URL:

https://github.com/SishnuMobile/Capcut-/blob/main/CapCut_7280720755476807682_installer.exe

Full analysis: https://app.any.run/tasks/6f812c07-1f72-4366-846c-056c085bef10
Verdict: Malicious activity
Analysis date: June 20, 2025, 14:15:22
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
arch-scr
Indicators:
MD5:

587938736AD13F500AF9F086D66E33BB

SHA1:

01A4595C19440FD8CB65A660EF992F6FD9C995CB

SHA256:

E298DBF95E461EA2430EC9C86BFFA03FD9A9DE87B804B0E0B7F0AED14E15AA49

SSDEEP:

3:N8tEdm9OKR5MERdjN4XdNVwDJOXLNn:2uQKs1o+VOXLN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • CapCut_7280720755476807682_installer.exe (PID: 8060)
    • The process creates files with name similar to system file names

      • CapCut_7280720755476807682_installer.exe (PID: 8060)
    • Executable content was dropped or overwritten

      • CapCut_7280720755476807682_installer.exe (PID: 8060)
      • app_package_1f584dbfc4.exe (PID: 7816)
    • Starts CMD.EXE for commands execution

      • CapCut_7280720755476807682_installer.exe (PID: 8060)
    • Uses WMIC.EXE to obtain Windows Installer data

      • cmd.exe (PID: 7316)
    • Uses WMIC.EXE to obtain operating system information

      • cmd.exe (PID: 7788)
    • Uses WMIC.EXE to obtain a list of video controllers

      • cmd.exe (PID: 6160)
    • Uses WMIC.EXE to obtain information about the network interface controller

      • cmd.exe (PID: 7884)
    • Uses WMIC.EXE to obtain physical disk drive information

      • cmd.exe (PID: 7948)
    • There is functionality for taking screenshot (YARA)

      • app_package_1f584dbfc4.exe (PID: 7816)
      • CapCut_7280720755476807682_installer.exe (PID: 8060)
    • The process drops C-runtime libraries

      • app_package_1f584dbfc4.exe (PID: 7816)
    • Process drops legitimate windows executable

      • app_package_1f584dbfc4.exe (PID: 7816)
    • Drops 7-zip archiver for unpacking

      • app_package_1f584dbfc4.exe (PID: 7816)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 5400)
      • firefox.exe (PID: 7100)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 7100)
    • Launching a file from the Downloads directory

      • firefox.exe (PID: 7100)
    • Checks supported languages

      • CapCut_7280720755476807682_installer.exe (PID: 8060)
      • app_package_1f584dbfc4.exe (PID: 7816)
    • Reads the computer name

      • CapCut_7280720755476807682_installer.exe (PID: 8060)
      • app_package_1f584dbfc4.exe (PID: 7816)
    • Reads security settings of Internet Explorer

      • WMIC.exe (PID: 8172)
      • WMIC.exe (PID: 7804)
      • WMIC.exe (PID: 7504)
      • WMIC.exe (PID: 4312)
      • WMIC.exe (PID: 2276)
    • The sample compiled with english language support

      • CapCut_7280720755476807682_installer.exe (PID: 8060)
      • firefox.exe (PID: 7100)
      • app_package_1f584dbfc4.exe (PID: 7816)
    • Creates files or folders in the user directory

      • CapCut_7280720755476807682_installer.exe (PID: 8060)
      • app_package_1f584dbfc4.exe (PID: 7816)
    • Create files in a temporary directory

      • CapCut_7280720755476807682_installer.exe (PID: 8060)
      • app_package_1f584dbfc4.exe (PID: 7816)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 7100)
    • Reads the software policy settings

