analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://telegra.ph/Description-02-12-3

Full analysis: https://app.any.run/tasks/6a3f8813-21f7-44fa-a6d0-f809b21aed33
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: April 01, 2023, 11:04:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
amadey
loader
Indicators:
MD5:

C80841E0E670CAA92A3C72064534ADFC

SHA1:

95CAC71FC81D3A1E5C211867B7A0CF1C68F6DB45

SHA256:

D5B7E953E82E7CBF31D27986893A6946E9B6F2243FBE305D78D69C2768934985

SSDEEP:

3:N8I0c7oYW:2IDW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • oneetx.exe (PID: 3880)
    • Uses Task Scheduler to run other applications

      • oneetx.exe (PID: 3880)
    • AMADEY was detected

      • oneetx.exe (PID: 3880)
    • AMADEY detected by memory dumps

      • oneetx.exe (PID: 3880)
    • Connects to the CnC server

      • oneetx.exe (PID: 3880)
  • SUSPICIOUS

    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • firefox.exe (PID: 2456)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 3128)
    • Reads the Internet Settings

      • Setup_for_Window`s_64_32.exe (PID: 1412)
      • oneetx.exe (PID: 3880)
    • Starts itself from another location

      • Setup_for_Window`s_64_32.exe (PID: 1412)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 2836)
      • oneetx.exe (PID: 3880)
    • Application launched itself

      • cmd.exe (PID: 2836)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 2836)
    • Connects to the server without a host name

      • oneetx.exe (PID: 3880)
    • The process executes via Task Scheduler

      • oneetx.exe (PID: 3608)
      • oneetx.exe (PID: 2880)
      • oneetx.exe (PID: 1872)
    • Uses RUNDLL32.EXE to load library

      • oneetx.exe (PID: 3880)
    • Process requests binary or script from the Internet

      • oneetx.exe (PID: 3880)
    • Executable content was dropped or overwritten

      • oneetx.exe (PID: 3880)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 3128)
    • The process uses the downloaded file

      • firefox.exe (PID: 2456)
      • WinRAR.exe (PID: 3128)
    • Application launched itself

      • firefox.exe (PID: 616)
      • firefox.exe (PID: 2456)
    • Create files in a temporary directory

      • firefox.exe (PID: 2456)
      • Setup_for_Window`s_64_32.exe (PID: 1412)
      • oneetx.exe (PID: 3880)
    • The process checks LSA protection

      • Setup_for_Window`s_64_32.exe (PID: 1412)
      • oneetx.exe (PID: 3880)
    • Checks supported languages

      • Setup_for_Window`s_64_32.exe (PID: 1412)
      • oneetx.exe (PID: 3880)
      • oneetx.exe (PID: 3608)
      • oneetx.exe (PID: 2880)
      • oneetx.exe (PID: 1872)
    • Reads the computer name

      • Setup_for_Window`s_64_32.exe (PID: 1412)
      • oneetx.exe (PID: 3880)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3128)
      • firefox.exe (PID: 2456)
    • Reads the machine GUID from the registry

      • Setup_for_Window`s_64_32.exe (PID: 1412)
      • oneetx.exe (PID: 3880)
    • Checks proxy server information

      • oneetx.exe (PID: 3880)
    • Creates files or folders in the user directory

      • oneetx.exe (PID: 3880)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Amadey

(PID) Process(3880) oneetx.exe
Strings (117)SCHTASKS
/Create /SC MINUTE /MO 1 /TN
/TR "
" /F
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Startup
Rem
cmd /C RMDIR /s/q
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
rundll32
/Delete /TN "
Programs
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%USERPROFILE%
\App
POST
GET
id=
&vs=
&sd=
&os=
&bi=
&ar=
&pc=
&un=
&dm=
&av=
&lv=
&og=
cred.dll|clip.dll|
d1
e1
e0
Main
http://
https://
exe
dll
cmd
ps1
<c>
<d>
Plugins/
+++
#
|
&unit=
=
shell32.dll
kernel32.dll
GetNativeSystemInfo
ProgramData\
AVAST Software
Avira
Kaspersky Lab
ESET
Panda Security
Doctor Web
AVG
360TotalSecurity
Bitdefender
Norton
Sophos
Comodo
WinDefender
0123456789
rb
wb
Content-Type: multipart/form-data; boundary=----
------
Content-Disposition: form-data; name="data"; filename="
" Content-Type: application/octet-stream
------
--
?scr=1
.jpg
Content-Type: application/x-www-form-urlencoded
SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName
ComputerName
abcdefghijklmnopqrstuvwxyz0123456789-_
-unicode-
SYSTEM\CurrentControlSet\Control\UnitedVideo\CONTROL\VIDEO\
SYSTEM\ControlSet001\Services\BasicDisplay\Video
VideoID
\0000
DefaultSettings.XResolution
DefaultSettings.YResolution
SOFTWARE\Microsoft\Windows NT\CurrentVersion
ProductName
2019
2022
2016
CurrentBuild
&&
echo Y|CACLS "
" /P "
:N"
CACLS "
" /P "
:R" /E
:F" /E
&&Exit
..\
\
:::
rundll32.exe
/k
"taskkill /f /im "
" && timeout 1 && del
&& Exit"
" && ren
&&
Powershell.exe
-executionpolicy remotesigned -File "
"
("j;o9i<$B5%HuFUo
Options
Drop nameoneetx.exe
Drop directoryeb256e24ee
Version3.69
C2 (1)http://77.91.78.118
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
24
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs winrar.exe setup_for_window`s_64_32.exe no specs setup_for_window`s_64_32.exe #AMADEY oneetx.exe schtasks.exe no specs cmd.exe no specs cmd.exe no specs cacls.exe no specs cacls.exe no specs cmd.exe no specs cacls.exe no specs cacls.exe no specs oneetx.exe no specs rundll32.exe no specs oneetx.exe no specs oneetx.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
616"C:\Program Files\Mozilla Firefox\firefox.exe" "https://telegra.ph/Description-02-12-3"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
2456"C:\Program Files\Mozilla Firefox\firefox.exe" https://telegra.ph/Description-02-12-3C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
3712"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2456.0.192008309\783121459" -parentBuildID 20201112153044 -prefsHandle 1124 -prefMapHandle 1116 -prefsLen 1 -prefMapSize 238726 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2456 "\\.\pipe\gecko-crash-server-pipe.2456" 1212 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
2916"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2456.6.872546017\1597103646" -childID 1 -isForBrowser -prefsHandle 2568 -prefMapHandle 2564 -prefsLen 181 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2456 "\\.\pipe\gecko-crash-server-pipe.2456" 2580 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
3248"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2456.13.1132633193\1836563055" -childID 2 -isForBrowser -prefsHandle 2792 -prefMapHandle 2760 -prefsLen 6644 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2456 "\\.\pipe\gecko-crash-server-pipe.2456" 2804 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1804"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2456.20.431269848\1323302398" -childID 3 -isForBrowser -prefsHandle 3632 -prefMapHandle 3624 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2456 "\\.\pipe\gecko-crash-server-pipe.2456" 3644 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msasn1.dll
3056"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2456.27.2000106373\1184976258" -childID 4 -isForBrowser -prefsHandle 3880 -prefMapHandle 1764 -prefsLen 7444 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2456 "\\.\pipe\gecko-crash-server-pipe.2456" 3892 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msasn1.dll
1864"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2456.34.1320238731\1128696838" -childID 5 -isForBrowser -prefsHandle 4044 -prefMapHandle 4040 -prefsLen 7799 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2456 "\\.\pipe\gecko-crash-server-pipe.2456" 4060 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
3128"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Setup_for_Windows_64_32.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4064"C:\Users\admin\AppData\Local\Temp\Rar$EXb3128.11683\Setup_for_Window`s_64_32\Setup_for_Window`s_64_32.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3128.11683\Setup_for_Window`s_64_32\Setup_for_Window`s_64_32.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3128.11683\setup_for_window`s_64_32\setup_for_window`s_64_32.exe
c:\windows\system32\ntdll.dll
Total events
26 026
Read events
25 834
Write events
192
Delete events
0

Modification events

(PID) Process:(616) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
09611C1E1E000000
(PID) Process:(2456) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
AD681C1E1E000000
(PID) Process:(2456) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(2456) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(2456) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(2456) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
(PID) Process:(2456) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|ServicesSettingsServer
Value:
https://firefox.settings.services.mozilla.com/v1
(PID) Process:(2456) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash
Value:
97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E
(PID) Process:(2456) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2456) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000003D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
58
Suspicious files
266
Text files
448
Unknown types
52

