URL:

https://www.easyobdii.com

Full analysis: https://app.any.run/tasks/1d5ed0de-7c3f-46d1-91f5-a68b0ac26f11
Verdict: Malicious activity
Analysis date: October 26, 2023, 07:27:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
SHA1:

A5D6FB2DF85398DBA105B7B7001ACB1A87EFB807

SHA256:

E6A885BAE9C0C700E4A7EBDAD4DAF3344474FEF19FFE99BF141E5EA64E333AEE

SSDEEP:

3:N8DSLAc4GT:2OLA6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • EasyObdII 2.5.7 Free Setup.exe (PID: 2924)
      • EasyObdII 2.5.7 Free Setup.exe (PID: 4064)
      • EasyObdII_Ver2_5_7.exe (PID: 2452)
    • Drops the executable file immediately after the start

      • EasyObdII 2.5.7 Free Setup.exe (PID: 2924)
      • EasyObdII 2.5.7 Free Setup.exe (PID: 4064)
      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3908)
    • Loads dropped or rewritten executable

      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3908)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3908)
    • Process drops legitimate windows executable

      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3908)
    • Reads the Internet Settings

      • EasyObdII_Ver2_5_7.exe (PID: 2452)
      • WMIC.exe (PID: 2680)
      • WMIC.exe (PID: 3560)
      • WMIC.exe (PID: 3492)
    • Starts CMD.EXE for commands execution

      • EasyObdII_Ver2_5_7.exe (PID: 2452)
    • Uses WMIC.EXE to obtain operating system information

      • cmd.exe (PID: 2052)
      • cmd.exe (PID: 3660)
      • cmd.exe (PID: 3072)
    • Detected use of alternative data streams (AltDS)

      • EasyObdII_Ver2_5_7.exe (PID: 2452)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 1412)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 852)
      • firefox.exe (PID: 1052)
    • The process uses the downloaded file

      • firefox.exe (PID: 1052)
      • WinRAR.exe (PID: 1324)
    • Manual execution by a user

      • WinRAR.exe (PID: 1324)
      • EasyObdII 2.5.7 Free Setup.exe (PID: 2924)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1324)
      • firefox.exe (PID: 1052)
    • Checks supported languages

      • EasyObdII 2.5.7 Free Setup.exe (PID: 2924)
      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3428)
      • EasyObdII 2.5.7 Free Setup.exe (PID: 4064)
      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3908)
      • EasyObdII_Ver2_5_7.exe (PID: 2452)
    • Create files in a temporary directory

      • EasyObdII 2.5.7 Free Setup.exe (PID: 2924)
      • EasyObdII 2.5.7 Free Setup.exe (PID: 4064)
      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3908)
    • Reads the computer name

      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3428)
      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3908)
      • EasyObdII_Ver2_5_7.exe (PID: 2452)
    • Creates files in the program directory

      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3908)
    • Application was dropped or rewritten from another process

      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3428)
      • EasyObdII 2.5.7 Free Setup.tmp (PID: 3908)
    • Checks proxy server information

      • EasyObdII_Ver2_5_7.exe (PID: 2452)
    • Reads the machine GUID from the registry

      • EasyObdII_Ver2_5_7.exe (PID: 2452)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
25
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winrar.exe no specs easyobdii 2.5.7 free setup.exe no specs easyobdii 2.5.7 free setup.tmp no specs easyobdii 2.5.7 free setup.exe easyobdii 2.5.7 free setup.tmp no specs easyobdii_ver2_5_7.exe cmd.exe no specs wmic.exe no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs wmic.exe no specs cmd.exe no specs reg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
852"C:\Program Files\Mozilla Firefox\firefox.exe" "https://www.easyobdii.com"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
1052"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.easyobdii.comC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1324"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Downloads\EasyObdII 2.5.7 Free Setup.zip" "C:\Users\admin\Downloads\EasyObdII 2.5.7 Free Setup\"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
1412cmd.exe /C REG QUERY "HKEY_LOCAL_MACHINE\HARDWARE\DEVICEMAP\SERIALCOMM" /sC:\Windows\System32\cmd.exeEasyObdII_Ver2_5_7.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1592"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1052.7.1267628217\1872969449" -childID 6 -isForBrowser -prefsHandle 7764 -prefMapHandle 7760 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c8e46d26-afb9-42b6-a7b7-5ffb5190de91} 1052 "\\.\pipe\gecko-crash-server-pipe.1052" 7776 19cf2c90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1904"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1052.2.2000720236\1157252166" -childID 1 -isForBrowser -prefsHandle 2056 -prefMapHandle 2052 -prefsLen 24491 -prefMapSize 244195 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7567a061-1b27-408b-8fbf-7542c7c1e181} 1052 "\\.\pipe\gecko-crash-server-pipe.1052" 2068 12a936d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2052cmd.exe /C wmic os get OSArchitectureC:\Windows\System32\cmd.exeEasyObdII_Ver2_5_7.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2268REG QUERY "HKEY_LOCAL_MACHINE\HARDWARE\DEVICEMAP\SERIALCOMM" /sC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2392"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1052.1.688139072\109518882" -parentBuildID 20230710165010 -prefsHandle 1400 -prefMapHandle 1396 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {424e50a3-c9e9-496c-b2fe-f170dc0d0465} 1052 "\\.\pipe\gecko-crash-server-pipe.1052" 1412 f231710 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msvcrt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2452"C:\Program Files\EasyObdII Free Software\EasyObdII_Ver2_5_7.exe"C:\Program Files\EasyObdII Free Software\EasyObdII_Ver2_5_7.exe
EasyObdII 2.5.7 Free Setup.tmp
User:
admin
Company:
EasyObdII.com
Integrity Level:
MEDIUM
Description:
EasyObdII 2.5.7 for Windows
Exit code:
0
Version:
2.5.7.0
Modules
Images
c:\program files\easyobdii free software\easyobdii_ver2_5_7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
16 116
Read events
16 062
Write events
48
Delete events
6

Modification events

(PID) Process:(852) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
2166C0A101000000
(PID) Process:(1052) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
044CC1A101000000
(PID) Process:(1052) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(1052) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(1052) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(1052) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(1052) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(1052) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(1052) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(1052) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
D14E5F3C23B0D901
Executable files
14
Suspicious files
279
Text files
46
Unknown types
0

Dropped files

PID
Process
Filename
Type
1052firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
1052firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
1052firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
1052firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:09CCD48FE48F98939135BFFB3F259E3B
SHA256:62B1C0EB03CD39728D9BE647ADB6EBAAE3286E36142CC224506A57BC1CC52BEF
1052firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:B7A3C61D0C144CC5E166B1E769CA8F8C
SHA256:7FADCB77FFACA6B9E9F15C6F1CD3AAD4C20DCD90FA92429A627A3A7110CA2644
1052firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:09CCD48FE48F98939135BFFB3F259E3B
SHA256:62B1C0EB03CD39728D9BE647ADB6EBAAE3286E36142CC224506A57BC1CC52BEF
1052firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
1052firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
1052firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.binbinary
MD5:1C3C58F7838DDE7F753614D170F110FC
SHA256:81C14432135B2A50DC505904E87781864CA561EFEF9E94BAECA3704D04E6DB3D
1052firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.tmpbinary
MD5:1C3C58F7838DDE7F753614D170F110FC
SHA256:81C14432135B2A50DC505904E87781864CA561EFEF9E94BAECA3704D04E6DB3D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
98
DNS requests
171
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1052
firefox.exe
POST
200
18.245.65.219:80
http://ocsp.r2m02.amazontrust.com/
unknown
binary
471 b
unknown
1052
firefox.exe
POST
95.101.54.131:80
http://r3.o.lencr.org/
unknown
unknown
1052
firefox.exe
POST
200
142.250.184.227:80
http://ocsp.pki.goog/gts1c3
unknown
binary
471 b
unknown
1052
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
1052
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
1052
firefox.exe
POST
200
142.250.184.227:80
http://ocsp.pki.goog/gts1c3
unknown
binary
471 b
unknown
1052
firefox.exe
POST
95.101.54.131:80
http://r3.o.lencr.org/
unknown
unknown
1052
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
1052
firefox.exe
POST
200
95.101.54.131:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
1052
firefox.exe
POST
200
142.250.184.227:80
http://ocsp.pki.goog/gts1c3
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1052
firefox.exe
172.217.16.202:443
safebrowsing.googleapis.com
whitelisted
1052
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
4
System
192.168.100.255:137
whitelisted
1052
firefox.exe
18.245.65.219:80
ocsp.r2m02.amazontrust.com
US
unknown
1052
firefox.exe
18.193.36.153:443
www.easyobdii.com
AMAZON-02
DE
unknown
1052
firefox.exe
142.250.184.227:80
ocsp.pki.goog
GOOGLE
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1052
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
unknown
1052
firefox.exe
34.117.65.55:443
push.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2656
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
www.easyobdii.com
  • 18.193.36.153
  • 3.67.141.185
  • 3.127.73.216
unknown
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
d1-hitch-eu-nlb-e064e2845fd0c838.elb.eu-central-1.amazonaws.com
  • 3.127.73.216
  • 18.193.36.153
  • 3.67.141.185
unknown
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted
r3.o.lencr.org
  • 95.101.54.131
  • 2.16.202.121
  • 184.24.77.54
  • 184.24.77.48
shared
spocs.getpocket.com
  • 3.221.31.29
  • 34.192.30.2
  • 54.86.121.215
  • 54.164.216.90
shared

Threats

No threats detected
No debug info