URL:

https://starbucks.cashstar.com/gift-card/view/aEu9GBKDvb1S7NEwLPIZQyBKC/mark.verrill%40zoominfo.com/

Full analysis: https://app.any.run/tasks/40ada015-9d04-4cda-a97c-7a4370bdf7c2
Verdict: Malicious activity
Analysis date: May 11, 2021, 19:32:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

87D61BCAB243EACA49F91A458EC773BD

SHA1:

C54049A4DBAE0F552912E2E9B8C7A1A52077929F

SHA256:

84D5D1A1C26F6DCA363484567394C20DE410EAFDE05251B4B1A398CBBBB63BD6

SSDEEP:

3:N8cnMaNOmDRIb8l5DiuF02xEkWX5RVil3:2cnfNO0uQlFF0mEkWXPVil3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • chrome.exe (PID: 1804)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1804"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "https://starbucks.cashstar.com/gift-card/view/aEu9GBKDvb1S7NEwLPIZQyBKC/mark.verrill%40zoominfo.com/"C:\Program Files\Google\Chrome\Application\chrome.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
2440"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6c1ea9d0,0x6c1ea9e0,0x6c1ea9ecC:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
71
DNS requests
38
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.124.249.22:80
http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D
US
der
1.69 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
151.101.1.24:443
starbucks.cashstar.com
Fastly
US
unknown
142.250.185.100:443
www.google.com
Google Inc.
US
whitelisted
172.217.23.109:443
accounts.google.com
Google Inc.
US
suspicious
142.250.185.202:443
fonts.googleapis.com
Google Inc.
US
whitelisted
151.101.194.217:443
cdn.ravenjs.com
Fastly
US
suspicious
54.216.48.107:443
mpsnare.iesnare.com
Amazon.com, Inc.
IE
unknown
3.218.219.174:443
bc-s.cashstar.com
US
unknown
142.250.186.131:443
www.gstatic.com
Google Inc.
US
whitelisted
216.58.212.163:443
fonts.gstatic.com
Google Inc.
US
whitelisted
172.217.23.99:443
ssl.gstatic.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
starbucks.cashstar.com
  • 151.101.1.24
  • 151.101.65.24
  • 151.101.129.24
  • 151.101.193.24
unknown
accounts.google.com
  • 172.217.23.109
shared
s3static.cashstar.com
  • 151.101.0.138
  • 151.101.64.138
  • 151.101.128.138
  • 151.101.192.138
unknown
www.google.com
  • 142.250.185.100
malicious
mpsnare.iesnare.com
  • 54.216.48.107
  • 52.19.133.188
whitelisted
cdn.ravenjs.com
  • 151.101.194.217
  • 151.101.2.217
  • 151.101.130.217
  • 151.101.66.217
whitelisted
www.gstatic.com
  • 142.250.186.131
whitelisted
fonts.googleapis.com
  • 142.250.185.202
whitelisted
fonts.gstatic.com
  • 216.58.212.163
whitelisted
clients1.google.com
  • 142.250.186.174
whitelisted

Threats

No threats detected
No debug info