Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Feb. 26, 2025, 9:45 a.m. | Feb. 26, 2025, 9:48 a.m. |
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2760 -
taskkill.exe taskkill /F /IM chrome.exe /T
2888 -
taskkill.exe taskkill /F /IM msedge.exe /T
2972 -
taskkill.exe taskkill /F /IM opera.exe /T
3052 -
taskkill.exe taskkill /F /IM brave.exe /T
1384 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
196-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
2220
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2532 -
taskkill.exe taskkill /F /IM chrome.exe /T
2644 -
taskkill.exe taskkill /F /IM msedge.exe /T
2380 -
taskkill.exe taskkill /F /IM opera.exe /T
2800 -
taskkill.exe taskkill /F /IM brave.exe /T
2988 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
3068-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3056
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2240 -
taskkill.exe taskkill /F /IM chrome.exe /T
2372 -
taskkill.exe taskkill /F /IM msedge.exe /T
828 -
taskkill.exe taskkill /F /IM opera.exe /T
2692 -
taskkill.exe taskkill /F /IM brave.exe /T
2740 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
2924-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3000
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2068 -
taskkill.exe taskkill /F /IM chrome.exe /T
1668 -
taskkill.exe taskkill /F /IM msedge.exe /T
2612 -
taskkill.exe taskkill /F /IM opera.exe /T
1376 -
taskkill.exe taskkill /F /IM brave.exe /T
1304 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
536-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
2732
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
744 -
taskkill.exe taskkill /F /IM chrome.exe /T
2244 -
taskkill.exe taskkill /F /IM msedge.exe /T
2356 -
taskkill.exe taskkill /F /IM opera.exe /T
1320 -
taskkill.exe taskkill /F /IM brave.exe /T
1792 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
2880-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3060
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2056 -
taskkill.exe taskkill /F /IM chrome.exe /T
2652 -
taskkill.exe taskkill /F /IM msedge.exe /T
544 -
taskkill.exe taskkill /F /IM opera.exe /T
2900 -
taskkill.exe taskkill /F /IM brave.exe /T
2120 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
2144-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
884
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
2132 -
taskkill.exe taskkill /F /IM chrome.exe /T
1064 -
taskkill.exe taskkill /F /IM msedge.exe /T
2400 -
taskkill.exe taskkill /F /IM opera.exe /T
2128 -
taskkill.exe taskkill /F /IM brave.exe /T
2224 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
3040-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
320
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
3124 -
taskkill.exe taskkill /F /IM chrome.exe /T
3216 -
taskkill.exe taskkill /F /IM msedge.exe /T
3300 -
taskkill.exe taskkill /F /IM opera.exe /T
3380 -
taskkill.exe taskkill /F /IM brave.exe /T
3460 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
3540-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3584
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
3712 -
taskkill.exe taskkill /F /IM chrome.exe /T
3792 -
taskkill.exe taskkill /F /IM msedge.exe /T
3896 -
taskkill.exe taskkill /F /IM opera.exe /T
3976 -
taskkill.exe taskkill /F /IM brave.exe /T
4056 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
3140-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
1152
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
1788 -
taskkill.exe taskkill /F /IM chrome.exe /T
3340 -
taskkill.exe taskkill /F /IM msedge.exe /T
3436 -
taskkill.exe taskkill /F /IM opera.exe /T
3516 -
taskkill.exe taskkill /F /IM brave.exe /T
1980 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
3688-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3776
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
3840 -
taskkill.exe taskkill /F /IM chrome.exe /T
3988 -
taskkill.exe taskkill /F /IM msedge.exe /T
3144 -
taskkill.exe taskkill /F /IM opera.exe /T
3172 -
taskkill.exe taskkill /F /IM brave.exe /T
3136 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
3364-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3400
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
872 -
taskkill.exe taskkill /F /IM chrome.exe /T
3676 -
taskkill.exe taskkill /F /IM msedge.exe /T
3876 -
taskkill.exe taskkill /F /IM opera.exe /T
3660 -
taskkill.exe taskkill /F /IM brave.exe /T
4032 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
1092-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3288
-
-
taskkill.exe taskkill /F /IM firefox.exe /T
3392 -
taskkill.exe taskkill /F /IM chrome.exe /T
3440 -
taskkill.exe taskkill /F /IM msedge.exe /T
3784 -
taskkill.exe taskkill /F /IM opera.exe /T
3892 -
taskkill.exe taskkill /F /IM brave.exe /T
3772 -
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking
4020-
firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" --kiosk https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --no-default-browser-check --disable-popup-blocking
3232
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Program Files\Mozilla Firefox\api-ms-win-crt-multibyte-l1-1-0.dll |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process |
section | {u'size_of_data': u'0x00015c00', u'virtual_address': u'0x000d4000', u'entropy': 7.145421915037016, u'name': u'.rsrc', u'virtual_size': u'0x00015ba8'} | entropy | 7.14542191504 | description | A section with a high entropy has been found |
url | https://aus5.mozilla.org/update/6/%PRODUCT%/%VERSION%/%BUILD_ID%/%BUILD_TARGET%/%LOCALE%/%CHANNEL%/%OS_VERSION%/%SYSTEM_CAPABILITIES%/%DISTRIBUTION%/%DISTRIBUTION_VERSION%/update.xml |
url | https://crash-reports.mozilla.com/submit?id= |
url | https://hg.mozilla.org/releases/mozilla-release/rev/92187d03adde4b31daef292087a266f10121379c |
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active |
cmdline | taskkill /F /IM opera.exe /T |
cmdline | taskkill /F /IM chrome.exe /T |
cmdline | taskkill /F /IM msedge.exe /T |
cmdline | taskkill /F /IM firefox.exe /T |
cmdline | taskkill /F /IM brave.exe /T |