| URL: | https://yotube.com |
| Full analysis: | https://app.any.run/tasks/e798f122-a6c1-4d7b-8950-5ef9fa88707e |
| Verdict: | Malicious activity |
| Analysis date: | June 20, 2024, 14:55:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 233BD4020A19C745F3B11B35E734E416 |
| SHA1: | CEBCD601643D2834F4B2E9F74A588FA22E073E18 |
| SHA256: | 2CA7CE78DD9733DE242675DDEA47C27EFBF9430067A816507B0B3F865FBD385E |
| SSDEEP: | 3:N8vQBn:2IB |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1180 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=2176 --field-trial-handle=1156,i,9403669799957609460,6596628796895888328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1460 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2028 --field-trial-handle=1156,i,9403669799957609460,6596628796895888328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1488 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=3624 --field-trial-handle=1156,i,9403669799957609460,6596628796895888328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1504 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1500 --field-trial-handle=1156,i,9403669799957609460,6596628796895888328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1524 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=3456 --field-trial-handle=1156,i,9403669799957609460,6596628796895888328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1968 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=20 --mojo-platform-channel-handle=3988 --field-trial-handle=1156,i,9403669799957609460,6596628796895888328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1992 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=4196 --field-trial-handle=1156,i,9403669799957609460,6596628796895888328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2008 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=24 --mojo-platform-channel-handle=3812 --field-trial-handle=1156,i,9403669799957609460,6596628796895888328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2020 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=2900 --field-trial-handle=1156,i,9403669799957609460,6596628796895888328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2100 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1068 --field-trial-handle=1156,i,9403669799957609460,6596628796895888328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| (PID) Process: | (3700) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3700) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3700) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (3700) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3700) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3700) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3700) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (3700) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3700) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3700) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3700 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF4e6e2.TMP | — | |
MD5:— | SHA256:— | |||
| 3700 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3700 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old~RF4e933.TMP | text | |
MD5:65239F35CB63C76EA1F59EF64F7AAFF4 | SHA256:252EF82CC03FDE4BEF13CF81CD1AC5CE45854212D1A7359035E7A5D6BEDBE229 | |||
| 3700 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:456D3EF989973A7C218E338A6CFFAD25 | SHA256:75631D994431F254B94255C50038A3657BFC45D76FCE9D794D514E57CA678872 | |||
| 3700 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Variations | binary | |
MD5:961E3604F228B0D10541EBF921500C86 | SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED | |||
| 3700 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\3e5c9ad2-979d-432c-99fe-510a56230649.tmp | binary | |
MD5:5058F1AF8388633F609CADB75A75DC9D | SHA256:— | |||
| 3700 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF4ef4e.TMP | — | |
MD5:— | SHA256:— | |||
| 3700 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3700 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:9C016064A1F864C8140915D77CF3389A | SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787 | |||
| 3700 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old~RF5071c.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3144 | chrome.exe | GET | 302 | 198.134.116.17:80 | http://click-v4.expdirclk.com/click?i=F6KRYxdNoJ8_0 | unknown | — | — | unknown |
1372 | svchost.exe | GET | 304 | 95.101.75.118:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33 | unknown | — | — | unknown |
1372 | svchost.exe | GET | 200 | 2.18.79.138:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
3144 | chrome.exe | GET | 302 | 198.134.116.17:80 | http://click-v4.expdirclk.com/click?i=h1BZ0Iz9pRw_0 | unknown | — | — | unknown |
1372 | svchost.exe | GET | 200 | 2.17.245.133:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
1060 | svchost.exe | GET | 304 | 95.101.75.76:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a9f83325acc8ca75 | unknown | — | — | unknown |
844 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/lvx4ng4qhhp4kpddwmwjgzrumu_2024.6.5.140657/eeigpngbgcognadeebkilcpcaedhellh_2024.06.05.140657_all_ccj7nw5iotmqmvpbhiiji4wfca.crx3 | unknown | — | — | unknown |
3144 | chrome.exe | GET | 302 | 142.93.240.225:80 | http://www.torcklmi.com/feed/click/?t1=128&tid=653&uid=3&subid=355570&id=8094d97651a0ddba54e12ee0b56cd5ca:09a54380eb2acb3f81c21cbef78121f808e2bd583bb76dc11e94e76700104134ca0f638a42be22a765eff33346d6b9d9ef01691a677ef06a8835043f1f24785187477d0c230258e8cc054d2da06ce0a3cd66f210dfd719535bee5a89666ba07c5559a2ba0c8a257a996a560ee92cb287e942cf9939d928d4a0e43b44fd8d4ab4ce25841727bef37ff1e2d44daa0a2858ac0f4cd53ea04dfd945fe5c5c4df72653383c572510df6b4229217143bb652d5de3df2c3a7ebcf956b6bcd2f03888f9c6b05b919a0fc5761cafc8d82cd8162de17076349f98fc07449ca2bd977740db3b402a97515bbdf1f1742d3890e03dd285c4aa29fe7e8ecd5d6ab15bfa7946d6f91083d25d90a689a5938c2ba2c5176b1322f1fcf300e18e8699b4595885ea9e5753853fc6f6b81bc6a75fda479d09b57a5434b53644f7b3d9400c6c7776b554929667c3e7b2dd84a3c810fd7b9649ec02fbc525143a5b5c1692e7a15fc9474af34b85ffd8c9bb0d826c76a36aebc7610225ff8bfe3c63feef701b3002db39b12ea650a0ffb3564157d36fdfd9f6eda159e13a75552c004749951d1093d27b3f82c9b24f3edec17f1f877958aded2bbed5f3d64cf0950b5272f0678446d30622e3275b9c7c3257b29d0e55503e690dabd3a3723c74bb70439783198a0c2c60ac079f2377a9bb86c095fa7fc81bbbfd1e513a50e4733bb0a8fb9948bff518618c2218815c357ae86d8f78b9c89b8bf8cb2b38dd27c7934caa272835d1d632f82c1f5d43488920c275e075cdc4443f7b1268e1c6697c1c62ce1e69f88ea01ca5f01b9d3b2433de6a060c09222915bf67f9508b8686a19a5a8f279733cc940ac0de59551ead935865635945b90c4252be8292597adfb16eaf6e26237a959baa298f2316e08f3b5da89bdb4abc288d68cc09672e7346ed51ea70af4fe08ff27dd7ef7a2c18c002b2b7525b6925b92b151059e252117053334ceecc57db74f24d0ed601130b0698814e0902cdf93f21b9098dfb15104a938d8294440c0d848cde59bbf4ade8e0750fc46ce5a5535cab8b0a9fc0396d0969a6079ccb8af49a752de786e87ab4fe1ec3f5969b5d87252c13943699a96fb54e53b253aab40f9fa79d01ffd0f204703517c52bfa5708fc5e18e3b8511a53d5415399c6ae84b63594e7edf29a70023a5b581609c036c5c29ce995952cc0594054686d3e5f1d1d7001805fb32c4855e6dd3ed1ca22c2f36a8c2243931c2f06400e15dc48b98157b8426556ab27349832ac3a34dc63045299756bee625a01369f69be5da5765de65b31ae2585e5fe4e3b8ddde6d6360d75c5262e0e501e1d31f21febec97be9e4d81b3eae659dd6dc33f445f8d2c0a6c91d9c7daa5220db57bc60ea204bf3cee3b221cb999bfa5dc976196a9ce692734a74fd485b3394b51e627c9faee191a041d49babd8c30da770755b911207634486a3c44475931a1d59602b0afe6c38969deb07741aa9dc91f88edc0b761e74f39880fd8ec9274747fad977619bbcc3ff1ae571a682d1e99fd7d34071c4e7fd91d3b98523e7c7cb1c23d15ef57abf84deff13919fc8a5df95e860b3893c9028cb7b50750b14ee78c7001dadfc85ef0f392532db1b9539817bc3f021f0f55d102cec5dd304ceec72b9a454b79ac77e78d956f8506fd110f7eede6d18e585b4ab313b3d75c7407459ea59d0639e53dd8e4090eaffe9a1ce3b1c091587774165e2ac614c58d84b416903176456923ddd14d7293ac219f0330bab435541ff612b800cdc0b5204207abb3f4b648b6b802d9bb64a64c2f676db99236a23cb6b6303cd0d90cbd6aed6e1f957d3e2c19482bcfe455970e19df1d8671d4a0a342828697382c88a3ac1a44c15063e07fbfd0f851dc9e74b43d759fa52af969c3061fa497d55011369a663afee4069a7c5ea8f41b25db0d054d6ec91bacf91c2d7dbc6fec7b34f6ee7cbc9eec515fc6055ae2aeeda801c09c547abc216844e2f8e25c86676351720e9b61ab098f39775d857ca38af9c74e6dd390aea947697114948f3675988db0a321d16b6b2f7a5d462cd0e748aa74dd68402e994c250d89e8a5486127e6756097e798c68a8c7b7ce4cbfe7bfbecbde0ce0207572a48472883f1f990756b563fa961d8123da7ffd5939f7d4f14d12b20a1550ea05cc87160c52dbf3dbe615c37dde8414170a7085aa83d50acf05eaa8755c503cdc7ff6e7fef10ea27258b7fead8a2912e5fbb89ce428fea1dc2cc8b10ba8ef7ad551049d7db71473dcaa6fdb1006003bb578d4b8b2951c9373d176cfb49b80ff79cb49db4d1c00658958773bf93ef9946f76216209322c7fca952578e8c6deabf68a590b4b5dda0d8ed934788f7937d714b5 | unknown | — | — | unknown |
844 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/lvx4ng4qhhp4kpddwmwjgzrumu_2024.6.5.140657/eeigpngbgcognadeebkilcpcaedhellh_2024.06.05.140657_all_ccj7nw5iotmqmvpbhiiji4wfca.crx3 | unknown | — | — | unknown |
844 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/lvx4ng4qhhp4kpddwmwjgzrumu_2024.6.5.140657/eeigpngbgcognadeebkilcpcaedhellh_2024.06.05.140657_all_ccj7nw5iotmqmvpbhiiji4wfca.crx3 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1372 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2564 | svchost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3700 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3144 | chrome.exe | 74.125.143.84:443 | accounts.google.com | GOOGLE | US | unknown |
3144 | chrome.exe | 93.115.28.104:443 | yotube.com | UAB Cherry Servers | LT | unknown |
3144 | chrome.exe | 198.134.116.17:80 | click-v4.expdirclk.com | WEBAIR-INTERNET | US | unknown |
3144 | chrome.exe | 18.196.138.182:443 | dessedcuression.com | AMAZON-02 | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
accounts.google.com |
| shared |
yotube.com |
| malicious |
click-v4.expdirclk.com |
| unknown |
dessedcuression.com |
| unknown |
brandsreview.co |
| unknown |
www.awin1.com |
| whitelisted |
www.groundies.com |
| unknown |
app.usercentrics.eu |
| whitelisted |
privacy-proxy.usercentrics.eu |
| unknown |
api.usercentrics.eu |
| whitelisted |