URL:

https://download.winzipdriverupdater.com/wzdu/wzdu53.exe

Full analysis: https://app.any.run/tasks/00f1cf63-f6f3-409c-95de-1ac57519415d
Verdict: Malicious activity
Analysis date: October 16, 2020, 14:11:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

BF473CF071815FC11E756832BDAB3D59

SHA1:

A36DC92359BC32D74BF0016AB5506177D966589B

SHA256:

BD5C1FD231394B0F1D8ED7B88CFA5E0D6F8A705B8F73906CE4104B93603B9CF8

SSDEEP:

3:N8SElDUaT8mqBQQQCn:2SKDnADmQ9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • wzdu53.exe (PID: 1016)
      • wzdu53.exe (PID: 3444)
      • ga_utility.exe (PID: 3232)
      • c5164949-5a29-4ee1-b858-e90ed8c69b81.exe (PID: 3820)
      • WinZip Smart Monitor Service.exe (PID: 4036)
      • WinZipSmartMonitorSetup.exe (PID: 2140)
      • WinZipSmartMonitor.exe (PID: 3164)
      • WinZip Smart Monitor Service.exe (PID: 860)
      • Settings.exe (PID: 3812)
      • DriverUpdater.exe (PID: 3516)
      • DriverUpdater.exe (PID: 1960)
      • DriverUpdater.exe (PID: 2068)
      • ga_utility.exe (PID: 3180)
      • DriverUpdater.exe (PID: 944)
      • DriverUpdater.exe (PID: 908)
      • DriverUpdater.exe (PID: 1968)
      • Settings.exe (PID: 3620)
    • Changes settings of System certificates

      • ga_utility.exe (PID: 3232)
      • Settings.exe (PID: 3812)
      • WinZip Smart Monitor Service.exe (PID: 4036)
      • DriverUpdater.exe (PID: 908)
    • Loads dropped or rewritten executable

      • c5164949-5a29-4ee1-b858-e90ed8c69b81.exe (PID: 3820)
      • DriverUpdater.exe (PID: 3516)
      • WinZipSmartMonitorSetup.exe (PID: 2140)
      • DriverUpdater.exe (PID: 1960)
      • DriverUpdater.exe (PID: 2068)
      • DriverUpdater.exe (PID: 944)
      • DriverUpdater.exe (PID: 908)
      • DriverUpdater.exe (PID: 1968)
    • Loads the Task Scheduler DLL interface

      • DriverUpdater.exe (PID: 3516)
      • DriverUpdater.exe (PID: 908)
    • Loads the Task Scheduler COM API

      • DriverUpdater.exe (PID: 3516)
      • DriverUpdater.exe (PID: 908)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • c5164949-5a29-4ee1-b858-e90ed8c69b81.exe (PID: 3820)
      • firefox.exe (PID: 4024)
      • wzdu53.exe (PID: 3444)
      • WinZipSmartMonitorSetup.exe (PID: 2140)
      • DriverUpdater.exe (PID: 3516)
    • Reads Internet Cache Settings

      • ga_utility.exe (PID: 3232)
      • DriverUpdater.exe (PID: 3516)
      • ga_utility.exe (PID: 3180)
      • DriverUpdater.exe (PID: 908)
    • Adds / modifies Windows certificates

      • ga_utility.exe (PID: 3232)
      • Settings.exe (PID: 3812)
      • WinZip Smart Monitor Service.exe (PID: 4036)
      • DriverUpdater.exe (PID: 908)
    • Creates files in the program directory

      • WinZipSmartMonitorSetup.exe (PID: 2140)
      • WinZipSmartMonitor.exe (PID: 3164)
      • c5164949-5a29-4ee1-b858-e90ed8c69b81.exe (PID: 3820)
      • DriverUpdater.exe (PID: 3516)
      • DriverUpdater.exe (PID: 1960)
      • DriverUpdater.exe (PID: 908)
      • Settings.exe (PID: 3620)
    • Removes files from Windows directory

      • WinZip Smart Monitor Service.exe (PID: 4036)
    • Starts SC.EXE for service management

      • WinZipSmartMonitorSetup.exe (PID: 2140)
    • Executed as Windows Service

      • WinZip Smart Monitor Service.exe (PID: 4036)
    • Creates files in the Windows directory

      • WinZip Smart Monitor Service.exe (PID: 4036)
    • Creates a software uninstall entry

      • c5164949-5a29-4ee1-b858-e90ed8c69b81.exe (PID: 3820)
      • DriverUpdater.exe (PID: 2068)
    • Executed via COM

      • Settings.exe (PID: 3620)
    • Starts Internet Explorer

      • DriverUpdater.exe (PID: 1968)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 2192)
      • firefox.exe (PID: 4024)
      • iexplore.exe (PID: 3740)
    • Reads CPU info

      • firefox.exe (PID: 4024)
    • Reads settings of System Certificates

      • firefox.exe (PID: 4024)
      • DriverUpdater.exe (PID: 908)
      • iexplore.exe (PID: 1752)
    • Creates files in the program directory

      • firefox.exe (PID: 4024)
    • Reads Internet Cache Settings

      • firefox.exe (PID: 4024)
      • iexplore.exe (PID: 3740)
      • iexplore.exe (PID: 1752)
    • Manual execution by user

      • wzdu53.exe (PID: 1016)
      • wzdu53.exe (PID: 3444)
    • Creates files in the user directory

      • firefox.exe (PID: 4024)
      • iexplore.exe (PID: 1752)
    • Changes internet zones settings

      • iexplore.exe (PID: 3740)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1752)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1752)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1752)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
26
Malicious processes
10
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe wzdu53.exe no specs wzdu53.exe c5164949-5a29-4ee1-b858-e90ed8c69b81.exe ga_utility.exe winzipsmartmonitorsetup.exe settings.exe no specs winzip smart monitor service.exe no specs winzipsmartmonitor.exe no specs sc.exe no specs winzip smart monitor service.exe driverupdater.exe driverupdater.exe no specs ga_utility.exe driverupdater.exe no specs driverupdater.exe driverupdater.exe no specs driverupdater.exe no specs settings.exe no specs iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
860"C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe" /ServiceC:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exeWinZipSmartMonitorSetup.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Smart Monitor Service
Exit code:
0
Version:
2,11,3,8
Modules
Images
c:\program files\winzip smart monitor\winzip smart monitor service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
908"C:\Program Files\WinZip Driver Updater\DriverUpdater.exe" -no_update -scan -first_start_after_install -guid "FCC326CF-2B9D-42CA-9FB6-8720478A0DC8" C:\Program Files\WinZip Driver Updater\DriverUpdater.exe
c5164949-5a29-4ee1-b858-e90ed8c69b81.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Driver Updater
Exit code:
0
Version:
5,34,3,2
Modules
Images
c:\program files\winzip driver updater\driverupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\newdev.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
944"C:\Program Files\WinZip Driver Updater\DriverUpdater.exe" -syncSMSettingsC:\Program Files\WinZip Driver Updater\DriverUpdater.exec5164949-5a29-4ee1-b858-e90ed8c69b81.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Driver Updater
Exit code:
0
Version:
5,34,3,2
Modules
Images
c:\program files\winzip driver updater\driverupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\newdev.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1016"C:\Users\admin\Downloads\wzdu53.exe" C:\Users\admin\Downloads\wzdu53.exeexplorer.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
MEDIUM
Description:
WinZip Driver Updater
Exit code:
3221226540
Version:
5.34.3.2
Modules
Images
c:\users\admin\downloads\wzdu53.exe
c:\systemroot\system32\ntdll.dll
1752"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3740 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1960"C:\Program Files\WinZip Driver Updater\DriverUpdater.exe" -build_id 53 -guid "FCC326CF-2B9D-42CA-9FB6-8720478A0DC8"C:\Program Files\WinZip Driver Updater\DriverUpdater.exec5164949-5a29-4ee1-b858-e90ed8c69b81.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Driver Updater
Exit code:
0
Version:
5,34,3,2
Modules
Images
c:\program files\winzip driver updater\driverupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\newdev.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1968"C:\Program Files\WinZip Driver Updater\DriverUpdater.exe" openinsturl langid=en -guid "FCC326CF-2B9D-42CA-9FB6-8720478A0DC8"C:\Program Files\WinZip Driver Updater\DriverUpdater.exec5164949-5a29-4ee1-b858-e90ed8c69b81.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Driver Updater
Exit code:
0
Version:
5,34,3,2
Modules
Images
c:\program files\winzip driver updater\driverupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\newdev.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2068"C:\Program Files\WinZip Driver Updater\DriverUpdater.exe" -osource "wzdu53"C:\Program Files\WinZip Driver Updater\DriverUpdater.exec5164949-5a29-4ee1-b858-e90ed8c69b81.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Driver Updater
Exit code:
0
Version:
5,34,3,2
Modules
Images
c:\program files\winzip driver updater\driverupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\newdev.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2140C:\Users\admin\AppData\Local\Temp\nsdFDCB.tmp\WinZipSmartMonitorSetup.exeC:\Users\admin\AppData\Local\Temp\nsdFDCB.tmp\WinZipSmartMonitorSetup.exe
c5164949-5a29-4ee1-b858-e90ed8c69b81.exe
User:
admin
Company:
Corel Corporation
Integrity Level:
HIGH
Description:
WinZip Smart Monitor installer
Exit code:
0
Version:
2.11.3.8
Modules
Images
c:\users\admin\appdata\local\temp\nsdfdcb.tmp\winzipsmartmonitorsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2192"C:\Program Files\Mozilla Firefox\firefox.exe" "https://download.winzipdriverupdater.com/wzdu/wzdu53.exe"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
Total events
2 366
Read events
2 072
Write events
293
Delete events
1

