File name:

zen.installer.exe

Full analysis: https://app.any.run/tasks/cb77b99a-0c12-43db-8794-7e34601cd871
Verdict: Malicious activity
Analysis date: August 26, 2024, 16:47:58
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

354E232749D124F20D9CA02B5858F96C

SHA1:

A9452107C186C697B0AABF3D985B72957064BB8C

SHA256:

B2FCD676174A7020B8CE221D666EE890B1262D2E3BE3D3BD7278B69BD9C8EC55

SSDEEP:

786432:XVSmTO1ry3cEr5Kx5aQNSUqWkPucvicpGynPv:FS4gs10xQQNSUqW2uc6cpGMv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.exe (PID: 6424)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • zen.installer.exe (PID: 6752)
      • setup.exe (PID: 6424)
    • Drops the executable file immediately after the start

      • setup.exe (PID: 6888)
      • setup.exe (PID: 6424)
      • zen.installer.exe (PID: 6752)
      • zen.exe (PID: 2384)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 6888)
      • setup.exe (PID: 6424)
    • The process drops C-runtime libraries

      • zen.installer.exe (PID: 6752)
      • setup.exe (PID: 6424)
    • Reads the date of Windows installation

      • setup.exe (PID: 6888)
    • Application launched itself

      • setup.exe (PID: 6888)
      • zen.exe (PID: 2180)
      • zen.exe (PID: 3540)
      • zen.exe (PID: 2384)
    • Executable content was dropped or overwritten

      • zen.installer.exe (PID: 6752)
      • setup.exe (PID: 6424)
      • setup.exe (PID: 6888)
      • zen.exe (PID: 2384)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • setup.exe (PID: 6888)
      • setup.exe (PID: 6424)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 6888)
      • setup.exe (PID: 6424)
      • zen.exe (PID: 2384)
    • Creates a software uninstall entry

      • setup.exe (PID: 6424)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 5908)
    • Searches for installed software

      • setup.exe (PID: 6424)
    • Loads DLL from Mozilla Firefox

      • default-browser-agent.exe (PID: 2628)
    • The process executes via Task Scheduler

      • default-browser-agent.exe (PID: 2628)
  • INFO

    • Create files in a temporary directory

      • setup.exe (PID: 6888)
      • setup.exe (PID: 6424)
      • zen.installer.exe (PID: 6752)
      • zen.exe (PID: 5104)
      • zen.exe (PID: 2384)
    • Reads the computer name

      • zen.installer.exe (PID: 6752)
      • setup.exe (PID: 6888)
      • setup.exe (PID: 6424)
      • zen.exe (PID: 5104)
      • zen.exe (PID: 2384)
      • zen.exe (PID: 4080)
      • zen.exe (PID: 2724)
      • zen.exe (PID: 6968)
      • zen.exe (PID: 5544)
      • zen.exe (PID: 7036)
      • zen.exe (PID: 940)
      • zen.exe (PID: 6192)
      • zen.exe (PID: 2040)
      • zen.exe (PID: 4540)
      • zen.exe (PID: 5344)
      • zen.exe (PID: 6648)
      • zen.exe (PID: 2056)
    • Process checks computer location settings

      • setup.exe (PID: 6888)
      • zen.exe (PID: 2384)
    • Checks supported languages

      • zen.installer.exe (PID: 6752)
      • setup.exe (PID: 6888)
      • setup.exe (PID: 6424)
      • zen.exe (PID: 5104)
      • zen.exe (PID: 2180)
      • zen.exe (PID: 2384)
      • zen.exe (PID: 3540)
      • zen.exe (PID: 2724)
      • zen.exe (PID: 4080)
      • zen.exe (PID: 6968)
      • zen.exe (PID: 5544)
      • zen.exe (PID: 7036)
      • zen.exe (PID: 940)
      • zen.exe (PID: 2056)
      • zen.exe (PID: 6192)
      • zen.exe (PID: 2040)
      • zen.exe (PID: 4540)
      • zen.exe (PID: 5344)
      • zen.exe (PID: 6648)
      • default-browser-agent.exe (PID: 2628)
    • Process checks whether UAC notifications are on

      • setup.exe (PID: 6888)
      • zen.exe (PID: 5104)
    • Creates files in the program directory

      • setup.exe (PID: 6424)
      • zen.exe (PID: 2384)
      • zen.exe (PID: 5104)
    • UPX packer has been detected

      • zen.installer.exe (PID: 6752)
    • Reads CPU info

      • zen.exe (PID: 5104)
      • zen.exe (PID: 2384)
      • zen.exe (PID: 4540)
    • Creates files or folders in the user directory

      • zen.exe (PID: 2384)
    • Reads Microsoft Office registry keys

      • setup.exe (PID: 6424)
      • zen.exe (PID: 2384)
    • Checks proxy server information

      • setup.exe (PID: 6424)
      • zen.exe (PID: 2384)
    • Reads the machine GUID from the registry

      • zen.exe (PID: 2384)
    • Application launched itself

      • firefox.exe (PID: 2080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (64.2)
.dll | Win32 Dynamic Link Library (generic) (15.6)
.exe | Win32 Executable (generic) (10.6)
.exe | Generic Win/DOS Executable (4.7)
.exe | DOS Executable Generic (4.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:08:30 22:18:33+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 69632
InitializedDataSize: 65536
UninitializedDataSize: 147456
EntryPoint: 0x34fa0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 18.5.0.0
ProductVersionNumber: 18.5.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Mozilla
FileDescription: Firefox
FileVersion: 18.05
InternalName: 7zS.sfx
LegalCopyright: Mozilla
OriginalFileName: 7zS.sfx.exe
ProductName: Firefox
ProductVersion: 18.05
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
23
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT zen.installer.exe setup.exe setup.exe regsvr32.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs zen.exe no specs default-browser-agent.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
940"C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=3592 -childID 3 -isForBrowser -prefsHandle 3512 -prefMapHandle 3444 -prefsLen 23528 -prefMapSize 258448 -jsInitHandle 1324 -jsInitLen 234852 -parentBuildID 20240826123120 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {8c587c7c-186c-4510-8b5a-737f3033749d} 2384 tabC:\Program Files\Zen Browser\zen.exezen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Zen Browser
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
1496"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent do-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
3
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2040"C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=4940 -childID 6 -isForBrowser -prefsHandle 4936 -prefMapHandle 4928 -prefsLen 29330 -prefMapSize 258448 -jsInitHandle 1324 -jsInitLen 234852 -parentBuildID 20240826123120 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {cce84127-6abb-4a8c-8f01-1c3fb88b6d61} 2384 tabC:\Program Files\Zen Browser\zen.exezen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Zen Browser
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
2056"C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=3368 -childID 4 -isForBrowser -prefsHandle 2500 -prefMapHandle 3228 -prefsLen 24379 -prefMapSize 258448 -jsInitHandle 1324 -jsInitLen 234852 -parentBuildID 20240826123120 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {7510c8a0-3ecf-4325-881d-2c178dc56d89} 2384 tabC:\Program Files\Zen Browser\zen.exezen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Zen Browser
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
2080"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent do-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exedefault-browser-agent.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
3
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
2180"C:\Program Files\Zen Browser\zen.exe" --backgroundtask installC:\Program Files\Zen Browser\zen.exesetup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Zen Browser
Exit code:
0
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\program files\zen browser\vcruntime140.dll
c:\program files\zen browser\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
2384"C:\Program Files\Zen Browser\zen.exe" -first-startupC:\Program Files\Zen Browser\zen.exe
zen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Zen Browser
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
2628"C:\Program Files\Mozilla Firefox\default-browser-agent.exe" do-task "308046B0AF4A39CB"C:\Program Files\Mozilla Firefox\default-browser-agent.exesvchost.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
MEDIUM
Exit code:
2147500037
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\default-browser-agent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ole32.dll
2724"C:\Program Files\Zen Browser\zen.exe" -contentproc --channel=2296 -parentBuildID 20240826123120 -prefsHandle 2288 -prefMapHandle 2276 -prefsLen 22121 -prefMapSize 258448 -win32kLockedDown -appDir "C:\Program Files\Zen Browser\browser" - {f8e6b1c9-4318-4766-b8b8-5985d04b937e} 2384 socketC:\Program Files\Zen Browser\zen.exezen.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Zen Browser
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
3540"C:\Program Files\Zen Browser\zen.exe" -first-startupC:\Program Files\Zen Browser\zen.exesetup.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Zen Browser
Exit code:
0
Version:
129.0.2
Modules
Images
c:\program files\zen browser\zen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\zen browser\mozglue.dll
c:\program files\zen browser\vcruntime140_1.dll
c:\program files\zen browser\msvcp140.dll
c:\program files\zen browser\vcruntime140.dll
Total events
28 400
Read events
28 248
Write events
136
Delete events
16

Modification events

(PID) Process:(6424) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6424) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6424) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6424) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6424) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\TaskBarIDs
Operation:writeName:C:\Program Files\Zen Browser
Value:
F0DC299D809B9700
(PID) Process:(6424) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RuntimeExceptionHelperModules
Operation:writeName:C:\Program Files\Zen Browser\mozwer.dll
Value:
0
(PID) Process:(5908) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1814CEEB-49E2-407F-AF99-FA755A7D2607}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(6424) setup.exeKey:HKEY_CLASSES_ROOT\FirefoxPDF-F0DC299D809B9700
Operation:writeName:FriendlyTypeName
Value:
Firefox PDF Document
(PID) Process:(6424) setup.exeKey:HKEY_CLASSES_ROOT\FirefoxPDF-F0DC299D809B9700
Operation:delete valueName:EditFlags
Value:
(PID) Process:(6424) setup.exeKey:HKEY_CLASSES_ROOT\FirefoxPDF-F0DC299D809B9700
Operation:writeName:EditFlags
Value:
2
Executable files
73
Suspicious files
1 113
Text files
320
Unknown types
78

Dropped files

PID
Process
Filename
Type
6752zen.installer.exeC:\Users\admin\AppData\Local\Temp\7zS06AB9492\core\browser\omni.ja
MD5:
SHA256:
6752zen.installer.exeC:\Users\admin\AppData\Local\Temp\7zS06AB9492\core\application.initext
MD5:BE1DD0C7B2CC2CA13730CBC84EB2B543
SHA256:BDC7CB8166622881E8204DC1AB53A8427EA64D5E2BA96108DDDF5DFA70DC6BC6
6752zen.installer.exeC:\Users\admin\AppData\Local\Temp\7zS06AB9492\core\browser\VisualElements\VisualElements_150.pngimage
MD5:273A7837B378DFFC994757FABCBE3338
SHA256:74B1EB2B2127DD1261AACB7FB922CDB0D8987495B85F2BBC5830370D1E54A4CE
6752zen.installer.exeC:\Users\admin\AppData\Local\Temp\7zS06AB9492\core\browser\VisualElements\PrivateBrowsing_70.pngimage
MD5:5B67016CE82086FE7D1C2D09F6C91FDD
SHA256:ED243D6267AC035C8501D9959F5D6CB74DD3CC2A8B779020AEB1734DD653C6EE
6752zen.installer.exeC:\Users\admin\AppData\Local\Temp\7zS06AB9492\core\freebl3.dllexecutable
MD5:5A6E10A9DD60443AAD0ACEDB27270F21
SHA256:4611A4D0BF87251BBE74939DDDB2FCDCF9C39AB58D41DD6D557B177723988712
6752zen.installer.exeC:\Users\admin\AppData\Local\Temp\7zS06AB9492\core\gmp-clearkey\0.1\manifest.jsonbinary
MD5:CFFDADFAEEAAF0A5A78E7F9A299AA7F1
SHA256:EF47E83036753B53F59D079FEF62BFEDC749ABDBCDB0FE16F448D9920F11114C
6752zen.installer.exeC:\Users\admin\AppData\Local\Temp\7zS06AB9492\core\gmp-clearkey\0.1\clearkey.dllexecutable
MD5:8ED33842701CAE286FE3208D32535B8C
SHA256:C0AE0B9ACEAB639BA06CD1B070EC88438776EA6202E3B7EACE363D64C13CE5BF
6752zen.installer.exeC:\Users\admin\AppData\Local\Temp\7zS06AB9492\core\dependentlibs.listtext
MD5:A515BC619743C790D426780ED4810105
SHA256:612E53338B53449BE39F2E9086E15EDC7BB3E7AA56C9D65A9D53B9EB3C3CC77D
6752zen.installer.exeC:\Users\admin\AppData\Local\Temp\7zS06AB9492\core\gkcodecs.dllexecutable
MD5:8D35468C91D0C512D826FE60712540A0
SHA256:E655BF9A67019B052D604DB89DD3EC1F78F8B1BBF92F32FE078B3CF1F7A3CD6C
6752zen.installer.exeC:\Users\admin\AppData\Local\Temp\7zS06AB9492\core\browser\features\formautofill@mozilla.org.xpicompressed
MD5:37C4A8C1A1014307B2EECD9D8B9819DA
SHA256:84589D8ED48BBB54806363A81CA9485AAEEB5E426FAC634FA2AA02EFE930F8EC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
276
TCP/UDP connections
119
DNS requests
76
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
101
34.107.243.93:443
https://push.services.mozilla.com/
unknown
GET
200
34.149.100.209:443
https://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?collection=fingerprinting-protection-overrides&bucket=main&_expected=0
unknown
binary
261 b
GET
301
142.250.185.129:443
https://s2.googleusercontent.com/s2/favicons?domain_url=https://www.wikipedia.org/
unknown
html
339 b
GET
200
34.149.100.209:443
https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/fingerprinting-protection-overrides/changeset?_expected=1715008862535
unknown
binary
32.1 Kb
GET
301
142.250.185.129:443
https://s2.googleusercontent.com/s2/favicons?domain_url=https://translate.google.com/
unknown
html
342 b
GET
200
35.190.72.216:443
https://location.services.mozilla.com/v1/country?key=no-mozilla-api-key
unknown
binary
47 b
GET
301
142.250.185.129:443
https://s2.googleusercontent.com/s2/favicons?domain_url=https://m.twitter.com/
unknown
html
335 b
GET
308
76.76.21.22:443
https://zen-browser.app/welcome/
unknown
html
150 b
GET
200
34.149.100.209:443
https://firefox.settings.services.mozilla.com/v1/
unknown
binary
939 b
GET
301
142.250.185.129:443
https://s2.googleusercontent.com/s2/favicons?domain_url=https://todoist.com/
unknown
html
333 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
2384
zen.exe
35.190.72.216:443
location.services.mozilla.com
GOOGLE
US
whitelisted
2384
zen.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
whitelisted
2384
zen.exe
142.250.185.129:443
s2.googleusercontent.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.110
whitelisted
location.services.mozilla.com
  • 35.190.72.216
whitelisted
prod.classify-client.prod.webservices.mozgcp.net
  • 35.190.72.216
unknown
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted
prod.remote-settings.prod.webservices.mozgcp.net
  • 34.149.100.209
whitelisted
s2.googleusercontent.com
  • 142.250.185.129
whitelisted
googlehosted.l.googleusercontent.com
  • 142.250.185.129
  • 2a00:1450:4001:810::2001
whitelisted
zen-browser.app
  • 76.76.21.93
  • 76.76.21.241
malicious
shavar.services.mozilla.com
  • 44.226.249.47
  • 44.239.24.213
  • 54.71.162.254
whitelisted

Threats

No threats detected
No debug info