General Info

URL

https://re8aspzxckoifazp.appspot.com/juzxi/

Full analysis
https://app.any.run/tasks/98f83bbe-1a7b-4f0e-b6a0-0af28c15c7fd
Verdict
Malicious activity
Analysis date
5/15/2019, 19:19:25
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO

No malicious indicators.

Executable content was dropped or overwritten
  • firefox.exe (PID: 3128)
Creates files in the program directory
  • firefox.exe (PID: 3128)
Application launched itself
  • firefox.exe (PID: 3128)
Reads settings of System Certificates
  • firefox.exe (PID: 3128)
Reads CPU info
  • firefox.exe (PID: 3128)
Dropped object may contain Bitcoin addresses
  • firefox.exe (PID: 3128)
Creates files in the user directory
  • firefox.exe (PID: 3128)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
37
Monitored processes
5
Malicious processes
0
Suspicious processes
0

Behavior graph

+
start firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3128
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" https://re8aspzxckoifazp.appspot.com/juzxi/
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Mozilla Corporation
Description
Firefox
Version
65.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\psapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\mscms.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\d2d1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\progra~1\mozill~1\nssckbi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\actxprxy.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\program files\mozilla firefox\mozavutil.dll
c:\program files\mozilla firefox\mozavcodec.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msmpeg2adec.dll
c:\windows\system32\slc.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll

PID
2060
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3128.0.127679456\1524193629" -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - "C:\Users\admin\AppData\LocalLow\Mozilla\Temp-{ce348e4c-7d33-445e-89f9-60108c51bcaf}" 3128 "\\.\pipe\gecko-crash-server-pipe.3128" 1140 gpu
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
No indicators
Parent process
firefox.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Mozilla Corporation
Description
Firefox
Version
65.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll

PID
1404
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3128.6.1960698376\707033108" -childID 1 -isForBrowser -prefsHandle 1644 -prefMapHandle 820 -prefsLen 1 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3128 "\\.\pipe\gecko-crash-server-pipe.3128" 1312 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
65.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll

PID
1132
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3128.13.1422572602\1958967738" -childID 2 -isForBrowser -prefsHandle 2624 -prefMapHandle 2628 -prefsLen 216 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3128 "\\.\pipe\gecko-crash-server-pipe.3128" 2640 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
65.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\mscms.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\program files\mozilla firefox\softokn3.dll
c:\program files\mozilla firefox\freebl3.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll

PID
332
CMD
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3128.20.1964497397\789030763" -childID 3 -isForBrowser -prefsHandle 3232 -prefMapHandle 3408 -prefsLen 5824 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3128 "\\.\pipe\gecko-crash-server-pipe.3128" 3420 tab
Path
C:\Program Files\Mozilla Firefox\firefox.exe
Indicators
Parent process
firefox.exe
User
admin
Integrity Level
LOW
Version:
Company
Mozilla Corporation
Description
Firefox
Version
65.0.2
Modules
Image
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\ucrtbase.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\mozilla firefox\nss3.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\mozilla firefox\lgpllibs.dll
c:\program files\mozilla firefox\xul.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\wship6.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\audioses.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll

Registry activity

Total events
1226
Read events
1214
Write events
12
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3128
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3128
firefox.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3128
firefox.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US

