| URL: | https://graph.org/FREE-VALORANT-HACK-07-19-3 |
| Full analysis: | https://app.any.run/tasks/28ba9ce3-559c-4057-816a-7b29cfcff480 |
| Verdict: | Malicious activity |
| Threats: | Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links. |
| Analysis date: | July 19, 2023, 20:32:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 5C436A4355D31217EF27881BC7CB6EA7 |
| SHA1: | C343AB178BF3C689EB3EDDCC36D5DFC54E0CE4FC |
| SHA256: | 7BE5FC360020D6A73CF922E0808CC65A647B1684EE1BF596D3460BD1303CC7F1 |
| SSDEEP: | 3:N82EnijQhgqGp5Wn:22cijPrp5W |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | C:\Windows\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 272 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2556.12.1068154803\55613555" -childID 10 -isForBrowser -prefsHandle 7136 -prefMapHandle 7140 -prefsLen 31547 -prefMapSize 242647 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {207554d4-b4af-45b1-b4f3-5d6249f93759} 2556 "\\.\pipe\gecko-crash-server-pipe.2556" 7124 26ae3e58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1912 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2556.6.1503329859\1947380226" -childID 4 -isForBrowser -prefsHandle 2216 -prefMapHandle 2204 -prefsLen 28631 -prefMapSize 242647 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a43b6598-b44c-44de-bd8e-24ee73b4fe23} 2556 "\\.\pipe\gecko-crash-server-pipe.2556" 2264 d85e58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2460 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2556.5.1913081787\1751268074" -parentBuildID 20230710165010 -prefsHandle 2668 -prefMapHandle 2672 -prefsLen 25927 -prefMapSize 242647 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f0139326-e067-4336-adb6-b55496a0a364} 2556 "\\.\pipe\gecko-crash-server-pipe.2556" 2616 d81258 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2556 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://graph.org/FREE-VALORANT-HACK-07-19-3" | C:\Program Files\Mozilla Firefox\firefox.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2576 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2556.0.1473837089\802537323" -parentBuildID 20230710165010 -prefsHandle 1528 -prefMapHandle 1320 -prefsLen 24055 -prefMapSize 242647 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d476f99a-0687-40ab-af4c-6f0409f7dfe1} 2556 "\\.\pipe\gecko-crash-server-pipe.2556" 1248 13c51b58 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2800 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2556.2.473134251\345421666" -childID 1 -isForBrowser -prefsHandle 2180 -prefMapHandle 2036 -prefsLen 23405 -prefMapSize 242647 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c1920584-30ca-4285-b6b7-921357a0d2b0} 2556 "\\.\pipe\gecko-crash-server-pipe.2556" 2192 145fd258 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2824 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2556.13.366318526\1098959597" -childID 11 -isForBrowser -prefsHandle 7684 -prefMapHandle 7692 -prefsLen 31547 -prefMapSize 242647 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c7939780-a2a2-4775-bb70-2e1e93ee4bdd} 2556 "\\.\pipe\gecko-crash-server-pipe.2556" 7688 284c0258 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2872 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2556.7.875215885\1143543252" -childID 5 -isForBrowser -prefsHandle 2396 -prefMapHandle 2356 -prefsLen 28631 -prefMapSize 242647 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d4302565-ba33-4fbd-83ec-2b328b6d5d69} 2556 "\\.\pipe\gecko-crash-server-pipe.2556" 2040 16b55a58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2888 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2556.3.1065290155\2143685108" -childID 2 -isForBrowser -prefsHandle 2820 -prefMapHandle 2816 -prefsLen 25821 -prefMapSize 242647 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1e0bcf6c-5f25-4607-bf96-3c0e2f3f9971} 2556 "\\.\pipe\gecko-crash-server-pipe.2556" 2832 1b6c5d58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (2556) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0000000000000000 | |||
| (PID) Process: | (2556) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (2556) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2556) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000008F000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2556) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\155\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2556) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|ScreenX |
Value: 4 | |||
| (PID) Process: | (2556) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|ScreenY |
Value: 4 | |||
| (PID) Process: | (2556) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Width |
Value: 1152 | |||
| (PID) Process: | (2556) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Height |
Value: 622 | |||
| (PID) Process: | (2556) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Maximized |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\webappsstore.sqlite-wal | — | |
MD5:— | SHA256:— | |||
| 2556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cookies.sqlite-shm | binary | |
MD5:F18993A92ABC693AC86FCC5FB9AF1F6B | SHA256:E313AACBD11281EC67B7E8834BE1A125AE1BB65440BAB5EA7FADD43CC14268DC | |||
| 2556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20230710165010 | text | |
MD5:6467179A4324D9C6D134D26A808BD092 | SHA256:6507CCA05311093F3498A47865BFB71D1586C61A02393E7987539E58574D0430 | |||
| 2556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\extensions.json | text | |
MD5:9D2F95C5091997A2B237D0530F53CB72 | SHA256:2C06EFF08658AE2F6A83C890190646D5881F7771BF4017EA4EDC56EF39FAE2D5 | |||
| 2556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\extensions.json.tmp | text | |
MD5:9D2F95C5091997A2B237D0530F53CB72 | SHA256:2C06EFF08658AE2F6A83C890190646D5881F7771BF4017EA4EDC56EF39FAE2D5 | |||
| 2556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\compatibility.ini | text | |
MD5:C6998EF9E767E571FE74299C971B9C98 | SHA256:69C387E1BE9E3C5A5BE3B767F5734E7E31755B67C3F6F409D175FB9265D53F2E | |||
| 2556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | — | |
MD5:— | SHA256:— | |||
| 2556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\webappsstore.sqlite-shm | binary | |
MD5:F5D5904A6B330DFDCF2FB10721D83634 | SHA256:B6C2E3937FFCE52E774C335AD7CAF753BA1062B1419C99DED699A16F99BBC43C | |||
| 2556 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\ls-archive-tmp.sqlite-journal | binary | |
MD5:27490F6B65B22DFF76467FBDFEC0C9D6 | SHA256:5359B7B219F9AADD1716BA6854AB24E4565FE50D6BC432A708F51E2422D6CAFB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2556 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2556 | firefox.exe | POST | — | 2.19.126.162:80 | http://r3.o.lencr.org/ | unknown | — | — | shared |
2556 | firefox.exe | POST | — | 192.124.249.41:80 | http://ocsp.godaddy.com/ | US | — | — | whitelisted |
2556 | firefox.exe | POST | 200 | 2.19.126.162:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | shared |
2556 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | US | text | 90 b | whitelisted |
2556 | firefox.exe | POST | 200 | 192.124.249.41:80 | http://ocsp.godaddy.com/ | US | der | 2.06 Kb | whitelisted |
2556 | firefox.exe | POST | 200 | 2.19.126.162:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | shared |
2556 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2556 | firefox.exe | POST | 200 | 2.19.126.162:80 | http://r3.o.lencr.org/ | unknown | der | 503 b | shared |
2556 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2556 | firefox.exe | 149.154.164.13:443 | graph.org | Telegram Messenger Inc | GB | suspicious |
2556 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
2556 | firefox.exe | 34.193.43.112:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
2556 | firefox.exe | 34.211.118.46:443 | shavar.services.mozilla.com | AMAZON-02 | US | unknown |
2556 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | suspicious |
2556 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | suspicious |
2556 | firefox.exe | 35.244.181.201:443 | aus5.mozilla.org | GOOGLE | US | suspicious |
2556 | firefox.exe | 52.24.231.34:443 | location.services.mozilla.com | AMAZON-02 | US | unknown |
2556 | firefox.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
graph.org |
| suspicious |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
firefox.settings.services.mozilla.com |
| whitelisted |
prod.remote-settings.prod.webservices.mozgcp.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2556 | firefox.exe | Misc activity | ET INFO Observed Telegram Domain (t .me in TLS SNI) |
324 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
324 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
324 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
324 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
324 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
324 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
324 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
324 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
324 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |