| URL: | https://www.skidrowcodex.net/ |
| Full analysis: | https://app.any.run/tasks/5a8b14ce-5b0f-49a4-802e-79519e50bfa9 |
| Verdict: | Malicious activity |
| Analysis date: | February 14, 2026, 22:21:15 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 1818A5A5A734E0A972E25421862BB2C9 |
| SHA1: | 1F14FD055610B6140B7BA94DACC8C56413536823 |
| SHA256: | FBC30223256146AEFCCC162FA35C6C316E89D697AD94B6086B90B6F600066E3A |
| SSDEEP: | 3:N8DSL0BAJ0s:2OL02J0s |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 876 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 8124 -prefsLen 40028 -prefMapHandle 6792 -prefMapSize 272981 -jsInitHandle 6452 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4812 -initialChannelId {2d1f7309-324a-47cb-a40a-0df7ac931ccb} -parentPid 8392 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8392" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 37 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 1512 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4844 -prefsLen 40028 -prefMapHandle 2612 -prefMapSize 272981 -jsInitHandle 5112 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4840 -initialChannelId {80e01bd2-1327-48c5-8e86-3151553bcb1b} -parentPid 8392 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8392" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 43 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 2280 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5916 -prefsLen 39330 -prefMapHandle 5920 -prefMapSize 272981 -jsInitHandle 5924 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5932 -initialChannelId {4e94c692-050c-4c29-8ecc-b127c12dac77} -parentPid 8392 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8392" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 9 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 2292 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2364 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6084 -prefsLen 45319 -prefMapHandle 6080 -prefMapSize 272981 -jsInitHandle 6088 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6096 -initialChannelId {c1e72294-c279-4e36-aa18-4c749f327c3f} -parentPid 8392 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8392" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 2372 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5396 -prefsLen 40028 -prefMapHandle 6448 -prefMapSize 272981 -jsInitHandle 4936 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 7252 -initialChannelId {dd3adccc-721a-48a6-b857-4e2c57008f39} -parentPid 8392 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8392" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 23 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 2392 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5584 -prefsLen 40028 -prefMapHandle 6452 -prefMapSize 272981 -jsInitHandle 7936 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 7912 -initialChannelId {86b50171-fb04-4720-b391-0e89c0c96528} -parentPid 8392 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8392" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 48 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 2428 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 3932 -prefsLen 45111 -prefMapHandle 3936 -prefMapSize 272981 -jsInitHandle 3940 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3948 -initialChannelId {e4004a85-6bcd-4ef5-b303-e2a2e47923de} -parentPid 8392 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8392" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 136.0 Modules
| |||||||||||||||
| 2820 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6924 -prefsLen 39934 -prefMapHandle 6424 -prefMapSize 272981 -jsInitHandle 4936 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5888 -initialChannelId {e290b0ae-98f8-4b4a-8832-88f7f9e365a0} -parentPid 8392 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8392" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 18 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
| 3024 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 2748 -prefsLen 40028 -prefMapHandle 7528 -prefMapSize 272981 -jsInitHandle 6888 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 3820 -initialChannelId {da9365a9-c413-4c24-86a0-b7f71a208c64} -parentPid 8392 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8392" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 30 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 136.0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 8392 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 8392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:06EC9EF5F3849870697DF71D2A2601DB | SHA256:ED9FBD40299C1BB16DE152AFA32020C3E1C700319925B84C024F8D75321A8F3C | |||
| 8392 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:3134ED3F12E4F4F8643DB90043B0FD7B | SHA256:26E4F122034D7A03F6DA0E707799B09CBEEBDAF8D7A3133A1F7BD894AC72EEA1 | |||
| 8392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 8392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 8392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | text | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 8392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.bin | binary | |
MD5:A6F5B563F1D3C413B0D881CC02BF629F | SHA256:C938FAC482858FBE7F184475A6523A8A9821B4E5387CBF83F73103D10A80690F | |||
| 8392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 8392 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.bin | binary | |
MD5:5152D8F49F1AD4219D935611EFE18437 | SHA256:9A6E50715E3C49A43E3D622EDE7E37ECF0767342B3039B8B0AE25BBE4FF6F66E | |||
| 8392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage.sqlite-journal | binary | |
MD5:FA19ACDE7662F082440FB540B2215AF4 | SHA256:FF6C3EE8576A3EDC4A52FFBA5019B5A08C01D16B3EB62BCEEF597BB1262C9A7E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.63.118.230:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D | unknown | — | — | whitelisted |
8392 | firefox.exe | GET | 200 | 188.114.97.3:443 | https://www.skidrowcodex.net/wp-content/plugins/ajax-search-plugin/css/ajax-search.css | unknown | text | 2.90 Kb | unknown |
8392 | firefox.exe | GET | 200 | 151.101.193.91:443 | https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/url-parser-default-unknown-schemes-interventions/changeset?_expected=1743513175300&_since=%221726769128879%22 | unknown | — | 1.76 Kb | unknown |
8392 | firefox.exe | GET | 200 | 188.114.97.3:443 | https://www.skidrowcodex.net/wp-content/themes/skidrowcodex-v4-child/tools/custom-carousel-slider/icons/arrow-prev.png | unknown | image | 4.78 Kb | unknown |
— | — | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D | unknown | — | — | whitelisted |
8392 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | unknown |
8392 | firefox.exe | POST | 200 | 142.251.208.3:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
8392 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | unknown |
8392 | firefox.exe | POST | — | 142.251.208.3:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
8392 | firefox.exe | POST | — | 142.251.208.3:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
8736 | RUXIMICS.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5568 | SearchApp.exe | 2.16.204.153:443 | www.bing.com | AKAMAI-ASN1 | NL | whitelisted |
— | — | 23.63.118.230:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
— | — | 204.79.197.203:80 | oneocsp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7428 | svchost.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
3412 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8392 | firefox.exe | 151.101.193.91:443 | firefox.settings.services.mozilla.com | FASTLY | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
oneocsp.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
mozilla.map.fastly.net |
| whitelisted |
www.skidrowcodex.net |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2292 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |