| URL: | https://www.youtube.com/redirect?event=video_description&redir_token=QUFFLUhqbkwyeGZuYnh1cGcySGM2X25BbzZTWDVXdU9ud3xBQ3Jtc0tuVnZNRmZjelNRaDNnb09DaWtyS3hIU3VWaVItUE12QWxZN2xjOUtuUFNnQVFGOXdFZlA1OG0zZ1FhWDhMM29zc0p2MmtCTWpUbmx5amNITFVzUXBBMHp4d0I1UkVMZXZnVVd2UEY3NGMzNDIzbnBVYw&q=https%3A%2F%2Foxy.cloud%2Fd%2FFVBe |
| Full analysis: | https://app.any.run/tasks/2510798a-6192-4df1-ac24-baec931d2202 |
| Verdict: | Malicious activity |
| Threats: | Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links. |
| Analysis date: | November 22, 2021, 17:15:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 5097896DEE9EBC7221CE62D33C7CDBC8 |
| SHA1: | 29BC7DFBAA0CF24AEEAB4C3DD0030C64ABEA27B6 |
| SHA256: | 3F8A3EF100F1D2C6EDF1AB97D56B4563EE86C2F3ECD844EBF8D263422108812C |
| SSDEEP: | 6:2OLUxGKmKLqZuNuyhLMcB6xNwvSkyXTRjd3Mn9ol573zOENBn:2jGRfuNuRhLwvsXRJMnallzB |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1468 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 1920 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\otc3fix.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2484 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3476.0.206386730\1207670917" -parentBuildID 20201112153044 -prefsHandle 1116 -prefMapHandle 1108 -prefsLen 1 -prefMapSize 238726 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3476 "\\.\pipe\gecko-crash-server-pipe.3476" 1200 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 2528 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3476.13.977324357\1777928894" -childID 2 -isForBrowser -prefsHandle 1980 -prefMapHandle 1780 -prefsLen 6644 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3476 "\\.\pipe\gecko-crash-server-pipe.3476" 1856 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 2816 | "C:\Users\admin\Desktop\ezinjector_reborn.exe" | C:\Users\admin\Desktop\ezinjector_reborn.exe | Explorer.EXE | ||||||||||||
User: admin Company: GitHub, Inc. Integrity Level: MEDIUM Description: Atom Exit code: 3221225477 Version: 1.58.0 Modules
| |||||||||||||||
| 3180 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3476.6.1579199003\1532972627" -childID 1 -isForBrowser -prefsHandle 4280 -prefMapHandle 4276 -prefsLen 245 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3476 "\\.\pipe\gecko-crash-server-pipe.3476" 4292 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 3372 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | ezinjector_reborn.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET ClickOnce Launch Utility Exit code: 0 Version: 4.0.30319.34209 built by: FX452RTMGDR Modules
| |||||||||||||||
| 3392 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1920.6453\ezinjector_reborn.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1920.6453\ezinjector_reborn.exe | WinRAR.exe | ||||||||||||
User: admin Company: GitHub, Inc. Integrity Level: MEDIUM Description: Atom Exit code: 3221225477 Version: 1.58.0 Modules
| |||||||||||||||
| 3420 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | ezinjector_reborn.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET ClickOnce Launch Utility Exit code: 0 Version: 4.0.30319.34209 built by: FX452RTMGDR Modules
| |||||||||||||||
| 3476 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://www.youtube.com/redirect?event=video_description&redir_token=QUFFLUhqbkwyeGZuYnh1cGcySGM2X25BbzZTWDVXdU9ud3xBQ3Jtc0tuVnZNRmZjelNRaDNnb09DaWtyS3hIU3VWaVItUE12QWxZN2xjOUtuUFNnQVFGOXdFZlA1OG0zZ1FhWDhMM29zc0p2MmtCTWpUbmx5amNITFVzUXBBMHp4d0I1UkVMZXZnVVd2UEY3NGMzNDIzbnBVYw&q=https%3A%2F%2Foxy.cloud%2Fd%2FFVBe | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| (PID) Process: | (3988) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 9478701E01000000 | |||
| (PID) Process: | (3476) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 2724721E01000000 | |||
| (PID) Process: | (3476) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (3476) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (3476) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (3476) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (3476) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|ServicesSettingsServer |
Value: https://firefox.settings.services.mozilla.com/v1 | |||
| (PID) Process: | (3476) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash |
Value: 97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E | |||
| (PID) Process: | (3476) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3476) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3476 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 3476 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 3476 | firefox.exe | C:\Users\admin\AppData\Local\Temp\mz_etilqs_SmNAAu3OOBepSJI | binary | |
MD5:— | SHA256:— | |||
| 3476 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:— | SHA256:— | |||
| 3476 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journal | binary | |
MD5:— | SHA256:— | |||
| 3476 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite-wal | sqlite-wal | |
MD5:— | SHA256:— | |||
| 3476 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-wal | sqlite-wal | |
MD5:— | SHA256:— | |||
| 3476 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\settings\main\ms-language-packs\asrouter.ftl | text | |
MD5:— | SHA256:— | |||
| 3476 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3476 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3476 | firefox.exe | POST | 200 | 142.250.184.227:80 | http://ocsp.pki.goog/gts1c3 | US | der | 471 b | whitelisted |
3476 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3476 | firefox.exe | POST | 200 | 5.45.205.244:80 | http://yandex.ocsp-responder.com/ | RU | der | 1.48 Kb | whitelisted |
3476 | firefox.exe | POST | 200 | 104.18.31.182:80 | http://ocsp.usertrust.com/ | US | der | 471 b | whitelisted |
3476 | firefox.exe | POST | 200 | 2.16.186.11:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
3476 | firefox.exe | POST | 200 | 2.16.186.11:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
3476 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3476 | firefox.exe | POST | 200 | 2.16.186.11:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
3476 | firefox.exe | POST | 200 | 2.16.186.11:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
3476 | firefox.exe | POST | 200 | 142.250.184.227:80 | http://ocsp.pki.goog/gts1c3 | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 142.250.186.99:443 | www.gstatic.com | Google Inc. | US | whitelisted |
3476 | firefox.exe | 142.250.186.99:443 | www.gstatic.com | Google Inc. | US | whitelisted |
3476 | firefox.exe | 142.250.186.74:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
— | — | 142.250.184.227:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
3476 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | — | US | whitelisted |
3476 | firefox.exe | 142.250.184.238:443 | www.youtube.com | Google Inc. | US | whitelisted |
— | — | 34.212.188.196:443 | push.services.mozilla.com | Amazon.com, Inc. | US | unknown |
3476 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3476 | firefox.exe | 13.225.78.36:443 | firefox-settings-attachments.cdn.mozilla.net | — | US | whitelisted |
3476 | firefox.exe | 13.224.195.32:443 | snippets.cdn.mozilla.net | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
www.youtube.com |
| whitelisted |
youtube-ui.l.google.com |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
pki-goog.l.google.com |
| whitelisted |
content-signature-2.cdn.mozilla.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
— | — | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
— | — | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
— | — | Potentially Bad Traffic | ET DNS Query for .to TLD |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
3476 | firefox.exe | Generic Protocol Command Decode | SURICATA STREAM ESTABLISHED invalid ack |