General Info

URL

http://guitarlessonsvideo.info/setupconfig/rottenhellboy12.php

Full analysis
https://app.any.run/tasks/a347837e-a45e-4abd-8c6b-7459103c0f47
Verdict
Malicious activity
Analysis date
10/9/2019, 21:18:37
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • SearchProtocolHost.exe (PID: 1768)
Executable content was dropped or overwritten
  • firefox.exe (PID: 3644)
Creates files in the program directory
  • firefox.exe (PID: 3772)
  • firefox.exe (PID: 3644)
Dropped object may contain TOR URL's
  • firefox.exe (PID: 3644)
Creates files in the user directory
  • firefox.exe (PID: 3772)
  • firefox.exe (PID: 3644)
Reads CPU info
  • firefox.exe (PID: 3644)
  • firefox.exe (PID: 3772)
Dropped object may contain Bitcoin addresses
  • firefox.exe (PID: 3644)
Application launched itself
  • firefox.exe (PID: 3772)
  • firefox.exe (PID: 2844)
  • firefox.exe (PID: 3644)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
51
Monitored processes
17
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe pingsender.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe firefox.exe firefox.exe firefox.exe searchprotocolhost.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
1768
CMD
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
Path
C:\Windows\System32\SearchProtocolHost.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Search Protocol Host
Version
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\tquery.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msshooks.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msidle.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\mssph.dll
c:\windows\system32\mapi32.dll
c:\windows\system32\authz.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\notepad.exe
c:\windows\system32\wshext.dll
c:\windows\system32\version.dll
c:\users\admin\desktop\old firefox data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll
c:\users\admin\desktop\old firefox data\qldyz51w.default\gmp-gmpopenh264\1.8.1\gmpopenh264.dll
c:\windows\system32\msxml3r.dll

PID
2844
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" "http://guitarlessonsvideo.info/setupconfig/rottenhellboy12.php"
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3772
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" http://guitarlessonsvideo.info/setupconfig/rottenhellboy12.php
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\psapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\winsta.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\d2d1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\progra~1\mozill~1\nssckbi.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\actxprxy.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\program files\mozilla firefox\pingsender.exe

PID
2928
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3772.0.1403600630\1008486951" -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3772 "\\.\pipe\gecko-crash-server-pipe.3772" 1164 gpu
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll

PID
3888
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3772.3.879859804\100249185" -childID 1 -isForBrowser -prefsHandle 1704 -prefMapHandle 1700 -prefsLen 1 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3772 "\\.\pipe\gecko-crash-server-pipe.3772" 1724 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
2508
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3772.13.888356803\1818891368" -childID 2 -isForBrowser -prefsHandle 2808 -prefMapHandle 2816 -prefsLen 5997 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3772 "\\.\pipe\gecko-crash-server-pipe.3772" 2828 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll

PID
2840
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3772.20.211272023\990620051" -childID 3 -isForBrowser -prefsHandle 3772 -prefMapHandle 3776 -prefsLen 7130 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3772 "\\.\pipe\gecko-crash-server-pipe.3772" 3788 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll

PID
3220
CMD
"C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/b3b9429a-25ee-4d7c-84df-880a3c05f394/main/Firefox/68.0.1/release/20190717172542?v=4 C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\b3b9429a-25ee-4d7c-84df-880a3c05f394
Path
C:\Program Files\Mozilla Firefox\pingsender.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Foundation
Description
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\pingsender.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll

PID
2664
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe"
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3644
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe"
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\psapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\winsta.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\d2d1.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\progra~1\micros~1\office14\outlook.exe
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\macromed\flash\npswf32_26_0_0_131.dll
c:\program files\java\jre1.8.0_92\bin\dtplugin\npdeployjava1.dll
c:\program files\java\jre1.8.0_92\bin\plugin2\npjp2.dll
c:\progra~1\micros~1\office14\npspwrap.dll
c:\progra~1\micros~1\office14\npauthz.dll
c:\program files\google\update\1.3.34.11\npgoogleupdate3.dll
c:\program files\videolan\vlc\npvlc.dll
c:\program files\adobe\acrobat reader dc\reader\air\nppdf32.dll
c:\windows\system32\msimg32.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\progra~1\mozill~1\nssckbi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\actxprxy.dll

PID
3816
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3644.0.759275805\120717061" -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3644 "\\.\pipe\gecko-crash-server-pipe.3644" 1088 gpu
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll

PID
2428
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3644.6.40141778\763018583" -childID 1 -isForBrowser -prefsHandle 2092 -prefMapHandle 2088 -prefsLen 1 -prefMapSize 184959 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3644 "\\.\pipe\gecko-crash-server-pipe.3644" 2112 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
2276
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3644.13.278725132\1096836457" -childID 2 -isForBrowser -prefsHandle 2320 -prefMapHandle 2324 -prefsLen 120 -prefMapSize 184959 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3644 "\\.\pipe\gecko-crash-server-pipe.3644" 2336 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
3296
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3644.20.1654698047\1299639885" -childID 3 -isForBrowser -prefsHandle 2424 -prefMapHandle 2352 -prefsLen 120 -prefMapSize 184959 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3644 "\\.\pipe\gecko-crash-server-pipe.3644" 2480 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
3236
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3644.27.1344830104\496900903" -childID 4 -isForBrowser -prefsHandle 2900 -prefMapHandle 2904 -prefsLen 1387 -prefMapSize 184959 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3644 "\\.\pipe\gecko-crash-server-pipe.3644" 2920 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll

PID
2216
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3644.34.2115975075\945479515" -childID 5 -isForBrowser -prefsHandle 1716 -prefMapHandle 1696 -prefsLen 8577 -prefMapSize 184959 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3644 "\\.\pipe\gecko-crash-server-pipe.3644" 3820 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
3488
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3644.41.1622955677\628012791" -childID 6 -isForBrowser -prefsHandle 4144 -prefMapHandle 4136 -prefsLen 9551 -prefMapSize 184959 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3644 "\\.\pipe\gecko-crash-server-pipe.3644" 4128 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
68.0.1
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll

Registry activity

Total events
1080
Read events
1052
Write events
28
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2664
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
80F8A7C600000000
2844
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
38EF2AC300000000
3772
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Browser
74CF38C300000000
3772
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
1
3772
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3772
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000093000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3220
pingsender.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3220
pingsender.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000094000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3220
pingsender.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
1768
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
1768
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
@C:\Windows\system32\notepad.exe,-469
Text Document
1768
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
@C:\Windows\System32\wshext.dll,-4804
JScript Script File
1768
SearchProtocolHost.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
@C:\Windows\System32\msxml3r.dll,-1
XML Document
3644
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Browser
6173ACC600000000
3644
firefox.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
1
3644
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3644
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000095000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000

Files activity

Executable files
2
Suspicious files
110
Text files
106
Unknown types
108

Dropped files

PID
Process
Filename
Type
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll
executable
MD5: f634756cf6a4be877fc71120738ac7f3
SHA256: 677072eb97381f11bb49561a4ebd01cbf012e3f8da070e0aa697ad9714c244ce
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-gmpopenh264\1.8.1\gmpopenh264.dll
executable
MD5: d23f706f2eacc190f2d4b75b041670d5
SHA256: ced08ce5bc45dbe505fa94b3a4268c0830ccda016a23c0acb16dd7268cfa7a65
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\crashes\store.json.mozlz4
jsonlz4
MD5: a6338865eb252d0ef8fcf11fa9af3f0d
SHA256: 078648c042b9b08483ce246b7f01371072541a2e90d1beb0c8009a6118cbd965
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\thumbnails\3b73552d647f56cf33b839c2fcb5541c.png
image
MD5: df6ea8e7a653fd4c29ab47472d20a159
SHA256: 735ef20723b7774ad911ec4da7abb8939235a96150a2bae7b88444eb2cb58115
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\thumbnails\3b73552d647f56cf33b839c2fcb5541c.png.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: 02d4ea76a39238d13f3724152d26d861
SHA256: e8a814c1aa24182cb4339ab4f3c5efab0601656d9f2c2a9ad57e23768a8de592
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs-1.js
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\0EDDF8C091E2FED62E44BEDDDC1723F5BF38FE4F
binary
MD5: 459ecf7598ff5cab8e1a8a71f2023bb7
SHA256: bde82e9fce1b8b07500527d84986229364f44e16ef5591f22bcf03d8d14b0232
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\E910D1FCE8BF27F5536B88567A4DC32624377CC3
binary
MD5: 58097f68191e9a0d0fba2a29a1f47677
SHA256: 7693d67ef157fbcc50eaa0eb651e5e4f3084e0feca46d9d6bf1257cc4fc48b57
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\66F684AF9CC570C6247262B47C769C601C2A338B
binary
MD5: 8f3e0c8fa87045877ac41f25e7e56c0e
SHA256: 28ce261a3f9cf03b0b6080acd4f46c40711aa81301573b269b1003f3bdf64b35
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\B1EC7128DC0CF2A43AE0D3031BAE8A64C0805C91
binary
MD5: 3023ef40e099d907b2b0425e25d955e4
SHA256: 27c3ef27bd341fd73ca337cededb5cbbb8c1c199cdf5f0631e6ebbecb359f117
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\9A3EF8133F0FA6C3DE8D839A13E7E624CC01FBCC
binary
MD5: 2ba0d509f2637e06233fedfd850d4fac
SHA256: 4b94fa410212132c2221da9b2f01142189005416ab27de7771e6675d9f69af68
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\ads-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\ads-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\mozplugin-block-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\block-flash-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\content-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\mozplugin-block-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\block-flash-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\base-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-backup
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\base-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\social-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\content-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\mozstd-trackwhite-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\mozstd-trackwhite-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\block-flashsubdoc-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\block-flashsubdoc-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\social-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\except-flashsubdoc-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\except-flash-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\except-flash-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\analytics-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\except-flashsubdoc-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\allow-flashallow-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\analytics-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\allow-flashallow-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\except-flashallow-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\except-flashallow-digest256.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-unwanted-simple.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-unwanted-simple.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-trackwhite-simple.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-trackwhite-simple.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-track-simple.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-track-simple.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-harmful-simple.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-phish-simple.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-malware-simple.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-block-simple.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-phish-simple.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-malware-simple.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-harmful-simple.sbstore
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\safebrowsing-updating\test-block-simple.pset
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\EE197B20CAB0419D1C0BD23EE03034F880EDC296
image
MD5: 1216367b580669a9bde37f91f66b57d7
SHA256: 2e0332413d19fd4d8140b9edda82fc514182c1fd301e143fbe56430e6c131265
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\8BCFC5F995406F8C1C2047E9C041B952FCACAE38
image
MD5: 64f00df93cb12985a0c591928b9f3279
SHA256: 7e3c38290c53e53f2ba32e454a63a8dd078885b5cebc15f791dd3218eb38176f
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\extension-preferences.json.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\addonStartup.json.lz4.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\E8A0BD36458D4C96F8BEF3E2CA3C2F7EC955137F
ini
MD5: 326a60b1d9017368c2ca59c2d8dae329
SHA256: 7942ed9efec55aa67492cd6ff2483d83de068a8f31c7de8611694f672d694e60
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\ACF2BF134D511780EB7EDFB70041A98F72DAF629
binary
MD5: 3662f554264cc3cd30113c9ed9ea965d
SHA256: bbc4a55a4be0a5f67b4ee7426b58aeb5a79e27ae8ab31bb959c134e279d268ca
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
sqlite
MD5: 6e245366e883aed090fb2d9c0df56490
SHA256: 18677408e50ac2eb4332d97a7535d2aca0adff235bfd45d224b31a26067d7199
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: c86c2e46097d15a30befe63ee3cc7c13
SHA256: 720ab8bca6107066f15c743fc78aa41e176f228579049cae6fa51af587a6561c
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\extensions.json
text
MD5: 2e70c22c0b90d8cd9d120b9336d162cd
SHA256: 8d5cad6294be93a5a084a591dd14fdee1b0bdea22712d1a51168271a90718aed
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\extensions.json.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\containers.json
text
MD5: 94a3843fad8c45c48b0e07342df3dfdc
SHA256: 854ff2076f71097b030c302a1ea71d8e851d2920b9ff5fc8dc8f16c91ba95b72
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\containers.json.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\0711EB74CC9D4D933A4B7EB6050318DF6F375942
cer
MD5: c99307a3ca7ceb58d9e6a875298b1f0f
SHA256: 0a190f6e6423591cf28fcfa1e6c3c3716d62f30b2eb68afd643027cdcb63b2f0
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\addonStartup.json.lz4
jsonlz4
MD5: 73b984efebc2fb9d4c403cdcfa1a62d0
SHA256: 89a5592400ee2933bbd6abd3dced8f7c3281139f59ddb3a8f674d4e15cfe84b5
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\extension-preferences.json
text
MD5: a3550cd95ea12c5332c2044f9aa91091
SHA256: a01aea70e6542424cf75ca23cad25dbfeb9a18148cdcf8255eee4d1b8f9a865f
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\search.json.mozlz4
jsonlz4
MD5: e18a0cf7522c90a0d9e5b392cf00b12e
SHA256: fa10c39d97488b86a088b78dcdcfae6b95de620770488e0e86fdaa1858c8a852
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\search.json.mozlz4.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\0861843F5BC67175B837834E080994F2D5261F6D
der
MD5: 4eb91f3faf34f19f3b323e59ff940066
SHA256: 8bb926ea607e0be8a141e6451f5878c430e131fd1362161b3e266cf8bc741c86
3644
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_ClojnfdzOh2ThCc
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\74475FFD70DEACC06F0A071A3DDB782D22CCDC41
binary
MD5: cc01e48931618ebd7edca64bd1c2ba5e
SHA256: df85e7be8df226429178f24eaade40d0f944679789781f30585cf9cff5af3ee9
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\CC23F944333E8CE7D2CAEA7AA93D7A20C7693127
cer
MD5: 0819d333e9095c4349be7705ce5e0cc4
SHA256: 9607e17b6fbec110dec56baf548f71f147ca4e8fa7396c8f6ba1cf9a750a6cad
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\BDB32A8E7170D9D10F5C5FE41F8132AC350A1472
binary
MD5: f69c0300cf9caa836e76f79a657b3d5d
SHA256: 0768352c224fe68202e47afac9c261d2e399f23d526616d7a11165460b86ffe1
3644
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_UKGETpDp46Nh7zs
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: 2e7632699a993d060a52a6a6979f477d
SHA256: da51069b02ee5a1a377cbb11d035b9f8d11ec9feae7fd6194f163b5c8bb2385b
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\CC272A84C437C06018182F241F266FFC52770F69
binary
MD5: 2a3e51d7cc85b61c0633643c558e9302
SHA256: 27e3581b27f944d395b9e8ace4336ffc79316bc2ac15df8de909f88f1ce4fed8
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\B548B1C9EA6404D183170E0D4B13A2817A2E4338
tss
MD5: f89e1bd25f0dfa9ab86ac23d8ee043ba
SHA256: a904fea0a574306e6218498649f72ed17203a38b800817afc4d19e7bbacab0f6
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\CC23F944333E8CE7D2CAEA7AA93D7A20C7693127
cer
MD5: f921310b80505cbe0a74368be04f2e7a
SHA256: fbdf0e746f4806e65ce4191d9858e8314bc35def67fb5d75de1a7fed58f3fd59
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\C7BCCD2D2CA294B38AE834D818CF5D5C0C7A65BE
compressed
MD5: d66670ee12956e1d0abf16853420ca54
SHA256: 1ed95984c2cf46b2b54730c0c6bf5888d3e009dd73b93fbadcbeb1b3968134a4
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\89DBE1DF558BB8439E2062ECC3272086F2E3FF1F
image
MD5: cb684f9773b4702b450ab8d3c223d499
SHA256: bb4dcdb2336944c75fa58810b17781c8f88e8a862247bb4f004f065b0cb1dd1a
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\EC27CA7D00C8F0121657A9E74A034C840089341B
binary
MD5: 18083179b18cc4d578513e74c67e6392
SHA256: d8b63a93448ebd7c1a77039a853540a41648d5c38103bcb7fc0b6014db3ae6a5
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\D5D7B247774E63182A9E2C82B62424AAB64C79A8
image
MD5: 79bdc890e36069c665ddd7c54f19aec7
SHA256: 927e0317115cc7c94402c31694d7eb0242ad181c45bde6151b05fe3087532dbb
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\A38709FA9C12948DAE5B4FF7FC59FEDC318136C1
binary
MD5: 1db5febf384979162bc18df50553ccc2
SHA256: 55ff23d7222ccea0defcff083f9d2bb50a1741fbb4e8fbcc9a107ee806cbf08d
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\AE3BA9E618B9FB78CEB4D8E1F504C5E757FB0E33
der
MD5: e0daba7596ecb329706981731d063ac9
SHA256: f76ebad5c5d5cf5e9cad2f7dc221eff54c62ddd6395c86746ec18a7f4492751d
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\996D20D018E4F7762222CD38EB107482289071F3
woff2
MD5: 6ad9e7fafe851a4053d8ee2e266afdb8
SHA256: dee0a946a5dd2858691694c527b5a39c50c44f90c2378312bbed8bfea8f08359
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\9DF825CC78A660D81D571A4A46F060676D7CF4F3
woff2
MD5: 62d2bc0c05a33fc060eb0d02fb1cba71
SHA256: 54b9db27f5eac86e02d2d5ff1ac33e8bfa5ced217cbedd16e7d3c501f02ce1b3
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\B9667D755101C1D21E786F253C654BD086964020
woff2
MD5: e12bbd174057c898665d8973bcd092c0
SHA256: 6e62362bc13cab3650852a9ecfac55087990874a370b694068a829c4f2c9a397
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\D68CAF7DF2821B6FF8FA7C896445E3FEDF710B49
woff2
MD5: d2a169abfd44fb8e880f4c67c460096f
SHA256: 8b1a560ba2d56540c35f021d09da6e895af74994bb5ff8d7109097a92183690a
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\69B226E39F064285D2B81C5DD987C26B0DE17DDE
der
MD5: 59f61f5bb974047dbb5123af049e42d2
SHA256: e182ff232bcfa2d4a64029bda11cec8fea8447f8bd3dfc343b564d6f97fd7166
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: 22295f024bf91d65c170c5ad85ebf1ab
SHA256: ce0759bae8963bdacbd1bf54aec6ce192ab8dddaa5d60c4f573dfe53b26a52eb
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\B6624C6016BE3D610BAE61266C13D445430ABA78
binary
MD5: aabb05549563c99e933c7de7064158f9
SHA256: 5212acec240e8b42833cfcebbf446140e46b599a8378b98ae7f03548fe129e25
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\extensions.json
text
MD5: cbd437c17f573b0fbf3908c7b94a4d60
SHA256: 15a53dc91ef70d13741e0c36df9409c30f64fd6db056fa4223023e311414becf
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\C664ABAE6A070392F60C7BFF721450AA0CF7DBA0
binary
MD5: 16fe3f175b9d8f8c43a61ba43e45fea8
SHA256: 04ae081c9b3133a298e6cd4d4ed4019e9312e100aca695c2e28766f04d6f950b
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\startupCache\webext.sc.lz4
binary
MD5: 3f251a4727336c10d33761eeafce9e46
SHA256: 76b42880c3f506d91310812890ce25699109486e3054780dda782c350e207005
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\4F271EF68152B94F2CC248CFCF902D80F159FB01
der
MD5: 7515dc58ac376a878ee804f496fafbf8
SHA256: d68d7cc2e06158599ccfda58a43ea9a6204b9528a8e914b2726a95b983ad8986
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\CC23F944333E8CE7D2CAEA7AA93D7A20C7693127
cer
MD5: af234c757dbb46625a996ee6c6aea64f
SHA256: 36e2e02a01f40d3ae38cda3b025cbea259c35da0fd402b3be257872f6ad0f34a
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\886A66C00E4C95EA49CEA079E33501561803AFC4
binary
MD5: 07483dd29fbfb20760f02ab4af79befb
SHA256: e3b6a07e67d02dde5718ee993fb6af429af4d297c3a7643e5f78175adfa243d4
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: dc7589366ea596a7d962f2ba4c55beee
SHA256: 933738c5c91f831971e9f6a5acf672441948b18e6f917d8296f1a6ec7516ecb4
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\handlers.json
text
MD5: d800e9ab0273862f33dcc591790698d5
SHA256: bc7344bab6ca4d308e1c379f23ef331f1bc221781aa0dc2b2f1d6f04d551607d
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\handlers.json.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\addonStartup.json.lz4
jsonlz4
MD5: e383e40028b4853a297ba4b670d137f1
SHA256: 97411ccdb77b73021d52d8640395f1d2515913e6b0d6beb6d659fc639b4601f8
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\extension-preferences.json
text
MD5: 07b8f0ce26bf4ae15d6585a8f9da7445
SHA256: 2782b8d7413efa779f483789bc913f919b1bf08da6c1ccad8bcbded82493f890
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\addons.json
text
MD5: 55b5026150dc3a60d07b8bea2ae0f983
SHA256: a13174f20dde2249a49853d6eae20f07ffc4ddf1e3007ab3e4911e511ecffc1c
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\addons.json.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\179977EC1B5CF43A769203F2E63E4D2CCB00C0BE
woff2
MD5: 6bc784cb2861ff885f312fbf793e91b7
SHA256: fada0fc37b57b5b7a3db68dea9207217f7782a624b91d3d880f4c726ca82f03a
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\search.json.mozlz4
jsonlz4
MD5: a1ef06be25e86a8a2002100fdc710bd8
SHA256: a80838dc680fca4ebad1916883248ae26421d530cd4564040c5f18252055e6be
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\4903E7ABE348ED39D98D1C844FB81A906D5ECA16
binary
MD5: 3a270d75ce78ab42cd1b9d77e00f25db
SHA256: 318e77d571fbc3e866ab20129ecb26e912f676e22d23ae2e705e8534835cd6cb
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\5C3B1B4A3AF3BDDFB5E032BA9BA685FAE38E7418
binary
MD5: c23ee3ca1e6b2ddf953a3173249c7660
SHA256: 69886579bbe97e8455af61ab6e9a5d370fd5c9735b19d85a25c4ff7a76083aaf
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\6D730121FD763F5F1F5C0FA06E1E8AC73C97591D
compressed
MD5: 746f2125647d69e85e953080010b59cd
SHA256: d24629d4a6493b62ca4993a128f3f2821e7ac9d8e6c2f2834974fb4fca03c7a0
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\B6F8D2A797B257A0FA38E0B262ECF974330E267C
compressed
MD5: cd56d36b0db609d3f7e22da67c89c507
SHA256: bc987d3f4a1338566e758b9363d95035bea9f2c6c5143563359e84107b4041b7
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\F8B51D2EC10AE9A943F8F24B1B1561CF237EA4EA
compressed
MD5: a9981d472e9845f097a867a4dbcd6176
SHA256: 5ad76d84ba7866ad1c7c0810f0ee2aae28f562baf355d9e515e26ba176454a98
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\340A10D652987DF5E54312E31F5C22F6E8DBA574
binary
MD5: 95af99e11d31fce85a38921f82694116
SHA256: 13c554cd1bf16da64c1f9bd5248516508685cac9ad0b9399c50b79848adb9f85
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: 830eaee92ba958b6539005d1a70529ef
SHA256: a26b5b98fa2c8b7f7f6826341200b8d42b1f26d08fd8294982153e354973eec3
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\A02D5AC48AAEBEAFEED63256030E5B9CD1889379
compressed
MD5: 711922dd942572a73db13925c8c8adc7
SHA256: d2b001aec7ffefcde4d105254674625a241cacc253a39ad59bc7cfa84fcd5c34
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\5F34A74D1380D10E61240C4B94321E6D5B7812DB
compressed
MD5: 48ffe28facbe45f289108828d6d60bbe
SHA256: 71802aba1072f35194094fe3924d3795985be3fc2cfecc0062ae6555d8cfb7b1
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\A698B6CF98F43F9B0EE1C1DAF3F2CB9BFF09A47C
image
MD5: 6610dd43852b1298343f751c84a2c064
SHA256: dd0020298ac76221e58172e54486213d78f438bba57e1c488b517c41d65cc86e
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\CAE566E3161122A04E6BA32CE31F3C402C71E694
image
MD5: 3a65465df5fe7b81429bdc2f65f2686d
SHA256: 859dbe78b2de471e17b79a586f05e437f8b6889f06fff3d0827d8f1484b81b99
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\44BA9A5AAB74A795209F8B1E91F45308B9E2D97C
image
MD5: e8640c98ebf00ec64014edc50e739f64
SHA256: 9a2a68d7ba480febe1cd5b377798ab554328c57cfdf13dd3d00cf36c52e51391
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\F8E127080251238867CB977D702209BC567B58B1
compressed
MD5: 1fc3493e16ffc0ef94103bca075c0191
SHA256: 20ad27937725dde5918ac94290f7a13f9076ec8713f943f9798f8655cc11b4cf
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\909126A7418CB20FB71D5D9693729771B68F00F2
der
MD5: 54f29568093c2bf4d7526e8402b5a163
SHA256: 48072e55b2bb4311c6097028759e1a5227242e3eace83fc14d731e06dacd01b4
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\BAEE5929C302B628351F8A770CA24F6C3585A52B
image
MD5: 35dc7b1dd638e6bf92836c3f74d536c3
SHA256: 7eca77b8120f4d4dc3550ae1eaea3f4fa8afb70949d369a23d3e645bd53eb707
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\447E62EE439AC61BDFBDB92986DBA56D2E79ADD8
image
MD5: 930510219081c3b6d4543fb57751c15a
SHA256: e3b8369cb1188a9553f40ead2194ac3df505607a757e0e318454016ea1375997
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\B6BAC957D639A5D3ADE0DD634B4EF2F9A9F3F0A6
compressed
MD5: 50877ed4641e1632fa94fbfcc41e958b
SHA256: 22d2224a18fa2b4abd391b46fbb1614f014049535dd8885ce4a7ad0f90ccd91f
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\1BD8AA08FBFE98073C4F723CD30D3F74E2CB5280
compressed
MD5: a8e584f13cbe62fd76c5b901bc7211ec
SHA256: 14e3b9993dcf2c8e123061e626badb476a2604dd187f1bb1f5de4f9cd7100dad
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\78DBE55782B7B81AF853B4884323B48C34429A53
image
MD5: 2a9c83abe580d0bc3669ee8e35ec881b
SHA256: e5e5baf88440dc42d2f6cc76efc3c7a57616a1198722f6b8598bceda62553492
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\699F6E253C1F02CC93AA746715E04B1168F0C3E3
compressed
MD5: 30e7c68a645dde102e8d1800426d3207
SHA256: 09da018f146ece87540c00624cc2f06959da676b1f12b155f44dec7ec0569900
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\EA16EBF0CB8BE8C20CE276A51C18ED7C928269D8
compressed
MD5: 86f2b6cfadbf9685a42ca1f3aaa3e064
SHA256: b85592e1e5a25def6e8665e6413b71687646b6d5e2a4f268407932bbed135a95
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\extensions.json
text
MD5: c2ba70f3a0cd2defecd0cb7f49fad3cc
SHA256: 1a9977a4fe5ab256c076e308ba2975e76076bdb41eef4987418d7f180c561d87
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\13EBBFCA831AC66E651348E841C5E938184CF2AB
compressed
MD5: 40e3257f03b7114814309134616332a1
SHA256: 98e055a72fd60d4b4b767be4e228055966244618cc80df4b9de8faa1ba6129cf
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
sqlite
MD5: 80ab741d65eb19b566f7b5b7dc94d9fa
SHA256: 0ca6190b715ac21396f95a091e2563aa5ed96f1f4abd25c1734cf7b6e907e78c
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\entries\E910D1FCE8BF27F5536B88567A4DC32624377CC3
binary
MD5: acd7d964eb44b0dd5dd256ef15aa373b
SHA256: aa67dc5e14d47301449582bb466e7509767504c4494c2a607559fc496b3d3656
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-wal
binary
MD5: af2f3ffeeffe15de1ae58c6732f0b17e
SHA256: be597f17c002f56c275ddeeeac64397e049e83f4b570a38513b089f6ce1ca475
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm
binary
MD5: 4c8a7eb988ae97c834069e9b73300c74
SHA256: 510fb158ffb5c33bc84ee06c87b4df3af3648c1a26b1c80def3002feea6e2824
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: 561c4ba9537d1d01ccc429c7cdd40000
SHA256: b6b05883682cf4a860cc3198805af9b0943a191812bf751f8f0c2e35ff4cd69f
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
sqlite
MD5: 039ae5a4145f5a1841b934cc20211973
SHA256: 57e3fa854ec03f497f571b9c457937dd336daa091920e5f39134dc8e52a38bbd
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm
binary
MD5: 2b93b827214851c2e57cbb29b7b8ce1f
SHA256: 6efe0d800055f5c3485a312573decce1e97379eef3c0a5093573251aea0eed25
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal
binary
MD5: f0089bfaa856e598c0eccf2030e12542
SHA256: 3268decc28cf06d025537c43a0b63e25d038d1d436a216c3bc61f1b7b8599336
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\OfflineCache\index.sqlite-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: 3b5f4d614a5bf3bd82e6e3999a6f96fc
SHA256: 6eebf6a0884b3010948e3bcfed96c9f89b0e687e731315ed7bbdd6469ea756bd
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
binary
MD5: 2fc1b6e2e2fbd46a357e86a794a14526
SHA256: 284516572970beba209b04fb2067b7cad607552c987965c30e37ef79ca0fa885
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-wal
binary
MD5: 626b8d816c6d5a3b2da848694ec39e0b
SHA256: d82b1d7ab70bb1c7d133303e9d1fd1896f31827669df3e1a936b71eb58b20b32
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
sqlite
MD5: 223e0fbaa07aa6bb7565c3393b8b4cc3
SHA256: 2d69eb3d6a6830951a93ea3800896841751f955065b047f5aeb3dd3dbe2554b0
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
binary
MD5: b3db35cdf13100c394705a635e5fae09
SHA256: 9fc8b4766328f05a8d044a41faf168922843844cdd1fde1a78faa4c4ad0e5ddd
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\content-prefs.sqlite-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\2918063365piupsah.sqlite
sqlite
MD5: 047e666dde21d4d8bd2b50ad5a2bcecf
SHA256: 4599ac01efb33652c6771b80179a947027ffdc326db1814c5cfb12398fe83663
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\2918063365piupsah.sqlite-wal
binary
MD5: 8ac92dbf1164eb79890dab5bdd142702
SHA256: a8613a784d6037f9978643eea6a608a94d6e4c3623404b9d176bda0ce2c9afba
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
binary
MD5: 0501638bd5b3baf99ca60451db867cad
SHA256: 131a6b36d8dbc4c224c09c775719b28e8f905f3fdd0ef6842d517110cc9d51f3
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\idb\2918063365piupsah.sqlite-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\sessionCheckpoints.json
text
MD5: c4ab2ee59ca41b6d6a6ea911f35bdc00
SHA256: 00ad9799527c3fd21f3a85012565eae817490f3e0d417413bf9567bb5909f6a2
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage.sqlite
sqlite
MD5: 9497b99dc92e100072d196ea0e4ed0c2
SHA256: d186a4f915c8e5df0d48e3cfb12bafe9af28209ea2814c1ff6af248d18ae7d06
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\.metadata-v2
binary
MD5: fbbf48242310891854e55fd8fcc022bf
SHA256: 3ede6a07066d9ce447dd5e043106c454df56aed3578c9c7b89262f291e6ed61b
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage\permanent\chrome\.metadata-v2-tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\storage.sqlite-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\sessionCheckpoints.json.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\webappsstore.sqlite-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs-1.js
text
MD5: b28ee65fb5f22150cc79e2f7c927fceb
SHA256: 8c665dcad09bfeee6b648891eae8ac7d6422f79902476c6ff05d4b589f793003
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: 1f828b78a3e29bc9fee0e8ec30d3f635
SHA256: a9d7a87a9e9bff1e07ab423997e8d7d4f7c5923d9307b469b6fd7345773777d0
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cert9.db-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\pkcs11.txt
text
MD5: bac1e94346f4f965ef42e7218f84a54e
SHA256: 5c6626b8ebe11afccf317587ae17d2414a787197dc7de20ff4facff3743f0775
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: c20b6fd68c8898881e066631f7a7bd75
SHA256: 08412ae8de4a0768371b05df540ca8f9ecebd28bac2b746520affbfaa1c914d4
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: ba9f21808de1eadd951b2dea0b99ef8f
SHA256: b6c8e1c7a0b96b1c0ea33bcf323b486e40c49e637c1b1d1abc6400c5cac5c33a
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\pluginreg.dat
text
MD5: bb41a5eee03ef43a7c1f9fcf0924ea7c
SHA256: b7251b1613038b056a60bc667d0a8982238c9b784485ce2b2e5d5ab302441dcd
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\pluginreg.dat.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\pluginreg.dat
text
MD5: 6c7eaefaa702f67deea219224d48a51d
SHA256: 3f28ae0454048e490f65886bf07f5beaab34ab1ebaa8c1489979a6cf2ab95a22
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\sessionCheckpoints.json
text
MD5: ea8b62857dfdbd3d0be7d7e4a954ec9a
SHA256: 792955295ae9c382986222c6731c5870bd0e921e7f7e34cc4615f5cd67f225da
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: ddef2857774cf727f94905b688340e17
SHA256: 7ea697061b396f4e51e99392c2c006acc2122fc9818869a3cf4d4f8d15aca9fd
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\extensions.json
text
MD5: a5e2800811d1383c07234898d520fbd8
SHA256: af55be653a92bd405d8828311357a14f45066e98296cd237330312f2ed95009d
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cookies.sqlite-shm
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\permissions.sqlite-journal
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
text
MD5: 0e2eebe5e0c1716efa54a33091baee11
SHA256: 9902ad42789bdfa28f24888e973e09cdd3787be088646509f3458989bf049201
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\installs.ini
text
MD5: 6768d5b44915d2c6231b18b238c7e36d
SHA256: 9e41840168eebe958d40259b9a737972a05c221fe03d2cfd0cfb5c07df13188b
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\xulstore.json
text
MD5: 183994dcbff834aa9b3088867d27de7c
SHA256: 2f82c9b7982ac2488fb61ca6b97e3674382eb40fa43a0e12f957ba8eb72901cc
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\weave\toFetch\tabs.json
text
MD5: f20674a0751f58bbd67ada26a34ad922
SHA256: 8f05bafd61f29998ca102b333f853628502d4e45d53cff41148d6dd15f011792
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\webappsstore.sqlite
sqlite
MD5: 446fbaa8b14b3c86bfcef8be65ee7d80
SHA256: 47dbd4af1ef0e76fd0fc756d4f3a397c251f63cb1b71b1b4405fca69c1ded6e0
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\weave\failed\tabs.json
text
MD5: f20674a0751f58bbd67ada26a34ad922
SHA256: 8f05bafd61f29998ca102b333f853628502d4e45d53cff41148d6dd15f011792
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage.sqlite
sqlite
MD5: dbd05dd2b9f5d1eda545a1e9a7633c57
SHA256: ea9a021f32f2d6843130d22e9c97831bcb75de8e57c40f5114d799afece0bf35
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\times.json
text
MD5: 7929ebc421c01545bd31e7a240642929
SHA256: 47dc332ba6b154f684848493cc7b1886d714d40b875c9c8dab3f1d3cbdc36124
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\Telemetry.FailedProfileLocks.txt
binary
MD5: c4ca4238a0b923820dcc509a6f75849b
SHA256: 6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
sqlite
MD5: 03f94eb2280d552fc63a5e989db6e9b0
SHA256: 447ad21ee804dcc92f5f679163488f4b8a7badaa49af587d71eb103340698751
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
sqlite
MD5: 489c022454909460f333b279bb069afb
SHA256: f513adf09c2970b5898d4942672ef1601ec089f0be4231e797c21101db9d78d4
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
sqlite
MD5: 4a2e7ea7ff01e9317ec51bec4de7eb71
SHA256: 737e63fac5c60dd26c5073b6c346c429434c3df2be6a7220323a314df2bf5c27
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
sqlite
MD5: a7ef12acabc39f008d786f0faf3db7a2
SHA256: bb4f94694b53f728158684ee8cf076929bc3b18331ff01de210347b03c1fa4a5
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: f697ca00f7a0cb1c5dd0406060535a96
SHA256: ce8583df29996083087ded2e7f91d930f7d1a95aa3339275addf326fc0afb3f0
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
sqlite
MD5: f09df169052e7fc8478b297f66bffced
SHA256: 7f50f5a9395c9926963039335c225603e794e8c20c830e3c2d1f1acc52ad0ed1
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
sqlite
MD5: 37ab83439b77c89c369b307db52f6d9b
SHA256: 2ae407a453cc9131b4191a65a5d37d1359f231742e37cc341e00813e8866df15
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
sqlite
MD5: 2bb13f4da6fd9dcc0e09afbb989ccea8
SHA256: 0111f4e91f0ca15fcd445d8c628076b3af5748c081c171b2346f8beffe3b8270
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
sqlite
MD5: c4dc14853b858cc423d2e3b637e3998c
SHA256: d89706d668282246bbb3ea7b06fbcab501968f916ab4aa4f187f671558122166
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\.metadata-v2
binary
MD5: 12778684c727cacc57627b0d249f2c0b
SHA256: 4ad62a9ed2f2c3f7d59c1aaeea8512079e30be90af22fef4bf2721e0963b9ff4
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\permanent\chrome\.metadata
binary
MD5: 36fd91409594bc22af29fe7d32790bda
SHA256: 762a066726a91f261c65a3d37c8287994a5411d850f56917e8b0dc9f66e07d8e
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\.metadata-v2
binary
MD5: ef8ceceb5a89391304b80c65665a20fa
SHA256: 052caee32481059890464ee5a2040fef6c87af0ec735e02529551bc987e8a1c2
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\idb\3647222921wleabcEoxlt-eengsairo.sqlite
sqlite
MD5: a93f08c9460d98a9ea46497097e9de70
SHA256: f918c21a229ba11596ccf66397c02fa2fbec51a87f1cca0522f4041058220fd7
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\.metadata
binary
MD5: 3e098415bd83cda44cd5a7d2a04465b1
SHA256: 236ed15c7cd71c108671aad7b54d73b58d7b188163df6e97db9d67abf2ce0437
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
sqlite
MD5: 1985c7557ce41ccce454603d4c503a4a
SHA256: 81a822fb068e6c31bb4e937a34d7214ee968c5a8fa03eddb8abd01920c32a4ed
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+newtab\.metadata-v2
binary
MD5: 6ea576a1be99d1312e936e51310cd6af
SHA256: 2443973700d8255d812eabc80587ffc5790221de4a5de5f3b6e134ba76c39acd
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+newtab\.metadata
binary
MD5: 40020cc2faa14d73774db0e2a57ca52a
SHA256: f2232593af09c07a850b59c3383878e381a4a01c4b769f2af800efc4d0b71c91
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\2
sz
MD5: c29e943cb5c5e456f96fee0d49aeb521
SHA256: 409717f04e3f1f68aeeeccc97e20a03148104ce3ee781db422f0569ba7047f00
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
sqlite
MD5: 5871408f922639851ec0e61a7917eb52
SHA256: 93a9f2bea4aebf70bed6a51019405cb9a1df9e3600f9e4b6037bc04a8c660590
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\SiteSecurityServiceState.txt
text
MD5: 6182131d9f5dfbd6dadf4d8c11df44e8
SHA256: a75fc506e88316ae349d8de04570db9af5cc69db15a65516f03b7c1438199f4e
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+home\.metadata-v2
binary
MD5: 23ab4b90a543a64d9335e10466f84313
SHA256: b30378104029ce3cb25d7291fb631d8fb43becf4458382b8e85eb309313b0013
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\storage\default\about+home\.metadata
binary
MD5: 6eac8fc2b98b4e57c56ff3b224cbfe2d
SHA256: f8a129c7152dae2427b67d1c55e82df4402a0aefa4e842bcf823c6ef6c41d4c8
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionstore.jsonlz4
jsonlz4
MD5: a3b14163b657860587aaee16ec5522c5
SHA256: 425f65f1f00b6a00c3eaee2b30afc1026f74dabfd217be81dd3ae369c9f23dd0
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: 9b8cc8c261f0ccc28c2860621744cf2f
SHA256: 140602c9529a5e9dcea931dab210ab5e5c1aad5e38aeedf3211fd71bcf34c3d0
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionstore-backups\previous.jsonlz4
jsonlz4
MD5: da5a84a2615e68822fa04e81e66ea403
SHA256: 1c43e3fbd8cf850c863bba57a263da38355b9021b4a9bcc9f1d59ecaf9841ce9
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionstore-backups\upgrade.jsonlz4-20190619235627
jsonlz4
MD5: 97ce580459a943b304de43f2fca70c48
SHA256: 368f3d7911e0ade59c90b08a226f57ecf4de77421063d0478b44615a4f7c9f2f
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionstore-backups\upgrade.jsonlz4-20190717172542
jsonlz4
MD5: ccc1c77e268639576eb28953b2cc4247
SHA256: a0faf3111b91c721362c11228fc01c498277e8d071641fe7f42cfdf0de73d4d3
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\search.json.mozlz4
jsonlz4
MD5: c7390d9948042e9ac90d87a6889dd38a
SHA256: ffb0f5eff8c141ac95a68d454f404079f89141140b9edc0322b041cef172dd80
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\sessionCheckpoints.json
text
MD5: 948a7403e323297c6bb8a5c791b42866
SHA256: 2fca1f29b73dd5b4159fa1eb16e69276482f5224ba7d2219a547039129a51f0e
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\prefs.js
text
MD5: 95091fc88b533f235f07bca664d952c8
SHA256: a5264c3b9dfdf3f3514d7dc77392e0409e57f818892bc8d2b88bfb526bb24627
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\revocations.txt
text
MD5: bef8ec74021a23512d2724a28c7dffa5
SHA256: f3f0fed4885bef62a9e666dd47c41b76adb1bd63a2ab14c30e524eb5d91046f6
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\pluginreg.dat
text
MD5: 37818d9b7248f34395c2db3c0bd4b07f
SHA256: ff229e03d2ab696e81957957ea8d71280b5800a2b0f70ea77998c3fa4e98a8a6
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\pkcs11.txt
text
MD5: 7649bb6f105448170e7e447e66d8cc3d
SHA256: 687ac2de1316be0e875e2fbbf7dee4547fe0b4eff7987517d216534ef2bbc3c3
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\permissions.sqlite
sqlite
MD5: 39ea44da251ca1c483ed3294299f9c86
SHA256: 593212c1409e17f114c361c59e185d6d61a0fd19af86c2a890bfb6094cc7d7c4
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\logins.json
text
MD5: e7ce898aadd69f4e4280010b7808116e
SHA256: c9214bb54f10242aa254f0758372a440c8d8f49934021f8f08b6df9fb377eb02
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\key4.db
sqlite
MD5: 0b3c43342ce2a99318aa0fe9e531c57b
SHA256: 0ccb4915e00390685621da3d75ebfd5edadc94155a79c66415a7f4e9763d71b8
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\startupCache\webext.sc.lz4
binary
MD5: b099ffa4ac560dfb2814edc139be1fd8
SHA256: 9a6a18252d6b1c5fdd7d399b5d01260fe94f671eb0f19ba45fcbf41bc107be84
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.lib
obj
MD5: f8e686a482db17ebdb9482cfc89caa24
SHA256: 02fa473df5bf436af35f2988ddd47418a2759090c905eabdc58cabc84e2adffb
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.sig
pi2
MD5: 0247346b91cfb2fdcb5ee655b1bd24f7
SHA256: 71bdc76129b97a8b63ac7768ec79157699bf74ce21f312c8b6a93dac289df71c
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\handlers.json
text
MD5: 9b266d3a494b64d3ec19fe585d0ae3cf
SHA256: c8390d32ce4e32bb263a5ca38c59d6a3608da72bed322543b1087ff8af9e2814
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\LICENSE.txt
text
MD5: 49ddb419d96dceb9069018535fb2e2fc
SHA256: 2af127b4e00f7303de8271996c0c681063e4dc7abdc7b2a8c3fe5932b9352539
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\manifest.json
text
MD5: a26609cfdb56a04fbb0e2b7630fb803f
SHA256: 0fcae47f7247f3531cf712fb4e13d3a30d687c7185056b280a13b30df88b5641
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\gmp-gmpopenh264\1.8.1\gmpopenh264.info
text
MD5: 3d33cdc0b3d281e67dd52e14435dd04f
SHA256: f526e9f98841d987606efeaff7f3e017ba9fd516c4be83890c7f9a093ea4c47b
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cache2\doomed\19067
binary
MD5: 3023ef40e099d907b2b0425e25d955e4
SHA256: 27c3ef27bd341fd73ca337cededb5cbbb8c1c199cdf5f0631e6ebbecb359f117
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\formhistory.sqlite
sqlite
MD5: 60b51ba20224ac3783e213ea9f55f125
SHA256: 0e305ba02985f26b29b234cd79d2c2af0a51085da2db2bed98d20f8c61b76254
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\features\{4b58246a-1239-4ff8-9650-839c3b3b38d1}\[email protected]
compressed
MD5: 60f708df8b2215113df57901ee314e0a
SHA256: e37e2740b600c52bdaed630d828a7d99e91566e2eeea3296f167243bb8810cc0
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\extensions.json
text
MD5: 9cf5e9e40b5f764838f42c8f2721957f
SHA256: ad9889206f043a9d31af59d6db2a74d9680930c009a560e8cd158bafa271af8f
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\extensions\[email protected]
compressed
MD5: 7721cf856c545b7ea36680d24705513d
SHA256: 5b048e1c16059d3d9b8cf91074a1da58a7e11b7741ca3e19a8b6e11be7bfa4fa
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\datareporting\session-state.json
text
MD5: 4f69e3ba16e80cf458ee28331f4490c6
SHA256: a759581ef8f8efea9664606c55a4e35c9ff1f1f1f274d21f4723358b36876d37
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\datareporting\state.json
text
MD5: 9c5351bbf9d0212293b813ee59dc9213
SHA256: 38b9c0fbd09cdcbd2703e194f1874948a0ff886bb2f46fd0edf7a39cb6d91f57
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\extension-preferences.json
text
MD5: 4e19dc99366d1124cb824af21b740535
SHA256: 25f91027becd2340f4c90e76fe5d439cd5c420e50f05b0ed21bb762cfdbc24c8
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\datareporting\archived\2019-10\1570648751052.b3b9429a-25ee-4d7c-84df-880a3c05f394.main.jsonlz4
jsonlz4
MD5: d864beacfc4ec47b0b6b74aef0b4fa06
SHA256: 95c32efba5fb8ad8803be9c415ba07bf12f9717a6c6143c00ed817639dd4e33c
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\cookies.sqlite
sqlite
MD5: 7c426e0fc19063a433349ce713da84a0
SHA256: 9925b2d80f8a85132ef4927979b25e0b9525e8317a71ffd844980b794b04234c
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.bin
binary
MD5: 5027177f513cdae07db2330e1ded5934
SHA256: 0c53f16051e738287a4612f68e296238087627e594cfd6ddfa1fecc2e998328b
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\content-prefs.sqlite
sqlite
MD5: d98c70110cb36f098c925d9143d3e82b
SHA256: f85e01375ff28aa8085ad214a2550edb7c20b147cb08db4a1a09e45d5120227b
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\containers.json
text
MD5: 94a3843fad8c45c48b0e07342df3dfdc
SHA256: 854ff2076f71097b030c302a1ea71d8e851d2920b9ff5fc8dc8f16c91ba95b72
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\compatibility.ini
ini
MD5: 88d1015305c702fd8eafc3b10fa893f9
SHA256: a3fd1a868a80e9e3a12caae1a00489a6fa03d1f0b6f388083f588e463b34c1c0
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\bookmarkbackups\bookmarks-2019-07-30_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
jsonlz4
MD5: 8b3a3845e8f6c6076b27362edb8388d7
SHA256: 4f98274fcd24d4a238a86ceec0ddd26c589ebc77ab21c4b18943d1d3ef73dd92
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\cert9.db
sqlite
MD5: 81f778dd9703205d32766ab4c3cde8e0
SHA256: 7833b6420c66c25619b9b8b1472a7faeec9582c7ed7cb2991dfd4bdb43776e7a
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\broadcast-listeners.json
text
MD5: b2b62e64121182a47880d14e697a961a
SHA256: 5daef5b92e2555d45e504be5138b2221949f602c94007026f7471dd00c4077d0
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\blocklist.xml
xml
MD5: 04bb50a80b2a49abec9e9540f6a1ca67
SHA256: ce9cf8d89739e3bd15b670f928cb996f5bf014aacb3ab891e371b20921f7f42a
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\addonStartup.json.lz4
jsonlz4
MD5: 65a8568f72fdf05a592210c52784c82a
SHA256: 353279aec0402d3777cd400ecfa22ece3e3e882cb1e57056965db44bd1306465
3644
firefox.exe
C:\Users\admin\Desktop\Old Firefox Data\qldyz51w.default\addons.json
text
MD5: 55b5026150dc3a60d07b8bea2ae0f983
SHA256: a13174f20dde2249a49853d6eae20f07ffc4ddf1e3007ab3e4911e511ecffc1c
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\sessionstore.jsonlz4
jsonlz4
MD5: 0f55c50d8786aef0c1a57b9783290914
SHA256: 2ee85346ff3bf8db6814dffd14c441305a262c2be7c61d8bbdddbd0b28bb8348
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\prefs.js
text
MD5: e58f081424192ef8791813467a154ee6
SHA256: b5a130bb687bf275ececf76248bcaf4cfe07b6d84dac2925fc6c9ad719935dd9
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\sessionstore.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\datareporting\session-state.json
text
MD5: 4f69e3ba16e80cf458ee28331f4490c6
SHA256: a759581ef8f8efea9664606c55a4e35c9ff1f1f1f274d21f4723358b36876d37
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\sessionCheckpoints.json
text
MD5: 948a7403e323297c6bb8a5c791b42866
SHA256: 2fca1f29b73dd5b4159fa1eb16e69276482f5224ba7d2219a547039129a51f0e
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\times.json
text
MD5: c79177df11cb2f6969e17c99dbbb607e
SHA256: 0c83c23afbd255d89d428b4aec75918ef9222ca9ed5bd2ce1d491954327e33bc
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\datareporting\state.json
text
MD5: 9c5351bbf9d0212293b813ee59dc9213
SHA256: 38b9c0fbd09cdcbd2703e194f1874948a0ff886bb2f46fd0edf7a39cb6d91f57
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\times.json.tmp
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\logins.json
text
MD5: e7ce898aadd69f4e4280010b7808116e
SHA256: c9214bb54f10242aa254f0758372a440c8d8f49934021f8f08b6df9fb377eb02
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\formhistory.sqlite
sqlite
MD5: 60b51ba20224ac3783e213ea9f55f125
SHA256: 0e305ba02985f26b29b234cd79d2c2af0a51085da2db2bed98d20f8c61b76254
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\bookmarkbackups\bookmarks-2019-07-30_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
jsonlz4
MD5: 8b3a3845e8f6c6076b27362edb8388d7
SHA256: 4f98274fcd24d4a238a86ceec0ddd26c589ebc77ab21c4b18943d1d3ef73dd92
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\key4.db
sqlite
MD5: 0b3c43342ce2a99318aa0fe9e531c57b
SHA256: 0ccb4915e00390685621da3d75ebfd5edadc94155a79c66415a7f4e9763d71b8
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\times.json
text
MD5: 7929ebc421c01545bd31e7a240642929
SHA256: 47dc332ba6b154f684848493cc7b1886d714d40b875c9c8dab3f1d3cbdc36124
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\cookies.sqlite
sqlite
MD5: 7c426e0fc19063a433349ce713da84a0
SHA256: 9925b2d80f8a85132ef4927979b25e0b9525e8317a71ffd844980b794b04234c
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\favicons.sqlite
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\places.sqlite
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\compatibility.ini
ini
MD5: 88d1015305c702fd8eafc3b10fa893f9
SHA256: a3fd1a868a80e9e3a12caae1a00489a6fa03d1f0b6f388083f588e463b34c1c0
3644
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\times.json
text
MD5: 1476df8f794a698d40bb7dfcee1263a4
SHA256: ed6ed3b5e8d9615c007d07b64512827026844c8f3a7fa082bc28925f8747d58d
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\b3b9429a-25ee-4d7c-84df-880a3c05f394
text
MD5: da24b11310fe8f1f0023b4f07e2320ce
SHA256: c09a22556a0ac25e0f819338d6e90f33a29ddda9138438caf5eeab601c57cfb1
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-10\1570648751052.b3b9429a-25ee-4d7c-84df-880a3c05f394.main.jsonlz4
jsonlz4
MD5: d864beacfc4ec47b0b6b74aef0b4fa06
SHA256: 95c32efba5fb8ad8803be9c415ba07bf12f9717a6c6143c00ed817639dd4e33c
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\b3b9429a-25ee-4d7c-84df-880a3c05f394.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-10\1570648751052.b3b9429a-25ee-4d7c-84df-880a3c05f394.main.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\aborted-session-ping.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\aborted-session-ping
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
text
MD5: 4f69e3ba16e80cf458ee28331f4490c6
SHA256: a759581ef8f8efea9664606c55a4e35c9ff1f1f1f274d21f4723358b36876d37
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: f697ca00f7a0cb1c5dd0406060535a96
SHA256: ce8583df29996083087ded2e7f91d930f7d1a95aa3339275addf326fc0afb3f0
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 95091fc88b533f235f07bca664d952c8
SHA256: a5264c3b9dfdf3f3514d7dc77392e0409e57f818892bc8d2b88bfb526bb24627
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
text
MD5: 183994dcbff834aa9b3088867d27de7c
SHA256: 2f82c9b7982ac2488fb61ca6b97e3674382eb40fa43a0e12f957ba8eb72901cc
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
sqlite
MD5: 39ea44da251ca1c483ed3294299f9c86
SHA256: 593212c1409e17f114c361c59e185d6d61a0fd19af86c2a890bfb6094cc7d7c4
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite-shm
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite-shm
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-wal
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-shm
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
text
MD5: 948a7403e323297c6bb8a5c791b42866
SHA256: 2fca1f29b73dd5b4159fa1eb16e69276482f5224ba7d2219a547039129a51f0e
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
text
MD5: 6182131d9f5dfbd6dadf4d8c11df44e8
SHA256: a75fc506e88316ae349d8de04570db9af5cc69db15a65516f03b7c1438199f4e
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 021444816a799c35f446d3eea2d40f0b
SHA256: 9c8124c21d337e103f7cdceadb0650abb4c5669839a9d72576457d50030b977f
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
text
MD5: e6c20f53d6714067f2b49d0e9ba8030e
SHA256: 50a670fb78ff2712aae2c16d9499e01c15fddf24e229330d02a69b0527a38092
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
sqlite
MD5: 81f778dd9703205d32766ab4c3cde8e0
SHA256: 7833b6420c66c25619b9b8b1472a7faeec9582c7ed7cb2991dfd4bdb43776e7a
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
jsonlz4
MD5: a3b14163b657860587aaee16ec5522c5
SHA256: 425f65f1f00b6a00c3eaee2b30afc1026f74dabfd217be81dd3ae369c9f23dd0
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: 03848c129c3351eb46f552992c355bda
SHA256: b9abe3967d01f9acf1e466a3130049039e687417178f3e9261ca436ed108592c
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child.bin
binary
MD5: 53bab10f85e0e0b269baa663c5a1ca4e
SHA256: 0a502d40d971963a960d0c9764951ba1f01757bf494fe6326ba5aaa768dc6f77
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-new.bin
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache.bin
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache.bin
binary
MD5: d5fcc1e35836ebf457a5d00cbb065d55
SHA256: 423e895cf927ebf26608bfa3129a4169e867ff961af1083d90a84a30eb85b3a5
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-new.bin
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-new.bin
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: f9345676ed8c74aa336b7f58d4dd763e
SHA256: c3c85ab1e83c4c18ca3800e216b1f6019689832ac82a43fddecfabe58e696183
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C9C43FF94BF75078752A25C37A0DB5285DA4C7D7
binary
MD5: d1f025b460d86320b19496d24f93358a
SHA256: 7d551e91c51e3e4669443d88db884e4802474bd467e19ca4108912d00a4888ce
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite-journal
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\ads-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\social-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\analytics-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-backup
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\social-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\ads-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\content-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\analytics-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\content-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-trackwhite-simple.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-track-simple.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-trackwhite-simple.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-track-simple.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-harmful-simple.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-block-simple.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-block-simple.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-harmful-simple.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozplugin-block-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.metadata
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.vlpset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozplugin-block-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto.metadata
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto.metadata
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto.vlpset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto.vlpset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto.vlpset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-downloadwhite-proto.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-downloadwhite-proto.metadata
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto.metadata
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashallow-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashsubdoc-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashsubdoc-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flash-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashallow-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flashsubdoc-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flash-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flashsubdoc-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.pset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C3F34DC32AE76AE938048CE364E9443F972A0FE8
der
MD5: 719bf8cf894857022548ed9ae8480ab0
SHA256: 25adb3bf85c9b54bc48339dfe973539f46ff948cb68408f08405c1d205ff97cb
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 49a1ef77e011f0c5786ff7b4f6c27770
SHA256: 50cc45df6e7c661d4aa5b0ffac88f160acbf57a2d77cb84f75223bc7daf6e3b6
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto-1.vlpset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto-1.vlpset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto-1.vlpset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto-1.vlpset
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\thumbnails\3b73552d647f56cf33b839c2fcb5541c.png
image
MD5: df6ea8e7a653fd4c29ab47472d20a159
SHA256: 735ef20723b7774ad911ec4da7abb8939235a96150a2bae7b88444eb2cb58115
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\thumbnails\3b73552d647f56cf33b839c2fcb5541c.png.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\broadcast-listeners.json
text
MD5: b2b62e64121182a47880d14e697a961a
SHA256: 5daef5b92e2555d45e504be5138b2221949f602c94007026f7471dd00c4077d0
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\broadcast-listeners.json.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 0b316444a2b05423bd3f9fdcd20fb914
SHA256: 89bf59d1023a1f4108349041bd84c413aaf1404cd2c1d3950a4b5241836702a9
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\A79369F2BD417DFBD4DFF62C1A62841C1CED1C98
compressed
MD5: 6c9f4eb8185844bf3004d40afab891d2
SHA256: 47f6038f26438cb1b401d3aa362274be429fda916a7222985167ee5590b41676
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\3F6A9E17FA9140F6954F43141BCA0696A91A69EC
compressed
MD5: 98472a655db27854303d9a25983a8e28
SHA256: ee501626d24f7ddce53ed89b673669e7e6ecd737b374db37264ea7a49684043b
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\doomed\16258
compressed
MD5: 35c0275c7aff69c7a4a46024fe175817
SHA256: 5a88aff7348226e3c79a800c8d25a2a055d06e73244debc95476708c2e5bd4d5
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple.sbstore
binary
MD5: 3675254e341df799d4307c1f59109185
SHA256: 23d108134bed6099793f7dd6b8b6e62081ec3b945efdbc7c5e0e779fd9b82f98
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-block-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-harmful-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-block-simple.sbstore
binary
MD5: e2cf527ca7550b7e7bdf7311e483a2c3
SHA256: f1e07b1d717433f47073dc54a7d98e3e87b3d0fa88e53466f93ea544af885d11
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.sbstore
binary
MD5: 2ad4445da23a8e50d667c09150cf1876
SHA256: c1550f9dc8f675c7ff2c896ee91c839e4e2b243e759d71c128521c17f53e91b1
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-harmful-simple.sbstore
binary
MD5: 051fb32dece757ba112ac36dc72e3a91
SHA256: 0806d98fb3de55f75d7c0b17e26146567e08c483031526659a4a35d09b97ef19
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozplugin-block-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozplugin-block-digest256.sbstore
binary
MD5: d6acf2573e12afdd7939568804d3fcc1
SHA256: 5525cbf8f8dc41d19ac632ed324e55293a510ae0eeba16d0e3f33c707aa58a0c
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.vlpset
binary
MD5: d9e28d043d05a069ac7962f181a05337
SHA256: efbb9ada8e5f662779444e4de88ce944036b7c73d61acfb70239f809dd153aa1
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.metadata
binary
MD5: 6ee2fe4d5c3460929a4eec3138d76e8e
SHA256: 1bd0d3301b97fe608243e61c8fa114cc1ae9b69c0622a10cafe5cc1814df3b7a
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto.metadata
binary
MD5: c0ff29e2429d6a67594d829b166b9d0b
SHA256: a8ab69af442ae86af43f2a3bf22b91341377be23874762de01e3e71ef08f0318
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto.vlpset
binary
MD5: 8996548565a96f6ba34bc8317fb4f09e
SHA256: f760f51c58a91fcc264b8d27f610372ad510209eae6d0911e0ac236e7405fdc8
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto.metadata
binary
MD5: f57521d4d31b44fbbb74ba8f2441f52f
SHA256: fd6f2adcf2bce0ac48f15b6a67110e24ec8d24a566422512df2269f2cfac7a0d
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-downloadwhite-proto.pset
binary
MD5: 7655fffe7cfbe1ebf96afea5fe2e1376
SHA256: ff2f663c4e453706b7817109f6a43e8b3389e8cfb1b7d64aace2bfba45f3a359
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-downloadwhite-proto.metadata
binary
MD5: 498dae4e538658a57f464748f2dabfda
SHA256: 8778f52cd9cb4f4787bf7ba18006d212f8c3004652d163f7786556a8eef3a067
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto.metadata
binary
MD5: b4d69f529bf6d261075d04c6a5c56158
SHA256: 2794c0426aa721104df6a8615d57a251af30a79865cc69e369ed41cae4ea4ee8
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto.vlpset
binary
MD5: 93fdf288da71b455cfcb53f9e78add2a
SHA256: 017ed2622f8e5e1d72df4bc872bcf81ccfea9681aede1afdc7f3ddac800b0cf5
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashsubdoc-digest256.sbstore
binary
MD5: ba0009932844173bc8f9af264229df24
SHA256: 66d1c00c04d86e313e9a02775cdf906b1be8d4cd6bef423a1b9e21cc4e9f50c1
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CC23F944333E8CE7D2CAEA7AA93D7A20C7693127
cer
MD5: 3c8432337d9a600d2d825e51a201fde8
SHA256: 891f71ee166ac5b97a24867deecc7545c78938c646428491d5044c16269304a5
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\28CD555C8F67F41397D93F6119AF6A2902BC6057
binary
MD5: 3a8076af591d8f06c568e086f0b04b09
SHA256: 108026db5f9bae053e0743c1cee7b4035e753d6989836cbdd0ea45f4894d9e7e
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: d436f8b00e6f1c605784e1e899bde2ca
SHA256: ae86558f99e3324bf8161cff08f82bdbdf0fca589e9aa9a7c7998d1d7ca52b58
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CC23F944333E8CE7D2CAEA7AA93D7A20C7693127
cer
MD5: 641307a86fd10999766a9c59fee9cc91
SHA256: ad6e0cad4ea6ab42a99380b4f50c230cae40fa3f8cf5da602975c0075b42b35d
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8D803A2E86C36C92675CBDED174B919329D848E4
binary
MD5: bed3c075451b027fd5bdfdad052bc45e
SHA256: 5016360ccd18dd8a33cfa2211cbd77523c57d00c634cef755360b9a526d47341
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
text
MD5: bef8ec74021a23512d2724a28c7dffa5
SHA256: f3f0fed4885bef62a9e666dd47c41b76adb1bd63a2ab14c30e524eb5d91046f6
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations-1.txt
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_JAIFxoYG24kLgBP
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0D8E16D0B115F97F1F183A86F585ED951978D83D
cer
MD5: cd03007f39693a7a7c65f1b9de036e49
SHA256: f40762fa43dd57ebb5573502018eb48d4cd592998ea00e4d86a73b6626eb8474
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C9C43FF94BF75078752A25C37A0DB5285DA4C7D7
binary
MD5: 7583a6aaa3d0a607a67984d3f8561f35
SHA256: 778bd32251630a7107412735bf9bd08a702804766a7c8dfaa3e66b5fc1854e8d
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\9A3EF8133F0FA6C3DE8D839A13E7E624CC01FBCC
binary
MD5: 6f0851da59b8330c1e4c60e0975db5c7
SHA256: 952d1cfae8d085ea12395d1c4e494e864b149dfa13d306bce8d9340bcdecca5f
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1D934245BFF92F546D1D205CC7BEBD74CC72A72A
binary
MD5: 37625926ff8dba69d575d4b88c9a322f
SHA256: c6246d08ff03667a29165fbb963dc323358373f5cf45616c57764db4b88b48a2
3772
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_diXiO2mCfXMTuF0
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: ba71b94f2ea2946daf7872ae67b89fa3
SHA256: 6899f5bfa57e70de12408a25c0f97f0cd95b2b4e20c55dc338ae4da8b34f33e8
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CC23F944333E8CE7D2CAEA7AA93D7A20C7693127
cer
MD5: f934865cb14d917feb512e21ff8c539e
SHA256: 1b7bd59828f981bb683894a287dd8c3f58cb61a909c61caaf9e6b6902b618747
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\ABEAA48B501FBD6A530EC9F222A741DA79987BC8
binary
MD5: e7eb08762c7095878f56be98669511e2
SHA256: eef0d6d4ffed33d3b2c8ee6a3bc25b2890819fb5819603ada962cbcc4ee5a226
3772
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_kD1iAofSLg1Q54Y
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: 9b8cc8c261f0ccc28c2860621744cf2f
SHA256: 140602c9529a5e9dcea931dab210ab5e5c1aad5e38aeedf3211fd71bcf34c3d0
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
jsonlz4
MD5: da5a84a2615e68822fa04e81e66ea403
SHA256: 1c43e3fbd8cf850c863bba57a263da38355b9021b4a9bcc9f1d59ecaf9841ce9
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CC23F944333E8CE7D2CAEA7AA93D7A20C7693127
cer
MD5: fe7928c2e25b1e337248cd74c021c442
SHA256: 9c908a79ced9f3db46e5a465175291fb5dc4920bf81e29fdbe6683cc8a15aefa
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B7E10A18EE4E507A772B333D6FAB9A360F069EFB
binary
MD5: 155fd89a16bc73675bc557ffe6de6dff
SHA256: 814d497fbdaa46029db186507adb91cd83950a7241e14791ee635bd51b178a7c
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 94ed1f9eeb08f92029d0fed78d278d9a
SHA256: bdf0a1bd0a856056e6f74fc73ea682edbad34370e6f6cbf4ef1baced8e525498
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CC23F944333E8CE7D2CAEA7AA93D7A20C7693127
cer
MD5: 8e8a9c68c27a750a47039d7d8d34e4fa
SHA256: a2c4d87187738bc6016454d66f24cd5ec854f6f950880e25604b3d0a2a2e1e24
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\195113AC8F4C3A570D0244DCAB0A999329A15F9F
binary
MD5: 1e35661ea89b61c4be5b74d52939cd73
SHA256: 8c4ed8ccc1f170b473cf6d65f05d7da351e60c37a1910a644ae862b2894e0fd3
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
jsonlz4
MD5: 65a8568f72fdf05a592210c52784c82a
SHA256: 353279aec0402d3777cd400ecfa22ece3e3e882cb1e57056965db44bd1306465
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_hNgPbnBFnNjo4hX
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 037cebeb760d297aeaab94aef4d30b44
SHA256: 1a0a73e95d31deddb7da703b3d361eaebc53b6bf848ecaf97dc128b0cbc95049
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4726FEC64ABC3EA704C8D1AE92ECDBA094EB0FAF
image
MD5: 757c229c25e1e35023e75992c032fd18
SHA256: 3090e4aaf66aeec7aa56b967c47078bba88699c5dcd8fc1407a94842a6eab8f5
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\43F5BE9D212D19F7B72BCAB1F0B317A33D6032B3
binary
MD5: 1eb736435e930ba1e346ce6f1aa53ab0
SHA256: 519dff0b7648793e15b279875c4f142b73b498e4e1e5faf9d7e3dd8b43784d70
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\EE197B20CAB0419D1C0BD23EE03034F880EDC296
image
MD5: ac936bb9e654d436e65a304c82363f2f
SHA256: 49219dcf2ca701b0e6b956da20b179f6d67c13f208c72539177795609e27b9a9
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\44E59AB52BB007B2EBFD1CC3641A39306D98C58A
binary
MD5: 1367264b68834bf1dff035310b4fdc3a
SHA256: 32d9a226b17bce622ac10d57801e6cf3ed8b9d68c6532d6444645e35e35b041f
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8B0F85FC69A3E538A350DE4CC72B2CEADB8FBDE1
der
MD5: 0db966a5f220d6442824ddae151bc4f7
SHA256: c0d65063cb4153ab884bb966cb61f94ad1fccedec11ebf534f94baaac0c6ef99
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\3DD70D16428E9E67298338EA0FB25112CCBFE0E5
binary
MD5: 7444cdf83cbd1ed851b1a5854fa181d5
SHA256: a4642127368f7ca6c55437edd9d517719be984e97f57d922d33817b2475293ba
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\A5D93CC48B83C8124FEB6A2E9448677EACA5BA86
binary
MD5: 8ab79dfbb980cf32ef72de3a466484f9
SHA256: 0508d76cc39c911019bd0a65ba425d583df4e0265b75478c95ebc84407f52fe9
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\doomed\16936
binary
MD5: a57eac8c4e0d59d6d62c92b05e210c46
SHA256: ba0e89eca0b891a962786df3685c27588ad196a7c42c5218c3e2fa6873f31e89
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
jsonlz4
MD5: c7390d9948042e9ac90d87a6889dd38a
SHA256: ffb0f5eff8c141ac95a68d454f404079f89141140b9edc0322b041cef172dd80
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\A79369F2BD417DFBD4DFF62C1A62841C1CED1C98
compressed
MD5: 9e237e5e0129cc3029c94794ed47f0bd
SHA256: 99f01579627f294bf62cada850c429a69fd06d7730af5b55ffc436310367115f
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-trackwhite-simple.sbstore
binary
MD5: 65e942614eee70680464ac4be75019fc
SHA256: 34395085da32c8b4efe9959e3b0d756b43ffed17694d66f39b966cd331bd9a94
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-trackwhite-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-trackwhite-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-block-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-track-simple.sbstore
binary
MD5: 95f28ede25c301301f25fbbd9a3c56ec
SHA256: 87763df78772f7d750b0fa5a31eec23e931fd3bd1cbb33beddfc61889da36478
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-track-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-track-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple.sbstore
binary
MD5: a5695cc64d77967232b0c1344c6e72b3
SHA256: 042a22b8681d754671d2018ba109b31a53ee3728d48c6379043f8e3394e7fbad
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-harmful-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple.sbstore
binary
MD5: 3d1ce5e50208f0cb3b979186043a548f
SHA256: 1e13d05d482c3d533dc6035af2b2d6e84749412a5748d1435b70cec8b312340b
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\79DE923799996CC6030E5846C3EF10AB4CB77E78
der
MD5: 8533e813378308cfc2780c8105bd36d3
SHA256: be1124c3050e514a9f0740f1ec06835d8d528fc51442a08cce8d4df6ce338821
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_85Kp2CEItgROmW2
––
MD5:  ––
SHA256:  ––
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E8A0BD36458D4C96F8BEF3E2CA3C2F7EC955137F
ini
MD5: deabf813fe23940cb31107652e2618b0
SHA256: 5fa39e2e3e42df97ed1a6a4bb4aabac0d78e77ddff2767fbd2c5673dcf3b2a5c
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\57B84B5664F1DFE7D2BC251B756220F886F07B86
der
MD5: e6b57badbe9478f95d8541063bba8273
SHA256: ab9f55d640f06baa672a06ef37b41c3cc26e9a1622b19d0e18049ac93efdf245
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\doomed\20976
binary
MD5: e2ad220e176539d8470f5661a7777caa
SHA256: 48f6f4550310d8a7a573960035008a92744fd448be98fc836612c5e9c5e51938
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashsubdoc-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashallow-digest256.sbstore
binary
MD5: 6f85bc4b2ecb49e26b0bd83a821065d0
SHA256: c0b3bc9b3dc507ab654caf72d13c3aefa58c9b13b1e4d14dd8816712d80a7e54
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashallow-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flash-digest256.sbstore
binary
MD5: c921d8e98fa01b4f303481e112202e92
SHA256: 4ef1038730ec8bc7206713c29a936768831b922c5e6c83355fd62d7401d8c1dc
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flashsubdoc-digest256.sbstore
binary
MD5: 04824a1f92353f43ebb9e7f74b7476fd
SHA256: b48e58ebab82e4c376f16150a3fff850c1111ff1f5985d68819cfd6f0db159d2
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flash-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flashsubdoc-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.sbstore
binary
MD5: 0e8fe60ccd7e9b4c32589a5743a95302
SHA256: 2b124d4026850a3cffd28dbacb58aec28f7dcd4d40bc14e52bbe96d60ce4e749
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\3F6A9E17FA9140F6954F43141BCA0696A91A69EC
compressed
MD5: 35c0275c7aff69c7a4a46024fe175817
SHA256: 5a88aff7348226e3c79a800c8d25a2a055d06e73244debc95476708c2e5bd4d5
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstore
binary
MD5: 4a1220fc03e11726f09e9981834345db
SHA256: 6ae7fc0fdbe217104f4034bf6a580a461106b50309abccff6e309124dca5ef39
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.sbstore
binary
MD5: d886a47c89d9c49c795da345bc236990
SHA256: a03c5e2656d2f292bf5794c8eeb8d223cd6ba4f4bfb2ed1f325460e879d0bcf7
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm
binary
MD5: b7c14ec6110fa820ca6b65f5aec85911
SHA256: fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm
binary
MD5: b7c14ec6110fa820ca6b65f5aec85911
SHA256: fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
jsonlz4
MD5: 6d378e0d40b6eaca22c8bce899a1c5c1
SHA256: ada2467b2477aceff837ac7820c435ad1ebbe844b2da31c7ab9ae8d010c7a639
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: a10de96a0ea7d4bd71840c778e9e55ae
SHA256: f5b294c83e49809fe9749d6947fec49f64f2cb77a7e8b9dfda7e5e4bbb182dca
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
text
MD5: c4ab2ee59ca41b6d6a6ea911f35bdc00
SHA256: 00ad9799527c3fd21f3a85012565eae817490f3e0d417413bf9567bb5909f6a2
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 354459382f30b8994109c88659dfa1f3
SHA256: e3e8e2b7e7eeca231620d83c70fa5a926e8b9ce74c51f595f71191dc0b50527e
3772
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
binary
MD5: b7c14ec6110fa820ca6b65f5aec85911
SHA256: fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin
binary
MD5: de9496aca551ade408ef6466a11833a1
SHA256: 8f9c7fdb3e0bc01024e43a8e242468fc4dd4f74c725e32a883571635203dc10a
3772
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
––
MD5:  ––
SHA256:  ––
3644
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\kkr0c89u.default-1570648751557\startupCache\webext.sc.lz4.tmp
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
16
TCP/UDP connections
50
DNS requests
96
Threats
2

