| URL: | tor-exit-2.allium.dev |
| Full analysis: | https://app.any.run/tasks/4cdaeb23-3157-4b7e-b784-e93affa0bf2a |
| Verdict: | Malicious activity |
| Analysis date: | August 21, 2024, 14:03:35 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MD5: | 34FEBEE56CC931E27154175C328CA296 |
| SHA1: | 6D63BE3AD593AB693C7F48C995B463E833C6836B |
| SHA256: | D65504409773B0F95472D6D47A596FB9E1632EFA13EE232FCA1C76D729DF276E |
| SSDEEP: | 3:2IqwJJRj:2IqwJJR |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1168 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="3784.5.1549790775\1657967699" -childID 4 -isForBrowser -prefsHandle 3884 -prefMapHandle 3892 -prefsLen 22491 -prefMapSize 240456 -jsInitHandle 1348 -jsInitLen 240916 -parentBuildID 20240805090000 -win32kLockedDown -appDir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - {224fe8de-c284-4ae7-aac6-bd2f28642142} 3784 tab | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Tor Browser Exit code: 0 Version: 115.14.0 Modules
| |||||||||||||||
| 1432 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="3784.13.1012651506\1060402845" -childID 12 -isForBrowser -prefsHandle 4280 -prefMapHandle 5432 -prefsLen 22865 -prefMapSize 240456 -jsInitHandle 1348 -jsInitLen 240916 -parentBuildID 20240805090000 -win32kLockedDown -appDir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - {85201649-7e95-47bb-91b1-fe788cd1d4d1} 3784 tab | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Tor Browser Version: 115.14.0 Modules
| |||||||||||||||
| 2016 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6132 --field-trial-handle=1844,i,6994825953249394300,14887553273385138370,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 2136 | "C:\Users\admin\Downloads\tor-browser-windows-x86_64-portable-13.5.2.exe" | C:\Users\admin\Downloads\tor-browser-windows-x86_64-portable-13.5.2.exe | chrome.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Tor Browser Portable Installer Exit code: 0 Version: 13.5.2 Modules
| |||||||||||||||
| 2456 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="3784.15.1060755002\594878737" -childID 14 -isForBrowser -prefsHandle 4924 -prefMapHandle 5552 -prefsLen 22917 -prefMapSize 240456 -jsInitHandle 1348 -jsInitLen 240916 -parentBuildID 20240805090000 -win32kLockedDown -appDir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - {e36ab6b8-a359-47d2-b279-90876563ef1b} 3784 tab | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Tor Browser Version: 115.14.0 Modules
| |||||||||||||||
| 2580 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5180 --field-trial-handle=1844,i,6994825953249394300,14887553273385138370,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 2768 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="3784.4.1262784873\494225321" -parentBuildID 20240805090000 -prefsHandle 3424 -prefMapHandle 3420 -prefsLen 21219 -prefMapSize 240456 -appDir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - {d430c29a-9ab1-4bdf-a46f-a00a379d86fb} 3784 rdd | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Tor Browser Version: 115.14.0 Modules
| |||||||||||||||
| 3144 | "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Tor\tor.exe" -f "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\torrc" DataDirectory "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor" ClientOnionAuthDir "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\onion-auth" --defaults-torrc "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\torrc-defaults" GeoIPFile "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\geoip" GeoIPv6File "C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Data\Tor\geoip6" +__ControlPort 127.0.0.1:9151 HashedControlPassword 16:eb8f7916003a5e8e60d4c84a817d59741783a730f0ab5472f78ed6f7f4 +__SocksPort "127.0.0.1:9150 ExtendedErrors IPv6Traffic PreferIPv6 KeepAliveIsolateSOCKSAuth" __OwningControllerProcess 3784 DisableNetwork 1 | C:\Users\admin\Desktop\Tor Browser\Browser\TorBrowser\Tor\tor.exe | firefox.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 3784 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Tor Browser Version: 115.14.0 Modules
| |||||||||||||||
| 4292 | "C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe" -contentproc --channel="3784.6.591286290\841555608" -childID 5 -isForBrowser -prefsHandle 2684 -prefMapHandle 2696 -prefsLen 22491 -prefMapSize 240456 -jsInitHandle 1348 -jsInitLen 240916 -parentBuildID 20240805090000 -win32kLockedDown -appDir "C:\Users\admin\Desktop\Tor Browser\Browser\browser" - {4d74560a-ea02-4d06-9b4a-f8593a7db025} 3784 tab | C:\Users\admin\Desktop\Tor Browser\Browser\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Tor Browser Exit code: 0 Version: 115.14.0 Modules
| |||||||||||||||
| (PID) Process: | (6668) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (6668) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (6668) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (6668) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (6668) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (6668) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (6668) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (6668) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (6668) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (6668) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF11e898.TMP | — | |
MD5:— | SHA256:— | |||
| 6668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF11e8a7.TMP | — | |
MD5:— | SHA256:— | |||
| 6668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | text | |
MD5:4B26172585D38A3DD6697E274D0608AC | SHA256:85899A7AF1BD1939EA8264009EC427930FC5C092C8C3193984D6391526319268 | |||
| 6668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Variations | binary | |
MD5:961E3604F228B0D10541EBF921500C86 | SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6920 | chrome.exe | GET | 200 | 107.189.8.181:80 | http://tor-exit-2.allium.dev/ | unknown | — | — | suspicious |
6288 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7628 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acptyb4l2whiaqodbedm2lwht7ua_1049/efniojlnjndmcbiieegkicadnoecjjef_1049_all_acdw2kbreyakuvofupntzp4oh67a.crx3 | unknown | — | — | whitelisted |
7628 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acptyb4l2whiaqodbedm2lwht7ua_1049/efniojlnjndmcbiieegkicadnoecjjef_1049_all_acdw2kbreyakuvofupntzp4oh67a.crx3 | unknown | — | — | whitelisted |
4672 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7628 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/obk5vqrbqu6chkdcf4lvwshzsi_2024.8.20.2/jflhchccmppkfebkiaminageehmchikm_2024.08.20.02_all_acdysxsm3my4w2azgbkdkonfq4wa.crx3 | unknown | — | — | whitelisted |
7628 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acptyb4l2whiaqodbedm2lwht7ua_1049/efniojlnjndmcbiieegkicadnoecjjef_1049_all_acdw2kbreyakuvofupntzp4oh67a.crx3 | unknown | — | — | whitelisted |
7628 | svchost.exe | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/obk5vqrbqu6chkdcf4lvwshzsi_2024.8.20.2/jflhchccmppkfebkiaminageehmchikm_2024.08.20.02_all_acdysxsm3my4w2azgbkdkonfq4wa.crx3 | unknown | — | — | whitelisted |
7628 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acptyb4l2whiaqodbedm2lwht7ua_1049/efniojlnjndmcbiieegkicadnoecjjef_1049_all_acdw2kbreyakuvofupntzp4oh67a.crx3 | unknown | — | — | whitelisted |
7628 | svchost.exe | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/AMpg5-cnrANo_2018.8.8.0/2018.8.8.0_win64_win_third_party_module_list.crx3 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2096 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1492 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6920 | chrome.exe | 172.217.218.84:443 | accounts.google.com | GOOGLE | US | unknown |
6668 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
6920 | chrome.exe | 107.189.8.181:443 | tor-exit-2.allium.dev | PONYNET | LU | unknown |
6920 | chrome.exe | 107.189.8.181:80 | tor-exit-2.allium.dev | PONYNET | LU | unknown |
3260 | svchost.exe | 40.113.110.67:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6668 | chrome.exe | 224.0.0.251:5353 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
tor-exit-2.allium.dev |
| unknown |
accounts.google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
2019.www.torproject.org |
| shared |
www.google.com |
| whitelisted |
arc.msn.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6920 | chrome.exe | Misc Attack | ET TOR Known Tor Exit Node Traffic group 9 |
6920 | chrome.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 9 |
3144 | tor.exe | Misc Attack | ET TOR Known Tor Exit Node Traffic group 50 |
3144 | tor.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 50 |
3144 | tor.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 189 |
3144 | tor.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 663 |
3144 | tor.exe | Misc Attack | ET TOR Known Tor Exit Node Traffic group 50 |
3144 | tor.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 50 |