\n\n\n\n \n \n \n\n\n\n \n \nstart \n \n\n\n\n \n \n \n\n\n\n \n \n \n\n\n\n \n \n \n\n\n\n \n \n \n\n\n\n \n\nfirefox.exe \nno specs \n \n\n\n\n\n \n\n\n\n \n\nfirefox.exe \n\n \n\n\n\n \n\nfirefox.exe \nno specs \n \n\n\n\n \n\nfirefox.exe \n\n \n\n\n\n \n\nfirefox.exe \n\n \n\n\n\n \n\nfirefox.exe \n\n \n\n\n","processesValues":[{"rowId":"39dd3cb1-b8d7-430e-8e48-4e4a5bf89779","rowData":{"threatLevel":2,"values":[1584,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" \"https://lgin.msa.trafficmanager.net\"","C:\\Program Files\\Mozilla Firefox\\firefox.exe",[],"explorer.exe"],"information":{"values":["admin","Mozilla Corporation","MEDIUM","Firefox","0","68.0.1"],"modules":[]}}},{"rowId":"d8e7012c-658a-4292-b90c-b7c8ae8cd10a","rowData":{"threatLevel":2,"values":[3100,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" https://lgin.msa.trafficmanager.net","C:\\Program Files\\Mozilla Firefox\\firefox.exe",["network"],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","MEDIUM","Firefox","","68.0.1"],"modules":[]}}},{"rowId":"1c4610d7-3f88-4281-8187-d2e615ffe737","rowData":{"threatLevel":0,"values":[516,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -contentproc --channel=\"3100.0.284746288\\906218836\" -parentBuildID 20190717172542 -greomni \"C:\\Program Files\\Mozilla Firefox\\omni.ja\" -appomni \"C:\\Program Files\\Mozilla Firefox\\browser\\omni.ja\" -appdir \"C:\\Program Files\\Mozilla Firefox\\browser\" - 3100 \"\\\\.\\pipe\\gecko-crash-server-pipe.3100\" 1180 gpu","C:\\Program Files\\Mozilla Firefox\\firefox.exe",[],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","MEDIUM","Firefox","","68.0.1"],"modules":[]}}},{"rowId":"547c485f-cfeb-405b-a5a0-c3bc29e5ce82","rowData":{"threatLevel":0,"values":[4080,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -contentproc --channel=\"3100.3.1182932075\\1404399766\" -childID 1 -isForBrowser -prefsHandle 1332 -prefMapHandle 1340 -prefsLen 1 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni \"C:\\Program Files\\Mozilla Firefox\\omni.ja\" -appomni \"C:\\Program Files\\Mozilla Firefox\\browser\\omni.ja\" -appdir \"C:\\Program Files\\Mozilla Firefox\\browser\" - 3100 \"\\\\.\\pipe\\gecko-crash-server-pipe.3100\" 1616 tab","C:\\Program Files\\Mozilla Firefox\\firefox.exe",["network"],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","LOW","Firefox","","68.0.1"],"modules":[]}}},{"rowId":"7b0dd3ff-a886-449c-b2f6-07a7a2242b89","rowData":{"threatLevel":0,"values":[2648,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -contentproc --channel=\"3100.13.2114074647\\491891171\" -childID 2 -isForBrowser -prefsHandle 2772 -prefMapHandle 2776 -prefsLen 5996 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni \"C:\\Program Files\\Mozilla Firefox\\omni.ja\" -appomni \"C:\\Program Files\\Mozilla Firefox\\browser\\omni.ja\" -appdir \"C:\\Program Files\\Mozilla Firefox\\browser\" - 3100 \"\\\\.\\pipe\\gecko-crash-server-pipe.3100\" 2788 tab","C:\\Program Files\\Mozilla Firefox\\firefox.exe",["network"],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","LOW","Firefox","","68.0.1"],"modules":[]}}},{"rowId":"6bef982a-7077-4ccd-b74c-03920ebb81ff","rowData":{"threatLevel":0,"values":[3452,"\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -contentproc --channel=\"3100.20.1381424292\\2097594901\" -childID 3 -isForBrowser -prefsHandle 3752 -prefMapHandle 3756 -prefsLen 7129 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni \"C:\\Program Files\\Mozilla Firefox\\omni.ja\" -appomni \"C:\\Program Files\\Mozilla Firefox\\browser\\omni.ja\" -appdir \"C:\\Program Files\\Mozilla Firefox\\browser\" - 3100 \"\\\\.\\pipe\\gecko-crash-server-pipe.3100\" 3768 tab","C:\\Program Files\\Mozilla Firefox\\firefox.exe",["network"],"firefox.exe"],"information":{"values":["admin","Mozilla Corporation","LOW","Firefox","","68.0.1"],"modules":[]}}}]},"registryActivity":{"stats":[{"name":"Total events","value":"415"},{"name":"Read events","value":"410"},{"name":"Write events","value":"0"},{"name":"Delete events","value":"0"}],"modificationEvents":[]},"filesActivity":{"stats":[{"name":"Executable files","value":"0"},{"name":"Suspicious files","value":"58"},{"name":"Text files","value":"25"},{"name":"Unknown types","value":"38"}],"droppedFiles":[{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\scriptCache-current.bin","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\prefs-1.js","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\sessionCheckpoints.json.tmp","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.sqlite-shm","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1451318868ntouromlalnodry--epcr.sqlite-shm","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\search.json.mozlz4.tmp","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1657114595AmcateirvtiSty.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\allow-flashallow-digest256.sbstore","md5":"D886A47C89D9C49C795DA345BC236990","sha256":"A03C5E2656D2F292BF5794C8EEB8D223CD6BA4F4BFB2ED1F325460E879D0BCF7","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\search.json.mozlz4","md5":"6D378E0D40B6EACA22C8BCE899A1C5C1","sha256":"ADA2467B2477ACEFF837AC7820C435AD1EBBE844B2DA31C7AB9AE8D010C7A639","type":{"value":"jsonlz4","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\base-track-digest256.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\sessionCheckpoints.json","md5":"EA8B62857DFDBD3D0BE7D7E4A954EC9A","sha256":"792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA","type":{"value":"text","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3561288849sdhlie.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\scriptCache-child-current.bin","md5":"5027177F513CDAE07DB2330E1DED5934","sha256":"0C53F16051E738287A4612F68E296238087627E594CFD6DDFA1FECC2E998328B","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3870112724rsegmnoittet-es.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cookies.sqlite-shm","md5":"B7C14EC6110FA820CA6B65F5AEC85911","sha256":"FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\prefs.js","md5":"24541906B8228313DB6AD3DFC5A4F35B","sha256":"36A8E5E8355B283FBFF0BF12690C0FF5C91083182F652694FB4E70B4F44D0C2C","type":{"value":"text","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\urlCache-current.bin","md5":"DE9496ACA551ADE408EF6466A11833A1","sha256":"8F9C7FDB3E0BC01024E43A8E242468FC4DD4F74C725E32A883571635203DC10A","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\allow-flashallow-digest256.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-phish-proto.vlpset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flash-digest256.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\block-flashsubdoc-digest256.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flash-digest256.sbstore","md5":"C921D8E98FA01B4F303481E112202E92","sha256":"4EF1038730EC8BC7206713C29A936768831B922C5E6C83355FD62D7401D8C1DC","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flashallow-digest256.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\block-flashsubdoc-digest256.sbstore","md5":"04824A1F92353F43EBB9E7F74B7476FD","sha256":"B48E58EBAB82E4C376F16150A3FFF850C1111FF1F5985D68819CFD6F0DB159D2","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flashallow-digest256.sbstore","md5":"6F85BC4B2ECB49E26B0BD83A821065D0","sha256":"C0B3BC9B3DC507AB654CAF72D13C3AEFA58C9B13B1E4D14DD8816712D80A7E54","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\block-flash-digest256.sbstore","md5":"0E8FE60CCD7E9B4C32589A5743A95302","sha256":"2B124D4026850A3CFFD28DBACB58AEC28F7DCD4D40BC14E52BBE96D60CE4E749","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\block-flash-digest256.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flashsubdoc-digest256.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\base-track-digest256.sbstore","md5":"4A1220FC03E11726F09E9981834345DB","sha256":"6AE7FC0FDBE217104F4034BF6A580A461106B50309ABCCFF6E309124DCA5EF39","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-badbinurl-proto.vlpset","md5":"93FDF288DA71B455CFCB53F9E78ADD2A","sha256":"017ED2622F8E5E1D72DF4BC872BCF81CCFEA9681AEDE1AFDC7F3DDAC800B0CF5","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-unwanted-proto.vlpset","md5":"D9E28D043D05A069AC7962F181A05337","sha256":"EFBB9ADA8E5F662779444E4DE88CE944036B7C73D61ACFB70239F809DD153AA1","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-downloadwhite-proto.metadata","md5":"498DAE4E538658A57F464748F2DABFDA","sha256":"8778F52CD9CB4F4787BF7BA18006D212F8C3004652D163F7786556A8EEF3A067","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-harmful-simple.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\mozstd-trackwhite-digest256.sbstore","md5":"2AD4445DA23A8E50D667C09150CF1876","sha256":"C1550F9DC8F675C7FF2C896EE91C839E4E2B243E759D71C128521C17F53E91B1","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-unwanted-proto.metadata","md5":"6EE2FE4D5C3460929A4EEC3138D76E8E","sha256":"1BD0D3301B97FE608243E61C8FA114CC1AE9B69C0622A10CAFE5CC1814DF3B7A","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\mozplugin-block-digest256.sbstore","md5":"D6ACF2573E12AFDD7939568804D3FCC1","sha256":"5525CBF8F8DC41D19AC632ED324E55293A510AE0EEBA16D0E3F33C707AA58A0C","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-malware-proto.vlpset","md5":"8996548565A96F6BA34BC8317FB4F09E","sha256":"F760F51C58A91FCC264B8D27F610372AD510209EAE6D0911E0AC236E7405FDC8","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\except-flashsubdoc-digest256.sbstore","md5":"BA0009932844173BC8F9AF264229DF24","sha256":"66D1C00C04D86E313E9A02775CDF906B1BE8D4CD6BEF423A1B9E21CC4E9F50C1","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-malware-simple-1.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-phish-simple-1.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-phish-simple.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-downloadwhite-proto.pset","md5":"7655FFFE7CFBE1EBF96AFEA5FE2E1376","sha256":"FF2F663C4E453706B7817109F6A43E8B3389E8CFB1B7D64AACE2BFBA45F3A359","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-malware-simple.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-harmful-simple.sbstore","md5":"051FB32DECE757BA112AC36DC72E3A91","sha256":"0806D98FB3DE55F75D7C0B17E26146567E08C483031526659A4A35D09B97EF19","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-malware-proto.metadata","md5":"C0FF29E2429D6A67594D829B166B9D0B","sha256":"A8AB69AF442AE86AF43F2A3BF22B91341377BE23874762DE01E3E71EF08F0318","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-phish-simple.sbstore","md5":"3D1CE5E50208F0CB3B979186043A548F","sha256":"1E13D05D482C3D533DC6035AF2B2D6E84749412A5748D1435B70CEC8B312340B","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-unwanted-simple-1.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-harmful-simple-1.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-track-simple.pset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-track-simple-1.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\mozplugin-block-digest256.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-phish-proto.metadata","md5":"F57521D4D31B44FBBB74BA8F2441F52F","sha256":"FD6F2ADCF2BCE0AC48F15B6A67110E24EC8D24A566422512DF2269F2CFAC7A0D","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-track-simple.sbstore","md5":"95F28EDE25C301301F25FBBD9A3C56EC","sha256":"87763DF78772F7D750B0FA5A31EEC23E931FD3BD1CBB33BEDDFC61889DA36478","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-badbinurl-proto.metadata","md5":"B4D69F529BF6D261075D04C6A5C56158","sha256":"2794C0426AA721104DF6A8615D57A251AF30A79865CC69E369ED41CAE4EA4EE8","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-trackwhite-simple-1.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-block-simple.pset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-block-simple.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-trackwhite-simple.pset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-trackwhite-simple.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-block-simple-1.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-backup","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\addonStartup.json.lz4.tmp","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\mozstd-trackwhite-digest256.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-unwanted-simple.sbstore","md5":"A5695CC64D77967232B0C1344C6E72B3","sha256":"042A22B8681D754671D2018BA109B31A53EE3728D48C6379043F8E3394E7FBAD","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-malware-simple.sbstore","md5":"3675254E341DF799D4307C1F59109185","sha256":"23D108134BED6099793F7DD6B8B6E62081EC3B945EFDBC7C5E0E779FD9B82F98","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\test-unwanted-simple.pset","md5":"076933FF9904D1110D896E2C525E39E5","sha256":"4CBBD8CA5215B8D161AEC181A74B694F4E24B001D5B081DC0030ED797A8973E0","type":{"value":"cdxl","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\mz_etilqs_glHFOYwnTt86434","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\sessionstore-backups\\recovery.jsonlz4.tmp","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\permissions.sqlite-journal","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\664D8B83F744FF1331F50BCDEA789F4A1ECA2F62","md5":"7D7339DEB67993FC24D68D7529782624","sha256":"06666455ECF103FEF1B25DED8C74E9570EC0B2D0FBB24109A34D40ED7E0EF5CC","type":{"value":"der","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\1BB1C23E26E0306BA64099A99F8765A18D4D330E","md5":"213B2C696BBCD10AD7F246FAF7CB27DF","sha256":"05BC2379BD124B0D70588B078DED90A1A62B8E897E86A3E74A5D9A21FD372CF5","type":{"value":"der","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\addonStartup.json.lz4","md5":"65A8568F72FDF05A592210C52784C82A","sha256":"353279AEC0402D3777CD400ECFA22ECE3E3E882CB1E57056965DB44BD1306465","type":{"value":"jsonlz4","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\298C63FF434869897753FB8FE1C032A2897DC10F","md5":"BC91B6296B8850C0A337248F89683DA6","sha256":"6CFBCBBBFB295F40CFF78783BE83F0F4D8BEDCB8AE36C46005610536AE65C976","type":{"value":"der","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\doomed\\15206","md5":"E2AD220E176539D8470F5661A7777CAA","sha256":"48F6F4550310D8A7A573960035008A92744FD448BE98FC836612C5E9C5E51938","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\D2DC8196468F9C49E5D462DD63699A42E6292CB1","md5":"CE3267EDA5F9DCE64F0B50B80E2A990E","sha256":"0E3B5FB50DE8E4B74101488E56D8CB56747BB76296A1D55887CB7BAEF9E0A265","type":{"value":"der","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\BE0CCFDEED023C83BCD6BAB4E7FA39C986B3EA5A","md5":"0E7A9930DF120DF925D7C12D81E14770","sha256":"E96F0BC02C66E45CA270464C861F5676D58AE9934605B2B5616A20948BC1247F","type":{"value":"ini","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\sessionstore-backups\\recovery.jsonlz4","md5":"27BFA6DFB1344D1494CE27E666A314E1","sha256":"D05EC939CBD0C2146BF170ECB9D186E3D24C32ADEBAAF69BCA3A48276A0BFB2B","type":{"value":"jsonlz4","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\F14CAE5A6CD01ECDDDDDA4CD61A1EF99F720D22D","md5":"125411646AF9CF95B8A44C72F3F48E5B","sha256":"D30FC70C327761E101C26AC448F89FE40BC3019CB586F95738D5EC6842AC7890","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\doomed\\1057","md5":"A57EAC8C4E0D59D6D62C92B05E210C46","sha256":"BA0E89ECA0B891A962786DF3685C27588AD196A7C42C5218C3E2FA6873F31E89","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\A5D93CC48B83C8124FEB6A2E9448677EACA5BA86","md5":"B17F7DAC05248AD5BAE36DCD72A2093E","sha256":"D5684D23AD5B3D0C7566EE19B9F9E1A5EBDF4BBC766BA0E03ABCA4547A26A1CB","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\sessionstore-backups\\previous.jsonlz4","md5":"DA5A84A2615E68822FA04E81E66EA403","sha256":"1C43E3FBD8CF850C863BBA57A263DA38355B9021B4A9BCC9F1D59ECAF9841CE9","type":{"value":"jsonlz4","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\E1E251A5BC5386C473A99AF28DFADE47B2A33EE4","md5":"64242C583D2F2B87499B866EEDF94DEE","sha256":"937A9940115FF766A2C13884DF58D29BC742E327FC4B3B38A8B560D96E263336","type":{"value":"image","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\mz_etilqs_plJj6CKfZYYSEdr","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3870112724rsegmnoittet-es.sqlite-wal","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3870112724rsegmnoittet-es.sqlite","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cert9.db-journal","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\urlCache-new.bin","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\scriptCache-new.bin","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\scriptCache.bin","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\scriptCache-child-new.bin","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\mz_etilqs_grPnpk1b0eqOWHi","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\mz_etilqs_eHEe5qLTvkAfFJt","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\doomed\\29199","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\B342653B7130D15A4BC0942CD2B219B312068A91","md5":"8B5E7D8819112D14E75D88129AD59F92","sha256":"8EE09364764D89F2C2DC34A186103E9B91C7E026F3AF37E1BD6A78BEC0F0BF72","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\6C7E8A81FA2BBE48C5C57402C8E7FDADEFD17011","md5":"CEAD27DDC1CEC8ECAFD66BC8513C32CB","sha256":"C491AEE1755606D67875BE2F2B40BD70B17DC16FD672191216C92443205929C0","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\9A3EF8133F0FA6C3DE8D839A13E7E624CC01FBCC","md5":"3B3F14D5BDA1E3F47732F84938BD7E3C","sha256":"410C08E720234023ADB68B684B192DFEC6B0C3B86B8A2E8593544E9D45BD1BF6","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\927970716423E2D1417F8996992FC6C7ADD70E69","md5":"283C27C009D9C45121FDD58D3852CCFC","sha256":"7754E8CEDD9F315D182E9A32C67288CEE2944F47B8028772CDB490AAA5BAA1CA","type":{"value":"cer","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\6ECA0FEA78766CD8D68B17D920A922EA2331E265","md5":"A602BF005502CB6A7BEA95CD007C14ED","sha256":"513F05F7CEE257182315558F72498CEF05EF9C73B9BE788AA1538D8509BC6048","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\EE197B20CAB0419D1C0BD23EE03034F880EDC296","md5":"7A98AF53E00BB788AAD310F7C7654570","sha256":"8E442A4048C0B275622F9B2B6B1705BE55227DA3459FE58F52602C0275445407","type":{"value":"image","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\mz_etilqs_pLb7NsMfecqppP5","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\revocations-1.txt","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cert_override.txt","md5":"0229A3CB73C4F800CCBB1F0576033C50","sha256":"ED31A5B0FEE72C42EE9CB3BD90C3B85AF66E1213E4880F515AFD7F18E1EEE0AA","type":{"value":"text","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\urlCache.bin","md5":"A9FB30D6AF509DA48CE0DF13738B96E2","sha256":"5F8F812B2BEF3FFD1834FC3FF346073AE398D1610422237BA6CDA66E5E9C4978","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cert9.db","md5":"AA3DC495C4F4D5AD8A874537315289A5","sha256":"34FE5BF5E1325F282D0AC3335F67296CBEF8B3A822C96F766FCA4FA5D28A43AB","type":{"value":"sqlite","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\scriptCache-child.bin","md5":"BD09AE31284F5F39C9A1BCC966EE4992","sha256":"5BFF27B82AED4DFEFA851620F78A7B6CE97825E32DDAA8E4F96B9BB950801760","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\B3E23AD3604E036212A893BC7E609F9E3CEE65D4","md5":"196BD1CBD06229FEFF91B415DEB70952","sha256":"B22F1C8B0D9AA6882A8D82C2676ED6570E400796493D4B6E4438CEDDFF45865A","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\AC30F8475DC59E5FA34E816A79BF3670D5E429AA","md5":"C949DA0BC698E915B25D8D0E9C56550E","sha256":"87F03777977D2711EFB6FA1B352FC00E031856452C8E1E93B590146E85F4465E","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1657114595AmcateirvtiSty.sqlite-wal","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\DC1BED99931D95F1B579835FC9F56E6BE518772E","md5":"3FE5917D2A9D1DFE4752BFA6167239F3","sha256":"14915991BFB4FB3D9C556581F02D722D972E068E616EBA96F6523C89E8B92AAC","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.sqlite-wal","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\revocations.txt","md5":"B37801656A16F18B1C067FB7826B2737","sha256":"DD9EA1387FCED5A4C5C833A5880E76F21DBACDED51B84646E06CEC778894532F","type":{"value":"text","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\EA8E7FF52ED662DF2659F01FD78053DDBA5113BA","md5":"BB1DE368DE6E1613828D638C33630863","sha256":"2443F5CC6B5033C6AD09639DA88B150D5DDE671CE146C257D17526EA9FB3DE8D","type":{"value":"image","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\6600D575DBF0A48A7EC979D6AB87FD7504E4638D","md5":"081511B3201FC41848CA3B83FBEB7981","sha256":"471762FCFF6766FDC05C2F6353444160A792324394136601A1357E52EB4D642D","type":{"value":"cer","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\CAE02EBF829D02A304987ADFCB2072E3D82666B3","md5":"C31FFC338F03DD47C49119F33CFDBBFF","sha256":"DC46FCE77CE739ADF33250006C128B5525B32CB45CCB737133E68CE6F45C8D56","type":{"value":"compressed","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\AE83001E23EA7F19571263EA6FFBF73271765ACA","md5":"513E4E2A8644A26B149F88F285557862","sha256":"C49852DC9ED106D8CF462DE42B1D5A06926E6F0A76D5ED9D16DA76A5B3B15B4F","type":{"value":"compressed","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\C42493F8ED1D0F3A5584E9B8D64E34B6F97A900D","md5":"E766B5D3669D85F2FE053FB893D765BD","sha256":"05B75D84BAC0BEC249620F92B7DF2D65BC0653DDC69A88EF3460F1F5DE306F99","type":{"value":"compressed","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\AB423DCD1B1F2AC64DFC45A9DF00554A51D532F5","md5":"533DB31B86278725826C989C538AA76C","sha256":"A8A756993CBAFF9D2800503A4A2D31441C62D5F269BED52CBEEA86D8B7210203","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\30A63F13174CD91A1F938AA6BD86F846A7F079CF","md5":"8FF06D63818A4D65053C63F317FD4C65","sha256":"ED4B9C7947F1EB95997BC16A31066D7D42D270C42804A3276AC7897C9400080C","type":{"value":"compressed","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1657114595AmcateirvtiSty.sqlite","md5":"CD875655CFC92D6305460CD7FA1420CB","sha256":"4C5E2E57B48C8FA1609C0A3E5F69002A0AC67C337EC74E0F3F56777E8ACBEE54","type":{"value":"sqlite","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\0072BC37ACDDC06C6067C46B3C534E493C3A8690","md5":"584BFC514A3FBC00633DA4C3375581B8","sha256":"066E6090BAC9CD617E05B4A530DA7AE0FBC3A8EC7DF18D5C06DAF9DE660F6942","type":{"value":"compressed","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\8F1785410647F7E133491D1F38DC63F33CA466CE","md5":"A005ABCAF6FD2B7C9EFCC538B48DE7B0","sha256":"A7B28092CAE7D7076253568F7DFF3FE99220B41360BF6811CD4BD41F2C3AAD60","type":{"value":"compressed","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-phish-proto-1.vlpset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\BDAA1D51200FBE56835928D99146BCF4A9B63FDA","md5":"ED6679D415DC24EB91D852BF75F67E01","sha256":"2F96D6A1F37BE9583067C671C49F6D59891D5040E3949D9E19ACD71D39789220","type":{"value":"image","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\902106735BDEBB4EBB7CA83279FF21BFD23EF313","md5":"FABFB597FBFCC4977FE2155FFAE15A1A","sha256":"53FB850A4B60C3BF0798A3C05FFBC78351B2B1DC72B149B7A2C17174B6696E3A","type":{"value":"image","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\ED4CE6DCD5C1EA4EBEB3F5CE4968C13FBFBA7575","md5":"0343113AA26028DAEC6665101626EE89","sha256":"64B7B17D1FBC477D77615D5E703714789CA6A6EAE07088D40DD53984D46CEB36","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-malware-proto-1.vlpset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-unwanted-proto-1.vlpset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\google4\\goog-badbinurl-proto-1.vlpset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\F36BA6E65505B424864C5907B9DCD4FA685F2145","md5":"4692C2A43E4254C4A59D0867F7D9F657","sha256":"887FDB22CBFF93BE0C3C2FB2DC39B946A8346307DEDF40526FAA790F4CC278A8","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\broadcast-listeners.json.tmp","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\extensions.json.tmp","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\sessionstore-backups\\recovery.baklz4","md5":"27BFA6DFB1344D1494CE27E666A314E1","sha256":"D05EC939CBD0C2146BF170ECB9D186E3D24C32ADEBAAF69BCA3A48276A0BFB2B","type":{"value":"jsonlz4","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\ABEAA48B501FBD6A530EC9F222A741DA79987BC8","md5":"D6056A1D2053B5E3520C63D5E23661A2","sha256":"C4405BE18F1EE36E58A080B55F2928998035A0D500BFF1D895911AE63DD1FFA6","type":{"value":"binary","type":1}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\54A252FAD6F4ABD8B203D690563A59196A88C22B","md5":"2F1B33982942E465A7E06E7915408230","sha256":"46620E8FAA1317B588F76B531F91523A463FECA1C993A07FA1EAE7CBCBDE2E18","type":{"value":"der","type":4}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\broadcast-listeners.json","md5":"E6EA4205CF1E397F6ABA1F4CDE66C55C","sha256":"D6B5B918E5DEEBF80E450EA0E0AF37CC2BEC5DD015185C8246472B726CEBD9A2","type":{"value":"text","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\extensions.json","md5":"9CF5E9E40B5F764838F42C8F2721957F","sha256":"AD9889206F043A9D31AF59D6DB2A74D9680930C009A560E8CD158BAFA271AF8F","type":{"value":"text","type":0}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\analytics-track-digest256.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\analytics-track-digest256.pset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\mozstd-trackwhite-digest256-1.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\social-track-digest256.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\social-track-digest256.pset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\base-track-digest256-1.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\content-track-digest256.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\content-track-digest256.pset","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\ads-track-digest256.sbstore","md5":"—","sha256":"—","type":{}},{"pid":3100,"process":"firefox.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing-updating\\ads-track-digest256.pset","md5":"—","sha256":"—","type":{}}]},"synchronization":{"values":[]},"rpsRequests":{"values":[]},"networkActivity":{"stats":[{"name":"HTTP(S) requests","value":"7"},{"name":"TCP/UDP connections","value":"20"},{"name":"DNS requests","value":"100"},{"name":"Threats","value":"0"}],"requests":[[3100,"firefox.exe","POST",200,"172.217.17.67:80","http://ocsp.pki.goog/gts1o1","US",{"value":"der","type":4},"471 b",{"value":"whitelisted","type":3}],[3100,"firefox.exe","GET",200,"104.84.152.177:80","http://detectportal.firefox.com/success.txt","NL",{"value":"text","type":0},"8 b",{"value":"whitelisted","type":3}],[3100,"firefox.exe","POST",200,"93.184.220.29:80","http://ocsp.digicert.com/","US",{"value":"der","type":4},"471 b",{"value":"shared","type":0}],[3100,"firefox.exe","POST",200,"93.184.220.29:80","http://ocsp.digicert.com/","US",{"value":"der","type":4},"471 b",{"value":"shared","type":0}],[3100,"firefox.exe","GET",200,"104.84.152.177:80","http://detectportal.firefox.com/success.txt","NL",{"value":"text","type":0},"8 b",{"value":"whitelisted","type":3}],[3100,"firefox.exe","POST",200,"93.184.220.29:80","http://ocsp.digicert.com/","US",{"value":"der","type":4},"471 b",{"value":"shared","type":0}],[3100,"firefox.exe","POST",200,"93.184.220.29:80","http://ocsp.digicert.com/","US",{"value":"der","type":4},"471 b",{"value":"shared","type":0}]],"connections":[[3100,"firefox.exe","93.184.220.29:80","ocsp.digicert.com","MCI Communications Services, Inc. d/b/a Verizon Business","US",{"value":"whitelisted","type":3}],[3100,"firefox.exe","172.217.17.67:80","ocsp.pki.goog","Google Inc.","US",{"value":"whitelisted","type":3}],[3100,"firefox.exe","192.229.221.185:443","logincdn.msauth.net","MCI Communications Services, Inc. d/b/a Verizon Business","US",{"value":"suspicious","type":1}],[3100,"firefox.exe","99.86.115.6:443","content-signature-2.cdn.mozilla.net","AT&T Services, Inc.","US",{"value":"unknown","type":4}],[3100,"firefox.exe","40.90.22.191:443","lgin.msa.trafficmanager.net","Microsoft Corporation","US",{"value":"malicious","type":2}],[3100,"firefox.exe","52.41.171.126:443","push.services.mozilla.com","Amazon.com, Inc.","US",{"value":"malicious","type":2}],[3100,"firefox.exe","35.162.117.80:443","tiles.services.mozilla.com","Amazon.com, Inc.","US",{"value":"unknown","type":4}],[3100,"firefox.exe","104.84.152.177:80","detectportal.firefox.com","Akamai International B.V.","NL",{"value":"whitelisted","type":3}],[3100,"firefox.exe","13.32.171.51:443","firefox.settings.services.mozilla.com","Amazon.com, Inc.","US",{"value":"unknown","type":4}],[3100,"firefox.exe","52.89.218.39:443","search.services.mozilla.com","Amazon.com, Inc.","US",{"value":"unknown","type":4}],[3100,"firefox.exe","52.84.90.120:443","snippets.cdn.mozilla.net","Amazon.com, Inc.","US",{"value":"unknown","type":4}],[3100,"firefox.exe","35.167.176.126:443","shavar.services.mozilla.com","Amazon.com, Inc.","US",{"value":"unknown","type":4}],[3100,"firefox.exe","172.217.17.42:443","safebrowsing.googleapis.com","Google Inc.","US",{"value":"whitelisted","type":3}],[3100,"firefox.exe","52.84.90.19:443","tracking-protection.cdn.mozilla.net","Amazon.com, Inc.","US",{"value":"unknown","type":4}]],"dns":[["detectportal.firefox.com",["104.84.152.177"],{"value":"whitelisted","type":3}],["search.services.mozilla.com",["52.89.218.39"],{"value":"whitelisted","type":3}],["push.services.mozilla.com",["52.41.171.126"],{"value":"shared","type":0}],["snippets.cdn.mozilla.net",["52.84.90.120"],{"value":"whitelisted","type":3}],["tiles.services.mozilla.com",["35.162.117.80"],{"value":"whitelisted","type":3}],["lgin.msa.trafficmanager.net",["40.90.22.191"],{"value":"malicious","type":2}],["safebrowsing.googleapis.com",["172.217.17.42"],{"value":"whitelisted","type":3}],["ocsp.pki.goog",["172.217.17.67"],{"value":"whitelisted","type":3}],["ocsp.digicert.com",["93.184.220.29"],{"value":"shared","type":0}],["support.mozilla.org",["34.213.134.214"],{"value":"whitelisted","type":3}],["www.facebook.com",["157.240.201.35"],{"value":"whitelisted","type":3}],["www.youtube.com",["216.58.208.110"],{"value":"shared","type":0}],["www.ebay.de",["104.81.141.226"],{"value":"whitelisted","type":3}],["www.reddit.com",["151.101.193.140"],{"value":"whitelisted","type":3}],["www.wikipedia.org",["91.198.174.192"],{"value":"shared","type":0}],["firefox.settings.services.mozilla.com",["13.32.171.51"],{"value":"whitelisted","type":3}],["www.mozilla.org",["104.16.142.228"],{"value":"whitelisted","type":3}],["content-signature-2.cdn.mozilla.net",["99.86.115.6"],{"value":"whitelisted","type":3}],["logincdn.msauth.net",["192.229.221.185"],{"value":"whitelisted","type":3}],["ipv6.login.live.com",["—"],{"value":"unknown","type":4}],["shavar.services.mozilla.com",["35.167.176.126"],{"value":"whitelisted","type":3}],["tracking-protection.cdn.mozilla.net",["52.84.90.19"],{"value":"whitelisted","type":3}]],"threatsProCount":0,"threats":[]},"debugOutputStrings":{"values":[]},"meta":{"sha256":"bd83b1b3c6e369a8e6bd3feb15f698ef17967fe795872c1ab41c7fa8d1ace8c5","uuid":"b485db54-21b1-44d1-8a2e-b94038c1fd87","isUrlType":true,"taskName":"https://lgin.msa.trafficmanager.net","title":"Free Malware Sandbox Online","isPrivate":false,"tags":["phishing","phish-outlook","phish-microsoft"],"copyrightYear":2022},"vue_isInlineMode":false,"vue_publicPath":"/report/"}
We're sorry but any.run reports doesn't work properly without JavaScript enabled. Please enable it to continue.
General Info Add for printing
URL: https://lgin.msa.trafficmanager.net Full analysis: https://app.any.run/tasks/b485db54-21b1-44d1-8a2e-b94038c1fd87 Verdict: Malicious activity Analysis date: December 11, 2019, 19:57:22 OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) Tags: Indicators: MD5: 2C1050A7B08142A528106F82815FEB89 SHA1: BED5680980DBFFBF5597FF49A76CEB453358FC59 SHA256: BD83B1B3C6E369A8E6BD3FEB15F698EF17967FE795872C1AB41C7FA8D1ACE8C5 SSDEEP: 3:N8CKLISx3ys:2Cuis
ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is.
ANY.RUN does not guarantee maliciousness or safety of the content.
Software environment set and analysis options Launch configuration Task duration: 60 seconds Heavy Evasion option: off Network geolocation: off Additional time used: none MITM proxy: off Privacy: Public submission Fakenet option: off Route via Tor: on Autoconfirmation of UAC: on Network: on Hotfixes Client LanguagePack Package Client Refresh LanguagePack Package CodecPack Basic Package Foundation Package IE Troubleshooters Package InternetExplorer Optional Package KB2534111 KB2999226 KB4019990 KB976902 LocalPack AU Package LocalPack CA Package LocalPack GB Package LocalPack US Package LocalPack ZA Package ProfessionalEdition UltimateEdition Processes Add for printing
Behavior graph Click at the process to see the details
start
firefox.exe
no specs
firefox.exe
firefox.exe
no specs
firefox.exe
firefox.exe
firefox.exe
- +
Specs description Program did not start Low-level access to the HDD Process was added to the startup Debug information is available Probably Tor was used Behavior similar to spam Task has injected processes Executable file was dropped Known threat RAM overrun Network attacks were detected Integrity level elevation Connects to the network CPU overrun Process starts the services System was rebooted Task contains several apps running Application downloaded the executable file Actions similar to stealing personal data Task has apps ended with an error File is detected by antivirus software Inspected object has suspicious PE structure Behavior similar to exploiting the vulnerability Task contains an error or was rebooted The process has the malware config Process information
Network activity Add for printing
HTTP requests Download PCAP, analyze network streams, HTTP content and a lot more at the
full report Connections
DNS requests
Threats