URL:

https://fwlink.taxcom.ru/ShowContents.aspx?ContentId=330

Full analysis: https://app.any.run/tasks/edd7f457-f351-4247-9124-fb717bf92349
Verdict: Malicious activity
Analysis date: April 16, 2024, 11:59:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

B6F266916091AA35DDB03F081F13766F

SHA1:

338D66058644034F38FF3CCF2D104213C20185A4

SHA256:

7D6701517C02D7C7B4B80DADE6812F53265001D7AE448996C5426D65068D7184

SSDEEP:

3:N8MM6suplWjqmlRsuRV:2wsuplsdLt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • assistant_fs.exe (PID: 2364)
  • SUSPICIOUS

    • Process drops SQLite DLL files

      • assistant_fs.exe (PID: 2364)
    • Executable content was dropped or overwritten

      • assistant_fs.exe (PID: 2364)
    • The process drops C-runtime libraries

      • assistant_fs.exe (PID: 2364)
    • Process drops legitimate windows executable

      • assistant_fs.exe (PID: 2364)
    • Reads the Internet Settings

      • assistant_fs.exe (PID: 2364)
      • assistant_spt.exe (PID: 2752)
      • assistant_spt.exe (PID: 3892)
    • Reads security settings of Internet Explorer

      • assistant_fs.exe (PID: 2364)
      • assistant_spt.exe (PID: 2752)
    • Application launched itself

      • assistant_spt.exe (PID: 2752)
      • assistant_spt.exe (PID: 3892)
      • assistant_spt.exe (PID: 3308)
    • Connects to unusual port

      • assistant_spt.exe (PID: 3892)
    • Executes as Windows Service

      • assistant_spt.exe (PID: 3308)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 2068)
    • Checks supported languages

      • assistant_fs.exe (PID: 2364)
      • assistant_spt.exe (PID: 2752)
      • assistant_spt.exe (PID: 3892)
      • assistant_spt.exe (PID: 1112)
      • assistant_spt.exe (PID: 3308)
      • assistant_spt.exe (PID: 1556)
      • wmpnscfg.exe (PID: 2972)
    • The process uses the downloaded file

      • chrome.exe (PID: 1196)
      • chrome.exe (PID: 2068)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2068)
    • Drops the executable file immediately after the start

      • chrome.exe (PID: 2068)
    • Create files in a temporary directory

      • assistant_fs.exe (PID: 2364)
      • assistant_spt.exe (PID: 3892)
    • Reads the computer name

      • assistant_fs.exe (PID: 2364)
      • assistant_spt.exe (PID: 2752)
      • assistant_spt.exe (PID: 1112)
      • assistant_spt.exe (PID: 3308)
      • wmpnscfg.exe (PID: 2972)
      • assistant_spt.exe (PID: 3892)
      • assistant_spt.exe (PID: 1556)
    • Checks proxy server information

      • assistant_spt.exe (PID: 3892)
    • Reads the machine GUID from the registry

      • assistant_spt.exe (PID: 1556)
      • assistant_spt.exe (PID: 3892)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2972)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
25
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs assistant_fs.exe assistant_spt.exe no specs assistant_spt.exe assistant_spt.exe no specs assistant_spt.exe no specs assistant_spt.exe chrome.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
480"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --mojo-platform-channel-handle=3856 --field-trial-handle=1184,i,4906210131377257404,16733691550459789371,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
784"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd4,0x6bb78b38,0x6bb78b48,0x6bb78b54C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
848"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --disable-quic --mojo-platform-channel-handle=3900 --field-trial-handle=1184,i,4906210131377257404,16733691550459789371,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1072"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --disable-quic --mojo-platform-channel-handle=3448 --field-trial-handle=1184,i,4906210131377257404,16733691550459789371,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1112"C:\Users\admin\AppData\Local\Temp\Assistant_fs\assistant_spt.exe" "-RUN=C:\Users\admin\AppData\Local\Temp\Assistant_fs\assistant_spt.exe" "-SID=1" "-PARAMS=-ASRCT#32-ISS:0#32-PID:3892#32-PIPE:CF25D0E8F2A749079AC24B75BFC44E19#32-UID:{60980A8D-F3F1-41CB-8EC3-4618A16625DC}#32-USER:"admin"#32-OSI:6_0_0_0_61#32-LNG:"eng.lng""C:\Users\admin\AppData\Local\Temp\Assistant_fs\assistant_spt.exeassistant_spt.exe
User:
admin
Company:
ООО «САФИБ»
Integrity Level:
HIGH
Description:
Ассистент 5
Exit code:
0
Version:
5.0.2208.1501
Modules
Images
c:\users\admin\appdata\local\temp\assistant_fs\assistant_spt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1196"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=3804 --field-trial-handle=1184,i,4906210131377257404,16733691550459789371,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1288"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --disable-quic --mojo-platform-channel-handle=3312 --field-trial-handle=1184,i,4906210131377257404,16733691550459789371,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1556C:\Users\admin\AppData\Local\Temp\Assistant_fs\assistant_spt.exe -ASRCT -ISS:0 -PID:3892 -PIPE:CF25D0E8F2A749079AC24B75BFC44E19 -UID:{60980A8D-F3F1-41CB-8EC3-4618A16625DC} -USER:admin -OSI:6_0_0_0_61 -LNG:eng.lngC:\Users\admin\AppData\Local\Temp\Assistant_fs\assistant_spt.exe
assistant_spt.exe
User:
SYSTEM
Company:
ООО «САФИБ»
Integrity Level:
SYSTEM
Description:
Ассистент 5
Version:
5.0.2208.1501
Modules
Images
c:\users\admin\appdata\local\temp\assistant_fs\assistant_spt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2068"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "https://fwlink.taxcom.ru/ShowContents.aspx?ContentId=330"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2292"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1072 --field-trial-handle=1184,i,4906210131377257404,16733691550459789371,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
16 803
Read events
16 561
Write events
234
Delete events
8

Modification events

(PID) Process:(2068) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2068) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2068) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2068) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2068) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2068) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2068) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2068) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2068) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(2068) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:metricsid
Value:
Executable files
20
Suspicious files
20
Text files
39
Unknown types
23

Dropped files

PID
Process
Filename
Type
2068chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.datbinary
MD5:
SHA256:
2068chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Variationsbinary
MD5:
SHA256:
2068chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Versiontext
MD5:
SHA256:
2068chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF18ff79.TMP
MD5:
SHA256:
2068chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
2068chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF18ff79.TMPtext
MD5:
SHA256:
2068chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldtext
MD5:
SHA256:
2068chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF18ffa8.TMPtext
MD5:
SHA256:
2068chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.oldtext
MD5:
SHA256:
2068chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\259a9709-69b1-492b-9b3b-7be9c015c5b1.tmpbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
66
DNS requests
109
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4072
chrome.exe
GET
301
193.0.214.48:80
http://www.taxcom.ru/404
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4072
chrome.exe
173.194.76.84:443
accounts.google.com
GOOGLE
US
whitelisted
2068
chrome.exe
239.255.255.250:1900
unknown
4072
chrome.exe
193.0.214.242:443
fwlink.taxcom.ru
OOO Taxcom
RU
unknown
4072
chrome.exe
193.0.214.48:443
taxcom.ru
OOO Taxcom
RU
unknown
2068
chrome.exe
224.0.0.251:5353
unknown
4072
chrome.exe
216.58.206.36:443
www.google.com
GOOGLE
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4072
chrome.exe
216.58.212.142:443
sb-ssl.google.com
GOOGLE
US
whitelisted
4072
chrome.exe
193.0.214.48:80
taxcom.ru
OOO Taxcom
RU
unknown

DNS requests

Domain
IP
Reputation
fwlink.taxcom.ru
  • 193.0.214.242
unknown
accounts.google.com
  • 173.194.76.84
shared
taxcom.ru
  • 193.0.214.48
whitelisted
www.google.com
  • 216.58.206.36
  • 172.217.18.100
whitelisted
sb-ssl.google.com
  • 216.58.212.142
whitelisted
www.taxcom.ru
  • 193.0.214.48
unknown
www.googleapis.com
  • 142.250.185.74
  • 142.250.185.170
  • 142.250.181.234
  • 216.58.212.138
  • 216.58.212.170
  • 172.217.16.138
  • 172.217.18.106
  • 142.250.185.106
  • 142.250.184.202
  • 142.250.185.138
  • 142.250.185.202
  • 142.250.185.234
  • 142.250.186.74
  • 216.58.206.42
  • 216.58.206.74
  • 142.250.184.234
whitelisted
www.googletagmanager.com
  • 142.250.185.136
whitelisted
dns.xn--80akicokc0aablc.xn--p1ai
  • 212.193.169.65
  • 45.84.85.231
  • 62.105.131.170
  • 185.40.77.118
  • 185.40.77.244
unknown
id-proxy.service.ast
  • 212.193.169.65
  • 185.40.77.244
  • 185.40.77.118
unknown

Threats

No threats detected
Process
Message
assistant_spt.exe
+12:00:37.093 R+rgondrrc 3892.03716 + Rct reg OnDrcRcv
assistant_spt.exe
4/16/2024 1:00:41 PM admin Çàïóùåí C:\Users\admin\AppData\Local\Temp\Assistant_fs\assistant_spt.exe
assistant_spt.exe
4/16/2024 1:00:41 PM admin Ïàðàìåòðû: -ASRCT -ISS:0 -PID:3892 -PIPE:CF25D0E8F2A749079AC24B75BFC44E19 -UID:{60980A8D-F3F1-41CB-8EC3-4618A16625DC} -USER:admin -OSI:6_0_0_0_61 -LNG:eng.lng
assistant_spt.exe
4/16/2024 1:00:41 PM admin Çàïóùåí ñëóæáîé: 0
assistant_spt.exe
4/16/2024 1:00:41 PM admin PID: 1556
assistant_spt.exe
4/16/2024 1:00:41 PM admin OS active user name: admin
assistant_spt.exe
4/16/2024 1:00:41 PM admin OS user name: SYSTEM
assistant_spt.exe
4/16/2024 1:00:41 PM admin Pipe user name: admin
assistant_spt.exe
4/16/2024 1:00:41 PM admin Pipe UID: CF25D0E8F2A749079AC24B75BFC44E19
assistant_spt.exe
4/16/2024 1:00:41 PM admin OSI: 6_0_0_0_61