File name:

windows-8-wallpapers-35.jpg

Full analysis: https://app.any.run/tasks/3359ed5e-573b-4833-ae68-d63b7800fde1
Verdict: Malicious activity
Analysis date: May 10, 2018, 14:45:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: image/jpeg
File info: JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2011:03:04 16:04:25], baseline, precision 8, 1920x1080, frames 3
MD5:

C63371C20874D383C618B4CB6B5F8A53

SHA1:

B07B873088928AF4E42E1730E0451A9D18D5085C

SHA256:

073F27D5710005DFE78F31D979D2E6BA440B2646E3EF040A7F5BE0E445744314

SSDEEP:

6144:tr7PFPy+eSxHpgGrbA/jTLKGF9h+kfYoOuzXaOM/:trbcmNmGrgTLKGnh+kwoOuzaOM/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • cmd.exe (PID: 660)
  • SUSPICIOUS

    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 1656)
    • Removes files from Windows directory

      • cmd.exe (PID: 660)
  • INFO

    • Dropped object may contain URL's

      • chrome.exe (PID: 2240)
      • chrome.exe (PID: 1656)
      • chrome.exe (PID: 1636)
    • Application launched itself

      • chrome.exe (PID: 1656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jpg | JFIF-EXIF JPEG Bitmap (43.4)
.jpg | JPEG bitmap (26)
.mp3 | MP3 audio (ID3 v1.x tag) (21.7)
.mp3 | MP3 audio (8.6)

EXIF

EXIF

Orientation: Horizontal (normal)
XResolution: 72
YResolution: 72
ResolutionUnit: inches
Software: Adobe Photoshop CS5 Windows
ModifyDate: 2011:03:04 16:04:25
ColorSpace: sRGB
ExifImageWidth: 1920
ExifImageHeight: 1080
Compression: JPEG (old-style)
ThumbnailOffset: 314
ThumbnailLength: 1497
ThumbnailImage: (Binary data 1497 bytes, use -b option to extract)

Photoshop

IPTCDigest: 00000000000000000000000000000000
XResolution: 72
DisplayedUnitsX: inches
YResolution: 72
DisplayedUnitsY: inches
PrintStyle: Centered
PrintPosition: 0 0
PrintScale: 1
GlobalAngle: 120
GlobalAltitude: 30
URL_List:
    SlicesGroupName: angryri
    NumSlices: 1
    PixelAspectRatio: 1
    PhotoshopThumbnail: (Binary data 1497 bytes, use -b option to extract)
    HasRealMergedData: Yes
    WriterName: Adobe Photoshop
    ReaderName: Adobe Photoshop CS5
    PhotoshopQuality: 12
    PhotoshopFormat: Standard
    ProgressiveScans: 3 Scans

    XMP

    XMPToolkit: Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00
    CreatorTool: Adobe Photoshop CS5 Windows
    CreateDate: 2011:03:04 15:54:56+01:00
    MetadataDate: 2011:03:04 16:04:25+01:00
    ModifyDate: 2011:03:04 16:04:25+01:00
    InstanceID: xmp.iid:7E5FAA986D46E0119F808571FA72789C
    DocumentID: xmp.did:7D5FAA986D46E0119F808571FA72789C
    OriginalDocumentID: xmp.did:7D5FAA986D46E0119F808571FA72789C
    Format: image/jpeg
    ColorMode: RGB
    ICCProfileName: sRGB IEC61966-2.1
    HistoryAction:
    • created
    • saved
    HistoryInstanceID:
    • xmp.iid:7D5FAA986D46E0119F808571FA72789C
    • xmp.iid:7E5FAA986D46E0119F808571FA72789C
    HistoryWhen:
    • 2011:03:04 15:54:56+01:00
    • 2011:03:04 16:04:25+01:00
    HistorySoftwareAgent:
    • Adobe Photoshop CS5 Windows
    • Adobe Photoshop CS5 Windows
    HistoryChanged: /

    ICC_Profile

    ProfileCMMType: Lino
    ProfileVersion: 2.1.0
    ProfileClass: Display Device Profile
    ColorSpaceData: RGB
    ProfileConnectionSpace: XYZ
    ProfileDateTime: 1998:02:09 06:49:00
    ProfileFileSignature: acsp
    PrimaryPlatform: Microsoft Corporation
    CMMFlags: Not Embedded, Independent
    DeviceManufacturer: IEC
    DeviceModel: sRGB
    DeviceAttributes: Reflective, Glossy, Positive, Color
    RenderingIntent: Media-Relative Colorimetric
    ConnectionSpaceIlluminant: 0.9642 1 0.82491
    ProfileCreator: HP
    ProfileID: -
    ProfileCopyright: Copyright (c) 1998 Hewlett-Packard Company
    ProfileDescription: sRGB IEC61966-2.1
    MediaWhitePoint: 0.95045 1 1.08905
    MediaBlackPoint: 0 0 0
    RedMatrixColumn: 0.43607 0.22249 0.01392
    GreenMatrixColumn: 0.38515 0.71687 0.09708
    BlueMatrixColumn: 0.14307 0.06061 0.7141
    DeviceMfgDesc: IEC http://www.iec.ch
    DeviceModelDesc: IEC 61966-2.1 Default RGB colour space - sRGB
    ViewingCondDesc: Reference Viewing Condition in IEC61966-2.1
    ViewingCondIlluminant: 19.6445 20.3718 16.8089
    ViewingCondSurround: 3.92889 4.07439 3.36179
    ViewingCondIlluminantType: D50
    Luminance: 76.03647 80 87.12462
    MeasurementObserver: CIE 1931
    MeasurementBacking: 0 0 0
    MeasurementGeometry: Unknown
    MeasurementFlare: 0.999%
    MeasurementIlluminant: D65
    Technology: Cathode Ray Tube Display
    RedTRC: (Binary data 2060 bytes, use -b option to extract)
    GreenTRC: (Binary data 2060 bytes, use -b option to extract)
    BlueTRC: (Binary data 2060 bytes, use -b option to extract)

    APP14

    DCTEncodeVersion: 100
    APP14Flags0: [14]
    APP14Flags1: (none)
    ColorTransform: YCbCr

    Composite

    ImageSize: 1920x1080
    Megapixels: 2.1
    No data.
    screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
    All screenshots are available in the full report
    All screenshots are available in the full report
    Total processes
    56
    Monitored processes
    19
    Malicious processes
    1
    Suspicious processes
    0

    Behavior graph

    Click at the process to see the details
    start rundll32.exe no specs cmd.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

