| URL: | http://82.147.84.248:8000/ |
| Full analysis: | https://app.any.run/tasks/b3ee8939-0b71-41ea-87c4-fbed3c1c44ea |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | November 28, 2023, 11:32:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| SHA1: | 8403F78C9EE34CD8FD95D043DFD52B215C690C7E |
| SHA256: | F9C54AFB273AEC9088F1B6A421F8444BBE8FEFDEF8DD682281423097822AD83C |
| SSDEEP: | 3:N1K1QRjRddI:CiW |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1404 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.3.252452399\642464138" -childID 2 -isForBrowser -prefsHandle 2860 -prefMapHandle 2856 -prefsLen 35454 -prefMapSize 244187 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {92fdc3b9-e159-432c-83a5-c93cc44410fb} 2532 "\\.\pipe\gecko-crash-server-pipe.2532" 2872 1e5d0b58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2292 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.4.873887105\1623898032" -childID 3 -isForBrowser -prefsHandle 3660 -prefMapHandle 3680 -prefsLen 30252 -prefMapSize 244187 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {b0175608-c101-4959-a089-9ff23062b909} 2532 "\\.\pipe\gecko-crash-server-pipe.2532" 3700 21d0eb58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2452 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.2.701683948\1272354818" -childID 1 -isForBrowser -prefsHandle 2008 -prefMapHandle 2004 -prefsLen 25524 -prefMapSize 244187 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d306a859-110b-44a7-952e-afc51f94c55e} 2532 "\\.\pipe\gecko-crash-server-pipe.2532" 2020 1954ad58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2532 | "C:\Program Files\Mozilla Firefox\firefox.exe" "http://82.147.84.248:8000/" | C:\Program Files\Mozilla Firefox\firefox.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2904 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.5.2126873322\192289366" -childID 4 -isForBrowser -prefsHandle 3692 -prefMapHandle 3688 -prefsLen 35572 -prefMapSize 244187 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d716b1df-b9fb-4b80-bd21-d4a03b50b961} 2532 "\\.\pipe\gecko-crash-server-pipe.2532" 3724 21d0ee58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2940 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.1.1862088642\321590528" -parentBuildID 20230710165010 -prefsHandle 1400 -prefMapHandle 1396 -prefsLen 29857 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {5ea3ab31-e20b-40c4-b763-91c5772c466a} 2532 "\\.\pipe\gecko-crash-server-pipe.2532" 1412 fdd0b58 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2956 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.0.1527264856\382522387" -parentBuildID 20230710165010 -prefsHandle 1100 -prefMapHandle 1092 -prefsLen 29780 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {9438ef31-6497-48dc-b413-e9a6e24aa98e} 2532 "\\.\pipe\gecko-crash-server-pipe.2532" 1184 fdcea58 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3188 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.6.1814728818\340285739" -childID 5 -isForBrowser -prefsHandle 3972 -prefMapHandle 3976 -prefsLen 30356 -prefMapSize 244187 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {407043e8-3de3-4da2-9375-2b156ffd18df} 2532 "\\.\pipe\gecko-crash-server-pipe.2532" 3692 1f0e3758 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3196 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.7.551839642\1264943787" -childID 6 -isForBrowser -prefsHandle 4156 -prefMapHandle 4160 -prefsLen 30356 -prefMapSize 244187 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f2b438d9-26bc-401b-aacd-5d87ba2c7b11} 2532 "\\.\pipe\gecko-crash-server-pipe.2532" 4144 22853e58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3556 | "C:\Users\admin\Downloads\1.exe" | C:\Users\admin\Downloads\1.exe | firefox.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2532) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0000000000000000 | |||
| (PID) Process: | (2532) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (2532) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (2532) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (2532) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (2532) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 0 | |||
| (PID) Process: | (2532) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (2532) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (2532) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: F8B731ACA1C5D901 | |||
| (PID) Process: | (2532) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2532 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2532 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\protections.sqlite-journal | binary | |
MD5:270EF99C838C91159925A1430AF9B111 | SHA256:2A6EA4E6868F673A9337F18819D00EE00F35C9A9AFAE2184AFB864F29250B3DE | |||
| 2532 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs.js | text | |
MD5:87EEC9627A96D848D5688EA326C165AE | SHA256:64BC125D24B889C8048E537EDD3C5347E02A1947EA2F664BA93093341AAEB395 | |||
| 2532 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.bin | binary | |
MD5:4DF9B77C7650AF87B264E535779AE2A4 | SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58 | |||
| 2532 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2532 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2532 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | binary | |
MD5:823065731ECF281D5EA7268DB4341AB3 | SHA256:D67EBB929DFDF3DDBCC70FFD7D0149DBC28940E990EFD90924D47EB2D8111365 | |||
| 2532 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage.sqlite-journal | binary | |
MD5:EDD8DB0084A4EF3BF87D423B1D85C047 | SHA256:54F4A1C474D884DF44F52330288E8E272492B196AA873A2E39CB735DA5799EF0 | |||
| 2532 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\ED9826654AE8BD972BDE17A9E0A449D3F881E430 | binary | |
MD5:2D7299D8909C3D44507B2D7681F7DDCF | SHA256:4C8DE74E305DED5E675B81A8CBBCC776711153E9617D8B2238DEAFDCD909D7F3 | |||
| 2532 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\796DAF34B89F77E44088F5C67B705300DF2D0B00 | binary | |
MD5:C00D50BB26108BEBFCA4AF2F3084C2EC | SHA256:841E124F1A7B25C446D238697B808016FE7CFE4C1BD34772FA28A4832AAA68CB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2532 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
2532 | firefox.exe | POST | 200 | 2.16.241.8:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2532 | firefox.exe | POST | 200 | 18.245.65.219:80 | http://ocsp.r2m02.amazontrust.com/ | unknown | binary | 471 b | unknown |
2532 | firefox.exe | POST | 200 | 142.250.185.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
2532 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 471 b | unknown |
2532 | firefox.exe | POST | 200 | 2.16.241.8:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2532 | firefox.exe | POST | 200 | 2.16.241.8:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2532 | firefox.exe | POST | 200 | 2.16.241.8:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2532 | firefox.exe | POST | 200 | 2.16.241.8:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2532 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2532 | firefox.exe | 82.147.84.248:8000 | — | Kravtsov Evgeniy Aleksandrovich | RU | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2532 | firefox.exe | 142.250.185.138:443 | safebrowsing.googleapis.com | — | — | whitelisted |
2532 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
2532 | firefox.exe | 142.250.185.195:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2532 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
2532 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
r3.o.lencr.org |
| shared |
content-signature-2.cdn.mozilla.net |
| whitelisted |
a1887.dscq.akamai.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2532 | firefox.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
2532 | firefox.exe | A Network Trojan was detected | ET MALWARE Single char EXE direct download likely trojan (multiple families) |
2532 | firefox.exe | Misc activity | ET INFO Packed Executable Download |
2532 | firefox.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2532 | firefox.exe | Potentially Bad Traffic | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response |
3556 | 1.exe | Potentially Bad Traffic | ET INFO Microsoft net.tcp Connection Initialization Activity |
3556 | 1.exe | A Network Trojan was detected | ET MALWARE Redline Stealer TCP CnC Activity |
3556 | 1.exe | A Network Trojan was detected | ET MALWARE [ANY.RUN] RedLine Stealer Family Related (MC-NMF Authorization) |
3556 | 1.exe | A Network Trojan was detected | ET MALWARE Redline Stealer TCP CnC - Id1Response |
3556 | 1.exe | A Network Trojan was detected | ET MALWARE Redline Stealer TCP CnC Activity |