URL:

https://pixeldrain.com/u/nkrGcBN3

Full analysis: https://app.any.run/tasks/80511482-dd16-4a08-88b5-41c0e835b9c2
Verdict: Malicious activity
Threats:

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.

Analysis date: October 28, 2023, 20:41:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
sinkhole
stealer
redline
Indicators:
SHA1:

75B1AAD354998CD2FE155E34D7FFA49999FFFA96

SHA256:

0AE17656BFC2EAC15BC1A04D23009D262DAE817FE31E9A0EA711AE908AF6B970

SSDEEP:

3:N8Icl/GKgJC:2IG/dgJC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • InfinityGateway.exe (PID: 2700)
    • Connects to the CnC server

      • InfinityGateway.exe (PID: 2700)
    • REDLINE has been detected (SURICATA)

      • InfinityGateway.exe (PID: 2700)
    • Actions looks like stealing of personal data

      • InfinityGateway.exe (PID: 2700)
  • SUSPICIOUS

    • Connects to unusual port

      • InfinityGateway.exe (PID: 2700)
    • Reads browser cookies

      • InfinityGateway.exe (PID: 2700)
    • Searches for installed software

      • InfinityGateway.exe (PID: 2700)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 3920)
      • WinRAR.exe (PID: 3704)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 3704)
      • firefox.exe (PID: 1392)
    • Checks supported languages

      • InfinityGateway.exe (PID: 2700)
    • Application launched itself

      • firefox.exe (PID: 1392)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3704)
      • firefox.exe (PID: 1392)
    • Reads the computer name

      • InfinityGateway.exe (PID: 2700)
    • Reads the machine GUID from the registry

      • InfinityGateway.exe (PID: 2700)
    • Reads Environment values

      • InfinityGateway.exe (PID: 2700)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
12
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winrar.exe no specs winrar.exe no specs #REDLINE infinitygateway.exe

Process information

PID
CMD
Path
Indicators
Parent process
904"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.4.749388963\589840850" -childID 3 -isForBrowser -prefsHandle 3700 -prefMapHandle 3688 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {bbf6d235-3ad5-4f8d-bb47-ca5995f7080a} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 3744 21f0c558 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
1392"C:\Program Files\Mozilla Firefox\firefox.exe" "https://pixeldrain.com/u/nkrGcBN3"C:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\mozglue.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll
1556"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.2.454005150\1245947642" -childID 1 -isForBrowser -prefsHandle 2032 -prefMapHandle 2028 -prefsLen 25524 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e7d3cbcc-db6b-49f3-9c0b-a2a78357f42b} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 2044 19c4cb58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1584"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.6.1416650468\185659845" -childID 5 -isForBrowser -prefsHandle 3872 -prefMapHandle 3876 -prefsLen 35557 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {3843f249-701d-4778-8f21-000c551e93de} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 3900 d42958 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll
2488"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.5.544768065\891037427" -childID 4 -isForBrowser -prefsHandle 3788 -prefMapHandle 3784 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ff216159-265a-4e5b-9b87-e78c26a84e23} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 3772 21fcfa58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\lpk.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
2492"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.1.308931248\119101475" -parentBuildID 20230710165010 -prefsHandle 1388 -prefMapHandle 1384 -prefsLen 29857 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4c9e7480-d168-4d77-b59e-ba8cbfda9c2b} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 1412 41d0858 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2548"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.0.36159396\1618910662" -parentBuildID 20230710165010 -prefsHandle 1100 -prefMapHandle 1092 -prefsLen 29780 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {dd43d8d6-f90c-474a-aace-89aba7379b32} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 1172 41ce458 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
2700"C:\Users\admin\AppData\Local\Temp\Rar$EXb3704.19102\InfinityGateway\InfinityGateway.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3704.19102\InfinityGateway\InfinityGateway.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3704.19102\infinitygateway\infinitygateway.exe
c:\windows\syswow64\ntdll.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernelbase.dll
2704"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1392.3.582324595\178993511" -childID 2 -isForBrowser -prefsHandle 2972 -prefMapHandle 2968 -prefsLen 35454 -prefMapSize 244187 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d32c5907-cd5e-4ebf-8af6-7793119c24e9} 1392 "\\.\pipe\gecko-crash-server-pipe.1392" 2984 1d12de58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\firefox.exe
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
3704"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\InfinityGateway.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
9 600
Read events
9 532
Write events
68
Delete events
0

Modification events

(PID) Process:(1392) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
0000000000000000
(PID) Process:(1392) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(1392) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(1392) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(1392) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(1392) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
0
(PID) Process:(1392) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(1392) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice
Value:
1
(PID) Process:(1392) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|AppLastRunTime
Value:
F8B731ACA1C5D901
(PID) Process:(1392) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
5
Suspicious files
436
Text files
49
Unknown types
0