    Process information

    PID
    CMD
    Path
    Indicators
    Parent process
    660"C:\Windows\system32\cmd.exe" C:\Windows\system32\cmd.exe
    explorer.exe
    User:
    admin
    Company:
    Microsoft Corporation
    Integrity Level:
    MEDIUM
    Description:
    Windows Command Processor
    Exit code:
    0
    Version:
    6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Modules
    Images
    c:\windows\system32\cmd.exe
    c:\systemroot\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\windows\system32\msvcrt.dll
    c:\windows\system32\winbrand.dll
    c:\windows\system32\user32.dll
    c:\windows\system32\gdi32.dll
    c:\windows\system32\lpk.dll
    c:\windows\system32\usp10.dll
    1428"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1596,3862311064696786850,9785342244180281321,131072 --service-pipe-token=C6EAA19B1AB90C350A5100771D3A2E11 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=C6EAA19B1AB90C350A5100771D3A2E11 --renderer-client-id=6 --mojo-platform-channel-handle=1640 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
    User:
    admin
    Company:
    Google Inc.
    Integrity Level:
    LOW
    Description:
    Google Chrome
    Exit code:
    0
    Version:
    61.0.3163.100
    Modules
    Images
    c:\program files\google\chrome\application\chrome.exe
    c:\systemroot\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files\google\chrome\application\61.0.3163.100\chrome_elf.dll
    c:\windows\system32\version.dll
    c:\windows\system32\msvcrt.dll
    c:\windows\system32\advapi32.dll
    c:\windows\system32\sechost.dll
    c:\windows\system32\rpcrt4.dll
    1476"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1596,3862311064696786850,9785342244180281321,131072 --service-pipe-token=86E5B43140C5F4F265D0DCAEFDD2114F --lang=en-US --disable-client-side-phishing-detection --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=86E5B43140C5F4F265D0DCAEFDD2114F --renderer-client-id=5 --mojo-platform-channel-handle=3276 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
    User:
    admin
    Company:
    Google Inc.
    Integrity Level:
    LOW
    Description:
    Google Chrome
    Exit code:
    0
    Version:
    61.0.3163.100
    Modules
    Images
    c:\program files\google\chrome\application\chrome.exe
    c:\systemroot\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files\google\chrome\application\61.0.3163.100\chrome_elf.dll
    c:\windows\system32\version.dll
    c:\windows\system32\msvcrt.dll
    c:\windows\system32\advapi32.dll
    c:\windows\system32\sechost.dll
    c:\windows\system32\rpcrt4.dll
    1636"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1596,3862311064696786850,9785342244180281321,131072 --lang=en-US --utility-allowed-dir="C:\Users\admin\AppData\Local\Temp\scoped_dir1656_27183" --service-request-channel-token=F55E8F0D77DD2FBE58E993317D01896A --mojo-platform-channel-handle=3772 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
    User:
    admin
    Company:
    Google Inc.
    Integrity Level:
    LOW
    Description:
    Google Chrome
    Exit code:
    0
    Version:
    61.0.3163.100
    Modules
    Images
    c:\program files\google\chrome\application\chrome.exe
    c:\systemroot\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files\google\chrome\application\61.0.3163.100\chrome_elf.dll
    c:\windows\system32\version.dll
    c:\windows\system32\msvcrt.dll
    c:\windows\system32\advapi32.dll
    c:\windows\system32\sechost.dll
    c:\windows\system32\rpcrt4.dll
    1656"C:\Program Files\Google\Chrome\Application\chrome.exe" C:\Program Files\Google\Chrome\Application\chrome.exe
    explorer.exe
    User:
    admin
    Company:
    Google Inc.
    Integrity Level:
    MEDIUM
    Description:
    Google Chrome
    Exit code:
    0
    Version:
    61.0.3163.100
    Modules
    Images
    c:\program files\google\chrome\application\chrome.exe
    c:\systemroot\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files\google\chrome\application\61.0.3163.100\chrome_elf.dll
    c:\windows\system32\version.dll
    c:\windows\system32\msvcrt.dll
    c:\windows\system32\advapi32.dll
    c:\windows\system32\sechost.dll
    c:\windows\system32\rpcrt4.dll
    2076"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1596,3862311064696786850,9785342244180281321,131072 --lang=en-US --service-request-channel-token=912E638CF2584C833780FC94F60DFD16 --mojo-platform-channel-handle=1220 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
    User:
    admin
    Company:
    Google Inc.
    Integrity Level:
    LOW
    Description:
    Google Chrome
    Exit code:
    0
    Version:
    61.0.3163.100
    Modules
    Images
    c:\program files\google\chrome\application\chrome.exe
    c:\systemroot\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files\google\chrome\application\61.0.3163.100\chrome_elf.dll
    c:\windows\system32\version.dll
    c:\windows\system32\msvcrt.dll
    c:\windows\system32\advapi32.dll
    c:\windows\system32\sechost.dll
    c:\windows\system32\rpcrt4.dll
    2220"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1596,3862311064696786850,9785342244180281321,131072 --service-pipe-token=3014153EE60856A440220DC23B55BD73 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=3014153EE60856A440220DC23B55BD73 --renderer-client-id=2 --mojo-platform-channel-handle=1744 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
    User:
    admin
    Company:
    Google Inc.
    Integrity Level:
    LOW
    Description:
    Google Chrome
    Exit code:
    0
    Version:
    61.0.3163.100
    Modules
    Images
    c:\program files\google\chrome\application\chrome.exe
    c:\systemroot\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files\google\chrome\application\61.0.3163.100\chrome_elf.dll
    c:\windows\system32\version.dll
    c:\windows\system32\msvcrt.dll
    c:\windows\system32\advapi32.dll
    c:\windows\system32\sechost.dll
    c:\windows\system32\rpcrt4.dll
    2240"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1596,3862311064696786850,9785342244180281321,131072 --lang=en-US --utility-allowed-dir="C:\Users\admin\AppData\Local\Temp\scoped_dir1656_31941" --service-request-channel-token=A25DE74F155CC246537E2DD729FBB8A7 --mojo-platform-channel-handle=1816 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
    User:
    admin
    Company:
    Google Inc.
    Integrity Level:
    LOW
    Description:
    Google Chrome
    Exit code:
    0
    Version:
    61.0.3163.100
    Modules
    Images
    c:\program files\google\chrome\application\chrome.exe
    c:\systemroot\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files\google\chrome\application\61.0.3163.100\chrome_elf.dll
    c:\windows\system32\version.dll
    c:\windows\system32\msvcrt.dll
    c:\windows\system32\advapi32.dll
    c:\windows\system32\sechost.dll
    c:\windows\system32\rpcrt4.dll
    2604"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=1288 --on-initialized-event-handle=296 --parent-handle=300 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
    User:
    admin
    Company:
    Google Inc.
    Integrity Level:
    MEDIUM
    Description:
    Google Chrome
    Exit code:
    0
    Version:
    61.0.3163.100
    Modules
    Images
    c:\program files\google\chrome\application\chrome.exe
    c:\systemroot\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files\google\chrome\application\61.0.3163.100\chrome_elf.dll
    c:\windows\system32\version.dll
    c:\windows\system32\msvcrt.dll
    c:\windows\system32\advapi32.dll
    c:\windows\system32\sechost.dll
    c:\windows\system32\rpcrt4.dll
    2844"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1596,3862311064696786850,9785342244180281321,131072 --lang=en-US --no-sandbox --service-request-channel-token=8B36A0038FC19B67CAA42171090405A4 --mojo-platform-channel-handle=4184 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
    User:
    admin
    Company:
    Google Inc.
    Integrity Level:
    MEDIUM
    Description:
    Google Chrome
    Exit code:
    0
    Version:
    61.0.3163.100
    Modules
    Images
    c:\program files\google\chrome\application\chrome.exe
    c:\systemroot\system32\ntdll.dll
    c:\windows\system32\kernel32.dll
    c:\windows\system32\kernelbase.dll
    c:\program files\google\chrome\application\61.0.3163.100\chrome_elf.dll
    c:\windows\system32\version.dll
    c:\windows\system32\msvcrt.dll
    c:\windows\system32\advapi32.dll
    c:\windows\system32\sechost.dll
    c:\windows\system32\rpcrt4.dll
    Total events
    245
    Read events
    137
    Write events
    102
    Delete events
    6

    Modification events

    (PID) Process:(3860) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
    Operation:writeName:Name
    Value:
    rundll32.exe
    (PID) Process:(3860) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows Photo Viewer\Viewer
    Operation:writeName:MainWndPos
    Value:
    6000000034000000A00400008002000000000000
    (PID) Process:(1656) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
    Operation:writeName:failed_count
    Value:
    0
    (PID) Process:(1656) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
    Operation:writeName:state
    Value:
    2
    (PID) Process:(1656) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
    Operation:writeName:state
    Value:
    1
    (PID) Process:(1656) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
    Operation:writeName:dr
    Value:
    1
    (PID) Process:(2604) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
    Operation:writeName:1656-13170437167172750
    Value:
    259
    (PID) Process:(1656) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
    Operation:writeName:UsageStatsInSample
    Value:
    1
    (PID) Process:(1656) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
    Operation:delete valueName:1924-13166792512537109
    Value:
    0
    (PID) Process:(1656) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
    Operation:writeName:usagestats
    Value:
    0
    Executable files
    0
    Suspicious files
    45
    Text files
    185
    Unknown types
    4

    Dropped files

    PID
    Process
    Filename
    Type
    1656chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000038.dbtmp
    MD5:
    SHA256:
    1656chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\f7aa21e6-c63a-4c1b-8136-e04ed4f1d859.tmp
    MD5:
    SHA256:
    1656chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\index
    MD5:
    SHA256:
    1656chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
    MD5:
    SHA256:
    1656chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
    MD5:
    SHA256:
    1656chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
    MD5:
    SHA256:
    1656chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
    MD5:
    SHA256:
    1656chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\000001.dbtmp
    MD5:
    SHA256:
    1656chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.ru_0.indexeddb.leveldb\000001.dbtmp
    MD5:
    SHA256:
    1656chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF133f1f.TMPtext
    MD5:2C1B2EBFEB29A28B64B7CD003FBFD758
    SHA256:1D864BCF3B655C5EBC05CC00B7512E7CECF1C65E6950F3B0AF0222CC8ED62B87
    Download PCAP, analyze network streams, HTTP content and a lot more at the full report
    HTTP(S) requests
    5
    TCP/UDP connections
    44
    DNS requests
    30
    Threats
    0

    HTTP requests

    PID
    Process
    Method
    HTTP Code
    IP
    URL
    CN
    Type
    Size
    Reputation
    1656
    chrome.exe
    GET
    200
    74.125.111.135:80
    http://r1---sn-hpa7znse.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYzU3QUFWbnlGT3kzQWtjM3lqNzVJallBUQ/1.0.0.4_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&ip=104.207.76.53&ipbits=0&mm=28&mn=sn-hpa7znse&ms=nvh&mt=1525963467&mv=m&pl=24&shardbypass=yes
    US
    crx
    184 Kb
    whitelisted
    1656
    chrome.exe
    GET
    200
    216.58.207.78:80
    http://clients1.google.com/tools/pso/ping?as=chrome&brand=GCEA&pid=&hl=en&rep=2&rlz=C1:1C1GCEA_enDE765UA770,C2:1C2GCEA_enDE765,C7:1C7GCEA_enDE765
    US
    text
    124 b
    whitelisted
    1656
    chrome.exe
    GET
    302
    172.217.22.78:80
    http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvMDczQUFWWkx6SzVQNEg1NzJ1NDh0TENtUQ/6117.717.0.4_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx
    US
    html
    516 b
    whitelisted
    1656
    chrome.exe
    GET
    302
    172.217.22.78:80
    http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYzU3QUFWbnlGT3kzQWtjM3lqNzVJallBUQ/1.0.0.4_nmmhkkegccagdldgiimedpiccmgmieda.crx
    US
    html
    511 b
    whitelisted
    1656
    chrome.exe
    GET
    200
    74.125.111.153:80
    http://r3---sn-hpa7znsl.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvMDczQUFWWkx6SzVQNEg1NzJ1NDh0TENtUQ/6117.717.0.4_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&ip=104.207.76.53&ipbits=0&mm=28&mn=sn-hpa7znsl&ms=nvh&mt=1525963467&mv=m&pl=24&shardbypass=yes
    US
    crx
    871 Kb
    whitelisted
    Download PCAP, analyze network streams, HTTP content and a lot more at the full report

    Connections

    PID
    Process
    IP
    Domain
    ASN
    CN
    Reputation
    1656
    chrome.exe
    172.217.22.35:443
    www.google.ru
    Google Inc.
    US
    whitelisted
    1656
    chrome.exe
    216.58.207.78:443
    apis.google.com
    Google Inc.
    US
    whitelisted
    1656
    chrome.exe
    172.217.23.142:443
    www.youtube.com
    Google Inc.
    US
    whitelisted
    1656
    chrome.exe
    172.217.21.226:443
    adservice.google.it
    Google Inc.
    US
    whitelisted
    1656
    chrome.exe
    172.217.133.168:443
    r3---sn-hpa7znsk.googlevideo.com
    Google Inc.
    US
    whitelisted
    1656
    chrome.exe
    172.217.22.98:443
    googleads.g.doubleclick.net
    Google Inc.
    US
    whitelisted
    1656
    chrome.exe
    172.217.21.195:443
    www.gstatic.com
    Google Inc.
    US
    whitelisted
    1656
    chrome.exe
    172.217.22.78:80
    www.youtube.com
    Google Inc.
    US
    whitelisted
    1656
    chrome.exe
    74.125.111.153:80
    r3---sn-hpa7znsl.gvt1.com
    Google Inc.
    US
    whitelisted
    1656
    chrome.exe
    74.125.111.135:80
    r1---sn-hpa7znse.gvt1.com
    Google Inc.
    US
    whitelisted

    DNS requests

    Domain
    IP
    Reputation
    clientservices.googleapis.com
    • 216.58.206.3
    whitelisted
    www.google.ru
    • 172.217.22.35
    whitelisted
    ssl.gstatic.com
    • 216.58.205.227
    whitelisted
    www.gstatic.com
    • 216.58.207.67
    • 172.217.21.195
    whitelisted
    apis.google.com
    • 216.58.207.78
    whitelisted
    www.google.com
    • 216.58.214.68
    malicious
    www.google.it
    • 172.217.22.35
    whitelisted
    consent.google.com
    • 64.233.167.102
    • 64.233.167.138
    • 64.233.167.139
    • 64.233.167.113
    • 64.233.167.101
    • 64.233.167.100
    shared
    adservice.google.it
    • 172.217.21.226
    whitelisted
    www.youtube.com
    • 172.217.23.142
    • 216.58.206.14
    • 216.58.207.46
    • 216.58.207.78
    • 216.58.214.78
    • 172.217.16.174
    • 216.58.208.46
    • 172.217.22.78
    • 216.58.210.14
    • 172.217.16.206
    • 216.58.205.238
    • 172.217.21.206
    • 172.217.21.238
    • 172.217.22.14
    • 172.217.18.14
    • 172.217.18.174
    whitelisted

    Threats

    No threats detected
    No debug info