IOC Report
https://generali.werbeartikel-online-shop.com

loading gif

Files

File Path
Type
Category
Malicious
/home/james/.cache/dconf/user
very short file (no magic)
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/17BCC6A55E85E8F6A4C660529BB763D3464877E1
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/1ACD9749AAE3D02FEE084B8576784A1535E5546C
ASCII text, with very long lines (32033)
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/1B22BDA5BA68A1448FCB56906398FE61B0AEE710
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/255180BBFC392A33F03051F3DC10335C080DDA20
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/40ABD0A962B8FE31514026AD426D53FC2AD624FE
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/66B7941C45385F0CD6B46B392D0BEF2CBD64288D
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/919AD4B6B4DF5BEE81EE8EC9665A5FC662F12E3B
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/9E876DD8AD3949F308300382320CBAFF2C684314
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/AD059B96D97FE240161540F36D46C5F70734D6F2
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/C389DE279BF5275924497D5B33D1F1900116E591
JSON data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/C451CAD6E876978E63FFFC9865A83D89CFBE951D
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/C7093830EE04AD47A1F61AE4D939134F0A4244BF
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/E39A30365062FED6A062C3B828869E960E9E1641
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/cache2/entries/E8D2EF960BE529ACF6A67B8DF1D64710B0CD15D1
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/allow-flashallow-digest256.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/allow-flashallow-digest256.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/base-track-digest256.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/base-track-digest256.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/block-flash-digest256.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/block-flash-digest256.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/block-flashsubdoc-digest256.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/block-flashsubdoc-digest256.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/except-flash-digest256.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/except-flash-digest256.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/except-flashallow-digest256.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/except-flashallow-digest256.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/except-flashsubdoc-digest256.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/except-flashsubdoc-digest256.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/mozplugin-block-digest256.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/mozplugin-block-digest256.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/mozstd-trackwhite-digest256.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/mozstd-trackwhite-digest256.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-block-simple-1.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-block-simple.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-block-simple.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-harmful-simple-1.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-harmful-simple.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-harmful-simple.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-malware-simple-1.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-malware-simple.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-malware-simple.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-phish-simple-1.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-phish-simple.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-phish-simple.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-track-simple-1.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-track-simple.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-track-simple.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-trackwhite-simple-1.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-trackwhite-simple.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-trackwhite-simple.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-unwanted-simple-1.sbstore
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-unwanted-simple.pset
data
dropped
/home/james/.cache/mozilla/firefox/5zxot757.default/safebrowsing-updating/test-unwanted-simple.sbstore
data
dropped
/home/james/.mozilla/firefox/5zxot757.default/addonStartup.json.lz4.tmp
Mozilla lz4 compressed data, originally 1426 bytes
dropped
/home/james/.mozilla/firefox/5zxot757.default/cert9.db
SQLite 3.x database, last written using SQLite version 3026000, page size 32768, file counter 4, database pages 7, cookie 0x5, schema 4, UTF-8, version-valid-for 4
dropped
/home/james/.mozilla/firefox/5zxot757.default/cert9.db-journal
data
dropped
/home/james/.mozilla/firefox/5zxot757.default/key4.db
SQLite 3.x database, last written using SQLite version 3026000, page size 32768, file counter 3, database pages 9, cookie 0x6, schema 4, UTF-8, version-valid-for 3
dropped
/home/james/.mozilla/firefox/5zxot757.default/key4.db-journal
data
dropped
/home/james/.mozilla/firefox/5zxot757.default/permissions.sqlite
SQLite 3.x database, user version 9, last written using SQLite version 3026000, page size 32768, file counter 5, database pages 3, cookie 0x2, schema 4, UTF-8, version-valid-for 5
dropped
/home/james/.mozilla/firefox/5zxot757.default/permissions.sqlite-journal
data
dropped
/home/james/.mozilla/firefox/5zxot757.default/places.sqlite-wal
SQLite Write-Ahead Log, version 3007000
dropped
/home/james/.mozilla/firefox/5zxot757.default/prefs-1.js
ASCII text, with very long lines (663)
dropped
/home/james/.mozilla/firefox/5zxot757.default/sessionCheckpoints.json.tmp
JSON data
dropped
/home/james/.mozilla/firefox/5zxot757.default/sessionstore-backups/recovery.jsonlz4.tmp
Mozilla lz4 compressed data, originally 26998 bytes
dropped
/proc/4923/gid_map
ASCII text, with no line terminators
dropped
/proc/4923/setgroups
ASCII text, with no line terminators
dropped
/proc/4923/uid_map
ASCII text, with no line terminators
dropped
/proc/4968/gid_map
ASCII text, with no line terminators
dropped
/proc/4968/setgroups
ASCII text, with no line terminators
dropped
/proc/4968/uid_map
ASCII text, with no line terminators
dropped
/proc/5009/gid_map
ASCII text, with no line terminators
dropped
/proc/5009/setgroups
ASCII text, with no line terminators
dropped
/proc/5009/uid_map
ASCII text, with no line terminators
dropped
There are 65 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
/usr/bin/exo-open
exo-open https://generali.werbeartikel-online-shop.com
/usr/bin/exo-open
-
/usr/bin/exo-open
-
/usr/lib/x86_64-linux-gnu/xfce4/exo-1/exo-helper-1
/usr/lib/x86_64-linux-gnu/xfce4/exo-1/exo-helper-1 --launch WebBrowser https://generali.werbeartikel-online-shop.com
/usr/lib/x86_64-linux-gnu/xfce4/exo-1/exo-helper-1
-
/usr/bin/sensible-browser
/bin/sh /usr/bin/sensible-browser https://generali.werbeartikel-online-shop.com
/usr/bin/x-www-browser
/bin/sh /usr/bin/x-www-browser https://generali.werbeartikel-online-shop.com
/usr/bin/x-www-browser
-
/usr/bin/which
/bin/sh /usr/bin/which /usr/bin/x-www-browser
/usr/lib/firefox/firefox
/usr/lib/firefox/firefox https://generali.werbeartikel-online-shop.com
/usr/lib/firefox/firefox
-
/usr/lib/firefox/firefox
-
/usr/lib/firefox/firefox
-
/usr/bin/lsb_release
/usr/bin/python3 -Es /usr/bin/lsb_release -idrc
/usr/lib/firefox/firefox
-
/usr/bin/dbus-launch
dbus-launch --autolaunch=11ced2f07072c6ae389b731c5cc84014 --binary-syntax --close-stderr
/usr/lib/firefox/firefox
-
/usr/lib/firefox/firefox
-
/usr/lib/firefox/firefox
/usr/lib/firefox/firefox -contentproc -childID 1 -isForBrowser -prefsLen 1 -prefMapSize 172334 -parentBuildID 20190410113011 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/firefox/browser 4797 true tab
/usr/lib/firefox/firefox
-
/usr/lib/firefox/firefox
-
/usr/lib/firefox/firefox
/usr/lib/firefox/firefox -contentproc -childID 2 -isForBrowser -prefsLen 6115 -prefMapSize 172334 -parentBuildID 20190410113011 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/firefox/browser 4797 true tab
/usr/lib/firefox/firefox
-
/usr/lib/firefox/firefox
-
/usr/lib/firefox/firefox
/usr/lib/firefox/firefox -contentproc -childID 3 -isForBrowser -prefsLen 6934 -prefMapSize 172334 -parentBuildID 20190410113011 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appdir /usr/lib/firefox/browser 4797 true tab
There are 15 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://generali.werbeartikel-online-shop.com
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/style.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/default/template/css/bramble_customDesign.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/shop/Core.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/css/shop/frame/style/de/bramble.min.2
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/lazyClasses.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/NormalizeCss/normalize.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/jQuerySlickCarousel/js/slick.js
95.142.78.35
http://www.debian.org/gro.naibed.www.
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/jQuerySlickCarousel/css/slick.css
95.142.78.35
http://www.ubuntu.com
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/jQuerySlickCarousel/css/slick-theme.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/css/shop/frame/style/de/bramble.min.2.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/Cosmoshop.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/external/jQuery/Loading.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/Helper.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/jQueryUI/jquery-ui.min.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/pix/template_vorlage/bramble/shop_header/de/apple-touch-icon.png
95.142.78.35
http://www.ubuntu.com/moc.utnubu.www.
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/jQuery/jquery-migrate.min.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/default/template/css/bramble_customDesign.cs
unknown
https://support.mozilla.org/en-US/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=fire
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/external/Ejs_3_1_6_min.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Fontello/font/cs.woff?29759507
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/default/lib/de_categories_61fc104855eb3a96fccf5f576c8595fd.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Fontello/fontello-animation.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/template/css/bramble_responsive.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/jQueryUI/jquery-ui.min.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/jQueryUI/jquery-ui.theme.min.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/default/template/css/bramble_customResponsive.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/FormLib/shop_formlib.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/template/js/bramble_shopFunctions.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/jQueryCookie/jquery.cookie.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/moc.pohs-enilno-lekitraebrew.ilareneg.d
unknown
http://www.debian.org
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/jQuery/jquery.min.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/external/jQuery/modal.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/css/shop/content/style/de/bramble.min.2.css
95.142.78.35
https://support.mozilla.org/en-US/products/firefoxgro.allizom.troppus.
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/default/css/shop/content/layout/bramble.min.2.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/Validators.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cgi-bin/cosmoshop/lshop.cgi
95.142.78.35
http://wiki.ubuntu.com/moc.utnubu.ikiw.
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/default/css/shop/content/layout/bramble.min.
unknown
https://pki.goog/repository/0
unknown
https://push.services.mozilla.com/
34.107.243.93
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/template/css/bramble_rootStyles.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/external/jQuery/Modal.js
95.142.78.35
https://answers.launchpad.net/ubuntu/
unknown
https://generali.werbeartikel-online-shop.com
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/default/css/shop/frame/layout/bramble.min.2.
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/pix/template_vorlage/bramble/shop_header/de/Logo.png
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/overrides.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/EventHandler.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/default/css/shop/frame/layout/bramble.min.2.css
95.142.78.35
https://answers.launchpad.net
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Fontello/fontello.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/Cache.js
95.142.78.35
https://generali.werbeartikel-online-shop.comd
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/LiveSearch/jQueryLiveSearch.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/pix/template_vorlage/bramble/suchleiste/de/logo.png
95.142.78.35
http://wiki.ubuntu.com
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/css/shop/content/style/de/bramble.min
unknown
https://generali.werbeartikel-online-shop.com/GENERALI
unknown
https://support.mozilla.org
unknown
http://crl.pki.goog/gsr2/gsr2.crl0?
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/jQueryUI/jquery-ui.structure.min.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/external/jQuery/loading.css
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/Cosmoshop/Ajax.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/default/template/css/bramble_customResponsiv
unknown
https://generali.werbeartikel-online-shop.com/cosmoshop/shared/libs/modernizr/modernizr.js
95.142.78.35
https://generali.werbeartikel-online-shop.com/cosmoshop/default/pix/s/favicon/icon.ico
95.142.78.35
There are 62 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
prod.balrog.prod.cloudops.mozgcp.net
35.244.181.201
push.services.mozilla.com
34.107.243.93
generali.werbeartikel-online-shop.com
95.142.78.35
d228z91au11ukj.cloudfront.net
13.32.121.112

IPs

IP
Domain
Country
Malicious
13.32.121.112
d228z91au11ukj.cloudfront.net
United States
35.244.181.201
prod.balrog.prod.cloudops.mozgcp.net
United States
95.142.78.35
generali.werbeartikel-online-shop.com
Germany
34.107.243.93
push.services.mozilla.com
United States