File name:

NjRat-0.7D-Green-Edition-SIGMASOFT-master.zip

Full analysis: https://app.any.run/tasks/ed81a7ee-700d-408e-8c85-4037f8be01c0
Verdict: Malicious activity
Threats:

njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world.

Analysis date: January 13, 2024, 20:02:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
securityxploded
rat
njrat
bladabindi
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

96C131D98F96D3C190AB14486206132B

SHA1:

7DFB425BD027831A96025F4C7010A7250E0397AD

SHA256:

2F3B9845217E48C1DD0DAF32DB8981007F5964EC3D4CF24840229AB8F64FCF90

SSDEEP:

98304:8u2wPVwBPlvOKN7Zcpfv6uzWuNXXrk8LNyZ6jkPQ0bQsv/1/je9C3jXYCjNC6qly:NXyhH7f7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • SecurityXploded is detected

      • WinRAR.exe (PID: 128)
    • Drops the executable file immediately after the start

      • ilasm.exe (PID: 2336)
      • NjRat 0.7D Green Edition SIGMASOFT.exe (PID: 1288)
      • Server.exe (PID: 2596)
    • NjRAT is detected

      • Server.exe (PID: 2748)
      • server.exe (PID: 2460)
      • Server.exe (PID: 2676)
      • Server.exe (PID: 3256)
      • Server.exe (PID: 124)
      • Server.exe (PID: 3592)
      • Server.exe (PID: 3428)
    • NJRAT has been detected (YARA)

      • server.exe (PID: 2460)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ilasm.exe (PID: 2336)
      • NjRat 0.7D Green Edition SIGMASOFT.exe (PID: 1288)
      • Server.exe (PID: 2596)
    • Reads the Internet Settings

      • NjRat 0.7D Green Edition SIGMASOFT.exe (PID: 1288)
      • Server.exe (PID: 2596)
    • Starts itself from another location

      • Server.exe (PID: 2596)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • server.exe (PID: 2460)
    • Uses TASKKILL.EXE to kill process

      • server.exe (PID: 2460)
  • INFO

    • Checks supported languages

      • NjRat 0.7D Green Edition SIGMASOFT.exe (PID: 1288)
      • ilasm.exe (PID: 2336)
      • server.exe (PID: 2460)
      • Server.exe (PID: 2596)
      • Server.exe (PID: 2748)
      • Server.exe (PID: 124)
      • Server.exe (PID: 3256)
      • Server.exe (PID: 2676)
      • Server.exe (PID: 3428)
      • Server.exe (PID: 3592)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 128)
    • Reads the computer name

      • NjRat 0.7D Green Edition SIGMASOFT.exe (PID: 1288)
      • Server.exe (PID: 2748)
      • Server.exe (PID: 2596)
      • Server.exe (PID: 2676)
      • server.exe (PID: 2460)
      • Server.exe (PID: 124)
      • Server.exe (PID: 3592)
      • Server.exe (PID: 3428)
      • Server.exe (PID: 3256)
    • Reads the machine GUID from the registry

      • NjRat 0.7D Green Edition SIGMASOFT.exe (PID: 1288)
      • Server.exe (PID: 2748)
      • Server.exe (PID: 2596)
      • server.exe (PID: 2460)
      • Server.exe (PID: 2676)
      • Server.exe (PID: 124)
      • Server.exe (PID: 3428)
      • Server.exe (PID: 3592)
      • Server.exe (PID: 3256)
    • Reads Environment values

      • NjRat 0.7D Green Edition SIGMASOFT.exe (PID: 1288)
      • server.exe (PID: 2460)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 128)
    • Create files in a temporary directory

      • NjRat 0.7D Green Edition SIGMASOFT.exe (PID: 1288)
    • Manual execution by a user

      • explorer.exe (PID: 452)
      • explorer.exe (PID: 2828)
      • explorer.exe (PID: 2888)
      • firefox.exe (PID: 2376)
      • Server.exe (PID: 2596)
      • Server.exe (PID: 2748)
      • WINWORD.EXE (PID: 1424)
      • Server.exe (PID: 124)
      • Server.exe (PID: 3256)
      • Server.exe (PID: 2676)
      • Server.exe (PID: 3428)
      • Server.exe (PID: 3592)
    • Application launched itself

      • firefox.exe (PID: 2380)
      • firefox.exe (PID: 2376)
    • Creates files in the program directory

      • Server.exe (PID: 2596)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

NjRat

(PID) Process(2460) server.exe
C2127.0.0.1
Ports5552
BotnetHacKed
Options
Auto-run registry keySoftware\Microsoft\Windows\CurrentVersion\Run\69a9d49c608b901eb62480c8365099ca
Splitter|'|'|
Versionim523
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 1980:01:01 00:00:00
ZipCRC: 0xffffffff
ZipCompressedSize: 4294967295
ZipUncompressedSize: 4294967295
ZipFileName: NjRat-0.7D-Green-Edition-SIGMASOFT-master/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
74
Monitored processes
27
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #SECURITYXPLODED winrar.exe njrat 0.7d green edition sigmasoft.exe ilasm.exe explorer.exe no specs explorer.exe no specs explorer.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winword.exe no specs server.exe #NJRAT server.exe no specs #NJRAT server.exe no specs #NJRAT server.exe no specs #NJRAT server.exe no specs #NJRAT server.exe no specs netsh.exe no specs taskkill.exe no specs #NJRAT server.exe no specs #NJRAT server.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Users\admin\Documents\Server.exe" C:\Users\admin\Documents\Server.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\documents\server.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
128"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NjRat-0.7D-Green-Edition-SIGMASOFT-master.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
452"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1288"C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\NjRat 0.7D Green Edition SIGMASOFT.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\NjRat 0.7D Green Edition SIGMASOFT.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
NjRat 0.7D Green Edition by im523
Exit code:
0
Version:
0.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb128.14132\njrat-0.7d-green-edition-sigmasoft-master\njrat 0.7d green edition sigmasoft.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1424"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Documents\modelpicture.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
2108"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2380.4.756863458\1369295226" -childID 3 -isForBrowser -prefsHandle 3660 -prefMapHandle 1612 -prefsLen 34336 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {9c51de07-0c1b-438e-b01b-a2b2cc52efb4} 2380 "\\.\pipe\gecko-crash-server-pipe.2380" 3656 138486d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2156netsh firewall add allowedprogram "C:\ProgramData\server.exe" "server.exe" ENABLEC:\Windows\System32\netsh.exeserver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2160"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2380.7.181966184\14342203" -childID 6 -isForBrowser -prefsHandle 4184 -prefMapHandle 4164 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ac81edc7-d7d1-4c50-b81e-a0c23d474ea2} 2380 "\\.\pipe\gecko-crash-server-pipe.2380" 4172 190e9b20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2228"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2380.5.1085965700\2141630143" -childID 4 -isForBrowser -prefsHandle 1636 -prefMapHandle 3864 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {72d0988e-8b8a-4a75-9658-180cf72c8236} 2380 "\\.\pipe\gecko-crash-server-pipe.2380" 3880 182f4e00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2336"C:\Windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe" /alignment=512 /QUIET "C:\Users\admin\AppData\Local\Temp\stub.il" /output:"C:\Users\admin\Documents\Server.exe"C:\Windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
NjRat 0.7D Green Edition SIGMASOFT.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Framework IL assembler
Exit code:
0
Version:
2.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\ilasm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
16 240
Read events
15 836
Write events
256
Delete events
148

Modification events

(PID) Process:(128) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
12
Suspicious files
102
Text files
104
Unknown types
3

