| URL: | http://columngym.top/storesx/tb.php?qydqjslz1645231732370 |
| Full analysis: | https://app.any.run/tasks/65b6577a-e0be-468d-8e88-c9bdd4d3a688 |
| Verdict: | Malicious activity |
| Analysis date: | February 19, 2022, 03:31:44 |
| OS: | Windows 10 Professional (build: 16299, 64 bit) |
| Indicators: | |
| MD5: | 870998D6784F7B4E42BF063D7C9D22C2 |
| SHA1: | 929F89062592DA24F0C9C49681159D06801331DB |
| SHA256: | FA9A7EFD43CAE7E3E9E8FB27C24E55FED9E8CC942BA189AD7BD5E95545D0456F |
| SSDEEP: | 3:N1KdKJQI2cILRl6WIhh/oRqUSOVn:CIelcILREhmR |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1256 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1572.20.860984130\903256374" -childID 3 -isForBrowser -prefsHandle 5084 -prefMapHandle 2256 -prefsLen 8160 -prefMapSize 234446 -parentBuildID 20201211215739 -appdir "C:\Program Files\Mozilla Firefox\browser" - 1572 "\\.\pipe\gecko-crash-server-pipe.1572" 5036 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 84.0 Modules
| |||||||||||||||
| 1424 | "C:\Program Files\Mozilla Firefox\firefox.exe" "http://columngym.top/storesx/tb.php?qydqjslz1645231732370" | C:\Program Files\Mozilla Firefox\firefox.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 84.0 Modules
| |||||||||||||||
| 1536 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1572.6.1286179077\369978321" -childID 1 -isForBrowser -prefsHandle 2400 -prefMapHandle 2396 -prefsLen 550 -prefMapSize 234446 -parentBuildID 20201211215739 -appdir "C:\Program Files\Mozilla Firefox\browser" - 1572 "\\.\pipe\gecko-crash-server-pipe.1572" 2412 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 84.0 Modules
| |||||||||||||||
| 1572 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://columngym.top/storesx/tb.php?qydqjslz1645231732370 | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 84.0 Modules
| |||||||||||||||
| 3820 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1572.13.194462532\1653197923" -childID 2 -isForBrowser -prefsHandle 4220 -prefMapHandle 4216 -prefsLen 7497 -prefMapSize 234446 -parentBuildID 20201211215739 -appdir "C:\Program Files\Mozilla Firefox\browser" - 1572 "\\.\pipe\gecko-crash-server-pipe.1572" 4188 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 84.0 Modules
| |||||||||||||||
| 4636 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1572.0.171162860\210331855" -parentBuildID 20201211215739 -prefsHandle 1432 -prefMapHandle 1424 -prefsLen 1 -prefMapSize 234446 -appdir "C:\Program Files\Mozilla Firefox\browser" - 1572 "\\.\pipe\gecko-crash-server-pipe.1572" 1552 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 84.0 Modules
| |||||||||||||||
| 5400 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1572.27.592578984\383635403" -childID 4 -isForBrowser -prefsHandle 5152 -prefMapHandle 5144 -prefsLen 8413 -prefMapSize 234446 -parentBuildID 20201211215739 -appdir "C:\Program Files\Mozilla Firefox\browser" - 1572 "\\.\pipe\gecko-crash-server-pipe.1572" 5060 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 84.0 Modules
| |||||||||||||||
| (PID) Process: | (1424) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 9327819F01000000 | |||
| (PID) Process: | (1572) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 764E829F01000000 | |||
| (PID) Process: | (1572) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (1572) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (1572) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (1572) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (1572) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|ServicesSettingsServer |
Value: https://firefox.settings.services.mozilla.com/v1 | |||
| (PID) Process: | (1572) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash |
Value: 97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E | |||
| (PID) Process: | (1572) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\61\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1572) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CWindows%5CSystemApps%5CMicrosoft.MicrosoftEdge_8wekyb3d8bbwe%5Cresources.pri\1d3d4f12be32f10\b687a3e3 |
| Operation: | write | Name: | LanguageList |
Value: _en-US;en_standard_100_MX_LTR_dark_Desktop | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1572 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 1572 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:— | SHA256:— | |||
| 1572 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.bin | binary | |
MD5:— | SHA256:— | |||
| 1572 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.js | text | |
MD5:— | SHA256:— | |||
| 1572 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.bin | dbf | |
MD5:— | SHA256:— | |||
| 1572 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 1572 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\deletion_request\3576220b-3cd0-4a55-8fd1-2f0e26c7a6c6 | text | |
MD5:— | SHA256:— | |||
| 1572 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\tmp\3576220b-3cd0-4a55-8fd1-2f0e26c7a6c6 | text | |
MD5:— | SHA256:— | |||
| 1572 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9KIE7C~1.DEF\cert9.db | sqlite | |
MD5:— | SHA256:— | |||
| 1572 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1572 | firefox.exe | GET | 200 | 188.114.96.7:80 | http://columngym.top/j/og2.js?_t=1645241513714 | US | text | 861 b | malicious |
1572 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
1572 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
1572 | firefox.exe | GET | 200 | 188.114.96.7:80 | http://columngym.top/.well-known/http-opportunistic | US | text | 44 b | malicious |
1572 | firefox.exe | POST | 200 | 92.123.195.28:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
1572 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
1572 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
1572 | firefox.exe | POST | 200 | 142.250.181.227:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
1572 | firefox.exe | POST | 200 | 142.250.181.227:80 | http://ocsp.pki.goog/gts1c3 | US | der | 471 b | whitelisted |
1572 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1572 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | — | US | whitelisted |
1572 | firefox.exe | 188.114.96.7:80 | columngym.top | Cloudflare Inc | US | malicious |
1572 | firefox.exe | 54.187.53.15:443 | location.services.mozilla.com | Amazon.com, Inc. | US | unknown |
1572 | firefox.exe | 52.41.138.103:443 | shavar.services.mozilla.com | Amazon.com, Inc. | US | unknown |
1572 | firefox.exe | 188.114.96.7:443 | columngym.top | Cloudflare Inc | US | malicious |
1572 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
1572 | firefox.exe | 44.233.196.75:443 | push.services.mozilla.com | University of California, San Diego | US | unknown |
1572 | firefox.exe | 18.66.248.105:443 | content-signature-2.cdn.mozilla.net | Massachusetts Institute of Technology | US | unknown |
1572 | firefox.exe | 18.64.115.107:443 | tracking-protection.cdn.mozilla.net | Massachusetts Institute of Technology | US | unknown |
1572 | firefox.exe | 216.58.212.168:443 | www.googletagmanager.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
columngym.top |
| malicious |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
location.services.mozilla.com |
| whitelisted |
locprod2-elb-us-west-2.prod.mozaws.net |
| whitelisted |
shavar.services.mozilla.com |
| whitelisted |
shavar.prod.mozaws.net |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
1572 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
1572 | firefox.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.top domain |
1572 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
1572 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
1572 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
— | — | Potentially Bad Traffic | ET INFO Observed DNS Query to .world TLD |