File name:

Firefox_Installer_x32.exe

Full analysis: https://app.any.run/tasks/5150fdad-cf9e-4189-8a81-4c90732efe3b
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: November 29, 2024, 15:52:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ransomware
infinitylock
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 4 sections
MD5:

B805DB8F6A84475EF76B795B0D1ED6AE

SHA1:

7711CB4873E58B7ADCF2A2B047B090E78D10C75B

SHA256:

F5D002BFE80B48386A6C99C41528931B7F5DF736CD34094463C3F85DDE0180BF

SSDEEP:

1536:YoCFfC303p22fkZrRQpnqjoi7l832fbu9ZXILwVENbMz:rCVC303p22sZrRQpnviB832Du9WMONu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • Firefox_Installer_x32.exe (PID: 1916)
    • INFINITYLOCK has been detected (SURICATA)

      • Firefox_Installer_x32.exe (PID: 1916)
  • SUSPICIOUS

    • Contacting a server suspected of hosting an CnC

      • Firefox_Installer_x32.exe (PID: 1916)
    • Reads the Internet Settings

      • Firefox_Installer_x32.exe (PID: 1916)
      • rundll32.exe (PID: 1776)
  • INFO

    • Reads the computer name

      • Firefox_Installer_x32.exe (PID: 1916)
      • wmpnscfg.exe (PID: 2264)
    • Creates files or folders in the user directory

      • Firefox_Installer_x32.exe (PID: 1916)
    • Checks supported languages

      • Firefox_Installer_x32.exe (PID: 1916)
      • wmpnscfg.exe (PID: 2264)
    • Reads Environment values

      • Firefox_Installer_x32.exe (PID: 1916)
    • Reads the machine GUID from the registry

      • Firefox_Installer_x32.exe (PID: 1916)
    • Reads CPU info

      • Firefox_Installer_x32.exe (PID: 1916)
    • Disables trace logs

      • Firefox_Installer_x32.exe (PID: 1916)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2264)
      • rundll32.exe (PID: 1776)
      • explorer.exe (PID: 1612)
      • rundll32.exe (PID: 1492)
    • Application launched itself

      • msedge.exe (PID: 2824)
      • msedge.exe (PID: 2504)
    • Sends debugging messages

      • msedge.exe (PID: 2540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (55.8)
.exe | Win64 Executable (generic) (21)
.scr | Windows screen saver (9.9)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:06:14 15:34:11+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 189440
InitializedDataSize: 25600
UninitializedDataSize: -
EntryPoint: 0x3035e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.3.77.2
ProductVersionNumber: 2.3.77.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: PremiereCrack
CompanyName: Adobe Inc.
FileDescription: PremiereCrack
FileVersion: 2.3.77.2
InternalName: PremiereCrack.exe
LegalCopyright: Copyright © Adobe 2017
LegalTrademarks: Adobe Inc.
OriginalFileName: PremiereCrack.exe
ProductName: PremiereCrack
ProductVersion: 2.3.77.2
AssemblyVersion: 2.3.77.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
26
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #INFINITYLOCK firefox_installer_x32.exe wmpnscfg.exe no specs rundll32.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs explorer.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1492"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\abouteducation.rtf.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1556"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2228 --field-trial-handle=1332,i,3338744597106636137,9095834199128114034,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1612"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1776"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\expectedpolitical.rtf.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1796"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=16 --mojo-platform-channel-handle=3708 --field-trial-handle=1332,i,3338744597106636137,9095834199128114034,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1916"C:\Users\admin\AppData\Local\Temp\Firefox_Installer_x32.exe" C:\Users\admin\AppData\Local\Temp\Firefox_Installer_x32.exe
explorer.exe
User:
admin
Company:
Adobe Inc.
Integrity Level:
MEDIUM
Description:
PremiereCrack
Version:
2.3.77.2
Modules
Images
c:\users\admin\appdata\local\temp\firefox_installer_x32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2264"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2324"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1660 --field-trial-handle=1332,i,3338744597106636137,9095834199128114034,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2504"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://go.microsoft.com/fwlink/?LinkId=57426&Ext=6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBC:\Program Files\Microsoft\Edge\Application\msedge.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2540"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6679f598,0x6679f5a8,0x6679f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
4 129
Read events
4 066
Write events
57
Delete events
6

Modification events

(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASMANCS
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1916) Firefox_Installer_x32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Firefox_Installer_x32_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
Executable files
4
Suspicious files
154
Text files
28
Unknown types
0

Dropped files

PID
Process
Filename
Type
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:E89C33B0C5592342FA3155CD4B767D60
SHA256:C51C6913A0172019EA14AEBFF87E19EF42022AF3D34177E4E96D7C40E48F8121
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\messagezone.rtf.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:FC052A4916303468F506887A332C9A55
SHA256:AC9214CFB77C09F055F7D26FB36448BF24BD30AA58DCD5DB91DFC52E6CD12B89
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:F6356EABF9F5BB27290E294125CB3DE4
SHA256:1382484AED621C500F15D89E155CB32209BEE8374A9844C7412B84566EDB33FA
1916Firefox_Installer_x32.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:507A931FAE97F798DF77730E348B3591
SHA256:7541A1C7E2F8F61ECE06B3068DC6FCDC136AFD51A12FFCA912046076FEEEF5B6
1916Firefox_Installer_x32.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:D28AEF14B37BC40DBD85486CB7D90E81
SHA256:9584D23633A817251425A5D84EC936F0454D0693BD47E94AAE1CF9FECA90BC9F
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\Outlook Files\honey@pot.com.pst.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:55D1412482C9D743AEEEAF61BA821CC8
SHA256:71154B1CB9BB5CD268BFBC82AA7AD32153DD8068F5E61EF2794B39AAD1367DC3
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\doingjustice.rtf.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:19AAA04437003B993B74A3A1411E2080
SHA256:7D94FE6BFE26A80308B5E32B64040A7D76392C5368340867BEB831596E7BB1BB
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\patientsport.rtf.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:F6C4779848A2B7032B8E26D1C35EB5C1
SHA256:34B97B52301CC179C2BB206CC26D638BD98684F76572D773C30F6E990A36F0AA
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:FCBEC05923409C0FF52FE23984B1E07B
SHA256:E37A2E3500C212F787B277EF0DDDD7D4A3A8A8DA2AF18E83F6416662194CB819
1916Firefox_Installer_x32.exeC:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DBbinary
MD5:AF2D6FE06F9DF7C666DF68D44B3FFC30
SHA256:8B55A02D92F0A0097CE01C93807A7AED4C6F2180816BC6F3D2592FA67BDA2DD2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
26
DNS requests
28
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3120
msedge.exe
GET
302
23.213.170.81:80
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DB
unknown
whitelisted
3120
msedge.exe
GET
301
184.24.77.9:80
http://shell.windows.com/fileassoc/fileassoc.asp?Ext=6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DB
unknown
whitelisted
3120
msedge.exe
GET
302
23.213.170.81:80
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DB
unknown
whitelisted
1916
Firefox_Installer_x32.exe
GET
403
162.55.0.137:80
http://arizonacode.bplaced.net/rnsm/add.php?type=add&data=InfinityCrypt%7Cadmin%7ChPVgCxXxynBsxXxAvIaxXxlVVyxXxRLX7xXxuRmlxXx%7CMicrosoft%20Windows%207%20Professional%20%7C6133A2928349ED47EAE20D7C5FE4195508C8D3EFE1F0ECD66255FBA5E59100DB%7C67
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1916
Firefox_Installer_x32.exe
162.55.0.137:80
arizonacode.bplaced.net
Hetzner Online GmbH
DE
whitelisted
2824
msedge.exe
239.255.255.250:1900
whitelisted
3120
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3120
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3120
msedge.exe
23.213.170.81:80
go.microsoft.com
AKAMAI-AS
DE
whitelisted
3120
msedge.exe
184.24.77.9:80
shell.windows.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
arizonacode.bplaced.net
  • 162.55.0.137
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
go.microsoft.com
  • 23.213.170.81
whitelisted
shell.windows.com
  • 184.24.77.9
  • 184.24.77.27
whitelisted
www.bing.com
  • 104.126.37.154
  • 104.126.37.161
  • 104.126.37.145
  • 104.126.37.137
  • 104.126.37.170
  • 104.126.37.179
  • 104.126.37.123
  • 104.126.37.139
  • 104.126.37.144
whitelisted
r.bing.com
  • 104.126.37.179
  • 104.126.37.139
  • 104.126.37.155
  • 104.126.37.145
  • 104.126.37.123
  • 104.126.37.137
  • 104.126.37.154
  • 104.126.37.144
  • 104.126.37.161
  • 104.126.37.170
whitelisted
th.bing.com
  • 104.126.37.137
  • 104.126.37.161
  • 104.126.37.170
  • 104.126.37.144
  • 104.126.37.155
  • 104.126.37.145
  • 104.126.37.139
  • 104.126.37.123
  • 104.126.37.154
whitelisted
login.microsoftonline.com
  • 20.190.159.0
  • 20.190.159.4
  • 40.126.31.67
  • 20.190.159.75
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.23
  • 20.190.159.71
whitelisted

Threats

PID
Process
Class
Message
1916
Firefox_Installer_x32.exe
Misc activity
ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M1
1 ETPRO signatures available at the full report
Process
Message
msedge.exe
[1129/155303.706:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)