URL: | https://www.google.com/url?sa=t&source=web&rct=j&url=https://daftsex.com/watch/-137457396_456239211&ved=2ahUKEwic0q20n4DvAhWC1VkKHY2nCz0Qo7QBMAh6BAgDEAE&usg=AOvVaw3Mm32l7BmV5fVao4XwXcuo |
Full analysis: | https://app.any.run/tasks/9b3b0851-edba-4475-8184-03ddcb213fff |
Verdict: | Malicious activity |
Analysis date: | February 23, 2021, 14:50:17 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | 6472B676214940131120381924DDD267 |
SHA1: | 689BD51E6B2DFC958F04FB1AAB6EC40495480C9A |
SHA256: | 5AF2AFE4CBF427132AE2C6EA4E7CCECDBEE7C298A99D709DC7D141D6C04DDE7D |
SSDEEP: | 3:N8DSLI2sljXoW+PWKRVYEdiEIWQd9YENb3+XHegm1u4seJKLhgkGELSDXc/cm1:2OLI2slQOKROEdi5WQdbNyX+gmC4IhhB |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
352 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,7684646189627079340,9804393595104396985,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=885598078336666882 --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3756 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
860 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1020,7684646189627079340,9804393595104396985,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=13669013123466516091 --mojo-platform-channel-handle=1004 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
968 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,7684646189627079340,9804393595104396985,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1274336093343944202 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2408 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
972 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,7684646189627079340,9804393595104396985,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4770843364283071161 --renderer-client-id=17 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4112 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
1000 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,7684646189627079340,9804393595104396985,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=2384643790824177067 --renderer-client-id=9 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2604 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
1184 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1020,7684646189627079340,9804393595104396985,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=10500889016437456928 --mojo-platform-channel-handle=4452 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
1220 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,7684646189627079340,9804393595104396985,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16407252707935612133 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2168 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
1480 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,7684646189627079340,9804393595104396985,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=2352109838351655944 --mojo-platform-channel-handle=4600 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
1680 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,7684646189627079340,9804393595104396985,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5577100219182980157 --renderer-client-id=14 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4496 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
1764 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,7684646189627079340,9804393595104396985,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7288261479674696936 --renderer-client-id=13 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4456 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
|
(PID) Process: | (2392) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
Operation: | write | Name: | failed_count |
Value: 0 | |||
(PID) Process: | (2392) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
Operation: | write | Name: | state |
Value: 2 | |||
(PID) Process: | (2392) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
Operation: | write | Name: | StatusCodes |
Value: | |||
(PID) Process: | (2392) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
(PID) Process: | (2392) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
Operation: | write | Name: | state |
Value: 1 | |||
(PID) Process: | (2592) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
Operation: | write | Name: | 2392-13258565433955125 |
Value: 259 | |||
(PID) Process: | (2392) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
Operation: | write | Name: | dr |
Value: 1 | |||
(PID) Process: | (2392) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
(PID) Process: | (2392) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
Operation: | delete value | Name: | 3252-13245750958665039 |
Value: 0 | |||
(PID) Process: | (2392) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
Operation: | write | Name: | usagestats |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2392 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-6035163A-958.pma | — | |
MD5:— | SHA256:— | |||
2392 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ecb8230c-8abc-4b2d-8d98-906142339519.tmp | — | |
MD5:— | SHA256:— | |||
2392 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp | — | |
MD5:— | SHA256:— | |||
2392 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old | — | |
MD5:— | SHA256:— | |||
2392 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RFcf765.TMP | text | |
MD5:— | SHA256:— | |||
2392 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
2392 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | text | |
MD5:— | SHA256:— | |||
2392 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
2392 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
2392 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RFcf9e6.TMP | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3968 | chrome.exe | GET | 200 | 35.227.196.138:80 | http://www.performanceonclick.com/jump/next.php?r=2575139&pub_clickid=PgS6DinvI_XKw5PmRHwIdnzOTgV1IgQ5UP_gFVIJflMsYpSUH4aBTKhEGi1r8ofH6FqO-WFZ_5hExziiC8CCclOxSmFIlerhQfUIuEXmOhxrGsmelej6EVmu1H9lT_10wZQ2ol1l7qQgYnlZgRZjAojuPRH9TvZgBscGjK5SknLNWhiDgvQ9vVMRe39RmTtqBuGjq8no8bki48hfvrU-Pkxb5gkZFEG2SfUyqzYjhLSPLuqXzd0HeTKrtSedgXs1PgJa_AepgO8mQp5RyX9yDamcilGtIfzJjJ43gpQufq0Gy1ZRwFeTk1cYBdVVSmPuRB1C9jkN1YaD81SZdB2UsgOZcLF5etGcOBl0Co_C46r2157ZUwu57Kf5IxYsKkdKJ_XNbMdb-8-oZNhT0ugE4RUGTVKsI2CePjfDn_n75RJ74K5KIEGgS-QhM1XVCiEceGnf-uCzkI0pzUQyEnzPNQ&sub1=wba_w10_1711_des | US | html | 3.90 Kb | suspicious |
3968 | chrome.exe | GET | 302 | 35.227.196.138:80 | http://www.performanceonclick.com/jump/next.php?stamat=m%7C%2C%2Cgifn4iJSoGU3B0-GH0dEdHP3xP.14f%2Ckax9S3LQqD492q0AsFFkXnduzungi5jIO3nV7SgMnhJ5vxelUSckyvCxMV8eiEokycs5P3-YRke4UouSGfiD-HfukWIfH1Uk1toicLo7KgbdQEDqe0wIjb-lLRKTG-jevkHDhBA5ZXtIck921Z_pxNuDzFSDCHlsvux0cRr8f4gvpeh5RmgvvHk97CtTIib_y1e1Bnu2VIZlmL-SmcEFVUGPKdYkYPbYuA7Uo1LM2W1ysIDCu-p5zldLqKS0suXn2eun5LTrFgRmsy1b2bgNbEfRGRfRLK1phgKzXlYaIy1YQjZSuMNq83Dygc0hPFMqGmHwbWE5-DbNMYAr_aBpfQREWkZzyw6XGxknr9g-hAZduCHgpOZsIr0OMFnyRBOwRQQ9KcU_yIeIbzEtGlGYUNzEEq44wpQg9bkPt6-WDtKtOItD0_5Juk73ahc3f4mZXpv6MOyn1UDnWTx_nZt6YWmdRtFC3ZIcADXhr7eIiWEAxdBT-OOployo8k8eUoQnG4p9lj4mnOQ8y6Z1vMcrR4PeF33AXVy1P2wsDXno-rMD3Ccha3ED3kQnP8dNgNzS1cZnNew4SzOlh_9pAWXkkfeEP-y7lks0EMuQmlr6p8A%2C&cbrandom=0.8886018579082149&cbtitle=&cbiframe=0&cbWidth=1280&cbHeight=620&cbdescription=&cbkeywords=&cbref= | US | binary | 1 b | suspicious |
3968 | chrome.exe | GET | 204 | 35.227.196.138:80 | http://www.performanceonclick.com/script/i.php?stamat=m%7C%2C%2CQjdTYiJ2tGU3BU_GH0dEdHP3xP.bf1%2CX3MAYmto3dIXvxtKLc047xDQ-ic8Cp1sSEXFdNwI3jCgEoCkeXaVcUEst563z9xAfCKJA0yh5SU1ghecaaHHYAYNteBK8OZ7DIvCV9esk8tEm020MNzbLv1SEuMRyPYlcADhSBFgrq1wmgX2gbDfcdP-JeUKXNjKTOe6NKnFXqKCcK-tXT9lGpamAvthqAWsRBRwrb6gI7rgsWS9aSVUCO2sfBzuNvhYwiDSC2YiB_sXqzjzG6BQ3uhR6rCrn82Gvs5JBcRDrgkaAnfD4AYoGboL0nh_FozRn9b582mMlnH9eJMCHZUjEP_gSYy0uASP1KBqrXfPo-gFtjfdepj_fsAS-R5qWSiHKeW12XWwaunHNxVLSIfIsihjEatmVAVktJuoMmlLF89SeZ300ii-P3PBBPDLrudAyeA_R6Y7AGK4WDprIrvhe8wyF3YEiNVkTzWb1LfqVclQWCso1eAc7BoeRPhkwqX58ek6mWTRCELFDqexaMrwthzA7jGXWf3DwK-XqU6RJvKAvs6WuuIJIHxX6qZYJwn15RAAUyPS0vTIz1UBD_wdrmuy2Z1ZnfqjOkgCbXQlaYjbwGjSCc9ZlwRIFYtP-WluOz8xPPMwI4oY7XNQ_LyHddTt62r98Nmw4WS79ObKZknbGGP1x2OPblwt6Te3aVwqxoFtp8gVYeBRfi18QPQWAJgy1UUQP99vgm2jWoK4c1xLj7--pl_pr_IYcVeh3CqM1N3XLtfPvKiQYVAJnHyK9NiNrvcqFsgEEfdUr1xfu3BBUgW9Oudb3rHGozT_aYem7aYsLNqpTzrZ6jhAB6yA3TE14STjpaoF9zvay5fx9d5PASoyGiSCqrSZ4l72noSUYb-6VsOgIFwuQu4P8yViNQxcdnc_FC2jshrsl3S_Q8yZwsNttO4ntA8tuZaNk87Db8avPt4MZi8YZin-cx8JmyF0rP9I3FAnd4Mcc4ALooVYg0UQcgQds7javHqtx1KpGsKOe2n-zOM%2C | US | binary | 1 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3968 | chrome.exe | 142.250.186.36:443 | www.google.com | Google Inc. | US | whitelisted |
3968 | chrome.exe | 93.186.227.133:443 | sun9-22.userapi.com | VKontakte Ltd | RU | unknown |
3968 | chrome.exe | 93.186.227.156:443 | sun9-73.userapi.com | VKontakte Ltd | RU | unknown |
3968 | chrome.exe | 104.21.88.111:443 | daftsex.com | Cloudflare Inc | US | unknown |
3968 | chrome.exe | 142.250.185.74:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
3968 | chrome.exe | 192.243.59.12:443 | sadsims.com | DataWeb Global Group B.V. | US | malicious |
3968 | chrome.exe | 95.142.206.0:443 | sun6-20.userapi.com | VKontakte Ltd | RU | unknown |
3968 | chrome.exe | 93.186.227.134:443 | sun9-23.userapi.com | VKontakte Ltd | RU | unknown |
3968 | chrome.exe | 95.142.206.2:443 | sun6-22.userapi.com | VKontakte Ltd | RU | unknown |
3968 | chrome.exe | 93.186.227.153:443 | sun9-58.userapi.com | VKontakte Ltd | RU | unknown |
Domain | IP | Reputation |
---|---|---|
www.google.com |
| malicious |
accounts.google.com |
| shared |
daftsex.com |
| whitelisted |
safebrowsing.googleapis.com |
| whitelisted |
sadsims.com |
| malicious |
sun9-10.userapi.com |
| unknown |
sun9-23.userapi.com |
| unknown |
sun6-20.userapi.com |
| malicious |
sun9-54.userapi.com |
| unknown |
sun6-22.userapi.com |
| unknown |