Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
VirusShare_661c60ba6e4e5e7864714aed6cda9d55.zip

Overview

General Information

Sample name:VirusShare_661c60ba6e4e5e7864714aed6cda9d55.zip
Analysis ID:1635119
MD5:c391c7137fba135fd9bb09b925dc1980
SHA1:d0767af0d449d0be7f48781d2073ef72650c5ff9
SHA256:d5c457f2646d7cb89e55a1b0bad4d823bf16bab2c1ad55daa4450113068f67c6
Infos:

Detection

Score:52
Range:0 - 100
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Tries to harvest and steal browser information (history, passwords, etc)
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to call native functions
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file does not import any functions
PE file overlay found
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)

Classification

  • System is w10x64_ra
  • rundll32.exe (PID: 6324 cmdline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
  • OpenWith.exe (PID: 6428 cmdline: C:\Windows\system32\OpenWith.exe -Embedding MD5: E4A834784FA08C17D47A1E72429C5109)
    • Acrobat.exe (PID: 6492 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\Temp1_VirusShare_661c60ba6e4e5e7864714aed6cda9d55.zip\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C)
  • OpenWith.exe (PID: 528 cmdline: C:\Windows\system32\OpenWith.exe -Embedding MD5: E4A834784FA08C17D47A1E72429C5109)
    • firefox.exe (PID: 912 cmdline: "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "C:\Users\user\Desktop\VirusShare_661c60ba6e4e5e7864714aed6cda9d55\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76" MD5: C86B1BE9ED6496FE0E0CBE73F81D8045)
      • firefox.exe (PID: 2108 cmdline: "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url C:\Users\user\Desktop\VirusShare_661c60ba6e4e5e7864714aed6cda9d55\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76 MD5: C86B1BE9ED6496FE0E0CBE73F81D8045)
        • firefox.exe (PID: 3568 cmdline: "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2304 -parentBuildID 20230927232528 -prefsHandle 2252 -prefMapHandle 2244 -prefsLen 25250 -prefMapSize 237879 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8f7bd64a-d03a-4edf-85a5-9ec518d890e8} 2108 "\\.\pipe\gecko-crash-server-pipe.2108" 26ee206d510 socket MD5: C86B1BE9ED6496FE0E0CBE73F81D8045)
        • firefox.exe (PID: 4380 cmdline: "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2516 -parentBuildID 20230927232528 -prefsHandle 3864 -prefMapHandle 3764 -prefsLen 26265 -prefMapSize 237879 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2412d5aa-b892-4f10-a6ac-0e5f62df1307} 2108 "\\.\pipe\gecko-crash-server-pipe.2108" 26ef4197b10 rdd MD5: C86B1BE9ED6496FE0E0CBE73F81D8045)
        • firefox.exe (PID: 7064 cmdline: "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5140 -parentBuildID 20230927232528 -sandboxingKind 0 -prefsHandle 5188 -prefMapHandle 5176 -prefsLen 33133 -prefMapSize 237879 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {273decd0-131e-4e1d-8093-0d28a711eee8} 2108 "\\.\pipe\gecko-crash-server-pipe.2108" 26ef2567710 utility MD5: C86B1BE9ED6496FE0E0CBE73F81D8045)
        • pingsender.exe (PID: 2336 cmdline: "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/4309612b-ce46-455b-bbea-0678ea7a053f/event/Firefox/118.0.1/release/20230927232528?v=4 C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\4309612b-ce46-455b-bbea-0678ea7a053f MD5: B380758F0DAA6B44346C7994EB2408D7)
          • conhost.exe (PID: 2216 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • pingsender.exe (PID: 2292 cmdline: "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/4b6c9ea4-2760-40af-b13f-c9a32b1f931b/health/Firefox/118.0.1/release/20230927232528?v=4 C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\4b6c9ea4-2760-40af-b13f-c9a32b1f931b MD5: B380758F0DAA6B44346C7994EB2408D7)
          • conhost.exe (PID: 2532 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • pingsender.exe (PID: 4128 cmdline: "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/2869bc7b-c35d-434e-b309-b1c625645d80/main/Firefox/118.0.1/release/20230927232528?v=4 C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\2869bc7b-c35d-434e-b309-b1c625645d80 MD5: B380758F0DAA6B44346C7994EB2408D7)
          • conhost.exe (PID: 2976 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • OpenWith.exe (PID: 1916 cmdline: C:\Windows\system32\OpenWith.exe -Embedding MD5: E4A834784FA08C17D47A1E72429C5109)
    • WINWORD.EXE (PID: 4136 cmdline: "C:\Program Files (x86)\Microsoft Office\root\Office16\Winword.exe" /n "C:\Users\user\AppData\Local\Temp\Temp1_VirusShare_661c60ba6e4e5e7864714aed6cda9d55.zip\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76" MD5: 1A0C2C2E7D9C4BC18E91604E9B0C7678)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Users\user\Downloads\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76 (copy)ReversingLabs: Detection: 42%
Source: C:\Users\user\Downloads\32FoVQqJ.partReversingLabs: Detection: 42%
Source: unknownHTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.160.144.191:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.160.144.191:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.16:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.149.100.209:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.149.100.209:443 -> 192.168.2.16:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.91:443 -> 192.168.2.16:49732 version: TLS 1.2
Source: Binary string: UxTheme.pdb source: firefox.exe, 0000000D.00000003.1694437422.0000026EF3E92000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: shlwapi.pdbp source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: gdi32.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: profapi.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ws2_32.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: WLDP.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: bcrypt.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: rpcrt4.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: sechost.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ktmw32.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: msvcrt.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: propsys.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ntmarta.pdb@@@@var(--toolbar-color) source: firefox.exe, 0000000D.00000003.1694437422.0000026EF3E92000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: winmm.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: xul.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: shcore.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: mozglue.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ole32.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: version.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: dbgcore.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: user32.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ntmarta.pdb source: firefox.exe, 0000000D.00000003.1694437422.0000026EF3E92000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: msasn1.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: psapi.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: DWrite.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: shlwapi.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ntdll.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: nss3.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: win32u.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: firefox.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: wsock32.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: dbghelp.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: crypt32.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: firefox.exeMemory has grown: Private usage: 39MB later: 270MB
Source: winword.exeMemory has grown: Private usage: 6MB later: 39MB
Source: Joe Sandbox ViewIP Address: 34.149.100.209 34.149.100.209
Source: Joe Sandbox ViewIP Address: 151.101.129.91 151.101.129.91
Source: Joe Sandbox ViewIP Address: 34.49.51.44 34.49.51.44
Source: Joe Sandbox ViewIP Address: 34.117.188.166 34.117.188.166
Source: Joe Sandbox ViewJA3 fingerprint: fb0aa01abe9d8e4037eb3473ca6e2dca
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global trafficHTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global trafficHTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global trafficHTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global trafficHTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global trafficHTTP traffic detected: GET /canonical.html HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateCache-Control: no-cachePragma: no-cacheConnection: keep-alive
Source: global trafficHTTP traffic detected: GET /success.txt?ipv4 HTTP/1.1Host: detectportal.firefox.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateConnection: keep-alivePragma: no-cacheCache-Control: no-cache
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: "url": "https://www.facebook.com/", equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: "url": "https://www.youtube.com/", equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: "default.sites": "https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/", equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: "default.sites": "https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/", equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: "default.sites": "https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/", equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: You may not unsubscribe from a store listener while the reducer is executing. See https://redux.js.org/api-reference/store#subscribe(listener) for more details.It looks like you are passing several store enhancers to createStore(). This is not supported. Instead, compose them together to a single functionhttps://www.youtube.com/,https://www.facebook.com/,https://www.amazon.de/,https://www.ebay.de/,https://www.wikipedia.org/,https://www.reddit.com/https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/moz-extension://06836808-3da5-4b66-93b7-b66b1a840a96/shims/spotify-embed.js equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: You may not unsubscribe from a store listener while the reducer is executing. See https://redux.js.org/api-reference/store#subscribe(listener) for more details.It looks like you are passing several store enhancers to createStore(). This is not supported. Instead, compose them together to a single functionhttps://www.youtube.com/,https://www.facebook.com/,https://www.amazon.de/,https://www.ebay.de/,https://www.wikipedia.org/,https://www.reddit.com/https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/moz-extension://06836808-3da5-4b66-93b7-b66b1a840a96/shims/spotify-embed.js equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: You may not unsubscribe from a store listener while the reducer is executing. See https://redux.js.org/api-reference/store#subscribe(listener) for more details.It looks like you are passing several store enhancers to createStore(). This is not supported. Instead, compose them together to a single functionhttps://www.youtube.com/,https://www.facebook.com/,https://www.amazon.de/,https://www.ebay.de/,https://www.wikipedia.org/,https://www.reddit.com/https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/moz-extension://06836808-3da5-4b66-93b7-b66b1a840a96/shims/spotify-embed.js equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: (browserSettings.update.channel == "release") && ((experiment.slug in activeExperiments) || ((version|versionCompare('112.!') >= 0)))Integration of a review quality checking feature to assist customers in checking the reliability of product reviews while shoppinghttps://www.youtube.com/,https://www.facebook.com/,https://allegro.pl/,https://www.wikipedia.org/,https://www.olx.pl/,https://www.wykop.pl/Opaque Response Blocking (ORB) is a security hardening technology that we are rolling out gradually, while we monitor web compatibly. equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: (browserSettings.update.channel == "release") && ((experiment.slug in activeExperiments) || ((version|versionCompare('112.!') >= 0)))Integration of a review quality checking feature to assist customers in checking the reliability of product reviews while shoppinghttps://www.youtube.com/,https://www.facebook.com/,https://allegro.pl/,https://www.wikipedia.org/,https://www.olx.pl/,https://www.wykop.pl/Opaque Response Blocking (ORB) is a security hardening technology that we are rolling out gradually, while we monitor web compatibly. equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: *://track.adform.net/serving/scripts/trackpoint/*://static.criteo.net/js/ld/publishertag.js*://static.chartbeat.com/js/chartbeat_video.js*://*.imgur.io/js/vendor.*.bundle.js*://web-assets.toggl.com/app/assets/scripts/*.js*://connect.facebook.net/*/sdk.js**://static.chartbeat.com/js/chartbeat.js*://www.googletagmanager.com/gtm.js**://www.google-analytics.com/gtm/js**://www.google-analytics.com/analytics.js**://libs.coremetrics.com/eluminate.js*://connect.facebook.net/*/all.js**://www.google-analytics.com/plugins/ua/ec.js*://ssl.google-analytics.com/ga.js*://s0.2mdn.net/instream/html5/ima3.js*://www.rva311.com/static/js/main.*.chunk.js*://imasdk.googleapis.com/js/sdkloader/ima3.js*://www.googletagservices.com/tag/js/gpt.js**://pagead2.googlesyndication.com/tag/js/gpt.js**://cdn.adsafeprotected.com/iasPET.1.js*://*.imgur.com/js/vendor.*.bundle.js equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: *://www.facebook.com/platform/impression.php* equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: *://www.facebook.com/platform/impression.php*toolkit.telemetry.updatePing.enabledtoolkit.telemetry.newProfilePing.enabledtoolkit.telemetry.previousBuildIDtoolkit.telemetry.eventping.maximumFrequencydatareporting.policy.dataSubmissionEnableddatareporting.healthreport.uploadEnableddatareporting.policy.minimumPolicyVersionc0ffeec0-ffee-c0ff-eec0-ffeec0ffeec0toolkit.telemetry.testing.overridePreReleasepartitionedPrincipalToInherit_base64 equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000003.1552852584.0000026EF4699000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: *://www.youtube.com/* equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFBC3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: -l10n-id="newtab-menu-content-tooltip" data-l10n-args="{&quot;title&quot;:&quot;Wikipedia&quot;}" class="context-menu-button icon"></button></div><div class="topsite-impression-observer"></div></div></li><li class="top-site-outer"><div class="top-site-inner"><a class="top-site-button" href="https://www.reddit.com/" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper" data-fallback="R"><div class="top-site-icon rich-icon" style="background-image:url(chrome://activity-stream/content/data/content/tippytop/images/reddit-com@2x.png)"></div></div></div><div class="title"><span dir="auto">Reddit<span class="sponsored-label" data-l10n-id="newtab-topsite-sponsored"></span></span></div></a><div><button aria-haspopup="true" data-l10n-id="newtab-menu-content-tooltip" data-l10n-args="{&quot;title&quot;:&quot;Reddit&quot;}" class="context-menu-button icon"></button></div><div class="topsite-impression-observer"></div></div></li><li class="top-site-outer hide-for-narrow"><div class="top-site-inner"><a class="top-site-button" href="https://twitter.com/" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper" data-fallback="T"><div class="top-site-icon rich-icon" style="background-image:url(chrome://activity-stream/content/data/content/tippytop/images/twitter-com@2x.png)"></div></div></div><div class="title"><span dir="auto">Twitter<span class="sponsored-label" data-l10n-id="newtab-topsite-sponsored"></span></span></div></a><div><button aria-haspopup="true" data-l10n-id="newtab-menu-content-tooltip" data-l10n-args="{&quot;title&quot;:&quot;Twitter&quot;}" class="context-menu-button icon"></button></div><div class="topsite-impression-observer"></div></div></li><li class="top-site-outer placeholder hide-for-narrow"><div class="top-site-inner"><a class="top-site-button" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper"><div class=""></div></div></div><div class="title"><span dir="auto"><br/><span class="sponsored-label" data-l10n-id="newtab-topsite-sponsored"></span></span></div></a><button aria-haspopup="dialog" class="context-menu-button edit-button icon" data-l10n-id="newtab-menu-topsites-placeholder-tooltip"></button><div class="topsite-impression-observer"></div></div></li></ul><div class="edit-topsites-wrapper"></div></div></section></div></div></div></div><style data-styles="[[null]]"></style></div><div class="discovery-stream ds-layout"><div class="ds-column ds-column-12"><div class="ds-column-grid"><div></div></div></div><style data-styles="[[null]]"></style></div></div></main></div></div> equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: -webkit-border-bottom-right-radiusget -webkit-border-top-right-radiusresource://gre/modules/SanityTest.sys.mjsset contain-intrinsic-inline-sizeset WebkitBorderBottomRightRadiusget webkitBorderBottomRightRadiusset -webkit-border-bottom-right-radiusget -webkit-border-bottom-left-radius created but addSetting was not called.resource://webcompat/aboutPageProcessScript.jsresource://gre/modules/ExtensionCommon.sys.mjsonManifestEntry/searchStartupPromise<["www.youtube.com","youtube.com"] equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1779234683.0000026EFBADB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1685296984.0000026EFBAC2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1685296984.0000026EFBADB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: 8*://www.facebook.com/* equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.2081947799.0000026EF37F3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2082471595.0000026EF380E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1760899339.0000026EF380E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: 8*://www.youtube.com/* equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1491861389.0000026EFA068000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA068000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1514566942.0000026EFA068000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: 8https://www.facebook.