URL:

pluralism.themancav.com

Full analysis: https://app.any.run/tasks/f185c44e-c439-4850-8127-11cb08c3a29d
Verdict: Malicious activity
Analysis date: March 01, 2024, 15:20:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

C337ABDD918A6AC33A69691D88669C8A

SHA1:

EB512C363439E08724CD08B905524BFF5BEF7224

SHA256:

CA0ECB0FAD7A2F4F56704B11630DDF984E38F82AF3D878EA0C76CF3CFEAB9005

SSDEEP:

3:1rlmTn:an

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • firefox.exe (PID: 3668)
      • firefox.exe (PID: 3864)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
20
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3864.6.1449287706\1770626303" -childID 5 -isForBrowser -prefsHandle 4088 -prefMapHandle 4092 -prefsLen 29313 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7126fdb3-ebd3-446f-b8b1-41dfc0a1dbee} 3864 "\\.\pipe\gecko-crash-server-pipe.3864" 3992 209fdf70 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
296"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3864.5.64105528\1015983801" -childID 4 -isForBrowser -prefsHandle 3788 -prefMapHandle 3772 -prefsLen 29313 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {8bd6dd6d-6707-4857-8afa-94a34fc3eed7} 3864 "\\.\pipe\gecko-crash-server-pipe.3864" 3976 209fde00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
996"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3864.14.1696510976\610126834" -childID 13 -isForBrowser -prefsHandle 8228 -prefMapHandle 8236 -prefsLen 31256 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {18494f5d-7e9e-4cf2-ab34-7ac4d84331ce} 3864 "\\.\pipe\gecko-crash-server-pipe.3864" 2144 1f28ce00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1220"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3864.16.928456664\421001377" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 2952 -prefMapHandle 4036 -prefsLen 36631 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a6bd7698-168d-42d5-bd73-993100859b21} 3864 "\\.\pipe\gecko-crash-server-pipe.3864" 8228 d016aa0 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1504"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3864.8.1641820162\16739489" -childID 7 -isForBrowser -prefsHandle 2356 -prefMapHandle 2364 -prefsLen 31054 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b7d1130f-4c9a-4167-8102-4d25ca1154ef} 3864 "\\.\pipe\gecko-crash-server-pipe.3864" 2176 21ed46d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2020"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3864.7.1673408688\540245430" -childID 6 -isForBrowser -prefsHandle 4264 -prefMapHandle 4268 -prefsLen 29313 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6ad95551-5e7d-4bfb-afe0-46de5160a7af} 3864 "\\.\pipe\gecko-crash-server-pipe.3864" 4256 21ed4c90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2148"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3864.12.1110719203\649457046" -childID 11 -isForBrowser -prefsHandle 3064 -prefMapHandle 3640 -prefsLen 31256 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {109a0f4e-438e-4db4-af68-4f0f6c697823} 3864 "\\.\pipe\gecko-crash-server-pipe.3864" 3288 11ef49b0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2384"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3864.11.1186118752\1073153529" -childID 10 -isForBrowser -prefsHandle 4080 -prefMapHandle 4184 -prefsLen 31256 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {395b8a3e-af07-4245-82b1-e70ca368f09e} 3864 "\\.\pipe\gecko-crash-server-pipe.3864" 4488 1f489110 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2448"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3864.13.2044308455\2076909154" -childID 12 -isForBrowser -prefsHandle 8448 -prefMapHandle 8452 -prefsLen 31256 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4f9e504b-8780-4221-8b65-a9f2705699ee} 3864 "\\.\pipe\gecko-crash-server-pipe.3864" 8472 21ed4c90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2564"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3864.3.1927345543\755004585" -childID 2 -isForBrowser -prefsHandle 2920 -prefMapHandle 2916 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 908 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {65f5e661-86a4-408c-8bcd-9d784910cfcc} 3864 "\\.\pipe\gecko-crash-server-pipe.3864" 2932 1f28cb20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
25 086
Read events
25 042
Write events
39
Delete events
5

Modification events

(PID) Process:(3668) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
B2A7E34E01000000
(PID) Process:(3864) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
D58BE54E01000000
(PID) Process:(3864) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB
Operation:delete valueName:installer.taskbarpin.win10.enabled
Value:
(PID) Process:(3864) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(3864) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(3864) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(3864) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(3864) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(3864) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(3864) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
Executable files
0
Suspicious files
112
Text files
33
Unknown types
83

