URL:

https://gchq.github.io/CyberChef/#recipe=From_Hex(%27Auto%27)&input=MUYgOEIgMDggMDAgMDAgMDAgMDAgMDAgMDAgMDMgODUgNTggNWQgYWYgZGIgYjggMTEgN2QgZDcgYWYgNjAgZmQgYjIgYmIgODAgN2QgN2QgNmYgYmEgNDkgZWUgMDYgYjYgMGIgMzQgNGQgZGIgYTAgMmQgMTIgMjAgNTkgMmMgZjYgOTEgOTYgNDYgMTIgNzMgMjkgNTIgMjUgMjkgM2IgZGEgYTcgZmMgOGQgMDUgZGEgM2YgOTcgNWYgZDIgMzMgNDMgYzkgZjIgY2QgYjYgY2QgNGIgYWUgMjUgOTEgYzMgMzMgNjcgY2UgN2MgMzAgYmIgZGYgZmQgZTkgY2QgY2IgZjcgM2YgYmYgN2QgYTUgZGEgZDQgZDkgNDMgYjEgZTMgM2YgY2EgNmEgZDcgZWMgNTcgZTQgMzYgM2YgYmUgNWIgMWQgMGEgYTUgNzYgMmQgZTkgOGEgN2YgZTAgNjcgNDcgNDkgYWIgYjIgZDUgMjEgNTIgZGEgN2YgMzMgYTQgN2EgNzMgZmYgY2QgZjUgMjcgYTcgM2IgZGEgYWYgNGUgODYgY2UgYmQgMGYgNjkgYTUgNGEgZWYgMTIgYjkgYjQgNWYgOWQgNGQgOTUgZGEgN2QgNDUgMjcgNTMgZDIgNDYgMWUgNTYgZDMgM2UgNmIgZGMgODMgMGEgNjQgZjcgYWIgOTggNDYgNGIgYjEgMjUgYzIgYzYgMzYgNTAgYmQgNWYgNmQgNzUgYzQgNDEgNzEgNWIgYzYgYjggYWQgNGMgNDggNDcgZGQgYzQgMWIgM2MgZmMgZTEgYjQgYmYgZDUgZTUgZjEgYjYgMmUgZWYgYWEgMjcgZmEgZWUgZjYgZWUgZjkgMGYgYjcgNGYgOWYgZGQgM2UgYjkgN2QgYTYgYmYgYmYgN2YgN2EgZjcgOWMgZTggZmIgMWYgOWUgM2MgYTMgZmIgZmIgYmIgZmIgZGYgMWUgNjMgMDAgNmEgYTUgZDIgZDggMDMgYTkgZTkgNzQgNDMgZGIgZGUgMzUgNWYgOWUgMjggMWYgZjAgMDcgNmIgNmYgZjggZjMgNjQgMjUgOTkgNjQgZTkgNzAgODEgZDIgOTggZDQgMGUgYzcgMWIgZTMgZDUgNzEgNTQgZjMgZGIgZGQgMzYgYWYgNjIgZWEgYjYgOTkgM2IgZmUgNzkgZjQgZDUgMzggNTkgNjkgZWYgOTQgYTkgZjYgMmIgNTkgYjYgM2EgYmMgNjQgOGUgNjIgNTIgYWYgNWQgMGEgYmUgMWEgY2EgNjQgYmMgYzMgYzYgM2IgNmMgZGIgZjUgODcgOWYgNDggOTUgODEgNzQgYTIgNGEgYTUgOTYgMTQgOWQgNDAgYTcgNGEgNWUgNjkgNmIgZmQgNTkgZjUgM2EgMjQgNTMgOWEgNWUgYTcgYzggMmYgNTMgMTggNTUgZjQgZjYgNjQgNWMgMDMgZWEgYmIgN2UgNDggMTQgNTQgYTQgNzIgMDggMjYgOGQgNDUgM2YgZmMgZjIgMGIgMDggNWUgMmIgZWQgMmEgNWUgNGQgYWUgODEgOTMgY2EgYjggN2MgODIgMzkgYzEgZmMgYzcgZGUgZmEgYTAgMTkgMDIgYmYgZDcgMmEgZWEgMWEgNmYgZGQgYzkgMDQgZWYgM2EgM2UgZmEgMGMgOTcgOGIgNDAgYzAgMDkgNDQgNjAgMjcgZDIgM2YgMDcgNzIgMjUgNDUgNTUgZmIgYTAgMzQgZDAgOWYgNGMgMzIgNzggNmMgYzggNTEgMDAgY2EgNTEgNTYgOTkgOGEgYjAgNDkgNzUgZGEgMDIgYWUgMWYgYTIgZjIgYTEgMzAgZDYgNTIgYTMgZWQgOGQgNTIgN2YgMWMgNTUgMWYgZmMgYzkgNTQgMGMgN2MgM2EgYjQgYjcgYmEgMjQgODEgMjkgOTggNjggYWQgMmEgYWEgYzkgYzEgNGUgNTQgM2EgOTAgM2EgNTIgODIgNzcgODUgM2UgNWEgNTkgNjUgNDkgMDcgYTcgY2UgYWQgNGUgZWEgYzEgYjggMGEgMDcgZDQgMmEgNTEgZDkgM2EgMDMgN2MgOTEgYjkgMWIgNTUgNjcgOWEgMzYgMjkgNDcgMjQgZWUgNjcgNzMgODUgNmUgYjQgNzEgMzEgZGQgZWMgYjYgM2QgMzMgM2UgYzUgYTYgMDQgZTMgOGQgMGYgNzAgMDQgMDEgYmEgZmMgNWUgYzIgZjIgNjYgMDggMDAgNDYgYTEgMzQgOTEgNWQgMDcgN2QgMDMgMzAgNzUgODMgNGQgYTYgMDcgYTAgNjUgZmIgMWEgOTggNGMgZDkgMGEgNjQgNjggY2UgOTQgNDIgODkgZjMgMDkgMjQgZGEgMWMgNTYgYjggYTggYjEgYzIgMDMgNjMgMDAgMTkgYWYgZjggNjEgMzIgMzAgNWUgMWQgYTIgYTcgNjggMGYgNTYgMjMgYTggMGYgNjAgMGYgNGEgYmQgMjkgZmUgMGMgZGEgZDkgMDEgOGQgMjAgMjAgYjQgMzkgZTUgMjAgYTcgNGUgOGYgMTcgNWMgYTUgYWYgZTggODggMTggODMgOTkgNjYgYWQgNmEgMjMgMDggYzMgNDkgOWUgODIgZWUgNGQgNTUgZjAgMGEgMzAgNzIgMjIgZWIgN2IgOGUgNzMgMTYgYzkgOGYgY2UgN2MgNTQgNzEgOGMgODkgM2EgYTUgYWIgY2UgMzggMTMgNTMgNTYgMDcgNzAgMmUgYjQgODggNzMgNjQgMTggN2YgNzEgMTUgZWMgY2YgOWYgZmUgMzUgNDkgZWUgZjMgYTcgN2YgMjMgZTAgZmMgYzIgNDIgNjUgNzggOWEgZDkgZWUgMGYgNmYgNjUgYzUgMTUgNjEgNjIgMmMgYWIgMmEgMTkgNmQgZDcgMGEgYWUgYzEgNmIgMzUgOTkgNDIgMjQgMTEgZTIgZDEgMGYgZDggZTIgNTQgZTUgY2YgY2UgN2EgNWQgMTUgYjAgN2UgODYgYzggNDkgZGUgMDggZjYgYjMgMGYgMGYgMGEgMzIgNjYgYzEgZmEgMjEgYTkgN2EgMDggMGMgMTAgNWMgNDEgMzYgNWEgYjIgNGMgYmUgNDkgNWEgNGQgYTQgMTUgOTEgYzIgNDkgODIgZjAgZjIgOGEgMzEgOTggNDMgMTggNzQgYzcgODEgODUgYWEgZjQgMDQgZTUgMTIgYTMgMTcgMDIgYTcgYTEgMjQgZWMgNTcgYjQgMmUgMzIgMTQgOTMgMzIgMWEgNjAgOGIgZmEgMjQgY2YgMmMgM2IgMTMgMWYgMzIgYmIgYjMgMTMgMDAgMDAgNGYgNTAgM2UgMTMgMDIgNWYgMDcgZGYgZjEgOWIgNjIgOGUgYTMgYTMgMjQgYWUgN2MgY2IgNjYgM2MgYWEgYWMgZTkgYzAgMDIgZjYgODYgNGIgOGEgN2YgMDcgYzAgYmYgZTUgNzEgODggMDMgNmIgYWQgZDAgNjcgMWQgMmEgZDUgN2IgMzggMWUgMjEgNDYgNzIgOTMgYzcgMjEgNTAgMDkgYzggMmUgOWUgOTkgOTUgODggMmMgNGYgMWMgMzYgNjAgNGIgOTMgNjYgZjkgMjggNTkgZWMgZTggNjMgOWEgY2EgMDcgOTcgMDUgN2UgMzUgZTcgM2QgZWYgZWMgMDMgNDUgZGUgNWQgMmQgNjEgZmQgM2IgNTcgOTMgMmIgMzAgMDEgY2IgOGQgMjggNTEgYTQgOWEgZmUgNmYgMTggNjYgOWYgNmYgMGEgMTEgZTAgNjMgZTUgZjEgODEgNWYgMDYgYzQgNWUgOWQgODYgNzAgODAgNjggYjYgYzQgNzkgNWQgODQgYzEgMzkgOGUgMjEgNDcgZDYgNzAgOTkgY2EgYWUgZjUgNTIgNmEgMjEgMTcgNTMgZDcgZjAgMWEgODAgZTAgMDMgYjIgMzcgYWEgYTMgOGUgZDAgYWUgMTcgMmYgMGQgY2IgMDUgMTQgZGYgMTQgM2YgMjMgNTYgZGQgMDAgNjggYmEgZmEgYzAgN2YgODQgN2YgZjkgOTYgZWIgYWUgNjkgMWEgYjAgNzggNGQgMmMgMzQgYzcgNWYgYjkgMmEgNjYgZWUgNmYgMGEgMjEgNjUgZDYgMzEgY2IgN2MgMGEgMTEgOTcgODMgMmIgYzkgYmYgNTAgMzMgNjggMjQgM2MgYmUgOTMgN2QgNWMgMjMgZDYgMDUgNWUgMmEgZGYgNzMgMjQgYTUgMTEgNzAgYWQgMWMgNTEgMTcgYmYgYTggNjEgMTEgNTAgMGMgZjcgYWUgNzcgZjkgYzcgNTIgYmQgZGUgMDMgYTcgM2YgN2UgYTAgNTIgOGEgYmUgOTEgZGUgZDEgZTkgODcgMWMgZWMgY2UgYzMgYmYgMDkgZjIgMjUgOWUgYWYgMjEgZTMgODEgN2IgNDkgMWEgZmEgNzUgYzYgOTIgNDggNzcgYmMgZjcgYTggNTMgYjIgOGMgNTYgMWEgODAgZWEgNTEgYWYgZTAgMDcgNzcgMTYgYzQgYzYgM2IgY2EgYjYgNDAgNTYgMjEgZGIgNzQgM2UgNzQgOGUgNTYgNGUgODUgNjUgNTMgMjYgNDYgNTcgNTUgYWUgOGMgZmUgYzggNjEgZTQgODAgZmIgOTMgYjQgOTMgODIgYmQgMjIgMzkgZWIgODIgMDIgZjIgN2YgZGYgMDIgODkgYTAgNDMgMjAgNTkgZjAgYzAgODUgZjQgYzUgOWMgMjEgZjYgOTkgZTAgOGEgZmEgZDQgNGEgYWUgODYgYzkgYzggMTkgMzUgMTQgN2QgNDQgYjUgZTggMGIgNTIgMTkgMGMgZDMgOGYgNzggOTggNWEgOTIgOTMgNWIgMjkgNjUgMTcgMmUgZGEgYWYgNzkgZmIgNzUgNzkgNDcgM2QgNzIgOGYgMzcgZjAgOTIgNGIgOTggYjEgODUgMGQgY2MgZWUgY2UgNTAgYjUgOGQgYmUgZTggMDggZDkgOTcgMGIgOWEgNTYgNGYgMjYgOWUgOTYgYTMgZjQgZDIgMDUgMjQgNDMgOWUgODIgOTAgYTQgZWQgOWMgY2EgYjAgODIgMjQgNDEgMzcgYWUgZDEgMGYgM2EgZjYgNjcgYTIgMjggNDMgZDIgZWEgZjcgYjcgYjcgNWYgYjUgZjkgZmMgNzYgNWUgZjQgMzggZDggMmMgODQgMmEgZjggN2UgODMgM2QgNTMgZDAgYTcgNjMgMzkgM2MgZGYgYjYgNTAgNWYgM2QgODAgYWEgZWYgYTYgODQgYzggZDEgYzIgMDggNjUgNTkgZmIgYWQgM2YgMTcgZGQgODAgZTggNTAgOGQgNDAgYTEgOWMgYTAgM2QgNDQgNTQgMTMgOWQgNDQgNmQgNTMgMzEgOTAgMmQgOTkgMzIgM2UgMmUgODMgMDQgNDEgOWMgNmIgMTEgMzUgZGIgNTYgMDggY2UgYTUgYzEgZTcgODUgNTcgYjQgNmEgMzcgYTIgYjQgYTIgZDUgMDggZjUgNjcgY2QgNGQgNmIgMmUgZjYgMjAgMjYgOGMgNTIgYmEgOGYgNzggMmMgMDQgZmEgNjYgY2EgMDcgMjUgOTUgODQgOWEgZjEgY2IgNzQgOTkgZTYgYTQgOGQgYWYgMzcgMmMgOTIgY2QgNWMgNWUgOTEgNDAgZDMgMjcgNTYgZjQgYTMgY2EgYmIgYTQgZDQgM2YgMzggNmIgNTggZjAgM2MgMTggZjAgOTAgYjYgZDQgM2MgODYgMDcgMDcgOGUgNzIgYjggNmMgZTcgYWUgMzAgOWIgODAgYzMgYWYgMTMgYjMgYzIgMWEgZDUgNDUgZTMgN2QgMDUgMzggYTQgOTcgMmQgN2EgOTkgZTUgMjQgNjYgYTYgZTMgZTEgM2EgMTcgNTEgZDAgZGIgZTUgYjIgYzggYTUgZTAgYjIgYjAgNjggNzUgZjkgOTAgYTcgNDAgYTkgYTggMzggMDQgODMgNjQgMjIgYWUgMTUgZTQgZmIgY2MgZTggZGMgYWEgZmYgNWIgZTkgMmQgNWEgZjggODMgMzkgNjEgOWQgYzMgZGEgNDEgNWEgNDIgZjggNzIgMzYgYjcgMjMgODIgODEgNWMgNDIgYWUgODAgMWMgYTkgNjYgMzEgZjIgYzQgODUgMjYgZDYgZDEgNjUgZGUgMDQgZWYgZGUgMzUgNTcgMDMgMjEgMGMgY2IgZTQgNjIgYTUgN2MgMzAgOGEgMzcgZWYgOTQgYWUgNTMgODYgMzQgN2UgZmUgZjQgMmIgNGMgNWIgYWEgZDMgMjIgY2QgOWYgYjggN2YgODEgZGYgMzAgZjIgM2MgOWQgMDkgZTIgZDEgYTggYzQgZmMgYjcgNzAgOWEgYzcgYmQgY2EgM2IgOTggYzAgMjQgODQgNzkgMTAgYTggYjAgOTIgZjEgYTAgZjIgNzcgOTggYTcgZDAgZTcgNGMgYzIgNjcgZGUgMmMgNTIgOTUgMGMgYWEgMDcgMzcgOGQgZDggNTIgNjAgZjggMWMgY2UgNWUgZTMgNGUgYWMgYmUgZWEgMDUgODIgYzQgZTcgMTYgM2MgNDMgNGEgZDUgMTQgYTEgNjUgOTUgNDkgNjUgODMgMWYgOTIgNjUgNjcgNGMgNWYgYjkgZDMgZTQgYTEgYjMgZDQgNDMgMjQgZjggOGIgZjQgYWQgMzQgZGYgMmQgYjAgYjkgMDAgYTEgNmMgNWQgOGEgZmEgMzIgY2EgNWYgYTUgZTIgYTQgY2MgYWIgZjkgN2IgNzUgNzggYjUgM2MgMmMgZWEgOWIgY2EgMzMgMWEgMzEgYmEgMTkgNjcgZDYgOTQgYjMgNjcgZWUgNzAgMzIgNGYgYTggZTAgMzEgNTggNTggMDYgOTMgNDcgOWEgNGEgYmEgYzYgNTQgMWQgMzcgMjcgOGYgYzEgMzQgMTYgOTggZDAgMDYgOTYgMmUgZmYgYzMgNDMgMWIgNzEgM2EgZTMgMzQgY2MgNWYgZTggN2UgYTYgY2MgM2EgY2EgYzcgYTAgZjAgM2IgYjQgMmMgZTQgMTUgZGYgZGIgNzAgYTIgNjYgY2IgNjggNWUgN2UgYzAgNTggOWQgMzggNmYgYTcgZTIgYzYgOWYgMTQgMmEgMzMgNzcgNGEgNzIgMzkgNGIgZjEgNGYgYzggMzcgMDggNDcgMzIgMDUgZTQgMGIgY2MgZDUgMmMgMzYgMGYgM2UgOWUgZjkgMDQgMzAgYmUgNGEgMjkgMzEgY2IgMDMgYTQgMDAgOTkgMjMgYWMgMmQgZjggOGUgMzIgODIgZTUgZDkgODQgZmIgYzAgMTkgZWIgN2UgYWQgMjYgYjAgZWIgODIgMGIgNDMgZDMgNjYgMzEgYjYgM2MgOGUgODUgMzkgZDYgYjkgOWEgNTggZTkgN2IgMTIgZjIgYzkgMDAgZGYgMDEgOGQgZTMgMDMgZDcgMzIgOTYgMTUgYTUgYzUgZWQgOTAgNzkgOGMgMzkgN2QgMjYgYjEgNTkgN2QgOTQgMTcgMTUgOGYgZTAgYWEgYjYgZGUgNWYgNWEgNzEgYmUgZWYgMzkgN2QgY2EgMzcgM2YgZmMgMWUgZWMgZmMgNTMgMmUgYTUgODcgOWQgOWUgNmYgOWUgYWIgYzMgNWYgOTEgMmQgYmIgYWQgM2UgZWMgYjYgZjggZjAgM2YgNTYgNGQgZWMgNmMgNzEgODMgZTUgZWIgZTMgN2UgODUgZjkgOWYgZDMgYjAgNTQgZDMgM2QgZjIgNzIgYTEgZmMgOWEgYTUgMGYgNzEgZDMgOGYgNjAgYzUgMmQgYjYgZGUgY2EgYjMgNjggZmYgYTUgZjcgNTYgZmQgY2QgNTQgYjggZmYgZTQgYjcgNWYgMzEgZDcgYTYgZDQgYzcgMTcgZGIgZWQgNzQgMjUgMDYgMzkgOTcgMWIgZmIgNjIgM2UgNzggOWUgMzkgMjIgODcgZjQgMmYgYjIgMGUgYzYgYTcgNzcgNWYgOWEgZGYgNmQgNjcgYTYgNzYgZGIgODkgYmYgZGQgMzYgZGYgYTEgMjEgN2IgZjk

Full analysis: https://app.any.run/tasks/b313a9a9-22dd-42b5-8f6c-02be72ca3c63
Verdict: Malicious activity
Analysis date: July 19, 2019, 17:56:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

A9BBE204F26E0931EF38AE184EAAA7D4

SHA1:

94DFE16D3891414D31FB2CE2423DCB9DEE5231AF

SHA256:

B19E60B3E00F8165E767BC7F414D04FF39B48EA3EE5B95DF22821D41F21625BB

SSDEEP:

192:5U7n6VVA0F6dxQj7Ku8wDr8Rc2zU7OG3a1S1iJPo:wnSVIQe6Dr8Rc2w7v3a1S1EPo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Uses RUNDLL32.EXE to load library

      • firefox.exe (PID: 3656)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 3656)
    • Executed via COM

      • DllHost.exe (PID: 3596)
  • INFO

    • Reads CPU info

      • firefox.exe (PID: 3656)
    • Dropped object may contain Bitcoin addresses

      • firefox.exe (PID: 3656)
    • Manual execution by user

      • explorer.exe (PID: 3616)
    • Application launched itself

      • firefox.exe (PID: 3656)
    • Reads settings of System Certificates

      • firefox.exe (PID: 3656)
    • Creates files in the user directory

      • firefox.exe (PID: 3656)
Find more information about signature artifacts and mapping to MITRE ATT&CKâ„¢ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
9
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe rundll32.exe no specs winrar.exe no specs PhotoViewer.dll no specs explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2232"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.0.1532046491\2004752078" -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 1156 gpuC:\Program Files\Mozilla Firefox\firefox.exe—firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
67.0.4
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
2992"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.20.482135568\1438305167" -childID 3 -isForBrowser -prefsHandle 3504 -prefMapHandle 3528 -prefsLen 6720 -prefMapSize 188076 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 3540 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
67.0.4
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
3568"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.3.1533076417\24174709" -childID 1 -isForBrowser -prefsHandle 1780 -prefMapHandle 1776 -prefsLen 1 -prefMapSize 188076 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 1768 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
67.0.4
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
3596C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\system32\DllHost.exe—svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3616"C:\Windows\explorer.exe" C:\Windows\explorer.exe—explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3656"C:\Program Files\Mozilla Firefox\firefox.exe" "https://gchq.github.io/CyberChef/#recipe=From_Hex(%27Auto%27)&input=MUYgOEIgMDggMDAgMDAgMDAgMDAgMDAgMDAgMDMgODUgNTggNWQgYWYgZGIgYjggMTEgN2QgZDcgYWYgNjAgZmQgYjIgYmIgODAgN2QgN2QgNmYgYmEgNDkgZWUgMDYgYjYgMGIgMzQgNGQgZGIgYTAgMmQgMTIgMjAgNTkgMmMgZjYgOTEgOTYgNDYgMTIgNzMgMjkgNTIgMjUgMjkgM2IgZGEgYTcgZmMgOGQgMDUgZGEgM2YgOTcgNWYgZDIgMzMgNDMgYzkgZjIgY2QgYjYgY2QgNGIgYWUgMjUgOTEgYzMgMzMgNjcgY2UgN2MgMzAgYmIgZGYgZmQgZTkgY2QgY2IgZjcgM2YgYmYgN2QgYTUgZGEgZDQgZDkgNDMgYjEgZTMgM2YgY2EgNmEgZDcgZWMgNTcgZTQgMzYgM2YgYmUgNWIgMWQgMGEgYTUgNzYgMmQgZTkgOGEgN2YgZTAgNjcgNDcgNDkgYWIgYjIgZDUgMjEgNTIgZGEgN2YgMzMgYTQgN2EgNzMgZmYgY2QgZjUgMjcgYTcgM2IgZGEgYWYgNGUgODYgY2UgYmQgMGYgNjkgYTUgNGEgZWYgMTIgYjkgYjQgNWYgOWQgNGQgOTUgZGEgN2QgNDUgMjcgNTMgZDIgNDYgMWUgNTYgZDMgM2UgNmIgZGMgODMgMGEgNjQgZjcgYWIgOTggNDYgNGIgYjEgMjUgYzIgYzYgMzYgNTAgYmQgNWYgNmQgNzUgYzQgNDEgNzEgNWIgYzYgYjggYWQgNGMgNDggNDcgZGQgYzQgMWIgM2MgZmMgZTEgYjQgYmYgZDUgZTUgZjEgYjYgMmUgZWYgYWEgMjcgZmEgZWUgZjYgZWUgZjkgMGYgYjcgNGYgOWYgZGQgM2UgYjkgN2QgYTYgYmYgYmYgN2YgN2EgZjcgOWMgZTggZmIgMWYgOWUgM2MgYTMgZmIgZmIgYmIgZmIgZGYgMWUgNjMgMDAgNmEgYTUgZDIgZDggMDMgYTkgZTkgNzQgNDMgZGIgZGUgMzUgNWYgOWUgMjggMWYgZjAgMDcgNmIgNmYgZjggZjMgNjQgMjUgOTkgNjQgZTkgNzAgODEgZDIgOTggZDQgMGUgYzcgMWIgZTMgZDUgNzEgNTQgZjMgZGIgZGQgMzYgYWYgNjIgZWEgYjYgOTkgM2IgZmUgNzkgZjQgZDUgMzggNTkgNjkgZWYgOTQgYTkgZjYgMmIgNTkgYjYgM2EgYmMgNjQgOGUgNjIgNTIgYWYgNWQgMGEgYmUgMWEgY2EgNjQgYmMgYzMgYzYgM2IgNmMgZGIgZjUgODcgOWYgNDggOTUgODEgNzQgYTIgNGEgYTUgOTYgMTQgOWQgNDAgYTcgNGEgNWUgNjkgNmIgZmQgNTkgZjUgM2EgMjQgNTMgOWEgNWUgYTcgYzggMmYgNTMgMTggNTUgZjQgZjYgNjQgNWMgMDMgZWEgYmIgN2UgNDggMTQgNTQgYTQgNzIgMDggMjYgOGQgNDUgM2YgZmMgZjIgMGIgMDggNWUgMmIgZWQgMmEgNWUgNGQgYWUgODEgOTMgY2EgYjggN2MgODIgMzkgYzEgZmMgYzcgZGUgZmEgYTAgMTkgMDIgYmYgZDcgMmEgZWEgMWEgNmYgZGQgYzkgMDQgZWYgM2EgM2UgZmEgMGMgOTcgOGIgNDAgYzAgMDkgNDQgNjAgMjcgZDIgM2YgMDcgNzIgMjUgNDUgNTUgZmIgYTAgMzQgZDAgOWYgNGMgMzIgNzggNmMgYzggNTEgMDAgY2EgNTEgNTYgOTkgOGEgYjAgNDkgNzUgZGEgMDIgYWUgMWYgYTIgZjIgYTEgMzAgZDYgNTIgYTMgZWQgOGQgNTIgN2YgMWMgNTUgMWYgZmMgYzkgNTQgMGMgN2MgM2EgYjQgYjcgYmEgMjQgODEgMjkgOTggNjggYWQgMmEgYWEgYzkgYzEgNGUgNTQgM2EgOTAgM2EgNTIgODIgNzcgODUgM2UgNWEgNTkgNjUgNDkgMDcgYTcgY2UgYWQgNGUgZWEgYzEgYjggMGEgMDcgZDQgMmEgNTEgZDkgM2EgMDMgN2MgOTEgYjkgMWIgNTUgNjcgOWEgMzYgMjkgNDcgMjQgZWUgNjcgNzMgODUgNmUgYjQgNzEgMzEgZGQgZWMgYjYgM2QgMzMgM2UgYzUgYTYgMDQgZTMgOGQgMGYgNzAgMDQgMDEgYmEgZmMgNWUgYzIgZjIgNjYgMDggMDAgNDYgYTEgMzQgOTEgNWQgMDcgN2QgMDMgMzAgNzUgODMgNGQgYTYgMDcgYTAgNjUgZmIgMWEgOTggNGMgZDkgMGEgNjQgNjggY2UgOTQgNDIgODkgZjMgMDkgMjQgZGEgMWMgNTYgYjggYTggYjEgYzIgMDMgNjMgMDAgMTkgYWYgZjggNjEgMzIgMzAgNWUgMWQgYTIgYTcgNjggMGYgNTYgMjMgYTggMGYgNjAgMGYgNGEgYmQgMjkgZmUgMGMgZGEgZDkgMDEgOGQgMjAgMjAgYjQgMzkgZTUgMjAgYTcgNGUgOGYgMTcgNWMgYTUgYWYgZTggODggMTggODMgOTkgNjYgYWQgNmEgMjMgMDggYzMgNDkgOWUgODIgZWUgNGQgNTUgZjAgMGEgMzAgNzIgMjIgZWIgN2IgOGUgNzMgMTYgYzkgOGYgY2UgN2MgNTQgNzEgOGMgODkgM2EgYTUgYWIgY2UgMzggMTMgNTMgNTYgMDcgNzAgMmUgYjQgODggNzMgNjQgMTggN2YgNzEgMTUgZWMgY2YgOWYgZmUgMzUgNDkgZWUgZjMgYTcgN2YgMjMgZTAgZmMgYzIgNDIgNjUgNzggOWEgZDkgZWUgMGYgNmYgNjUgYzUgMTUgNjEgNjIgMmMgYWIgMmEgMTkgNmQgZDcgMGEgYWUgYzEgNmIgMzUgOTkgNDIgMjQgMTEgZTIgZDEgMGYgZDggZTIgNTQgZTUgY2YgY2UgN2EgNWQgMTUgYjAgN2UgODYgYzggNDkgZGUgMDggZjYgYjMgMGYgMGYgMGEgMzIgNjYgYzEgZmEgMjEgYTkgN2EgMDggMGMgMTAgNWMgNDEgMzYgNWEgYjIgNGMgYmUgNDkgNWEgNGQgYTQgMTUgOTEgYzIgNDkgODIgZjAgZjIgOGEgMzEgOTggNDMgMTggNzQgYzcgODEgODUgYWEgZjQgMDQgZTUgMTIgYTMgMTcgMDIgYTcgYTEgMjQgZWMgNTcgYjQgMmUgMzIgMTQgOTMgMzIgMWEgNjAgOGIgZmEgMjQgY2YgMmMgM2IgMTMgMWYgMzIgYmIgYjMgMTMgMDAgMDAgNGYgNTAgM2UgMTMgMDIgNWYgMDcgZGYgZjEgOWIgNjIgOGUgYTMgYTMgMjQgYWUgN2MgY2IgNjYgM2MgYWEgYWMgZTkgYzAgMDIgZjYgODYgNGIgOGEgN2YgMDcgYzAgYmYgZTUgNzEgODggMDMgNmIgYWQgZDAgNjcgMWQgMmEgZDUgN2IgMzggMWUgMjEgNDYgNzIgOTMgYzcgMjEgNTAgMDkgYzggMmUgOWUgOTkgOTUgODggMmMgNGYgMWMgMzYgNjAgNGIgOTMgNjYgZjkgMjggNTkgZWMgZTggNjMgOWEgY2EgMDcgOTcgMDUgN2UgMzUgZTcgM2QgZWYgZWMgMDMgNDUgZGUgNWQgMmQgNjEgZmQgM2IgNTcgOTMgMmIgMzAgMDEgY2IgOGQgMjggNTEgYTQgOWEgZmUgNmYgMTggNjYgOWYgNmYgMGEgMTEgZTAgNjMgZTUgZjEgODEgNWYgMDYgYzQgNWUgOWQgODYgNzAgODAgNjggYjYgYzQgNzkgNWQgODQgYzEgMzkgOGUgMjEgNDcgZDYgNzAgOTkgY2EgYWUgZjUgNTIgNmEgMjEgMTcgNTMgZDcgZjAgMWEgODAgZTAgMDMgYjIgMzcgYWEgYTMgOGUgZDAgYWUgMTcgMmYgMGQgY2IgMDUgMTQgZGYgMTQgM2YgMjMgNTYgZGQgMDAgNjggYmEgZmEgYzAgN2YgODQgN2YgZjkgOTYgZWIgYWUgNjkgMWEgYjAgNzggNGQgMmMgMzQgYzcgNWYgYjkgMmEgNjYgZWUgNmYgMGEgMjEgNjUgZDYgMzEgY2IgN2MgMGEgMTEgOTcgODMgMmIgYzkgYmYgNTAgMzMgNjggMjQgM2MgYmUgOTMgN2QgNWMgMjMgZDYgMDUgNWUgMmEgZGYgNzMgMjQgYTUgMTEgNzAgYWQgMWMgNTEgMTcgYmYgYTggNjEgMTEgNTAgMGMgZjcgYWUgNzcgZjkgYzcgNTIgYmQgZGUgMDMgYTcgM2YgN2UgYTAgNTIgOGEgYmUgOTEgZGUgZDEgZTkgODcgMWMgZWMgY2UgYzMgYmYgMDkgZjIgMjUgOWUgYWYgMjEgZTMgODEgN2IgNDkgMWEgZmEgNzUgYzYgOTIgNDggNzcgYmMgZjcgYTggNTMgYjIgOGMgNTYgMWEgODAgZWEgNTEgYWYgZTAgMDcgNzcgMTYgYzQgYzYgM2IgY2EgYjYgNDAgNTYgMjEgZGIgNzQgM2UgNzQgOGUgNTYgNGUgODUgNjUgNTMgMjYgNDYgNTcgNTUgYWUgOGMgZmUgYzggNjEgZTQgODAgZmIgOTMgYjQgOTMgODIgYmQgMjIgMzkgZWIgODIgMDIgZjIgN2YgZGYgMDIgODkgYTAgNDMgMjAgNTkgZjAgYzAgODUgZjQgYzUgOWMgMjEgZjYgOTkgZTAgOGEgZmEgZDQgNGEgYWUgODYgYzkgYzggMTkgMzUgMTQgN2QgNDQgYjUgZTggMGIgNTIgMTkgMGMgZDMgOGYgNzggOTggNWEgOTIgOTMgNWIgMjkgNjUgMTcgMmUgZGEgYWYgNzkgZmIgNzUgNzkgNDcgM2QgNzIgOGYgMzcgZjAgOTIgNGIgOTggYjEgODUgMGQgY2MgZWUgY2UgNTAgYjUgOGQgYmUgZTggMDggZDkgOTcgMGIgOWEgNTYgNGYgMjYgOWUgOTYgYTMgZjQgZDIgMDUgMjQgNDMgOWUgODIgOTAgYTQgZWQgOWMgY2EgYjAgODIgMjQgNDEgMzcgYWUgZDEgMGYgM2EgZjYgNjcgYTIgMjggNDMgZDIgZWEgZjcgYjcgYjcgNWYgYjUgZjkgZmMgNzYgNWUgZjQgMzggZDggMmMgODQgMmEgZjggN2UgODMgM2QgNTMgZDAgYTcgNjMgMzkgM2MgZGYgYjYgNTAgNWYgM2QgODAgYWEgZWYgYTYgODQgYzggZDEgYzIgMDggNjUgNTkgZmIgYWQgM2YgMTcgZGQgODAgZTggNTAgOGQgNDAgYTEgOWMgYTAgM2QgNDQgNTQgMTMgOWQgNDQgNmQgNTMgMzEgOTAgMmQgOTkgMzIgM2UgMmUgODMgMDQgNDEgOWMgNmIgMTEgMzUgZGIgNTYgMDggY2UgYTUgYzEgZTcgODUgNTcgYjQgNmEgMzcgYTIgYjQgYTIgZDUgMDggZjUgNjcgY2QgNGQgNmIgMmUgZjYgMjAgMjYgOGMgNTIgYmEgOGYgNzggMmMgMDQgZmEgNjYgY2EgMDcgMjUgOTUgODQgOWEgZjEgY2IgNzQgOTkgZTYgYTQgOGQgYWYgMzcgMmMgOTIgY2QgNWMgNWUgOTEgNDAgZDMgMjcgNTYgZjQgYTMgY2EgYmIgYTQgZDQgM2YgMzggNmIgNTggZjAgM2MgMTggZjAgOTAgYjYgZDQgM2MgODYgMDcgMDcgOGUgNzIgYjggNmMgZTcgYWUgMzAgOWIgODAgYzMgYWYgMTMgYjMgYzIgMWEgZDUgNDUgZTMgN2QgMDUgMzggYTQgOTcgMmQgN2EgOTkgZTUgMjQgNjYgYTYgZTMgZTEgM2EgMTcgNTEgZDAgZGIgZTUgYjIgYzggYTUgZTAgYjIgYjAgNjggNzUgZjkgOTAgYTcgNDAgYTkgYTggMzggMDQgODMgNjQgMjIgYWUgMTUgZTQgZmIgY2MgZTggZGMgYWEgZmYgNWIgZTkgMmQgNWEgZjggODMgMzkgNjEgOWQgYzMgZGEgNDEgNWEgNDIgZjggNzIgMzYgYjcgMjMgODIgODEgNWMgNDIgYWUgODAgMWMgYTkgNjYgMzEgZjIgYzQgODUgMjYgZDYgZDEgNjUgZGUgMDQgZWYgZGUgMzUgNTcgMDMgMjEgMGMgY2IgZTQgNjIgYTUgN2MgMzAgOGEgMzcgZWYgOTQgYWUgNTMgODYgMzQgN2UgZmUgZjQgMmIgNGMgNWIgYWEgZDMgMjIgY2QgOWYgYjggN2YgODEgZGYgMzAgZjIgM2MgOWQgMDkgZTIgZDEgYTggYzQgZmMgYjcgNzAgOWEgYzcgYmQgY2EgM2IgOTggYzAgMjQgODQgNzkgMTAgYTggYjAgOTIgZjEgYTAgZjIgNzcgOTggYTcgZDAgZTcgNGMgYzIgNjcgZGUgMmMgNTIgOTUgMGMgYWEgMDcgMzcgOGQgZDggNTIgNjAgZjggMWMgY2UgNWUgZTMgNGUgYWMgYmUgZWEgMDUgODIgYzQgZTcgMTYgM2MgNDMgNGEgZDUgMTQgYTEgNjUgOTUgNDkgNjUgODMgMWYgOTIgNjUgNjcgNGMgNWYgYjkgZDMgZTQgYTEgYjMgZDQgNDMgMjQgZjggOGIgZjQgYWQgMzQgZGYgMmQgYjAgYjkgMDAgYTEgNmMgNWQgOGEgZmEgMzIgY2EgNWYgYTUgZTIgYTQgY2MgYWIgZjkgN2IgNzUgNzggYjUgM2MgMmMgZWEgOWIgY2EgMzMgMWEgMzEgYmEgMTkgNjcgZDYgOTQgYjMgNjcgZWUgNzAgMzIgNGYgYTggZTAgMzEgNTggNTggMDYgOTMgNDcgOWEgNGEgYmEgYzYgNTQgMWQgMzcgMjcgOGYgYzEgMzQgMTYgOTggZDAgMDYgOTYgMmUgZmYgYzMgNDMgMWIgNzEgM2EgZTMgMzQgY2MgNWYgZTggN2UgYTYgY2MgM2EgY2EgYzcgYTAgZjAgM2IgYjQgMmMgZTQgMTUgZGYgZGIgNzAgYTIgNjYgY2IgNjggNWUgN2UgYzAgNTggOWQgMzggNmYgYTcgZTIgYzYgOWYgMTQgMmEgMzMgNzcgNGEgNzIgMzkgNGIgZjEgNGYgYzggMzcgMDggNDcgMzIgMDUgZTQgMGIgY2MgZDUgMmMgMzYgMGYgM2UgOWUgZjkgMDQgMzAgYmUgNGEgMjkgMzEgY2IgMDMgYTQgMDAgOTkgMjMgYWMgMmQgZjggOGUgMzIgODIgZTUgZDkgODQgZmIgYzAgMTkgZWIgN2UgYWQgMjYgYjAgZWIgODIgMGIgNDMgZDMgNjYgMzEgYjYgM2MgOGUgODUgMzkgZDYgYjkgOWEgNTggZTkgN2IgMTIgZjIgYzkgMDAgZGYgMDEgOGQgZTMgMDMgZDcgMzIgOTYgMTUgYTUgYzUgZWQgOTAgNzkgOGMgMzkgN2QgMjYgYjEgNTkgN2QgOTQgMTcgMTUgOGYgZTAgYWEgYjYgZGUgNWYgNWEgNzEgYmUgZWYgMzkgN2QgY2EgMzcgM2YgZmMgMWUgZWMgZmMgNTMgMmUgYTUgODcgOWQgOWUgNmYgOWUgYWIgYzMgNWYgOTEgMmQgYmIgYWQgM2UgZWMgYjYgZjggZjAgM2YgNTYgNGQgZWMgNmMgNzEgODMgZTUgZWIgZTMgN2UgODUgZjkgOWYgZDMgYjAgNTQgZDMgM2QgZjIgNzIgYTEgZmMgOWEgYTUgMGYgNzEgZDMgOGYgNjAgYzUgMmQgYjYgZGUgY2EgYjMgNjggZmYgYTUgZjcgNTYgZmQgY2QgNTQgYjggZmYgZTQgYjcgNWYgMzEgZDcgYTYgZDQgYzcgMTcgZGIgZWQgNzQgMjUgMDYgMzkgOTcgMWIgZmIgNjIgM2UgNzggOWUgMzkgMjIgODcgZjQgMmYgYjIgMGUgYzYgYTcgNzcgNWYgOWEgZGYgNmQgNjcgYTYgNzYgZGIgODkgYmYgZGQgMzYgZGYgYTEgMjEgN2IgZjk"C:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
67.0.4
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
3736"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\download.datC:\Windows\system32\rundll32.exe—firefox.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3740"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\download.zip"C:\Program Files\WinRAR\WinRAR.exe—firefox.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3964"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3656.13.1025395500\313059851" -childID 2 -isForBrowser -prefsHandle 2708 -prefMapHandle 2712 -prefsLen 5842 -prefMapSize 188076 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3656 "\\.\pipe\gecko-crash-server-pipe.3656" 2736 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
67.0.4
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
Total events
1 487
Read events
1 440
Write events
47
Delete events
0

