URL:

https://github.com/EugeneSunrise/reWASD/releases/tag/reWASD6.6_x86%2Fx64_FIX

Full analysis: https://app.any.run/tasks/fee50013-6095-4b7f-9b31-a1f3c122cdf1
Verdict: Malicious activity
Analysis date: January 10, 2024, 12:36:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

459656C365DFC08F08BCCA42B2625E4B

SHA1:

6363646DC15F337C1005634C526AF4F6DFB0B828

SHA256:

D8A58DE6B7282B45B2DD43B6BF80AA354AE1FEBAC606104D6214D131FC741DAA

SSDEEP:

3:N8tEd+2QLcWAKXPJMqKQA4Az3bn:2uw3LcWAKhMx94A7b

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • drvinst.exe (PID: 1124)
      • drvinst.exe (PID: 3664)
      • drvinst.exe (PID: 3452)
  • SUSPICIOUS

    • Reads the Internet Settings

      • rewasd660-7726.exe (PID: 3492)
    • Drops a system driver (possible attempt to evade defenses)

      • reWASDService.exe (PID: 3004)
      • drvinst.exe (PID: 1124)
      • drvinst.exe (PID: 3664)
    • Searches for installed software

      • reWASDService.exe (PID: 3004)
    • Adds/modifies Windows certificates

      • reWASDService.exe (PID: 3004)
    • Checks Windows Trust Settings

      • reWASDService.exe (PID: 3004)
      • drvinst.exe (PID: 1124)
      • drvinst.exe (PID: 4084)
      • drvinst.exe (PID: 3452)
      • drvinst.exe (PID: 3664)
      • drvinst.exe (PID: 3900)
      • drvinst.exe (PID: 3824)
    • Reads settings of System Certificates

      • reWASDService.exe (PID: 3004)
      • rundll32.exe (PID: 3556)
      • rundll32.exe (PID: 4068)
    • Creates files in the driver directory

      • drvinst.exe (PID: 1124)
      • drvinst.exe (PID: 3664)
      • drvinst.exe (PID: 3452)
    • Reads security settings of Internet Explorer

      • reWASDService.exe (PID: 3004)
    • Suspicious use of NETSH.EXE

      • rewasd660-7726.exe (PID: 3492)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • rewasd660-7726.exe (PID: 3492)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 124)
      • firefox.exe (PID: 2040)
    • Reads the computer name

      • rewasd660-7726.exe (PID: 3492)
      • reWASDService.exe (PID: 560)
      • reWASDService.exe (PID: 3004)
      • drvinst.exe (PID: 1124)
      • drvinst.exe (PID: 3664)
      • drvinst.exe (PID: 4084)
      • drvinst.exe (PID: 3452)
      • drvinst.exe (PID: 3780)
      • drvinst.exe (PID: 3900)
      • reWASDService.exe (PID: 3612)
      • reWASDService.exe (PID: 2776)
      • drvinst.exe (PID: 3824)
      • mscorsvw.exe (PID: 748)
      • mscorsvw.exe (PID: 3740)
      • ngen.exe (PID: 3832)
      • ngen.exe (PID: 3148)
      • mscorsvw.exe (PID: 1556)
      • mscorsvw.exe (PID: 3992)
      • mscorsvw.exe (PID: 4020)
      • mscorsvw.exe (PID: 3248)
      • ngen.exe (PID: 2840)
    • Checks supported languages

      • rewasd660-7726.exe (PID: 3492)
      • reWASDService.exe (PID: 560)
      • reWASDService.exe (PID: 3004)
      • drvinst.exe (PID: 1124)
      • drvinst.exe (PID: 3664)
      • drvinst.exe (PID: 3452)
      • drvinst.exe (PID: 4084)
      • drvinst.exe (PID: 3824)
      • reWASDService.exe (PID: 3612)
      • reWASDService.exe (PID: 2776)
      • drvinst.exe (PID: 3780)
      • drvinst.exe (PID: 3900)
      • ngen.exe (PID: 3148)
      • mscorsvw.exe (PID: 1556)
      • mscorsvw.exe (PID: 3740)
      • mscorsvw.exe (PID: 748)
      • ngen.exe (PID: 3832)
      • mscorsvw.exe (PID: 4020)
      • mscorsvw.exe (PID: 3992)
      • mscorsvw.exe (PID: 3248)
      • ngen.exe (PID: 2840)
    • Reads the machine GUID from the registry

      • rewasd660-7726.exe (PID: 3492)
      • reWASDService.exe (PID: 3004)
      • drvinst.exe (PID: 1124)
      • drvinst.exe (PID: 3664)
      • drvinst.exe (PID: 4084)
      • drvinst.exe (PID: 3452)
      • drvinst.exe (PID: 3900)
      • drvinst.exe (PID: 3780)
      • drvinst.exe (PID: 3824)
      • mscorsvw.exe (PID: 1556)
      • mscorsvw.exe (PID: 3740)
      • mscorsvw.exe (PID: 748)
      • ngen.exe (PID: 3148)
      • ngen.exe (PID: 3832)
      • mscorsvw.exe (PID: 3992)
      • mscorsvw.exe (PID: 4020)
      • ngen.exe (PID: 2840)
      • mscorsvw.exe (PID: 3248)
    • The process uses the downloaded file

      • firefox.exe (PID: 124)
    • Drops 7-zip archiver for unpacking

      • rewasd660-7726.exe (PID: 3492)
    • Reads Environment values

      • rewasd660-7726.exe (PID: 3492)
    • Create files in a temporary directory

      • rewasd660-7726.exe (PID: 3492)
      • reWASDService.exe (PID: 3004)
    • Creates files in the program directory

      • rewasd660-7726.exe (PID: 3492)
      • reWASDService.exe (PID: 3004)
    • Drops the executable file immediately after the start

      • rewasd660-7726.exe (PID: 3492)
      • firefox.exe (PID: 124)
      • reWASDService.exe (PID: 3004)
      • drvinst.exe (PID: 1124)
      • drvinst.exe (PID: 3664)
      • mscorsvw.exe (PID: 748)
      • mscorsvw.exe (PID: 3740)
      • mscorsvw.exe (PID: 3992)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 3556)
      • rundll32.exe (PID: 4068)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1384)
      • reWASDService.exe (PID: 2776)
    • Creates files or folders in the user directory

      • rundll32.exe (PID: 3512)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
107
Monitored processes
51
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs rewasd660-7726.exe no specs rewasd660-7726.exe logman.exe no specs logman.exe no specs rewasdservice.exe no specs rewasdservice.exe no specs vssvc.exe no specs drvinst.exe no specs rundll32.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs rundll32.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs rundll32.exe no specs rundll32.exe no specs rewasdservice.exe no specs rewasdservice.exe no specs logman.exe no specs logman.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs ngen.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs ngen.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs ngen.exe no specs mscorsvw.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\Mozilla Firefox\firefox.exe" https://github.com/EugeneSunrise/reWASD/releases/tag/reWASD6.6_x86%2Fx64_FIXC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
548C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
560"C:\Program Files\reWASD\reWASDService.exe" -drvcheckC:\Program Files\reWASD\reWASDService.exerewasd660-7726.exe
User:
admin
Company:
Disc Soft Ltd
Integrity Level:
HIGH
Description:
Game Controller Mapping Service
Exit code:
21
Version:
5.09.0.0
Modules
Images
c:\program files\rewasd\rewasdservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
668"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="124.1.371810183\552268014" -parentBuildID 20230710165010 -prefsHandle 1408 -prefMapHandle 1404 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {56d22037-e4ac-4d17-a283-c9096833bd52} 124 "\\.\pipe\gecko-crash-server-pipe.124" 1420 eb4e6b0 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
748C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 198 -InterruptEvent 0 -NGENProcess 114 -Pipe 194 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
924"netsh.exe" advfirewall firewall add rule name="reWASD Engine Http (In) 35475" dir=in action=allow protocol=TCP localport=35475C:\Windows\System32\netsh.exerewasd660-7726.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1016"C:\Windows\System32\logman.exe" start REWASD_service -p {0CEA7670-4CD6-45B1-9133-71A9DC48464E} 0xff 255 -o "C:\Users\Public\Documents\reWASD\Logs\REWASD_service.etl" -etsC:\Windows\System32\logman.exerewasd660-7726.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Performance Log Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\logman.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1124DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{02a48b36-5fbb-0bc9-dfbd-fb4695b38c67}\hidgamemap.inf" "0" "67bb1681b" "000005D8" "WinSta0\Default" "000005D0" "208" "c:\program files\rewasd"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1384C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1392"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="124.0.1801774526\966619025" -parentBuildID 20230710165010 -prefsHandle 1112 -prefMapHandle 1104 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {809241bc-389b-41e5-b46e-59a499132f91} 124 "\\.\pipe\gecko-crash-server-pipe.124" 1184 d2a9d80 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
72 778
Read events
71 678
Write events
1 099
Delete events
1

Modification events

(PID) Process:(2040) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
2166C0A101000000
(PID) Process:(124) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
044CC1A101000000
(PID) Process:(124) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(124) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(124) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(124) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(124) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(124) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(124) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(124) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
D14E5F3C23B0D901
Executable files
65
Suspicious files
228
Text files
72
Unknown types
1

Dropped files

PID
Process
Filename
Type
124firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:B7A3C61D0C144CC5E166B1E769CA8F8C
SHA256:7FADCB77FFACA6B9E9F15C6F1CD3AAD4C20DCD90FA92429A627A3A7110CA2644
124firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
124firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
124firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.binbinary
MD5:63B1BB87284EFE954E1C3AE390E7EE44
SHA256:B017EE25A7F5C09EB4BF359CA721D67E6E9D9F95F8CE6F741D47F33BDE6EF73A
124firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
124firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
124firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
124firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
124firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
124firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
79
DNS requests
164
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
124
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
312 b
124
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
124
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
124
firefox.exe
POST
200
95.101.54.107:80
http://r3.o.lencr.org/
unknown
binary
503 b
124
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
312 b
124
firefox.exe
POST
200
95.101.54.107:80
http://r3.o.lencr.org/
unknown
binary
503 b
124
firefox.exe
POST
200
172.217.16.195:80
http://ocsp.pki.goog/gts1c3
unknown
binary
472 b
124
firefox.exe
POST
13.32.117.210:80
http://ocsp.r2m02.amazontrust.com/
unknown
124
firefox.exe
POST
200
95.101.54.107:80
http://r3.o.lencr.org/
unknown
binary
503 b
124
firefox.exe
POST
200
95.101.54.99:80
http://r3.o.lencr.org/
unknown
binary
503 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
124
firefox.exe
140.82.121.4:443
github.com
GITHUB
US
unknown
124
firefox.exe
172.217.18.10:443
safebrowsing.googleapis.com
whitelisted
124
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
124
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
124
firefox.exe
44.197.73.21:443
spocs.getpocket.com
AMAZON-AES
US
unknown
124
firefox.exe
185.199.108.154:443
github.githubassets.com
FASTLY
US
unknown
124
firefox.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
unknown
github.com
  • 140.82.121.4
unknown
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
unknown
contile.services.mozilla.com
  • 34.117.237.239
unknown
example.org
  • 93.184.216.34
unknown
spocs.getpocket.com
  • 44.197.73.21
  • 18.235.58.129
  • 54.205.248.223
  • 18.215.61.248
  • 54.235.84.23
  • 3.211.58.243
  • 35.171.113.32
  • 3.219.12.119
unknown
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
fp2e7a.wpc.phicdn.net
  • 192.229.221.95
unknown
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 44.197.73.21
  • 18.235.58.129
  • 54.205.248.223
  • 18.215.61.248
  • 54.235.84.23
  • 3.211.58.243
  • 35.171.113.32
  • 3.219.12.119
unknown

Threats

No threats detected
No debug info