Dropped files

PID
Process
Filename
Type
2456firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
2456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
2456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
2456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:299A2B747C11E4BDA194E563FEA4A699
SHA256:94EE461F62E8B4A0A65471A41E10C8C56722B73C0A019D76ACA7F5BAF109813E
2456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-walsqlite-wal
MD5:FFEDA2D2F9ADC2333C303CE25AA2B626
SHA256:A0474736378117EEEC3CDF54FCB3DA23C74756765F841593DACE020DF1AFFA05
2456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2456firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:994A33896BB41A278A315D0D796422B6
SHA256:54EC50A20FFF8CC016710E49437CF6A11D3FE5EE7B28C185E4A9AAFEE2908B63
2456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
2456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
40
DNS requests
117
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2456
firefox.exe
POST
200
192.124.249.22:80
http://ocsp.godaddy.com/
US
der
1.74 Kb
whitelisted
2456
firefox.exe
POST
142.250.185.195:80
http://ocsp.pki.goog/gts1c3
US
whitelisted
2456
firefox.exe
POST
200
2.16.186.90:80
http://r3.o.lencr.org/
unknown
der
503 b
shared
2456
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt
US
text
8 b
whitelisted
3880
oneetx.exe
POST
200
77.91.78.118:80
http://77.91.78.118/u83mfdS2/index.php?scr=1
RU
malicious
2456
firefox.exe
POST
200
2.16.186.90:80
http://r3.o.lencr.org/
unknown
der
503 b
shared
2456
firefox.exe
POST
200
142.250.185.195:80
http://ocsp.pki.goog/gts1c3
US
der
471 b
whitelisted
2456
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt
US
text
8 b
whitelisted
2456
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
2456
firefox.exe
POST
200
2.16.186.90:80
http://r3.o.lencr.org/
unknown
der
503 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2456
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
2456
firefox.exe
192.124.249.22:80
ocsp.godaddy.com
SUCURI-SEC
US
suspicious
2456
firefox.exe
2.16.186.90:80
r3.o.lencr.org
Akamai International B.V.
DE
whitelisted
2456
firefox.exe
35.241.9.150:443
firefox.settings.services.mozilla.com
GOOGLE
US
suspicious
2456
firefox.exe
149.154.164.13:443
telegra.ph
Telegram Messenger Inc
GB
suspicious
149.154.167.99:443
t.me
Telegram Messenger Inc
GB
malicious
142.250.186.138:443
safebrowsing.googleapis.com
GOOGLE
US
whitelisted
2456
firefox.exe
142.250.186.138:443
safebrowsing.googleapis.com
GOOGLE
US
whitelisted
2456
firefox.exe
52.40.44.47:443
location.services.mozilla.com
AMAZON-02
US
unknown
2456
firefox.exe
13.32.121.112:443
snippets.cdn.mozilla.net
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 34.107.221.82
whitelisted
telegra.ph
  • 149.154.164.13
malicious
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
firefox.settings.services.mozilla.com
  • 35.241.9.150
whitelisted
example.org
  • 93.184.216.34
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
r3.o.lencr.org
  • 2.16.186.90
  • 2.16.186.80
  • 2.16.186.65
  • 2.16.186.96
  • 2.16.186.104
  • 2.16.186.57
  • 2.16.186.83
  • 2.16.186.8
  • 2.16.186.41
shared
ocsp.godaddy.com
  • 192.124.249.22
  • 192.124.249.24
  • 192.124.249.41
  • 192.124.249.23
  • 192.124.249.36
whitelisted
a1887.dscq.akamai.net
  • 2.16.186.96
  • 2.16.186.65
  • 2.16.186.80
  • 2.16.186.90
  • 2a02:26f0:b700:7::210:ce94
  • 2a02:26f0:b700:7::210:ce8f
  • 2.16.186.83
  • 2.16.186.104
  • 2.16.186.57
  • 2.16.186.41
  • 2.16.186.8
whitelisted
ocsp.godaddy.com.akadns.net
  • 192.124.249.36
  • 192.124.249.23
  • 192.124.249.41
  • 192.124.249.24
  • 192.124.249.22
whitelisted

Threats

PID
Process
Class
Message
2456
firefox.exe
Misc activity
ET INFO Observed Telegram Domain (t .me in TLS SNI)
3880
oneetx.exe
A Network Trojan was detected
AV TROJAN Agent.DHOA System Info Exfiltration
3880
oneetx.exe
Unknown Classtype
ET MALWARE Amadey CnC Check-In
3880
oneetx.exe
A Network Trojan was detected
ET MALWARE Amadey Bot Activity (POST)
3880
oneetx.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
3880
oneetx.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .dll file with no User-Agent
3880
oneetx.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
3880
oneetx.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .dll file with no User-Agent
3880
oneetx.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3880
oneetx.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
No debug info