| URL: | http://putsinhack.ru/ |
| Full analysis: | https://app.any.run/tasks/cd57ba65-1879-43e0-83d7-45785a2a6126 |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | October 22, 2023, 07:22:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 15CEEF3CCD625E8F98CCDFEEA8F3B901 |
| SHA1: | 5D848884728F5DF7E74AA5D9BD932CB056469DB1 |
| SHA256: | 001AC5D51EE6E9178F672A678E9E3F327BC4D6CD59A4915FD6EA584A354DBD32 |
| SSDEEP: | 3:N1KOQRFEGOr:COyOr |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 616 | C:\Windows\system32\cmd.exe /c ""C:\Surrogateperf\2MBQ9VPv8CeTlfHahis8DN.bat" " | C:\Windows\SysWOW64\cmd.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 844 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2220.7.397287104\95562413" -childID 6 -isForBrowser -prefsHandle 4220 -prefMapHandle 4080 -prefsLen 35557 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {52710c8f-b479-4c12-ad06-aebfb21b1d16} 2220 "\\.\pipe\gecko-crash-server-pipe.2220" 4236 23ddfa58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1436 | "C:\Surrogateperf/runtimePerfDll.exe" | C:\Surrogateperf\runtimePerfDll.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 1.2.7.1277 Modules
| |||||||||||||||
| 2100 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2220.2.532988182\972574730" -childID 1 -isForBrowser -prefsHandle 2012 -prefMapHandle 2008 -prefsLen 25589 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7c6af0cf-a8ea-4d8c-a619-721f404590d8} 2220 "\\.\pipe\gecko-crash-server-pipe.2220" 2024 1934be58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2220 | "C:\Program Files\Mozilla Firefox\firefox.exe" "http://putsinhack.ru/" | C:\Program Files\Mozilla Firefox\firefox.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2468 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2220.3.1147555364\80987765" -childID 2 -isForBrowser -prefsHandle 608 -prefMapHandle 580 -prefsLen 35402 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d3d28394-6d08-4666-833a-b431b90057a4} 2220 "\\.\pipe\gecko-crash-server-pipe.2220" 2696 e81b58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2584 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2220.1.749241842\1097881662" -parentBuildID 20230710165010 -prefsHandle 1392 -prefMapHandle 1388 -prefsLen 29857 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7f557b6e-746f-4d4a-9603-1fe41b931218} 2220 "\\.\pipe\gecko-crash-server-pipe.2220" 1416 43d5558 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2600 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2220.5.671978716\436421996" -childID 4 -isForBrowser -prefsHandle 3836 -prefMapHandle 3832 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0f57683b-7daf-40a6-b984-d8b4c3631b0e} 2220 "\\.\pipe\gecko-crash-server-pipe.2220" 3744 21593e58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2700 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2220.6.393940620\2091664488" -childID 5 -isForBrowser -prefsHandle 3856 -prefMapHandle 3996 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e622033d-5587-41f2-a010-72c74b02e01f} 2220 "\\.\pipe\gecko-crash-server-pipe.2220" 4064 21595658 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2844 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2220.0.607584511\2032932553" -parentBuildID 20230710165010 -prefsHandle 1104 -prefMapHandle 1096 -prefsLen 29780 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {38fe83c4-d322-45fb-954d-749fceac90c0} 2220 "\\.\pipe\gecko-crash-server-pipe.2220" 1176 43d4958 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (2220) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0000000000000000 | |||
| (PID) Process: | (2220) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (2220) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (2220) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (2220) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (2220) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 0 | |||
| (PID) Process: | (2220) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (2220) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (2220) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: F8B731ACA1C5D901 | |||
| (PID) Process: | (2220) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2220 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs.js | text | |
MD5:F42921723A3596D2FA57BE1279C18862 | SHA256:5D6A78D6523693521C6D337C72269B0320B0C5A82D699D74FF2490813574C652 | |||
| 2220 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2220 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\ED9826654AE8BD972BDE17A9E0A449D3F881E430 | binary | |
MD5:526D6D4631EC67D23D1D4758A0C9D00B | SHA256:89690E9682C8A73C76C990E379020E2C6212BAA32C3650AEEF65694B9578F314 | |||
| 2220 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2220 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2220 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs-1.js | text | |
MD5:F42921723A3596D2FA57BE1279C18862 | SHA256:5D6A78D6523693521C6D337C72269B0320B0C5A82D699D74FF2490813574C652 | |||
| 2220 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2220 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2220 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:4F056690F6D78B4F60B196EE8D96D2C2 | SHA256:7212B320B1DBF734D921CE1EE5348C3D832354FF5548C43919357065F607AB43 | |||
| 2220 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.bin | binary | |
MD5:4DF9B77C7650AF87B264E535779AE2A4 | SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2220 | firefox.exe | GET | — | 141.8.192.82:80 | http://putsinhack.ru/images/background.png | unknown | — | — | unknown |
2220 | firefox.exe | GET | — | 141.8.192.82:80 | http://putsinhack.ru/css/media.css | unknown | — | — | unknown |
2220 | firefox.exe | GET | — | 141.8.192.82:80 | http://putsinhack.ru/images/step_there.png | unknown | — | — | unknown |
2220 | firefox.exe | GET | — | 141.8.192.82:80 | http://putsinhack.ru/images/icon_one.png | unknown | — | — | unknown |
2220 | firefox.exe | GET | — | 141.8.192.82:80 | http://putsinhack.ru/images/logo.png | unknown | — | — | unknown |
2220 | firefox.exe | POST | — | 216.58.212.3:80 | http://ocsp.pki.goog/gts1c3 | unknown | — | — | unknown |
2220 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2220 | firefox.exe | GET | 200 | 141.8.192.82:80 | http://putsinhack.ru/images/step_two.png | unknown | image | 18.8 Mb | unknown |
2220 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
2220 | firefox.exe | GET | 200 | 141.8.192.82:80 | http://putsinhack.ru/ | unknown | image | 87.6 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2220 | firefox.exe | 104.18.10.207:443 | stackpath.bootstrapcdn.com | — | — | unknown |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2220 | firefox.exe | 172.64.102.11:443 | use.fontawesome.com | — | — | unknown |
2220 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
2220 | firefox.exe | 104.17.24.14:443 | cdnjs.cloudflare.com | — | — | unknown |
2220 | firefox.exe | 141.8.192.82:80 | putsinhack.ru | Sprinthost.ru LLC | RU | unknown |
2220 | firefox.exe | 34.117.65.55:443 | push.services.mozilla.com | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
putsinhack.ru |
| unknown |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| unknown |
content-signature-2.cdn.mozilla.net |
| whitelisted |
prod.content-signature-chains.prod.webservices.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
324 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
3052 | IMEDICTUPDATE.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.top domain |
— | — | Misc activity | SUSPICIOUS [ANY.RUN] Possible DarkCrystal Rat Encrypted Connection |
3052 | IMEDICTUPDATE.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.top domain |
3052 | IMEDICTUPDATE.exe | A Network Trojan was detected | REMOTE [ANY.RUN] DarkCrystal Rat Exfiltration (POST) |
3052 | IMEDICTUPDATE.exe | Misc activity | SUSPICIOUS [ANY.RUN] Sending an HTTP request body with a Base64 encoded ZIP file |
3052 | IMEDICTUPDATE.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.top domain |
3052 | IMEDICTUPDATE.exe | Misc activity | SUSPICIOUS [ANY.RUN] Possible DarkCrystal Rat Encrypted Connection |