File name:

Firefox_Installer_x32.exe

Full analysis: https://app.any.run/tasks/5150fdad-cf9e-4189-8a81-4c90732efe3b
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: November 29, 2024, 15:52:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ransomware
infinitylock
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 4 sections
MD5:

B805DB8F6A84475EF76B795B0D1ED6AE

SHA1:

7711CB4873E58B7ADCF2A2B047B090E78D10C75B

SHA256:

F5D002BFE80B48386A6C99C41528931B7F5DF736CD34094463C3F85DDE0180BF

SSDEEP:

1536:YoCFfC303p22fkZrRQpnqjoi7l832fbu9ZXILwVENbMz:rCVC303p22sZrRQpnviB832Du9WMONu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • INFINITYLOCK has been detected (SURICATA)

      • Firefox_Installer_x32.exe (PID: 1916)
    • Connects to the CnC server

      • Firefox_Installer_x32.exe (PID: 1916)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Firefox_Installer_x32.exe (PID: 1916)
      • rundll32.exe (PID: 1776)
    • Contacting a server suspected of hosting an CnC

      • Firefox_Installer_x32.exe (PID: 1916)
  • INFO

    • Reads CPU info

      • Firefox_Installer_x32.exe (PID: 1916)
    • Reads the computer name

      • Firefox_Installer_x32.exe (PID: 1916)
      • wmpnscfg.exe (PID: 2264)
    • Checks supported languages

      • Firefox_Installer_x32.exe (PID: 1916)
      • wmpnscfg.exe (PID: 2264)
    • Reads the machine GUID from the registry

      • Firefox_Installer_x32.exe (PID: 1916)
    • Creates files or folders in the user directory

      • Firefox_Installer_x32.exe (PID: 1916)
    • Reads Environment values

      • Firefox_Installer_x32.exe (PID: 1916)
    • Disables trace logs

      • Firefox_Installer_x32.exe (PID: 1916)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2264)
      • rundll32.exe (PID: 1776)
      • explorer.exe (PID: 1612)
      • rundll32.exe (PID: 1492)
    • Application launched itself

      • msedge.exe (PID: 2824)
      • msedge.exe (PID: 2504)
    • Sends debugging messages

      • msedge.exe (PID: 2540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (55.8)
.exe | Win64 Executable (generic) (21)
.scr | Windows screen saver (9.9)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:06:14 15:34:11+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 189440
InitializedDataSize: 25600
UninitializedDataSize: -
EntryPoint: 0x3035e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.3.77.2
ProductVersionNumber: 2.3.77.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: PremiereCrack
CompanyName: Adobe Inc.
FileDescription: PremiereCrack
FileVersion: 2.3.77.2
InternalName: PremiereCrack.exe
LegalCopyright: Copyright © Adobe 2017
LegalTrademarks: Adobe Inc.
OriginalFileName: PremiereCrack.exe
ProductName: PremiereCrack
ProductVersion: 2.3.77.2
AssemblyVersion: 2.3.77.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
26
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #INFINITYLOCK firefox_installer_x32.exe wmpnscfg.exe no specs rundll32.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs explorer.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1492"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\abouteducation.rtf.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1556"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2228 --field-trial-handle=1332,i,3338744597106636137,9095834199128114034,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1612"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1776"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\expectedpolitical.rtf.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1796"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=16 --mojo-platform-channel-handle=3708 --field-trial-handle=1332,i,3338744597106636137,9095834199128114034,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1916"C:\Users\admin\AppData\Local\Temp\Firefox_Installer_x32.exe" C:\Users\admin\AppData\Local\Temp\Firefox_Installer_x32.exe
explorer.exe
User:
admin
Company:
Adobe Inc.
Integrity Level:
MEDIUM
Description:
PremiereCrack
Version:
2.3.77.2
Modules
Images
c:\users\admin\appdata\local\temp\firefox_installer_x32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2264"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2324"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1660 --field-trial-handle=1332,i,3338744597106636137,9095834199128114034,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2504"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://go.microsoft.com/fwlink/?LinkId=57426&Ext=6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBC:\Program Files\Microsoft\Edge\Application\msedge.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2540"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6679f598,0x6679f5a8,0x6679f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
4 129
Read events
4 066
Write events
57
Delete events
6

Modification events

(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASMANCS
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
Executable files
4
Suspicious files
154
Text files
28
Unknown types
0

Dropped files

PID
Process
Filename
Type
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\doingboard.rtf.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:CFC02366F2FEA1A20E2D08E486E14522
SHA256:AA35C8721508234AC541A580F6A57FD478CA620062BAAB9DEB0CEB6C6409992A
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\patientsport.rtf.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:F6C4779848A2B7032B8E26D1C35EB5C1
SHA256:34B97B52301CC179C2BB206CC26D638BD98684F76572D773C30F6E990A36F0AA
1916Firefox_Installer_x32.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:B70E26AE13A681D930758D5C8846C302
SHA256:9E5ACFA4B05409165998C6D9DC361ED01663EAF7852B1C60A71F16A3720E8CDA
1916Firefox_Installer_x32.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:D28AEF14B37BC40DBD85486CB7D90E81
SHA256:9584D23633A817251425A5D84EC936F0454D0693BD47E94AAE1CF9FECA90BC9F
1916Firefox_Installer_x32.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:779B8DD2ED5BB97F254EF651D83985AD
SHA256:EF588D7B68E1AFCC96B4BF4BEC40CB8DE1B1F7B11BB84DA46653DCEB7770A368
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\doingjustice.rtf.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:19AAA04437003B993B74A3A1411E2080
SHA256:7D94FE6BFE26A80308B5E32B64040A7D76392C5368340867BEB831596E7BB1BB
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:F6356EABF9F5BB27290E294125CB3DE4
SHA256:1382484AED621C500F15D89E155CB32209BEE8374A9844C7412B84566EDB33FA
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:E89C33B0C5592342FA3155CD4B767D60
SHA256:C51C6913A0172019EA14AEBFF87E19EF42022AF3D34177E4E96D7C40E48F8121
1916Firefox_Installer_x32.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:507A931FAE97F798DF77730E348B3591
SHA256:7541A1C7E2F8F61ECE06B3068DC6FCDC136AFD51A12FFCA912046076FEEEF5B6
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\PowerShell\Modules\PSSQLite\1.1.0\Invoke-SqliteQuery.ps1.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:59BEA3C2905592E474706F0E22DDE920
SHA256:7283A8729D8EEA057D686DE0A048A7CBEEA9DB8921E0FDFD5E393C4A3BA826A3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
26
DNS requests
28
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3120
msedge.exe
GET
302
23.213.170.81:80
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DB
unknown
whitelisted
3120
msedge.exe
GET
301
184.24.77.9:80
http://shell.windows.com/fileassoc/fileassoc.asp?Ext=6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DB
unknown
whitelisted
3120
msedge.exe
GET
302
23.213.170.81:80
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DB
unknown
whitelisted
1916
Firefox_Installer_x32.exe
GET
403
162.55.0.137:80
http://arizonacode.bplaced.net/rnsm/add.php?type=add&data=InfinityCrypt%7Cadmin%7ChPVgCxXxynBsxXxAvIaxXxlVVyxXxRLX7xXxuRmlxXx%7CMicrosoft%20Windows%207%20Professional%20%7C6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DB%7C67
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1916
Firefox_Installer_x32.exe
162.55.0.137:80
arizonacode.bplaced.net
Hetzner Online GmbH
DE
whitelisted
2824
msedge.exe
239.255.255.250:1900
whitelisted
3120
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3120
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3120
msedge.exe
23.213.170.81:80
go.microsoft.com
AKAMAI-AS
DE
whitelisted
3120
msedge.exe
184.24.77.9:80
shell.windows.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
arizonacode.bplaced.net
  • 162.55.0.137
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
go.microsoft.com
  • 23.213.170.81
whitelisted
shell.windows.com
  • 184.24.77.9
  • 184.24.77.27
whitelisted
www.bing.com
  • 104.126.37.154
  • 104.126.37.161
  • 104.126.37.145
  • 104.126.37.137
  • 104.126.37.170
  • 104.126.37.179
  • 104.126.37.123
  • 104.126.37.139
  • 104.126.37.144
whitelisted
r.bing.com
  • 104.126.37.179
  • 104.126.37.139
  • 104.126.37.155
  • 104.126.37.145
  • 104.126.37.123
  • 104.126.37.137
  • 104.126.37.154
  • 104.126.37.144
  • 104.126.37.161
  • 104.126.37.170
whitelisted
th.bing.com
  • 104.126.37.137
  • 104.126.37.161
  • 104.126.37.170
  • 104.126.37.144
  • 104.126.37.155
  • 104.126.37.145
  • 104.126.37.139
  • 104.126.37.123
  • 104.126.37.154
whitelisted
login.microsoftonline.com
  • 20.190.159.0
  • 20.190.159.4
  • 40.126.31.67
  • 20.190.159.75
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.23
  • 20.190.159.71
whitelisted

Threats

PID
Process
Class
Message
1916
Firefox_Installer_x32.exe
Misc activity
ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M1
1 ETPRO signatures available at the full report
Process
Message
msedge.exe
[1129/155303.706:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)