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000003.1484521088.0000026EFF0FE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1509784326.0000026EFC2B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB68000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: 8https://www.youtube.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1779234683.0000026EFBADB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1685296984.0000026EFBAC2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1726462103.0000026F02183000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: 8www.facebook.com equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.2081947799.0000026EF37F3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2082471595.0000026EF380E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1760899339.0000026EF380E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: 8www.youtube.com equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: @mozilla.org/addons/addon-manager-startup;1*://cdn.branch.io/branch-latest.min.js**://pub.doubleverify.com/signals/pub.js*FileUtils_openSafeFileOutputStream@mozilla.org/network/atomic-file-output-stream;1https://smartblock.firefox.etp/facebook.svg*://auth.9c9media.ca/auth/main.js*://c.amazon-adsystem.com/aax2/apstag.js*://web-assets.toggl.com/app/assets/scripts/*.js*://www.everestjs.net/static/st.v3.js*resource://gre/modules/FileUtils.sys.mjs*://*.imgur.io/js/vendor.*.bundle.js*://libs.coremetrics.com/eluminate.jshttps://smartblock.firefox.etp/play.svgwebcompat-reporter@mozilla.org.xpi*://connect.facebook.net/*/sdk.js**://*.imgur.com/js/vendor.*.bundle.js*://connect.facebook.net/*/all.js*@mozilla.org/network/file-output-stream;1pictureinpicture%40mozilla.org:1.0.0FileUtils_openAtomicFileOutputStream*://track.adform.net/serving/scripts/trackpoint/@mozilla.org/network/safe-file-output-stream;1FileUtils_closeSafeFileOutputStream*://static.chartbeat.com/js/chartbeat_video.jsresource://gre/modules/addons/XPIProvider.jsmwebcompat-reporter%40mozilla.org:1.5.1*://static.criteo.net/js/ld/publishertag.js*://static.chartbeat.com/js/chartbeat.js*://www.rva311.com/static/js/main.*.chunk.jsFileUtils_closeAtomicFileOutputStream*://www.google-analytics.com/analytics.js**://www.googletagmanager.com/gtm.js**://www.google-analytics.com/plugins/ua/ec.js*://imasdk.googleapis.com/js/sdkloader/ima3.js*://www.googletagservices.com/tag/js/gpt.js**://pagead2.googlesyndication.com/tag/js/gpt.js**://static.adsafeprotected.com/iasPET.1.js*://adservex.media.net/videoAds.js**://*.moatads.com/*/moatheader.js**://cdn.optimizely.com/public/*.js*://*.vidible.tv/*/vidible-min.js**://cdn.adsafeprotected.com/iasPET.1.js*://s.webtrends.com/js/advancedLinkTracking.js*://s.webtrends.com/js/webtrends.js*://s.webtrends.com/js/webtrends.min.jscolor-mix(in srgb, currentColor 9%, transparent)*://www.google-analytics.com/gtm/js**://js.maxmind.com/js/apis/geoip2/*/geoip2.js*://ssl.google-analytics.com/ga.js*://s0.2mdn.net/instream/html5/ima3.js equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: CHANGE_REASON_USER_SEARCHBAR_CONTEXT["www.facebook.com","facebook.com"] equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: ["www.facebook.com","facebook.com"] equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: ["www.youtube.com","youtube.com"] equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: [{incognito:null, tabId:null, types:["image"], urls:["*://track.adform.net/Serving/TrackPoint/*", "*://pixel.advertising.com/firefox-etp", "*://*.advertising.com/*.js*", "*://*.advertising.com/*", "*://securepubads.g.doubleclick.net/gampad/*ad-blk*", "*://pubads.g.doubleclick.net/gampad/*ad-blk*", "*://securepubads.g.doubleclick.net/gampad/*xml_vmap1*", "*://pubads.g.doubleclick.net/gampad/*xml_vmap1*", "*://vast.adsafeprotected.com/vast*", "*://securepubads.g.doubleclick.net/gampad/*xml_vmap2*", "*://pubads.g.doubleclick.net/gampad/*xml_vmap2*", "*://securepubads.g.doubleclick.net/gampad/*ad*", "*://pubads.g.doubleclick.net/gampad/*ad*", "*://www.facebook.com/platform/impression.php*", "https://ads.stickyadstv.com/firefox-etp", "*://ads.stickyadstv.com/auto-user-sync*", "*://ads.stickyadstv.com/user-matching*", "https://static.adsafeprotected.com/firefox-etp-pixel", "*://*.adsafeprotected.com/*.gif*", "*://*.adsafeprotected.com/*.png*", "*://*.adsafeprotected.com/*.js*", "*://*.adsafeprotected.com/*/adj*", "*://*.adsafeprotected.com/*/imp/*", "*://*.adsafeprotected.com/*/Serving/*", "*://*.adsafeprotected.com/*/unit/*", "*://*.adsafeprotected.com/jload", "*://*.adsafeprotected.com/jload?*", "*://*.adsafeprotected.com/jsvid", "*://*.adsafeprotected.com/jsvid?*", "*://*.adsafeprotected.com/mon*", "*://*.adsafeprotected.com/tpl", "*://*.adsafeprotected.com/tpl?*", "*://*.adsafeprotected.com/services/pub*", "*://*.adsafeprotected.com/*"], windowId:null}, ["blocking"]] equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: [{incognito:null, tabId:null, types:["imageset"], urls:["*://track.adform.net/Serving/TrackPoint/*", "*://pixel.advertising.com/firefox-etp", "*://*.advertising.com/*.js*", "*://*.advertising.com/*", "*://securepubads.g.doubleclick.net/gampad/*ad-blk*", "*://pubads.g.doubleclick.net/gampad/*ad-blk*", "*://securepubads.g.doubleclick.net/gampad/*xml_vmap1*", "*://pubads.g.doubleclick.net/gampad/*xml_vmap1*", "*://vast.adsafeprotected.com/vast*", "*://securepubads.g.doubleclick.net/gampad/*xml_vmap2*", "*://pubads.g.doubleclick.net/gampad/*xml_vmap2*", "*://securepubads.g.doubleclick.net/gampad/*ad*", "*://pubads.g.doubleclick.net/gampad/*ad*", "*://www.facebook.com/platform/impression.php*", "https://ads.stickyadstv.com/firefox-etp", "*://ads.stickyadstv.com/auto-user-sync*", "*://ads.stickyadstv.com/user-matching*", "https://static.adsafeprotected.com/firefox-etp-pixel", "*://*.adsafeprotected.com/*.gif*", "*://*.adsafeprotected.com/*.png*", "*://*.adsafeprotected.com/*.js*", "*://*.adsafeprotected.com/*/adj*", "*://*.adsafeprotected.com/*/imp/*", "*://*.adsafeprotected.com/*/Serving/*", "*://*.adsafeprotected.com/*/unit/*", "*://*.adsafeprotected.com/jload", "*://*.adsafeprotected.com/jload?*", "*://*.adsafeprotected.com/jsvid", "*://*.adsafeprotected.com/jsvid?*", "*://*.adsafeprotected.com/mon*", "*://*.adsafeprotected.com/tpl", "*://*.adsafeprotected.com/tpl?*", "*://*.adsafeprotected.com/services/pub*", "*://*.adsafeprotected.com/*"], windowId:null}, ["blocking"]] equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE255000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: [{incognito:null, tabId:null, types:["script"], urls:["*://webcompat-addon-testbed.herokuapp.com/shims_test.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test_2.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test_3.js", "*://s7.addthis.com/icons/official-addthis-angularjs/current/dist/official-addthis-angularjs.min.js*", "*://track.adform.net/serving/scripts/trackpoint/", "*://track.adform.net/serving/scripts/trackpoint/async/", "*://*.adnxs.com/*/ast.js*", "*://*.adnxs.com/*/pb.js*", "*://*.adnxs.com/*/prebid*", "*://www.everestjs.net/static/st.v3.js*", "*://static.adsafeprotected.com/vans-adapter-google-ima.js", "*://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js", "*://cdn.branch.io/branch-latest.min.js*", "*://pub.doubleverify.com/signals/pub.js*", "*://c.amazon-adsystem.com/aax2/apstag.js", "*://auth.9c9media.ca/auth/main.js", "*://static.chartbeat.com/js/chartbeat.js", "*://static.chartbeat.com/js/chartbeat_video.js", "*://static.criteo.net/js/ld/publishertag.js", "*://*.imgur.com/js/vendor.*.bundle.js", "*://*.imgur.io/js/vendor.*.bundle.js", "*://www.rva311.com/static/js/main.*.chunk.js", "*://web-assets.toggl.com/app/assets/scripts/*.js", "*://libs.coremetrics.com/eluminate.js", "*://connect.facebook.net/*/sdk.js*", "*://connect.facebook.net/*/all.js*", "*://secure.cdn.fastclick.net/js/cnvr-launcher/*/launcher-stub.min.js*", "*://www.google-analytics.com/analytics.js*", "*://www.google-analytics.com/gtm/js*", "*://www.googletagmanager.com/gtm.js*", "*://www.google-analytics.com/plugins/ua/ec.js", "*://ssl.google-analytics.com/ga.js", "*://s0.2mdn.net/instream/html5/ima3.js", "*://imasdk.googleapis.com/js/sdkloader/ima3.js", "*://www.googleadservices.com/pagead/conversion_async.js", "*://www.googletagservices.com/tag/js/gpt.js*", "*://pagead2.googlesyndication.com/tag/js/gpt.js*", "*://pagead2.googlesyndication.com/gpt/pubads_impl_*.js*", "*://securepubads.g.doubleclick.net/tag/js/gpt.js*", "*://securepubads.g.doubleclick.net/gpt/pubads_impl_*.js*", "*://script.ioam.de/iam.js", "*://cdn.adsafeprotected.com/iasPET.1.js", "*://static.adsafeprotected.com/iasPET.1.js", "*://adservex.media.net/videoAds.js*", "*://*.moatads.com/*/moatad.js*", "*://*.moatads.com/*/moatapi.js*", "*://*.moatads.com/*/moatheader.js*", "*://*.moatads.com/*/yi.js*", "*://*.imrworldwide.com/v60.js", "*://cdn.optimizely.com/js/*.js", "*://cdn.optimizely.com/public/*.js", "*://id.rambler.ru/rambler-id-helper/auth_events.js", "*://media.richrelevance.com/rrserver/js/1.2/p13n.js", "*://www.gstatic.com/firebasejs/*/firebase-messaging.js*", "*://*.vidible.tv/*/vidible-min.js*", "*://vdb-cdn-files.s3.amazonaws.com/*/vidible-min.js*", "*://js.maxmind.com/js/apis/geoip2/*/geoip2.js", "*://s.webtrends.com/js/advancedLinkTracking.js", "*://s.webtrends.com/js/webtrends.js", "*://s.webtrends.com/js/webtrends.min.js"], windowId
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE255000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: [{incognito:null, tabId:null, types:["script"], urls:["*://webcompat-addon-testbed.herokuapp.com/shims_test.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test_2.js", "*://example.com/browser/browser/extensions/webcompat/tests/browser/shims_test_3.js", "*://s7.addthis.com/icons/official-addthis-angularjs/current/dist/official-addthis-angularjs.min.js*", "*://track.adform.net/serving/scripts/trackpoint/", "*://track.adform.net/serving/scripts/trackpoint/async/", "*://*.adnxs.com/*/ast.js*", "*://*.adnxs.com/*/pb.js*", "*://*.adnxs.com/*/prebid*", "*://www.everestjs.net/static/st.v3.js*", "*://static.adsafeprotected.com/vans-adapter-google-ima.js", "*://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js", "*://cdn.branch.io/branch-latest.min.js*", "*://pub.doubleverify.com/signals/pub.js*", "*://c.amazon-adsystem.com/aax2/apstag.js", "*://auth.9c9media.ca/auth/main.js", "*://static.chartbeat.com/js/chartbeat.js", "*://static.chartbeat.com/js/chartbeat_video.js", "*://static.criteo.net/js/ld/publishertag.js", "*://*.imgur.com/js/vendor.*.bundle.js", "*://*.imgur.io/js/vendor.*.bundle.js", "*://www.rva311.com/static/js/main.*.chunk.js", "*://web-assets.toggl.com/app/assets/scripts/*.js", "*://libs.coremetrics.com/eluminate.js", "*://connect.facebook.net/*/sdk.js*", "*://connect.facebook.net/*/all.js*", "*://secure.cdn.fastclick.net/js/cnvr-launcher/*/launcher-stub.min.js*", "*://www.google-analytics.com/analytics.js*", "*://www.google-analytics.com/gtm/js*", "*://www.googletagmanager.com/gtm.js*", "*://www.google-analytics.com/plugins/ua/ec.js", "*://ssl.google-analytics.com/ga.js", "*://s0.2mdn.net/instream/html5/ima3.js", "*://imasdk.googleapis.com/js/sdkloader/ima3.js", "*://www.googleadservices.com/pagead/conversion_async.js", "*://www.googletagservices.com/tag/js/gpt.js*", "*://pagead2.googlesyndication.com/tag/js/gpt.js*", "*://pagead2.googlesyndication.com/gpt/pubads_impl_*.js*", "*://securepubads.g.doubleclick.net/tag/js/gpt.js*", "*://securepubads.g.doubleclick.net/gpt/pubads_impl_*.js*", "*://script.ioam.de/iam.js", "*://cdn.adsafeprotected.com/iasPET.1.js", "*://static.adsafeprotected.com/iasPET.1.js", "*://adservex.media.net/videoAds.js*", "*://*.moatads.com/*/moatad.js*", "*://*.moatads.com/*/moatapi.js*", "*://*.moatads.com/*/moatheader.js*", "*://*.moatads.com/*/yi.js*", "*://*.imrworldwide.com/v60.js", "*://cdn.optimizely.com/js/*.js", "*://cdn.optimizely.com/public/*.js", "*://id.rambler.ru/rambler-id-helper/auth_events.js", "*://media.richrelevance.com/rrserver/js/1.2/p13n.js", "*://www.gstatic.com/firebasejs/*/firebase-messaging.js*", "*://*.vidible.tv/*/vidible-min.js*", "*://vdb-cdn-files.s3.amazonaws.com/*/vidible-min.js*", "*://js.maxmind.com/js/apis/geoip2/*/geoip2.js", "*://s.webtrends.com/js/advancedLinkTracking.js", "*://s.webtrends.com/js/webtrends.js", "*://s.webtrends.com/js/webtrends.min.js"], windowId
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B0F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: [{incognito:null, tabId:null, types:["xmlhttprequest"], urls:["*://track.adform.net/Serving/TrackPoint/*", "*://pagead2.googlesyndication.com/pagead/*.js*fcd=true", "*://pagead2.googlesyndication.com/pagead/js/*.js*fcd=true", "*://pixel.advertising.com/firefox-etp", "*://cdn.cmp.advertising.com/firefox-etp", "*://*.advertising.com/*.js*", "*://*.advertising.com/*", "*://securepubads.g.doubleclick.net/gampad/*ad-blk*", "*://pubads.g.doubleclick.net/gampad/*ad-blk*", "*://securepubads.g.doubleclick.net/gampad/*xml_vmap1*", "*://pubads.g.doubleclick.net/gampad/*xml_vmap1*", "*://vast.adsafeprotected.com/vast*", "*://securepubads.g.doubleclick.net/gampad/*xml_vmap2*", "*://pubads.g.doubleclick.net/gampad/*xml_vmap2*", "*://securepubads.g.doubleclick.net/gampad/*ad*", "*://pubads.g.doubleclick.net/gampad/*ad*", "*://www.facebook.com/platform/impression.php*", "https://ads.stickyadstv.com/firefox-etp", "*://ads.stickyadstv.com/auto-user-sync*", "*://ads.stickyadstv.com/user-matching*", "https://static.adsafeprotected.com/firefox-etp-pixel", "https://static.adsafeprotected.com/firefox-etp-js", "*://*.adsafeprotected.com/*.gif*", "*://*.adsafeprotected.com/*.png*", "*://*.adsafeprotected.com/*.js*", "*://*.adsafeprotected.com/*/adj*", "*://*.adsafeprotected.com/*/imp/*", "*://*.adsafeprotected.com/*/Serving/*", "*://*.adsafeprotected.com/*/unit/*", "*://*.adsafeprotected.com/jload", "*://*.adsafeprotected.com/jload?*", "*://*.adsafeprotected.com/jsvid", "*://*.adsafeprotected.com/jsvid?*", "*://*.adsafeprotected.com/mon*", "*://*.adsafeprotected.com/tpl", "*://*.adsafeprotected.com/tpl?*", "*://*.adsafeprotected.com/services/pub*", "*://*.adsafeprotected.com/*"], windowId:null}, ["blocking"]] equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000003.1597630546.0000026EF47B4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: `https://www.facebook.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000003.1597630546.0000026EF47B4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: `https://www.youtube.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1925115156.0000026EE20E3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: doff-text" data-l10n-args="{&quot;engine&quot;: &quot;Google&quot;}"></div><input type="search" class="fake-editable" tabindex="-1" aria-hidden="true"/><div class="fake-caret"></div></button></div></div></div><div class="body-wrapper on"><div class="discovery-stream ds-layout"><div class="ds-column ds-column-12"><div class="ds-column-grid"><div><div class="ds-top-sites"><section class="collapsible-section top-sites" data-section-id="topsites"><div class="section-top-bar"><h3 class="section-title-container " style="visibility:hidden"><span class="section-title"><span data-l10n-id="newtab-section-header-topsites"></span></span><span class="learn-more-link-wrapper"></span></h3></div><div><ul class="top-sites-list"><li class="top-site-outer placeholder "><div class="top-site-inner"><a class="top-site-button" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper"><div class=""></div></div></div><div class="title"><span dir="auto"><br/><span class="sponsored-label" data-l10n-id="newtab-topsite-sponsored"></span></span></div></a><button aria-haspopup="dialog" class="context-menu-button edit-button icon" data-l10n-id="newtab-menu-topsites-placeholder-tooltip"></button><div class="topsite-impression-observer"></div></div></li><li class="top-site-outer placeholder "><div class="top-site-inner"><a class="top-site-button" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper"><div class=""></div></div></div><div class="title"><span dir="auto"><br/><span class="sponsored-label" data-l10n-id="newtab-topsite-sponsored"></span></span></div></a><button aria-haspopup="dialog" class="context-menu-button edit-button icon" data-l10n-id="newtab-menu-topsites-placeholder-tooltip"></button><div class="topsite-impression-observer"></div></div></li><li class="top-site-outer"><div class="top-site-inner"><a class="top-site-button" href="https://www.youtube.com/" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper" data-fallback="Y"><div class="top-site-icon rich-icon" style="background-image:url(chrome://activity-stream/content/data/content/tippytop/images/youtube-com@2x.png)"></div></div></div><div class="title"><span dir="auto">YouTube<span class="sponsored-label" data-l10n-id="newtab-topsite-sponsored"></span></span></div></a><div><button aria-haspopup="true" data-l10n-id="newtab-menu-content-tooltip" data-l10n-args="{&quot;title&quot;:&quot;YouTube&quot;}" class="context-menu-button icon"></button></div><div class="topsite-impression-observer"></div></div></li><li class="top-site-outer"><div class="top-site-inner"><a class="top-site-button" href="https://www.facebook.com/" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper" data-fallback="F"><div class="top-site-icon rich-icon" style="backgroun
Source: firefox.exe, 0000000D.00000002.1925115156.0000026EE20E3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: doff-text" data-l10n-args="{&quot;engine&quot;: &quot;Google&quot;}"></div><input type="search" class="fake-editable" tabindex="-1" aria-hidden="true"/><div class="fake-caret"></div></button></div></div></div><div class="body-wrapper on"><div class="discovery-stream ds-layout"><div class="ds-column ds-column-12"><div class="ds-column-grid"><div><div class="ds-top-sites"><section class="collapsible-section top-sites" data-section-id="topsites"><div class="section-top-bar"><h3 class="section-title-container " style="visibility:hidden"><span class="section-title"><span data-l10n-id="newtab-section-header-topsites"></span></span><span class="learn-more-link-wrapper"></span></h3></div><div><ul class="top-sites-list"><li class="top-site-outer placeholder "><div class="top-site-inner"><a class="top-site-button" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper"><div class=""></div></div></div><div class="title"><span dir="auto"><br/><span class="sponsored-label" data-l10n-id="newtab-topsite-sponsored"></span></span></div></a><button aria-haspopup="dialog" class="context-menu-button edit-button icon" data-l10n-id="newtab-menu-topsites-placeholder-tooltip"></button><div class="topsite-impression-observer"></div></div></li><li class="top-site-outer placeholder "><div class="top-site-inner"><a class="top-site-button" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper"><div class=""></div></div></div><div class="title"><span dir="auto"><br/><span class="sponsored-label" data-l10n-id="newtab-topsite-sponsored"></span></span></div></a><button aria-haspopup="dialog" class="context-menu-button edit-button icon" data-l10n-id="newtab-menu-topsites-placeholder-tooltip"></button><div class="topsite-impression-observer"></div></div></li><li class="top-site-outer"><div class="top-site-inner"><a class="top-site-button" href="https://www.youtube.com/" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper" data-fallback="Y"><div class="top-site-icon rich-icon" style="background-image:url(chrome://activity-stream/content/data/content/tippytop/images/youtube-com@2x.png)"></div></div></div><div class="title"><span dir="auto">YouTube<span class="sponsored-label" data-l10n-id="newtab-topsite-sponsored"></span></span></div></a><div><button aria-haspopup="true" data-l10n-id="newtab-menu-content-tooltip" data-l10n-args="{&quot;title&quot;:&quot;YouTube&quot;}" class="context-menu-button icon"></button></div><div class="topsite-impression-observer"></div></div></li><li class="top-site-outer"><div class="top-site-inner"><a class="top-site-button" href="https://www.facebook.com/" tabindex="0" draggable="true" data-is-sponsored-link="false"><div class="tile" aria-hidden="true"><div class="icon-wrapper" data-fallback="F"><div class="top-site-icon rich-icon" style="backgroun
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://compose.mail.yahoo.co.jp/ym/Compose?To=%sCan't invoke URIFixup in the content processhttp://www.inbox.lv/rfc2368/?value=%sSEC_ALLOW_CROSS_ORIGIN_SEC_CONTEXT_IS_NULL@mozilla.org/network/async-stream-copier;1@mozilla.org/scriptableinputstream;1https://mail.yahoo.co.jp/compose/?To=%shttps://mail.yandex.ru/compose?mailto=%snewChannel requires a single object argument@mozilla.org/network/simple-stream-listener;1@mozilla.org/intl/converter-input-stream;1https://e.mail.ru/cgi-bin/sentmsg?mailto=%shttps://mail.inbox.lv/compose?to=%shttps://poczta.interia.pl/mh/?mailto=%sMust have a source and a callbackpdfjs.previousHandler.preferredActionpdfjs.previousHandler.alwaysAskBeforeHandling@mozilla.org/uriloader/handler-service;1VALIDATE_DONT_COLLAPSE_WHITESPACE@mozilla.org/uriloader/handler-service;1First argument should be an nsIInputStream@mozilla.org/network/input-stream-pump;1Non-zero amount of bytes must be specified equals www.yahoo.com (Yahoo)
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.cdn.mozilla.net/v3/firefox/global-recs?version=3&consumer_key=$apiKey&locale_lang=en-US&feed_variant=default_spocs_offShow update notifications to Windows 10+ users who have not used Firefox for a long time and are background updated to Firefox 106+.You must provide a target ID as the second parameter of AlsoToOneContent. If you want to send to all content processes, use BroadcastToContenthttps://vk.com/,https://www.youtube.com/,https://ok.ru/,https://www.avito.ru/,https://www.aliexpress.com/,https://www.wikipedia.org/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://vk.com/,https://www.youtube.com/,https://ok.ru/,https://www.avito.ru/,https://www.aliexpress.com/,https://www.wikipedia.org/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1491861389.0000026EFA068000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA068000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1514566942.0000026EFA068000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.facebook.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000003.1484521088.0000026EFF0FE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1509784326.0000026EFC2B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB68000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://allegro.pl/,https://www.wikipedia.org/,https://www.olx.pl/,https://www.wykop.pl/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://allegro.pl/,https://www.wikipedia.org/,https://www.olx.pl/,https://www.wykop.pl/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://twitter.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://twitter.com/ equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://twitter.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://twitter.com/https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/url('chrome://activity-stream/content/data/content/assets/mr-mobilecrosspromo.svg') var(--mr-secondary-position) no-repeat var(--mr-screen-background-color) equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://twitter.com/https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/url('chrome://activity-stream/content/data/content/assets/mr-mobilecrosspromo.svg') var(--mr-secondary-position) no-repeat var(--mr-screen-background-color) equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://twitter.com/https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/url('chrome://activity-stream/content/data/content/assets/mr-mobilecrosspromo.svg') var(--mr-secondary-position) no-repeat var(--mr-screen-background-color) equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.de/,https://www.ebay.de/,https://www.wikipedia.org/,https://www.reddit.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.amazon.de/,https://www.ebay.de/,https://www.wikipedia.org/,https://www.reddit.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.amazon.co.uk/,https://www.bbc.co.uk/,https://www.ebay.co.uk/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.amazon.co.uk/,https://www.bbc.co.uk/,https://www.ebay.co.uk/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/ equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/https://www.mozilla.org/firefox/mobile/get-app/?utm_medium=firefox-desktop&utm_source=onboarding-modal&utm_campaign=mr2022&utm_content=existing-global equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/https://www.mozilla.org/firefox/mobile/get-app/?utm_medium=firefox-desktop&utm_source=onboarding-modal&utm_campaign=mr2022&utm_content=existing-global equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.wikipedia.org/,https://www.amazon.ca/,https://twitter.com/https://www.mozilla.org/firefox/mobile/get-app/?utm_medium=firefox-desktop&utm_source=onboarding-modal&utm_campaign=mr2022&utm_content=existing-global equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/ equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/L equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/L equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/L equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/ equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.amazon.fr/,https://www.leboncoin.fr/,https://twitter.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1581592389.0000026EF9D7E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/ equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000003.1581592389.0000026EF9D7E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/ equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000003.1581592389.0000026EF9D7E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/ equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.amazon.co.uk/,https://www.bbc.co.uk/,https://www.ebay.co.uk/moz-extension://06836808-3da5-4b66-93b7-b66b1a840a96/shims/microsoftLogin.js equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.amazon.co.uk/,https://www.bbc.co.uk/,https://www.ebay.co.uk/moz-extension://06836808-3da5-4b66-93b7-b66b1a840a96/shims/microsoftLogin.js equals www.twitter.com (Twitter)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/,https://www.facebook.com/,https://www.wikipedia.org/,https://www.reddit.com/,https://www.amazon.com/,https://twitter.com/https://www.youtube.com/,https://www.facebook.com/,https://www.reddit.com/,https://www.amazon.co.uk/,https://www.bbc.co.uk/,https://www.ebay.co.uk/moz-extension://06836808-3da5-4b66-93b7-b66b1a840a96/shims/microsoftLogin.js equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1647746960.0000026EFC45D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1552852584.0000026EF4699000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1699447895.0000026EFC472000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: moz-extension://06836808-3da5-4b66-93b7-b66b1a840a96/injections/js/bug1842437-www.youtube.com-performance-now-precision.js equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: verifySignatures@XPIDatabase.jsm:2217:12moz-extension://06836808-3da5-4b66-93b7-b66b1a840a96/injections/css/bug1800000-www.honda.co.uk-choose-dealer-button-fix.css(messageImpressions.FIREFOX_VIEW_SPOTLIGHT[messageImpressions.FIREFOX_VIEW_SPOTLIGHT | length - 1] == null || messageImpressions.FIREFOX_VIEW_SPOTLIGHT[messageImpressions.FIREFOX_VIEW_SPOTLIGHT | length - 1] < 1741607829137)(messageImpressions.FIREFOX_VIEW_FEATURE_TOUR[messageImpressions.FIREFOX_VIEW_FEATURE_TOUR | length - 1] == null || messageImpressions.FIREFOX_VIEW_FEATURE_TOUR[messageImpressions.FIREFOX_VIEW_FEATURE_TOUR | length - 1] < 1741607829137)C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\sessionCheckpoints.json.tmpC:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\sessionCheckpoints.json.tmp{"id":"snippets","enabled":false,"type":"remote","url":"https://snippets.cdn.mozilla.net/%STARTPAGE_VERSION%/%NAME%/%VERSION%/%APPBUILDID%/%BUILD_TARGET%/%LOCALE%/%CHANNEL%/%OS_VERSION%/%DISTRIBUTION%/%DISTRIBUTION_VERSION%/","updateCycleInMs":14400000}C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\extensions.json.tmphttps://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?collection=whats-new-panel&bucket=main&_expected=0https://aus5.mozilla.org/update/3/GMP/118.0.1/20230927232528/WINNT_x86_64-msvc-x64/en-US/release/Windows_NT%252010.0.0.0.19045.2006%2520(x64)/default/default/update.xmlC:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\addonStartup.json.lz4.tmphttps://aus5.mozilla.org/update/6/Firefox/118.0.1/20230927232528/WINNT_x86_64-msvc-x64/en-US/release/Windows_NT%252010.0.0.0.19045.2006%2520(x64)/ISET%3ASSE4_2%2CMEM%3A8191/default/default/update.xmlAAAAAAAAAAAAAAAQAAAAlQa6rZo0zAZPjNBgbH6P81kwgZIxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMSowKAYDVQQKDCFUaGUgVW5pdmVyc2UgU2VjdXJpdHkgQ29tcGFueSBMdGQxKjAoBgNVBAMMIVRoZSBVbml2ZXJzZSBTZWN1cml0eSBDb21wYW55IEx0ZA==https://aus5.mozilla.org/update/3/GMP/118.0.1/20230927232528/WINNT_x86_64-msvc-x64/en-US/release/Windows_NT%252010.0.0.0.19045.2006%2520(x64)/default/default/update.xmlC:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\sessionCheckpoints.json.tmpC:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\targeting.snapshot.json.tmphttps://aus5.mozilla.org/update/6/Firefox/118.0.1/20230927232528/WINNT_x86_64-msvc-x64/en-US/release/Windows_NT%252010.0.0.0.19045.2006%2520(x64)/ISET%3ASSE4_2%2CMEM%3A8191/default/default/update.xml?force=1moz-extension://06836808-3da5-4b66-93b7-b66b1a840a96/injections/js/bug1842437-www.youtube.com-performance-now-precision.jsAAAAAAAAAAAAAAAQAAAAlQa6rZo0zAZPjNBgbH6P81kwgZIxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMSowKAYDVQQKDCFUaGUgVW5pdmVyc2UgU2VjdXJpdHkgQ29tcGFueSBMdGQxKjAoBgNVBAMMIVRoZSBVbml2ZXJzZSBTZWN1cml0eSBDb21wYW55IEx
Source: firefox.exe, 0000000D.00000002.2051275263.0000026EF280C000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1779234683.0000026EFBADB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1742404168.0000026EF280C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: www.facebook.com equals www.facebook.com (Facebook)
Source: firefox.exe, 0000000D.00000002.2081947799.0000026EF37F3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2082471595.0000026EF380E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1760899339.0000026EF380E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: www.youtube.com equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1701334170.0000026EFF407000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: www.youtube.com- equals www.youtube.com (Youtube)
Source: firefox.exe, 0000000D.00000003.1731781069.0000026EF29E5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1460587802.0000026F02169000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1731781069.0000026EF29B2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: x*://www.facebook.com/platform/impression.php* equals www.facebook.com (Facebook)
Source: global trafficDNS traffic detected: DNS query: prod.classify-client.prod.webservices.mozgcp.net
Source: global trafficDNS traffic detected: DNS query: detectportal.firefox.com
Source: global trafficDNS traffic detected: DNS query: prod.detectportal.prod.cloudops.mozgcp.net
Source: global trafficDNS traffic detected: DNS query: contile.services.mozilla.com
Source: global trafficDNS traffic detected: DNS query: example.org
Source: global trafficDNS traffic detected: DNS query: ipv4only.arpa
Source: global trafficDNS traffic detected: DNS query: spocs.getpocket.com
Source: global trafficDNS traffic detected: DNS query: prod.ads.prod.webservices.mozgcp.net
Source: global trafficDNS traffic detected: DNS query: prod.balrog.prod.cloudops.mozgcp.net
Source: global trafficDNS traffic detected: DNS query: content-signature-2.cdn.mozilla.net
Source: global trafficDNS traffic detected: DNS query: prod.content-signature-chains.prod.webservices.mozgcp.net
Source: global trafficDNS traffic detected: DNS query: shavar.services.mozilla.com
Source: global trafficDNS traffic detected: DNS query: shavar.prod.mozaws.net
Source: global trafficDNS traffic detected: DNS query: push.services.mozilla.com
Source: global trafficDNS traffic detected: DNS query: telemetry-incoming.r53-2.services.mozilla.com
Source: global trafficDNS traffic detected: DNS query: firefox.settings.services.mozilla.com
Source: global trafficDNS traffic detected: DNS query: prod.remote-settings.prod.webservices.mozgcp.net
Source: global trafficDNS traffic detected: DNS query: services.addons.mozilla.org
Source: global trafficDNS traffic detected: DNS query: normandy.cdn.mozilla.net
Source: global trafficDNS traffic detected: DNS query: normandy.tombstone.experimenter.prod.webservices.mozgcp.net
Source: firefox.exe, 0000000D.00000003.1491861389.0000026EFA054000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA054000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1639494732.0000026EFA054000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1925115156.0000026EE206B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF570000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1688773230.0000026EF9D19000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1581592389.0000026EF9D19000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: http://127.0.0.1:
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2068695454.0000026EF3003000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://a9.com/-/spec/opensearch/1.0/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://a9.com/-/spec/opensearch/1.0/resource://gre/modules/NetUtil.sys.mjsguids
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2068695454.0000026EF3003000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://a9.com/-/spec/opensearch/1.1/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://a9.com/-/spec/opensearch/1.1/featureUpdate:searchConfigurationimport-infreq-make-self-at-home
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2068695454.0000026EF3003000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://a9.com/-/spec/opensearchdescription/1.0/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://a9.com/-/spec/opensearchdescription/1.0/resource://gre/modules/PlacesUtils.sys.mjsUnexpected
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2068695454.0000026EF3003000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://a9.com/-/spec/opensearchdescription/1.1/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1724777581.0000026EF30C0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ciscobinary.openh264.org/openh264-linux32-2e1774ab6dc6c43debb0b5b628bdf122a391d521.zip
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1724777581.0000026EF30C0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ciscobinary.openh264.org/openh264-linux64-2e1774ab6dc6c43debb0b5b628bdf122a391d521.zip
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ciscobinary.openh264.org/openh264-macosx64-2e1774ab6dc6c43debb0b5b628bdf122a391d521-2.zipTake
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ciscobinary.openh264.org/openh264-macosx64-2e1774ab6dc6c43debb0b5b628bdf122a391d521-2.zipfile
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1724777581.0000026EF30C0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ciscobinary.openh264.org/openh264-win32-2e1774ab6dc6c43debb0b5b628bdf122a391d521.zip
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1729714585.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2070471619.0000026EF3079000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1724777581.0000026EF30C0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ciscobinary.openh264.org/openh264-win64-2e1774ab6dc6c43debb0b5b628bdf122a391d521.zip
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://compose.mail.yahoo.co.jp/ym/Compose?To=%ss
