| URL: | https://wearedevs.net/d/JJSploit |
| Full analysis: | https://app.any.run/tasks/a207bc01-1226-45f3-92d1-518653c1c06d |
| Verdict: | Malicious activity |
| Analysis date: | May 01, 2022, 16:20:45 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | AF4F0F3F58AF746C6F1F8983436ACBD9 |
| SHA1: | 09E980C8D1D92C3DF8498BD3A725CB83F4314AAB |
| SHA256: | 484ABDB18866BC82426BE62FDF91D5C82FB9C951B25C22B00E1AA3EFC95E4B95 |
| SSDEEP: | 3:N8R/BApK83BQ:25BuBq |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 920 | "C:\Users\admin\AppData\Local\Programs\JJS-UI\JJS-UI.exe" --type=utility --field-trial-handle=1064,10150708239102304460,17302404249355172644,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --lang=en-US --service-sandbox-type=network --mojo-platform-channel-handle=1372 /prefetch:8 | C:\Users\admin\AppData\Local\Programs\JJS-UI\JJS-UI.exe | JJS-UI.exe | |
User: admin Company: GitHub, Inc. Integrity Level: MEDIUM Description: JJS-UI Exit code: 0 Version: 6.4.8 | ||||
| 1620 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3172.0.894616726\112218128" -parentBuildID 20201112153044 -prefsHandle 1008 -prefMapHandle 940 -prefsLen 1 -prefMapSize 238726 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3172 "\\.\pipe\gecko-crash-server-pipe.3172" 1228 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 83.0 | ||||
| 1656 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3172.27.321528967\2060865110" -childID 4 -isForBrowser -prefsHandle 8064 -prefMapHandle 3808 -prefsLen 8042 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3172 "\\.\pipe\gecko-crash-server-pipe.3172" 8000 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 | ||||
| 1856 | "C:\Program Files\Internet Explorer\iexplore.exe" https://www.youtube.com/c/Omnidev_ | C:\Program Files\Internet Explorer\iexplore.exe | — | JJS-UI.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) | ||||
| 1976 | "C:\Program Files\Internet Explorer\iexplore.exe" https://www.youtube.com/channel/UC3YNONzSHPW12m3AT48fMHw?view_as=subscriber | C:\Program Files\Internet Explorer\iexplore.exe | — | JJS-UI.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) | ||||
| 2044 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3172.6.1911519516\634708620" -childID 1 -isForBrowser -prefsHandle 3128 -prefMapHandle 3124 -prefsLen 245 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3172 "\\.\pipe\gecko-crash-server-pipe.3172" 3140 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 | ||||
| 2248 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3172.20.41564619\1053298849" -childID 3 -isForBrowser -prefsHandle 3812 -prefMapHandle 3808 -prefsLen 7470 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 3172 "\\.\pipe\gecko-crash-server-pipe.3172" 3824 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 | ||||
| 2592 | "C:\Users\admin\AppData\Local\Programs\JJS-UI\JJS-UI.exe" --type=gpu-process --field-trial-handle=1064,10150708239102304460,17302404249355172644,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --gpu-preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --mojo-platform-channel-handle=1076 --ignored=" --type=renderer " /prefetch:2 | C:\Users\admin\AppData\Local\Programs\JJS-UI\JJS-UI.exe | — | JJS-UI.exe |
User: admin Company: GitHub, Inc. Integrity Level: LOW Description: JJS-UI Exit code: 0 Version: 6.4.8 | ||||
| 2832 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://wearedevs.net/d/JJSploit" | C:\Program Files\Mozilla Firefox\firefox.exe | — | Explorer.EXE |
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 83.0 | ||||
| 2904 | "C:\Users\admin\Downloads\JJSploit_Installer.exe" | C:\Users\admin\Downloads\JJSploit_Installer.exe | firefox.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 6.4.8 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3172 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 3172 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 3172 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-wal | sqlite-wal | |
MD5:— | SHA256:— | |||
| 3172 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:— | SHA256:— | |||
| 3172 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3172 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:299A2B747C11E4BDA194E563FEA4A699 | SHA256:94EE461F62E8B4A0A65471A41E10C8C56722B73C0A019D76ACA7F5BAF109813E | |||
| 3172 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3172 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3172 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3172 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite-wal | sqlite-wal | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3172 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3172 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 471 b | whitelisted |
3172 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
3172 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
3172 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
3172 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 471 b | whitelisted |
3172 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3172 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
3172 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
3172 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3172 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | — | US | whitelisted |
3172 | firefox.exe | 143.204.201.62:443 | firefox.settings.services.mozilla.com | — | US | suspicious |
3172 | firefox.exe | 13.32.21.124:443 | content-signature-2.cdn.mozilla.net | Amazon.com, Inc. | US | unknown |
3172 | firefox.exe | 142.250.186.130:443 | pagead2.googlesyndication.com | Google Inc. | US | whitelisted |
3172 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3172 | firefox.exe | 142.250.185.234:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
3172 | firefox.exe | 142.250.186.131:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
3172 | firefox.exe | 104.26.6.147:443 | wearedevs.net | Cloudflare Inc | US | suspicious |
3172 | firefox.exe | 142.250.181.234:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
3172 | firefox.exe | 142.250.186.34:443 | adservice.google.co.uk | Google Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
location.services.mozilla.com |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
locprod2-elb-us-west-2.prod.mozaws.net |
| whitelisted |
wearedevs.net |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
cs9.wac.phicdn.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3172 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
3172 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
3172 | firefox.exe | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
3496 | JJS-UI.exe | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
3496 | JJS-UI.exe | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |