| URL: | https://digitalrecovery.com/en/decrypt-ransomware/qilin/ |
| Full analysis: | https://app.any.run/tasks/bb06d0cb-8a16-4474-9be3-be49a86af699 |
| Verdict: | Malicious activity |
| Analysis date: | February 13, 2024, 13:18:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 886A27DB6D2B715FEF2E2E1747838C0B |
| SHA1: | E1646AF60B96DDFBAD59B05C0C8ADD38D32C98F0 |
| SHA256: | EA2A632A6A786DCEB4E65F00BE143DBE4DF07E5B58135C1F0C181999EEDB5CCE |
| SSDEEP: | 3:N8UF3FBA57/ie+bR:2UzBI7KzN |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 552 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3500.4.168342797\737376999" -childID 3 -isForBrowser -prefsHandle 3700 -prefMapHandle 3708 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {de1a26e1-da3a-4b69-b9f8-7eb6124d590b} 3500 "\\.\pipe\gecko-crash-server-pipe.3500" 3684 179ce840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 712 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3500.3.1043507980\1374859203" -childID 2 -isForBrowser -prefsHandle 2868 -prefMapHandle 2864 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {02aa0e35-1e8e-4f89-83c2-39382e91563f} 3500 "\\.\pipe\gecko-crash-server-pipe.3500" 2880 1689b280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 956 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3500.1.1736351576\1738815930" -parentBuildID 20230710165010 -prefsHandle 1400 -prefMapHandle 1396 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7fe05838-69cb-489f-9a6f-7a9b7022ed3a} 3500 "\\.\pipe\gecko-crash-server-pipe.3500" 1412 ec46d50 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 984 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3500.5.2075035962\1676568918" -childID 4 -isForBrowser -prefsHandle 3840 -prefMapHandle 3848 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {eb6e8277-6898-4eaa-b0a2-a0e5b3ab35f6} 3500 "\\.\pipe\gecko-crash-server-pipe.3500" 3864 179cec90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1388 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3500.10.1762783377\2076478911" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 7952 -prefMapHandle 7944 -prefsLen 36627 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ec85c207-acb1-4106-b9e6-0ca738c7ad90} 3500 "\\.\pipe\gecko-crash-server-pipe.3500" 7868 11b8d010 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1776 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3500.13.1348481352\129730603" -childID 9 -isForBrowser -prefsHandle 3896 -prefMapHandle 8172 -prefsLen 31256 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ce15e222-98c3-49a3-b225-511dd8a6bdc9} 3500 "\\.\pipe\gecko-crash-server-pipe.3500" 3924 150da9b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2092 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3500.9.1464796744\749292103" -parentBuildID 20230710165010 -prefsHandle 3228 -prefMapHandle 3820 -prefsLen 36627 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f0f3a6df-cb08-40d9-9d2a-ffdecc910ba9} 3500 "\\.\pipe\gecko-crash-server-pipe.3500" 7940 1adc99e0 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2376 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3500.6.777220748\577401951" -childID 5 -isForBrowser -prefsHandle 4036 -prefMapHandle 4040 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {9d6f8a69-81e4-4401-9258-51f0ea4c11f7} 3500 "\\.\pipe\gecko-crash-server-pipe.3500" 4024 18b71f70 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2388 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3500.12.1049886749\1007371496" -parentBuildID 20230710165010 -sandboxingKind 0 -prefsHandle 7680 -prefMapHandle 7560 -prefsLen 36627 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4c604fbf-b947-461b-8703-711ef6c81087} 3500 "\\.\pipe\gecko-crash-server-pipe.3500" 7676 11b8aa90 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: 662591520 | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31088255 | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 962750270 | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31088255 | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3864) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3864 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFD1847268F93D78F0.TMP | gmc | |
MD5:5DE2ECC6D55383B1734A100DCD120124 | SHA256:1088CFBA1B6B99D5BD1BAFF56369A4F29537EBA02B0504DB27F281F4AF0EF6AC | |||
| 3500 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3500 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 3864 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{6523C6B3-CA72-11EE-AE0A-12A9866C77DE}.dat | binary | |
MD5:4F8A02976CBD5B43DB37557CE2B3BF82 | SHA256:0E8E3BF3A2758945A0F6A8257258B9494A665094C564D079089574A49028E7C4 | |||
| 3500 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3500 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3500 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db | binary | |
MD5:69F31D042AC2BE117009E38319F14943 | SHA256:8ABA6BFD5D98859AAD07208B0C8D62F96B052AE5B035179D4B0DB9961D9FF865 | |||
| 3500 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:B7A3C61D0C144CC5E166B1E769CA8F8C | SHA256:7FADCB77FFACA6B9E9F15C6F1CD3AAD4C20DCD90FA92429A627A3A7110CA2644 | |||
| 3500 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3500 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal | binary | |
MD5:93D5EE592A6D683331E9C6A2627B187C | SHA256:6783CC58544956581F8FF62E692D5D1C333BFBFDEA70DBE598842EDEE3A74E12 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 200 | 2.16.172.35:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3500 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
3500 | firefox.exe | POST | 200 | 142.250.185.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | unknown |
— | — | POST | 200 | 2.16.172.35:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
— | — | POST | 200 | 2.16.172.35:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
3864 | iexplore.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?18014fff35250a83 | unknown | — | — | unknown |
3500 | firefox.exe | POST | 200 | 142.250.185.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
3864 | iexplore.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?76ad697231f9b13b | unknown | — | — | unknown |
3500 | firefox.exe | POST | 200 | 142.250.185.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | unknown |
— | — | POST | 200 | 2.16.172.35:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3692 | iexplore.exe | 165.232.139.172:443 | digitalrecovery.com | DIGITALOCEAN-ASN | US | unknown |
3864 | iexplore.exe | 23.64.12.9:443 | www.bing.com | Akamai International B.V. | PL | unknown |
3500 | firefox.exe | 142.250.186.74:443 | safebrowsing.googleapis.com | — | — | whitelisted |
3500 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
3500 | firefox.exe | 34.117.188.166:443 | spocs.getpocket.com | — | — | unknown |
3500 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
3500 | firefox.exe | 142.250.185.195:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
digitalrecovery.com |
| unknown |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
gkegw.prod.ads.prod.webservices.mozgcp.net |
| unknown |
r3.o.lencr.org |
| shared |
a1887.dscq.akamai.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .to TLD |