| URL: | http://4pe.us/3l5W8L |
| Full analysis: | https://app.any.run/tasks/c958feb2-b8ad-400e-a49d-5fe3427eca95 |
| Verdict: | No threats detected |
| Analysis date: | March 15, 2019, 11:30:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 1A718D7BB342028C0DBC7F110AAF0FB8 |
| SHA1: | D34C57E2456AF9B605673E96D2A90C2B81175BC8 |
| SHA256: | 4F3002A922F323B1941881159A527CE46D4FA967040C83CAFCEF091B104B82C6 |
| SSDEEP: | 3:N1Kvi6rn:CH |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1964 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6446415706175171745,7615301987602728214,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=60518FCD971E012A3F5D29E63B763897 --mojo-platform-channel-handle=516 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
| 2288 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1012,6446415706175171745,7615301987602728214,131072 --enable-features=PasswordImport --disable-gpu-sandbox --gpu-preferences=KAAAAAAAAACAAwBAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=1DA23EE6E239220E3CC9E9ABDAAF6E83 --mojo-platform-channel-handle=3704 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
| 2292 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6446415706175171745,7615301987602728214,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=3AF7A462E8E9736B3615A1C5DE273A66 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=3AF7A462E8E9736B3615A1C5DE273A66 --renderer-client-id=11 --mojo-platform-channel-handle=1684 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
| 2472 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6446415706175171745,7615301987602728214,131072 --enable-features=PasswordImport --service-pipe-token=DC5907BBB8AE4D0A1A6FFA03477E20E4 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=DC5907BBB8AE4D0A1A6FFA03477E20E4 --renderer-client-id=4 --mojo-platform-channel-handle=1900 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
| 2640 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6446415706175171745,7615301987602728214,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=6CA1D5A241F07D4C126D141723F6FCE9 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6CA1D5A241F07D4C126D141723F6FCE9 --renderer-client-id=12 --mojo-platform-channel-handle=3764 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
| 2728 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6446415706175171745,7615301987602728214,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=1EE0E181C941C364016358D10C4B19F8 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1EE0E181C941C364016358D10C4B19F8 --renderer-client-id=9 --mojo-platform-channel-handle=2032 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
| 2860 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2872 --on-initialized-event-handle=304 --parent-handle=308 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
| 2868 | "C:\Program Files\Google\Chrome\Application\chrome.exe" http://4pe.us/3l5W8L | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 3221225547 Version: 68.0.3440.106 Modules
| |||||||||||||||
| 2940 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3640 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3144 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6446415706175171745,7615301987602728214,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=380BE6C17E0D8282A84AA6E305820893 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=380BE6C17E0D8282A84AA6E305820893 --renderer-client-id=10 --mojo-platform-channel-handle=1648 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 68.0.3440.106 Modules
| |||||||||||||||
| (PID) Process: | (2868) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2868) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2868) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2860) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2868-13197123031595000 |
Value: 259 | |||
| (PID) Process: | (2868) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2868) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2868) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3516-13180984670829101 |
Value: 0 | |||
| (PID) Process: | (2868) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (2868) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 2868-13197123031595000 |
Value: 259 | |||
| (PID) Process: | (2868) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2868 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2868 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF198795.TMP | — | |
MD5:— | SHA256:— | |||
| 2868 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\990d5da7-0433-4b62-8a46-e8180ccbbc62.tmp | — | |
MD5:— | SHA256:— | |||
| 2868 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\000016.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2868 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000016.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2868 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\abfc23bf-1517-4316-9737-10b101153ce9.tmp | — | |
MD5:— | SHA256:— | |||
| 2868 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:— | SHA256:— | |||
| 2868 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2868 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF1987b4.TMP | text | |
MD5:— | SHA256:— | |||
| 2868 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Translate Ranker Model~RF198b3e.TMP | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2868 | chrome.exe | GET | 302 | 89.255.250.70:80 | http://ico.fomaska.com/kt/no/79/favicon.ico | DE | — | — | unknown |
2868 | chrome.exe | GET | 302 | 198.134.116.30:80 | http://click.eclk.club/click?i=EMk02--73A4_0 | US | — | — | malicious |
2868 | chrome.exe | GET | — | 34.200.70.236:80 | http://tango-deg.com/126795_no_1630_4f7faa5a5849amp_windows?rpm=0.05&fallbackUrl=https%3A%2F%2Fonwardinated.com%2Fk%2Fc4854bb1-4715-11e9-8697-019fff81ac8b%2Fc%2F5a37c8ad-f104-11e5-9f1f-0626cc8adced%2F%3F_d%3D7%257C0%257C0%257C0%257C1%257C1%257Ct%257Ct%257C1280x720%257Cu%257C1%257CGoogle%2BInc.%257C1%257C24%257C24%257C96%257C74-9cf8cd60%257C0%257C0%257C281%257C1%257C2%257Ct%257Ct%257Cy9j1d2%252Cqmn4ze%252Cu%257Cen%252Cen-US%257CWin32%257Cpch21%257C20030107%257C5.0%2B%2528Windows%2BNT%2B6.1%2529%2BAppleWebKit%252F537.36%2B%2528KHTML%252C%2Blike%2BGecko%2529%2BChrome%252F68.0.3440.106%2BSafari%252F537.36%257C0%257C4%257C192.168.100.60%257Cu%257Ct%257Ct%257Ct%257Cxuagn%257CWebGL%2B1.0%2B%2528OpenGL%2BES%2B2.0%2BChromium%2529%257CGoogle%2BInc.%257CGoogle%2BSwiftShader%257Cex%253Anq6ww%257C1%257Cu%257Ct%257Cn%257Cn%257Cn%257Cn%257C1280x626%257C0%257C1%257C0%257C0%257Ct%257Cc4854cfe-4715-11e9-8699-119fff81acd6%257Ccs_rr%26_i%3D3%26_r%3Dup.trkgenius.com%26_s%3Dc4854bf1-4715-11e9-8698-019fff81acc5%26pubid%3Ddvx%26subid%3D9b5b4baecb3d615f04fa3a123806c018%26_a%3D137%26_o%3D116796&domainerId=b6c4e1c1-f280-11e5-8984-0ea7743a2ad5&keywords=0&extclickid=e802c742-4715-11e9-b214-11433dd98693&_uu= | US | — | — | shared |
2868 | chrome.exe | GET | 302 | 174.137.133.18:80 | http://xml.boffoadsfeeds.com/click?i=ROZbWKoAkb0_0 | US | — | — | suspicious |
2868 | chrome.exe | GET | 302 | 198.134.116.16:80 | http://xml.hueadsxml.com/click?i=GuNXswrfmqk_0 | US | — | — | unknown |
2868 | chrome.exe | GET | 302 | 198.134.116.30:80 | http://click.eclk.club/click?i=P0o1G5WUtrI_0 | US | — | — | malicious |
2868 | chrome.exe | GET | 302 | 173.239.53.18:80 | http://xml.admidainsight.com/click?i=1Dq7nBLoX2A_0 | US | — | — | suspicious |
2868 | chrome.exe | GET | 302 | 174.137.133.18:80 | http://xml.flairadscpc.com/click?i=pTCBXb-a-1M_0 | US | — | — | suspicious |
2868 | chrome.exe | GET | 301 | 104.25.118.11:80 | http://normour.com/r/c4ff04c2-4715-11e9-a97f-114465c907a2/0/?_rh=a32101eNInOw7875zxp2NuMfKbk49MMQhDdxDMtzae3iDU38Dvl0Lq0TQ43dTxIHIoxm7Z_UzUSNJlAHmn7M15anY696lZzTyr-ssYlZQJ7JKwdub65uRHVd8-YSG5dGPMOURSdQ7k75X8-Nx9qKwRRCG2a_6kCcRLfy3xVydbk-KgW4abAZODdFGpHAXTjT4E-74PctMuA2Ugzrev7OklgoZ-6hSKZC68KZJlNHVDezT9h01H6_B2d8IMyJS4ujuz1ypzyeMUdGCEJR5R29IGt9Bnyx9o_ssz4LUEZDGiG681_tn13afkxoTH8fgTjFVpcilxxw4yEoMPReJMJXYoXE3Mi0sXbUDlrMf2hdgBGaHMg3k0r7NV2UVU50_6WFywFXoiw8j-AYVXfBAMtZ0z9Rig | US | — | — | whitelisted |
2868 | chrome.exe | GET | 302 | 174.137.133.18:80 | http://xml.adoperatorx.com/click?i=uYLlRMd5dLI_0 | US | — | — | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2868 | chrome.exe | 216.58.208.35:443 | www.gstatic.com | Google Inc. | US | whitelisted |
2868 | chrome.exe | 34.195.8.133:443 | tl.nasdois.com | Amazon.com, Inc. | US | unknown |
2868 | chrome.exe | 99.84.13.12:80 | x.ss2.us | AT&T Services, Inc. | US | unknown |
2868 | chrome.exe | 13.107.4.50:80 | www.download.windowsupdate.com | Microsoft Corporation | US | whitelisted |
2868 | chrome.exe | 198.143.165.221:443 | go.monetizer.club | SingleHop, Inc. | US | suspicious |
2868 | chrome.exe | 104.25.142.28:443 | img.circultural.com | Cloudflare Inc | US | shared |
2868 | chrome.exe | 18.195.174.160:80 | pashollar-compears.com | Amazon.com, Inc. | DE | malicious |
2868 | chrome.exe | 104.25.118.11:443 | normour.com | Cloudflare Inc | US | shared |
2868 | chrome.exe | 104.25.118.11:80 | normour.com | Cloudflare Inc | US | shared |
2868 | chrome.exe | 35.157.125.133:443 | track.addictedtoethereum.com | Amazon.com, Inc. | DE | suspicious |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
4pe.us |
| suspicious |
www.gstatic.com |
| whitelisted |
accounts.google.com |
| shared |
code.jquery.com |
| whitelisted |
pashollar-compears.com |
| shared |
tl.nasdois.com |
| unknown |
x.ss2.us |
| whitelisted |
www.download.windowsupdate.com |
| whitelisted |
go.monetizer.club |
| suspicious |