Source: firefox.exe, 0000000D.00000003.1514566942.0000026EFA068000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1655149967.0000026EF3EDC000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1639410219.0000026EFA065000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1724229890.0000026EF38F3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA0C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1658874341.0000026EF38F2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1627757372.0000026EF3EC7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1694834197.0000026EF38F3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1788343221.0000026EF316B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1509784326.0000026EFC2B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2074575124.0000026EF316B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1962455087.0000026EEE1C9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1741380216.0000026EF316B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1718493534.0000026EF371D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1788343221.0000026EF3149000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2107317447.0000026EF3EDC000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1720238362.0000026EF3160000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1669738605.0000026EFA068000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2118222772.0000026EF4147000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1491510442.0000026EFA0CF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1720238362.0000026EF3149000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://detectportal.firefox.com
Source: firefox.exe, 0000000D.00000002.2045177705.0000026EF2551000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1745214336.0000026EF2551000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1911893455.0000026EF2551000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1831079224.0000026EF2549000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://detectportal.firefox.com/
Source: firefox.exe, 0000000D.00000002.2009305625.0000026EEFBCE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2074575124.0000026EF3182000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1720238362.0000026EF3177000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1581592389.0000026EF9D2A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1913295191.0000026EEFBCE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2100561176.0000026EF3D18000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1688773230.0000026EF9D39000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1883012070.0000026EEFBC3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1706074109.0000026EFC267000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1962455087.0000026EEE1C9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1699896543.0000026EF9D3C000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1741380216.0000026EF3190000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1511469654.0000026EFC267000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1997030933.0000026EEF598000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1991317775.0000026EEF436000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF58E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: http://detectportal.firefox.com/canonical.html
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://detectportal.firefox.com/canonical.htmlACTIVITY_SUBTYPE_REQUEST_BODY_SENTACTIVITY_SUBTYPE_PRO
Source: firefox.exe, 0000000D.00000002.1925115156.0000026EE20D8000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1608522889.0000026EFDB6C000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1706155333.0000026EFC22D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1726132000.0000026F0236A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1962455087.0000026EEE1E0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1511469654.0000026EFC20F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: http://detectportal.firefox.com/success.txt?ipv4
Source: firefox.exe, 0000000D.00000002.2078244023.0000026EF3727000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1712132122.0000026EFDB6C000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1991317775.0000026EEF418000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1608522889.0000026EFDB6C000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF029000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1798884255.0000026EFBA7C000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1513972158.0000026EFBA6E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF570000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1718493534.0000026EF371D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1997030933.0000026EEF570000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: http://detectportal.firefox.com/success.txt?ipv6
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://developer.mozilla.org/en/docs/DOM:element.addEventListenerUseOfReleaseEventsWarningUse
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://developer.mozilla.org/en/docs/DOM:element.removeEventListener
Source: firefox.exe, 0000000D.00000003.1485336487.0000026EFF053000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://json-schema.org/draft-04/schema#
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://json-schema.org/draft-04/schema#Instance
Source: firefox.exe, 0000000D.00000003.1485336487.0000026EFF053000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://json-schema.org/draft-06/schema#
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://json-schema.org/draft-06/schema#http://json-schema.org/draft-07/schema#_getTimeoutPromise/tim
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://json-schema.org/draft-07/schema#
Source: firefox.exe, 0000000D.00000003.1485336487.0000026EFF053000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://json-schema.org/draft-07/schema#-
Source: firefox.exe, 0000000D.00000003.1485336487.0000026EFF053000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org
Source: firefox.exe, 0000000D.00000003.1713723357.0000026EFF0B6000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1711448146.0000026EFF0B7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1484521088.0000026EFF0B7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1701460875.0000026EFF0B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1723392257.0000026EFF0B7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/aboutWelcomeBehavior
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/appId
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/appName
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/autoFillAdaptiveHistoryMinCharsThreshold
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/autoFillAdaptiveHistoryMinCharsThresholdhttp://mozilla.org/#/propert
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/autoFillAdaptiveHistoryUseCountThreshold
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/autoFillAdaptiveHistoryUseCountThresholdhttp://mozilla.org/#/propert
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/bestMatchBlockingEnabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/bestMatchBlockingEnabledhttps://bugzilla.mozilla.org/show_bug.cgi?id
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/bestMatchEnabledhttp://mozilla.org/#/properties/merinoEnabled
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/boolean
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/0/items
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/0/items/properties/feature
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/0/items/properties/feature/properties/featureId
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/0/items/properties/feature/properties/value
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/0/items/properties/feature/properties/value/additiona
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/0/items/properties/ratio
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/0/items/properties/slug
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/0http://mozilla.org/#/properties/branches/anyOf/1http
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/feature
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/feature/properties/enabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/feature/properties/featureId
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/feature/properties/value
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/feature/properties/value/additiona
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/features
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/features/items/properties/featureI
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/features/items/properties/value
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/features/items/properties/value/ad
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/features/itemshttp://mozilla.org/#
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/ratio
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/1/items/properties/slug
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/2/items
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/2/items/properties/features
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/2/items/properties/features/items/properties/featureI
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/2/items/properties/features/items/properties/value
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/2/items/properties/features/items/properties/value/ad
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/2/items/properties/ratio
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/2/items/properties/slug
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/branches/anyOf/2privateContextWithoutExplicitConsent
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/bucketConfig
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/bucketConfig/properties/count
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/bucketConfig/properties/namespace
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/bucketConfig/properties/randomizationUnit
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/bucketConfig/properties/start
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/bucketConfig/properties/total
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/cbhStudyRow
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/cbhStudyUs
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/channel
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/csvImport
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/disableGreaseOnFallback
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/dnsMaxAnyPriorityThreads
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/dnsMaxPriorityThreads
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/ehPreconnectEnabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/ehPreloadEnabledhttps://json-schema.org/draft/2019-09/schema
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/endDate
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/enrollmentEndDate
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/experimentType
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/exposureResults
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/extraParams
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/featureIds/itemsgetAPI/register/tabsApi.tabs.onZoomChange
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/featureValidationOptOut
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/forceWaitHttpsRRON_COLLECTION_CHANGED_NOTIFICATION
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/greasePaddingSize
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/h3Enabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/h3GreaseEnabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/id
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/insecureFallback
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/isEnrollmentPaused
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/isRollout
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/louserzations
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/louserzations/anyOf/0
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/louserzations/anyOf/0/additionalProperties
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/louserzations/anyOf/0/additionalProperties/additionalProperties
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/louserzations/anyOf/1
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/mdnFeatureGate
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/merinoEndpointURL
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/merinoEndpointURLhttps://bugzilla.mozilla.org/show_bug.cgi?id=167844
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/merinoProviders
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/merinoTimeoutMs
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/migrateExtensions
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/networkPredictorchrome://global/content/elements/editor.js
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/originsDaysCutOff
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/outcomes
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/outcomes/items
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/outcomes/items/properties/priority
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/outcomes/items/properties/slug
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/pagesAlternativeEnable
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/pagesHalfLifeDays
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/pagesMediumWeight
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/pagesNumSampledVisits
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/preconnect
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/proposedDurationhttp://mozilla.org/#/properties/featureIds
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/proposedEnrollment
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestAllowPositionInSuggestions
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestDataCollectionEnabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestImpressionCapsNonSponsoredEnabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestImpressionCapsSponsoredEnabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestImpressionCapsSponsoredEnabledbrowser.newtabpage.activit
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestOnboardingDialogVariation
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestRemoteSettingsDataType
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestRemoteSettingsEnabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestShouldShowOnboardingDialog
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestShowOnboardingDialogAfterNRestarts
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/quickSuggestShowOnboardingDialogAfterNRestartshttp://mozilla.org/#/p
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/recordNavigationalSuggestionTelemetry
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/richSuggestionsFeatureGate
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/schemaVersion
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/serpEventTelemetryEnabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/showExposureResults
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/showExposureResultsdevices:0x2a42
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/showImportAll
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/showPreferencesEntrypoint
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/slug
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/startDate
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/targeting
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/tlsEnabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/tlsGreaseProb
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/trendingEnabled
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/trendingMaxResultsNoSearchMode
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/trendingRequireSearchMode
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/useNewWizard
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/userFacingDescription
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/#/properties/userFacingName
Source: firefox.exe, 0000000D.00000002.2013177027.0000026EF0103000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1995218626.0000026EEF53F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1381006099.0000026EF9EE2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2002881245.0000026EEF737000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1805304495.0000026EF53D9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1468203222.0000026EF5456000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1448883441.0000026EF3A19000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1583338326.0000026EF53D7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1447376924.0000026EF3A8B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2143639306.0000026EF4963000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1751560573.0000026EF0574000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1653588666.0000026EF41A4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1439158299.0000026EF2EC3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1737470482.0000026EF9F7A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1335991077.0000026EF20E6000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1745606809.0000026EF253F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1588544437.0000026EF4961000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA0B2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1731781069.0000026EF2939000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1469617232.0000026EF53DA000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mozilla.org/MPL/2.0/.
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://poczta.interia.pl/mh/?mailto=%sw
Source: firefox.exe, 0000000D.00000003.1707064650.0000026EFA0C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1592420869.0000026EFA0C4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2108643621.0000026EF3F2D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://r3.i.lencr.org/0
Source: firefox.exe, 0000000D.00000003.1707064650.0000026EFA0C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1592420869.0000026EFA0C4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA0C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2108643621.0000026EF3F2D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://r3.o.lencr.org0
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://win.mail.ru/cgi-bin/sentmsg?mailto=%sy
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.inbox.lv/rfc2368/?value=%su
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/2005/app-update
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/2005/app-updateBITS_IDLE_NO_PROGRESS_TIMEOUT_SECSPREF_APP_UPDATE_SOCKET_RETRY
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2068695454.0000026EF3003000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/2006/browser/search/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/2006/browser/search/http://a9.com/-/spec/opensearchdescription/1.1/_onLoad:
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1904719973.0000026EF427F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719018157.0000026EF31F4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1734860528.0000026EF28F3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2053015192.0000026EF28FA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1911893455.0000026EF2567000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1720238362.0000026EF3177000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA0C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1883012070.0000026EEFBF4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1716575206.0000026EF373E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2058012003.0000026EF2DBA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1793766145.0000026EF223E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1644379730.0000026EF427F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2053015192.0000026EF28CB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1589092022.0000026EF4507000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719303726.0000026EF31AF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1604915328.0000026EF427F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDBA9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1734860528.0000026EF28B4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2041668855.0000026EF2272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulMAX_HANDLER_BEHAVIOR_CHANGED_CALLS_PER_
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulchrome://global/content/elements/moz-me
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulchrome://passwordmgr/locale/passwordmgr
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulhttp://www.mozilla.org/keymaster/gateke
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xuloncommand=closebuttoncommand
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulresource:///modules/UrlbarProviderHisto
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulresource:///modules/UrlbarProviderInter
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulresource:///modules/UrlbarProviderQuick
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulresource://autofill/FormAutofillStorage
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulresource://gre/modules/PrivateBrowsingU
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xulsrc=image
Source: firefox.exe, 0000000D.00000003.1592420869.0000026EFA0C4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA0C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2108643621.0000026EF3F2D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2055010796.0000026EF2933000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1469617232.0000026EF53DE000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://x1.c.lencr.org/0
Source: firefox.exe, 0000000D.00000003.1592420869.0000026EFA0C4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA0C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2108643621.0000026EF3F2D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2055010796.0000026EF2933000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1469617232.0000026EF53DE000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://x1.i.lencr.org/0
Source: firefox.exe, 0000000D.00000003.1462639263.0000026EFDB79000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://MD8.mozilla.org/1/m
Source: firefox.exe, 0000000D.00000003.1491059886.0000026EFBAC3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1328781884.0000026EEF716000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ac.duckduckgo.com/ac/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://account.bellmedia.ca
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://account.bellmedia.caget
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://accounts.firefox.com
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: https://accounts.firefox.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://accounts.firefox.com/frequencyCapSpocs/result
Source: firefox.exe, 0000000D.00000003.1465583729.0000026EFBAD1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://accounts.firefox.comK
Source: firefox.exe, 0000000D.00000002.2008846809.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1913295191.0000026EEFBE9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1883012070.0000026EEFBE9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1884841588.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2009305625.0000026EEFBE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org
Source: firefox.exe, 0000000D.00000002.2077853279.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719018157.0000026EF31F4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1729714585.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2070471619.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1909096087.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/en-US/firefox/collections/4757633/25c2b44583534b3fa8fea977c419cd/?page=1&
Source: firefox.exe, 0000000D.00000003.1701334170.0000026EFF407000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/firefox/addon/enhancer-for-youtube/
Source: firefox.exe, 0000000D.00000003.1701334170.0000026EFF407000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/firefox/addon/facebook-container/
Source: firefox.exe, 0000000D.00000003.1701334170.0000026EFF407000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/firefox/addon/reddit-enhancement-suite/
Source: firefox.exe, 0000000D.00000003.1701334170.0000026EFF407000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/firefox/addon/to-google-translate/
Source: firefox.exe, 0000000D.00000003.1701334170.0000026EFF407000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/firefox/addon/wikipedia-context-menu-search/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/firefox/downloads/file/4040738/cookie_autodelete-3.8.2.xpi
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/firefox/downloads/file/4128570/languagetool-7.1.13.xpi
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/firefox/downloads/file/4129240/privacy_badger17-2023.6.23.xpi
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/firefox/downloads/file/4134489/enhancer_for_youtube-2.0.119.1.xpi
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/firefox/downloads/file/4141092/facebook_container-2.3.11.xpi
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/user-media/addon_icons/506/506646-64.png?modified=mcrushed
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/user-media/addon_icons/700/700308-64.png?modified=4bc8e79f
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/user-media/addon_icons/708/708770-64.png?modified=4f881970
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/user-media/addon_icons/784/784287-64.png?modified=mcrushed
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.org/user-media/addon_icons/954/954390-64.png?modified=97d4c956
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://addons.mozilla.orgaccount-connection-connecteddevice-connected-notificationaccount-connectio
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ads-us.rd.linksynergy.com/as.php
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1731781069.0000026EF29E5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1556835420.0000026F0218C000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B08000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B0F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1731781069.0000026EF29B2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1460587802.0000026F0218B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1834723822.0000026EF2D56000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ads.stickyadstv.com/firefox-etp
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1701157885.0000026EFF412000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://app.adjust.com/167k4ih?campaign=firefox-desktop&adgroup=pb&creative=focus-omc172&redirect=ht
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1701157885.0000026EFF412000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://app.adjust.com/a8bxj8j?campaign=firefox-desktop&adgroup=pb&creative=focus-omc172&redirect=ht
Source: firefox.exe, 0000000D.00000002.2105130178.0000026EF3E03000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1711933271.0000026EFDBC8000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1925115156.0000026EE200C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aus5.mozilla.org
Source: firefox.exe, 0000000D.00000002.1962455087.0000026EEE16E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF570000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1711933271.0000026EFDBC8000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1997030933.0000026EEF570000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aus5.mozilla.org/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: https://aus5.mozilla.org/update/3/GMP/%VERSION%/%BUILD_ID%/%BUILD_TARGET%/%LOCALE%/%CHANNEL%/%OS_VER
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF570000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1997030933.0000026EEF57E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aus5.mozilla.org/update/3/GMP/118.0.1/20230927232528/WINNT_x86_64-msvc-x64/en-US/release/Win
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1997030933.0000026EEF59F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF58E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aus5.mozilla.org/update/3/SystemAddons/118.0.1/20230927232528/WINNT_x86_64-msvc-x64/en-US/re
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aus5.mozilla.org/update/6/%PRODUCT%/%VERSION%/%BUILD_ID%/%BUILD_TARGET%/%LOCALE%/%CHANNEL%/%
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1384988670.0000026EFA0D7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1597271236.0000026EF4905000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1707064650.0000026EFA0D6000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1744385960.0000026EF2563000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2142099934.0000026EF4903000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1925115156.0000026EE206B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF570000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1911893455.0000026EF2567000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1802094254.0000026EFA0D3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2045177705.0000026EF2568000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1997030933.0000026EEF59F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1831079224.0000026EF2567000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1491265158.0000026EFA0D7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF58E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1592420869.0000026EFA0D3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA0D7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aus5.mozilla.org/update/6/Firefox/118.0.1/20230927232528/WINNT_x86_64-msvc-x64/en-US/release
Source: firefox.exe, 0000000D.00000002.1941972565.0000026EED8B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624E9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1789185978.0000022A5F303000.00000004.00000800.00020000.00000000.sdmp, prefs-1.js.13.drString found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&ci=1696581201119.12791&key=1696581201400600
Source: firefox.exe, 0000000D.00000002.1941972565.0000026EED8B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624E9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1789185978.0000022A5F303000.00000004.00000800.00020000.00000000.sdmp, prefs-1.js.13.drString found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&ci=1696581201119.12791&key=1696581201400600000.1&cta
Source: firefox.exe, 0000000D.00000003.1559188431.0000026F00CFA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1656421414.0000026EF3CDB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1559188431.0000026F00CB2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mo
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1170143
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1545118818.0000026EF9FD7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1189266
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1545118818.0000026EF9FE0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1193802
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1207993
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1266220
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1545118818.0000026EF9FD7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1283601
Source: firefox.exe, 0000000D.00000003.1465583729.0000026EFBAE3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1539075
Source: firefox.exe, 0000000D.00000003.1465583729.0000026EFBAE3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1584464
Source: firefox.exe, 0000000D.00000003.1465583729.0000026EFBAE3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1607439
Source: firefox.exe, 0000000D.00000003.1465583729.0000026EFBAE3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1616739
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1678448
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1678942
Source: firefox.exe, 0000000D.00000003.1447376924.0000026EF3A8B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1694699#c21
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=1817617
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=792480
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=793869
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=806991
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=809550
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=815437
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=840161
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=951422
Source: firefox.exe, 0000000D.00000003.1328432644.0000026EEF500000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1328781884.0000026EEF716000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://completion.amazon.com/search/complete?q=
Source: firefox.exe, 0000000D.00000003.1608522889.0000026EFDB7F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB7F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1711999313.0000026EFDB7F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://content-signature-2.cdn.mozilla.net/
Source: firefox.exe, 0000000D.00000003.1707064650.0000026EFA0DA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1639494732.0000026EFA049000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA049000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1802094254.0000026EFA0D3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1491265158.0000026EFA0D7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1592420869.0000026EFA0D3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA0D7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://content-signature-2.cdn.mozilla.net/chains/remote-settings.content-signature.mozilla.org-202
Source: firefox.exe, 0000000D.00000002.1941972565.0000026EED8B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624E9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1789185978.0000022A5F303000.00000004.00000800.00020000.00000000.sdmp, prefs-1.js.13.drString found in binary or memory: https://contile-images.services.mozilla.com/T23eBL4EHswiSaF6kya2gYsRHvdfADK-NYjs1mVRNGE.3351.jpg
Source: firefox.exe, 0000000D.00000002.1941972565.0000026EED8B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624E9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1789185978.0000022A5F303000.00000004.00000800.00020000.00000000.sdmp, prefs-1.js.13.drString found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
Source: firefox.exe, 0000000D.00000003.1743424356.0000026EF25F7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1593546450.0000026EF5456000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1515707957.0000026EF5457000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1383839910.0000026EFBDBF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1568206848.0000026EFC4BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1578836623.0000026EFC4C0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609561126.0000026EF5457000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1509150928.0000026EFC4C0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1831079224.0000026EF25F7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1487864021.0000026EFC4BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1911485906.0000026EF25F7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1383057893.0000026EFC4BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1777271390.0000026EFC4BE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: https://contile.services.mozilla.com/v1/tiles
Source: firefox.exe, 0000000D.00000002.1925115156.0000026EE2012000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1925115156.0000026EE2035000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://crash-reports.mozilla.com/submit?id=
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1549688918.0000026EF4691000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1686405066.0000026EFA029000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://datastudio.google.com/embed/reporting/
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://developer.mozilla.org/docs/Mozilla/Add-ons/WebExtensions/API/tabs/captureTabMozRequestFullSc
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://developer.mozilla.org/docs/Web/API/Element/releasePointerCapture
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://developer.mozilla.org/docs/Web/API/Element/setPointerCaptureElementReleaseCaptureWarning
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://developer.mozilla.org/docs/Web/API/Push_API/Using_the_Push_API#EncryptionPreventDefaultFromP
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://developer.mozilla.org/en-US/Add-ons/WebExtensions/manifest.json/commands#Key_combinations
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://developer.mozilla.org/en-US/Add-ons/WebExtensions/manifest.json/commands#Key_combinationschr
Source: firefox.exe, 0000000D.00000003.1647746960.0000026EFC459000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://developer.mozilla.org/en-US/docs/Glossary/speculative_parsingDocumentWriteIgnored
Source: firefox.exe, 0000000D.00000003.1491059886.0000026EFBAC3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1902832259.0000026F0216F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1460587802.0000026F02169000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1726462103.0000026F02171000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB68000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1328781884.0000026EEF716000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1437544639.0000026F02221000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/
Source: firefox.exe, 0000000D.00000003.1375789032.0000026EF9EDA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2004924979.0000026EEF870000.00000002.08000000.00040000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/y
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1330178677.0000026EF0133000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1955690126.0000026EEDE85000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2013177027.0000026EF013B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://e.mail.ru/cgi-bin/sentmsg?mailto=%s
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://e.mail.ru/cgi-bin/sentmsg?mailto=%sz
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://e.mail.ru/cgi-bin/sentmsg?mailto=%szw
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1330178677.0000026EF0133000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2013177027.0000026EF013B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://email.seznam.cz/newMessageScreen?mailto=%s
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://extensionworkshop.com/documentation/publish/self-distribution/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD19000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD62412000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F213000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox-api-proxy.cdn.mozilla.net/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1396372154.0000026EF9FD2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1395337274.0000026EFBEFA000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox-settings-attachments.cdn.mozilla.net/main-workspace/ms-images/673d2808-e5d8-41b9-957
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1392146505.0000026EF9FCB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1396372154.0000026EF9FD2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1395916732.0000026EF9FE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox-settings-attachments.cdn.mozilla.net/main-workspace/ms-images/706c7a85-cf23-442e-8a9
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox-settings-attachments.cdn.mozilla.net/main-workspace/ms-images/74f06853-c80d-4afc-9b2
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1395337274.0000026EFBEFA000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox-settings-attachments.cdn.mozilla.net/main-workspace/ms-images/d8e772fe-4909-4f05-9f9
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox-settings-attachments.cdn.mozilla.net/main-workspace/ms-images/f0f51715-7f5e-48de-839
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox-source-docs.mozilla.org/remote/Security.html
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox.settings.services.allizom.org/v1/buckets/main-preview/collections/search-config/reco
Source: firefox.exe, 0000000D.00000003.1726462103.0000026F02183000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1902832259.0000026F02183000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1685296984.0000026EFBADB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1573375506.0000026F021EC000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1706619377.0000026EFBADB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1564864968.0000026F021ED000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1638740956.0000026EFBAD9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1556835420.0000026F021E9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox.settings.services.mozilla.com
Source: firefox.exe, 0000000D.00000003.1902832259.0000026F021A2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1685296984.0000026EFBAA2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1726462103.0000026F021A2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox.settings.services.mozilla.com/
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox.settings.services.mozilla.com/v1/buckets/main-preview/collections/search-config/reco
Source: firefox.exe, 0000000D.00000003.1700667969.0000026EFF429000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1686263553.0000026EFBA97000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/ms-language-packs/records/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719303726.0000026EF31AF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2076145405.0000026EF31AF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1766492835.0000026EF31B1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?_expe
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF570000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1813221272.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2107317447.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1997030933.0000026EEF59F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF58E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1760538377.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1997030933.0000026EEF57E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?colle
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://firefox.settings.services.mozilla.com/v1_scheduleStartupIdleTasks/task/observer/
Source: firefox.exe, 0000000D.00000002.2008846809.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1884841588.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://fpn.firefox.com
Source: firefox.exe, 0000000D.00000002.2077853279.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719018157.0000026EF31F4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1729714585.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719303726.0000026EF31BE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2070471619.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1909096087.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://fpn.firefox.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD19000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD62412000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F213000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.cdn.mozilla.net/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1509784326.0000026EFC2B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1925115156.0000026EE2035000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD19000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F2C4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.cdn.mozilla.net/v3/firefox/global-recs?version=3&consumer_key=$apiKey&locale_lang=
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1925115156.0000026EE2035000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD19000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F2C4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.cdn.mozilla.net/v3/firefox/trending-topics?version=2&consumer_key=$apiKey&locale_l
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466230863.0000026EFBA93000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD19000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD6242F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F230000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.cdn.mozilla.net/v3/newtab/layout?version=1&consumer_key=$apiKey&layout_variant=bas
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore/career?utm_source=pocket-newtab
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore/entertainment?utm_source=pocket-newtab
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore/food?utm_source=pocket-newtab
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore/health?utm_source=pocket-newtab
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore/science?utm_source=pocket-newtab
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore/self-improvement?utm_source=pocket-newtab
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore/technology?utm_source=pocket-newtab
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1925115156.0000026EE2035000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F2C4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore/trending?src=fx_new_tab
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore/trending?src=fx_new_tabchrome://global/content/elements/notificationbo
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore/trending?src=fx_new_tabchrome://global/content/elements/toolbarbutton.
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/explore?utm_source=pocket-newtab
Source: firefox.exe, 0000000D.00000003.1509784326.0000026EFC297000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/firefox/new_tab_learn_more
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/firefox/new_tab_learn_morediscoverystream.endpointSpocsClear
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/firefox/new_tab_learn_morediscoverystream.endpointSpocsCleardiscoverystream.re
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/firefox/new_tab_learn_morehome-prefs-recommended-by-option-recent-saves
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1925115156.0000026EE2035000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F2C4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/recommendations
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/recommendationsConfiguration
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/recommendationsfinished
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://getpocket.com/v3/newtab/layout?version=1&consumer_key=$apiKey&layout_variant=basic
Source: firefox.exe, 0000000D.00000003.1328432644.0000026EEF500000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1328781884.0000026EEF716000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mozilla-services/screenshots
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mozilla-services/screenshotshandleDiscoveryStreamImpressionStats/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mozilla/webcompat-reporter
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mozilla/webcompat-reporterUnknown
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1565789166.0000026EFF532000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/uuidjs/uuid#getrandomvalues-not-supported
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/w3c/csswg-drafts/blob/master/css-grid-2/MASONRY-EXPLAINER.md
Source: firefox.exe, 0000000D.00000003.1465583729.0000026EFBAE3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/w3c/csswg-drafts/issues/4650
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/zertosh/loose-envify)
Source: firefox.exe, 0000000D.00000003.1465583729.0000026EFBAE3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://gpuweb.github.io/gpuweb/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://gpuweb.github.io/gpuweb/set-default-browser-user-choice
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://gpuweb.github.io/gpuweb/set-default-browser-user-choicesetDefaultBrowserUserChoiceexperiment
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1925115156.0000026EE2012000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://hg.mozilla.org/releases/mozilla-release/rev/68e4c357d26c5a1f075a1ec0c696d4fe684ed881
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://hg.mozilla.org/releases/mozilla-release/rev/68e4c357d26c5a1f075a1ec0c696d4fe684ed881jar:file
Source: firefox.exe, 0000000D.00000003.1598688528.0000026EF42CA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1690688376.0000026EF42CD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1825372929.0000026EF3E38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2124000866.0000026EF42CC000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1549688918.0000026EF4691000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2105644401.0000026EF3E38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1643214417.0000026EF42CD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1631638270.0000026EF3E32000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ib.absa.co.za/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://identity.mozilla.com/apps/oldsync
Source: firefox.exe, 0000000D.00000003.1567673443.0000026EFF453000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://identity.mozilla.com/apps/oldsyncS
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B03000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1564197580.0000026F023BD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://identity.mozilla.com/apps/relay
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://identity.mozilla.com/cmd/
Source: firefox.exe, 0000000D.00000003.1567673443.0000026EFF453000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://identity.mozilla.com/cmd/H
Source: firefox.exe, 0000000D.00000003.1567673443.0000026EFF453000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://identity.mozilla.com/cmd/HCX
Source: firefox.exe, 0000000D.00000003.1567673443.0000026EFF453000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://identity.mozilla.com/ids/ecosystem_telemetryU
Source: firefox.exe, 0000000D.00000003.1567673443.0000026EFF453000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://identity.mozilla.com/ids/ecosystem_telemetryUFj
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img-getpocket.cdn.mozilla.net/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img-getpocket.cdn.mozilla.net/resource://gre/modules/Timer.sys.mjshttps://spocs.getpocket.co
Source: firefox.exe, 0000000D.00000002.1941972565.0000026EED8B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624E9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1789185978.0000022A5F303000.00000004.00000800.00020000.00000000.sdmp, prefs-1.js.13.drString found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4CLXfQbX4pbW4QbWfpbW7ReNxR3UIG8zInwYIFIVs9eYi
Source: firefox.exe, 0000000D.00000003.1556027653.0000026F02480000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1683235945.0000026F02482000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1997030933.0000026EEF590000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BDD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1634912780.0000026F02481000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1941972565.0000026EED8D7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF58E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1581592389.0000026EF9D2A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1688773230.0000026EF9D39000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624C0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F2F4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit
Source: firefox.exe, 0000000D.00000003.1700667969.0000026EFF429000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1568206848.0000026EFC4BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1947214670.0000026EED903000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/firefox-desktop/events/1/9879cb77-be6a-412c-b6d6-1bda4
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/firefox-desktop/metrics/1/12d4e7e1-c632-436b-b028-81f2
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/messaging-system/undesired-events/1/4e7c69b3-1d09-47a5
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1813221272.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2107317447.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1760538377.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/messaging-system/undesired-events/1/67234304-2e4b-4f49
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2053015192.0000026EF28E4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1829530777.0000026EF28E6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/telemetry/1864eebe-a97d-4196-ba9e-40ba8339789c/health/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, pingsender.exe, 00000012.00000002.1803728648.00000272A4392000.00000004.00000020.00020000.00000000.sdmp, pingsender.exe, 00000012.00000002.1803728648.00000272A43D8000.00000004.00000020.00020000.00000000.sdmp, pingsender.exe, 00000012.00000002.1803728648.00000272A4380000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/telemetry/4309612b-ce46-455b-bbea-0678ea7a053f/event/F
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2058012003.0000026EF2DBA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1834723822.0000026EF2DB6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/telemetry/4543e2b6-0dac-4484-972e-233c4ffdcfcd/first-s
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2058012003.0000026EF2DBA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1834723822.0000026EF2DB6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/telemetry/59f06e22-78e3-4143-9d34-bd19d6977013/main/Fi
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1802094254.0000026EFA0D3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/telemetry/5d988596-6564-4348-8936-85489365ee69/health/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/telemetry/639d6aff-3521-475f-a165-426024f2d9f0/health/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1792773249.0000026EF2506000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2044527074.0000026EF2506000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/telemetry/717ed3b2-ea8b-46bf-926c-0346b661d09a/event/F
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2058012003.0000026EF2DBA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1834723822.0000026EF2DB6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/telemetry/8c7e12a2-deef-4b63-9655-b8092c733a4d/event/F
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2058012003.0000026EF2DBA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1834723822.0000026EF2DB6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/telemetry/b0fc05c3-ead2-408e-9808-728375d77a75/new-pro
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1834723822.0000026EF2D29000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit/telemetry/c52da37e-6215-4698-a8c6-7dbc7928eb26/main/Fi
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submit9c4f630b-d3dc-4236-9fe2-a1415309e4e4b28caf77-5f17-4748-
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submitDISCOVERY_STREAM_PERSONALIZATION_INITNumber
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submitStructured
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://incoming.telemetry.mozilla.org/submithttps://spocs.getpocket.com/userresource://activity-str
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://json-schema.org/draft/2019-09/schema
Source: firefox.exe, 0000000D.00000003.1485336487.0000026EFF053000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://json-schema.org/draft/2019-09/schema.
Source: firefox.exe, 0000000D.00000003.1485336487.0000026EFF053000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://json-schema.org/draft/2019-09/schema./
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://json-schema.org/draft/2019-09/schemaInstance
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://json-schema.org/draft/2020-12/schema
Source: firefox.exe, 0000000D.00000003.1485336487.0000026EFF053000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://json-schema.org/draft/2020-12/schema/
Source: firefox.exe, 0000000D.00000003.1485336487.0000026EFF053000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://json-schema.org/draft/2020-12/schema/=
Source: firefox.exe, 0000000D.00000002.2043438455.0000026EF22FE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1793287133.0000026EF22FC000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://location.services.mozilla.com
Source: firefox.exe, 0000000D.00000002.2046460693.0000026EF25C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1743424356.0000026EF25C5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1911485906.0000026EF25C5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://location.services.mozilla.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1743424356.0000026EF25C5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1745214336.0000026EF2551000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1793766145.0000026EF223E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719303726.0000026EF31AF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1714220722.0000026EF413F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1813221272.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1694437422.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1831079224.0000026EF25C5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2107317447.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1694144605.0000026EF413F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2041668855.0000026EF22C6000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1760538377.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1911485906.0000026EF25C5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1766492835.0000026EF31B1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://location.services.mozilla.com/v1/country?key=7e40f68c-7938-4c5d-9f95-e61647c213eb
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1469617232.0000026EF53F9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://login.live.com
Source: firefox.exe, 0000000D.00000003.1472707433.0000026EF49B6000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1465583729.0000026EFBAE3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://login.microsoftonline.com
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://login.microsoftonline.compermission-popup-permission-reload-hintpermission-popup-mainView-pa
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1549688918.0000026EF4691000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://lookerstudio.google.com/embed/reporting/
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1330178677.0000026EF0133000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2013177027.0000026EF013B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mail.google.com/mail/?extsrc=mailto&url=%s
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1330178677.0000026EF0133000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1955690126.0000026EEDE85000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2013177027.0000026EF013B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mail.inbox.lv/compose?to=%s
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mail.inbox.lv/compose?to=%sv
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1330178677.0000026EF0133000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1955690126.0000026EEDE85000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2013177027.0000026EF013B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mail.yahoo.co.jp/compose/?To=%s
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mail.yahoo.co.jp/compose/?To=%st
Source: firefox.exe, 0000000D.00000002.1925115156.0000026EE20D8000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD62486000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F28F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://merino.services.mozilla.com/api/v1/suggest
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://merino.services.mozilla.com/api/v1/suggestresource://activity-stream/common/Actions.sys.mjsr
Source: firefox.exe, 0000000D.00000002.2008846809.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1962455087.0000026EEE184000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1884841588.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://monitor.firefox.com
Source: firefox.exe, 0000000D.00000002.2077853279.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719018157.0000026EF31F4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1729714585.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2070471619.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1909096087.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://monitor.firefox.com/
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mozilla-hub.atlassian.net/browse/SDK-405
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mozilla-hub.atlassian.net/browse/SDK-405moz-extension://06836808-3da5-4b66-93b7-b66b1a840a96
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mzl.la/3NS9KJd
Source: firefox.exe, 0000000D.00000002.2126857420.0000026EF45FD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1690547063.0000026EF45FE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1783743388.0000026EF45FE000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://normandy.cdn.mozilla.net
Source: firefox.exe, 0000000D.00000003.1902832259.0000026F021A2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1813221272.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1703397260.0000026EFDBFE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1694437422.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BB8000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1726462103.0000026F021A2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1760538377.0000026EF3E8A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://normandy.cdn.mozilla.net/api/v1/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ok.ru/
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1330178677.0000026EF0133000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2013177027.0000026EF013B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://outlook.live.com/default.aspx?rru=compose&to=%s
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1330178677.0000026EF0133000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1955690126.0000026EEDE85000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2013177027.0000026EF013B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://poczta.interia.pl/mh/?mailto=%s
Source: firefox.exe, 0000000D.00000003.1883012070.0000026EEFB95000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://poczta.interia.pl/mh/?mailto=%sx
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://probeinfo.telemetry.mozilla.org/glean/repositories.
Source: firefox.exe, 0000000D.00000002.2008059760.0000026EEFB5E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1885154494.0000026EEFB5E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://profiler.firefox.com/
Source: firefox.exe, 0000000D.00000002.1991317775.0000026EEF418000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1792773249.0000026EF2506000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2044527074.0000026EF2506000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1842785098.0000026EF2508000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://push.services.mozilla.com
Source: firefox.exe, 0000000D.00000002.2078244023.0000026EF3727000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1792773249.0000026EF2506000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1842785098.0000026EF250B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1718493534.0000026EF371D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2044527074.0000026EF2506000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://push.services.mozilla.com/
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BB8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://redirector.gvt1.com/edgedl/widevine-cdm/4.10.2557.0-linux-x64.zip
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BB8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://redirector.gvt1.com/edgedl/widevine-cdm/4.10.2557.0-mac-arm64.zip
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BB8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://redirector.gvt1.com/edgedl/widevine-cdm/4.10.2557.0-mac-x64.zip
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BB8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://redirector.gvt1.com/edgedl/widevine-cdm/4.10.2557.0-win-arm64.zip
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1729714585.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2070471619.0000026EF3079000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BB8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://redirector.gvt1.com/edgedl/widevine-cdm/4.10.2557.0-win-x64.zip
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BB8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://redirector.gvt1.com/edgedl/widevine-cdm/4.10.2557.0-win-x86.zip
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: https://relay.firefox.com/api/v1/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://safebrowsing.googleapis.com/v4/fullHashes:find?$ct=application/x-protobuf&key=AIzaSyC7jsptDS
Source: firefox.exe, 0000000D.00000003.1466652134.0000026EFA054000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1639494732.0000026EFA054000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://safebrowsing.googleapis.com/v4/threatListUpdates:fetch?$ct=application/x-protobuf&key=AIzaSy
Source: firefox.exe, 0000000D.00000002.2008846809.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1962455087.0000026EEE184000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1884841588.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://screenshots.firefox.com
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1997030933.0000026EEF58B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719018157.0000026EF31F4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1729714585.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719303726.0000026EF31BE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1328781884.0000026EEF716000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2070471619.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1909096087.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF58B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1995218626.0000026EEF551000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://screenshots.firefox.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://screenshots.firefox.com/AS_ROUTER_TELEMETRY_USER_EVENT
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://screenshots.firefox.comcreateContentPrincipalFromOriginremoveTabsProgressListenermaybeShowOn
Source: firefox.exe, 0000000D.00000002.1962455087.0000026EEE13A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://services.addons.mozilla.org
Source: firefox.exe, 0000000D.00000003.1700667969.0000026EFF429000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://services.addons.mozilla.org/api/v4/addons/addon
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: https://services.addons.mozilla.org/api/v4/addons/search/?guid=%IDS%&lang=%LOCALE%
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE262000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1718493534.0000026EF3733000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1915620305.0000026EEF570000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2078244023.0000026EF3734000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B13000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://services.addons.mozilla.org/api/v4/addons/search/?guid=default-theme%40mozilla.org%2Caddons-
Source: firefox.exe, 0000000D.00000003.1508436759.0000026EFDBD4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1577915762.0000026EFDBD4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1903926601.0000026EFDBD0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1625103497.0000026EFDBD3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1636459272.0000026EFDBD4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDBCF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://shavar.services.mozilla.com
Source: firefox.exe, 0000000D.00000002.2045177705.0000026EF2551000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1745214336.0000026EF2551000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1911893455.0000026EF2551000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1831079224.0000026EF2549000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://shavar.services.mozilla.com/
Source: firefox.exe, 0000000D.00000002.2074575124.0000026EF3182000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1902832259.0000026F02159000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1720238362.0000026EF3177000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1574007695.0000026F02155000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1741380216.0000026EF3190000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1484372028.0000026F0215B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1556835420.0000026F02156000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://shavar.services.mozilla.com/downloads?client=navclient-auto-ffox&appver=118.0&pver=2.2
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://shavar.services.mozilla.com/downloads?client=navclient-auto-ffox&appver=118.0&pver=2.2moz-ex
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://shavar.services.mozilla.com/gethash?client=navclient-auto-ffox&appver=118.0&pver=2.2
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1834723822.0000026EF2D45000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://smartblock.firefox.etp/facebook.svg
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://smartblock.firefox.etp/facebook.svgresource://gre/modules/ExtensionParent.sys.mjswebcompat
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1834723822.0000026EF2D45000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://smartblock.firefox.etp/play.svg
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://smartblock.firefox.etp/play.svgwebcompat
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://smartblock.firefox.etp/play.svgwebcompat-reporter
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: https://snippets.cdn.mozilla.net/%STARTPAGE_VERSION%/%NAME%/%VERSION%/%APPBUILDID%/%BUILD_TARGET%/%L
Source: firefox.exe, 0000000D.00000003.1466652134.0000026EFA068000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1798884255.0000026EFBA62000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1384988670.0000026EFA068000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://spocs.getpocket.com
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1568206848.0000026EFC4BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1578836623.0000026EFC4C0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1509150928.0000026EFC4C0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1487864021.0000026EFC4BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1383057893.0000026EFC4BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1777271390.0000026EFC4BE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1667535452.0000026EF37F1000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD19000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD62412000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F213000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://spocs.getpocket.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://spocs.getpocket.com/maybeOfferTranslations
Source: firefox.exe, 0000000D.00000003.1466652134.0000026EFA068000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1568206848.0000026EFC4BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1578836623.0000026EFC4C0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1509150928.0000026EFC4C0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1716575206.0000026EF373E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1487864021.0000026EFC4BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1383057893.0000026EFC4BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1469617232.0000026EF53F9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1578836623.0000026EFC4E7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1568206848.0000026EFC4E7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1777271390.0000026EFC4BE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1667535452.0000026EF37F1000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1487864021.0000026EFC4E7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1384988670.0000026EFA068000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://spocs.getpocket.com/spocs
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://spocs.getpocket.com/spocs:
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1798884255.0000026EFBA62000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD19000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624C0000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F2F4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://spocs.getpocket.com/user
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://spocs.getpocket.com/usergetValue/preffedBlockRegions
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1731781069.0000026EF29E5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1556835420.0000026F0218C000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B0F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1460587802.0000026F0218B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://static.adsafeprotected.com/firefox-etp-js
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://static.adsafeprotected.com/firefox-etp-jshttps://bugzilla.mozilla.org/show_bug.cgi?id=126622
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://static.adsafeprotected.com/firefox-etp-jsresource://normandy/lib/ClientEnvironment.sys.mjs
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1731781069.0000026EF29E5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1556835420.0000026F0218C000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B08000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B0F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1731781069.0000026EF29B2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1460587802.0000026F0218B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1834723822.0000026EF2D56000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://static.adsafeprotected.com/firefox-etp-pixel
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://static.adsafeprotected.com/firefox-etp-pixelbrowser.safebrowsing.features.fingerprinting.ann
Source: firefox.exe, 0000000D.00000002.2008846809.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1962455087.0000026EEE184000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1564197580.0000026F023BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1884841588.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1474320511.0000026EF38ED000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1658874341.0000026EF38ED000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org
Source: firefox.exe, 0000000D.00000002.2077853279.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719018157.0000026EF31F4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1729714585.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719303726.0000026EF31BE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2070471619.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1909096087.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/1/firefox/%VERSION%/%OS%/%LOCALE%/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1556835420.0000026F02172000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1385549274.0000026EF42D4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1581122742.0000026EF9DCB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1770326141.0000026EF42F3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1902832259.0000026F02178000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1472935374.0000026EF42F2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1690688376.0000026EF42F3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2124000866.0000026EF42F3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1598688528.0000026EF42ED000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/1/firefox/118.0.1/WINNT/en-US/
Source: firefox.exe, 0000000D.00000003.1868473968.0000026EFC07D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1687878444.0000026EFC07D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1638161569.0000026EFC076000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1579573008.0000026EFC01D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/1/firefox/118.0.1/WINNT/en-US/firefox-relay-integration
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1805806676.0000026EF53C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2007268734.0000026EEFB06000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1469617232.0000026EF53C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1466652134.0000026EFA049000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2083981769.0000026EF38CA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1640194503.0000026EF53CC000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1583338326.0000026EF53C9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781413616.0000022A5EF30000.00000002.10000000.00040000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/captive-portal
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/firefox-crashes-troubleshoot-prevent-and-get-helpA
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/fix-video-audio-problems-firefox-windowsMediaPlatformDecoderNotFoundT
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/fix-video-audio-problems-firefox-windowsMediaWMFNeededTo
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/refresh-firefox-reset-add-ons-and-settings
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/warning-unresponsive-script#w_other-causes
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/warning-unresponsive-script#w_other-causestransitionState
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/website-translation
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/website-translationresource://gre/modules/addons/siteperms-addon-util
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.orgtestPermissionFromPrincipalwidget.use-xdg-desktop-portalmedia.autoplay.bl
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2032681797.0000026EF1FA0000.00000002.08000000.00040000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/draft-ietf-httpbis-encryption-encoding-02#section-2
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2032681797.0000026EF1FA0000.00000002.08000000.00040000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/draft-ietf-httpbis-encryption-encoding-02#section-3.1
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2032681797.0000026EF1FA0000.00000002.08000000.00040000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/draft-ietf-httpbis-encryption-encoding-02#section-4
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2032681797.0000026EF1FA0000.00000002.08000000.00040000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc7515#appendix-C)
Source: firefox.exe, 0000000D.00000002.2008846809.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2009305625.0000026EEFBCE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1913295191.0000026EEFBCE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1884841588.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1883012070.0000026EEFBC3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://truecolors.firefox.com
Source: firefox.exe, 0000000D.00000002.2077853279.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2117314409.0000026EF4106000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719018157.0000026EF31F4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1909096087.0000026EF31F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://truecolors.firefox.com/
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://truecolors.firefox.commigrateXULAttributeToStylegeckoprofiler
Source: firefox.exe, 0000000D.00000003.1597630546.0000026EF47B4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1883012070.0000026EEFBC3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB68000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://twitter.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://vk.com/
Source: firefox.exe, 0000000D.00000003.1902832259.0000026F021A2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1726462103.0000026F021A2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1460587802.0000026F0219F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://watch.sling.com/
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://webpack.js.org/concepts/mode/)
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://weibo.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1511469654.0000026EFC20F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.aliexpress.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1384988670.0000026EFA0B5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.co.uk/
Source: firefox.exe, 0000000D.00000003.1597630546.0000026EF47B4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB68000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1511469654.0000026EFC20F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.com/
Source: firefox.exe, 0000000D.00000002.1941972565.0000026EED8B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624E9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1789185978.0000022A5F303000.00000004.00000800.00020000.00000000.sdmp, prefs-1.js.13.drString found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_39e4b8f6fd6635158ad433436bdaa069841cfdf8e1989e03
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1720238362.0000026EF3177000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB7F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1741380216.0000026EF3190000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1328781884.0000026EEF716000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1437544639.0000026F02221000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.com/exec/obidos/external-search/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1384988670.0000026EFA0B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.avito.ru/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.baidu.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.ctrip.com/
Source: firefox.exe, 0000000D.00000003.1597630546.0000026EF47B4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.ebay.co.uk/
Source: firefox.exe, 0000000D.00000003.1597630546.0000026EF47B4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB68000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1489351621.0000026EFBD60000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE2DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/complete/search
Source: firefox.exe, 0000000D.00000003.1328432644.0000026EEF500000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1328781884.0000026EEF716000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/complete/search?client=firefox&q=
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/policies/privacy/
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/policies/privacy/Exception
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1720238362.0000026EF3177000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1484521088.0000026EFF0FE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1741380216.0000026EF3190000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1328781884.0000026EEF716000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1437544639.0000026F02221000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search
Source: firefox.exe, 0000000D.00000003.1491059886.0000026EFBAC3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BF5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2143089475.0000026EF4949000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BDD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BE9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2053015192.0000026EF28CB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1734860528.0000026EF28B4000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB68000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BB8000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1485336487.0000026EFF039000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BF1000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3BED000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1567673443.0000026EFF448000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDBCF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search?client=firefox-b-d&q=
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search?client=firefox-b-d&q=Fixes
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search?client=firefox-b-d&q=Invalid
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search?client=firefox-b-d&q=https://www.google.com/search?client=firefox-b-d&
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search?client=firefox-b-d&q=media.gmp-gmpopenh264.lastDownloadFailReasonhttps
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3BCD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search?client=firefox-b-d&q=resource://activity-stream/lib/FeatureCalloutBrok
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1384988670.0000026EFA0B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.ifeng.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1384988670.0000026EFA0B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.iqiyi.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.iqiyi.com/(browserSettings.update.channel
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1384988670.0000026EFA0B5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.leboncoin.fr/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1720238362.0000026EF3177000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mobilesuica.com/
Source: firefox.exe, 0000000D.00000002.2008846809.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1564197580.0000026F023BD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1884841588.0000026EEFB7D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1474320511.0000026EF38ED000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDBDD000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1658874341.0000026EF38ED000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB5D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org
Source: firefox.exe, 0000000D.00000002.2077127512.0000026EF31DA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1729714585.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1719303726.0000026EF31BE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2070471619.0000026EF306F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDBA1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1392146505.0000026EF9FCB000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1396372154.0000026EF9FD2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1395916732.0000026EF9FE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/about/legal/terms/mozilla/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/about/legal/terms/mozilla/firefox-desktop-glean-nightly-no_targeting-rollout
Source: firefox.exe, 0000000D.00000003.1825372929.0000026EF3E38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2105644401.0000026EF3E4E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2007268734.0000026EEFB06000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2105644401.0000026EF3E38000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1604915328.0000026EF429A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE2AF000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1631638270.0000026EF3E32000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1685296984.0000026EFBAD1000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2122091903.0000026EF42A1000.00000004.00000800.00020000.00000000.sdmp, targeting.snapshot.json.tmp.13.drString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1701157885.0000026EFF412000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/firefox/mobile/get-app/?utm_medium=firefox-desktop&utm_source=onboarding-mod
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B03000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/firefox/new/
Source: firefox.exe, 0000000D.00000002.1941972565.0000026EED85A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624C7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F2F4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/#suggest-relevant-content
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/discoverystream.sponsored-collections.enabledTried
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1469617232.0000026EF53F9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1947214670.0000026EED9DA000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE2AF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.openh264.org/
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.openh264.org/updateAddonRepositoryDataError
Source: firefox.exe, 0000000D.00000002.1984498116.0000026EEF02F000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1883012070.0000026EEFBC3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB68000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1384988670.0000026EFA0B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1511469654.0000026EFC20F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.reddit.com/
Source: firefox.exe, 0000000D.00000003.1902832259.0000026F021A2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1726462103.0000026F021A2000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1460587802.0000026F0219F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.sling.com/
Source: firefox.exe, 0000000D.00000002.1941972565.0000026EED8B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD624E9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1789185978.0000022A5F303000.00000004.00000800.00020000.00000000.sdmp, prefs-1.js.13.drString found in binary or memory: https://www.t-mobile.com/cell-phones/brand/apple?cmpid=MGPO_PAM_P_EVGRNIPHN_
Source: firefox.exe, 0000000D.00000003.1638740956.0000026EFBAE7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1685296984.0000026EFBAE7000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1778067196.0000026EFBD10000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1552178038.0000026EF435D000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1706552454.0000026EFBAE8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.tiktok.com/
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.widevine.com/
Source: firefox.exe, 0000000D.00000002.1967422368.0000026EEE203000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.widevine.com/FIRST_CONTENT_PROCESS_TOPICget
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1925115156.0000026EE20E3000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1967422368.0000026EEE272000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1484521088.0000026EFF0FE000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1509784326.0000026EFC2B5000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1688773230.0000026EF9DA9000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1462639263.0000026EFDB68000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1984498116.0000026EEF078000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1847868069.000001FD6240A000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1783343111.0000022A5F20C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1386596487.0000026EF406E000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1609932426.0000026EF4079000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.zhihu.com/
Source: firefox.exe, 0000000D.00000003.1576802103.0000026EFF723000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://xhr.spec.whatwg.org/#sync-warningWindow_Cc_ontrollersWarningwindow.controllers/Controllers
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.160.144.191:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.160.144.191:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.16:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.149.100.209:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.244.181.201:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.149.100.209:443 -> 192.168.2.16:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.129.91:443 -> 192.168.2.16:49732 version: TLS 1.2
Source: C:\Program Files\Mozilla Firefox\firefox.exeCode function: 15_2_000001FD62573177 NtQuerySystemInformation,15_2_000001FD62573177
Source: C:\Program Files\Mozilla Firefox\firefox.exeCode function: 15_2_000001FD62599272 NtQuerySystemInformation,15_2_000001FD62599272
Source: C:\Program Files\Mozilla Firefox\firefox.exeCode function: 15_2_000001FD6257317715_2_000001FD62573177
Source: C:\Program Files\Mozilla Firefox\firefox.exeCode function: 15_2_000001FD6259927215_2_000001FD62599272
Source: C:\Program Files\Mozilla Firefox\firefox.exeCode function: 15_2_000001FD6259999C15_2_000001FD6259999C
Source: C:\Program Files\Mozilla Firefox\firefox.exeCode function: 15_2_000001FD625992B215_2_000001FD625992B2
Source: 32FoVQqJ.part.13.drStatic PE information: No import functions for PE file found
Source: 32FoVQqJ.part.13.drStatic PE information: Data appended to the last section found
Source: 32FoVQqJ.part.13.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: classification engineClassification label: mal52.spyw.winZIP@35/35@38/11
Source: C:\Program Files\Mozilla Firefox\firefox.exeFile created: C:\Users\user\AppData\Local\Mozilla\Firefox\SkeletonUILock-c388d246Jump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2532:120:WilError_03
Source: C:\Windows\System32\OpenWith.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1916:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2976:120:WilError_03
Source: C:\Windows\System32\OpenWith.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:528:120:WilError_03
Source: C:\Windows\System32\OpenWith.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6428:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2216:120:WilError_03
Source: C:\Program Files\Mozilla Firefox\firefox.exeFile created: C:\Users\user\AppData\Local\Temp\firefoxJump to behavior
Source: C:\Windows\System32\OpenWith.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: firefox.exe, 0000000D.00000003.1566688343.0000026EFF485000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1565651138.0000026EFF5BC000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT * FROM events WHERE timestamp BETWEEN date(:dateFrom) AND date(:dateTo);
Source: firefox.exe, 0000000D.00000003.1566688343.0000026EFF485000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE events (id INTEGER PRIMARY KEY, type INTEGER NOT NULL, count INTEGER NOT NULL, timestamp DATE );
Source: firefox.exe, 0000000D.00000003.1566688343.0000026EFF485000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: INSERT INTO events (type, count, timestamp) VALUES (:type, 1, date(:date));
Source: firefox.exe, 0000000D.00000003.1566688343.0000026EFF485000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT timestamp FROM events ORDER BY timestamp ASC LIMIT 1;;
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1684349929.0000026EFBD97000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000003.1649942599.0000026EFBD97000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT sum(count) FROM events;
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT timestamp FROM events ORDER BY timestamp ASC LIMIT 1;
Source: firefox.exe, 0000000D.00000003.1566688343.0000026EFF485000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT timestamp FROM events ORDER BY timestamp ASC LIMIT 1;;Fy6
Source: firefox.exe, 0000000D.00000003.1566688343.0000026EFF485000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: UPDATE events SET count = count + 1 WHERE id = :id;-
Source: firefox.exe, 0000000D.00000003.1566688343.0000026EFF485000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT sum(count) FROM events;9'
Source: firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: UPDATE events SET count = count + 1 WHERE id = :id;
Source: firefox.exe, 0000000D.00000003.1566688343.0000026EFF485000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT sum(count) FROM events;9
Source: firefox.exe, 0000000D.00000003.1566688343.0000026EFF485000.00000004.00000800.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.2090038738.0000026EF3B1B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT * FROM events WHERE type = :type AND timestamp = date(:date);
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Windows\System32\OpenWith.exe C:\Windows\system32\OpenWith.exe -Embedding
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\Temp1_VirusShare_661c60ba6e4e5e7864714aed6cda9d55.zip\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76"
Source: unknownProcess created: C:\Windows\System32\OpenWith.exe C:\Windows\system32\OpenWith.exe -Embedding
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "C:\Users\user\Desktop\VirusShare_661c60ba6e4e5e7864714aed6cda9d55\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76"
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url C:\Users\user\Desktop\VirusShare_661c60ba6e4e5e7864714aed6cda9d55\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2304 -parentBuildID 20230927232528 -prefsHandle 2252 -prefMapHandle 2244 -prefsLen 25250 -prefMapSize 237879 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8f7bd64a-d03a-4edf-85a5-9ec518d890e8} 2108 "\\.\pipe\gecko-crash-server-pipe.2108" 26ee206d510 socket
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2516 -parentBuildID 20230927232528 -prefsHandle 3864 -prefMapHandle 3764 -prefsLen 26265 -prefMapSize 237879 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2412d5aa-b892-4f10-a6ac-0e5f62df1307} 2108 "\\.\pipe\gecko-crash-server-pipe.2108" 26ef4197b10 rdd
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5140 -parentBuildID 20230927232528 -sandboxingKind 0 -prefsHandle 5188 -prefMapHandle 5176 -prefsLen 33133 -prefMapSize 237879 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {273decd0-131e-4e1d-8093-0d28a711eee8} 2108 "\\.\pipe\gecko-crash-server-pipe.2108" 26ef2567710 utility
Source: unknownProcess created: C:\Windows\System32\OpenWith.exe C:\Windows\system32\OpenWith.exe -Embedding
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\pingsender.exe "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/4309612b-ce46-455b-bbea-0678ea7a053f/event/Firefox/118.0.1/release/20230927232528?v=4 C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\4309612b-ce46-455b-bbea-0678ea7a053f
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\pingsender.exe "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/4b6c9ea4-2760-40af-b13f-c9a32b1f931b/health/Firefox/118.0.1/release/20230927232528?v=4 C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\4b6c9ea4-2760-40af-b13f-c9a32b1f931b
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\pingsender.exe "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/2869bc7b-c35d-434e-b309-b1c625645d80/main/Firefox/118.0.1/release/20230927232528?v=4 C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\2869bc7b-c35d-434e-b309-b1c625645d80
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\root\Office16\Winword.exe" /n "C:\Users\user\AppData\Local\Temp\Temp1_VirusShare_661c60ba6e4e5e7864714aed6cda9d55.zip\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76"
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\Temp1_VirusShare_661c60ba6e4e5e7864714aed6cda9d55.zip\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76"Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "C:\Users\user\Desktop\VirusShare_661c60ba6e4e5e7864714aed6cda9d55\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76"Jump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url C:\Users\user\Desktop\VirusShare_661c60ba6e4e5e7864714aed6cda9d55\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76Jump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2304 -parentBuildID 20230927232528 -prefsHandle 2252 -prefMapHandle 2244 -prefsLen 25250 -prefMapSize 237879 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8f7bd64a-d03a-4edf-85a5-9ec518d890e8} 2108 "\\.\pipe\gecko-crash-server-pipe.2108" 26ee206d510 socketJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2516 -parentBuildID 20230927232528 -prefsHandle 3864 -prefMapHandle 3764 -prefsLen 26265 -prefMapSize 237879 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2412d5aa-b892-4f10-a6ac-0e5f62df1307} 2108 "\\.\pipe\gecko-crash-server-pipe.2108" 26ef4197b10 rddJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5140 -parentBuildID 20230927232528 -sandboxingKind 0 -prefsHandle 5188 -prefMapHandle 5176 -prefsLen 33133 -prefMapSize 237879 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {273decd0-131e-4e1d-8093-0d28a711eee8} 2108 "\\.\pipe\gecko-crash-server-pipe.2108" 26ef2567710 utilityJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\pingsender.exe "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/4309612b-ce46-455b-bbea-0678ea7a053f/event/Firefox/118.0.1/release/20230927232528?v=4 C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\4309612b-ce46-455b-bbea-0678ea7a053fJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\pingsender.exe "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/4b6c9ea4-2760-40af-b13f-c9a32b1f931b/health/Firefox/118.0.1/release/20230927232528?v=4 C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\4b6c9ea4-2760-40af-b13f-c9a32b1f931bJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeProcess created: C:\Program Files\Mozilla Firefox\pingsender.exe "C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/2869bc7b-c35d-434e-b309-b1c625645d80/main/Firefox/118.0.1/release/20230927232528?v=4 C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\2869bc7b-c35d-434e-b309-b1c625645d80Jump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\root\Office16\Winword.exe" /n "C:\Users\user\AppData\Local\Temp\Temp1_VirusShare_661c60ba6e4e5e7864714aed6cda9d55.zip\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76"Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: unknown unknown
Source: C:\Windows\System32\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinui.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: pdh.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: actxprxy.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.appdefaults.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uiautomationcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dui70.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: duser.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uianimation.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: edputil.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: thumbcache.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: sxs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: slc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: sppc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinui.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: pdh.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: actxprxy.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.appdefaults.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uiautomationcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dui70.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: duser.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uianimation.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: edputil.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: thumbcache.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: sxs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office
Source: Binary string: UxTheme.pdb source: firefox.exe, 0000000D.00000003.1694437422.0000026EF3E92000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: shlwapi.pdbp source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: gdi32.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: profapi.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ws2_32.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: WLDP.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: bcrypt.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: rpcrt4.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: sechost.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ktmw32.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: msvcrt.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: propsys.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ntmarta.pdb@@@@var(--toolbar-color) source: firefox.exe, 0000000D.00000003.1694437422.0000026EF3E92000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: winmm.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: xul.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: shcore.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: mozglue.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ole32.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: version.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: dbgcore.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: user32.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ntmarta.pdb source: firefox.exe, 0000000D.00000003.1694437422.0000026EF3E92000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: msasn1.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: psapi.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: DWrite.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: shlwapi.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: ntdll.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: nss3.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: win32u.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: firefox.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: wsock32.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: dbghelp.pdb source: firefox.exe, 0000000D.00000003.1694375828.0000026EF4053000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: crypt32.pdb source: firefox.exe, 0000000D.00000003.1694968067.0000026EF38B0000.00000004.00000800.00020000.00000000.sdmp
Source: 32FoVQqJ.part.13.drStatic PE information: real checksum: 0x267ae should be: 0x34a60
Source: C:\Program Files\Mozilla Firefox\firefox.exeFile created: C:\Users\user\Downloads\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76 (copy)Jump to dropped file
Source: C:\Program Files\Mozilla Firefox\firefox.exeFile created: C:\Users\user\Downloads\32FoVQqJ.partJump to dropped file
Source: C:\Program Files\Mozilla Firefox\firefox.exeFile created: C:\Users\user\Downloads\32FoVQqJ.partJump to dropped file
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Mozilla Firefox\pingsender.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEJump to behavior
Source: C:\Program Files\Mozilla Firefox\firefox.exeCode function: 15_2_000001FD62573177 rdtsc 15_2_000001FD62573177
Source: C:\Windows\System32\OpenWith.exe TID: 6432Thread sleep count: 61 > 30Jump to behavior
Source: C:\Windows\System32\OpenWith.exe TID: 6476Thread sleep count: 54 > 30Jump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: OpenWith.exe, 0000000B.00000002.1324424787.0000026330D49000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: #CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}cda9d55
Source: firefox.exe, 0000000D.00000002.1929401010.0000026EE39AE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}K
Source: firefox.exe, 0000000F.00000002.1862697178.000001FD62A31000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllo
Source: firefox.exe, 0000000E.00000002.1838752638.000002827E24A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWp
Source: pingsender.exe, 00000012.00000002.1803728648.00000272A4392000.00000004.00000020.00020000.00000000.sdmp, pingsender.exe, 00000016.00000002.1803988205.000001400DF69000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW0
Source: firefox.exe, 0000000D.00000002.1929401010.0000026EE391C000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1929401010.0000026EE38CB000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000000D.00000002.1929401010.0000026EE38C0000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000000E.00000002.1854925424.000002827E800000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1841567535.000001FD6221A000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1862697178.000001FD62A20000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1781130119.0000022A5EE30000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 00000010.00000002.1779849876.0000022A5EDDA000.00000004.00000020.00020000.00000000.sdmp, pingsender.exe, 00000012.00000002.1803728648.00000272A4417000.00000004.00000020.00020000.00000000.sdmp, pingsender.exe, 00000013.00000002.1806354122.000001B56E64B000.00000004.00000020.00020000.00000000.sdmp, pingsender.exe, 00000013.00000002.1806354122.000001B56E5D2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: firefox.exe, 0000000D.00000002.1947214670.0000026EED9BD000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW : 2 : 34 : 1 : 1 : 0x20026 : 0x8 : %SystemRoot%\system32\mswsock.dll : : 1234191b-4bf7-4ca7-86e0-dfd7c32b5445
Source: firefox.exe, 0000000D.00000002.1929401010.0000026EE391C000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000000E.00000002.1854925424.000002827E812000.00000004.00000020.00020000.00000000.sdmp, firefox.exe, 0000000F.00000002.1862697178.000001FD62A31000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information queried: ProcessInformation
Source: C:\Program Files\Mozilla Firefox\firefox.exeCode function: 15_2_000001FD62573177 rdtsc 15_2_000001FD62573177
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\Temp1_VirusShare_661c60ba6e4e5e7864714aed6cda9d55.zip\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76"Jump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "C:\Users\user\Desktop\VirusShare_661c60ba6e4e5e7864714aed6cda9d55\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76"Jump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\root\Office16\Winword.exe" /n "C:\Users\user\AppData\Local\Temp\Temp1_VirusShare_661c60ba6e4e5e7864714aed6cda9d55.zip\17e673356139d5d678e0641e43512c6406a5dfd573e5600cfb3800cad057ea76"Jump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior

Stealing of Sensitive Information

barindex
Source: C:\Program Files\Mozilla Firefox\pingsender.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\2869bc7b-c35d-434e-b309-b1c625645d80
Source: C:\Program Files\Mozilla Firefox\pingsender.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\4309612b-ce46-455b-bbea-0678ea7a053f
Source: C:\Program Files\Mozilla Firefox\pingsender.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\4b6c9ea4-2760-40af-b13f-c9a32b1f931b
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
11
Process Injection
11
Masquerading
1
OS Credential Dumping
111
Security Software Discovery
Remote Services1
Archive Collected Data
12
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop Protocol1
Data from Local System
1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Extra Window Memory Injection
11
Process Injection
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Rundll32
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture3
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Software Packing
LSA Secrets12
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
Extra Window Memory Injection
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1635119 Sample: VirusShare_661c60ba6e4e5e78... Startdate: 11/03/2025 Architecture: WINDOWS Score: 52 47 telemetry-incoming.r53-2.services.mozilla.com 2->47 49 spocs.getpocket.com 2->49 51 24 other IPs or domains 2->51 59 Multi AV Scanner detection for dropped file 2->59 10 OpenWith.exe 6 2->10         started        12 OpenWith.exe 19 6 2->12         started        14 OpenWith.exe 2 6 2->14         started        16 rundll32.exe 2->16         started        signatures3 process4 process5 18 firefox.exe 1 10->18         started        20 Acrobat.exe 42 12->20         started        22 WINWORD.EXE 14->22         started        process6 24 firefox.exe 10 218 18->24         started        dnsIp7 53 prod.detectportal.prod.cloudops.mozgcp.net 34.107.221.82, 49707, 49710, 49717 GOOGLEUS United States 24->53 55 push.services.mozilla.com 34.107.243.93, 443, 49721 GOOGLEUS United States 24->55 57 9 other IPs or domains 24->57 43 C:\Users\user\Downloads\32FoVQqJ.part, PE32 24->43 dropped 45 17e673356139d5d678...00cad057ea76 (copy), PE32 24->45 dropped 28 pingsender.exe 24->28         started        31 pingsender.exe 24->31         started        33 pingsender.exe 24->33         started        35 3 other processes 24->35 file8 process9 signatures10 61 Tries to harvest and steal browser information (history, passwords, etc) 28->61 37 conhost.exe 28->37         started        39 conhost.exe 31->39         started        41 conhost.exe 33->41         started        process11

This section contains all screenshots as thumbnails, including those not shown in the slideshow.