Files activity

Executable files
1
Suspicious files
111
Text files
39
Unknown types
81

Dropped files

PID
Process
Filename
Type
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1146.0\widevinecdm.dll
executable
MD5: 7f636be36a85d45a148b0fe13bd311a5
SHA256: 5566c2c4b1839386e1b951b13eeb7aaceb1fb52e9f1cfdbc345c5e4f7b6d9745
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.bin
binary
MD5: 82f61c08d68502377826ca7ea054cea7
SHA256: 85801bce5d7ce3a2abc14e3208151ac9d324a6ea82fb2ada1d10baa8ef58e7df
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms
binary
MD5: dede936755995e9681d37c6a2a948a5d
SHA256: b2c8558bb061daf08c8199ca137990a3b4699b3becae5c8c8acc44b42e89c00d
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms~RF15a0be.TMP
binary
MD5: dede936755995e9681d37c6a2a948a5d
SHA256: b2c8558bb061daf08c8199ca137990a3b4699b3becae5c8c8acc44b42e89c00d
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ET2H11Z8G0S30UGRJ8QT.temp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\startupCache.4.little
compressed
MD5: cc0c952b517d9fbe68af8dc9944735b0
SHA256: 689e99a18aeb74e800d65d894ccf51a02f8302296f66dc56fb9d77e7e769b080
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-05\1557940942575.2e7ac304-6f8e-4ca0-b073-4279ec74958c.modules.jsonlz4
jsonlz4
MD5: 61dcd682450c546f1bc9879c47d890e1
SHA256: 4c5475c115344c1de7666a7d814b484a470b346c9f7fa2439357c9b61cc2a3b5
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-05\1557940942575.2e7ac304-6f8e-4ca0-b073-4279ec74958c.modules.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 452cbf826fc47ee6e1421a2c3f0926cf
SHA256: 0bd046c186eabdc83474d47f3e2eb580bbb46373bf5d14cfc460db367655a71b
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\jumpListCache\pV+3TL7Nu3EP5juvr_gPjg==.ico
image
MD5: 847cf8580806fda649b20afc264f4736
SHA256: 0697b6004d8408ab86ccee76bb59eb07a9012e6f3e7adbc01f6e390f5c9b8836
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\jumpListCache\FyIfWsxToJ7C+3NcbZgKmw==.ico
image
MD5: 012111c480290d97c36079a025c7e272
SHA256: 840d34f7508683fda7ab7de97cfd5acafe847bb34b7a1f754a6bbe99b5b7a39f
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\jumpListCache\NZ25c8nxXfI0WczfdW84Hw==.ico
image
MD5: 012111c480290d97c36079a025c7e272
SHA256: 840d34f7508683fda7ab7de97cfd5acafe847bb34b7a1f754a6bbe99b5b7a39f
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\jumpListCache\pRD1tPKALYj80aQHgaiUig==.ico
image
MD5: ed46992c4022b5d9ea97f13066238385
SHA256: 097d5f9818a0ccd309d3bc55ab66cf0746776c5f9f974b470962cb4b38432755
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms
binary
MD5: 6c1d5e31534cd6b324c4c523ae08b74e
SHA256: 9e7f7d800c42678f6bafd92f9357dc19a762fb612cdeb0af6b934a8deb631a41
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms~RF13ccb9.TMP
binary
MD5: 6c1d5e31534cd6b324c4c523ae08b74e
SHA256: 9e7f7d800c42678f6bafd92f9357dc19a762fb612cdeb0af6b934a8deb631a41
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\jumpListCache\c2y+08u0_63F2rIrvXtxJg==.ico
image
MD5: 88b48ce20644063f896b4773c1ac1d91
SHA256: 4910f163a5cd41c4b118e08ed3499191efbe57cb26df84bf39e71e71254404fc
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\86L47OCGVURAWLR8690K.temp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: c824625cf38834198aad988d209e449a
SHA256: a97c9effa652b05aee3f23b532e9f7f0f07bc57eeb314298181205f6d7644707
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
sqlite
MD5: 8db476e312a74c1fd8a7d0811a74d606
SHA256: 534011d8f76319d275be4805fba81130f0df12659223eef3b4c11f3def82deae
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
sqlite
MD5: 2c3e51fb065c6dba373df15894c8615d
SHA256: 52b55974cfe5cb96d78f04d1a421785835e085ba59420219b55335337348440f
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite-wal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite-wal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
sqlite
MD5: 65bca54352b2f1273963ed7387b989f6
SHA256: 582454ca00420fc95f26e435435addc1b4c5d1f1fdee75eec3b6ae2ce79e6e78
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite-wal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
sqlite
MD5: ac60db316fbc1af68fb41314695991f8
SHA256: 518ca1c3a0793fdb66fdecf10adaf0b031b85a1187a591a628232353df4c9166
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite-wal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 47f8aa2c1923936f164111c9450d65f7
SHA256: 104399d9c0bc55ae8b109fb6f001e26f9323c0d428b2b6a48cc84c252a63c0f1
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-wal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 9400d3fc72c89516a51996ef99b02446
SHA256: 11b5c3401fe1f1087bf222365ec365d5de176e7a49de5d945dad094cd4047ce1
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\43B6655E5F16BC2535236452C6E5FF7FB6F2BD90
binary
MD5: cd840f88286b58c73a30835389732fd7
SHA256: 7b71ae7f54c180aeafd7f140d834a6b2b8bb951cd90b0a17dec6c76abb63ecb3
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1146.0\widevinecdm.dll.lib
obj
MD5: 5a33e95804ea80f06f97453b1a163e27
SHA256: 33bb1b23908e20870aefd100fb10983753b3ffbb308c55316b7b9cb6c9f45a6a
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1146.0\widevinecdm.dll.sig
pi2
MD5: bba147013aa78944b2530f3e4acf231d
SHA256: 2347297ebdd087df38fad1acc207f625938ff575f0d7c0533c6c5572f042f6c9
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1146.0\widevinecdm.dll.sig.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2019-05-15_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
jsonlz4
MD5: 8b3a3845e8f6c6076b27362edb8388d7
SHA256: 4f98274fcd24d4a238a86ceec0ddd26c589ebc77ab21c4b18943d1d3ef73dd92
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1146.0\widevinecdm.dll.lib.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1146.0\widevinecdm.dll.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1146.0\manifest.json
text
MD5: 6489d53ce5fbfd0eba9deceb95323c61
SHA256: 1a8ce8afcfddd04cfb3dd743b0bcde8d439d9f86a1fe262d2f99fe6876631fc7
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1146.0\LICENSE.txt
text
MD5: 49ddb419d96dceb9069018535fb2e2fc
SHA256: 2af127b4e00f7303de8271996c0c681063e4dc7abdc7b2a8c3fe5932b9352539
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1146.0\manifest.json.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1146.0\LICENSE.txt.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Temp\tmpaddon
compressed
MD5: c787e9b06b44e979c9aff51c8da64b4e
SHA256: 7e8db6c2e3e62999814d198745067e04e7c61c1580d75cf73534712540df5d9e
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\63228AD98503416DDA80F603E24A7685E6577117
compressed
MD5: 1754aaf4ae45bedc801841ed38213f91
SHA256: 03c646884f0f2ebfb746f3c9c8b37da136f8f3dd79a53d3f82e79e3b28c9b1e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E6CBD0BB3DFBF5EB17CA9F1AFFAA5ECA70BE5E38
der
MD5: 6d06afd390d814f3e3ed93415c03b091
SHA256: eb2fa6eb67f59e92f131d7e0443fd140bcb667664680cef4792fe17d9626bb52
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\broadcast-listeners.json
text
MD5: aa21a638037d4ac14a8261daedf8490d
SHA256: cdd6f5b7c86245fca13928eb1ce7697128d6aa2942a11a8810a0c3ed5f2ab777
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\broadcast-listeners.json.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\7CA340001926F44B11BD8281193FD7F888DE0BC2
der
MD5: 43cfcad8edc667a8c258f903cdd01ae9
SHA256: d6e4efd5a830ad9d9de9aef64919e237a35014d9a4135cc41cc72fbbd90b5efc
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 50a0a8119e6c97d85c348b43247c7299
SHA256: 4743e02f9976c83e9ff93e91c726ab327ffd53f549d9d997c651686946bb7d63
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 2ce34af3c2b99c9b1118d3f5642cea04
SHA256: aec7b0b0038f4777fa9043650e6631bd87a078e8b96723d99f58f2ab854fb9c1
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\5C7B977822727CB2F63B6B3D2381C7E60F2D05AD
der
MD5: e4e90dc643ed51f097ecb2757093cb76
SHA256: d0d702361e18ea2565e8f0f4da7e6fdbb5c8270962401eef542a48c39aaf11e3
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.baklz4
jsonlz4
MD5: d47d78a217dee26a97ea4c1e2c65e150
SHA256: 0c261747b235895600e7cacb05cbb582770e7cdc0e23bb49d1bd8d0ea7af4f6a
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: 6fe1785366a47710492dd6d567267da1
SHA256: 07dbe988b571b86130ac5c9d1e9d304ee4cef057d63059d14efbcf1cd283d70d
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\168597AE0B0E6F07493B7D195BA2BE5086485E03
der
MD5: 14990eaf24b86fefaecebf626b9c8eea
SHA256: 1cfd2779531fa313e11c83c7129c60309ad6bc82c231019e14b37d1bf8a257dd
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4CD79862D68E495E822FD2A988EBD0772927D5AB
der
MD5: f0474351f6e29ca4d6e3d3705dc26c75
SHA256: 272cd54c2b02b29215cb028bad729aeeff44576312723806284b2c099624de38
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0C6AA7D33A704A0BA4A8832693818F96FBC320FC
der
MD5: 0777ff6bb1bbb926b4a154e126738171
SHA256: b74c43c9ecfa618a563e59e1b3b5e69662c183b4fb8001394557dbf2a1fd6af1
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\doomed\10013
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E0485CC86B72EDB98BC57A0024EC76FB9174682D
binary
MD5: 2f6a888207a279bc27ca9fa6ec541f6d
