URL: | http://msn.com |
Full analysis: | https://app.any.run/tasks/1790b11d-0154-4498-8305-2e422b48a0f0 |
Verdict: | Malicious activity |
Analysis date: | April 25, 2019, 06:41:44 |
OS: | Windows 10 Professional (build: 16299, 32 bit) |
Indicators: | |
MD5: | AED8E7C849B355084F4F1ED4064EF6C3 |
SHA1: | 6354CA65DA9C7B21FA4C3ED094B194F9C703F904 |
SHA256: | C0A96AE38E82DB36A12A11D286B7DBBCD6A46C34795F545A046611DC659DAF8B |
SSDEEP: | 3:N1KT1:Ch |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2776 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://msn.com | C:\Program Files\Mozilla Firefox\firefox.exe | explorer.exe | |
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 65.0.2 | ||||
3944 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2776.0.440765659\811712508" -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - "C:\Users\admin\AppData\LocalLow\Mozilla\Temp-{ca100fe7-9efb-4b30-9dae-2d42221607d9}" 2776 "\\.\pipe\gecko-crash-server-pipe.2776" 1400 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 65.0.2 | ||||
240 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2776.6.1264736226\1435735341" -childID 1 -isForBrowser -prefsHandle 2900 -prefMapHandle 2880 -prefsLen 1 -prefMapSize 181073 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2776 "\\.\pipe\gecko-crash-server-pipe.2776" 1732 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 65.0.2 | ||||
1156 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2776.13.1379267843\2070868503" -childID 2 -isForBrowser -prefsHandle 2412 -prefMapHandle 2032 -prefsLen 1 -prefMapSize 181073 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2776 "\\.\pipe\gecko-crash-server-pipe.2776" 2180 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 65.0.2 | ||||
2280 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2776.20.1629791128\455585199" -childID 3 -isForBrowser -prefsHandle 2188 -prefMapHandle 2148 -prefsLen 1 -prefMapSize 181073 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2776 "\\.\pipe\gecko-crash-server-pipe.2776" 2372 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 65.0.2 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2776 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ymgarh1v.default\cookies.sqlite-wal | — | |
MD5:— | SHA256:— | |||
2776 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ymgarh1v.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
2776 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ymgarh1v.default\extensions.json.tmp | — | |
MD5:— | SHA256:— | |||
2776 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ymgarh1v.default\pluginreg.dat.tmp | — | |
MD5:— | SHA256:— | |||
2776 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ymgarh1v.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
2776 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ymgarh1v.default\cert9.db-journal | — | |
MD5:— | SHA256:— | |||
2776 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ymgarh1v.default\key4.db-journal | — | |
MD5:— | SHA256:— | |||
2776 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ymgarh1v.default\addonStartup.json.lz4.tmp | — | |
MD5:— | SHA256:— | |||
2776 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ymgarh1v.default\compatibility.ini | ini | |
MD5:D6FF99308B6BB17E79D208B32DD14489 | SHA256:6BCB9DD4A2B7FF9D52DA70E10FCA5983BAD5AC8CC6D6A456F05652A55F7AD26F | |||
2776 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ymgarh1v.default\prefs.js | text | |
MD5:B5C9EB1587DAA26A415A30E7672817F6 | SHA256:162F65E5707D5A8C87CE7C9E8A305B92F1151D55748B83AEAC935DF0ADB21481 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.43 Kb | whitelisted |
2776 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2776 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2776 | firefox.exe | GET | 301 | 13.82.28.61:80 | http://msn.com/ | US | html | 142 b | whitelisted |
2776 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2776 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2776 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2776 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2776 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2776 | firefox.exe | GET | 200 | 2.16.186.112:80 | http://detectportal.firefox.com/success.txt | unknown | text | 8 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2776 | firefox.exe | 2.16.186.112:80 | detectportal.firefox.com | Akamai International B.V. | — | whitelisted |
2776 | firefox.exe | 204.79.197.203:80 | www.msn.com | Microsoft Corporation | US | whitelisted |
— | — | 65.55.163.91:443 | login.live.com | Microsoft Corporation | US | unknown |
2776 | firefox.exe | 13.82.28.61:80 | msn.com | Microsoft Corporation | US | whitelisted |
2776 | firefox.exe | 34.251.59.153:443 | location.services.mozilla.com | Amazon.com, Inc. | IE | unknown |
2776 | firefox.exe | 52.85.184.119:443 | snippets.cdn.mozilla.net | Amazon.com, Inc. | US | unknown |
2776 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2776 | firefox.exe | 54.149.115.79:443 | tiles.services.mozilla.com | Amazon.com, Inc. | US | unknown |
2776 | firefox.exe | 54.200.51.65:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
---|---|---|
self.events.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
msn.com |
| whitelisted |
location.services.mozilla.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
locprod1-elb-eu-west-1.prod.mozaws.net |
| whitelisted |
a1089.dscd.akamai.net |
| whitelisted |
snippets.cdn.mozilla.net |
| whitelisted |
drcwo519tnci7.cloudfront.net |
| shared |