| File name: | holycat.exe |
| Full analysis: | https://app.any.run/tasks/e33f83aa-c9b7-41a2-8c9a-24d21c198ca2 |
| Verdict: | Malicious activity |
| Threats: | Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying. |
| Analysis date: | May 17, 2025, 14:28:32 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows, 10 sections |
| MD5: | F99312126CA35F943E26E6DB6832A581 |
| SHA1: | F200905C4F668D2385D1BBFD015CF8DD5206649B |
| SHA256: | 5AD6F5AF51159DA0CACD1AA4480813E0ED8BDF0039D8F5034FEE872EEB73A8AD |
| SSDEEP: | 49152:qZtDppy+Cderlp8rsaWgsJgAe1tVaR6Ix:ozyNA5R6Ix |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2025:05:17 14:16:26+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, Large address aware, No debug |
| PEType: | PE32+ |
| LinkerVersion: | 2.44 |
| CodeSize: | 777728 |
| InitializedDataSize: | 272896 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x13f0 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 536 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2188 -parentBuildID 20240213221259 -prefsHandle 2180 -prefMapHandle 2168 -prefsLen 31031 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {75fc7ef5-6c68-4792-9237-f396d55e926b} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 17e32a82910 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2320 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6596 -childID 20 -isForBrowser -prefsHandle 6344 -prefMapHandle 4456 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {cb944d11-7c94-45d4-aa78-9839d0d87084} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 17e45faf690 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2384 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6600 -childID 21 -isForBrowser -prefsHandle 6608 -prefMapHandle 6612 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4ac21d0c-74e4-4687-b9a7-0c295c4149c8} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 17e45faf850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2800 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2728 -childID 1 -isForBrowser -prefsHandle 2780 -prefMapHandle 2816 -prefsLen 32306 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {2ad727ca-4cc4-4635-8d73-6e899b5c6b7b} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 17e446c1f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 3096 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7028 -childID 24 -isForBrowser -prefsHandle 7024 -prefMapHandle 7020 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {0e618411-8c58-4576-bae8-9c2224f03546} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 17e45faff50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 4880 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6064 -childID 16 -isForBrowser -prefsHandle 6152 -prefMapHandle 6156 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e207f632-927f-4d6c-8b37-b391428d7c02} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 17e45faf150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 5416 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7156 -childID 26 -isForBrowser -prefsHandle 7164 -prefMapHandle 6924 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b22eca68-c2a1-43aa-83cc-254c2d327fb5} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 17e460f3f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 5452 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6892 -childID 23 -isForBrowser -prefsHandle 6884 -prefMapHandle 6880 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {82ce1b5d-95ce-44e6-ba0d-d71f8295aaa1} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 17e45fafd90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 5556 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6236 -childID 17 -isForBrowser -prefsHandle 6244 -prefMapHandle 6248 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {9f1c3215-2a10-4a62-bda5-1203ba4667eb} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 17e45faf310 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 5608 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4212 -childID 2 -isForBrowser -prefsHandle 4224 -prefMapHandle 4220 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {fa5ee5f5-f6cf-4f55-878d-7db19c9fac76} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 17e46bdcbd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (8016) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (8656) notepad.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosX |
Value: 235 | |||
| (PID) Process: | (8656) notepad.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosY |
Value: 102 | |||
| (PID) Process: | (8656) notepad.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosDX |
Value: 960 | |||
| (PID) Process: | (8656) notepad.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosDY |
Value: 491 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7320 | holycat.exe | C:\Users\admin\Documents\budgetwhen.rtf | binary | |
MD5:7FE9DE24D0F5F1DBD7C6F4EF3B59B25F | SHA256:6C270386002D1E2062EE025F6605B5140FC1505B60EF1B37B4392818961C8236 | |||
| 7320 | holycat.exe | C:\Users\admin\Documents\desktop.hc | binary | |
MD5:BD830C41D67802AD520A224939EFAE49 | SHA256:EBCB432AA45E161BA7786F5A179E6ED2E2F85421D6CC87040921D92108073AB9 | |||
| 7320 | holycat.exe | C:\Users\admin\Documents\desktop.ini | binary | |
MD5:BD830C41D67802AD520A224939EFAE49 | SHA256:EBCB432AA45E161BA7786F5A179E6ED2E2F85421D6CC87040921D92108073AB9 | |||
| 7320 | holycat.exe | C:\Users\admin\Documents\engineeringreading.hc | binary | |
MD5:B81F21B496547533D17F687546BC744F | SHA256:6D661047B21977A5D2CC0DA3E3E6B63424816F07DD81A7E9457E68262625ADD1 | |||
| 7320 | holycat.exe | C:\Users\admin\Documents\budgetwhen.hc | binary | |
MD5:7FE9DE24D0F5F1DBD7C6F4EF3B59B25F | SHA256:6C270386002D1E2062EE025F6605B5140FC1505B60EF1B37B4392818961C8236 | |||
| 7320 | holycat.exe | C:\Users\admin\Documents\engineeringreading.rtf | binary | |
MD5:B81F21B496547533D17F687546BC744F | SHA256:6D661047B21977A5D2CC0DA3E3E6B63424816F07DD81A7E9457E68262625ADD1 | |||
| 7320 | holycat.exe | C:\Users\admin\Documents\minutetotal.rtf | binary | |
MD5:A430158BCE7B1BE1EC1EC6D73602ADC9 | SHA256:8438128B5ABDF30930C4BECF2D88B42F7A7D3B807986AAB92CAE8E83F064C2BA | |||
| 7320 | holycat.exe | C:\Users\admin\Documents\OneNote Notebooks\My Notebook\Quick Notes.one | binary | |
MD5:A745FCD6A6044EFDE5F19766D8E3FB45 | SHA256:3BD02E6092968CA7BB1C4C9C4DFE946AA7F7A07F82B5363AD052316C412AF649 | |||
| 7320 | holycat.exe | C:\Users\admin\Documents\OneNote Notebooks\My Notebook\Open Notebook.hc | binary | |
MD5:04ED8768B2D6014D5D89B12BD48D3879 | SHA256:27F88AFF07A9D21A1FD2BE3BFF0406E8ADD798C6EC0DBD838B10B7175501F74D | |||
| 7320 | holycat.exe | C:\Users\admin\Documents\OneNote Notebooks\My Notebook\Open Notebook.onetoc2 | binary | |
MD5:04ED8768B2D6014D5D89B12BD48D3879 | SHA256:27F88AFF07A9D21A1FD2BE3BFF0406E8ADD798C6EC0DBD838B10B7175501F74D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
8016 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
8016 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
8016 | firefox.exe | POST | 200 | 216.58.206.67:80 | http://o.pki.goog/s/wr3/FIY | unknown | — | — | whitelisted |
8016 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
8016 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
8016 | firefox.exe | POST | 200 | 184.24.77.45:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
8016 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.216.77.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6544 | svchost.exe | 20.190.160.132:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
8016 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
8016 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |