URL:

https://clientperipherals.dell.com/DPeM/updates/v2/x64/FullInstaller/Setup.exe

Full analysis: https://app.any.run/tasks/acc3e902-9dad-4584-80c4-d9a2c44f912d
Verdict: Malicious activity
Analysis date: November 13, 2024, 11:37:19
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

BE27889697699E5A153485700F962C69

SHA1:

5C266FF0C0723FA71DE0979374BAF37A240EB657

SHA256:

E89E1A4C58F19523A4265A76D765D36B5E52A9986A10C603B9DCC8A5943AFB87

SSDEEP:

3:N8UxXYL2SKIfohDNSlTXK2aA:2UxoL2SKMo6XGA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates file in the systems drive root

      • firefox.exe (PID: 6624)
    • The process creates files with name similar to system file names

      • Setup.exe (PID: 2784)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Setup.exe (PID: 2784)
    • Creates files in the driver directory

      • drvinst.exe (PID: 7600)
      • drvinst.exe (PID: 2684)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 2784)
      • pnputil.exe (PID: 1048)
      • drvinst.exe (PID: 7600)
      • pnputil.exe (PID: 5912)
      • drvinst.exe (PID: 2684)
      • pnputil.exe (PID: 7592)
      • drvinst.exe (PID: 5652)
      • IndiDriverInstallUtilx64.exe (PID: 7092)
      • drvinst.exe (PID: 7528)
    • Drops a system driver (possible attempt to evade defenses)

      • pnputil.exe (PID: 1048)
      • Setup.exe (PID: 2784)
      • pnputil.exe (PID: 5912)
      • drvinst.exe (PID: 2684)
      • IndiDriverInstallUtilx64.exe (PID: 7092)
      • drvinst.exe (PID: 7600)
      • drvinst.exe (PID: 7528)
    • Process drops legitimate windows executable

      • Setup.exe (PID: 2784)
    • The process drops C-runtime libraries

      • Setup.exe (PID: 2784)
    • Executes as Windows Service

      • DPMService.exe (PID: 6856)
  • INFO

    • Executable content was dropped or overwritten

      • firefox.exe (PID: 6624)
    • Application launched itself

      • firefox.exe (PID: 1576)
      • firefox.exe (PID: 6624)
    • Reads the software policy settings

      • slui.exe (PID: 6168)
      • drvinst.exe (PID: 7600)
    • The process uses the downloaded file

      • firefox.exe (PID: 6624)
    • Checks supported languages

      • Setup.exe (PID: 2784)
      • drvinst.exe (PID: 7600)
    • Reads the computer name

      • Setup.exe (PID: 2784)
    • Creates files in the program directory

      • Setup.exe (PID: 2784)
    • Create files in a temporary directory

      • Setup.exe (PID: 2784)
      • pnputil.exe (PID: 1048)
      • pnputil.exe (PID: 7592)
      • pnputil.exe (PID: 5912)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 7600)
    • Sends debugging messages

      • DPM.exe (PID: 6472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
186
Monitored processes
45
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs sppextcomobj.exe no specs slui.exe slui.exe setup.exe no specs setup.exe pnputil.exe conhost.exe no specs drvinst.exe pnputil.exe conhost.exe no specs drvinst.exe pnputil.exe conhost.exe no specs drvinst.exe indidriverinstallutilx64.exe no specs conhost.exe no specs indidriverinstallutilx64.exe conhost.exe no specs drvinst.exe drvinst.exe no specs dpmservice.exe no specs conhost.exe no specs dpmservice.exe no specs conhost.exe no specs installerhelper.exe no specs conhost.exe no specs dpmservice.exe no specs conhost.exe no specs dpmcrashhandler.exe no specs dpmservice.exe dpmcrashhandler.exe no specs dpm.exe dpmcrashhandler.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
512"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2832 -childID 1 -isForBrowser -prefsHandle 2824 -prefMapHandle 2820 -prefsLen 26798 -prefMapSize 244343 -jsInitHandle 1316 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {503e4128-b736-4fe4-8c9f-c6aa80a2231b} 6624 "\\.\pipe\gecko-crash-server-pipe.6624" 207a6585150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
848\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeDPMService.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1048"C:\WINDOWS\system32\PnPutil.exe" /add-driver "C:\Program Files\Dell\Dell Peripheral Manager\temp\WacomComponents\WacHIDRouterISDU.inf" /installC:\Windows\System32\pnputil.exe
Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft PnP Utility - Tool to add, delete, export, and enumerate driver packages.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\pnputil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\devobj.dll
c:\windows\system32\advapi32.dll
1172"C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exe" "--database=C:\Users\admin\AppData\Roaming\Dell\Dell Peripheral Manager\DPM\Log\\crashdumps\database" "--metrics-dir=C:\Users\admin\AppData\Roaming\Dell\Dell Peripheral Manager\DPM\Log\\crashdumps\metrics" --annotation=VERSION_FULL_SEMVER=1.7.7 --annotation=VERSION_SEMVER=1.7.7 --initial-client-data=0x648,0x678,0x67c,0x674,0x684,0x7ff6edbcb658,0x7ff6edbcb670,0x7ff6edbcb688C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exeDPM.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\dell\dell peripheral manager\dpmcrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1200"C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exe" "--database=C:\ProgramData\Dell\Dell Peripheral Manager\DPMService\Log\\crashdumps\database" "--metrics-dir=C:\ProgramData\Dell\Dell Peripheral Manager\DPMService\Log\\crashdumps\metrics" --annotation=VERSION_FULL_SEMVER=1.7.7 --annotation=VERSION_SEMVER=1.7.7 --initial-client-data=0x504,0x52c,0x530,0x528,0x538,0x7ff7a07f1958,0x7ff7a07f1970,0x7ff7a07f1988C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exeDPMService.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files\dell\dell peripheral manager\dpmcrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1576"C:\Program Files\Mozilla Firefox\firefox.exe" "https://clientperipherals.dell.com/DPeM/updates/v2/x64/FullInstaller/Setup.exe"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
2684DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{d49fcc1f-1195-5041-b4f4-14bdcbc806ec}\WacHIDRouterISDF.inf" "9" "423699577" "00000000000001EC" "WinSta0\Default" "00000000000001FC" "208" "C:\Program Files\Dell\Dell Peripheral Manager\temp\WacomComponents"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2784"C:\Users\admin\Downloads\Setup.exe" C:\Users\admin\Downloads\Setup.exe
firefox.exe
User:
admin
Company:
Dell
Integrity Level:
HIGH
Description:
Dell Peripheral Manager Installer
Exit code:
0
Version:
${FILE_VERSION}
Modules
Images
c:\users\admin\downloads\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
3024"C:\Program Files\Dell\Dell Peripheral Manager\DPMService.exe" -regserverC:\Program Files\Dell\Dell Peripheral Manager\DPMService.exeSetup.exe
User:
admin
Company:
Dell Inc.
Integrity Level:
HIGH
Description:
Dell Peripheral Manager Service
Exit code:
0
Version:
1.7.7
Modules
Images
c:\program files\dell\dell peripheral manager\dpmservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wintrust.dll
c:\program files\dell\dell peripheral manager\qt5network.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
3620\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepnputil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
47 654
Read events
47 530
Write events
116
Delete events
8

Modification events

(PID) Process:(6624) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(6624) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(1048) pnputil.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPMDriver
Operation:writeName:Owners
Value:
oem8.inf
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPMDriver\Parameters\Wdf
Operation:writeName:KmdfLibraryVersion
Value:
1.15
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemRoot%/System32/drivers/DPMDriver.sys
Operation:writeName:Owners
Value:
oem8.inf
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Descriptors\Root\DPMDriver
Operation:writeName:Configuration
Value:
DPMDriver_Device.NT
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Descriptors\Root\DPMDriver
Operation:writeName:Manufacturer
Value:
%manufacturername%
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Descriptors\Root\DPMDriver
Operation:writeName:Description
Value:
%dpmdriver.devicedesc%
(PID) Process:(8168) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Configurations\DPMDriver_Device.NT
Operation:writeName:Service
Value:
DPMDriver
Executable files
279
Suspicious files
800
Text files
103
Unknown types
23

Dropped files

PID
Process
Filename
Type
6624firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.tmpdbf
MD5:F759EB25271E6A6F0A3500520813E5FE
SHA256:015E515D432DD64FDC9502ABE9C723EEF544E7AF11C36BDFE8B38412597CA1EC
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:F81FD355961DC964C7A4B57FB359C157
SHA256:F468B0845CE66427A71D5F0D41CDF0E19EB3E6A7C64772ECD89D230EF01A6061
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.dbbinary
MD5:FF680518BF4ABD23AE2D25C24B050864
SHA256:2A743CABB6714DF481CC77B8B0DDB6B3B87A1D2DD006ACE99410BC256FAC5F50
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6624firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
106
DNS requests
123
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6624
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
6624
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
6624
firefox.exe
POST
200
2.16.202.121:80
http://r11.o.lencr.org/
unknown
whitelisted
6624
firefox.exe
POST
200
142.250.184.195:80
http://o.pki.goog/s/wr3/yvU
unknown
whitelisted
6624
firefox.exe
POST
200
2.16.202.121:80
http://r11.o.lencr.org/
unknown
whitelisted
6624
firefox.exe
POST
142.250.184.195:80
http://o.pki.goog/wr2
unknown
whitelisted
6624
firefox.exe
POST
200
2.16.202.121:80
http://r10.o.lencr.org/
unknown
whitelisted
6624
firefox.exe
POST
200
2.16.202.121:80
http://r11.o.lencr.org/
unknown
whitelisted
6624
firefox.exe
POST
200
2.16.202.121:80
http://r10.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2660
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5488
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2.23.209.173:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6944
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
6624
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
6624
firefox.exe
2.19.126.160:443
clientperipherals.dell.com
Akamai International B.V.
DE
whitelisted
6624
firefox.exe
34.117.188.166:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.23.209.173
  • 2.23.209.168
  • 2.23.209.177
  • 2.23.209.174
  • 2.23.209.182
  • 2.23.209.175
  • 2.23.209.176
  • 2.23.209.166
  • 2.23.209.179
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.142
  • 2.23.209.137
  • 2.23.209.193
  • 2.23.209.189
  • 2.23.209.192
  • 2.23.209.136
  • 2.23.209.141
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.186.46
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
clientperipherals.dell.com
  • 2.19.126.160
  • 2.19.126.141
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
a664.dscd.akamai.net
  • 2.19.126.160
  • 2.19.126.141
  • 2a02:26f0:480:33::212:40d9
  • 2a02:26f0:480:33::212:40db
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
example.org
  • 93.184.215.14
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted

Threats

No threats detected
Process
Message
DPM.exe
C:\Users\Public\Desktop\Adobe Acrobat.lnk
DPM.exe
C:\Users\Public\Desktop\Skype.lnk
DPM.exe
C:\Users\Public\Desktop\Microsoft Edge.lnk
DPM.exe
C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
DPM.exe
C:\Users\Public\Desktop\VLC media player.lnk
DPM.exe
real path
DPM.exe
real path
DPM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
DPM.exe
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
DPM.exe
C:\Users\Public\Desktop\CCleaner.lnk