| URL: | http://securesearchnow.com |
| Full analysis: | https://app.any.run/tasks/af11b488-621e-49c7-8541-17d30ec67783 |
| Verdict: | Malicious activity |
| Analysis date: | December 27, 2020, 23:05:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 3C050741E49F5E938865CD53F207B1C5 |
| SHA1: | 971BBCD12053DC8C66C36856236D5574243F5B43 |
| SHA256: | 36FACD0F880CEFC7FDFC5BE73C44F2FFA992532FE437B17A4FACBB1FA4AFF0FA |
| SSDEEP: | 3:N1KNAGCzAEXKyT:CSGCsM |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 280 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1036,1132559374030115817,1958380418486136881,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=4218176665839981795 --mojo-platform-channel-handle=2184 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 688 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1132559374030115817,1958380418486136881,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12077208341262076256 --renderer-client-id=11 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3732 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1120 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "http://securesearchnow.com" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1636 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1132559374030115817,1958380418486136881,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=376425054641585263 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1872 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1792 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1036,1132559374030115817,1958380418486136881,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=7546098359240135316 --mojo-platform-channel-handle=1428 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1892 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=1856 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2096 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1132559374030115817,1958380418486136881,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7297119772709722805 --renderer-client-id=13 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2036 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2104 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1132559374030115817,1958380418486136881,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=2255288590545318400 --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3176 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2208 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1132559374030115817,1958380418486136881,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4392216708999802042 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2184 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2604 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1132559374030115817,1958380418486136881,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11253623618502096935 --renderer-client-id=19 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2924 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (1120) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (1120) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (1120) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (1120) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (1120) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1892) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 1120-13253583962208000 |
Value: 259 | |||
| (PID) Process: | (1120) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (1120) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (1120) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3252-13245750958665039 |
Value: 0 | |||
| (PID) Process: | (1120) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1120 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5FE9135B-460.pma | — | |
MD5:— | SHA256:— | |||
| 1120 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\30b8219e-e058-4fd0-b32d-4d73b306e6a6.tmp | — | |
MD5:— | SHA256:— | |||
| 1120 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp | — | |
MD5:— | SHA256:— | |||
| 1120 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1120 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 1120 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 1120 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | text | |