Dropped files

PID
Process
Filename
Type
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\Plugin\mic.dllexecutable
MD5:D4C5DDC00F27162FC0947830E0E762B7
SHA256:B6FB6B66821E70A27A4750B0CD0393E4EE2603A47FEAC48D6A3D66D1C1CB56D5
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\Plugin\ch.dllexecutable
MD5:73C8A5CD64FCF87186A6A9AC870DF509
SHA256:7722206DBA0CFB290F33093F9430CB770A160947001715AE11E6DBBFAEF1C0EE
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\Plugin\plg.dllexecutable
MD5:0CBC2D9703FEEAD9783439E551C2B673
SHA256:EA9ECF8723788FEEF6492BF938CDFAB1266A1558DFFE75E1F78A998320F96E39
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\src\NjRat 0.7D Green Edition SIGMA SOFT.slntext
MD5:7F94E0FB00C9562F3A4E75EB789B9B72
SHA256:03F1B56DB0C2A75C7D08779A4177D699809E839F67AAABFD7781081DB737A1C0
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\src\NjRat 0.7D Green Edition SIGMASOFT\My\MyComputer.vbtext
MD5:C9717C1BAF9A83F104F229C4BA69E7C6
SHA256:78FAF3CA541C78FBEA72B16EB6D3634CCB76EFC6A50E1FFE3CEA04C582C440CF
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\Plugin\sc2.dllexecutable
MD5:19967E886EDCD2F22F8D4A58C8EA3773
SHA256:3E5141C75B7746C0EB2B332082A165DEACB943CEF26BD84668E6B79B47BDFD93
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\Plugin\pw.dllexecutable
MD5:872401528FC94C90F3DE6658E776CC36
SHA256:3A1CC072EFFD8C38406A6FDDF4D8F49C5366BB0E32071311D90DB669940987CE
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\src\NjRat 0.7D Green Edition SIGMASOFT\My\Resources\Resources.vbtext
MD5:76861BB9FC9B5AC1BE6D83CBF351E8D6
SHA256:D4F779A4A93820FD8B923FA53F898B9592E5B45542BF2AF8D4D06D3EFCA2B1CB
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\src\NjRat 0.7D Green Edition SIGMASOFT\My\MySettings.settingsxml
MD5:C9BDCCB5565BD459317380FAE14D1634
SHA256:276C0F68FF287380AF1B934BFBE50B60A2FC35DB2AB20D63917629E1F029C5F5
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\src\NjRat 0.7D Green Edition SIGMASOFT\My\MyApplication.vbtext
MD5:E7EA435EFDE50708788B14EDC0E4A09E
SHA256:19A1179804754E178B0C24409DD5D04F2DFD08EC554A0DB709A3F65280BF1929
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
24
DNS requests
44
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2380
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
2380
firefox.exe
POST
184.24.77.61:80
http://r3.o.lencr.org/
unknown
unknown
2380
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
2380
firefox.exe
POST
184.24.77.61:80
http://r3.o.lencr.org/
unknown
unknown
2380
firefox.exe
POST
184.24.77.61:80
http://r3.o.lencr.org/
unknown
unknown
2380
firefox.exe
POST
18.245.65.219:80
http://ocsp.r2m02.amazontrust.com/
unknown
unknown
2380
firefox.exe
POST
142.250.186.35:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
2380
firefox.exe
POST
184.24.77.61:80
http://r3.o.lencr.org/
unknown
unknown
2380
firefox.exe
POST
184.24.77.61:80
http://r3.o.lencr.org/
unknown
unknown
2380
firefox.exe
POST
184.24.77.61:80
http://r3.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2380
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
2380
firefox.exe
172.217.18.10:443
safebrowsing.googleapis.com
whitelisted
2380
firefox.exe
34.107.243.93:443
push.services.mozilla.com
unknown
2380
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2380
firefox.exe
44.197.73.21:443
spocs.getpocket.com
AMAZON-AES
US
unknown
2380
firefox.exe
184.24.77.61:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
2380
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.237.239
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
whitelisted
spocs.getpocket.com
  • 44.197.73.21
  • 54.205.248.223
  • 3.214.112.20
  • 18.215.61.248
  • 3.219.12.119
  • 35.171.113.32
  • 18.235.58.129
  • 3.211.58.243
shared
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 44.197.73.21
  • 54.205.248.223
  • 3.214.112.20
  • 18.215.61.248
  • 3.219.12.119
  • 35.171.113.32
  • 18.235.58.129
  • 3.211.58.243
shared
r3.o.lencr.org
  • 184.24.77.61
  • 184.24.77.71
  • 184.24.77.54
shared
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted
a1887.dscq.akamai.net
  • 184.24.77.61
  • 184.24.77.71
  • 184.24.77.54
  • 2a02:26f0:3500:e::1732:835c
  • 2a02:26f0:3500:e::1732:8353
whitelisted

Threats

No threats detected
No debug info