SHA256: 39c96e7e86a6cdbfb7dff8c4d84a1939bb622fa678ef3651a896c024854fafc0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\11D7E0D2885C1A98631F19A3E22045062A47BC4D
binary
MD5: 0b3e7e7fde15997076ad50523e7d3879
SHA256: 1ae95bdf1cdabbcb9e2cae1be2fde0bf52b9ba3118522982ac242c7e99dc6b90
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\A461A52E4DA4D682795A114A3EF5AEB4E67C1052
binary
MD5: 900f0be52410c84d644081d7be63a8d5
SHA256: 5a73cf9dfee06ae2c6a48d1df43ea7de7345b32db477de9fba46de82cb07d668
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\aborted-session-ping
text
MD5: 0bf77f703ce4ad329e49b185726f8180
SHA256: 7191dc76732333de9e6bc3a2d64c48b62f69d688049fa47627d647cb94c68425
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\aborted-session-ping.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
text
MD5: 3ad6cfd155e5d4e3ad9a639a9593e95d
SHA256: 48ee6d04702898a62d2cfcbaacee8f6ebc576f8b818a0d90a662c517cab3af09
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\607DEFEB27EB2E03232975461EA1E735CDDB640B
compressed
MD5: a555e8bc7d782300952e0603ba6fe612
SHA256: 74d80e1b85ae83dff92ab2449fd95895f5816591e4b562ce243554e843076a12
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\219E0C91DB1D3ECBFD8F1D78BE7ACEFEE8A318D2
image
MD5: 8feae96c09c7ca4996e0b9f4e7b621e4
SHA256: f1250636ab9a870b4553c5e013b3664887d4167f8ccfa88172cb55cd6a91d3db
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\745C76F47FB9E443CC8DA60A897F52774F0C882C
compressed
MD5: 73c30483b4836c2dd6d02254556c4a72
SHA256: 3f8160cb50495ee338337da62c20d1675712f8f5b9325abf57a1f71abd7f7397
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\BF164BEC25EBE285C984D9A128305566F7EF24D3
woff
MD5: 6e928e5aec8bbd5f0464a5fc6ae2874e
SHA256: e4917dce66582f1b7037b1710202c8d7cba0ae2c368ae8118c62a4c105d66442
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\EB84B3B1BD679DFB36E3332A48F825E634390232
woff2
MD5: 6a5fa1b936c6074242e9b019f30ec4d1
SHA256: 30dd70e4671822d2b86dd380fdf6e54b0cb19903d09f29cce12a43a777848a07
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\DC3435DB2C9E09135033131E4BAB0CE55339F339
compressed
MD5: 9a29240cfc01d1530edc7f58608a7ef3
SHA256: 4beaba4f64d65cf1eb9dd3689f16343ab600fc408e0090964d5c7e8496e1f555
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\3C526859EE11082AECD7323BAB16CAD50A6DA0D3
compressed
MD5: 0eb76fb2580cf0ba24236175058d8bd0
SHA256: fccb33939f17eb055d6a81e78d1242737d90bfdb57972a16543fedbd2b58b241
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CB4A7D8CE4FD9FDEA2939BBFCC443B028DD31837
image
MD5: 81815ac4fe4f36454eb026d803538a30
SHA256: 45bcd46d9f9abf38347b04eabf8c0bd8f92b9cb250ad7c391b17d2237954aa9c
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0C00FC527B1A0DB2518F703B0B5A32B07A496A97
compressed
MD5: 1e1512de87edadf0e1186fe8e7e08008
SHA256: 055fbfbf3106c08abd9e8c923954409e43c584cd6dbc09797890cacdd9614ba5
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\EF2ED6C67A58E8F95A5A99E8FFEB3AE6F87AAB47
compressed
MD5: fd2f85c0109b1fd42a93d5101f946365
SHA256: f9b79836225389f5522c3d99be661710bb424a21f60c321934b0f35f8d5aa31e
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\A598D8672F9F892BB56487ED713ABC2A88D641AA
compressed
MD5: e33271c53e8e5c26302826dff7b8dfbf
SHA256: f1ad1ed8f6d9d02292ce2f254258a2c3a57ddf1478767d13c8956bc4d3a2eedd
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\32E1CFFBE1B7483A6DAD1FA7C5B92EF534E6F696
compressed
MD5: 026f72fc69495861e23f1ff139497886
SHA256: 61b76f3288735364b45f2760a76b5626075bfd5fd0ca0b256e32ec145e0e2de1
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\69D185F722EF655C865D5760FC3423F724E8E25B
compressed
MD5: 4af6a341c290c3653edda6853ad58d93
SHA256: 85c1368d523d86d817e9a4042dac0e8f101c25cb5795883f6e7343d2945984fa
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\399E1BD9C9A488BED4B2E1590043930067A8162D
compressed
MD5: f55d527b8b0c431ef4f66e18b2d23583
SHA256: 2b067613e6544ae0592e32f0b7fa466099805eb8c976981196d66f4aae89976f
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\227493F9E93C57C188D9EBB66860F02D843B9AD6
compressed
MD5: e32ee9b51aec355bef7fd792901809a5
SHA256: a4e65ec7aae1a37a7202af5d23ef00ee8710a041211e05339205b63dca9df2f4
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\20227FAA9AF68414EBCC7ACC63D624BF695606AD
image
MD5: 855060caf807419a3fde2a78914d89fa
SHA256: e56bd18dee6ddbdd4c68cec709c7ec14cb09dcf878281a4e8199cb05f2f94cc5
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\BC86491B03A7AC82DB2BFE46EB2C5B725E3D550E
compressed
MD5: cc128010ce8611e74c8fc39ecb1b18b3
SHA256: 6129e2db43ce8812612733867a5a01418999de0fb28ce3323d649db049c6f9aa
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
sqlite
MD5: c066fc563e4cdf7a01a0474806570c02
SHA256: 9f5ccf3b3fd971b887b465a60c6037955de0b14effb6a64a05b6418f6c4e181c
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\9D1E80EF9B28380A82A09F41D76F9F10B9C6B169
compressed
MD5: e44d74a6c8294c2f34a68b4b4f94df2b
SHA256: 50fe3a041369b2b988f651c5db855a7f92dd2a91a93d4cbc89184b02b73774d0
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
jsonlz4
MD5: a6338865eb252d0ef8fcf11fa9af3f0d
SHA256: 078648c042b9b08483ce246b7f01371072541a2e90d1beb0c8009a6118cbd965
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
sqlite
MD5: fe42f7763e24092e959fa0eb88516fe2
SHA256: 25261259ecfe56ec0a283c7005e81f3d859be4b079a0f215e89d869f62ab81dd
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: d47d78a217dee26a97ea4c1e2c65e150
SHA256: 0c261747b235895600e7cacb05cbb582770e7cdc0e23bb49d1bd8d0ea7af4f6a
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.baklz4
jsonlz4
MD5: 83cc16c8e6e23be2e845da2b8a9c1784
SHA256: 33a6651b6b29284e2e0f72a48d8c7d440e866572125c559e2b5723fcedcb9d24
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: cab3cc960f8de0884bf2fb4283afbb8f
SHA256: c0e961b2ee5a06bb45481e1af58b7f3ef827d72fc09f3389982310d2c03e25ea
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
sqlite
MD5: 8b85e08422394686cbfa45a1dea5424d
SHA256: 460797ac66047daf7478c806cd9788636e6d6ce29eb1b07d7991b0b05d5da8ed
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 1fdb231e402a3d20fcadcea9333fbb91
SHA256: b52785fec4070b7d1c579ba3549c43969a486a71690148a244bf625592ad5e97
3128
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_PhyhAMumGNYnYS0
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1D015190C6E9AF106093FE0E23CADFE7DCE5C0D6
cer
MD5: 3761e2db94b1a1cb1a913cbfe730ab82
SHA256: 794f257c4df9398ad348ec23b7e94d82da7bcf9ce077cd44353c26b184d47798
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\D00A688072D5E651DFCBF1F615D0FF8CC68B8989
binary
MD5: 663ebe86d2ec06382f386547642bd89c
SHA256: 4030cf47b524acbfdc40b9835c49ab805e1dfb2e7e6e8d18c4a196e76d046460
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
text
MD5: 26a0b1e5ce791866cdcc6711a97c8512
SHA256: 36c8b217ccfa2c2b46d18eede7cde41d06a022c27fe6a10bc9acece7c6e5d1d7
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations-1.txt
text
MD5: 26a0b1e5ce791866cdcc6711a97c8512
SHA256: 36c8b217ccfa2c2b46d18eede7cde41d06a022c27fe6a10bc9acece7c6e5d1d7
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\F70D8C9D3E7D30072A56F7D30E16FE61B9E6338A
cer
MD5: b4415439137b4cd8de1819d48510658e
SHA256: 4847e7f2d75af283aa45f273cec0f99b9acaf1ebc10fbb111d40c7b58ddfbe3e
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\19D35396B61B26D7ABD842C17AC9F57D42ADA0D3
binary
MD5: 3f8b1c00f5fc29f1319cad48d22abc08
SHA256: c3617762f57353afdad4749270baaa9bd1fd19ad47b1ef6222972612317aa8e8
3128
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_Llv92NOwKWcgAQV
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: bb5c0a415714c73bfc11b063247806c0
SHA256: a12294f52d5f5775d52ba4fbc2d83fb06ea4047ddc7ca2a2cc4d8132ec2e34c2
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 36328eab451c95ce4cbd93a2d2c724ef
SHA256: 4524dc888e667258712d55316788570530410ff5b670554743d1f6d35434a37c
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1EA7BF89DC6525298C79732BA96F91FE6B33F206
cer
MD5: 07e06c55ec23d38c8f09d714b7c01ae7
SHA256: e8bc32f31dd73908040dbae65ebaaec028723c8dea59d564e57320a3192b5621
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1346ECB39C6CF8279C06E5302A9BE2BD86431973
binary
MD5: 5fc8350af6601e5993c7d8725465b9a8
SHA256: 7def903a848f3483ee419e282888f4ca94fc1027c3b142cf38964618035052a8
3128
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_LJrciTKwPul5qHn
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1EA7BF89DC6525298C79732BA96F91FE6B33F206
cer
MD5: d11db4a30d5d686aea11be816fa4e755
SHA256: 4de9ac6cb697530fcf74fc1f8d34e3b4e32813789321828423906348399b031c
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C7BF762EDFF44AD7B5A6EE80EA52F7A62A020A23
binary
MD5: 3014e249ef398ae11a6a9e97b62bfb8e
SHA256: 53c6fd64e870daeeb28887242ec2166aa6e323cd9a3a307c529b29b22b75552f
3128
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_tD5kkjz8n3iBYgU
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1EA7BF89DC6525298C79732BA96F91FE6B33F206
cer
MD5: 28a0cce97cf191b00eaef784a32a538a
SHA256: e355218767958c11a6bc8433ad628750cf51ed9ef173310d11684b710c96d409
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\EA608B8ED0D449F36E298CF2F7F28CF7326FB6D2
binary
MD5: 7d65a6f331e6cdd04ef4045b14210054
SHA256: b790445dfaca7dd5a27b555b855c23d09a994da654ac223c570184a20686eb80
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: 83cc16c8e6e23be2e845da2b8a9c1784
SHA256: 33a6651b6b29284e2e0f72a48d8c7d440e866572125c559e2b5723fcedcb9d24
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.baklz4
jsonlz4
MD5: 5905e31e1393ea73f9e71beccda48b48
SHA256: 6ace04a93453cda556de7cde2faaf78d9cb34af6e5c5eabed453511b92fc02a5
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
sqlite
MD5: c6105c6d81ee7f2dcfdd096ffba64c22
SHA256: 6c8ebf9bf6f476d5b86692667e21f5ddb4a5b294a6c29fea7189a371bcb427cb
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B01C994411DE035339202FE9A507124C3DD1E728
binary
MD5: b7c629f360f0427827f78917c4d42bee
SHA256: a1af36a19c9ac558a00348ce4f53aab9332cfcf4390233f1f2820b5dc9922b76
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\EA608B8ED0D449F36E298CF2F7F28CF7326FB6D2
binary
MD5: 6f9869fa16b7f1ba26f369da0e938975
SHA256: c0acb4be2aab37c85b312b4b7ae6c33007e13b9860f2fa4c678827ca3698785d
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: cde0e4c1bb89af0a694dc76b4559d1b9
SHA256: 19d320a2fda69be8c08931cde5ffd05b78f35cefc9732e7ff71b01ee8fa0aabd
3128
firefox.exe
C:\Users\admin\AppData\Local\Temp\mz_etilqs_UnhavzBIuy1fta4
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 3f2b7c7c381f96d569ded0b45e752b43
SHA256: f7f13ecde8c6386ccbda843fbe0c2de44bfe58c0d1948b03edfc200b354e7f09
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
sqlite
MD5: ff60cf83d1b4a03329e231953de13a2b
SHA256: abb400239aea65ea20d4df9b0678d17a24cb8d80b3fe4e375f0a79324add38bd
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal
binary
MD5: 65373d268182e97cde3b6718e0480d36
SHA256: c26154ce50ffb167e34b2507774176eac902e13d90885fdcbc7c65bee382fdad
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-journal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\2B8FB3A7C1E8990CE64886D66718692D2B2ED2BC
binary
MD5: 0e4efe47a8f07448dbb8265d420a3648
SHA256: 0d3d73424b7d18902248c0d8cbd3ab23e84c9c617c05abd4d4ebb4bbbcee934a
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1EFA04D278CC1821400DDEF30A6AD40A1C7A54A1
compressed
MD5: 80c5030496c48ea111985eec180c47d9
SHA256: 1a7361f8e3c1eb4293e8622a9f9c651f0de24825f4627d33c7ccc13b5313e7d5
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\7395119D342AA2F541781B43EEF9E58F4D412C12
der
MD5: 01ec3cef3a8c8342cbad5ef4a5cd961a
SHA256: fc33d6bd52bb4735700e901e1110e26414add5462f33f3ed432efcf848ad246c
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
sqlite
MD5: c1aa1748bd66f02fa93a9d8d28be03b5
SHA256: 10adb9ed90c02f8463b14b891d5bb92c4fd2344f0c85b8aaf46c207e4b9aa335
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\31A456374F0AD30CB6474F2066E382F969F84CA6
der
MD5: 56a4a2a57d5501c81eb69ad84dca1db9
SHA256: f904fe17b18ba4913537739923298675d8cbab0e1c3f230698a2963ece0b859e
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite-journal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: f8e8abfef06e93d71a11614c192b80f1
SHA256: ef3d0cc4fff85107f95c0dcfc231f07a98b04f6abfdecc0771cfdfe7874ab6d9
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
sqlite
MD5: 80c58c8ff5b32bfb7b08dc5fa77fa1c3
SHA256: 44aa020a157b1d2cea8e196efdb347b207be3cbf0d39cb6c99a2409c00855e25
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-backup
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256-1.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256-1.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-trackwhite-simple.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-trackwhite-simple.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-track-simple.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-track-simple.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-harmful-simple.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.metadata
binary
MD5: 50acd27658cb4adce19fab60c74a311f
SHA256: 676a3201ec0db146ed9359a3d87504b9809060a1f430d7eb84770f5ea6800227
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.pset
binary
MD5: 81c91deecd59030401c4e03ed78a1314
SHA256: 78f650293ae9ce88f51016b596c3b2b3c18e98a738b0720f64d61eb52b929295
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto.metadata
binary
MD5: 2d81105e0b71915086c3f8ff66275288
SHA256: 2b63f4ae394c2334ac5dd546752f1a17ed858ac4b126c151c95d0a986181acdb
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto.pset
binary
MD5: 7610dc5dd6ba8b0589413cdd8ac53e67
SHA256: 794c44cfc2d22a9f8b41366954db7f47016905a28ae56eceb37e34206d30bc59
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto.pset
binary
MD5: 3a40a0cae9a7c4b4b4bd4519877bec85
SHA256: 44a6790cfcf09d7bd9fd3a9083063006f09cdc2d1873930e9905ae5839352688
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto.metadata
binary
MD5: 934252565b869eaca7b4ca2624384f22
SHA256: 0117ca3326d062906c29dcd20b8f7db2103ef967d5bfaa5fbf951b1f91f681a7
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.baklz4
jsonlz4
MD5: e53204bcde5d04d2eb90178e3f1dac2f
SHA256: 58305c0c2d0b16dbc05ae1256f7291a3a80ea836eb6f039d5fa67ce92e98dc58
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: 5905e31e1393ea73f9e71beccda48b48
SHA256: 6ace04a93453cda556de7cde2faaf78d9cb34af6e5c5eabed453511b92fc02a5
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\D598F217A2DCBE6BBBE91DC044BE6AF09786843B
der
MD5: 31f208f84596a5f9beb25c779c1602a9
SHA256: a6d5d3aa60793ba61de12ed71d5e778ab9411ab35b808df4f35e857c68338e00
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 1a8c68dea570f4f68de11884f6710c5f
SHA256: 364fd35b8544ccc41bee38321b10755fee0465c7a25a377944c408f7452042fb
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto.metadata
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.metadata
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto.metadata
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto.metadata
binary
MD5: e94d7d1223845881291d7fb281a6db9f
SHA256: a5b5f7d0bf9ccb6e6a50e81e6b219d3e50b658670b7433fbc9fae82d7831e70d
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple.sbstore
binary
MD5: a5695cc64d77967232b0c1344c6e72b3
SHA256: 042a22b8681d754671d2018ba109b31a53ee3728d48c6379043f8e3394e7fbad
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-trackwhite-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-trackwhite-simple.sbstore
binary
MD5: 65e942614eee70680464ac4be75019fc
SHA256: 34395085da32c8b4efe9959e3b0d756b43ffed17694d66f39b966cd331bd9a94
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple.sbstore
binary
MD5: 3d1ce5e50208f0cb3b979186043a548f
SHA256: 1e13d05d482c3d533dc6035af2b2d6e84749412a5748d1435b70cec8b312340b
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple.sbstore
binary
MD5: 3675254e341df799d4307c1f59109185
SHA256: 23d108134bed6099793f7dd6b8b6e62081ec3b945efdbc7c5e0e779fd9b82f98
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-track-simple.sbstore
binary
MD5: 95f28ede25c301301f25fbbd9a3c56ec
SHA256: 87763df78772f7d750b0fa5a31eec23e931fd3bd1cbb33beddfc61889da36478
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-track-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-harmful-simple.sbstore
binary
MD5: 051fb32dece757ba112ac36dc72e3a91
SHA256: 0806d98fb3de55f75d7c0b17e26146567e08c483031526659a4a35d09b97ef19
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-block-simple.sbstore
binary
MD5: e2cf527ca7550b7e7bdf7311e483a2c3
SHA256: f1e07b1d717433f47073dc54a7d98e3e87b3d0fa88e53466f93ea544af885d11
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-block-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-harmful-simple.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.sbstore
binary
MD5: d772261ff33497d3681e094f23282ffe
SHA256: 8ee76fa11d5a67f0c93766da3b1ac0c942020afba15b55a8750a896292cf4dce
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozstd-trackwhite-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozplugin-block-digest256.sbstore
binary
MD5: d6acf2573e12afdd7939568804d3fcc1
SHA256: 5525cbf8f8dc41d19ac632ed324e55293a510ae0eeba16d0e3f33c707aa58a0c
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozplugin-block-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite-journal
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.metadata
binary
MD5: eb744b05b13e9410146dab0bd459efa0
SHA256: bfde7f131200eb06c1d54b03d2ce1be1ff31062e8009c937243464712dcd2d50
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-unwanted-proto.pset
binary
MD5: 72e2352f7976b0dd90f2a68047493b8c
SHA256: e0d74336b6c041b6087a697dd7f65fa1da7ea035e202e3d977cc6a7e5bdc13a8
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto.pset
binary
MD5: 844aff63a5f67cd54d9814b7b54abf18
SHA256: 8985970b72a7bcfcf54c4a2474c36ea9a911ab3672881ee299d58f5a4e64e690
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto.metadata
binary
MD5: 704df61fa2e3f587b268ad85126bc689
SHA256: 7e97db3c9370a35f59a6a649e6cf608e4f5ed572f87f433ea652977ac2cc48d5
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-malware-proto.pset
binary
MD5: e608435b687616692a96462e1ac26756
SHA256: 6aa8ee3813d86411d8073a4c2f850b1e8e734c3759d860cbe54ec7f378a82a52
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto.metadata
binary