MD5:— | SHA256:— | |||
| 1120 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | text | |
MD5:— | SHA256:— | |||
| 1120 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1120 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF14394e.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1792 | chrome.exe | GET | 302 | 208.91.197.132:80 | http://208.91.197.132/ | VG | — | — | malicious |
1792 | chrome.exe | GET | 302 | 208.91.197.132:80 | http://208.91.197.132/ | VG | — | — | malicious |
1792 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://securesearchnow.com/?fp=qdY5qV3H4h6j3KUk9YoZjZanIvzwxsH2lhq12ohJeBDUbmMaBJRHYWoRMVA97c86EdsOp1OSsVf9CUBra1rh35Qlhm2S3%2BWg8xHvaaM0eG6vnVD3FRunuZM3Oiu4TLMlLj7gLUKw3hrWo2en3t8bVJW57xvLB6XU6gcC7zrN%2F622MHUKpjEBxAxNQssT30qm&prvtof=QpDYhGFdj%2FFeZwlUSWZ%2BgA7YoMUK%2BZxVV5wo1g2yPyQ%3D&poru=zlhOenKtzWYvaprZWP7qvDA8iy1324LUNqqdX6FnIyR6Wg9I37GRW89trhX0Hxn4& | VG | html | 588 b | suspicious |
1792 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://securesearchnow.com/ | VG | html | 1.05 Kb | suspicious |
1792 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://securesearchnow.com/?fp=YEzsPi%2Bh%2FDqxEIFlwcxvEhTgRq7cCmN5KterrpJct9%2F3lFZ%2FZBM1s8JMWPzxLZbkMjfXtHMUXkCtFn9tdbVfMK1nW6OcCv7jcViT4PUuFuaee%2FuUoWDKHozpwZykqq7BpIgYX1xCR6GjX0ehp6UCiE8PdcOXDTOvsCq1w1%2BKhlM%3D&prvtof=xsg9wQuUeDVffry1yoGHXBbUFCz7P6oyI5qlKB4N%2FAk%3D&poru=FM69mwbZRekN0CzoSLBeBLAl3VCYuEZohcuttClNV2pjrP7o2M2S0y11Ze%2BWF9dx& | VG | html | 589 b | suspicious |
1792 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://securesearchnow.com/ | VG | html | 1.07 Kb | suspicious |
1792 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://securesearchnow.com/ | VG | html | 1.06 Kb | suspicious |
1792 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://securesearchnow.com/?fp=Bp7lpNkCFeAOZ8Xy2i2aQjxpjE%2F%2F2PKZIHkMv6KZ%2Bw8%2Fk1UaIGHz1L6Zp99DiPl%2Bx%2BkTmsvJzb9FRcUh5Hy62Vz5DFXzbLyTgdiopBf7chnuf4kLBsL8pyzTUWx0AyXoTqQty3mCVq%2BCOTXnnkWYmSkUCQzPfsSkvPTzOo0P%2FrQ3qGY6gK1UxNiZBnkSi3b6&prvtof=nOwL6m85MR0t2hSWQ%2F4%2FwGhedtsrlqI1aTPvREMG%2BlI%3D&poru=Mt4NbS%2BYCaJBZEu7QHjKsZEtxgHI4Uba80VkP87NB60noTlrnAMvcTZaAK7vRgBw& | VG | html | 588 b | suspicious |
1792 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://securesearchnow.com/ | VG | html | 1.07 Kb | suspicious |
1792 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://securesearchnow.com/?fp=0xnsAmkJCJpNAnpimfURssu3j2pvVVfpUqVzpz2TSNRxsvNvue2aLFSPRZA2T9otoVJ3aWHQOcGS%2BkK1HpdFjt%2BKQqEXUO7ABBOv%2FsuJpfxjC%2BJSE%2FXZRwcLA6ioQZ7BW%2BJikGQMpoRYsaaXiDYIK1VdXKkn536HSDuhXA2btNQ3Pt%2B8mms4O%2Fx79VdVsEwa&prvtof=Ovkwa83vQ2QTWCP4kmqKw3fir2Tx0nLVQzKIcE0QhIE%3D&poru=9UGXKsMpYdsmzWGQeH1GzYzOgemnX8OKhp9T82dSr723OYPETfAFluJmb1FRWwNL& | VG | html | 588 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1792 | chrome.exe | 208.91.196.46:80 | securesearchnow.com | Confluence Networks Inc | VG | malicious |
1792 | chrome.exe | 66.81.207.66:443 | subscribe.steersearch.com | Confluence Networks Inc | VG | unknown |
1792 | chrome.exe | 172.67.215.251:443 | wp.webpushonline.com | — | US | suspicious |
1792 | chrome.exe | 2.16.107.33:443 | i7cdnimg-a.akamaihd.net | Akamai International B.V. | — | whitelisted |
1792 | chrome.exe | 172.217.23.110:443 | android.clients.google.com | Google Inc. | US | whitelisted |
1792 | chrome.exe | 64.233.167.188:5228 | mtalk.google.com | Google Inc. | US | whitelisted |
1792 | chrome.exe | 172.217.22.67:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
1792 | chrome.exe | 172.217.16.131:443 | www.google.com.ua | Google Inc. | US | whitelisted |
1792 | chrome.exe | 172.217.21.238:443 | encrypted-tbn0.gstatic.com | Google Inc. | US | whitelisted |
1792 | chrome.exe | 2.16.107.18:443 | i8cdnimg-a.akamaihd.net | Akamai International B.V. | — | malicious |
Domain | IP | Reputation |
|---|---|---|
securesearchnow.com |
| suspicious |
accounts.google.com |
| shared |
subscribe.steersearch.com |
| unknown |
i7cdnimg-a.akamaihd.net |
| whitelisted |
wp.webpushonline.com |
| malicious |
android.clients.google.com |
| whitelisted |
mtalk.google.com |
| whitelisted |
ssl.gstatic.com |
| whitelisted |
www.google.com.ua |
| whitelisted |
encrypted-tbn0.gstatic.com |
| whitelisted |