| URL: | https://abbaspc.net |
| Full analysis: | https://app.any.run/tasks/2794071b-baf5-4e13-ae44-e40a61e9c540 |
| Verdict: | Malicious activity |
| Threats: | Raccoon is an info stealer type malware available as a Malware as a Service. It can be obtained for a subscription and costs $200 per month. Raccoon malware has already infected over 100,000 devices and became one of the most mentioned viruses on the underground forums in 2019. |
| Analysis date: | July 27, 2023, 07:27:45 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | E1EE041D9D4D2E7E2736E95DEA432F98 |
| SHA1: | DDBD88A9CE2CA47C7115782AE47C042D980E9B30 |
| SHA256: | EE1062B2B1AED2A130CD1E646AE306935384D1632CE069B1F3F5FB41F87825A6 |
| SSDEEP: | 3:N8lLAR:2RAR |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 896 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1956.3.1051048606\753657112" -childID 2 -isForBrowser -prefsHandle 2324 -prefMapHandle 2364 -prefsLen 25821 -prefMapSize 242647 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {359a837f-2c27-46ec-98cc-9ebc928dcf50} 1956 "\\.\pipe\gecko-crash-server-pipe.1956" 2352 e7ea58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1276 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1956.13.668625897\895865206" -childID 11 -isForBrowser -prefsHandle 8580 -prefMapHandle 8568 -prefsLen 32534 -prefMapSize 242647 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ec425204-b918-469c-a76b-e275df17dfe8} 1956 "\\.\pipe\gecko-crash-server-pipe.1956" 8584 e7a458 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1356 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1956.7.2118178836\1930941093" -childID 5 -isForBrowser -prefsHandle 4076 -prefMapHandle 4080 -prefsLen 28952 -prefMapSize 242647 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {17c80a04-c3b3-4f6d-b5f5-b8b2095d57be} 1956 "\\.\pipe\gecko-crash-server-pipe.1956" 4064 e41158 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1412 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1956.6.2015491670\1537065654" -childID 4 -isForBrowser -prefsHandle 3964 -prefMapHandle 3932 -prefsLen 28952 -prefMapSize 242647 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4c6591a7-ba5d-4630-8afe-c91294aebd55} 1956 "\\.\pipe\gecko-crash-server-pipe.1956" 3936 222c9158 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1468 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1956.15.1738730073\1208525580" -childID 13 -isForBrowser -prefsHandle 4092 -prefMapHandle 4584 -prefsLen 32534 -prefMapSize 242647 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {dfcef2fb-b0a0-484f-9d99-6313fa30e3c9} 1956 "\\.\pipe\gecko-crash-server-pipe.1956" 3968 1cc36058 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1624 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1956.1.64247997\949619053" -parentBuildID 20230710165010 -prefsHandle 1676 -prefMapHandle 1664 -prefsLen 24131 -prefMapSize 242647 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fc1fc6d4-acb0-4847-9ba5-43c2e33133b3} 1956 "\\.\pipe\gecko-crash-server-pipe.1956" 1688 13b05658 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1752 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1956.5.1538431368\111306250" -parentBuildID 20230710165010 -prefsHandle 3160 -prefMapHandle 3156 -prefsLen 26175 -prefMapSize 242647 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0dc7cfd1-7e3a-43fc-a8fa-a2dd07a266f9} 1956 "\\.\pipe\gecko-crash-server-pipe.1956" 3172 1c898d58 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1956 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://abbaspc.net" | C:\Program Files\Mozilla Firefox\firefox.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2208 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1956.8.1140806039\419716065" -childID 6 -isForBrowser -prefsHandle 4260 -prefMapHandle 4264 -prefsLen 28952 -prefMapSize 242647 -jsInitHandle 876 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {5fdeebd1-3155-4cfa-9199-63b576b97edf} 1956 "\\.\pipe\gecko-crash-server-pipe.1956" 4352 212dad58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2604 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1956.0.953132738\776662501" -parentBuildID 20230710165010 -prefsHandle 1332 -prefMapHandle 1324 -prefsLen 24055 -prefMapSize 242647 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d553623e-016f-4536-99fe-de2b42fbf0ca} 1956 "\\.\pipe\gecko-crash-server-pipe.1956" 1416 13b06b58 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (1956) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0000000000000000 | |||
| (PID) Process: | (1956) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (1956) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1956) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000096000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1956) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\155\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1956) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1956) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1956) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1956) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3172) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\155\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1956 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\webappsstore.sqlite-wal | — | |
MD5:— | SHA256:— | |||
| 1956 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20230710165010 | text | |
MD5:2BB9D5F7D17338A8455A1E637C75F5CD | SHA256:ADF56602F8EB1F3443E56A106BEE6B852AF1314AD2CA1C88240EDD733C09C8F0 | |||
| 1956 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\ls-archive-tmp.sqlite-journal | binary | |
MD5:2BD28D78185C838E6B7E2501B91E0246 | SHA256:D8533543D48179779DB3CC724D7F7F683C0B98C776BA4F4CEACD2AC0631DFD9B | |||
| 1956 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\compatibility.ini | text | |
MD5:C6998EF9E767E571FE74299C971B9C98 | SHA256:69C387E1BE9E3C5A5BE3B767F5734E7E31755B67C3F6F409D175FB9265D53F2E | |||
| 1956 | firefox.exe | C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\update-config.json | binary | |
MD5:E812E56D0B6EDF84B4A0B959F53E239F | SHA256:D55B72651CD0C5B834EAA29BA778BE7EDC357C16163A77AE778DCD61E85C3582 | |||
| 1956 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage.sqlite-journal | binary | |
MD5:699297541D85A65CC68DE0B94B7EE0BA | SHA256:F143AC788AB959F76826BA901EF829F76331653C4E9B9FD7C604BFCA9CD903C3 | |||
| 1956 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1956 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 1956 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs-1.js | text | |
MD5:DA1DEDC3D0341D04C815457047701190 | SHA256:276BA64F1367201B52A99F67831F4363E888CF6CDA037886240164969A4EEA80 | |||
| 1956 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1956 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | US | text | 8 b | whitelisted |
1956 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
1956 | firefox.exe | POST | 200 | 184.24.77.79:80 | http://r3.o.lencr.org/ | US | der | 503 b | shared |
1956 | firefox.exe | POST | 200 | 184.24.77.79:80 | http://r3.o.lencr.org/ | US | binary | 503 b | shared |
1956 | firefox.exe | POST | 200 | 142.250.186.35:80 | http://ocsp.pki.goog/gts1c3 | US | binary | 472 b | whitelisted |
1956 | firefox.exe | POST | 200 | 184.24.77.79:80 | http://r3.o.lencr.org/ | US | der | 503 b | shared |
1956 | firefox.exe | POST | 200 | 142.250.186.35:80 | http://ocsp.pki.goog/gts1c3 | US | binary | 472 b | whitelisted |
1956 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | US | text | 90 b | whitelisted |
1956 | firefox.exe | POST | 200 | 184.24.77.79:80 | http://r3.o.lencr.org/ | US | binary | 503 b | shared |
1956 | firefox.exe | POST | — | 108.138.16.146:80 | http://ocsp.r2m02.amazontrust.com/ | US | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
328 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1956 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | suspicious |
1956 | firefox.exe | 184.24.77.79:80 | r3.o.lencr.org | Akamai International B.V. | DE | suspicious |
1956 | firefox.exe | 192.0.77.2:443 | i0.wp.com | AUTOMATTIC | US | suspicious |
1956 | firefox.exe | 34.211.118.46:443 | shavar.services.mozilla.com | AMAZON-02 | US | unknown |
1956 | firefox.exe | 142.250.185.200:443 | www.googletagmanager.com | GOOGLE | US | suspicious |
1956 | firefox.exe | 34.117.65.55:443 | push.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | suspicious |
1956 | firefox.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1956 | firefox.exe | 3.229.85.40:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
1956 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
abbaspc.net |
| malicious |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
firefox.settings.services.mozilla.com |
| whitelisted |
prod.remote-settings.prod.webservices.mozgcp.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
4068 | Setupz-Vers4.1009.exe | A Network Trojan was detected | ET MALWARE Win32/RecordBreaker CnC Checkin M1 |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |