firefox.exe (PID: 2700)
      • WinRAR.exe (PID: 3440)
    • Manual execution by a user

      • WinRAR.exe (PID: 3440)
    • Drops the executable file immediately after the start

      • firefox.exe (PID: 2700)
      • WinRAR.exe (PID: 3440)
    • Reads the computer name

      • Setup.exe (PID: 3260)
    • Checks supported languages

      • Setup.exe (PID: 3260)
    • Checks proxy server information

      • Setup.exe (PID: 3260)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 3260)
    • Creates files or folders in the user directory

      • Setup.exe (PID: 3260)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
21
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winrar.exe no specs #LUMMA setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
1268"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.6.550596247\697624178" -childID 5 -isForBrowser -prefsHandle 4092 -prefMapHandle 4080 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 864 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {05ff3b38-2456-4597-be3a-baabd33065f7} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 4116 233d7158 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1296"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.1.1054295105\12232237" -parentBuildID 20230710165010 -prefsHandle 1412 -prefMapHandle 1408 -prefsLen 29857 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fad5e577-7212-4de1-a941-da67fce30ed0} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 1424 43d4858 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2220"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.2.2110894171\1183738065" -childID 1 -isForBrowser -prefsHandle 2052 -prefMapHandle 2044 -prefsLen 25524 -prefMapSize 244187 -jsInitHandle 864 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {25b346a9-707e-4ac7-9179-6a7c63efb54c} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 2064 19a59b58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2488"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.3.537178461\479300741" -childID 2 -isForBrowser -prefsHandle 2864 -prefMapHandle 2860 -prefsLen 35402 -prefMapSize 244187 -jsInitHandle 864 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {426e05f6-2915-4a59-bd60-831e3523b1a1} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 2876 1e6b2858 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2496"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.7.685805823\507135715" -childID 6 -isForBrowser -prefsHandle 3908 -prefMapHandle 3756 -prefsLen 35569 -prefMapSize 244187 -jsInitHandle 864 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {cc40fd26-4d70-44a0-8091-444756ea621b} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 4284 d86d58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2700"C:\Program Files\Mozilla Firefox\firefox.exe" "goharpc.com"C:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2748"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.0.1910655269\1732283839" -parentBuildID 20230710165010 -prefsHandle 1108 -prefMapHandle 1100 -prefsLen 29780 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8cd478aa-3ba7-4300-906e-e9e44f37af4f} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 1180 43d2a58 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2812"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.5.1985479221\1239614985" -childID 4 -isForBrowser -prefsHandle 3872 -prefMapHandle 3876 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 864 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4c61914a-2f03-477b-bb1f-280376ec0c0e} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 3952 233d6e58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2884"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.4.839074937\1391813508" -childID 3 -isForBrowser -prefsHandle 3736 -prefMapHandle 3636 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 864 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f658890f-b641-4060-aa36-69c48024ad3d} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 3760 233d8658 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3128"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.16.1466342695\432264920" -childID 13 -isForBrowser -prefsHandle 8376 -prefMapHandle 8272 -prefsLen 30425 -prefMapSize 244187 -jsInitHandle 864 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {38ed3eba-bfc0-4690-9840-444b543fea2f} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 8216 25293358 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
15 696
Read events
15 613
Write events
83
Delete events
0

Modification events

(PID) Process:(2700) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
0000000000000000
(PID) Process:(2700) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(2700) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(2700) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(2700) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(2700) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
0
(PID) Process:(2700) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(2700) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(2700) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
F8B731ACA1C5D901
(PID) Process:(2700) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
182
Suspicious files
615
Text files
177
Unknown types
0

Dropped files

PID
Process
Filename
Type
2700firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2700firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.binbinary
MD5:4DF9B77C7650AF87B264E535779AE2A4
SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58
2700firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
2700firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
2700firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2700firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2700firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\ED9826654AE8BD972BDE17A9E0A449D3F881E430binary
MD5:79BFFD0DEC41F7B078772DD3D2DC6FEC
SHA256:016690815C02B2C0A15771528E6068D062FAF786FBB6CAAAB73C29D891AB2AA7
2700firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2700firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\places.sqlite-walbinary
MD5:AB99BCAFC177E5C62F3B545D1CEA495D
SHA256:8FB10A2F0E3D615BA97E47C08A838327BCFED1DB4A26AA08BD80B02B38B62D14
2700firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage.sqlite-journalbinary
MD5:CAF10CB1F37D57B79FCAE46FDB80A42B
SHA256:6265C487B468A819B30E750360979F79C3C95B587F432DBCC91A303768533DD5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
75
TCP/UDP connections
180
DNS requests
274
Threats
47

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2700
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
2700
firefox.exe
GET
200
188.114.96.3:80
http://goharpc.com/wp-content/themes/generatepress/assets/css/main.min.css?ver=3.3.1
unknown
compressed
4.57 Kb
unknown
2700
firefox.exe
GET
200
188.114.96.3:80
http://goharpc.com/wp-includes/js/mediaelement/wp-mediaelement.min.css?ver=6.3.2
unknown
compressed
1.13 Kb
unknown
2700
firefox.exe
GET
200
188.114.96.3:80
http://goharpc.com/wp-includes/js/mediaelement/mediaelementplayer-legacy.min.css?ver=4.2.17
unknown
compressed
2.53 Kb
unknown
2700
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
2700
firefox.exe
GET
200
188.114.96.3:80
http://goharpc.com/
unknown
html
46.5 Kb
unknown
2700
firefox.exe
POST
200
184.24.77.81:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
2700
firefox.exe
POST
200
184.24.77.81:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
2700
firefox.exe
GET
200
188.114.96.3:80
http://goharpc.com/wp-includes/css/dist/block-library/style.min.css?ver=6.3.2
unknown
compressed
13.5 Kb
unknown
2700
firefox.exe
POST
200
142.250.185.67:80
http://ocsp.pki.goog/gts1c3
unknown
binary
472 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
2700
firefox.exe
188.114.96.3:80
goharpc.com
CLOUDFLARENET
NL
unknown
4
System
192.168.100.255:138
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
2700
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
2700
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2700
firefox.exe
34.196.199.111:443
spocs.getpocket.com
AMAZON-AES
US
unknown
2700
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
unknown
2700
firefox.exe
188.114.96.3:443
goharpc.com
unknown

DNS requests

Domain
IP
Reputation
goharpc.com
  • 188.114.96.3
  • 188.114.97.3
  • 188.114.97.9
  • 188.114.96.9
  • 2a06:98c1:3120::3
  • 2a06:98c1:3121::3
unknown
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
spocs.getpocket.com
  • 34.196.199.111
  • 34.200.129.107
  • 3.218.237.85
  • 44.194.239.237
shared
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 44.194.239.237
  • 34.196.199.111
  • 34.200.129.107
  • 3.218.237.85
shared
r3.o.lencr.org
  • 184.24.77.81
  • 184.24.77.53
  • 184.24.77.61
  • 184.24.77.58
  • 184.24.77.46
  • 95.101.54.129
  • 95.101.54.113
  • 95.101.54.201
  • 95.101.54.144
shared
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted

Threats

PID
Process
Class
Message
324
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
324
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
324
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
324
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
324
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
324
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
324
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
324
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
324
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.pw domain - Likely Hostile
3260
Setup.exe
Misc activity
ET INFO HTTP Request to a *.pw domain
5 ETPRO signatures available at the full report
No debug info