| download: | misc_download2.php |
| Full analysis: | https://app.any.run/tasks/0cdc68a6-fede-411d-a879-050a6f5e0943 |
| Verdict: | Malicious activity |
| Analysis date: | July 31, 2020, 20:23:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/html |
| File info: | HTML document, UTF-8 Unicode text, with very long lines |
| MD5: | 004FB48C6EE799252F0370F771BC8E0E |
| SHA1: | A3CC05075D47DBFCAD5B1694360BC428AEDB241C |
| SHA256: | 12A7B40D78590E682045B72C28838E9B94E864662A19BCA84B8396A9D46116B7 |
| SSDEEP: | 768:QiVylLsjWnradLz6sjrZZ+wIoblr5fQoBr:QiVz0gf/V |
| .htm/html | | | HyperText Markup Language with DOCTYPE (80.6) |
|---|---|---|
| .html | | | HyperText Markup Language (19.3) |
| Title: | Download LastPass | LastPass |
|---|---|
| HTTPEquivXUACompatible: | IE=edge |
| referrer: | origin |
| viewport: | width=device-width, initial-scale=1 |
| ContentType: | text/html;charset=utf-8 |
| ContentStyleType: | text/css |
| Keywords: | last password, last pass, remember password, remember passwords, password manager, online password manager, password, password management, password recovery, recover password, export passwords, form fill, formfill, form filler, safe password, local encryption, generate password, password generator, identity theft protection |
| Description: | LastPass is an online password manager and form filler that makes web browsing easier and more secure. |
| comSilverpopBrandeddomains: | www.pages04.net,appguru.com,boldchat.com,boldchat.dev.cms.3amlabs.net,boldchat.local.noclab.net,cubby.com,dcjoinme.cms.3amlabs.net,gamma.boldchat.com,gamma.join.me,gamma.logmein.com,gamma.logmeininc.com,gamma.logmeinrescue.com,join.me,joinmedev.cms.3amlabs.net,lastpass.com,logmein.com,logmeininc-cm.logmeindev.local,logmeininc-dev,logmeininc.cms.3amlabs.net,logmeininc.com,logmeininc.local.noclab.net,logmeinrescue.com,rescue.local.noclab.net,rescuedev.cms.3amlabs.net,review.boldchat.com,review.join.me,review.logmein.com,review.logmeininc.com,review.logmeinrescue.com,secure.logmein.com,sitecore01-001.boldchat.com,sitecore01-001.join.me,sitecore01-001.logmeininc.com,sitecore01-001.logmeinrescue.com,sitecore02-001.boldchat.com,sitecore02-001.join.me,sitecore02-001.logmeininc.com,sitecore02-001.logmeinrescue.com,sitecore03-001.boldchat.com,sitecore03-001.join.me,sitecore03-001.logmeininc.com,sitecore03-001.logmeinrescue.com,sitecore04-001.boldchat.com,sitecore04-001.join.me,sitecore04-001.logmeininc.com,sitecore04-001.logmeinrescue.com,sitecore05-001.boldchat.com,sitecore05-001.join.me,sitecore05-001.logmeininc.com,sitecore05-001.logmeinrescue.com,solutions.appguru.com,solutions.boldchat.com,solutions.cubby.com,solutions.join.me,solutions.lastpass.com,solutions.logmein.com,solutions.logmeinrescue-enterprise.com,solutions.logmeinrescue.com,solutions.xively.com,test.boldchat.com,www.boldchat.com,www.cubby.com,www.join.me,www.logmein.com,www.logmeininc.com,www.logmeinrescue.com,www.xively.com,xively.com |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 256 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1016,12483410321735463651,12792608159611881203,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=6606753781497255974 --mojo-platform-channel-handle=1932 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 440 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\misc_download2.php | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 924 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1016,12483410321735463651,12792608159611881203,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8333700374926296494 --renderer-client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3604 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1012 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1016,12483410321735463651,12792608159611881203,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=18089044280856645211 --renderer-client-id=31 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3848 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1076 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6eb1a9d0,0x6eb1a9e0,0x6eb1a9ec | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1140 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1016,12483410321735463651,12792608159611881203,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=9291898380361174495 --mojo-platform-channel-handle=3880 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1320 | rundll32.exe "C:\Windows\Installer\MSI4FD2.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1003484 22 CustomActions!CustomActions.CustomActions.SetDirectoryPermissions | C:\Windows\system32\rundll32.exe | MsiExec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1468 | rundll32.exe "C:\Windows\Installer\MSI89B3.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1018328 36 CustomActions!CustomActions.CustomActions.DisableSideloading | C:\Windows\system32\rundll32.exe | MsiExec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1508 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1016,12483410321735463651,12792608159611881203,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=14771331435546777139 --mojo-platform-channel-handle=3576 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1544 | "C:\program files\mozilla firefox\firefox.exe" https://addons.mozilla.org/en-US/firefox/addon/lastpass-password-manager/ | C:\program files\mozilla firefox\firefox.exe | — | LastPassInstaller.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| (PID) Process: | (3952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (3952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 2832-13239195546717773 |
Value: 0 | |||
| (PID) Process: | (3952) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3952-13240700650404750 |
Value: 259 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000032.dbtmp | — | |
MD5:— | SHA256:— | |||
| 3952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\fe393d0a-2b31-4e1b-9662-5f8593e38b9e.tmp | — | |
MD5:— | SHA256:— | |||
| 3952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RFd8daa.TMP | text | |
MD5:— | SHA256:— | |||
| 3952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | text | |
MD5:— | SHA256:— | |||
| 3952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\000001.dbtmp | — | |
MD5:— | SHA256:— | |||
| 3952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RFd8daa.TMP | text | |
MD5:— | SHA256:— | |||
| 3952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | text | |
MD5:— | SHA256:— | |||
| 3952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Tabs | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2208 | firefox.exe | POST | — | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | — | — | whitelisted |
2544 | opera.exe | GET | — | 93.184.220.29:80 | http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl | US | — | — | whitelisted |
2208 | firefox.exe | POST | — | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | — | — | whitelisted |
2208 | firefox.exe | POST | — | 172.217.18.99:80 | http://ocsp.pki.goog/gts1o1core | US | — | — | whitelisted |
2208 | firefox.exe | POST | — | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | — | — | whitelisted |
2208 | firefox.exe | POST | — | 172.217.18.99:80 | http://ocsp.pki.goog/gts1o1core | US | — | — | whitelisted |
2544 | opera.exe | GET | — | 172.217.18.99:80 | http://ocsp.pki.goog/gts1o1core/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEGFpmz%2Bo1EPiCAAAAABL9JI%3D | US | — | — | whitelisted |
2544 | opera.exe | GET | — | 172.217.18.99:80 | http://crl.pki.goog/gsr2/gsr2.crl | US | — | — | whitelisted |
2544 | opera.exe | GET | — | 93.184.220.29:80 | http://crl3.digicert.com/DigiCertGlobalRootCA.crl | US | — | — | whitelisted |
2544 | opera.exe | GET | — | 172.217.18.99:80 | http://ocsp.pki.goog/gts1o1core/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEDGoSaOuAphrCAAAAABL9JA%3D | US | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2900 | chrome.exe | 172.217.18.173:443 | accounts.google.com | Google Inc. | US | whitelisted |
2900 | chrome.exe | 216.58.206.4:443 | www.google.com | Google Inc. | US | whitelisted |
2900 | chrome.exe | 172.217.23.138:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
2900 | chrome.exe | 216.58.212.163:443 | www.gstatic.com | Google Inc. | US | whitelisted |
2900 | chrome.exe | 172.217.18.3:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
2900 | chrome.exe | 172.217.18.110:443 | ogs.google.com | Google Inc. | US | whitelisted |
2900 | chrome.exe | 172.217.22.14:443 | clients2.google.com | Google Inc. | US | whitelisted |
2900 | chrome.exe | 216.58.208.35:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
2900 | chrome.exe | 172.217.18.174:443 | consent.google.com | Google Inc. | US | whitelisted |
2900 | chrome.exe | 172.217.18.2:443 | adservice.google.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| malicious |
fonts.googleapis.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
apis.google.com |
| whitelisted |
ogs.google.com |
| whitelisted |
clients2.google.com |
| whitelisted |
ssl.gstatic.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1048 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
1048 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
2544 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2544 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2544 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2544 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |