| URL: | https://teraboxapp.com/s/1vtunKRkzf1iE-ERhsMjChg |
| Full analysis: | https://app.any.run/tasks/80389a5c-9a63-43fa-86b8-f48f4907bf96 |
| Verdict: | Malicious activity |
| Analysis date: | November 14, 2023, 15:28:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| SHA1: | 2CEE74111C5C90605A4E5BB327E46A0D2ABA0730 |
| SHA256: | 88EE668056D19845F72F537F9DE61CA7A819B423426A6E5BC93EA9AFC4359998 |
| SSDEEP: | 3:N8IUqWC+rVNy4Q:2IVgnyn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3448.5.39228422\485940659" -childID 4 -isForBrowser -prefsHandle 3900 -prefMapHandle 3668 -prefsLen 29208 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ee5dad26-fe5f-4025-b884-2a535b72b4fb} 3448 "\\.\pipe\gecko-crash-server-pipe.3448" 3916 189a7110 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 968 | "C:\Users\admin\AppData\Roaming\TeraBox\TeraBoxRender.exe" --type=renderer --no-sandbox --log-file="C:\Users\admin\AppData\Roaming\TeraBox\debug.log" --field-trial-handle=2008,5653900821654063532,11684110516160924601,131072 --enable-features=CastMediaRouteProvider --lang=en-US --locales-dir-path="C:\Users\admin\AppData\Roaming\TeraBox\browserres\locales" --log-file="C:\Users\admin\AppData\Roaming\TeraBox\debug.log" --log-severity=disable --resources-dir-path="C:\Users\admin\AppData\Roaming\TeraBox\browserres" --user-agent="Mozilla/5.0; (Windows NT 6.1); AppleWebKit/537.36; (KHTML, like Gecko); Chrome/86.0.4240.198; Safari/537.36; terabox;1.25.0.12;PC;PC-Windows;6.1.7601;WindowsTeraBox" --disable-extensions --ppapi-flash-path="C:\Users\admin\AppData\Roaming\TeraBox\pepflashplayer.dll" --ppapi-flash-version=20.0.0.306 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3156 /prefetch:1 | C:\Users\admin\AppData\Roaming\TeraBox\TeraBoxRender.exe | — | TeraBox.exe | |||||||||||
User: admin Company: Flextech Inc. Integrity Level: MEDIUM Description: TeraBoxRender Exit code: 0 Version: 2.0.1.1 Modules
| |||||||||||||||
| 1584 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3448.8.1390210872\1085437663" -childID 7 -isForBrowser -prefsHandle 8472 -prefMapHandle 8476 -prefsLen 30599 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fa02eac1-58fe-48c0-94c1-f7014be1735c} 3448 "\\.\pipe\gecko-crash-server-pipe.3448" 8460 165b63f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1608 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3448.4.1455517300\584608503" -childID 3 -isForBrowser -prefsHandle 3668 -prefMapHandle 3672 -prefsLen 34335 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1460e4e4-f91e-4345-aba2-5566b0de1179} 3448 "\\.\pipe\gecko-crash-server-pipe.3448" 3688 13765840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1840 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3448.6.1387312785\435902154" -childID 5 -isForBrowser -prefsHandle 4048 -prefMapHandle 4028 -prefsLen 29208 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {34f6486e-f113-4b55-bb81-221994f354ce} 3448 "\\.\pipe\gecko-crash-server-pipe.3448" 4016 189a7280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2088 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3448.7.1295580000\618693695" -childID 6 -isForBrowser -prefsHandle 4208 -prefMapHandle 4212 -prefsLen 29208 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {10a16b2d-ade5-4293-a52a-cf8b400c1e4f} 3448 "\\.\pipe\gecko-crash-server-pipe.3448" 4196 189a73f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2412 | "C:\Users\admin\AppData\Roaming\TeraBox\TeraBoxHost.exe" -PluginId 1502 -PluginPath "C:\Users\admin\AppData\Roaming\TeraBox\kernel.dll" -ChannelName terabox.2792.0.244596849\2109353274 -QuitEventName TERABOX_KERNEL_SDK_997C8EFA-C5ED-47A0-A6A8-D139CD6017F4 -TeraBoxId "" -IP "192.168.100.130" -PcGuid "TBIMXV2-O_D16162E105CE418582333FB6A0E8C0E4-C_0-D_4d51303030302031202020202020202020202020-M_12A9866C77DE-V_C4BA3647" -Version "1.25.0.12" -DiskApiHttps 0 -StatisticHttps 0 -ReportCrash 1 | C:\Users\admin\AppData\Roaming\TeraBox\TeraBoxHost.exe | TeraBox.exe | ||||||||||||
User: admin Company: Flextech Inc. Integrity Level: MEDIUM Description: TeraBoxHost Exit code: 0 Version: 1.25.0.12 Modules
| |||||||||||||||
| 2416 | C:\Users\admin\AppData\Roaming\TeraBox\TeraBoxWebService.exe | C:\Users\admin\AppData\Roaming\TeraBox\TeraBoxWebService.exe | TeraBox_sl_b_1.25.0.12.exe | ||||||||||||
User: admin Company: Flextech Inc. Integrity Level: MEDIUM Description: TeraBoxWebService Exit code: 0 Version: 1.25.0.12 Modules
| |||||||||||||||
| 2476 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3448.11.449264219\226229166" -childID 8 -isForBrowser -prefsHandle 2020 -prefMapHandle 3308 -prefsLen 31121 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7be2f214-f259-4372-8415-c4a80b202648} 3448 "\\.\pipe\gecko-crash-server-pipe.3448" 1908 167e3840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2484 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3448.10.162717432\343731034" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 3480 -prefMapHandle 3476 -prefsLen 36024 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {caeab6d6-812f-4f76-9868-d3aca0f01bc0} 3448 "\\.\pipe\gecko-crash-server-pipe.3448" 8356 19c820d0 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (3436) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 2166C0A101000000 | |||
| (PID) Process: | (3448) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 044CC1A101000000 | |||
| (PID) Process: | (3448) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (3448) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (3448) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (3448) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (3448) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (3448) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (3448) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (3448) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: D14E5F3C23B0D901 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3448 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3448 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3448 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:B7A3C61D0C144CC5E166B1E769CA8F8C | SHA256:7FADCB77FFACA6B9E9F15C6F1CD3AAD4C20DCD90FA92429A627A3A7110CA2644 | |||
| 3448 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3448 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:569715507E55EEC5E2D63F088C9EE0CE | SHA256:87A9C50E0A6B23DE0092305F10EA10AE58A26AD71D6743AEDC8181FE62F1CFF3 | |||
| 3448 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3448 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 3448 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3448 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.tmp | binary | |
MD5:63B1BB87284EFE954E1C3AE390E7EE44 | SHA256:B017EE25A7F5C09EB4BF359CA721D67E6E9D9F95F8CE6F741D47F33BDE6EF73A | |||
| 3448 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journal | binary | |
MD5:26D38879762CF55A514870386E22BC10 | SHA256:5FA06C44EED86489EDEAD8D946C97E04071E7D2F0AA6F717D1EB54EB0451ABC1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3448 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3448 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 727 b | unknown |
3448 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3448 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3448 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
3448 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3448 | firefox.exe | POST | 200 | 163.181.56.214:80 | http://ocsp.dcocsp.cn/ | unknown | binary | 471 b | unknown |
3448 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3448 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 727 b | unknown |
3448 | firefox.exe | POST | 200 | 163.181.56.214:80 | http://ocsp.dcocsp.cn/ | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3448 | firefox.exe | 210.148.85.41:443 | teraboxapp.com | Internet Initiative Japan Inc. | JP | unknown |
3448 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
3448 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
3448 | firefox.exe | 18.235.78.81:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
3448 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
3448 | firefox.exe | 184.24.77.48:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
3448 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
teraboxapp.com |
| unknown |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
r3.o.lencr.org |
| shared |
firefox.settings.services.mozilla.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2792 | TeraBox.exe | Misc activity | ET INFO Observed Google DNS over HTTPS Domain (dns .google in TLS SNI) |
Process | Message |
|---|---|
TeraBoxHost.exe | vast_media--[2023-11-14 15:32:31:457] Initialized hardware_type=3001
|
TeraBoxHost.exe | vast_media--[2023-11-14 15:32:31:456] Initialized sdl_video_render_driver=software
|
TeraBoxHost.exe | vast_media--[2023-11-14 15:32:31:457] Initialized sdl_audio_play_driver=directsound
|