| URL: | http://iyfbodn.com/?dn=bursakart.com&pid=9POT3387I&pbsubid=2347ab1b-2c77-4573-9bf9-04082d9dfe57&noads=http%3A%2F%2Fiyfbodn.com%2F%3Fdn%3Dbursakart.com%26skipskenzo%3Dtrue |
| Full analysis: | https://app.any.run/tasks/70c69027-70f6-4df5-b352-f54a8cbfec40 |
| Verdict: | Malicious activity |
| Analysis date: | March 27, 2024, 08:19:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | E38CA6BFA1751C6F4D0F487E57B58896 |
| SHA1: | 16DF6D88E0043DE8E362B4647C5CA14A7BCF5331 |
| SHA256: | 8C790FDD0C1CB5B8151BDF2193049A29BB0BEA105EF28E20D42C20D241DF8242 |
| SSDEEP: | 3:N1KXy6L2WEOu2DsNsA9VXV2l5VqZwRtJsXju2yLzRCWnu2AXTJMnAq:CppMCc9Ul5VqZkHszuNLzRuVMnAq |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 968 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=3220 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1348 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1304 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1504 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=3500 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1536 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --mojo-platform-channel-handle=3976 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2040 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=3224 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2064 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1520 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2124 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "http://iyfbodn.com/?dn=bursakart.com&pid=9POT3387I&pbsubid=2347ab1b-2c77-4573-9bf9-04082d9dfe57&noads=http%3A%2F%2Fiyfbodn.com%2F%3Fdn%3Dbursakart.com%26skipskenzo%3Dtrue" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2128 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3304 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2596 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2036 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2640 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3428 --field-trial-handle=1168,i,2554266307810238065,3833392754331759930,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (2124) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Variations | binary | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF182381.TMP | — | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF182381.TMP | text | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF182390.TMP | text | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2124 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\bcf6e48e-1dee-4981-8bb4-4d5ec94709b1.tmp | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1348 | chrome.exe | GET | 200 | 208.91.196.253:80 | http://i1.cdn-image.com/__media__/pics/29590/bg1.png | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://iyfbodn.com/px.js?ch=1 | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://iyfbodn.com/px.js?ch=2 | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.46:80 | http://iyfbodn.com/?dn=bursakart.com&pid=9POT3387I&pbsubid=2347ab1b-2c77-4573-9bf9-04082d9dfe57&noads=http%3A%2F%2Fiyfbodn.com%2F%3Fdn%3Dbursakart.com%26skipskenzo%3Dtrue | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.253:80 | http://i1.cdn-image.com/__media__/js/min.js?v2.3 | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.253:80 | http://i1.cdn-image.com/__media__/pics/28905/arrrow.png | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.253:80 | http://i1.cdn-image.com/__media__/fonts/montserrat-bold/montserrat-bold.woff | unknown | — | — | unknown |
1348 | chrome.exe | GET | 200 | 208.91.196.253:80 | http://i1.cdn-image.com/__media__/fonts/montserrat-regular/montserrat-regular.woff | unknown | — | — | unknown |
1348 | chrome.exe | GET | 404 | 208.91.196.46:80 | http://iyfbodn.com/favicon.ico | unknown | — | — | unknown |
1348 | chrome.exe | GET | — | 208.91.196.46:80 | http://iyfbodn.com/Equities.cfm?domain=bursakart.com&fp=Rq1oVJzINRsvW65Xta15JDLertdX4LEP7WwcpyL6PUuf%2Bb1SuKZmhUz5Zsu1vD1WikretG83RP3kGczpwA%2BVKBdBD40MBZ%2FjgMaojkXJ65qjXjzA0EqN1lLKNIbZktnys7XbfiNOe%2FcOMdhNI8pRAiuG2mW9hXPH4c0SttJRZp9fMOnmpKjv%2FI28gerISXfEFNZ8BscuEGcuPXWiOfAu6D0fWpRmsDk1B5WzHHI%2B%2F1p1xjU%2BS4RRcFzO05ONJ8BeV%2F0U97putavZkGnOkgS7FC9ZjQXlsTeUa7aoku0%2FLrNRnEa3d5Ox%2BTqMn1ad8LnC&yep=lSacZ8jCLgDp36HGLCMdGhe%2Fl%2FmGktYZqFFeNF8pv4Ep2DG4%2Bh0O8zWFeZ4fO6alDmH4cVAserM09fEzQUPfx3NG%2Bozb%2BMoxqA4bhzX6jgO1LeAfDg3GmeJd2vvqOqhmLbyAY7SOvrFGHcUR%2FaYDJU5YjszhXXf7xNPBpJvzAyXzC3GipMEUEPEcKiyQsrjWxJuWsOfo9BGNLKMer9nAFiwX0KjIVlw%2BhEhJIWyzRPXeqhwhW5GhHwF4z%2Frt%2BrhB94myMugPRt5BEPOJ4vjKi8EOPQSpPO0XoFgiwRfj2z4EZn4FIV2Q4BK8cSRKmA4VtIlPdH0s%2BNhMAmLM0491ogFmSZB%2BsdQQV3UmBBv3LoMXULB6nJmW3bs%2F7VDoVOZhDBJxRp9iu9vrWHotWADJB8mCAWEb9PEa7ff5%2B%2BMpwoA1Z8CY6YHaf2%2FjxpNTvRxIEDD3w3UruFFt6uD835%2F3eO1bep5wufUREStHiHPfO9sAe2AZH4CkEp9A32cmFc%2B%2BxIh4QQJ7y5wX8Z1I%2BmeYjJu55eUK8OmVh0BcMzewW8s%2Fze%2FryMrH8pTFeULTO2B1waFoFTK1xkxvU4dJqxFzcqdTSju7u2zSPWijZGfHbZij%2BqFkxe7hBU9HqZ00CvVBQ1qrKpt1jC7cai9vfiXhibrBTAGPMiL0HoSszxsB1wlkfx5yEJWkRgpf602H8rXkX2b4swEfhcuw%2FNdhvBPHJOErg8vd%2Fuo1OPD1uy3TTEwMnlkIODz1kP%2BCQbSeRmIIDDZq6NuAHJpC5aNCpFp2mYdXSziESG8NkQEWPTsWMebbGWBg7QtV5R%2BTEypiUgLa7CXFabPW0z2xFFmhd%2BUqD1%2BfpCRLm7wjT%2FrFnHQHtSQ33rF27YIaxO%2FDaOkrqS9my%2Fk47bFAeFY9JjzZ8bKGEYnw8RrWod2Oi40FzOCooG3TgyAZz6MEBBNBa3ccJDBGzFWsJmIvIgdk1fkjc00d2NvJX7dVzEK6ZSsNz%2F18xLNlDzB3jcdmdGZ6Adn8ep7BkMk5pgeIPT4PY9QhoZOo%2BbfjllDstMTKXG05Yt1%2F%2BdtrxYJ9ho2g6rqYLOf13p7gFGgN%2FXF7uoNR%2B0zdvVXTyGpidxDWB7KrX0%2Bf2475d6Z52bHLiT1qSyg%2B2Z%2BkPObP%2B0OZvu%2FYkrOywIld3mIfuPoBA4JSUHBlpM8aks6MAsdSl1IAjsJN%2BmwL3Oz2e26fyoQH6sxnkV2FGApcszE7S%2BN5THMYTngFOYmxw%2BFrAUCDJUc3f1EOB7eN%2FyFw7qN95KR90z2xsnZ99BSxVO%2FEDtaoYLW6ix4egtrj%2B8HvimsAhZ%2FlB6F4LvyzmRAXJblN7seWLeddouCg8cH66C92AQkleUOlN6prr5l%2FUjhWYI3T1p7Ysmy2DPqcgcMLoAjAsFaY8go%2F6sMKQADcJS260zRci3vrnvRZqaKQN%2BcdL8P2%2BnANRC4rdlKx%2BpCeZGXALt4oUmgrAI5W4B%2BB5vMVCTwpJmBZI1hBAbXz%2BUjP59M4KrWVhnk2Xi8B1elcsczQ7n%2FiUf%2BxiddktQ%2BIO9h84glqyVVu%2BTRVNqDI3u%2B%2FB64WoXz3uShcTRrADpAik6lH5NBlD%2B4iVNX22bR%2BVc6Ujg%3D%3D>np=0>pp=0&tp1=2347ab1b-2c77-4573-9bf9-04082d9dfe57&kbetu=1&maxads=0&kld=1003&yprpnd=UHM6ofc%2BmzTMdphcWy%2Bzzw%3D%3D&_opnslfp=1&prvtof=gonkIfSXWnUBtj4ctu7c2jrUO6NFSS6HVyfVslBeTsaLYDZjWssBwKtDdQYsYzKraIwnzRXXil6wprPKUbhqqh74Fe6VGLF8ty3%2BMlbqAJrD8Saipb8JPPf3V74QUPWeme8k%2FTAVkdDxOMrrOCH2YeoVhdFP%2FVyYWKXvEwd0LSkl%2FcI0ToJPlvOQQGzXIlcEO%2BrXkoT%2FgGb99q7iHKJ12A%3D%3D&pbsubid=2347ab1b-2c77-4573-9bf9-04082d9dfe57&noads=http%3A%2F%2Fiyfbodn.com%2F%3Fdn%3Dbursakart.com%26skipskenzo%3Dtrue>np=0>pp=0&kt=362&&kbc=bursa&ki=9934307&ktd=0&kld=1003&kp=1&bd=0%23720%231280%231%230%23608%23246 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2124 | chrome.exe | 239.255.255.250:1900 | — | — | — | unknown |
1348 | chrome.exe | 142.250.27.84:443 | accounts.google.com | GOOGLE | US | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1348 | chrome.exe | 208.91.196.46:80 | iyfbodn.com | CONFLUENCE-NETWORK-INC | VG | unknown |
1348 | chrome.exe | 87.230.98.78:443 | delivery.consentmanager.net | PlusServer GmbH | DE | unknown |
1348 | chrome.exe | 208.91.196.253:80 | i1.cdn-image.com | CONFLUENCE-NETWORK-INC | VG | unknown |
1348 | chrome.exe | 195.181.175.40:443 | cdn.consentmanager.net | Datacamp Limited | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
accounts.google.com |
| shared |
iyfbodn.com |
| unknown |
i1.cdn-image.com |
| whitelisted |
delivery.consentmanager.net |
| malicious |
cdn.consentmanager.net |
| malicious |
a.delivery.consentmanager.net |
| unknown |
bursakart.com |
| unknown |
skenzo.com |
| unknown |
www.google.com |
| whitelisted |
i3.cdn-image.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1348 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Global content delivery network (unpkg .com) |