URL:

http://download.tidal.com/desktop/TIDALSetup.exe

Full analysis: https://app.any.run/tasks/7613cbc1-bb77-4854-baa9-27f8f85813e1
Verdict: Malicious activity
Analysis date: March 23, 2020, 12:16:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

A62C2C33F2941AA2C369CBEAABA3BB83

SHA1:

D1789FDD74BC6D3D122DB1A5D51681EF7B32382C

SHA256:

E4C6BA93C84B141228549467F954B3D2C7F87774222584218615540AEE1C8071

SSDEEP:

3:N1KaKElRLKaAW1VKq4A:Ca5kL214A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • TIDALSetup.exe (PID: 2948)
      • update.exe (PID: 1744)
      • Update.exe (PID: 1232)
      • TIDALPlayer.exe (PID: 3340)
      • Update.exe (PID: 392)
    • Loads dropped or rewritten executable

      • TIDAL.exe (PID: 2496)
      • TIDAL.exe (PID: 2520)
      • TIDAL.exe (PID: 1696)
      • TIDAL.exe (PID: 2492)
      • TIDAL.exe (PID: 2612)
      • TIDAL.exe (PID: 2560)
      • TIDALPlayer.exe (PID: 3340)
      • TIDAL.exe (PID: 1940)
      • TIDAL.exe (PID: 1688)
      • TIDAL.exe (PID: 2576)
      • TIDAL.exe (PID: 2452)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • TIDALSetup.exe (PID: 2948)
      • Update.exe (PID: 1232)
      • firefox.exe (PID: 3776)
    • Creates files in the program directory

      • firefox.exe (PID: 3776)
    • Application launched itself

      • TIDAL.exe (PID: 2520)
      • TIDAL.exe (PID: 1696)
    • Creates files in the user directory

      • update.exe (PID: 1744)
      • TIDALPlayer.exe (PID: 3340)
      • TIDAL.exe (PID: 2560)
      • TIDAL.exe (PID: 1696)
    • Starts CMD.EXE for commands execution

      • TIDAL.exe (PID: 1696)
    • Creates a software uninstall entry

      • Update.exe (PID: 1232)
    • Uses REG.EXE to modify Windows registry

      • TIDAL.exe (PID: 1696)
    • Uses WMIC.EXE to obtain a system information

      • cmd.exe (PID: 3472)
    • Reads Environment values

      • Update.exe (PID: 392)
      • TIDAL.exe (PID: 1696)
      • Update.exe (PID: 1232)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 3776)
      • firefox.exe (PID: 2896)
    • Creates files in the user directory

      • firefox.exe (PID: 3776)
    • Reads CPU info

      • firefox.exe (PID: 3776)
    • Reads Internet Cache Settings

      • firefox.exe (PID: 3776)
      • pingsender.exe (PID: 2640)
    • Reads settings of System Certificates

      • firefox.exe (PID: 3776)
      • pingsender.exe (PID: 2640)
      • Update.exe (PID: 1232)
      • TIDAL.exe (PID: 2560)
    • Reads the hosts file

      • TIDAL.exe (PID: 1696)
      • TIDAL.exe (PID: 2560)
    • Dropped object may contain Bitcoin addresses

      • TIDAL.exe (PID: 1696)
      • TIDAL.exe (PID: 2560)
    • Adds / modifies Windows certificates

      • pingsender.exe (PID: 2640)
    • Changes settings of System certificates

      • pingsender.exe (PID: 2640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
25
Malicious processes
7
Suspicious processes
5

