| URL: | https://jsjcorporation-my.sharepoint.com/:o:/g/personal/gillesm_jsjcorp_com/El3LMnws4WZAn7a-DWcgo-oBQOivV1QSdopp5DSJ_EMPKQ?e=13FjPv |
| Full analysis: | https://app.any.run/tasks/0ca6aec5-919c-4598-b5bb-3d7699e97d47 |
| Verdict: | Malicious activity |
| Analysis date: | May 17, 2025, 06:09:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 22A7F6B7F82DB4C6FBA91C37D639CC2D |
| SHA1: | C52A805E195DD2B766F9F0A625FE6B9F53D3E747 |
| SHA256: | DAC827E4401DAEB8865F53BF41C2B12F50EFC654BF22B506E012D3E6D3DD7EDE |
| SSDEEP: | 3:N8oXS88hiN+ArL5+KVFSCIOtTKI3mREcoKIK0qS4028VVQhf5w:2Kqhu+AfNQOtTKIC3oTlj402EVQh+ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.0.366841850\182190046" -parentBuildID 20230710165010 -prefsHandle 1096 -prefMapHandle 1088 -prefsLen 28739 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {00316026-92c8-4424-a80f-7ef4ee534cd2} 372 "\\.\pipe\gecko-crash-server-pipe.372" 1180 d3820d0 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 372 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://jsjcorporation-my.sharepoint.com/:o:/g/personal/gillesm_jsjcorp_com/El3LMnws4WZAn7a-DWcgo-oBQOivV1QSdopp5DSJ_EMPKQ?e=13FjPv | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 752 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.1.1427210512\290432066" -parentBuildID 20230710165010 -prefsHandle 1320 -prefMapHandle 1316 -prefsLen 28816 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {40987c98-2f3e-4872-b775-b58ad806c7a2} 372 "\\.\pipe\gecko-crash-server-pipe.372" 1332 8045e0 socket | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 984 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.14.393792905\1100821733" -childID 11 -isForBrowser -prefsHandle 7512 -prefMapHandle 7524 -prefsLen 29609 -prefMapSize 244371 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {91dbf00f-b81d-40c1-95b5-3bb8e82310c4} 372 "\\.\pipe\gecko-crash-server-pipe.372" 7492 1dc52560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1080 | C:\Windows\system32\svchost.exe -k NetworkService | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1276 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.2.746821663\1494519448" -childID 1 -isForBrowser -prefsHandle 2216 -prefMapHandle 2140 -prefsLen 24527 -prefMapSize 244371 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1b3b26d0-0579-43fc-872c-6ded66d05b29} 372 "\\.\pipe\gecko-crash-server-pipe.372" 2176 1394e560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1332 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.8.8600991\1091232264" -childID 7 -isForBrowser -prefsHandle 7940 -prefMapHandle 7948 -prefsLen 29349 -prefMapSize 244371 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {78d32d1b-15f8-402d-a669-eaf3ab695dc6} 372 "\\.\pipe\gecko-crash-server-pipe.372" 7928 ff93b20 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1548 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.12.784552678\1688824317" -parentBuildID 20230710165010 -prefsHandle 3940 -prefMapHandle 3936 -prefsLen 36654 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6b8a3e24-4bd3-41d1-a152-265e57a9fe31} 372 "\\.\pipe\gecko-crash-server-pipe.372" 7524 1d6e8f20 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1596 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.11.1920454876\1622257291" -childID 10 -isForBrowser -prefsHandle 3968 -prefMapHandle 7728 -prefsLen 29609 -prefMapSize 244371 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {dc9914f2-2c71-45df-9aab-69d33492a960} 372 "\\.\pipe\gecko-crash-server-pipe.372" 3956 1b964560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1980 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.13.1365880231\1358825622" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 7536 -prefMapHandle 7540 -prefsLen 36654 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {40f0392a-e734-4984-93c6-0b2d2f2d2336} 372 "\\.\pipe\gecko-crash-server-pipe.372" 7508 12fb8710 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (2472) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 9BEBFF5001000000 | |||
| (PID) Process: | (372) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: C8AC015101000000 | |||
| (PID) Process: | (1080) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\Intranet |
| Operation: | write | Name: | {4040CF00-1B3E-486A-B407-FA14C56B6FC0} |
Value: D4DA6D39D73C | |||
| (PID) Process: | (372) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB |
| Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
| (PID) Process: | (372) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (372) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (372) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (372) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (372) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (372) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 372 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\activity-stream.discovery_stream.json.tmp | binary | |
MD5:B89F821178FDCFB57C4446F1970FB124 | SHA256:53A1BCC3D48836F88F6C98576083A0C1F7A719B36A7AC85E213FD2F3BD7A7B4B | |||
| 372 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 372 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\activity-stream.discovery_stream.json | binary | |
MD5:B89F821178FDCFB57C4446F1970FB124 | SHA256:53A1BCC3D48836F88F6C98576083A0C1F7A719B36A7AC85E213FD2F3BD7A7B4B | |||
| 372 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.tmp | binary | |
MD5:B1C8AA9861B461806C9E738511EDD6AE | SHA256:7CEA48E7ADD3340B36F47BA4EA2DED8D6CB0423FFC2A64B44D7E86E0507D6B70 | |||
| 372 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 372 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 372 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:10838BA4D091CD29EB56089222ECB443 | SHA256:934225516EF688A07796A04C2358410D6F7238FD8056C261780E20B098F1189C | |||
| 372 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 372 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:10838BA4D091CD29EB56089222ECB443 | SHA256:934225516EF688A07796A04C2358410D6F7238FD8056C261780E20B098F1189C | |||
| 372 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite-journal | binary | |
MD5:35A9F683D6C49B62E51BF1FD9CAD5E0B | SHA256:E47AC382D0B2EF3FF1571F9C27B4823E6F831F4A00D8C43A7E0EFA2B2EC634EE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
372 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
372 | firefox.exe | POST | — | 172.217.16.195:80 | http://o.pki.goog/s/wr3/FIY | unknown | — | — | whitelisted |
372 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
372 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
372 | firefox.exe | POST | — | 184.24.77.62:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
372 | firefox.exe | POST | 200 | 184.24.77.62:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
372 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
372 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
372 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
372 | firefox.exe | POST | 200 | 184.24.77.62:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
372 | firefox.exe | 13.107.138.10:443 | jsjcorporation-my.sharepoint.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
372 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
372 | firefox.exe | 34.36.137.203:443 | spocs.getpocket.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
372 | firefox.exe | 142.250.184.234:443 | safebrowsing.googleapis.com | — | — | whitelisted |
372 | firefox.exe | 172.217.16.195:80 | o.pki.goog | GOOGLE | US | whitelisted |
372 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
jsjcorporation-my.sharepoint.com |
| unknown |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
dual-spo-0005.spo-msedge.net |
| unknown |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
mc.prod.ads.prod.webservices.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
372 | firefox.exe | Not Suspicious Traffic | INFO [ANY.RUN] Request to SharePoint public/private file sharing TLS SNI (.sharepoint .com) |
372 | firefox.exe | Not Suspicious Traffic | INFO [ANY.RUN] Request to SharePoint public/private file sharing TLS SNI (.sharepoint .com) |
1080 | svchost.exe | Possible Social Engineering Attempted | SUSPICIOUS [ANY.RUN] Suspected Malicious Domain ( .spo-msedge .net) |
1080 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Request to SharePoint public/private file sharing DNS (.sharepoint .com) |
1080 | svchost.exe | Possible Social Engineering Attempted | SUSPICIOUS [ANY.RUN] Suspected Malicious Domain ( .spo-msedge .net) |
372 | firefox.exe | Possible Social Engineering Attempted | SUSPICIOUS [ANY.RUN] Accessing SharePoint content without a legitimate Microsoft Sign-In |
1080 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
1080 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
1080 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
1080 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |