| URL: | http://iyfbodn.com/?dn=bursakart.com&pid=9POT3387I&pbsubid=2347ab1b-2c77-4573-9bf9-04082d9dfe57&noads=http%3A%2F%2Fiyfbodn.com%2F%3Fdn%3Dbursakart.com%26skipskenzo%3Dtrue |
| Full analysis: | https://app.any.run/tasks/70c69027-70f6-4df5-b352-f54a8cbfec40 |
| Verdict: | Malicious activity |
| Analysis date: | March 27, 2024, 08:19:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | E38CA6BFA1751C6F4D0F487E57B58896 |
| SHA1: | 16DF6D88E0043DE8E362B4647C5CA14A7BCF5331 |
| SHA256: | 8C790FDD0C1CB5B8151BDF2193049A29BB0BEA105EF28E20D42C20D241DF8242 |
| SSDEEP: | 3:N1KXy6L2WEOu2DsNsA9VXV2l5VqZwRtJsXju2yLzRCWnu2AXTJMnAq:CppMCc9Ul5VqZkHszuNLzRuVMnAq |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 968 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=3220 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1348 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1304 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1504 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=3500 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1536 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --mojo-platform-channel-handle=3976 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2040 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=3224 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2064 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1520 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2124 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "http://iyfbodn.com/?dn=bursakart.com&pid=9POT3387I&pbsubid=2347ab1b-2c77-4573-9bf9-04082d9dfe57&noads=http%3A%2F%2Fiyfbodn.com%2F%3Fdn%3Dbursakart.com%26skipskenzo%3Dtrue" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2128 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3304 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2596 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2036 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2640 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3428 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Variations | binary | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF182381.TMP | — | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF182381.TMP | text | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF182390.TMP | text | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\bcf6e48e-1dee-4981-8bb4-4d5ec94709b1.tmp | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1348 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://iyfbodn.com/?dn=bursakart.com&pid=9POT3387I&pbsubid=2347ab1b-2c77-4573-9bf9-04082d9dfe57&noads=http%3A%2F%2Fiyfbodn.com%2F%3Fdn%3Dbursakart.com%26skipskenzo%3Dtrue | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.253:80 | http://i1.cdn-image.com/__media__/pics/29590/bg1.png | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://iyfbodn.com/px.js?ch=2 | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.253:80 | http://i1.cdn-image.com/__media__/js/min.js?v2.3 | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://iyfbodn.com/px.js?ch=1 | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.253:80 | http://i1.cdn-image.com/__media__/pics/28905/arrrow.png | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.253:80 | http://i1.cdn-image.com/__media__/fonts/montserrat-bold/montserrat-bold.woff | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.253:80 | http://i1.cdn-image.com/__media__/fonts/montserrat-regular/montserrat-regular.woff | unknown | — | — | unknown |
1348 | chrome.exe | GET | 404 | 208.91.196.46:80 | http://iyfbodn.com/favicon.ico | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://iyfbodn.com/Equities.cfm?domain=bursakart.com&fp=Rq1oVJzINRsvW65Xta15JDLertdX4LEP7WwcpyL6PUvKeNdB01NaUjXlsMoX3wKmJqJgtEhQ90UW%2FxYqHUYVs%2F8UyeB7BHUoRJX%2BYdGWofMLG4ecg%2BqeVAwdfvlREmXkpmvix5sxYmVbuZ6WZLYGDpXJsWVols5z023LW3M%2FoidrULsC1mah8PRsrpun4HC23CdiHeC7uP7vZkZHFt47I7IUIqvCs7j9Ifj%2BPr153%2BNfGvHxktQC7Q3ulDfYVBWvH4oUBd09OuPa8ypqNdCC5Cs%2FYhVFFDSsQwbzDeaUcB%2BmBiVZEdmKGBPl3ZmMp9aN&yep=C2kfdZMQEyGGAf3GbYxsU1RunfTyproQk1QWJibFEqS%2BLfEcNKkAn8pXhKiKygpYSS1HnWg8he7XM7UB6q9gD%2BDJ9GayFwDtEI54%2BzNb77cRwYo1%2FKrENXxVQA2jFJN3RvRSOPVfu9U4tN9xwtyibwBv96ow8IGaCDz44zWg9zy5ru5E8IzJ5u6NVrfMozvkddhiDf8N9Udt5U1HLY%2FYu3dEu%2Fgr%2FZdVSZMo7YkiCAaYYFWbAYMnpgLMl1FaIX683ENdJ8w3bJDqiEIYeva2fWj0f2y8ajxdMBZJkGPpIoriz3YYHLlzIhb1eLaybTjCdQQnx3uBc9wdrkVzOPt8Cgxusda%2FLvr46w1f6alzFz3xrym%2BBtY6b4CKvHu5TW6Ks5UP43n5kSKf7oUwQf3HEbC%2BhCrFbE3nbNk%2B%2B6y5iXHpVTfgBMeFcOEo79RRNTiQZod2tS2%2FXXmerxP9nXRHOM2Y6F5JEra65r%2FMqEuoiLqcweVxEPKTOHdzexdJWnRJrObCNpv7MUECJ%2FbHZ0AHRrYQi1hVYLmKxp5CjeEeLguRRoLDL4HCjRNZ6olzY4A4mT8D2nq247gDlrjOyOhADpmVekfkYCyzQiEaXngeJeU18XcvLfPhQU1aKGrxqcf6Wo3L3bRuMFwmbI78rzSFpFuh6jV6qpT8q0XGrOn98UuuFCcueXY2ubzR%2F34M3%2FxmgPJUoVzMfWACedwb2JAQaPHRGQP5tG%2FlnvyJ1sN4N6QZSUB%2B3r5mFGce8JvL4LGI9SIiSxcPwhMwgrQEXh9LiMO1l6jTzqcoU%2BhBMP7XKF0HG84BRXrmI9peL03ZIJTbtaG0k7edh5nx03LDkdJuHIhRGNV9FpAJgoa5sn5E88e7L5kM2iScOdQy2Ym%2BaG9R0bHcazhVZs6UwInTW2OZvPvNNaUiE%2FeBFxHxCJ3b0pnGWCBOu%2FK%2Fnatu%2F%2FSCOluXeDyjBMfgPx8aJgwaQiI6qhBoHmf0f3AR5H0gUpa6bmxnMHcTBudqX09tXw7j0PGAOQnWv2A2YOY5qhPJTSmDmaNL0GlFFGiarwXWuAGcsMIEED1qmmlWH%2BMX%2FPV2ZcM2MHiPP%2Bnxo3NeGDU3W%2Fw0A8n6%2B7alhvK1wGty7D1MJ0IUTMtq1QWUNNCu%2F6AHNL0kmrvkAM%2B%2BtUyk3yI8JwS4IWVRNHeV8qMj4RWLJQnm0rNGd9pRje3f1dNnKSryBH8iPUA5Q1qQw0BBy2RxWDV97CcWDm4pmd7m%2FTFzxbHnMXkbEZXNe95Ic1kD82%2BvGMjMWUiTuoY2%2F%2FHFBIH8u51PLIEQU4%2FU4CD0yprAPomVHFb%2F96cv9yjVW72LR1PClex5%2FqrCCTvBXUTkiCp905nZYfDgfe1W59xtv%2BueRB3ItCYtV%2Bkn8ZwyxRvX%2BU6JFeczgzKN1IkCxKWSYKHu3q6zbmTvEHcq8x0HMLezxe3sp%2FURzK16mwaJdhyHCgwjaSriyB9GJRuuLQexU05BxUXj2DOAGAOA5kalt3CJS%2FpiynHKkUKnPZbPXQcZeNmfyh2hgvsRLQ%2F00jMWkxk%2FmOrfmowHkDxENGYB1MclBrndtyVr1fjNpeRoT66gI5E43lHgFsigfpzHILcGWs%2BOsq3vjw%3D%3D>np=0>pp=0&tp1=2347ab1b-2c77-4573-9bf9-04082d9dfe57&kbetu=1&maxads=0&kld=1003&yprpnd=UHM6ofc%2BmzTMdphcWy%2Bzzw%3D%3D&_opnslfp=1&pbsubid=2347ab1b-2c77-4573-9bf9-04082d9dfe57&noads=http%3A%2F%2Fiyfbodn.com%2F%3Fdn%3Dbursakart.com%26skipskenzo%3Dtrue>np=0>pp=0&kt=362&&kbc=bursa&ki=9934307&ktd=0&kld=1003&kp=1&bd=0%23720%231280%231%230%23564%23163 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2124 | chrome.exe | 239.255.255.250:1900 | — | — | — | unknown |
1348 | chrome.exe | 142.250.27.84:443 | accounts.google.com | GOOGLE | US | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1348 | chrome.exe | 208.91.196.46:80 | iyfbodn.com | CONFLUENCE-NETWORK-INC | VG | unknown |
1348 | chrome.exe | 87.230.98.78:443 | delivery.consentmanager.net | PlusServer GmbH | DE | unknown |
1348 | chrome.exe | 208.91.196.253:80 | i1.cdn-image.com | CONFLUENCE-NETWORK-INC | VG | unknown |
1348 | chrome.exe | 195.181.175.40:443 | cdn.consentmanager.net | Datacamp Limited | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
accounts.google.com |
| shared |
iyfbodn.com |
| unknown |
i1.cdn-image.com |
| whitelisted |
delivery.consentmanager.net |
| malicious |
cdn.consentmanager.net |
| malicious |
a.delivery.consentmanager.net |
| unknown |
bursakart.com |
| unknown |
skenzo.com |
| unknown |
www.google.com |
| whitelisted |
i3.cdn-image.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1348 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Global content delivery network (unpkg .com) |