| URL: | http://bing.com/images/search?view=detailV2&ccid=AJ8+gUMu&id=E361D206E148F4EE1F174CEA4E56A3CA3EFFF80C&thid=OIP.AJ8-gUMu5eOtfm_6WBF76AHaGq&mediaurl=https://thumbs.dreamstime.com/b/szcz%c4%99%c5%9bliwy-zwyci%c4%99zca-10763730.jpg&exph=720&expw=800&q=zwyci%c4%99zca&simid=608017005821627258&selectedIndex=0&mode=overlay |
| Full analysis: | https://app.any.run/tasks/052e4880-d731-491a-b453-82f42bedc55e |
| Verdict: | Malicious activity |
| Analysis date: | November 08, 2019, 15:21:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | A678AEAAD558C5ADA6881E3CFD01CFD6 |
| SHA1: | D7B0C85B5B50094EE38FF38112089F84C6389590 |
| SHA256: | 5002B02B343BD0D34CA6D969E957A503ADA879559D534D4079E07ABA3729E3F9 |
| SSDEEP: | 6:Cc1qW1MjHmQCH9meOybqYNObpq8/UcfnakVDojpcDI6KXB/6sYc:J1qMGHCHEelbq5V/XfnpKWDBM4E |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 252 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1008,7777587245234641936,15062026379159450785,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=6236202668089936529 --mojo-platform-channel-handle=3932 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 292 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1008,7777587245234641936,15062026379159450785,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=852599931952520241 --mojo-platform-channel-handle=3916 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 532 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1008,7777587245234641936,15062026379159450785,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8740667976974147195 --renderer-client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2976 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 896 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1008,7777587245234641936,15062026379159450785,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=16837151928656490335 --mojo-platform-channel-handle=3936 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1404 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1008,7777587245234641936,15062026379159450785,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=7227411959685051331 --mojo-platform-channel-handle=3384 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1516 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2132 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1544 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1008,7777587245234641936,15062026379159450785,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=7139322614481725209 --mojo-platform-channel-handle=3988 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1576 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1008,7777587245234641936,15062026379159450785,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=4489188521009661029 --mojo-platform-channel-handle=4240 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2084 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1008,7777587245234641936,15062026379159450785,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=10217920051663695633 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2240 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2112 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1008,7777587245234641936,15062026379159450785,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=4284056441967377886 --mojo-platform-channel-handle=1624 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (2172) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2172) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2172) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2172) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2172) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1516) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2172-13217700099327500 |
Value: 259 | |||
| (PID) Process: | (2172) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2172) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2172) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 1512-13197841398593750 |
Value: 0 | |||
| (PID) Process: | (2172) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 2172-13217700099327500 |
Value: 259 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2172 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\2099dc88-fb70-4aa5-9b02-625d411ff906.tmp | — | |
MD5:— | SHA256:— | |||
| 2172 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2172 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old~RF39a95a.TMP | text | |
MD5:— | SHA256:— | |||
| 2172 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2172 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2172 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old~RF39a8cd.TMP | text | |
MD5:— | SHA256:— | |||
| 2172 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2172 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
| 2172 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2172 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2112 | chrome.exe | GET | 301 | 13.107.21.200:80 | http://bing.com/images/search?view=detailV2&ccid=AJ8+gUMu&id=E361D206E148F4EE1F174CEA4E56A3CA3EFFF80C&thid=OIP.AJ8-gUMu5eOtfm_6WBF76AHaGq&mediaurl=https://thumbs.dreamstime.com/b/szcz%c4%99%c5%9bliwy-zwyci%c4%99zca-10763730.jpg&exph=720&expw=800&q=zwyci%c4%99zca&simid=608017005821627258&selectedIndex=0&mode=overlay | US | — | — | whitelisted |
2112 | chrome.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/images/search?view=detailV2&ccid=AJ8+gUMu&id=E361D206E148F4EE1F174CEA4E56A3CA3EFFF80C&thid=OIP.AJ8-gUMu5eOtfm_6WBF76AHaGq&mediaurl=https://thumbs.dreamstime.com/b/szcz%c4%99%c5%9bliwy-zwyci%c4%99zca-10763730.jpg&exph=720&expw=800&q=zwyci%c4%99zca&simid=608017005821627258&selectedIndex=0&mode=overlay | US | html | 112 Kb | whitelisted |
2112 | chrome.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/images/detail/insights?&IG=F65EF959720845EEA5C008BE9BD25512&iid=idpscrpt&iss=&mmasync=1&q=zwyci%c4%99zca | US | html | 80.8 Kb | whitelisted |
2112 | chrome.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/rs/3R/7o/cc,nc/b94ee139/e1783ef5.css | US | text | 730 b | whitelisted |
2112 | chrome.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/rb/3Q/cir2,cc,nc/55467d0d/78a2ecf3.css?bu=A8kT0RPVEw | US | text | 2.03 Kb | whitelisted |
2112 | chrome.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/rb/3Q/cj,nj/a072cfca/1055befd.js?bu=BIIchxyKHIAa | US | text | 6.71 Kb | whitelisted |
2112 | chrome.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/rs/3Q/1HP/ic/1c925074/0e571010.svg | US | image | 302 b | whitelisted |
2112 | chrome.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/sa/simg/Roboto_Semibold.woff2 | US | woff2 | 15.1 Kb | whitelisted |
2112 | chrome.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/rs/5e/A/cj,nj/96ac7c8b/68b0925c.js | US | binary | 23 b | whitelisted |
2112 | chrome.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/rs/3Q/RG/cj,nj/4c347eb9/0a1d4532.js | US | text | 1.24 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2112 | chrome.exe | 172.217.23.99:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
2112 | chrome.exe | 13.107.21.200:80 | bing.com | Microsoft Corporation | US | whitelisted |
2112 | chrome.exe | 204.79.197.200:80 | bing.com | Microsoft Corporation | US | whitelisted |
2112 | chrome.exe | 216.58.208.45:443 | accounts.google.com | Google Inc. | US | whitelisted |
2112 | chrome.exe | 204.79.197.200:443 | bing.com | Microsoft Corporation | US | whitelisted |
2112 | chrome.exe | 172.217.18.170:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
2112 | chrome.exe | 46.105.50.41:80 | www.tekiano.com | OVH SAS | FR | unknown |
2112 | chrome.exe | 104.18.82.97:443 | cdn.pixabay.com | Cloudflare Inc | US | shared |
2112 | chrome.exe | 2.20.164.43:80 | static3.depositphotos.com | Akamai Technologies, Inc. | — | unknown |
2112 | chrome.exe | 2.20.164.43:443 | static3.depositphotos.com | Akamai Technologies, Inc. | — | unknown |
Domain | IP | Reputation |
|---|---|---|
bing.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.bing.com |
| whitelisted |
thumbs.dreamstime.com |
| suspicious |
tse4.mm.bing.net |
| whitelisted |
tse1.mm.bing.net |
| whitelisted |
tse2.mm.bing.net |
| whitelisted |
tse3.mm.bing.net |
| whitelisted |
safebrowsing.googleapis.com |
| whitelisted |