| URL: | https://poc-imailer.hunet.co.kr/trace/checker.jsp?mailidx=4205128&linkno=10&seqidx=241782&service=0&dmidx=0&emidx=0&uidx=16&gidx=2&site=1&linkurl=https://www.happysuccess.or.kr/Story/SnsShareGate?shareType=K&num=6131 |
| Full analysis: | https://app.any.run/tasks/4bdf7d68-ee6d-437b-9b31-37a61911b2ea |
| Verdict: | Malicious activity |
| Analysis date: | November 13, 2023, 08:20:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| SHA1: | 880248F67771494F9E220807195313177F46A356 |
| SHA256: | 4ADFD366A784DFF9E0B1C085037BE8F37DEAA4980D413EB9A144F7CADA0344FA |
| SSDEEP: | 6:2OfJTA5xWNApkkQcK6xtvVYxnEGMOOGLKK687bkAjQlQ:2MTGWN23K6XMnEGoK6qkA2Q |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 284 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3428.6.303452312\1416924847" -childID 5 -isForBrowser -prefsHandle 4208 -prefMapHandle 3528 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6866b522-1643-454c-9a60-948abca5b4c0} 3428 "\\.\pipe\gecko-crash-server-pipe.3428" 3540 21d80110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 552 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3428.9.288262254\1943334111" -childID 8 -isForBrowser -prefsHandle 8504 -prefMapHandle 8508 -prefsLen 31103 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b6f4be7e-aaa0-4fe0-bbcf-a56f400b1488} 3428 "\\.\pipe\gecko-crash-server-pipe.3428" 8492 20b5f840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 664 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3428.4.1715791177\1852800222" -childID 3 -isForBrowser -prefsHandle 3764 -prefMapHandle 3780 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c1f9ca8a-d4b2-49ff-9017-9ef2f69cef6d} 3428 "\\.\pipe\gecko-crash-server-pipe.3428" 3808 20f6c280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 788 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3428.5.2142316634\1422971131" -childID 4 -isForBrowser -prefsHandle 3940 -prefMapHandle 3944 -prefsLen 34336 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b6d738fc-5317-45b7-8ebd-a9d2f1166ddf} 3428 "\\.\pipe\gecko-crash-server-pipe.3428" 3876 20f6c560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 988 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3428.8.1107819698\1199131745" -childID 7 -isForBrowser -prefsHandle 2312 -prefMapHandle 2336 -prefsLen 29626 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e54ce4d7-214c-481b-8103-7405c75ef2a6} 3428 "\\.\pipe\gecko-crash-server-pipe.3428" 2092 23d573f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1436 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3428.13.11383165\1337318019" -childID 12 -isForBrowser -prefsHandle 7980 -prefMapHandle 3012 -prefsLen 31256 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6d817a05-37a8-46d5-96b3-735d5156fdc9} 3428 "\\.\pipe\gecko-crash-server-pipe.3428" 7988 164ade00 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2312 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3428.7.301421738\215891569" -childID 6 -isForBrowser -prefsHandle 3764 -prefMapHandle 3536 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7d820ddc-1351-4835-b06f-0d11edc69a79} 3428 "\\.\pipe\gecko-crash-server-pipe.3428" 3932 21d80280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2492 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3428.14.1078944677\1082940631" -childID 13 -isForBrowser -prefsHandle 888 -prefMapHandle 3580 -prefsLen 31256 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4eb8ee6f-296c-4192-933c-0769844246e4} 3428 "\\.\pipe\gecko-crash-server-pipe.3428" 2680 133fb6d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2504 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3428.10.1586300597\66169030" -childID 9 -isForBrowser -prefsHandle 2596 -prefMapHandle 2580 -prefsLen 31256 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f9aa4894-2ada-4588-b8eb-083f70482065} 3428 "\\.\pipe\gecko-crash-server-pipe.3428" 3660 21d809b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2736 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3376) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 2166C0A101000000 | |||
| (PID) Process: | (3428) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 044CC1A101000000 | |||
| (PID) Process: | (3428) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (3428) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (3428) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (3428) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (3428) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (3428) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (3428) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (3428) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: D14E5F3C23B0D901 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.bin | binary | |
MD5:B1C8AA9861B461806C9E738511EDD6AE | SHA256:7CEA48E7ADD3340B36F47BA4EA2DED8D6CB0423FFC2A64B44D7E86E0507D6B70 | |||
| 3428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 3428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 3428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.tmp | binary | |
MD5:B1C8AA9861B461806C9E738511EDD6AE | SHA256:7CEA48E7ADD3340B36F47BA4EA2DED8D6CB0423FFC2A64B44D7E86E0507D6B70 | |||
| 3428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3428 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
3428 | firefox.exe | POST | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/gsrsaovsslca2018 | unknown | binary | 1.40 Kb | unknown |
3428 | firefox.exe | POST | 200 | 184.24.77.53:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3428 | firefox.exe | POST | 200 | 184.24.77.53:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3428 | firefox.exe | POST | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/gsrsaovsslca2018 | unknown | binary | 1.40 Kb | unknown |
3428 | firefox.exe | POST | 200 | 184.24.77.53:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3428 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
3428 | firefox.exe | POST | 200 | 184.24.77.53:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3428 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://status.thawte.com/ | unknown | binary | 471 b | unknown |
3428 | firefox.exe | POST | 200 | 184.24.77.53:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3428 | firefox.exe | 222.122.166.62:443 | poc-imailer.hunet.co.kr | Korea Telecom | KR | unknown |
3428 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
3428 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
3428 | firefox.exe | 3.214.21.201:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
3428 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
3428 | firefox.exe | 184.24.77.53:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
3428 | firefox.exe | 172.217.16.202:443 | safebrowsing.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
poc-imailer.hunet.co.kr |
| unknown |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
r3.o.lencr.org |
| shared |
firefox.settings.services.mozilla.com |
| whitelisted |