URL:

http://www.kuaizip.com/en/download.html

Full analysis: https://app.any.run/tasks/7f503766-7145-4564-9188-325d5796af5e
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 18, 2025, 09:39:45
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
Indicators:
MD5:

A83F9D136C003B0005E090220D8CADFD

SHA1:

23DC1A941FD13AB4E234A97E9FF6A4AEF8B3A483

SHA256:

B874EF1AAB9F519B641321BF0DBC744B343CAF7F21365A45424DF2E75E130056

SSDEEP:

3:N1KJS4KLKSBKSDQ:Cc4KLKSB5Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • KuaiZip_setup_multi.exe (PID: 8708)
      • KuaiZip_setup_multi.exe (PID: 8756)
      • KuaiZip.exe (PID: 2040)
      • KuaiZip.exe (PID: 8304)
      • KuaiZip.exe (PID: 8316)
      • KZMount.exe (PID: 536)
      • Update.exe (PID: 1228)
      • KZMount.exe (PID: 6028)
      • KuaiZip.exe (PID: 8392)
      • Update.exe (PID: 1812)
    • Registers / Runs the DLL via REGSVR32.EXE

      • KuaiZip_setup_multi.exe (PID: 8756)
  • SUSPICIOUS

    • Potential Corporate Privacy Violation

      • firefox.exe (PID: 2140)
    • The process creates files with name similar to system file names

      • KuaiZip_setup_multi.exe (PID: 8756)
    • Executable content was dropped or overwritten

      • KuaiZip_setup_multi.exe (PID: 8756)
      • KZMount.exe (PID: 6028)
      • KuaiZip.exe (PID: 8392)
    • Drops a system driver (possible attempt to evade defenses)

      • KuaiZip_setup_multi.exe (PID: 8756)
      • KZMount.exe (PID: 6028)
    • There is functionality for taking screenshot (YARA)

      • KuaiZip_setup_multi.exe (PID: 8756)
    • Reads security settings of Internet Explorer

      • KuaiZip_setup_multi.exe (PID: 8756)
      • KuaiZip.exe (PID: 8392)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 4180)
      • regsvr32.exe (PID: 2516)
    • Creates a software uninstall entry

      • KuaiZip_setup_multi.exe (PID: 8756)
    • Creates files in the driver directory

      • KZMount.exe (PID: 6028)
    • Start notepad (likely ransomware note)

      • KuaiZip_setup_multi.exe (PID: 8756)
    • Reads Internet Explorer settings

      • KuaiZip.exe (PID: 8392)
    • Executes application which crashes

      • Desktop.exe (PID: 8740)
    • Application launched itself

      • Desktop.exe (PID: 8432)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 2284)
      • firefox.exe (PID: 2140)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 2140)
    • The sample compiled with chinese language support

      • firefox.exe (PID: 2140)
      • KuaiZip_setup_multi.exe (PID: 8756)
    • Reads the computer name

      • KuaiZip_setup_multi.exe (PID: 8756)
      • KZMount.exe (PID: 6028)
      • KuaiZip.exe (PID: 8392)
      • Update.exe (PID: 1228)
      • Update.exe (PID: 1812)
    • Checks supported languages

      • KuaiZip_setup_multi.exe (PID: 8756)
      • KuaiZip.exe (PID: 2040)
      • KuaiZip.exe (PID: 8304)
      • KuaiZip.exe (PID: 8316)
      • KZMount.exe (PID: 6028)
      • KuaiZip.exe (PID: 8392)
      • KZMount.exe (PID: 536)
      • Update.exe (PID: 1228)
      • Update.exe (PID: 1812)
    • Creates files in the program directory

      • KuaiZip_setup_multi.exe (PID: 8756)
    • The sample compiled with english language support

      • KuaiZip_setup_multi.exe (PID: 8756)
      • KZMount.exe (PID: 6028)
    • Creates files or folders in the user directory

      • KuaiZip_setup_multi.exe (PID: 8756)
    • Process checks computer location settings

      • KuaiZip_setup_multi.exe (PID: 8756)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 1764)
    • Reads the software policy settings

      • slui.exe (PID: 8368)
    • Manual execution by a user

      • Desktop.exe (PID: 8740)
      • Desktop.exe (PID: 8432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
167
Monitored processes
33
Malicious processes
5
Suspicious processes
9