MD5: ddf263974b1925672d369bbcc8f830de
SHA256: 92a7323dd7eb199618a1e2e823a71919285a70196bfe627808c66cf1c1f3c8e3
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-downloadwhite-proto.pset
binary
MD5: 7655fffe7cfbe1ebf96afea5fe2e1376
SHA256: ff2f663c4e453706b7817109f6a43e8b3389e8cfb1b7d64aace2bfba45f3a359
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-downloadwhite-proto.metadata
binary
MD5: 498dae4e538658a57f464748f2dabfda
SHA256: 8778f52cd9cb4f4787bf7ba18006d212f8c3004652d163f7786556a8eef3a067
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\82F1A8E6D7B03AC509F11EBF456AD798475FA656
image
MD5: 50fd9ed9ff1411ddd7a7ae5dfb59fe5c
SHA256: 9514d2a505701b304638e6797d6741d631a45ce48d98aa71585913d61882a033
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\4CAC58BABC6531CD30C5FBD266E2E31C9A001B8C
image
MD5: 8bd2516f2215da2b57c5a29a36c2a650
SHA256: f5ff7d034b54eccda4b82e40f2cc520f40927deff7ccface99a8e6c561b48cb0
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
sqlite
MD5: 4cfd5c5defdcd25a76d22c04e55945c2
SHA256: 1f9c0b8f72a2ae9bc8cc4a49cd7fac1991cd4a0a0940d01af7dbee712ba7c2e4
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E815A436FE41EFFE98AA4FF55A67D304BA0AED40
image
MD5: 466991ae8fd990a01db49d551df39c16
SHA256: 2b46859e85c41dac6516d42985717bdeb7523992f8740a50b1db53705b9e2154
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\83052BDA0D84ED9D7D1F11C3AA989845302CF4F7
der
MD5: c6a208fe1d6a7982f0c4d032e6f148ca
SHA256: 40f2210542e265af7d0b962f221f5bb660f4bdd322250985c40724377667bf7b
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\3E0D6162E58FCEE0651DBA9A8BE107E8841CFC12
der
MD5: 0a9cb3df13cf09c35140915f0aeb0dd7
SHA256: 1691a0c5aa813e4e57b667e2786d6f61b504b702175aee72dac282ad0928d4e7
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\05085D3FBC34CA31250CBD04A62E604D868C32E6
der
MD5: 29839ae48022645eda6b4e6d6f719bbe
SHA256: 84004d3154e6a0c05886e474306fc89e9edc314e7e7259dda8aa994b9cc1cb4e
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C8D33452DED7D327F5C0429885B5D846920A9F3C
compressed
MD5: be2c8b78424c28238782109e49029251
SHA256: 7a148b44b6137b7c5b3fe633bac16d46b7707ee749b4446f575a346cdfa7ce20
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E048F76A6F4A4BD955E6AD30B98D62A90A729178
compressed
MD5: 548bc78b50775d091338c8ad5e7cdf2c
SHA256: 6906989d91afd59f0c9e7e810f4440a08845f9533349cef5474fcb7865630d41
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\D8C9B95C6E5B13E0BDD8981E6D744AFCEDD3FBBC
compressed
MD5: 4ce76143d4e2f58555fab037de111e44
SHA256: df5075d6b5e3bdc384868605a181a1c31031b6b26c593c2d41d8f2cd01ec7fc0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child.bin
binary
MD5: 558efecb4cdb09a52b64b7737a278a26
SHA256: 660da5a16623cb99f05b166ef13dc4da9b481c5c73ad9d714bea1c9fca07d4d6
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-new.bin
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache.bin
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache.bin
binary
MD5: ae9372bd836fab8be31655ebb36e269a
SHA256: d87e60954d8fc6fe071c91e202cc037483bf67168c2d23793e770945946f0de8
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-new.bin
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-new.bin
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E815A436FE41EFFE98AA4FF55A67D304BA0AED40
binary
MD5: 059f3355636aa2a2015b4283e289fc00
SHA256: c470f73b0f2f85b63764fee6f7a4fc1549e8568925f1cb8a0099d16bd4f0f728
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\7A6C67A13F8B440B5F6CDA04903D4D7D590BB885
binary
MD5: 8936756db51f7f0f28b8b9d6472732c6
SHA256: f75c97251d6190e26b793e8e8fc4f05fcc3b6ea52439a61f0774163722bd1d03
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\D8C9B95C6E5B13E0BDD8981E6D744AFCEDD3FBBC
binary
MD5: 2115c46f5340172863de9268b82720cb
SHA256: 4ebc07b28d0da8a9fff82ce56503aea003876fcb8cd5dcfc1cc464add1ce7f55
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\C8D33452DED7D327F5C0429885B5D846920A9F3C
binary
MD5: bfb4a56840c18125705a8f7f53e77439
SHA256: 5889ac9674dec29850780a60615d7e998a754d169947b236d14df85863260710
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\25218EE79CFF5F3AC18C58CFDF44A674E3560C47
binary
MD5: 965d35e203e421df7c2ab25c763216f1
SHA256: 55ffdeedbcf45793b5f6c8ce66692f00dcaff9bbc627155a5dfe8bb0f56f9ee9
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\E048F76A6F4A4BD955E6AD30B98D62A90A729178
binary
MD5: 63b0cc7f16821a8bb07c102ce4a15d41
SHA256: f85c38daff3ec96ba177642b4e7ca08f32aac5ce62661221998f8b5daa8f1a80
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B01C994411DE035339202FE9A507124C3DD1E728
binary
MD5: bf104ab91eafa657064558eba9a6090c
SHA256: 3494ba97fd70dc4683c94bae1355d61ded7603de1d5b2403a8929d59e2dacfe3
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\82F1A8E6D7B03AC509F11EBF456AD798475FA656
binary
MD5: 48fef71a49837d5ae6ac7d29124a9ccc
SHA256: b83d2addc21c265ee7f4a0b40a9c6d23a11a501222f35c52acebcffbb3acbf9c
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\DEC61A09D8F6F853535E6F6098CEB21C79B9F421
compressed
MD5: 7e89514bbd0e9ab241ff31a5f3d04d82
SHA256: d756aa63f987e191191a3952bd4182b64309bb515c79a4ba7f700b7cbc787ef9
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\A3BC6ED0C8B8C428DA19CE1495237AE6CCA62476
compressed
MD5: 80d3af5d643c783f675bf1aa2e25885b
SHA256: 3ecdbdf0cb036d0882f11b7188ed51133b61f4bef24f7035ad6c06091b17d9bb
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\05904507BA1F757902D4627E97420AE3AEBCD5F5
ini
MD5: 6220074b3beff5565ada672acf56247d
SHA256: 4d39b5013e76e7f14ccf2f84ea69fc44c2f4928c20c0105aa3562ac0ad6a54d9
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\doomed\27564
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\7E2C703DFAF5011CD125447AE2228F9F277EC946
compressed
MD5: 5c87866819646591323b5204c9797ec7
SHA256: a81869d912d64a12c61b18bc31dadbeb542276d5b104fa4a00e256c4a9bb7a96
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\01464243384EDC3BF7B08E79430A387FB67372D8
der
MD5: cbe2d2c8b9d34880773064e87701b314
SHA256: b8bdb6cef64c7cab786901c730b9261f4d73d2a03a645b404a8606e43f303d72
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\AA1C62990A0428E550E7C5BA50676DA070539B7E
der
MD5: f07b2d716c13c2b47aed09bdde8ff6cd
SHA256: a04a1ae821437851bd649d02afb9cb99b868d3240974753db738f6fa0d95962b
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\61F837C736420F42B843F8D5F95C11EB505F01C9
binary
MD5: 9c1fcaa36775fb64162bcef7429a3f5d
SHA256: ba683c5e8fea75c67d424741b392e6c9f2173ba332055f5b1ffa1767cfa0edc2
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\8B8F3912FF723F775A5B874890212B294098FA21
compressed
MD5: 9f6e32d482d4f2f7f1cfa6df4b73c344
SHA256: 8cfefad94fff2823fe074e62fe7aa5b9ffea3f2f855c33e247412dff671c143c
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\27B863C4407358EFA568F0472838CE153C76289B
binary
MD5: d993495dab298d2834816b8bbea30dd6
SHA256: 9a1aab1209cad92ea5491f662d174ce959055d32ead804f23dd7f45333ceb3ae
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\28C9ABF3DA509BDA153E31B23DB7627516BED98B
binary
MD5: f4483087a4a75323e9e4027743bd5b8c
SHA256: 4a98ff1d2c544a462a58efafde916d0ea3a97881a2bead01e042b3dafe1cc883
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CB005C9761C5140638F5B0756D0A223407E6BD0D
binary
MD5: 40cba2f4e418dc93bac9ce5e8f4d4ef2
SHA256: 9882a3e325d9528e44c47046591a329bfbdf80d4c9b8517f47bb0edd836ff3d1
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\93655620968B40DB87DBE8CA0E51AC348D1E16BC
binary
MD5: 12866a18b2e8640257711db3a07134c1
SHA256: 20cbdf7950ebe517b2267704f4a6019164bce27cedbb101c822abae8db824d03
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\FBFE45CC16FA07D187A98598F2F765A30BCFCCFD
binary
MD5: 69ad39a7858ca9b79934aec34320bbfe
SHA256: 7a2f9d52aee6a2ba18e1fcfc9753c856688242ee445fd1ee4da71d479d402b1e
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\BA879334683CA698ECB0E0CE816B947406566559
binary
MD5: 94f539585371c9217749a0a6b7f29bff
SHA256: 9fdf49cea5a16c83ef8213d58a3cc9a117021486b7f688b0b7345000af59bae3
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\659822F8D0870840A598667BE936E0C41EE54933
binary
MD5: 45a42262af2a85835c7d1861c75f3fa4
SHA256: e84561346b25862605b5fac577c92eb992dae19c046a353383ec98e7964902fa
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\5B99DED405F166A3B5894267B775B1D34A290B4D
binary
MD5: cdd81ca4a46c8c43455627fe42c42349
SHA256: e733ab260a91be41489ddfa969176535a4e883613cee4110ae2aefcb5ce9b80b
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0030897022053DE02E6B064E7B77927FF21BF2AB
der
MD5: bf5b8a57c66866bf9362350dd483ce1b
SHA256: f11ef198dad3e9590fae60272c4a4fbddfb5b00b2be7c12625152b2307c3f1f2
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\83BA2839547FB8D264D35914EDF08BBCC235A0C5
der
MD5: 5ae188c60af615f431f66cee1f292a7a
SHA256: 486d618b6fa8d17e591bd40271dea3b1fbb36a7359a1a911703cbad1b175a17f
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\1C00E9EB937A477483A8D8FD13483594641E2F11
binary
MD5: f906589208bad344ccbbe4420ea44a60
SHA256: 550ed1bdf7ef04407b9817147a51536a2920e8f571b6e331bfdc5b0e7729dca3
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4
jsonlz4
MD5: e53204bcde5d04d2eb90178e3f1dac2f
SHA256: 58305c0c2d0b16dbc05ae1256f7291a3a80ea836eb6f039d5fa67ce92e98dc58
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
jsonlz4
MD5: 97ce580459a943b304de43f2fca70c48
SHA256: 368f3d7911e0ade59c90b08a226f57ecf4de77421063d0478b44615a4f7c9f2f
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
sqlite
MD5: 0ae2a436b7483330f8572f002f6d0f5b
SHA256: ad85fdd18651711b046ed90bbea7dd958a2af42c9968c33e38beff5024f6ee6a
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\D694857AD7D66AB1D01D6681DB0070490BE279F1
der
MD5: b4faab50f251d594e26539b2e0ae82c5
SHA256: 35b05deed49f8b98c55fd56f4a06f24fff43714c3a704d633b2e7bcfde4912eb
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0512352DDF97C450253BEA905F53CD6C21AAD38C
compressed
MD5: 718443e479958f62e71cb6f534752d5a
SHA256: a543330491a0cf25fa98c4f4937658a658c970dc2c6f46e6d6eaf74b857901fa
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\D49D7FD6CEB456A6DC0D153E0D0315024530A9AE
compressed
MD5: 9163959a27e86561390b0be92454712d
SHA256: c1fa24bf0f58cee9136ced7327a68a226a831acb40d1d7b20a28e9edb1199a30
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0240DD41C7344861D7E8BEEA81577DB284D9D8E9
compressed
MD5: 42a324e6d996122339f5d395574fe120
SHA256: 328ae00f064c62daf67c6051413939d9c01143b363bc25e08eac0c123d60a2aa
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
jsonlz4
MD5: c5ddf33db50a8d0f1764704fbf49793a
SHA256: 59577f0470c86d8ad2bcfef516c4d8dc27ec1ebef58ab26f708a1814f24b447f
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\DDF3552173BA5501AAC2505F71BA0FD42E9076F3
compressed
MD5: fab9e9b638e0feef2b38258e10e485e6
SHA256: 7da3f66e0f06364c2b1af5805c55f98855435a4350d1bd22108dbe51a72bcfb0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\DEC61A09D8F6F853535E6F6098CEB21C79B9F421
compressed
MD5: f56715ac7cfb578fdc029c4917cce606
SHA256: ba74af72d45edeeb096f32d881609d24d6b23aaa419cb059692488ad04739aa7
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\25218EE79CFF5F3AC18C58CFDF44A674E3560C47
binary
MD5: 696acf28e41b754c81c9e1721108a81a
SHA256: 5b64650be9536853ea0b71cea2359908a36cb0715d80398ae7584e6ed2c7ab7b
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\61F837C736420F42B843F8D5F95C11EB505F01C9
binary
MD5: e6ddfb4b920e16ef5d02bd6080c473ab
SHA256: ca91256ecc9760808967a3d740ebc3c92a0fcdd2c13cb36b90d679c2eb8c784e
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0240DD41C7344861D7E8BEEA81577DB284D9D8E9
binary
MD5: 89b58766b310ac810d94fb5ba6b8edb5
SHA256: 0bc3fec78fe3f9b342b3d2d9a94d0313cf66fe2cb01a32e70c50573873cac45c
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\B01C994411DE035339202FE9A507124C3DD1E728
binary
MD5: 5783d6ef6cada56926fbcb7f54758e41
SHA256: e921065c76df47faef2d67da20bada54a7858f95d25a1d2f1aa1bf88150175f0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\DDF3552173BA5501AAC2505F71BA0FD42E9076F3
binary
MD5: 1870009c085c03812baabc6a802ca2f8
SHA256: d41013ee5931467288e712141d5228ffd10a2065f480c161b0b458089bc93a12
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\49968F5AAF6C3D4E162E052C301E673D6E1D2552
binary
MD5: f8a29c1e5016687ef8ab0900bf0ad76f
SHA256: 90d304a821891d1ed79a4825975dc6830e21e859767228c7557ece19de256596
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\doomed\1456
binary
MD5: 00845cfa655570ede0374d9c0df85b59
SHA256: a421e6f7103b60091014b90f4118ae00b723d80599d4356e3e150b8f2be2359d
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
jsonlz4
MD5: 7337d087ec76e87a76778b4eec5e8e63
SHA256: aa4398d1716aadeb35a4ddddc4e7d2429c71defd15cb45401938889f5b2f05e0
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\025EF3D2A7E1AA5CA759D971EF8408DF3DC03485
der
MD5: 6fd73e9ec773dda7d651feec7f89b38f
SHA256: 5de79e6eba5bf95d9f1e6ba9b6186e5ff8ca896e1a935d7b78b5910337e4f076
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-block-simple.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-block-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-block-simple.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-trackwhite-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-track-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-harmful-simple.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-harmful-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple-1.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozplugin-block-digest256.sbstore
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\mozplugin-block-digest256.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-phish-proto.metadata
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-downloadwhite-proto.pset
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-downloadwhite-proto.metadata
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\google4\goog-badbinurl-proto.metadata
binary
MD5: 778202e2ee08f4b4073413c0b03e05fc
SHA256: 33147037ce75ec0a48b3da60d619bc76c2471f5f20c15f9d075671de2067cfb0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashsubdoc-digest256.sbstore
binary
MD5: ba0009932844173bc8f9af264229df24
SHA256: 66d1c00c04d86e313e9a02775cdf906b1be8d4cd6bef423a1b9e21cc4e9f50c1
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashallow-digest256.sbstore
binary
MD5: 6f85bc4b2ecb49e26b0bd83a821065d0
SHA256: c0b3bc9b3dc507ab654caf72d13c3aefa58c9b13b1e4d14dd8816712d80a7e54
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashsubdoc-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flashallow-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flash-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\except-flash-digest256.sbstore
binary
MD5: c921d8e98fa01b4f303481e112202e92
SHA256: 4ef1038730ec8bc7206713c29a936768831b922c5e6c83355fd62d7401d8c1dc
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flashsubdoc-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flashsubdoc-digest256.sbstore
binary
MD5: 04824a1f92353f43ebb9e7f74b7476fd
SHA256: b48e58ebab82e4c376f16150a3fff850c1111ff1f5985d68819cfd6f0db159d2
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\75EF05F6707F8BD5923C2906E673883C32125E82
der
MD5: 8dad1041c739fc9a6e8d4c101c1e44f1
SHA256: 4f630628b027a4178137a470e2b7c342907e77b9dec4944c519d6ed99868d6fb
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.sbstore
binary
MD5: 0e8fe60ccd7e9b4c32589a5743a95302
SHA256: 2b124d4026850a3cffd28dbacb58aec28f7dcd4d40bc14e52bbe96d60ce4e749
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\block-flash-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\CF2088406785B71B5D2260D234E98CA163770D8D
der
MD5: ce55aff06b7dc7c8fa8757fc31a0b312
SHA256: f123946d127942b129fed45aaa481125fdcc68b040a86f16e546af03e6b5f6fb
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\entries\0A831CA7887354BEEC61B7DFC8C0E780DCE0627B
der
MD5: 4f37cb2656ba305259642099bc409538
SHA256: 9d464d6542c4c46f2fc7e030976dc2871918476067890e2a9c9c07fa477dcdb7
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstore
binary
MD5: 23e438fd4af1829d4469ff8d0bc83854
SHA256: 96e0d7644aea81d26f039ae633eb405583e11b020363090dac5cad9b4b188846
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.sbstore
binary
MD5: d886a47c89d9c49c795da345bc236990
SHA256: a03c5e2656d2f292bf5794c8eeb8d223cd6ba4f4bfb2ed1f325460e879d0bcf7
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\allow-flashallow-digest256.pset
cdxl
MD5: 076933ff9904d1110d896e2c525e39e5
SHA256: 4cbbd8ca5215b8d161aec181a74b694f4e24b001d5b081dc0030ed797a8973e0
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm
binary
MD5: b7c14ec6110fa820ca6b65f5aec85911
SHA256: fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
binary
MD5: b7c14ec6110fa820ca6b65f5aec85911
SHA256: fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm
binary
MD5: b7c14ec6110fa820ca6b65f5aec85911
SHA256: fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm
binary
MD5: b7c14ec6110fa820ca6b65f5aec85911
SHA256: fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: f878deb53c334de134cf80d61f3bbe3d
SHA256: 9537dfbeee83f95e198efa262f78297d04f98ab6ab5d9e82286f0b4749146a2b
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
text
MD5: c4ab2ee59ca41b6d6a6ea911f35bdc00
SHA256: 00ad9799527c3fd21f3a85012565eae817490f3e0d417413bf9567bb5909f6a2
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: efaea18acf09de1c5ec05c57e2cc201a
SHA256: 100573a52abb66be93265900b6776910f944ff8a2cafb0711c4055ba0970b7cf
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
text
MD5: ea8b62857dfdbd3d0be7d7e4a954ec9a
SHA256: 792955295ae9c382986222c6731c5870bd0e921e7f7e34cc4615f5cd67f225da
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: 8f89a5889e1615f65674daf6a01a2454
SHA256: f6d3fde91836d607a3311a6e0a12463c811f791a9f231d2ff8542d772fa22ed7
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\trash31827
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
––
MD5:  ––
SHA256:  ––
3128
firefox.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin
binary
MD5: 6c32cb3fd01869207e7aae8b28598f29
SHA256: 4f8ecf8007f6cc603991256aacf38224adba7d0a16685706072d1aadc0604303
3128
firefox.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
text
MD5: dfd721bd78cbe870b1078b47be1947b7
SHA256: ea927a693140574dfed1afb6cbf1b3d14ed461e9307a805e6ecf1f3aafea8f5f

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
25
TCP/UDP connections
79
DNS requests
134
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3128 firefox.exe GET 200 2.16.186.112:80 http://detectportal.firefox.com/success.txt unknown
text
whitelisted
3128 firefox.exe POST 200 172.217.22.35:80 http://ocsp.pki.goog/GTSGIAG3 US
binary
der
whitelisted
3128 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 172.217.22.35:80 http://ocsp.pki.goog/GTSGIAG3 US
binary
der
whitelisted
3128 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 151.139.128.14:80 http://ocsp.comodoca4.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 151.139.128.14:80 http://ocsp.comodoca4.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 151.139.128.14:80 http://ocsp.comodoca4.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 151.139.128.14:80 http://ocsp.comodoca4.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 151.139.128.14:80 http://ocsp.comodoca4.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 172.217.22.35:80 http://ocsp.pki.goog/GTSGIAG3 US
binary
der
whitelisted
3128 firefox.exe POST 200 172.217.22.35:80 http://ocsp.pki.goog/GTSGIAG3 US
binary
der
whitelisted
3128 firefox.exe POST 200 104.18.24.243:80 http://ocsp.msocsp.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 104.18.24.243:80 http://ocsp.msocsp.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 104.18.24.243:80 http://ocsp.msocsp.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3128 firefox.exe GET 200 2.16.186.112:80 http://detectportal.firefox.com/success.txt unknown
text
whitelisted
3128 firefox.exe POST 200 93.184.220.29:80 http://ocsp.digicert.com/ US
binary
der
whitelisted
3128 firefox.exe POST 200 172.217.22.35:80 http://ocsp.pki.goog/GTSGIAG3 US
binary
der
whitelisted
3128 firefox.exe POST 200 172.217.22.35:80 http://ocsp.pki.goog/GTSGIAG3 US
binary
der
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3128 firefox.exe 52.43.79.30:443 Amazon.com, Inc. US unknown
3128 firefox.exe 216.58.205.244:443 Google Inc. US whitelisted
3128 firefox.exe 2.16.186.112:80 Akamai International B.V. –– whitelisted
3128 firefox.exe 52.27.173.161:443 Amazon.com, Inc. US unknown
3128 firefox.exe 172.217.22.35:80 Google Inc. US whitelisted
3128 firefox.exe 93.184.220.29:80 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
3128 firefox.exe 143.204.205.62:443 US unknown
3128 firefox.exe 52.26.166.58:443 Amazon.com, Inc. US unknown
3128 firefox.exe 172.217.22.74:443 Google Inc. US whitelisted
3128 firefox.exe 104.16.123.175:443 Cloudflare Inc US shared
3128 firefox.exe 104.19.196.151:443 Cloudflare Inc US shared
3128 firefox.exe 216.58.207.74:443 Google Inc. US whitelisted
3128 firefox.exe 151.139.128.14:80 Highwinds Network Group, Inc. US suspicious
3128 firefox.exe 184.28.113.141:443 Akamai International B.V. US suspicious
3128 firefox.exe 23.77.208.56:443 Akamai International B.V. NL unknown
3128 firefox.exe 104.18.24.243:80 Cloudflare Inc US shared
3128 firefox.exe 54.187.176.55:443 Amazon.com, Inc. US unknown
3128 firefox.exe 143.204.214.80:443 US suspicious
3128 firefox.exe 104.27.147.139:443 Cloudflare Inc US unknown
3128 firefox.exe 143.204.214.123:443 US suspicious
3128 firefox.exe 143.204.214.4:443 US suspicious
3128 firefox.exe 52.108.240.70:443 Microsoft Corporation US unknown
3128 firefox.exe 13.107.6.156:443 Microsoft Corporation US whitelisted
3128 firefox.exe 2.16.186.27:443 Akamai International B.V. –– whitelisted
3128 firefox.exe 2.16.186.32:443 Akamai International B.V. –– whitelisted
3128 firefox.exe 104.111.216.109:443 Akamai International B.V. NL unknown
3128 firefox.exe 23.37.48.112:443 Akamai Technologies, Inc. NL whitelisted
3128 firefox.exe 104.111.216.162:443 Akamai International B.V. NL whitelisted
3128 firefox.exe 2.23.106.83:443 Akamai International B.V. –– suspicious
3128 firefox.exe 104.111.243.146:443 Akamai International B.V. NL whitelisted
3128 firefox.exe 40.77.226.250:443 Microsoft Corporation IE whitelisted
3128 firefox.exe 52.142.114.2:443 Microsoft Corporation IE whitelisted
3128 firefox.exe 52.27.128.21:443 Amazon.com, Inc. US unknown
3128 firefox.exe 52.114.158.92:443 Microsoft Corporation US unknown
3128 firefox.exe 204.79.197.200:443 Microsoft Corporation US whitelisted
3128 firefox.exe 52.40.226.98:443 Amazon.com, Inc. US unknown
3128 firefox.exe 54.71.52.202:443 Amazon.com, Inc. US unknown
3128 firefox.exe 172.217.22.14:443 Google Inc. US whitelisted
3128 firefox.exe 173.194.138.199:443 Google Inc. US whitelisted
3128 firefox.exe 35.160.159.212:443 Amazon.com, Inc. US unknown

