| URL: | redlib.felix.onthewifi.com |
| Full analysis: | https://app.any.run/tasks/fad98eba-6614-47c4-8bb3-30c2d1661a13 |
| Verdict: | Malicious activity |
| Analysis date: | March 04, 2026, 09:08:53 |
| OS: | Ubuntu 22.04.2 |
| MD5: | 7C5877046818494B4B8B18E6ACDCF2EB |
| SHA1: | C9CB9ECB3588CCE45425AA0E8AA155894EDDB609 |
| SHA256: | A2C800B637D58E8E9F7CD627D7645F3ADB69F1BED592BB2832DF7C790A9558B8 |
| SSDEEP: | 3:bdoS/QLGT:bySGK |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 415 | /lib/systemd/systemd-resolved | /usr/lib/systemd/systemd-resolved | systemd | ||||||||||||
User: systemd-resolve Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1972 | /bin/sh -c "DISPLAY=:0 sudo --preserve-env=SSLKEYLOGFILE -iu user google-chrome-stable --disable-features=HttpsUpgrades,HttpsFirstModeV2,HttpsOnlyMode,HttpsFirstBalancedMode --no-first -run --no-default-browser-check redlib\.felix\.onthewifi\.com " | /usr/bin/dash | — | 2EwNpII9hL0vkNEQ | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1973 | sudo --preserve-env=SSLKEYLOGFILE -iu user google-chrome-stable --disable-features=HttpsUpgrades,HttpsFirstModeV2,HttpsOnlyMode,HttpsFirstBalancedMode --no-first -run --no-default-browser-check redlib.felix.onthewifi.com | /usr/bin/sudo | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1974 | /usr/bin/google-chrome-stable --disable-features=HttpsUpgrades,HttpsFirstModeV2,HttpsOnlyMode,HttpsFirstBalancedMode --no-first -run --no-default-browser-check redlib.felix.onthewifi.com | /opt/google/chrome/chrome | — | sudo | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1975 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1976 | readlink -f /usr/bin/google-chrome-stable | /usr/bin/readlink | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1977 | dirname /opt/google/chrome/google-chrome | /usr/bin/dirname | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1978 | mkdir -p /home/user/.local/share/applications | /usr/bin/mkdir | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1979 | cat | /usr/bin/cat | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1980 | cat | /usr/bin/cat | — | chrome | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1974 | chrome | /home/user/.config/google-chrome/ShaderCache/data_3 | binary | |
MD5:— | SHA256:— | |||
| 1974 | chrome | /home/user/.config/google-chrome/ShaderCache/data_2 | binary | |
MD5:— | SHA256:— | |||
| 1974 | chrome | /home/user/.config/google-chrome/ShaderCache/data_0 | binary | |
MD5:— | SHA256:— | |||
| 1974 | chrome | /home/user/.config/google-chrome/Default/GPUCache/data_0 | binary | |
MD5:— | SHA256:— | |||
| 1974 | chrome | /home/user/.config/google-chrome/Default/GPUCache/data_3 | binary | |
MD5:— | SHA256:— | |||
| 1974 | chrome | /home/user/.config/google-chrome/Default/GPUCache/data_2 | binary | |
MD5:— | SHA256:— | |||
| 2015 | chrome | /home/user/.cache/mesa_shader_cache/index | binary | |
MD5:— | SHA256:— | |||
| 2100 | chrome | /home/user/.cache/mesa_shader_cache/index | binary | |
MD5:— | SHA256:— | |||
| 2116 | chrome | /home/user/.cache/mesa_shader_cache/index | binary | |
MD5:— | SHA256:— | |||
| 2145 | chrome | /home/user/.cache/mesa_shader_cache/index | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 91.189.91.48:80 | http://connectivity-check.ubuntu.com/ | GB | — | — | whitelisted |
2021 | chrome | GET | 200 | 142.250.201.163:443 | https://clientservices.googleapis.com/chrome-variations/seed?osname=linux&channel=stable&milestone=141 | US | compressed | 56.1 Kb | whitelisted |
2021 | chrome | POST | 200 | 142.251.208.174:443 | https://android.clients.google.com/checkin | US | binary | 496 b | whitelisted |
2021 | chrome | POST | 200 | 142.251.208.174:443 | https://android.clients.google.com/c2dm/register3 | US | text | 30 b | whitelisted |
2021 | chrome | GET | 200 | 172.217.16.206:80 | http://clients2.google.com/time/1/current?cup2key=9:7331jZvwf9G-Cqh02CgNCxxqxwV0mGgkwEECqU1s10M&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | US | text | 107 b | whitelisted |
2021 | chrome | POST | 200 | 142.251.208.174:443 | https://android.clients.google.com/c2dm/register3 | US | text | 30 b | whitelisted |
2021 | chrome | GET | 301 | 82.66.176.223:80 | http://redlib.felix.onthewifi.com/ | FR | html | 166 b | unknown |
2021 | chrome | POST | 200 | 142.251.208.174:443 | https://android.clients.google.com/c2dm/register3 | US | text | 30 b | whitelisted |
2021 | chrome | GET | 200 | 82.66.176.223:443 | https://redlib.felix.onthewifi.com/ | FR | — | 48.9 Kb | unknown |
2021 | chrome | POST | 200 | 216.58.206.67:443 | https://update.googleapis.com/service/update2/json?cup2key=15:2VVUb7xYsOaQ1CgLzBfBUvlxRIUThOLg1CU1ndRf8M4&cup2hreq=276b8295518a10cfda4517cf3fb268ffab7a34c1e46d266a7a3e7da6b576cefb | US | text | 289 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
456 | avahi-daemon | 224.0.0.251:5353 | — | — | — | whitelisted |
— | — | 91.189.91.48:80 | connectivity-check.ubuntu.com | CANONICAL-AS | GB | whitelisted |
— | — | 79.127.216.203:443 | odrs.gnome.org | CDN77 _ | GB | whitelisted |
— | — | 185.125.188.59:443 | api.snapcraft.io | CANONICAL-AS | GB | whitelisted |
2021 | chrome | 172.217.16.206:80 | clients2.google.com | GOOGLE | US | whitelisted |
2021 | chrome | 142.250.201.163:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
473 | snapd | 185.125.188.57:443 | api.snapcraft.io | CANONICAL-AS | GB | whitelisted |
2021 | chrome | 142.251.208.170:443 | safebrowsingohttpgateway.googleapis.com | GOOGLE | US | whitelisted |
2021 | chrome | 82.66.176.223:80 | redlib.felix.onthewifi.com | PROXAD | FR | unknown |
2021 | chrome | 142.251.127.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
odrs.gnome.org |
| whitelisted |
connectivity-check.ubuntu.com |
| whitelisted |
api.snapcraft.io |
| whitelisted |
8.100.168.192.in-addr.arpa |
| whitelisted |
clients2.google.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
clients.l.google.com |
| whitelisted |
safebrowsingohttpgateway.googleapis.com |
| whitelisted |
redlib.felix.onthewifi.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
415 | systemd-resolved | Potentially Bad Traffic | ET DYN_DNS DNS Query to DynDNS Domain *.onthewifi .com |
415 | systemd-resolved | Potentially Bad Traffic | ET DYN_DNS DNS Query to DynDNS Domain *.onthewifi .com |
415 | systemd-resolved | Potentially Bad Traffic | ET DYN_DNS DNS Query to DynDNS Domain *.onthewifi .com |
2021 | chrome | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.onthewifi .com Domain |
2021 | chrome | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.onthewifi .com Domain |
2021 | chrome | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.onthewifi .com Domain |
2021 | chrome | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.onthewifi .com Domain |
2021 | chrome | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.onthewifi .com Domain |
2021 | chrome | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.onthewifi .com Domain |
2021 | chrome | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.onthewifi .com Domain |