Behavior graph

Click at the process to see the details
start drop and start drop and start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe tidalsetup.exe update.exe pingsender.exe tidal.exe no specs tidal.exe no specs update.exe no specs tidal.exe no specs tidal.exe no specs tidalplayer.exe no specs tidal.exe no specs update.exe tidal.exe cmd.exe no specs reg.exe no specs wmic.exe no specs tidal.exe no specs tidal.exe no specs tidal.exe no specs tidal.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
392C:\Users\admin\AppData\Local\TIDAL\Update.exe --checkForUpdate https://download.tidal.com/desktop/windows/C:\Users\admin\AppData\Local\TIDAL\Update.exe
TIDAL.exe
User:
admin
Company:
GitHub
Integrity Level:
MEDIUM
Description:
Update
Exit code:
0
Version:
1.9.0.0
Modules
Images
c:\users\admin\appdata\local\tidal\update.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1232"C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe" --install . C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe
TIDALSetup.exe
User:
admin
Company:
GitHub
Integrity Level:
MEDIUM
Description:
Update
Exit code:
0
Version:
1.9.0.0
Modules
Images
c:\users\admin\appdata\local\squirreltemp\update.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1688"C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exe" --type=renderer --autoplay-policy=no-user-gesture-required --field-trial-handle=1088,7559522889639697177,4989307167848346218,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --disable-gpu-compositing --lang=en-US --app-user-model-id=com.squirrel.TIDAL.TIDAL --app-path="C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\resources\app.asar" --enable-plugins --no-sandbox --no-zygote --preload="C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\resources\app.asar\app\init_clientInterface.js" --enable-remote-module --background-color=#1c1c1c --disable-electron-site-instance-overrides --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1744 /prefetch:1C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exeTIDAL.exe
User:
admin
Company:
TIDAL Music AS
Integrity Level:
MEDIUM
Description:
TIDAL
Exit code:
0
Version:
2.14.0
Modules
Images
c:\users\admin\appdata\local\tidal\app-2.14.0\tidal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\tidal\app-2.14.0\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1696"C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exe" --squirrel-firstrunC:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exeUpdate.exe
User:
admin
Company:
TIDAL Music AS
Integrity Level:
MEDIUM
Description:
TIDAL
Exit code:
0
Version:
2.14.0
Modules
Images
c:\users\admin\appdata\local\tidal\app-2.14.0\tidal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\tidal\app-2.14.0\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1744C:\Users\admin\AppData\Local\TIDAL\update.exe --createShortcut TIDAL.exeC:\Users\admin\AppData\Local\TIDAL\update.exeTIDAL.exe
User:
admin
Company:
GitHub
Integrity Level:
MEDIUM
Description:
Update
Exit code:
0
Version:
1.9.0.0
Modules
Images
c:\users\admin\appdata\local\tidal\update.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1940"C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exe" --type=gpu-process --field-trial-handle=1088,7559522889639697177,4989307167848346218,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --gpu-preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --mojo-platform-channel-handle=1272 --ignored=" --type=renderer " /prefetch:2C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exeTIDAL.exe
User:
admin
Company:
TIDAL Music AS
Integrity Level:
LOW
Description:
TIDAL
Exit code:
0
Version:
2.14.0
Modules
Images
c:\users\admin\appdata\local\tidal\app-2.14.0\tidal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\tidal\app-2.14.0\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2452"C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exe" --type=utility --field-trial-handle=1088,7559522889639697177,4989307167848346218,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=2000 /prefetch:8C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exeTIDAL.exe
User:
admin
Company:
TIDAL Music AS
Integrity Level:
MEDIUM
Description:
TIDAL
Exit code:
0
Version:
2.14.0
Modules
Images
c:\users\admin\appdata\local\tidal\app-2.14.0\tidal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\tidal\app-2.14.0\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2492"C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exe" --type=gpu-process --field-trial-handle=1088,7559522889639697177,4989307167848346218,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --gpu-preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --mojo-platform-channel-handle=1112 --ignored=" --type=renderer " /prefetch:2C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exeTIDAL.exe
User:
admin
Company:
TIDAL Music AS
Integrity Level:
LOW
Description:
TIDAL
Exit code:
0
Version:
2.14.0
Modules
Images
c:\systemroot\system32\ntdll.dll
c:\users\admin\appdata\local\tidal\app-2.14.0\tidal.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\tidal\app-2.14.0\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2496C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exe --no-rate-limit --no-upload-gzip --type=crash-handler "--crashes-directory=C:\Users\admin\AppData\Local\Temp\TIDAL Crashes" "--database=C:\Users\admin\AppData\Local\Temp\TIDAL Crashes" "--metrics-dir=C:\Users\admin\AppData\Local\Temp\TIDAL Crashes" --url=https://sentry.io/api/1539696/minidump?sentry_key=6284ad8712864a21a2b95fc0ef7fba7d --initial-client-data=0x2e0,0x2e4,0x2e8,0x2dc,0x2ec,0x54d0b10,0x54d0b20,0x54d0b2cC:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exeTIDAL.exe
User:
admin
Company:
TIDAL Music AS
Integrity Level:
MEDIUM
Description:
TIDAL
Exit code:
0
Version:
2.14.0
Modules
Images
c:\users\admin\appdata\local\tidal\app-2.14.0\tidal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\tidal\app-2.14.0\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2520"C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exe" --squirrel-install 2.14.0C:\Users\admin\AppData\Local\TIDAL\app-2.14.0\TIDAL.exeUpdate.exe
User:
admin
Company:
TIDAL Music AS
Integrity Level:
MEDIUM
Description:
TIDAL
Exit code:
0
Version:
2.14.0
Modules
Images
c:\users\admin\appdata\local\tidal\app-2.14.0\tidal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\tidal\app-2.14.0\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
5 635
Read events
1 993
Write events
2 455
Delete events
1 187

Modification events

(PID) Process:(3776) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
7BF675EE08000000
(PID) Process:(2896) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
D1E572EE08000000
(PID) Process:(3776) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(3776) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3776) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3776) firefox.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3776) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3776) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1232) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Update.exe
(PID) Process:(2640) pingsender.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
69
Suspicious files
369
Text files
199
Unknown types
125

Dropped files

PID
Process
Filename
Type
3776firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
3776firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
MD5:
SHA256:
3776firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
MD5:
SHA256:
3776firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
MD5:
SHA256:
3776firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
MD5:
SHA256:
3776firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
MD5:
SHA256:
3776firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
MD5:
SHA256:
3776firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp
MD5:
SHA256:
3776firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:
SHA256:
3776firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4jsonlz4
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
19
DNS requests
66
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3776
firefox.exe
GET
143.204.201.75:80
http://download.tidal.com/desktop/TIDALSetup.exe
US
malicious
3776
firefox.exe
POST
200
172.217.21.195:80
http://ocsp.pki.goog/gts1o1
US
der
472 b
whitelisted
3776
firefox.exe
GET
200
23.55.110.80:80
http://detectportal.firefox.com/success.txt
US
text
8 b
whitelisted
3776
firefox.exe
POST
200
72.21.91.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3776
firefox.exe
POST
200
72.21.91.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3776
firefox.exe
POST
200
72.21.91.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3776
firefox.exe
GET
200
23.55.110.80:80
http://detectportal.firefox.com/success.txt
US
text
8 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3776
firefox.exe
23.55.110.80:80
detectportal.firefox.com
NTT America, Inc.
US
unknown
3776
firefox.exe
143.204.201.75:80
download.tidal.com
US
suspicious
3776
firefox.exe
54.149.124.142:443
search.services.mozilla.com
Amazon.com, Inc.
US
unknown
3776
firefox.exe
72.21.91.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3776
firefox.exe
143.204.201.83:443
snippets.cdn.mozilla.net
US
suspicious
3776
firefox.exe
99.86.3.76:443
firefox.settings.services.mozilla.com
AT&T Services, Inc.
US
shared
3776
firefox.exe
54.191.143.31:443
push.services.mozilla.com
Amazon.com, Inc.
US
unknown
3776
firefox.exe
54.213.38.240:443
shavar.services.mozilla.com
Amazon.com, Inc.
US
unknown
3776
firefox.exe
143.204.201.3:443
tracking-protection.cdn.mozilla.net
US
malicious
3776
firefox.exe
99.86.3.118:443
content-signature-2.cdn.mozilla.net
AT&T Services, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
download.tidal.com
  • 143.204.201.75
  • 143.204.201.29
  • 143.204.201.97
  • 143.204.201.19
malicious
detectportal.firefox.com
  • 23.55.110.80
  • 23.55.110.53
whitelisted
a1089.dscd.akamai.net
  • 23.55.110.53
  • 23.55.110.80
whitelisted
search.services.mozilla.com
  • 54.149.124.142
  • 52.38.153.3
  • 52.11.143.45
whitelisted
search.r53-2.services.mozilla.com
  • 52.11.143.45
  • 52.38.153.3
  • 54.149.124.142
whitelisted
push.services.mozilla.com
  • 54.191.143.31
whitelisted
autopush.prod.mozaws.net
  • 54.191.143.31
whitelisted
ocsp.digicert.com
  • 72.21.91.29
whitelisted
cs9.wac.phicdn.net
  • 72.21.91.29
whitelisted
snippets.cdn.mozilla.net
  • 143.204.201.83
  • 143.204.201.78
  • 143.204.201.68
  • 143.204.201.119
whitelisted

Threats

PID
Process
Class
Message
3776
firefox.exe
Potentially Bad Traffic
ET POLICY Executable served from Amazon S3
3776
firefox.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info