| URL: | https://urldefense.com/v3/__https://avredir.com/s/a3z24Ei6yfH2__;!!CYQycLDRcg!4SpdLF2k7vsGwJrhkZ4nXc63MSrREriYkThgJqmVXsUlvrp3opdRm2XaK0sv7Oqh2Bs4gfQ$ |
| Full analysis: | https://app.any.run/tasks/19cbb2ed-4260-43db-9617-864cf63c75c9 |
| Verdict: | Malicious activity |
| Analysis date: | February 05, 2021, 21:31:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 4AF86C4F9C2FC1C55FD90F1E7FD6692B |
| SHA1: | 7102FA0E55C0C8CA1B8F4F37F401D92DDDF0E1DC |
| SHA256: | 0BC9479B7B92ACFE4DFBD313DA85F6A341FB215093C1B1D257F81A7818A04A15 |
| SSDEEP: | 3:N8U2DAL5IKTWK66NR0mRe61tm8cPO2r0pTa3xN1OHToXrUZl:2UJtIrhVElry09aBNwzF |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 184 | cmd /c reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20" /v ProfileImagePath | C:\Windows\system32\cmd.exe | — | wscript.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 184 | \??\C:\Windows\system32\conhost.exe "-73684062418934071513944517091849645272008767169-932283602-557567937-1467260456" | C:\Windows\system32\conhost.exe | — | csrss.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 236 | "C:\Windows\system32\Dwm.exe" | C:\Windows\System32\dwm.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Desktop Window Manager Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 264 | \SystemRoot\System32\smss.exe | C:\Windows\System32\smss.exe | System | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Session Manager Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 272 | cmd /c echo %PROCESSOR_ARCHITEW6432% | C:\Windows\system32\cmd.exe | — | wscript.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 320 | \??\C:\Windows\system32\conhost.exe "-1644028916137653106-382274838-18416767111155376076-2067736481261866964-556627205" | C:\Windows\system32\conhost.exe | — | csrss.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 336 | "C:\Program Files\PCMatic\PC Matic\\ntrights.exe" +r SeCreateGlobalPrivilege -u PCPitstopSVC | C:\Program Files\PCMatic\PC Matic\ntrights.exe | — | cmd.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 344 | sc query "PCPitstop Scheduling" | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 344 | regsvr32.exe /s jscript.dll | C:\Windows\system32\regsvr32.exe | — | PCPitstopScheduleService.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 348 | %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 | C:\Windows\System32\csrss.exe | — | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Client Server Runtime Process Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1236) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (1236) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (1236) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (1236) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2176) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 1236-13257034316626500 |
Value: 259 | |||
| (PID) Process: | (1236) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1236) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (1236) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (1236) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3252-13245750958665039 |
Value: 0 | |||
| (PID) Process: | (1236) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1236 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-601DB94D-4D4.pma | — | |
MD5:— | SHA256:— | |||
| 1236 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\80bc75a3-f529-4f2b-8f62-291c86434891.tmp | — | |
MD5:— | SHA256:— | |||
| 1236 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp | — | |
MD5:— | SHA256:— | |||
| 828 | svchost.exe | C:\Windows\ServiceProfiles\LocalService\AppData\Local\~FontCache-S-1-5-21-1302019708-1500728564-335382590-1000.dat | — | |
MD5:— | SHA256:— | |||
| 856 | svchost.exe | C:\Windows\appcompat\programs\RecentFileCache.bcf | txt | |
MD5:— | SHA256:— | |||
| 1236 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 1236 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RFced34.TMP | text | |
MD5:— | SHA256:— | |||
| 1236 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 1236 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old~RFced92.TMP | text | |
MD5:— | SHA256:— | |||
| 1236 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2208 | chrome.exe | GET | 302 | 216.239.36.21:80 | http://virustotal.com/ | US | — | — | whitelisted |
1848 | MsiExec.exe | GET | 200 | 23.51.123.27:80 | http://t2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEHGgtzaV3bGvwjsrmhjuVMs%3D | NL | der | 1.52 Kb | whitelisted |
1848 | MsiExec.exe | GET | 200 | 23.51.123.27:80 | http://tl.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSFBjxN%2BWY73bfUnSOp7HDKJ%2Fbx0wQUV4abVLi%2BpimK5PbC4hMYiYXN3LcCEAkk53ol4NPmnzTXlIvuJVw%3D | NL | der | 1.40 Kb | whitelisted |
1048 | svchost.exe | GET | 200 | 8.241.122.126:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.7 Kb | whitelisted |
2792 | wscript.exe | GET | 200 | 23.51.123.27:80 | http://tl.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSFBjxN%2BWY73bfUnSOp7HDKJ%2Fbx0wQUV4abVLi%2BpimK5PbC4hMYiYXN3LcCEAkk53ol4NPmnzTXlIvuJVw%3D | NL | der | 1.40 Kb | whitelisted |
2792 | wscript.exe | GET | 200 | 23.51.123.27:80 | http://t2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEHGgtzaV3bGvwjsrmhjuVMs%3D | NL | der | 1.52 Kb | whitelisted |
1792 | PCPitstopRTService.exe | GET | 200 | 2.16.186.120:80 | http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | unknown | der | 781 b | whitelisted |
1792 | PCPitstopRTService.exe | GET | 200 | 2.16.186.120:80 | http://crl.microsoft.com/pki/crl/products/WinPCA.crl | unknown | der | 530 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2208 | chrome.exe | 52.71.28.102:443 | urldefense.com | Amazon.com, Inc. | US | suspicious |
2208 | chrome.exe | 104.21.9.82:443 | avredir.com | Cloudflare Inc | US | unknown |
2208 | chrome.exe | 64.233.177.84:443 | accounts.google.com | Google Inc. | US | unknown |
2208 | chrome.exe | 142.250.185.195:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
2208 | chrome.exe | 104.20.82.39:443 | www.pcpitstop.com | Cloudflare Inc | US | shared |
2208 | chrome.exe | 142.250.186.78:443 | sb-ssl.google.com | Google Inc. | US | whitelisted |
2208 | chrome.exe | 52.204.90.22:443 | urldefense.com | Amazon.com, Inc. | US | suspicious |
2208 | chrome.exe | 142.250.186.67:443 | www.google.com.ua | Google Inc. | US | whitelisted |
2208 | chrome.exe | 172.217.16.131:443 | www.gstatic.com | Google Inc. | US | whitelisted |
2208 | chrome.exe | 142.250.185.142:443 | apis.google.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
urldefense.com |
| shared |
accounts.google.com |
| shared |
avredir.com |
| unknown |
www.pcpitstop.com |
| suspicious |
files.pcpitstop.com |
| suspicious |
ssl.gstatic.com |
| whitelisted |
sb-ssl.google.com |
| whitelisted |
www.google.com.ua |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
Process | Message |
|---|---|
PCMaticRT.exe | PidOwner.cpp(49) : [21:33:29] Unicode; Domain:|NT AUTHORITY| User:|SYSTEM|
|
PCMaticRT.exe | Realtime.cpp(339) : [21:33:29] Log file path 'C:\ProgramData\PCPitstop'
|
PCMaticRT.exe | LimitSingleInstance.h(35) : [21:33:29] CLimitSingleInstance: m_hMutex=140 m_dwLastError=0
|
PCMaticRT.exe | Realtime.cpp(392) : [21:33:29] PCMaticRT directory location=C:\Program Files\PCPitstop\Super Shield
|
PCMaticRT.exe | Realtime.cpp(416) : [21:33:29] Load language library dll C:\Program Files\PCPitstop\Super Shield\PCMaticRTen.dll
|
PCMaticRT.exe | ClientComm.cpp(699) : [21:33:29] pid=2356
|
PCMaticRT.exe | PidOwner.cpp(49) : [21:33:29] Unicode; Domain:|NT AUTHORITY| User:|SYSTEM|
|
PCMaticRT.exe | NamedPipe.cpp(120) : [21:33:29] Client opening pipes
|
PCMaticRT.exe | NamedPipe.cpp(125) : [21:33:29] Pipes not ready, sleeping for 5 seconds. Error=2
|
PCPitstopRTService.exe | NTService.cpp(588) : [21:33:29.489] (3600) Start PCMATICRTService
|