Modification events

(PID) Process:(3656) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
0000000000000000
(PID) Process:(3656) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3656) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000077000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3656) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3656) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3656) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids
Operation:writeName:WinRAR.ZIP
Value:
(PID) Process:(3740) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\download.zip
Executable files
2
Suspicious files
78
Text files
42
Unknown types
57

Dropped files

PID
Process
Filename
Type
3656firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin —
MD5:—
SHA256:—
3656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm —
MD5:—
SHA256:—
3656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.tmp —
MD5:—
SHA256:—
3656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js —
MD5:—
SHA256:—
3656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp —
MD5:—
SHA256:—
3656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm —
MD5:—
SHA256:—
3656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm —
MD5:—
SHA256:—
3656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm —
MD5:—
SHA256:—
3656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp —
MD5:—
SHA256:—
3656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal —
MD5:—
SHA256:—
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
40
DNS requests
80
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3656
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3656
firefox.exe
POST
200
172.217.18.3:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3656
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3656
firefox.exe
POST
200
172.217.18.3:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3656
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3656
firefox.exe
POST
200
172.217.18.3:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3656
firefox.exe
POST
200
172.217.18.3:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3656
firefox.exe
POST
200
216.58.207.67:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3656
firefox.exe
GET
200
2.16.186.112:80
http://detectportal.firefox.com/success.txt
unknown
text
8 b
whitelisted
3656
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3656
firefox.exe
2.16.186.112:80
detectportal.firefox.com
Akamai International B.V.
—
whitelisted
3656
firefox.exe
216.58.205.238:443
www.google-analytics.com
Google Inc.
US
whitelisted
3656
firefox.exe
172.217.16.138:443
safebrowsing.googleapis.com
Google Inc.
US
whitelisted
3656
firefox.exe
64.233.184.157:443
stats.g.doubleclick.net
Google Inc.
US
whitelisted
3656
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3656
firefox.exe
52.26.103.165:443
tiles.services.mozilla.com
Amazon.com, Inc.
US
unknown
3656
firefox.exe
172.217.18.3:80
ocsp.pki.goog
Google Inc.
US
whitelisted
3656
firefox.exe
216.58.207.46:443
redirector.gvt1.com
Google Inc.
US
whitelisted
3656
firefox.exe
54.201.35.95:443
shavar.services.mozilla.com
Amazon.com, Inc.
US
unknown
3656
firefox.exe
52.85.183.17:443
aus5.mozilla.org
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 2.16.186.112
  • 2.16.186.50
  • 23.212.109.139
  • 23.212.109.152
whitelisted
a1089.dscd.akamai.net
  • 2.16.186.50
  • 2.16.186.112
  • 23.212.109.152
  • 23.212.109.139
whitelisted
location.services.mozilla.com
  • 52.210.139.31
  • 108.128.247.43
  • 52.50.56.62
whitelisted
locprod1-elb-eu-west-1.prod.mozaws.net
  • 52.50.56.62
  • 108.128.247.43
  • 52.210.139.31
whitelisted
gchq.github.io
  • 185.199.111.153
  • 185.199.110.153
  • 185.199.108.153
  • 185.199.109.153
suspicious
push.services.mozilla.com
  • 52.41.251.72
whitelisted
autopush.prod.mozaws.net
  • 52.41.251.72
whitelisted
snippets.cdn.mozilla.net
  • 54.192.202.51
whitelisted
tiles.services.mozilla.com
  • 52.26.103.165
  • 52.27.87.181
  • 52.26.166.58
  • 35.166.166.56
  • 52.35.96.157
  • 52.34.132.219
  • 52.25.71.236
  • 52.42.232.148
whitelisted
tiles.r53-2.services.mozilla.com
  • 52.42.232.148
  • 52.25.71.236
  • 52.34.132.219
  • 52.35.96.157
  • 35.166.166.56
  • 52.26.166.58
  • 52.27.87.181
  • 52.26.103.165
whitelisted

Threats

No threats detected
Process
Message
firefox.exe
Too long ^
firefox.exe
Too long restart command line passed
firefox.exe