| URL: | http://dynssi.net/0f8aac5497?l=10 |
| Full analysis: | https://app.any.run/tasks/69b7f5ca-82af-41c1-b334-0c00c772f337 |
| Verdict: | No threats detected |
| Analysis date: | November 18, 2019, 03:37:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 37A86D3B60C24A34EF8F2AAD6E06A3EA |
| SHA1: | 241E3A986792EB76D0D674DB0AAC63B96A460F60 |
| SHA256: | 1EA3EDD5C56CD805A4E84D73A921A4AD999600283C351B580E75DCA89D489038 |
| SSDEEP: | 3:N1KacL+zZGQS:Ca9lHS |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 392 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,3398346313461323196,5557776554578625593,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=14707115539093272213 --mojo-platform-channel-handle=4304 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 720 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,3398346313461323196,5557776554578625593,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=9323149734633935819 --mojo-platform-channel-handle=3504 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 748 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,3398346313461323196,5557776554578625593,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=18431067383949244289 --mojo-platform-channel-handle=4216 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1044 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=532 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1048 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,3398346313461323196,5557776554578625593,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=2805351093085750031 --renderer-client-id=22 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3964 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1404 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,3398346313461323196,5557776554578625593,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=18136605249616429798 --mojo-platform-channel-handle=3360 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1532 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1004,3398346313461323196,5557776554578625593,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=3095916793459536237 --mojo-platform-channel-handle=1024 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1712 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,3398346313461323196,5557776554578625593,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6580192723868937219 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2476 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1768 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,3398346313461323196,5557776554578625593,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=7170636624042324670 --mojo-platform-channel-handle=3792 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1876 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,3398346313461323196,5557776554578625593,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=17231112115726524151 --mojo-platform-channel-handle=1588 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (2580) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2580) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2580) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2580) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2580) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1044) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2580-13218521877932375 |
Value: 259 | |||
| (PID) Process: | (2580) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2580) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2580) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 1512-13197841398593750 |
Value: 0 | |||
| (PID) Process: | (2580) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\b49491e7-0117-4fa0-abba-4a92718f7e8c.tmp | — | |
MD5:— | SHA256:— | |||
| 2580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF39a95a.TMP | text | |
MD5:— | SHA256:— | |||
| 2580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
| 2580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF39a969.TMP | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1876 | chrome.exe | GET | 200 | 52.31.150.82:80 | http://dynssi.net/0f8aac5497?l=10 | IE | html | 917 b | suspicious |
1876 | chrome.exe | GET | 200 | 52.31.150.82:80 | http://dynssi.net/assets/google-tracking.js?g=0f8aac5497 | IE | text | 316 b | suspicious |
1876 | chrome.exe | GET | 200 | 52.31.150.82:80 | http://dynssi.net/assets/all.js?g=0f8aac5497 | IE | text | 7.17 Kb | suspicious |
1876 | chrome.exe | GET | 302 | 172.217.23.110:80 | http://www.google-analytics.com/r/collect?v=1&_v=j79&a=1460730238&t=pageview&_s=1&dl=http%3A%2F%2Fdynssi.net%2F0f8aac5497%3Fl%3D10&ul=en-us&de=UTF-8&sd=24-bit&sr=1280x720&vp=1280x572&je=0&_u=IEBAAEAB~&jid=679674719&gjid=1432267861&cid=909392006.1574048281&tid=UA-83403-17&_gid=1581779514.1574048281&_r=1&z=2079810830 | US | html | 416 b | whitelisted |
1876 | chrome.exe | GET | 200 | 52.31.150.82:80 | http://dynssi.net/trace?id=0f8aac5497&msg=BrowserDetect%20-%20localStorage%20%3D%20true&correlation_id=d8b183f4-6b28-4180-8d20-c965d15b888d | IE | binary | 20 b | suspicious |
1876 | chrome.exe | GET | 200 | 52.31.150.82:80 | http://dynssi.net/trace?id=unknown&msg=get-id%20is%20undefined&correlation_id=d8b183f4-6b28-4180-8d20-c965d15b888d | IE | binary | 20 b | suspicious |
1876 | chrome.exe | GET | 200 | 52.31.150.82:80 | http://dynssi.net/trace?id=unknown&msg=did%20not%20find%20guid%20in%20last%20part%20of%20location&correlation_id=d8b183f4-6b28-4180-8d20-c965d15b888d | IE | binary | 20 b | suspicious |
1876 | chrome.exe | GET | 200 | 52.31.150.82:80 | http://dynssi.net/trace?id=0f8aac5497&msg=BrowserDetect%20-%20sessionStorage%20%3D%20true&correlation_id=d8b183f4-6b28-4180-8d20-c965d15b888d | IE | binary | 20 b | suspicious |
1876 | chrome.exe | GET | 200 | 172.217.23.110:80 | http://www.google-analytics.com/collect?v=1&_v=j79&a=881013201&t=pageview&_s=2&dl=http%3A%2F%2Fdynssi.net%2Fload_training%3Fguid%3D0f8aac5497%26correlation_id%3Dd8b183f4-6b28-4180-8d20-c965d15b888d&ul=en-us&de=UTF-8&sd=24-bit&sr=1280x720&vp=1264x572&je=0&_u=QACAAEAB~&jid=&gjid=&cid=909392006.1574048281&tid=UA-83403-17&_gid=1581779514.1574048281&z=1394400196 | US | image | 35 b | whitelisted |
1876 | chrome.exe | GET | 200 | 172.217.16.170:80 | http://ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.min.js | US | text | 32.2 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1876 | chrome.exe | 52.31.150.82:80 | dynssi.net | Amazon.com, Inc. | IE | unknown |
1876 | chrome.exe | 52.31.150.82:49152 | dynssi.net | Amazon.com, Inc. | IE | unknown |
1876 | chrome.exe | 172.217.16.170:80 | ajax.googleapis.com | Google Inc. | US | whitelisted |
1876 | chrome.exe | 52.216.137.132:443 | tslp.s3.amazonaws.com | Amazon.com, Inc. | US | shared |
1876 | chrome.exe | 143.204.208.162:80 | d2wy8f7a9ursnm.cloudfront.net | — | US | malicious |
1876 | chrome.exe | 172.217.23.110:80 | www.google-analytics.com | Google Inc. | US | whitelisted |
1876 | chrome.exe | 52.31.150.82:443 | dynssi.net | Amazon.com, Inc. | IE | unknown |
1876 | chrome.exe | 74.125.206.156:443 | stats.g.doubleclick.net | Google Inc. | US | whitelisted |
1876 | chrome.exe | 216.58.207.68:443 | www.google.com | Google Inc. | US | whitelisted |
1876 | chrome.exe | 172.217.22.67:443 | www.google.it | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
dynssi.net |
| unknown |
accounts.google.com |
| shared |
tslp.s3.amazonaws.com |
| shared |
d2wy8f7a9ursnm.cloudfront.net |
| shared |
ajax.googleapis.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
dataentry.eu.threatsim.com |
| suspicious |
stats.g.doubleclick.net |
| whitelisted |
www.google.com |
| malicious |