Modification events

(PID) Process:(2192) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
88D2EE5100000000
(PID) Process:(4024) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
9AD2EE5100000000
(PID) Process:(4024) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(4024) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(4024) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(4024) firefox.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4024) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(4024) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3232) ga_utility.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3232) ga_utility.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
72
Suspicious files
249
Text files
478
Unknown types
124

Dropped files

PID
Process
Filename
Type
4024firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
4024firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
MD5:
SHA256:
4024firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
MD5:
SHA256:
4024firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
MD5:
SHA256:
4024firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp
MD5:
SHA256:
4024firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:
SHA256:
4024firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:
SHA256:
4024firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.binbinary
MD5:
SHA256:
4024firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstorebinary
MD5:
SHA256:
4024firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashsubdoc-digest256.sbstore
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
84
TCP/UDP connections
124
DNS requests
143
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4024
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
4024
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
4024
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
4024
firefox.exe
POST
200
172.217.20.227:80
http://ocsp.pki.goog/gts1o1core
US
der
472 b
whitelisted
3232
ga_utility.exe
GET
200
172.217.22.227:80
http://ocsp.pki.goog/gts1o1core/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEB3oRgfjsJWUCAAAAABbLrQ%3D
US
der
471 b
whitelisted
4024
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
4036
WinZip Smart Monitor Service.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAfIzLTdo4Aja9qETrklkTo%3D
US
der
471 b
whitelisted
4036
WinZip Smart Monitor Service.exe
GET
200
13.227.171.121:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
4036
WinZip Smart Monitor Service.exe
GET
200
52.222.136.220:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D
US
der
1.39 Kb
shared
4024
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4024
firefox.exe
35.161.199.137:443
search.services.mozilla.com
Amazon.com, Inc.
US
unknown
4024
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
4024
firefox.exe
54.192.86.8:443
snippets.cdn.mozilla.net
Amazon.com, Inc.
US
unknown
4024
firefox.exe
13.227.150.21:443
firefox.settings.services.mozilla.com
US
unknown
4024
firefox.exe
54.192.86.43:443
tracking-protection.cdn.mozilla.net
Amazon.com, Inc.
US
unknown
4024
firefox.exe
54.192.86.95:443
content-signature-2.cdn.mozilla.net
Amazon.com, Inc.
US
unknown
4024
firefox.exe
44.240.228.139:443
shavar.services.mozilla.com
University of California, San Diego
US
unknown
4024
firefox.exe
172.217.17.46:443
sb-ssl.google.com
Google Inc.
US
whitelisted
3232
ga_utility.exe
172.217.22.227:80
ocsp.pki.goog
Google Inc.
US
whitelisted
4024
firefox.exe
23.217.99.145:80
detectportal.firefox.com
Akamai Technologies, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 23.217.99.145
whitelisted
download.winzipdriverupdater.com
  • 104.101.100.39
whitelisted
search.services.mozilla.com
  • 35.161.199.137
whitelisted
push.services.mozilla.com
  • 52.26.177.54
whitelisted
tiles.services.mozilla.com
whitelisted
snippets.cdn.mozilla.net
  • 54.192.86.8
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
safebrowsing.googleapis.com
  • 172.217.22.202
whitelisted
www.facebook.com
  • 157.240.9.35
  • 157.240.221.35
whitelisted
www.mozilla.org
  • 104.18.165.34
whitelisted

Threats

No threats detected
No debug info