| URL: | https://ws.cs.1worldsync.com |
| Full analysis: | https://app.any.run/tasks/fef75151-b086-4d93-b0de-36cfcf8c2a69 |
| Verdict: | Malicious activity |
| Analysis date: | September 26, 2023, 07:13:45 |
| OS: | Windows 10 Professional (build: 19044, 32 bit) |
| Indicators: | |
| MD5: | E2ED5B3986852D458D072EF96131BE0C |
| SHA1: | CFCDA6CDD977372F81FE8D89B086053759A4B9D2 |
| SHA256: | 3A709E8E2CB5B22977482987D3931215DA74D6093AFACB1DFD88CF7E4FE2D281 |
| SSDEEP: | 3:N8HSJJBv6I:2yJJ1j |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 204 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --mojo-platform-channel-handle=4320 --field-trial-handle=1776,i,17153137466816386999,4832052102507718248,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 103.0.5060.134 Modules
| |||||||||||||||
| 520 | "C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Exit code: 0 Version: 121.9202.4105.0 Modules
| |||||||||||||||
| 716 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --mojo-platform-channel-handle=3876 --field-trial-handle=1776,i,17153137466816386999,4832052102507718248,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 103.0.5060.134 Modules
| |||||||||||||||
| 1196 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --display-capture-permissions-policy-allowed --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2860 --field-trial-handle=1776,i,17153137466816386999,4832052102507718248,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 103.0.5060.134 Modules
| |||||||||||||||
| 1632 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=103.0.5060.134 --initial-client-data=0x104,0x108,0x10c,0xe0,0x110,0x5be094d8,0x5be094e8,0x5be094f4 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 103.0.5060.134 Modules
| |||||||||||||||
| 2136 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=16 --mojo-platform-channel-handle=2984 --field-trial-handle=1776,i,17153137466816386999,4832052102507718248,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 103.0.5060.134 Modules
| |||||||||||||||
| 3240 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --display-capture-permissions-policy-allowed --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2856 --field-trial-handle=1776,i,17153137466816386999,4832052102507718248,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 103.0.5060.134 Modules
| |||||||||||||||
| 3796 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "https://ws.cs.1worldsync.com" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 103.0.5060.134 Modules
| |||||||||||||||
| 3984 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --display-capture-permissions-policy-allowed --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=4112 --field-trial-handle=1776,i,17153137466816386999,4832052102507718248,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 103.0.5060.134 Modules
| |||||||||||||||
| 4268 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2100 --field-trial-handle=1776,i,17153137466816386999,4832052102507718248,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 103.0.5060.134 Modules
| |||||||||||||||
| (PID) Process: | (3796) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3796) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3796) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3796) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3796) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3796) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 1 | |||
| (PID) Process: | (3796) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 1 | |||
| (PID) Process: | (3796) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3796) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_installdate |
Value: 0 | |||
| (PID) Process: | (3796) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_enableddate |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3796 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History-journal | — | |
MD5:— | SHA256:— | |||
| 3796 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:31D145FA9AB7AC0CF13BFF9A82EB1145 | SHA256:3A9657A7EF816450FD40CEC9818CBE4558E1CD533F912D5E6E7CDD21A40AC6E3 | |||
| 3796 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Variations | binary | |
MD5:F80110DC99DFD872123A9B3DC428B6F7 | SHA256:4DC62005F08BD3364EBF4034A03AC515F0BD1C9C2C91FCAAD6A20F89804335A6 | |||
| 3796 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:82767A8D796BCA951DDB4CB839F2CB45 | SHA256:2A14FDC4A5EADED22B0BC3423EC0D4D930FD716A9FA9217F46612DB00E4AB40F | |||
| 3796 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RFfb81b.TMP | text | |
MD5:39DF7591E8D760BE6E996E5D62EA3FCD | SHA256:EEADAE1BD0064C1F3493E389BB0DAACEB3E4C7357B11322F22E731B8F5F4CC02 | |||
| 3796 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old | text | |
MD5:57CEF6D4157364ECD88DE374A342B4BD | SHA256:F602283B94E2366C77A041F22026A46914D70B7825AF75D0187B6B0C22FE290B | |||
| 3796 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3796 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3796 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3796 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old | text | |
MD5:AA9BA61A9C5D0D17D7C4BE551A9F5904 | SHA256:36C917BD87D8462776CDF4890B9D441764BA92C121EAB5CBD13730B0AE2746CF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4824 | chrome.exe | GET | 404 | 142.250.203.195:80 | http://www.gstatic.com/generate_204 | unknown | xml | 341 b | unknown |
4824 | chrome.exe | GET | 404 | 141.193.213.11:80 | http://1worldsync.com/ | unknown | xml | 341 b | unknown |
4824 | chrome.exe | GET | 404 | 142.250.203.195:80 | http://www.gstatic.com/generate_204 | unknown | xml | 341 b | unknown |
4824 | chrome.exe | GET | 404 | 141.193.213.11:80 | http://1worldsync.com/favicon.ico | unknown | xml | 341 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3796 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4824 | chrome.exe | 216.58.215.77:443 | accounts.google.com | GOOGLE | US | whitelisted |
4824 | chrome.exe | 40.113.128.101:443 | ws.cs.1worldsync.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
3796 | chrome.exe | 224.0.0.251:5353 | — | — | — | unknown |
4824 | chrome.exe | 142.250.203.196:443 | www.google.com | GOOGLE | US | unknown |
4824 | chrome.exe | 142.250.186.202:443 | optimizationguide-pa.googleapis.com | GOOGLE | US | unknown |
4824 | chrome.exe | 142.250.203.195:80 | www.gstatic.com | GOOGLE | US | unknown |
1200 | svchost.exe | 52.165.165.26:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4824 | chrome.exe | 142.250.203.195:443 | www.gstatic.com | GOOGLE | US | unknown |
4824 | chrome.exe | 141.193.213.11:443 | 1worldsync.com | Cloudflare London, LLC | US | unknown |
Domain | IP | Reputation |
|---|---|---|
ws.cs.1worldsync.com |
| unknown |
accounts.google.com |
| shared |
www.google.com |
| whitelisted |
optimizationguide-pa.googleapis.com |
| whitelisted |
officeclient.microsoft.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
1worldsync.com |
| malicious |
self.events.data.microsoft.com |
| whitelisted |