URL:

https://abbaspc.net

Full analysis: https://app.any.run/tasks/9146087f-c9b3-44a8-90c2-d2902dfb277c
Verdict: Malicious activity
Threats:

CryptBot is an advanced Windows-targeting infostealer delivered via pirate sites with "cracked" software. It has been first observed in the wild in 2019.

Analysis date: September 19, 2023, 11:16:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
stealer
cryptbot
g0njxa
Indicators:
MD5:

E1EE041D9D4D2E7E2736E95DEA432F98

SHA1:

DDBD88A9CE2CA47C7115782AE47C042D980E9B30

SHA256:

EE1062B2B1AED2A130CD1E646AE306935384D1632CE069B1F3F5FB41F87825A6

SSDEEP:

3:N8lLAR:2RAR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • free_setup-activator.exe (PID: 3292)
    • CRYPTBOT was detected

      • free_setup-activator.exe (PID: 3292)
    • Actions looks like stealing of personal data

      • free_setup-activator.exe (PID: 3292)
  • SUSPICIOUS

    • Searches for installed software

      • free_setup-activator.exe (PID: 3292)
    • Reads the Internet Settings

      • free_setup-activator.exe (PID: 3292)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 3788)
      • firefox.exe (PID: 3420)
    • Application launched itself

      • firefox.exe (PID: 3420)
    • Manual execution by a user

      • WinRAR.exe (PID: 3788)
    • Checks supported languages

      • free_setup-activator.exe (PID: 3292)
    • Reads the computer name

      • free_setup-activator.exe (PID: 3292)
    • Reads CPU info

      • free_setup-activator.exe (PID: 3292)
    • Reads Environment values

      • free_setup-activator.exe (PID: 3292)
    • Reads product name

      • free_setup-activator.exe (PID: 3292)
    • Checks proxy server information

      • free_setup-activator.exe (PID: 3292)
    • Reads the machine GUID from the registry

      • free_setup-activator.exe (PID: 3292)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
14
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winrar.exe no specs #CRYPTBOT free_setup-activator.exe

Process information

PID
CMD
Path
Indicators
Parent process
780"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3420.2.1046703321\866938396" -childID 1 -isForBrowser -prefsHandle 2036 -prefMapHandle 2032 -prefsLen 25361 -prefMapSize 244147 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {85076844-8558-4b18-8226-c088be8bed14} 3420 "\\.\pipe\gecko-crash-server-pipe.3420" 2052 1965a258 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
832"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3420.1.1444304581\1589387931" -parentBuildID 20230710165010 -prefsHandle 1384 -prefMapHandle 1380 -prefsLen 29601 -prefMapSize 244147 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f664b9fb-3245-47d2-b510-a6468167e05e} 3420 "\\.\pipe\gecko-crash-server-pipe.3420" 1396 42d0258 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2224"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3420.7.464732396\1486807298" -childID 6 -isForBrowser -prefsHandle 4080 -prefMapHandle 4076 -prefsLen 35552 -prefMapSize 244147 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7df01cd2-22e0-4cfb-9b17-0c6e6e32bd53} 3420 "\\.\pipe\gecko-crash-server-pipe.3420" 4064 23254258 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
2316"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3420.6.1668161302\1976604718" -childID 5 -isForBrowser -prefsHandle 3768 -prefMapHandle 3840 -prefsLen 30211 -prefMapSize 244147 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fe1a7d40-cb80-4737-86f1-c0193ebf9ee8} 3420 "\\.\pipe\gecko-crash-server-pipe.3420" 3948 23253958 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
2360"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3420.3.859793402\506857069" -childID 2 -isForBrowser -prefsHandle 2892 -prefMapHandle 2888 -prefsLen 35203 -prefMapSize 244147 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e5b5256b-e4b7-4abf-80b2-3bdf99ef3cbe} 3420 "\\.\pipe\gecko-crash-server-pipe.3420" 2908 1e107c58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
2532"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3420.10.354502256\1318730900" -childID 9 -isForBrowser -prefsHandle 8376 -prefMapHandle 8368 -prefsLen 30292 -prefMapSize 244147 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {157317c8-8ad8-41d3-82c2-3c9e483a560c} 3420 "\\.\pipe\gecko-crash-server-pipe.3420" 8356 26feed58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
2704"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3420.5.1048966822\1169253940" -childID 4 -isForBrowser -prefsHandle 3860 -prefMapHandle 3864 -prefsLen 30211 -prefMapSize 244147 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {434166a8-f8f2-43ba-b4ed-f937d1e88d33} 3420 "\\.\pipe\gecko-crash-server-pipe.3420" 3848 23252a58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2912"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3420.4.1564401165\1555329265" -childID 3 -isForBrowser -prefsHandle 3740 -prefMapHandle 3664 -prefsLen 30211 -prefMapSize 244147 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {79f1ba7c-9677-46bb-9df6-303c580c5f6f} 3420 "\\.\pipe\gecko-crash-server-pipe.3420" 3752 1f27fb58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
3292"C:\Users\admin\AppData\Local\Temp\Rar$EXb3788.25043\free_setup-activator.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3788.25043\free_setup-activator.exe
WinRAR.exe
User:
admin
Company:
Spiritspin Software
Integrity Level:
MEDIUM
Description:
Spiritspin Setup
Exit code:
0
Version:
2.0.4.1230
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\rar$exb3788.25043\free_setup-activator.exe
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
3420"C:\Program Files\Mozilla Firefox\firefox.exe" "https://abbaspc.net"C:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
Total events
11 291
Read events
11 186
Write events
105
Delete events
0

Modification events

(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
0000000000000000
(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
0
(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
CA0A97189BC5D901
(PID) Process:(3420) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
2
Suspicious files
426
Text files
62
Unknown types
37

Dropped files

PID
Process
Filename
Type
3420firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3420firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3420firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\scriptCache-child-current.binbinary
MD5:3E687F1CDE81D724075D31C078C104E7
SHA256:ADB1769C7BB3D37001B58B504E1BE58AA6FC1CCC2E8D763BAA58CD69256571FC
3420firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3420firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
3420firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
3420firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
3420firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cert9.db-journalbinary
MD5:1453B228BFB95775809AA8D3DBE7BF36
SHA256:AA315A4A3AB93E60CAC73E01D3F0EC64E7FB2F578184E10CA550A9FB4BF3381B
3420firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.binbinary
MD5:4DF9B77C7650AF87B264E535779AE2A4
SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58
3420firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\15440FE6823902A6B41FD6285FDE2DD23D66FD3Bbinary
MD5:750EE7DA2BC7AC6A35B5F3439B0F6041
SHA256:0CF5D76BB62FD1BDF72984079BECACB55650C0E3398FF7AB16BFD85B097EC3DD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
96
DNS requests
204
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3420
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
3420
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
der
471 b
unknown
3420
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
3420
firefox.exe
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
3420
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
der
471 b
unknown
3420
firefox.exe
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
3420
firefox.exe
POST
200
18.238.20.52:80
http://ocsp.r2m02.amazontrust.com/
unknown
der
471 b
unknown
3420
firefox.exe
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
3420
firefox.exe
POST
200
142.250.74.195:80
http://ocsp.pki.goog/gts1c3
unknown
der
471 b
unknown
3420
firefox.exe
POST
200
142.250.74.195:80
http://ocsp.pki.goog/gts1c3
unknown
der
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3420
firefox.exe
104.26.15.242:443
abbaspc.net
CLOUDFLARENET
US
shared
1208
svchost.exe
239.255.255.250:1900
whitelisted
3420
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
3420
firefox.exe
35.244.181.201:443
aus5.mozilla.org
GOOGLE
US
unknown
3420
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3420
firefox.exe
34.197.137.200:443
spocs.getpocket.com
AMAZON-AES
US
unknown
3420
firefox.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3420
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
abbaspc.net
  • 104.26.15.242
  • 104.26.14.242
  • 172.67.69.237
  • 2606:4700:20::681a:ef2
  • 2606:4700:20::ac43:45ed
  • 2606:4700:20::681a:ff2
unknown
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
aus5.mozilla.org
  • 35.244.181.201
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
prod.balrog.prod.cloudops.mozgcp.net
  • 35.244.181.201
whitelisted
spocs.getpocket.com
  • 34.197.137.200
  • 18.215.75.185
  • 184.72.95.230
  • 44.214.229.86
shared
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 44.214.229.86
  • 184.72.95.230
  • 18.215.75.185
  • 34.197.137.200
shared

Threats

PID
Process
Class
Message
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
332
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
332
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
3292
free_setup-activator.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
3292
free_setup-activator.exe
A Network Trojan was detected
ET HUNTING Observed Malicious Filename in Outbound POST Request (Information.txt)
3292
free_setup-activator.exe
A Network Trojan was detected
ET MALWARE Win32/Cryptbot CnC Activity (POST)
No debug info