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs sppextcomobj.exe no specs slui.exe kuaizip_setup_multi.exe no specs kuaizip_setup_multi.exe kuaizip.exe no specs regsvr32.exe no specs regsvr32.exe no specs kuaizip.exe no specs regsvr32.exe no specs regsvr32.exe no specs kuaizip.exe no specs kuaizip.exe kzmount.exe kzmount.exe no specs update.exe no specs notepad.exe no specs update.exe no specs slui.exe no specs desktop.exe no specs desktop.exe desktop.exe werfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536"C:\Program Files\KuaiZip\KZMount.exe" -AssocAllC:\Program Files\KuaiZip\KZMount.exeKuaiZip_setup_multi.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\kuaizip\kzmount.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
960C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1228"C:\Program Files\KuaiZip\Update.exe" -install /PS=firefox.exeC:\Program Files\KuaiZip\Update.exeKuaiZip_setup_multi.exe
User:
admin
Company:
Suzhou Shijie Software Co., LTD
Integrity Level:
HIGH
Description:
kuaizip
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\program files\kuaizip\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1764"C:\Windows\System32\notepad.exe" C:\Program Files\KuaiZip\readme.txtC:\Windows\SysWOW64\notepad.exeKuaiZip_setup_multi.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
1812"C:\Program Files\KuaiZip\Update.exe" -KZTips -op:0C:\Program Files\KuaiZip\Update.exeKuaiZip.exe
User:
admin
Company:
Suzhou Shijie Software Co., LTD
Integrity Level:
HIGH
Description:
kuaizip
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\program files\kuaizip\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2040"C:\Program Files\KuaiZip\KuaiZip.exe" -AssociateAllC:\Program Files\KuaiZip\KuaiZip.exeKuaiZip_setup_multi.exe
User:
admin
Integrity Level:
HIGH
Description:
KuaiZip Application
Exit code:
0
Version:
2, 3, 2
Modules
Images
c:\program files\kuaizip\kuaizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2140"C:\Program Files\Mozilla Firefox\firefox.exe" http://www.kuaizip.com/en/download.htmlC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2284"C:\Program Files\Mozilla Firefox\firefox.exe" "http://www.kuaizip.com/en/download.html"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
2516 "C:\Program Files\KuaiZip\KZipShell.dll" -sC:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4180 "C:\Program Files\KuaiZip\KZipShell.dll" -sC:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
20 871
Read events
20 483
Write events
84
Delete events
304

Modification events

(PID) Process:(2140) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(2140) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(8756) KuaiZip_setup_multi.exeKey:HKEY_CURRENT_USER\SOFTWARE\KuaiZipSFX\KuaiZip
Operation:writeName:path
Value:
C:\Program Files\KuaiZip\
(PID) Process:(8756) KuaiZip_setup_multi.exeKey:HKEY_CURRENT_USER\SOFTWARE\KuaiZipSFX\KuaiZip
Operation:writeName:version
Value:
2.3.2
(PID) Process:(2040) KuaiZip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kz
Operation:delete valueName:Progid
Value:
(PID) Process:(2040) KuaiZip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kz\UserChoice
Operation:delete valueName:Progid
Value:
(PID) Process:(2040) KuaiZip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip
Operation:delete valueName:Progid
Value:
(PID) Process:(2040) KuaiZip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\UserChoice
Operation:delete valueName:Progid
Value:
(PID) Process:(2040) KuaiZip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cab
Operation:delete valueName:Progid
Value:
(PID) Process:(2040) KuaiZip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cab\UserChoice
Operation:delete valueName:Progid
Value:
Executable files
19
Suspicious files
189
Text files
37
Unknown types
0

Dropped files

PID
Process
Filename
Type
2140firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
2140firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:2C99A16AED3906D92FFE3EF1808E2753
SHA256:08412578CC3BB4922388F8FF8C23962F616B69A1588DA720ADE429129C73C452
2140firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.binbinary
MD5:C95DDC2B1A525D1A243E4C294DA2F326
SHA256:3A5919E086BFB31E36110CF636D2D5109EB51F2C410B107F126126AB25D67363
2140firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:2C99A16AED3906D92FFE3EF1808E2753
SHA256:08412578CC3BB4922388F8FF8C23962F616B69A1588DA720ADE429129C73C452
2140firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
2140firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
2140firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
2140firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2140firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:56D853DF7F955D4685B00E15F1E953CE
SHA256:2C5D8C1471FDED7C16F3CB2CCCC6B2838765107B87ECF48682A180C472F20590
2140firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
71
TCP/UDP connections
111
DNS requests
113
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.30:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2140
firefox.exe
GET
200
122.188.45.182:80
http://www.kuaizip.com/en/stylesheets/kzcss.css
unknown
malicious
2140
firefox.exe
GET
200
122.188.45.182:80
http://www.kuaizip.com/en/images/kzjj.png
unknown
malicious
2140
firefox.exe
GET
200
122.188.45.182:80
http://www.kuaizip.com/en/images/copyright.png
unknown
malicious
2140
firefox.exe
GET
200
122.188.45.182:80
http://www.kuaizip.com/en/images/page_bg.png
unknown
malicious
2140
firefox.exe
GET
200
122.188.45.182:80
http://www.kuaizip.com/en/images/download.png
unknown
malicious
2140
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2140
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
2140
firefox.exe
POST
200
184.24.77.56:80
http://r11.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.30:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
2140
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
2140
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
2140
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
whitelisted
2140
firefox.exe
142.250.185.106:443
safebrowsing.googleapis.com
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.216.77.30
  • 23.216.77.21
  • 23.216.77.22
  • 23.216.77.41
  • 23.216.77.38
  • 23.216.77.35
  • 23.216.77.31
  • 23.216.77.26
  • 23.216.77.37
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
google.com
  • 142.250.185.206
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
www.kuaizip.com
  • 122.188.45.182
  • 59.83.212.226
  • 122.188.44.51
  • 122.188.45.51
  • 122.188.45.140
  • 116.196.150.249
  • 116.153.3.100
  • 119.188.174.59
  • 122.188.44.139
  • 101.72.254.91
  • 60.221.17.73
  • 119.188.174.58
malicious
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 23.215.0.133
  • 96.7.128.192
  • 23.215.0.132
  • 96.7.128.186
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted

Threats

PID
Process
Class
Message
2140
firefox.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
No debug info