| URL: | https://abbaspc.net |
| Full analysis: | https://app.any.run/tasks/ae4ac2bf-5b8d-4368-aa27-bca3e22ee4bd |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | June 18, 2023, 21:33:45 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | E1EE041D9D4D2E7E2736E95DEA432F98 |
| SHA1: | DDBD88A9CE2CA47C7115782AE47C042D980E9B30 |
| SHA256: | EE1062B2B1AED2A130CD1E646AE306935384D1632CE069B1F3F5FB41F87825A6 |
| SSDEEP: | 3:N8lLAR:2RAR |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 584 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2436.0.1240642811\1846926680" -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 1196 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 67.0.4 Modules
| |||||||||||||||
| 644 | "C:\Users\admin\AppData\Local\Temp\is-0BNDS.tmp\XRECODE 3 Pro\Snapseed.exe" | C:\Users\admin\AppData\Local\Temp\is-0BNDS.tmp\XRECODE 3 Pro\Snapseed.exe | Setup.tmp | ||||||||||||
User: admin Company: Piriform Software Ltd Integrity Level: MEDIUM Description: Recuva Installer Exit code: 0 Version: 1.53.0.1087 Modules
| |||||||||||||||
| 1664 | "C:\Windows\System32\cmd.exe" /c timeout /t 6 & del /f /q "C:\Users\admin\AppData\Local\Temp\is-0BNDS.tmp\XRECODE 3 Pro\Snapseed.exe" & exit | C:\Windows\SysWOW64\cmd.exe | — | Snapseed.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1672 | "C:\Users\admin\AppData\Local\Temp\is-N8HT2.tmp\Setup.tmp" /SL5="$801D2,47029741,832512,C:\Users\admin\AppData\Local\Temp\Rar$EXb3060.9248\Setup.exe" | C:\Users\admin\AppData\Local\Temp\is-N8HT2.tmp\Setup.tmp | Setup.exe | ||||||||||||
User: admin Company: xrecode3 Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2164 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3060.9248\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3060.9248\Setup.exe | WinRAR.exe | ||||||||||||
User: admin Company: xrecode3 Integrity Level: MEDIUM Description: XRECODE 3 Pro Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 2436 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://abbaspc.net" | C:\Program Files\Mozilla Firefox\firefox.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 67.0.4 Modules
| |||||||||||||||
| 2572 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2436.13.833571589\1501462999" -childID 2 -isForBrowser -prefsHandle 2892 -prefMapHandle 2896 -prefsLen 5823 -prefMapSize 189239 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 2908 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 67.0.4 Modules
| |||||||||||||||
| 2580 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2436.20.967949157\215745495" -childID 3 -isForBrowser -prefsHandle 2632 -prefMapHandle 3372 -prefsLen 6545 -prefMapSize 189239 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 3476 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 67.0.4 Modules
| |||||||||||||||
| 2608 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2436.27.1381246008\1972007794" -childID 4 -isForBrowser -prefsHandle 3704 -prefMapHandle 3712 -prefsLen 6545 -prefMapSize 189239 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 3724 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 67.0.4 Modules
| |||||||||||||||
| 2684 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2436.3.1891261432\243552053" -childID 1 -isForBrowser -prefsHandle 1696 -prefMapHandle 1724 -prefsLen 1 -prefMapSize 189239 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2436 "\\.\pipe\gecko-crash-server-pipe.2436" 1796 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 67.0.4 Modules
| |||||||||||||||
| (PID) Process: | (2436) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0000000000000000 | |||
| (PID) Process: | (2436) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2436) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000008B000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2436) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2436) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2436) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2436) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\14C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2436 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 2436 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2436 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2436 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\permissions.sqlite-journal | binary | |
MD5:8C385EE9576B6385777AC5FF311E2899 | SHA256:BE94DBB7E740C5BE6200FD4CA8488EDE2C0E2DCE6012E49399D92205341D11D2 | |||
| 2436 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs-1.js | text | |
MD5:1759FBCEFAC92AE1A7B8E457ACF71748 | SHA256:5DA473B0E0C84BE5B289DC97C259B98F674E17AF49F4723B4A90F73AA972B739 | |||
| 2436 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.bin | binary | |
MD5:6BED2A248268034CA1F73B2925365DE2 | SHA256:A45996AA907815E86366A17ED448F75A584D7B600AA9398E14DE21DFAD3D613A | |||
| 2436 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\NLTXVM~1.DEF\cert9.db | binary | |
MD5:819BE7B9493F08F28B444C7F182EEA06 | SHA256:553C7D534AE88558DF0868C3E94354D597892AFBA2869EB8BAF32146C2FA5EDE | |||
| 2436 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\NLTXVM~1.DEF\cert9.db-journal | binary | |
MD5:B378D605B784F113F9B9FBCB4F865026 | SHA256:34D653B157294A359AB5F9654FE5388399AE7CD7E5E10C9E228AA2C9C319BBBC | |||
| 2436 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\89FC1CAFB0B9F7EE9E7F37CC3AA85C8676E4C824 | binary | |
MD5:01E049B95665F4E22C7038BC7AB008EB | SHA256:5AD61B080DCD8AD201189C517B705EFB3B2871EDD0229C0B089A7B40C7C25395 | |||
| 2436 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\C6E9F6ED815F933E1BE8907D751B229F9BFD6A9B | binary | |
MD5:0395501CCA9A672BF0BDBE72EA88E53A | SHA256:15483887BA0B1957FD57A00E01DCDFF4E3A802D55244193F30B1A9E5B47DE328 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2436 | firefox.exe | GET | 200 | 104.26.14.242:80 | http://abbaspc.net/.well-known/http-opportunistic | US | binary | 92 b | malicious |
2436 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gts1c3 | US | binary | 472 b | whitelisted |
2436 | firefox.exe | POST | 200 | 184.24.77.59:80 | http://r3.o.lencr.org/ | US | binary | 503 b | shared |
2436 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | US | binary | 471 b | whitelisted |
2436 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gts1c3 | US | binary | 472 b | whitelisted |
2436 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
2436 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gts1c3 | US | binary | 472 b | whitelisted |
2436 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | US | binary | 471 b | whitelisted |
2436 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gts1c3 | US | binary | 471 b | whitelisted |
2436 | firefox.exe | POST | 200 | 184.24.77.59:80 | http://r3.o.lencr.org/ | US | binary | 503 b | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
328 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2436 | firefox.exe | 104.26.14.242:443 | abbaspc.net | CLOUDFLARENET | US | shared |
2436 | firefox.exe | 34.160.46.54:443 | search.services.mozilla.com | GOOGLE | US | suspicious |
2436 | firefox.exe | 184.24.77.59:80 | r3.o.lencr.org | Akamai International B.V. | DE | suspicious |
2436 | firefox.exe | 192.0.76.3:443 | stats.wp.com | AUTOMATTIC | US | suspicious |
2436 | firefox.exe | 13.32.121.112:443 | snippets.cdn.mozilla.net | AMAZON-02 | US | unknown |
2436 | firefox.exe | 34.117.65.55:443 | push.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | suspicious |
2436 | firefox.exe | 192.0.77.2:443 | i0.wp.com | AUTOMATTIC | US | suspicious |
2436 | firefox.exe | 104.26.14.242:80 | abbaspc.net | CLOUDFLARENET | US | shared |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
abbaspc.net |
| malicious |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
r3.o.lencr.org |
| shared |
stats.wp.com |
| whitelisted |
a1887.dscq.akamai.net |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
328 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
2436 | firefox.exe | Generic Protocol Command Decode | SURICATA STREAM ESTABLISHED packet out of window |
2436 | firefox.exe | Generic Protocol Command Decode | SURICATA STREAM ESTABLISHED invalid ack |
2436 | firefox.exe | Generic Protocol Command Decode | SURICATA STREAM Packet with invalid ack |
2436 | firefox.exe | Generic Protocol Command Decode | SURICATA STREAM ESTABLISHED packet out of window |