DNS requests

Domain IP Reputation
detectportal.firefox.com 2.16.186.112
2.16.186.50
whitelisted
re8aspzxckoifazp.appspot.com 216.58.205.244
unknown
aus5.mozilla.org 52.43.79.30
52.32.77.100
35.164.82.230
34.218.159.169
34.214.241.105
52.40.226.98
52.27.144.31
54.148.138.18
whitelisted
balrog-aus5.r53-2.services.mozilla.com 54.148.138.18
52.27.144.31
52.40.226.98
34.214.241.105
34.218.159.169
35.164.82.230
52.32.77.100
52.43.79.30
whitelisted
a1089.dscd.akamai.net 2.16.186.50
2.16.186.112
whitelisted
search.services.mozilla.com 52.27.173.161
52.10.97.252
52.88.179.171
whitelisted
search.r53-2.services.mozilla.com 52.88.179.171
52.10.97.252
52.27.173.161
whitelisted
ocsp.pki.goog 172.217.22.35
whitelisted
pki-goog.l.google.com 172.217.22.35
whitelisted
ocsp.digicert.com 93.184.220.29
whitelisted
cs9.wac.phicdn.net 93.184.220.29
whitelisted
tiles.services.mozilla.com 52.26.166.58
52.25.71.236
52.26.103.165
35.164.130.113
34.208.143.106
35.165.22.140
34.209.86.85
35.164.218.3
whitelisted
snippets.cdn.mozilla.net 143.204.205.62
whitelisted
drcwo519tnci7.cloudfront.net 143.204.205.62
whitelisted
tiles.r53-2.services.mozilla.com 35.164.218.3
52.26.166.58
52.25.71.236
52.26.103.165
35.164.130.113
34.208.143.106
35.165.22.140
34.209.86.85
whitelisted
safebrowsing.googleapis.com 172.217.22.74
whitelisted
unpkg.com 104.16.123.175
104.16.125.175
104.16.122.175
104.16.126.175
104.16.124.175
whitelisted
cdnjs.cloudflare.com 104.19.196.151
104.19.198.151
104.19.199.151
104.19.197.151
104.19.195.151
whitelisted
ajax.googleapis.com 216.58.207.74
216.58.208.42
172.217.16.138
172.217.22.42
172.217.22.106
172.217.21.202
216.58.205.234
172.217.21.234
172.217.22.10
172.217.18.10
172.217.18.170
172.217.23.138
216.58.206.10
whitelisted
googleapis.l.google.com 216.58.206.10
172.217.23.138
172.217.18.170
172.217.18.10
172.217.22.10
172.217.21.234
216.58.205.234
172.217.21.202
172.217.22.106
172.217.22.42
172.217.16.138
216.58.208.42
216.58.207.74
whitelisted
ocsp.comodoca4.com 151.139.128.14
whitelisted
t3j2g9x7.stackpathcdn.com 151.139.128.14
malicious
auth.gfx.ms 184.28.113.141
whitelisted
e13551.dscg.akamaiedge.net 184.28.113.141
whitelisted
secure.aadcdn.microsoftonline-p.com 23.77.208.56
whitelisted
e13761.dscg.akamaiedge.net 23.77.208.56
whitelisted
ocsp.msocsp.com 104.18.24.243
104.18.25.243
whitelisted
ocsp.globalsign.cloud No response malicious
shavar.services.mozilla.com 54.187.176.55
52.32.141.83
54.186.120.41
52.88.72.192
34.223.203.249
34.212.119.231
whitelisted
shavar.prod.mozaws.net 34.212.119.231
34.223.203.249
52.88.72.192
54.186.120.41
52.32.141.83
54.187.176.55
whitelisted
tracking-protection.cdn.mozilla.net 143.204.214.80
143.204.214.50
143.204.214.105
143.204.214.56
whitelisted
d1zkz3k4cclnv6.cloudfront.net 143.204.214.56
143.204.214.105
143.204.214.50
143.204.214.80
whitelisted
awz.sptech.org 104.27.147.139
104.27.146.139
unknown
firefox.settings.services.mozilla.com 143.204.214.123
143.204.214.45
143.204.214.77
143.204.214.68
whitelisted
d2k03kvdk5cku0.cloudfront.net 143.204.214.68
143.204.214.77
143.204.214.45
143.204.214.123
whitelisted
content-signature.cdn.mozilla.net 143.204.214.4
143.204.214.118
143.204.214.72
143.204.214.86
whitelisted
d12uj65dsn9ho1.cloudfront.net 143.204.214.86
143.204.214.72
143.204.214.118
143.204.214.4
whitelisted
office.com 52.108.240.70
52.108.248.9
52.108.208.1
52.108.36.3
52.108.236.4
52.108.32.5
whitelisted
www.office.com 13.107.6.156
whitelisted
b-0004.b-msedge.net No response whitelisted
c.s-microsoft.com 104.111.216.109
whitelisted
img-prod-cms-rt-microsoft-com.akamaized.net 2.16.186.27
2.16.186.40
whitelisted
blob.officehome.msocdn.com 23.37.48.112
unknown
statics-uhf-wus.akamaized.net 2.16.186.32
2.16.186.11
whitelisted
mem.gfx.ms 104.111.216.162
whitelisted
a1449.dscg2.akamai.net 2.16.186.40
2.16.186.27
whitelisted
a849.dscg2.akamai.net 2.16.186.11
2.16.186.32
whitelisted
e13678.dscg.akamaiedge.net 104.111.216.109
malicious
e12520.g.akamaiedge.net 23.37.48.112
unknown
e55.dspb.akamaiedge.net 104.111.216.162
whitelisted
www.microsoft.com 2.23.106.83
whitelisted
e13678.dspb.akamaiedge.net 2.23.106.83
whitelisted
uhf.microsoft.com 104.111.243.146
whitelisted
e11095.dspg.akamaiedge.net 104.111.243.146
whitelisted
web.vortex.data.microsoft.com 40.77.226.250
whitelisted
db5.vortex.data.microsoft.com.akadns.net 40.77.226.250
whitelisted
c1.microsoft.com 52.142.114.2
whitelisted
c.msn.com.nsatc.net 52.142.114.2
whitelisted
incoming.telemetry.mozilla.org 52.27.128.21
52.89.114.227
52.34.167.99
52.34.248.21
52.39.195.123
52.89.110.41
52.41.57.47
52.27.23.108
whitelisted
pipeline-edge-prod-25-561439127.us-west-2.elb.amazonaws.com 52.27.23.108
52.41.57.47
52.89.110.41
52.39.195.123
52.34.248.21
52.34.167.99
52.89.114.227
52.27.128.21
shared
browser.pipe.aria.microsoft.com 52.114.158.92
whitelisted
pipe.cloudapp.aria.akadns.net 52.114.158.92
unknown
c.bing.com 204.79.197.200
13.107.21.200
whitelisted
dual-a-0001.a-msedge.net 13.107.21.200
204.79.197.200
whitelisted
push.services.mozilla.com 54.71.52.202
whitelisted
autopush.prod.mozaws.net 54.71.52.202
whitelisted
redirector.gvt1.com 172.217.22.14
whitelisted
r2---sn-aigzrn7d.gvt1.com 173.194.138.199
whitelisted
r2.sn-aigzrn7d.gvt1.com 173.194.138.199
whitelisted

Threats

No threats detected.

Debug output strings

No debug info.