Dropped files

PID
Process
Filename
Type
3864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:7B0C28439752532F32410A9EDCA365BA
SHA256:94B0E4AE36960C07BFAE4C37AC79F8F84B674B1C6623F753F43A1747E10E5CF9
3864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
3864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:7B0C28439752532F32410A9EDCA365BA
SHA256:94B0E4AE36960C07BFAE4C37AC79F8F84B674B1C6623F753F43A1747E10E5CF9
3864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journalbinary
MD5:B23D9DF06C19C717B3A89277FF40378C
SHA256:F87C4B190CE8F03D6FCC350B455874F295C9144B879918F6717452B29A4A5BCC
3864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
3864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3864firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.dbbinary
MD5:4F2E98C973CDCA4B696E23BD73D1131F
SHA256:5C78B7A9F9363A7066C359FD6AEF6181A90FDDE1F27D44D7D2199193D74B6E3D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
44
TCP/UDP connections
152
DNS requests
251
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3864
firefox.exe
POST
172.64.149.23:80
http://zerossl.ocsp.sectigo.com/
unknown
unknown
3864
firefox.exe
POST
200
142.250.186.99:80
http://ocsp.pki.goog/gts1c3
unknown
binary
472 b
unknown
3864
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
3864
firefox.exe
GET
301
166.1.173.27:80
http://pluralism.themancav.com/
unknown
html
162 b
unknown
3864
firefox.exe
POST
200
95.101.54.209:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
3864
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
3864
firefox.exe
POST
200
95.101.54.209:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
3864
firefox.exe
POST
200
142.250.186.99:80
http://ocsp.pki.goog/gts1c3
unknown
binary
472 b
unknown
3864
firefox.exe
POST
200
95.101.54.209:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
3864
firefox.exe
POST
200
95.101.54.209:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3864
firefox.exe
34.117.188.166:443
spocs.getpocket.com
unknown
3864
firefox.exe
166.1.173.27:80
pluralism.themancav.com
SPRINTLINK
US
unknown
3864
firefox.exe
172.217.18.10:443
safebrowsing.googleapis.com
whitelisted
3864
firefox.exe
142.250.186.99:80
ocsp.pki.goog
GOOGLE
US
whitelisted
3864
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
3864
firefox.exe
34.107.243.93:443
push.services.mozilla.com
unknown
3864
firefox.exe
172.64.149.23:80
zerossl.ocsp.sectigo.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
pluralism.themancav.com
  • 166.1.173.27
malicious
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
spocs.getpocket.com
  • 34.117.188.166
shared
gkegw.prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
unknown
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted
r3.o.lencr.org
  • 95.101.54.209
  • 2.16.202.120
  • 95.101.54.144
  • 95.101.54.201
  • 2.16.202.115
  • 95.101.54.216
  • 95.101.54.121
  • 95.101.54.130
  • 95.101.54.145
  • 2.16.202.121
  • 95.101.54.112
  • 23.220.255.55
  • 23.220.255.62
  • 23.220.255.33
  • 23.220.255.4
  • 23.220.255.52
  • 23.220.255.48
  • 23.220.255.54
  • 23.220.255.60
  • 23.220.255.34
  • 23.220.255.13
shared

Threats

PID
Process
Class
Message
1080
svchost.exe
A Network Trojan was detected
ET MALWARE SocGholish Domain in DNS Lookup (pluralism .themancav .com)
1080
svchost.exe
A Network Trojan was detected
ET MALWARE SocGholish Domain in DNS Lookup (pluralism .themancav .com)
1080
svchost.exe
A Network Trojan was detected
ET MALWARE SocGholish Domain in DNS Lookup (pluralism .themancav .com)
1080
svchost.exe
A Network Trojan was detected
ET MALWARE SocGholish Domain in DNS Lookup (pluralism .themancav .com)
1080
svchost.exe
A Network Trojan was detected
ET MALWARE SocGholish Domain in DNS Lookup (pluralism .themancav .com)
3864
firefox.exe
A Network Trojan was detected
ET MALWARE SocGholish Domain in TLS SNI (pluralism .themancav .com)
3864
firefox.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
No debug info