      • slui.exe (PID: 6840)
    • Checks proxy server information

      • slui.exe (PID: 6840)
    • The sample compiled with chinese language support

      • app_package_1f584dbfc4.exe (PID: 7816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
190
Monitored processes
37
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs capcut_7280720755476807682_installer.exe no specs capcut_7280720755476807682_installer.exe cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs app_package_1f584dbfc4.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs slui.exe ucpdmgr.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1964"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6652 -prefsLen 39438 -prefMapHandle 6612 -prefMapSize 272997 -jsInitHandle 6604 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4456 -initialChannelId {0c2015a3-8013-4235-8239-7304b8b3c97c} -parentPid 7100 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7100" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 14 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\vcruntime140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
2276wmic path Win32_VideoController get CurrentVerticalResolution,CurrentHorizontalResolution /valueC:\Windows\SysWOW64\wbem\WMIC.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2648"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -sandboxingKind 1 -prefsHandle 2600 -prefsLen 45492 -prefMapHandle 2632 -prefMapSize 272997 -ipcHandle 6596 -initialChannelId {e09842e0-7b9f-4f75-beb3-4daac8edd0b4} -parentPid 7100 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7100" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 13 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
2804"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 1892 -prefsLen 36520 -prefMapHandle 1896 -prefMapSize 272997 -ipcHandle 1952 -initialChannelId {11eeffa3-8c51-4755-bdec-f1cf23c8d2cb} -parentPid 7100 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7100" -appDir "C:\Program Files\Mozilla Firefox\browser" - 1 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\vcruntime140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
2808"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6424 -prefsLen 39438 -prefMapHandle 6328 -prefMapSize 272997 -jsInitHandle 6280 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6616 -initialChannelId {83760cd1-6264-4e2f-8022-4bca92e75bf5} -parentPid 7100 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7100" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 12 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3636"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3976 -prefsLen 44823 -prefMapHandle 3980 -prefMapSize 272997 -jsInitHandle 3984 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3920 -initialChannelId {01aa5ffa-5d49-474a-935f-0a8c5b66acd2} -parentPid 7100 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7100" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
3788"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3204 -prefsLen 31090 -prefMapHandle 3208 -prefMapSize 272997 -jsInitHandle 3212 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3144 -initialChannelId {7d8c4281-812b-44d6-87cc-a8a6bc2d1f9a} -parentPid 7100 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7100" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 3 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
3884"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4672 -prefsLen 39068 -prefMapHandle 4676 -prefMapSize 272997 -jsInitHandle 4680 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4688 -initialChannelId {19629844-1e15-4c96-9632-b305905f86ec} -parentPid 7100 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7100" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 8 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3964"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -parentBuildID 20250227124745 -prefsHandle 3340 -prefsLen 36996 -prefMapHandle 3344 -prefMapSize 272997 -ipcHandle 3200 -initialChannelId {241469ab-c113-46af-b511-afbd5d27a092} -parentPid 7100 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7100" -appDir "C:\Program Files\Mozilla Firefox\browser" - 4 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4080"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4904 -prefsLen 45031 -prefMapHandle 4908 -prefMapSize 272997 -jsInitHandle 4912 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4812 -initialChannelId {781e6680-1fcf-474b-83ea-6c99a422166c} -parentPid 7100 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7100" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
Total events
21 289
Read events
21 285
Write events
4
Delete events
0

Modification events

(PID) Process:(7100) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(7100) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(8060) CapCut_7280720755476807682_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\DeviceInfo\MacAddr
Operation:writeName:mac
Value:
32433A43343A37413A36433A38323A3334
(PID) Process:(8060) CapCut_7280720755476807682_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\ByteDance\CapCut\Common
Operation:writeName:Info
Value:
7463051000004145119403C19464C51ED1F09D6CA96689FD3641A9C6A6CEAB074AE9862FEA0818BD8415D7144F5B1A70ACEC2581240BBFC84933F4308D1B530066838ADB807BCBC8193D1B67F473063B76B379746592AB887B349E0B433A99BC689337A4A7061136E6A47447DE7D5FB802EF60D51131F300EFD0F56D26912AEC0083A023C6946EB89D9BCBF7E8BC9A2C6EC90476AD138CE750879ECCC89C2F47BCDFC3BAAE3CEB5519BA69D57EDD51D1FCA03FAE3C0A34693D8C13225F457F3DC8057D34EE91BDF8CFFDFD36468C9568D8DF40032A00F424C144FCD94C2E23F6966E4D0D0086845DBD37B79DF981D8D42F222234E9C1
Executable files
505
Suspicious files
1 728
Text files
1 922
Unknown types
459

Dropped files

PID
Process
Filename
Type
7100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
7100firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:3134ED3F12E4F4F8643DB90043B0FD7B
SHA256:26E4F122034D7A03F6DA0E707799B09CBEEBDAF8D7A3133A1F7BD894AC72EEA1
7100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
7100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
7100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
7100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbs
MD5:62209BA23EA67E019F8B806E430E5009
SHA256:CF52F403053F9127FCFA500996A134566DC79D0594B44419CF208D873EB9FDA7
7100firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:6249053F5F1BA19491AF399CEAFDA039
SHA256:861232ECC721A888F5FE507EAD6926AEB32A8E63DC33F574F399C278DF06A855
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
131
DNS requests
187
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7100
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
7100
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
7100
firefox.exe
POST
200
172.64.149.23:80
http://ocsp.sectigo.com/
unknown
whitelisted
7100
firefox.exe
POST
200
172.64.149.23:80
http://ocsp.sectigo.com/
unknown
whitelisted
7100
firefox.exe
POST
200
142.250.181.227:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
7100
firefox.exe
POST
200
142.250.181.227:80
http://o.pki.goog/we2
unknown
whitelisted
7100
firefox.exe
POST
200
172.64.149.23:80
http://ocsp.sectigo.com/
unknown
whitelisted
7100
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
7100
firefox.exe
POST
200
142.250.181.227:80
http://o.pki.goog/we2
unknown
whitelisted
7100
firefox.exe
POST
200
142.250.181.227:80
http://o.pki.goog/s/wr3/azY
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3108
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7100
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
whitelisted
7100
firefox.exe
140.82.121.4:443
github.com
GITHUB
US
whitelisted
7100
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
7100
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
7100
firefox.exe
172.64.149.23:80
ocsp.sectigo.com
CLOUDFLARENET
US
whitelisted
7100
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.206
whitelisted
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted
content-signature-chains.prod.autograph.services.mozaws.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted
github.com
  • 140.82.121.4
  • 140.82.121.3
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.36.137.203
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted
mc.prod.ads.prod.webservices.mozgcp.net
  • 34.36.137.203
whitelisted
example.org
  • 96.7.128.186
  • 23.215.0.132
  • 96.7.128.192
  • 23.215.0.133
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
Process
Message
CapCut_7280720755476807682_installer.exe
checkBoxCreateShortcut status:1