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3772 firefox.exe GET 200 2.16.186.112:80 http://detectportal.firefox.com/success.txt unknown
text
whitelisted
3772 firefox.exe GET 200 50.63.210.1:80 http://guitarlessonsvideo.info/setupconfig/rottenhellboy12.php US
binary
unknown
3772 firefox.exe GET 200 50.63.210.1:80 http://guitarlessonsvideo.info/favicon.ico US
html
unknown
3772 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3772 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3772 firefox.exe POST 200 172.217.16.131:80 http://ocsp.pki.goog/gts1o1 US
binary
der
whitelisted
3772 firefox.exe GET 200 50.63.210.1:80 http://guitarlessonsvideo.info/setupconfig/rottenhellboy12.php US
binary
unknown
3772 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3644 firefox.exe GET 200 2.16.186.112:80 http://detectportal.firefox.com/success.txt unknown
text
whitelisted
3644 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3644 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3644 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3644 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3644 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3644 firefox.exe GET 200 50.63.210.1:80 http://guitarlessonsvideo.info/setupconfig/rottenhellboy12.php US
binary
unknown
3644 firefox.exe GET 200 50.63.210.1:80 http://guitarlessonsvideo.info/favicon.ico US
html
unknown

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3772 firefox.exe 50.63.210.1:80 GoDaddy.com, LLC US unknown
3772 firefox.exe 2.16.186.112:80 Akamai International B.V. –– whitelisted
3772 firefox.exe 52.26.8.178:443 Amazon.com, Inc. US unknown
3772 firefox.exe 54.191.170.25:443 Amazon.com, Inc. US unknown
3772 firefox.exe 143.204.97.178:443 US unknown
3772 firefox.exe 93.184.220.29:80 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
3772 firefox.exe 34.223.160.244:443 Amazon.com, Inc. US unknown
3772 firefox.exe 13.32.158.244:443 Amazon.com, Inc. US unknown
3772 firefox.exe 172.217.22.42:443 Google Inc. US whitelisted
3772 firefox.exe 172.217.16.131:80 Google Inc. US whitelisted
3772 firefox.exe 13.225.78.78:443 US unknown
3772 firefox.exe 52.32.91.14:443 Amazon.com, Inc. US unknown
3772 firefox.exe 143.204.101.56:443 US suspicious
3220 pingsender.exe 34.208.47.123:443 Amazon.com, Inc. US unknown
3644 firefox.exe 104.16.40.2:443 Cloudflare Inc US shared
3644 firefox.exe 2.16.186.112:80 Akamai International B.V. –– whitelisted
3644 firefox.exe 54.171.74.178:443 Amazon.com, Inc. IE unknown
3644 firefox.exe 54.191.170.25:443 Amazon.com, Inc. US unknown
3644 firefox.exe 93.184.220.29:80 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
3644 firefox.exe 63.245.208.195:443 Mozilla Corporation US unknown
3644 firefox.exe 143.204.101.114:443 US unknown
3644 firefox.exe 13.32.158.244:443 Amazon.com, Inc. US unknown
3644 firefox.exe 34.98.75.36:443 US unknown
3644 firefox.exe 13.225.78.78:443 US unknown
3644 firefox.exe 52.26.8.178:443 Amazon.com, Inc. US unknown
3644 firefox.exe 52.32.91.14:443 Amazon.com, Inc. US unknown
3644 firefox.exe 54.230.201.111:443 Amazon.com, Inc. US unknown
3644 firefox.exe 143.204.101.56:443 US suspicious
3644 firefox.exe 52.39.125.254:443 Amazon.com, Inc. US unknown
3644 firefox.exe 50.63.210.1:80 GoDaddy.com, LLC US unknown

DNS requests

Domain IP Reputation
detectportal.firefox.com 2.16.186.112
2.16.186.50
whitelisted
guitarlessonsvideo.info 50.63.210.1
unknown
a1089.dscd.akamai.net No response whitelisted
search.services.mozilla.com 52.26.8.178
52.36.193.139
34.210.145.79
whitelisted
search.r53-2.services.mozilla.com 34.210.145.79
52.36.193.139
52.26.8.178
whitelisted
push.services.mozilla.com 54.191.170.25
whitelisted
autopush.prod.mozaws.net 54.191.170.25
whitelisted
snippets.cdn.mozilla.net 143.204.97.178
whitelisted
d228z91au11ukj.cloudfront.net 143.204.97.178
unknown
ocsp.digicert.com 93.184.220.29
whitelisted
cs9.wac.phicdn.net 93.184.220.29
whitelisted
tiles.services.mozilla.com 34.223.160.244
52.89.51.22
54.68.223.18
54.69.207.70
54.186.225.209
54.68.132.173
34.210.143.213
52.39.224.180
whitelisted
tiles.r53-2.services.mozilla.com 52.39.224.180
34.210.143.213
54.68.132.173
54.186.225.209
54.69.207.70
54.68.223.18
52.89.51.22
34.223.160.244
whitelisted
firefox.settings.services.mozilla.com 13.32.158.244
13.32.158.194
13.32.158.178
13.32.158.199
whitelisted
d2k03kvdk5cku0.cloudfront.net 13.32.158.199
13.32.158.178
13.32.158.194
13.32.158.244
whitelisted
safebrowsing.googleapis.com 172.217.22.42
whitelisted
ocsp.pki.goog 172.217.16.131
whitelisted
pki-goog.l.google.com No response whitelisted
content-signature-2.cdn.mozilla.net 13.225.78.78
13.225.78.8
13.225.78.104
13.225.78.106
whitelisted
d2nxq2uap88usk.cloudfront.net 13.225.78.106
13.225.78.104
13.225.78.8
13.225.78.78
whitelisted
www.mozilla.org 104.16.40.2
104.16.41.2
whitelisted
support.mozilla.org 34.213.134.214
34.209.95.119
whitelisted
www.youtube.com 172.217.23.174
172.217.21.206
216.58.205.238
172.217.23.142
216.58.206.14
172.217.23.110
216.58.207.46
172.217.16.174
216.58.208.46
172.217.16.142
172.217.22.46
172.217.22.78
172.217.22.110
216.58.210.14
whitelisted
www.mozilla.org.cdn.cloudflare.net 104.16.41.2
104.16.40.2
whitelisted
prod-tp.sumo.mozit.cloud 34.209.95.119
34.213.134.214
whitelisted
www.facebook.com 185.60.216.35
whitelisted
youtube-ui.l.google.com 216.58.210.14
172.217.22.110
172.217.22.78
172.217.22.46
172.217.16.142
216.58.208.46
172.217.16.174
216.58.207.46
172.217.23.110
216.58.206.14
172.217.23.142
216.58.205.238
172.217.21.206
172.217.23.174
whitelisted
www.ebay.de 2.18.234.244
whitelisted
star-mini.c10r.facebook.com 185.60.216.35
whitelisted
e11847.g.akamaiedge.net 2.18.234.244
whitelisted
www.wikipedia.org 91.198.174.192
whitelisted
www.reddit.com 151.101.1.140
151.101.65.140
151.101.129.140
151.101.193.140
whitelisted
dyna.wikimedia.org 91.198.174.192
whitelisted
reddit.map.fastly.net 151.101.193.140
151.101.129.140
151.101.65.140
151.101.1.140
whitelisted
shavar.services.mozilla.com 52.32.91.14
52.40.41.239
34.213.214.155
34.209.180.237
34.209.199.162
54.68.166.121
whitelisted
shavar.prod.mozaws.net No response whitelisted
tracking-protection.cdn.mozilla.net 143.204.101.56
143.204.101.88
143.204.101.101
143.204.101.95
whitelisted
d1zkz3k4cclnv6.cloudfront.net 143.204.101.95
143.204.101.101
143.204.101.88
143.204.101.56
whitelisted
incoming.telemetry.mozilla.org 34.208.47.123
52.40.106.174
52.39.3.8
52.43.139.170
54.68.90.7
54.68.191.13
52.89.247.143
35.160.208.145
whitelisted
location.services.mozilla.com 54.171.74.178
52.215.229.35
108.128.206.167
whitelisted
locprod1-elb-eu-west-1.prod.mozaws.net No response whitelisted
mozilla.org 63.245.208.195
unknown
d6wjo2hisqfy2.cloudfront.net 143.204.101.92
143.204.101.80
143.204.101.87
143.204.101.114
whitelisted
normandy.cdn.mozilla.net 143.204.101.114
143.204.101.87
143.204.101.80
143.204.101.92
whitelisted
classify-client.services.mozilla.com 34.98.75.36
whitelisted
prod-classifyclient.normandy.prod.cloudops.mozgcp.net No response unknown
www.bbc.co.uk 212.58.244.66
212.58.249.208
unknown
mozilla.wpengine.com 35.197.18.156
whitelisted
blog.mozilla.org 35.197.18.156
whitelisted
www.ebay.co.uk 2.18.234.244
unknown
www.bbc.net.uk 212.58.249.208
212.58.244.66
unknown

Threats

PID Process Class Message
–– –– Potentially Bad Traffic ET INFO Observed DNS Query to .cloud TLD
–– –– Potentially Bad Traffic ET INFO Observed DNS Query to .cloud TLD

Debug output strings

No debug info.