Dropped files

PID
Process
Filename
Type
1392firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
1392firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
1392firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-walbinary
MD5:08FAEBB14DA679C01F5F2EA21FA1C7A1
SHA256:667D9231713884F5E2E26BA081CA2EE32C34705B8EC7AFA1D6DAA57481B313E6
1392firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\protections.sqlite-journalbinary
MD5:319FDE0598B72959C57A65B3E0AEDD67
SHA256:DF311DEE7C7177A0CCB98ECCF381CFDCF55F595C9B1E9BBF8DC2A80BE9A54D81
1392firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\doomed\8591compressed
MD5:58BF90C279D403DC2DFB9B9DF37D9B81
SHA256:4A922FE9DF274368DBD30EC32F033BC5404E868AE1F512F6CFB291D7A4D781C5
1392firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\5F06CF600E03140A884AC4DEDF008D5BF091E926binary
MD5:184F8DED7C530C6E3FB64EF755D6BDEB
SHA256:4076C2AAF64ED2677CA428A66C10EAA26DD0745018C6D5A436206A680E2F1D9F
1392firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\ED9826654AE8BD972BDE17A9E0A449D3F881E430binary
MD5:48D15A16CADB9632D9F7D144CD5F9D77
SHA256:FEA3E0272E243FFAA8B46EA3BE664B4E879D9CEC3AAB6B45F2F8652EA8FFFC07
1392firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlitebinary
MD5:823065731ECF281D5EA7268DB4341AB3
SHA256:D67EBB929DFDF3DDBCC70FFD7D0149DBC28940E990EFD90924D47EB2D8111365
1392firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\6D89348819C8881868053197CA0754F36784BF5Fcompressed
MD5:22CD362943AAC88FFB2A493476311960
SHA256:AE95F1ED7D9E9D0991EBAD0D72B2EF6F7A72FD02679E88A3C13B8832D76299A4
1392firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\300BCB4FCDB6090532D9DDDAD2DFBD00BDE45E59binary
MD5:8A2BEF06F10C814904A5D3F88279E47D
SHA256:2CC13A1B0BE0AFA130B4AA2407C217C1C8C099399A39C890B72027CB46C7FAE9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
71
DNS requests
143
Threats
30

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1392
firefox.exe
POST
200
23.32.238.82:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
1392
firefox.exe
POST
200
23.32.238.82:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
1392
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
1392
firefox.exe
POST
200
23.32.238.82:80
http://r3.o.lencr.org/
unknown
der
503 b
unknown
1392
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
1392
firefox.exe
POST
200
23.32.238.82:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
1392
firefox.exe
POST
200
3.162.33.170:80
http://ocsp.r2m02.amazontrust.com/
unknown
binary
471 b
unknown
1392
firefox.exe
POST
200
23.32.238.82:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
1392
firefox.exe
POST
200
23.32.238.82:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
1392
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
324
svchost.exe
224.0.0.252:5355
unknown
1392
firefox.exe
50.7.22.10:443
pixeldrain.com
COGENT-174
NL
unknown
4
System
192.168.100.255:137
whitelisted
1392
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
1392
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
1392
firefox.exe
34.197.137.200:443
spocs.getpocket.com
AMAZON-AES
US
unknown
1392
firefox.exe
23.32.238.82:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
1392
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
unknown
1956
svchost.exe
239.255.255.250:1900
whitelisted
1392
firefox.exe
3.162.33.170:80
ocsp.r2m02.amazontrust.com
US
unknown

DNS requests

Domain
IP
Reputation
pixeldrain.com
  • 50.7.22.10
  • 50.7.236.50
  • 2001:49f0:d0ae:6::2
  • 2001:49f0:d0f5:5::2
  • 50.7.24.66
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
unknown
spocs.getpocket.com
  • 34.197.137.200
  • 44.215.179.220
  • 44.214.198.60
  • 18.214.83.77
shared
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 44.215.179.220
  • 18.214.83.77
  • 34.197.137.200
  • 44.214.198.60
shared
r3.o.lencr.org
  • 23.32.238.82
  • 23.32.238.27
  • 184.24.77.54
  • 184.24.77.56
shared
a1887.dscq.akamai.net
  • 23.32.238.82
  • 23.32.238.27
  • 2a02:26f0:3500:f::1732:831e
  • 2a02:26f0:3500:f::1732:831a
whitelisted

Threats

PID
Process
Class
Message
2700
InfinityGateway.exe
Potentially Bad Traffic
ET INFO Microsoft net.tcp Connection Initialization Activity
2700
InfinityGateway.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
2700
InfinityGateway.exe
A Network Trojan was detected
ET MALWARE [ANY.RUN] RedLine Stealer Related (MC-NMF Authorization)
2700
InfinityGateway.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC - Id1Response
2700
InfinityGateway.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
2700
InfinityGateway.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
2700
InfinityGateway.exe
A Network Trojan was detected
ET MALWARE Redline Stealer Activity (Response)
2700
InfinityGateway.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
2700
InfinityGateway.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
2700
InfinityGateway.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
No debug info