URL: | https://docs.vtex.com.br/pdf/qjIkS-download-Blue-Team-Field-Manual-BTFM-RTFM-154101636X-By-Alan-J-White.pdf |
Full analysis: | https://app.any.run/tasks/0b923137-6e6e-43a4-9e88-7254fddfbaf4 |
Verdict: | No threats detected |
Analysis date: | January 10, 2019, 20:26:41 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | 81952BE26ECF1BDB6CF2306241533B26 |
SHA1: | 74B12E8F925911DF608616C509EBD5107F1B83D1 |
SHA256: | 47BFA69E63C435309F8C80E63506038E8847FBC42FBFFF329C136F9CF0C75D6A |
SSDEEP: | 3:N8SQdt1KqBJLkJQLj/EsxjP+QRVTUqcIhLIQIVBDn:2SKKFQvEsxzvPUq5d7IX |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2416 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=880,5487067942639420157,11828165495858623895,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=6CF561F6EEC7C2EC8536FDCE23E6CD42 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6CF561F6EEC7C2EC8536FDCE23E6CD42 --renderer-client-id=9 --mojo-platform-channel-handle=3780 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
2504 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=880,5487067942639420157,11828165495858623895,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=A13785763F252B86D64B4832175A3305 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=A13785763F252B86D64B4832175A3305 --renderer-client-id=10 --mojo-platform-channel-handle=3796 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
2576 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=880,5487067942639420157,11828165495858623895,131072 --enable-features=PasswordImport --service-pipe-token=3B7461A966AFAF10C12EB132B02C3B3A --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=3B7461A966AFAF10C12EB132B02C3B3A --renderer-client-id=4 --mojo-platform-channel-handle=1916 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
2720 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=880,5487067942639420157,11828165495858623895,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=4E163C69D469E2C8C18C57FF1F05FCF4 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4E163C69D469E2C8C18C57FF1F05FCF4 --renderer-client-id=5 --mojo-platform-channel-handle=3316 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
2856 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=ppapi --field-trial-handle=880,5487067942639420157,11828165495858623895,131072 --enable-features=PasswordImport --ppapi-flash-args --lang=en-US --device-scale-factor=1 --ppapi-antialiased-text-enabled=0 --ppapi-subpixel-rendering-setting=0 --service-request-channel-token=2AFB5816FE93F78DE11E03133D72A72C --mojo-platform-channel-handle=3668 --ignored=" --type=renderer " /prefetch:3 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
2952 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3004 --on-initialized-event-handle=304 --parent-handle=308 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
3000 | "C:\Program Files\Google\Chrome\Application\chrome.exe" https://docs.vtex.com.br/pdf/qjIkS-download-Blue-Team-Field-Manual-BTFM-RTFM-154101636X-By-Alan-J-White.pdf | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
3176 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=880,5487067942639420157,11828165495858623895,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=5DC2FE46756A84C9F3A6309D98F5648C --mojo-platform-channel-handle=3592 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
3260 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=880,5487067942639420157,11828165495858623895,131072 --enable-features=PasswordImport --service-pipe-token=0EF65028865BFFBDDCB6D4115137D7B8 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=0EF65028865BFFBDDCB6D4115137D7B8 --renderer-client-id=3 --mojo-platform-channel-handle=2152 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
3448 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=880,5487067942639420157,11828165495858623895,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=13194B8B3EAF087C614C3CF9B81847A9 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=13194B8B3EAF087C614C3CF9B81847A9 --renderer-client-id=12 --mojo-platform-channel-handle=2340 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
|
(PID) Process: | (2952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
Operation: | write | Name: | 3000-13191625616810625 |
Value: 259 | |||
(PID) Process: | (3000) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
Operation: | write | Name: | failed_count |
Value: 0 | |||
(PID) Process: | (3000) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
Operation: | write | Name: | state |
Value: 2 | |||
(PID) Process: | (3000) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
Operation: | write | Name: | state |
Value: 1 | |||
(PID) Process: | (3000) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
Operation: | write | Name: | dr |
Value: 1 | |||
(PID) Process: | (3000) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
(PID) Process: | (3000) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
Operation: | delete value | Name: | 3516-13180984670829101 |
Value: 0 | |||
(PID) Process: | (3000) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
Operation: | write | Name: | usagestats |
Value: 0 | |||
(PID) Process: | (3000) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
Operation: | delete value | Name: | 3000-13191625616810625 |
Value: 259 | |||
(PID) Process: | (3000) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
Operation: | write | Name: | metricsid |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
3000 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\aab4a202-87b0-413f-a4e6-22869ff219f8.tmp | — | |
MD5:— | SHA256:— | |||
3000 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\000016.dbtmp | — | |
MD5:— | SHA256:— | |||
3000 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000016.dbtmp | — | |
MD5:— | SHA256:— | |||
3000 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\415039f0-9148-4707-b2c5-8c2b3a6ffcda.tmp | — | |
MD5:— | SHA256:— | |||
3000 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | text | |
MD5:— | SHA256:— | |||
3000 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF20e87f.TMP | text | |
MD5:— | SHA256:— | |||
3000 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old | text | |
MD5:— | SHA256:— | |||
3000 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF20e860.TMP | text | |
MD5:— | SHA256:— | |||
3000 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:— | SHA256:— | |||
3000 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3000 | chrome.exe | GET | 200 | 93.123.73.193:80 | http://booktosuccess.me/?download=154101636X | BG | html | 2.93 Kb | whitelisted |
3000 | chrome.exe | GET | 200 | 93.123.73.193:80 | http://booktosuccess.me/assets/images/award.png | BG | image | 376 Kb | whitelisted |
3000 | chrome.exe | GET | 200 | 52.222.146.192:80 | http://images.amazon.com/images/P/154101636X.jpg | US | image | 10.8 Kb | whitelisted |
3000 | chrome.exe | GET | 200 | 93.123.73.193:80 | http://booktosuccess.me/go.php?title=Blue+Team+Field+Manual+%28BTFM%29+%28RTFM%29 | BG | html | 205 b | whitelisted |
3000 | chrome.exe | GET | 200 | 46.105.201.240:80 | http://s10.histats.com/js15_as.js | FR | html | 4.42 Kb | whitelisted |
3000 | chrome.exe | GET | 302 | 18.195.108.165:80 | http://titan.infra.systems/signup?asdf_domain=look.djfiln.com&asdf_path=%2Fsmart_asdf%2Fdisplay&prod=2&ref=5062794&q=%5BEbook%5D%20Blue%20Team%20Field%20Manual%20(BTFM)%20(RTFM).pdf&sf=&utm_source=booktosuccess.me&utm_medium=referral&placement=http%3A%2F%2Fbooktosuccess.me%2Fgo.php%3Ftitle%3DBlue%2BTeam%2BField%2BManual%2B%2528BTFM%2529%2B%2528RTFM%2529&adserver=1.2.22 | DE | html | 944 b | unknown |
3000 | chrome.exe | GET | 521 | 104.20.2.47:80 | http://c.statcounter.com/t.php?sc_project=11781556&java=1&security=364e24be&u1=BD16CE4852204F7CCCBB66A5E385E762&sc_random=0.8255867230477938&jg=new&rr=1.1.1.1.1.1.1.1.1&resolution=1280&h=720&camefrom=&u=http%3A//booktosuccess.me/%3Fdownload%3D154101636X&t=Download%20Blue%20Team%20Field%20Manual%20(BTFM)%20(RTFM)%20-%20Book%20To%20Success&rcat=d&rdom=d&rdomg=new&bb=1&sc_snum=1&sess=4ea83c&p=0&invisible=1 | US | html | 4.40 Kb | whitelisted |
3000 | chrome.exe | GET | 200 | 93.123.73.193:80 | http://booktosuccess.me/assets/images/icon.ico | BG | image | 97.3 Kb | whitelisted |
3000 | chrome.exe | GET | 302 | 79.125.121.154:80 | http://look.djfiln.com/offer?prod=2&ref=5062794&q=%5BEbook%5D+Blue+Team+Field+Manual+%28BTFM%29+%28RTFM%29.pdf | IE | html | 858 b | suspicious |
3000 | chrome.exe | GET | 302 | 54.208.224.91:80 | http://studcat.infra.systems/signup?asdf_domain=look.djfiln.com&asdf_path=%2Fsmart_asdf%2Fdisplay&prod=2&ref=5062794&q=%5BEbook%5D%20Blue%20Team%20Field%20Manual%20(BTFM)%20(RTFM).pdf&sf=&utm_source=booktosuccess.me&utm_medium=referral&placement=http%3A%2F%2Fbooktosuccess.me%2Fgo.php%3Ftitle%3DBlue%2BTeam%2BField%2BManual%2B(BTFM)%2B(RTFM)&adserver=1.2.22&m=books&lid=33e68cf7-9d1d-4df6-9c8e-39c712b1325d | US | html | 1.39 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3000 | chrome.exe | 216.58.206.10:443 | ajax.googleapis.com | Google Inc. | US | whitelisted |
3000 | chrome.exe | 185.199.111.153:443 | docs.vtex.com.br | GitHub, Inc. | NL | shared |
3000 | chrome.exe | 216.58.205.227:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
3000 | chrome.exe | 216.58.208.35:443 | www.gstatic.com | Google Inc. | US | whitelisted |
3000 | chrome.exe | 93.123.73.193:80 | booktosuccess.me | Histate Global Corp. | BG | malicious |
3000 | chrome.exe | 172.217.18.170:443 | ajax.googleapis.com | Google Inc. | US | whitelisted |
3000 | chrome.exe | 104.24.131.10:443 | www.friendlyduck.com | Cloudflare Inc | US | shared |
3000 | chrome.exe | 104.20.3.47:443 | www.statcounter.com | Cloudflare Inc | US | shared |
3000 | chrome.exe | 52.222.146.192:80 | images.amazon.com | Amazon.com, Inc. | US | whitelisted |
3000 | chrome.exe | 93.184.221.240:80 | www.download.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
clientservices.googleapis.com |
| whitelisted |
docs.vtex.com.br |
| malicious |
www.gstatic.com |
| whitelisted |
accounts.google.com |
| shared |
booktosuccess.me |
| whitelisted |
ajax.googleapis.com |
| whitelisted |
www.friendlyduck.com |
| whitelisted |
images.amazon.com |
| whitelisted |
www.statcounter.com |
| whitelisted |
www.download.windowsupdate.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |