| URL: | http://www.whatdoesitmean.com/index3011.htm |
| Full analysis: | https://app.any.run/tasks/13a0e546-13b6-4c82-9894-dbeae1c8672b |
| Verdict: | Malicious activity |
| Analysis date: | October 14, 2019, 14:22:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 4F717CB42E05172CD10EF3B7371CD061 |
| SHA1: | B639E0EE316D5C65A909971CFF5F3FD181DFAE99 |
| SHA256: | 9B7721BB04F66627171ED24DE0F226B1AA00CCABA21A5B5A5103F75F2AD7D6D5 |
| SSDEEP: | 3:N1KJS47RRzqMK0Nun:Cc4VoMK0U |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 836 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,2249942421517559100,7704110724703682479,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=9833517603646209815 --renderer-client-id=9 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3100 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1212 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2249942421517559100,7704110724703682479,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=10875048172947201944 --mojo-platform-channel-handle=1556 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1244 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2249942421517559100,7704110724703682479,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=5302350915627867923 --mojo-platform-channel-handle=5364 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1748 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,2249942421517559100,7704110724703682479,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=13284866930945208779 --renderer-client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3168 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1768 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,2249942421517559100,7704110724703682479,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16816945510925462442 --renderer-client-id=16 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2560 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1936 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,2249942421517559100,7704110724703682479,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4042364500379012107 --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2532 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1940 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2249942421517559100,7704110724703682479,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=15168065923579578344 --mojo-platform-channel-handle=5040 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1952 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2249942421517559100,7704110724703682479,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=6175697816582805756 --mojo-platform-channel-handle=5068 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1956 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2300 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1972 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2249942421517559100,7704110724703682479,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=7302749070545396455 --mojo-platform-channel-handle=4264 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (2148) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2148) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2148) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2148) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2148) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1956) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2148-13215536567592750 |
Value: 259 | |||
| (PID) Process: | (2148) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2148) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2148) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 1512-13197841398593750 |
Value: 0 | |||
| (PID) Process: | (2148) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2148 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\eeeb5a3b-94d9-4c71-89f4-fabe3b0b8734.tmp | — | |
MD5:— | SHA256:— | |||
| 2148 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2148 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2148 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2148 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2148 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF39a94a.TMP | text | |
MD5:— | SHA256:— | |||
| 2148 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2148 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
| 2148 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF39a95a.TMP | text | |
MD5:— | SHA256:— | |||
| 2148 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1212 | chrome.exe | GET | 302 | 72.52.179.175:80 | http://ad.reduxmedia.com/st?ad_type=iframe&ad_size=468x60§ion=822778 | US | — | — | malicious |
1212 | chrome.exe | GET | 302 | 108.168.193.183:80 | http://mybestdc.com/aS/feedclick?s=yytAuj_c3ed9KQX-OZ0z6uRQmJGd3rlti1AmguPZWJdouem6LYRNW191PGhifrDPu-nYe6d-YnsGvLcNuFljMD6MSGYX3p7McA8X4COsxS7emNSwEph1cB1lVC9oF4FMmrbARTGkk3NUUOUcZEDwassk593LVzcvJowUU7N6v2WYJPceosojLopx0p5bbs_4cfHroBQnH_-08G0jW4doeTxrCWc9TdRZayVzb2P68qMVHThyCvsRR72a5LKcIQPOefdal80INopxcEA-tkeRaGv-NqDt69bZLGTRSEmIUk-ymnP0DMfyf-22OVu4KSrp_azDt7cZ7e1FuFdN5OqVZ8cywq27j_8pWbjNUEDbdjebUWzI8P6c1wJBE1S5W4_33ZXvf2aS-udp8vvRO-InQottsPmnKH_2wB5ijH16V_LcwiDrCwKmGwcKdq-rxwXM8FDPDqOlNyJruw8Y03efqYn-1N3MqzwDxXxA-Oruc-AxveYye6PUoRjJ9QT4ZiNKHq7ASpkLzw6bVs7V0A2wXXt4ek-mMcKH1hO8T3hMHEPOJ5HMl1ZMRL8AfYB3AJOSfIz9QZV-p6D17YKwwYW6cdBIysdRmy2oJYbj7-jr4NKUaotihpO91JkWSw8Iu9-vnIUxcds0ty1qZLpSltPsbUFB-CybmxNW-maDg96dVC9-c5C1wCF_1r21ymvRotXPikoZt6h5OWMdAaMyujrPvFTrpMxhSfZSizQPz3axeoN5bTJBLfhJFtKX1gHwc97RJLj1uGisifa6gopTy2pBxUPhq_ivGiH60andAQv-e3n1cgIVMBUeEtOyvcQVW1CHZ74oc9nG_giXfRqKjAeW-VvNrmNuoOaebgHwSiOXg5eAYCTZAfnTPrF5g7J_uG82dFnOglS6K2Ogr4PRus0wHs0SEO9hR1sF4Ry1oqaOeqio4OwgjmIebXRDCzMNa6Ay9HsFuyh555M3DblZ6pMceS40DqZ7ERPjFN7KNHoS2oRCE5ctRvVfaG3Kl8L6UqLyGkorVNvWdz5wr3EzfLQYaTTDY9M_UjvKR4X36tuBsD90BtLm-45ucxtflCcNIcDiqJ8ofaN5-SLj2LilHCY4T8l76oX7PfaYQeMPhTS6uLyIxgbOdWoBzgJcOf7hUS1KrPnyI5y1u6uHJ6la0Bic2qgejVIrehRGC0Wy4qwZ9KUUarbi3qQuL4R5soFxzwXkiS9kVZ-q2rhCJ8nJgYn5WTKSSZqiMEWvsJ-30WbcSlwhcfYN3I46DhPV9wGELAqQBJ96XZxkqEKR0wOys_X6PeJip01C8trXZb_zJrX5I5QNlbqDXjUnQVQw4K1E-HTs-Feat60ijNzUBtLQ9JdmnRXHs3m32_EEaT9y8U6NjsKzLcKOpAXCSOvv5efjwLxrmH1dXImhb1CLYv7gI6xZ1OUg_mm1P-lix9UXEhndma6AV89IZE6SFU_Uwor2Z2o7oVzdaKuRclGWk90KVQ3rk3ch3wS4ilfXW9gY99LB0BzEJuGe6_-50neKz96xvxHbdrm_ccF9cB5pMMO_iiuFuIBXz0hkTpIV99PYFCyPgiVxtMqDC1viHDesTqDqxhb9e-D6rVyesoyYdxZs2lKpizTmoHNv1vU8ZE1IfvDZ-gj5e4qlV_SIdCkkpd-BkEmpXugTBfjD0eA7MRCw2iDeXvOuFCKizhE-jy9C1pDEDzMHESrWYMCrnTmMMKiT1gysKeiziFt6W_lctrYyHDwyUMYjFXZ7VyMb | US | — | — | malicious |
1212 | chrome.exe | GET | 200 | 23.37.58.95:80 | http://a.tribalfusion.com/j.ad?flashVer=0&ver=1.28&th=6796529920&tagKey=2659306998&site=whatdoesitmeancom&adSpace=ros¢er=1&size=728x90,468x60&env=display&url=http%3A%2F%2Fwww.whatdoesitmean.com%2Findex3011.htm&f=0&p=2901134&tKey=aYmneM5AUZcod6sTt7fYFMjUcFXTJElit&a=1&adContainerId=richmedia_2&rnd=2906748 | NL | text | 1.97 Kb | whitelisted |
1212 | chrome.exe | GET | 200 | 23.37.58.95:80 | http://a.tribalfusion.com/p.media?clickID=aImRKWTTBlQEYZdRsFZdQFivSdj7WsYP5U6pntInXEeM3dvZbQVrA5AnKoWIqVWFf0rnaYUYgXqytRrYZbUFMPVtF3nbBvRFryXqFp3T7g2avRna7GXbj6TtMSoArBnVftmWfH5qYe2Wmr3AjJmr3JYcb0YVF2XG7nnEvU5Un2WbBEUPQ1QabXScnsQWFx1djqTmQw4GBU0UZbDTBInR9QSjW5RQL&mediaDataID=6719746&mediaName=frame.html | NL | html | 323 b | whitelisted |
1212 | chrome.exe | GET | 200 | 108.62.121.31:80 | http://www.whatdoesitmean.com/index3011.htm | US | html | 35.3 Kb | whitelisted |
1212 | chrome.exe | GET | 200 | 23.37.58.95:80 | http://a.tribalfusion.com/p.media?clickID=aFmRKWUqbvVE3jQTnZdRsFCRF6qStv9VGbW5U2rmWqnYqqn2tbDPsZbB4AYZdmdZaNVHJ7Xbfd1FQf0qaMRrrZcUUZbYWdYUnFQvQbrn1Eno3TZba5TnYnaBBXFU8WH7XmP7ZapV7qmtMA2aZbg5tan4ABLmUfEXsfP1c3V0VvwpTZb45bYTTUJDV673REY0QG3pQdBvYdZbnTPbp4sBUXafIXDmB73UeQr&mediaDataID=8039566&mediaName=frame.html | NL | html | 262 b | whitelisted |
1212 | chrome.exe | GET | 200 | 23.37.58.95:80 | http://a.tribalfusion.com/p.media?clickID=aEmRKWorYxPFjqYqJp5qBa5Ej1mTBDXbU7TWBVmmfZdmGMuoWfF2qri3H6s3AjEpbMZcXGfS1sZb20VfnnEF33UJVWU7ZaWm7VQqb4ScvpStZbr0HbtTPYw3GB40UQDT6at2AZbcRPfD3tZbqXWUZdmdaO4AZbY5Gj6VcQjWsMfPPnoTHn4UFb22F2nUqQoVqY7QEUJQGbLRFuvPH7iWdBTRsyAeQiHBv&mediaDataID=6680176&mediaName=frame.html | NL | html | 198 b | whitelisted |
1212 | chrome.exe | GET | 200 | 23.37.58.95:80 | http://a.tribalfusion.com/p.media?clickID=ammRCV2afRoEFHXFF6UdMVnPbZcpV3qmHvH2qrg5tIo5mnZaprULYV3QYcQV0cnpnE7V5UQ4TUfEWA74QqfYSVUpPHJMYtntT6Yp3VvUXFZbLUmum5AFdR67K2dZbrXHrCpdan5AUT3sngTGr7VsJlP6FvWd33UbM05bAuVTjtWaU8PanIQVFCQFamRHYcWsU35bquodqO0qeu1Hvql6mq26&mediaDataID=5406476&mediaName=frame.html | NL | html | 269 b | whitelisted |
1212 | chrome.exe | GET | 200 | 23.37.58.95:80 | http://a.tribalfusion.com/displayAd.js?dver=0.8&th=6796529920 | NL | text | 329 b | whitelisted |
1212 | chrome.exe | GET | 200 | 23.37.58.95:80 | http://a.tribalfusion.com/p.media?clickID=aGmRKWREjQQsQrQdYs0WjuWPrw3sJYYFZbLU6Pq46ZbcQ67I2HZbp1dvZbnWZax36U13cr6TcJaUsreRAUoUtv4Urn02rZawVTjxWaJ6STrLQVJCPritPWv7VcbT2Fyxmtyo0aeM4WnGPcrH2m3Ipd6nUt3hXUfa1UB90qqsPbMZbTb33WWYUnUQoRUJrYaUo5EBe2qU1oaMI1rUfUsYSyprwfyEK2N&mediaDataID=4056396&mediaName=frame.html | NL | html | 196 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1212 | chrome.exe | 108.62.121.31:80 | www.whatdoesitmean.com | Nobis Technology Group, LLC | US | unknown |
1212 | chrome.exe | 172.217.21.227:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
1212 | chrome.exe | 172.217.22.13:443 | accounts.google.com | Google Inc. | US | whitelisted |
1212 | chrome.exe | 172.217.16.132:443 | www.google.com | Google Inc. | US | whitelisted |
1212 | chrome.exe | 95.100.79.150:80 | tags.expo9.exponential.com | Akamai Technologies, Inc. | — | whitelisted |
1212 | chrome.exe | 72.52.179.175:80 | ad.reduxmedia.com | Liquid Web, L.L.C | US | malicious |
1212 | chrome.exe | 23.37.58.95:80 | a.tribalfusion.com | Akamai Technologies, Inc. | NL | whitelisted |
1212 | chrome.exe | 185.64.189.115:443 | image6.pubmatic.com | PubMatic, Inc. | GB | unknown |
1212 | chrome.exe | 216.58.210.2:443 | cm.g.doubleclick.net | Google Inc. | US | whitelisted |
1212 | chrome.exe | 52.28.145.127:443 | pixel.advertising.com | Amazon.com, Inc. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
www.whatdoesitmean.com |
| unknown |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
tags.expo9.exponential.com |
| whitelisted |
www.google.com |
| malicious |
a.tribalfusion.com |
| whitelisted |
ad.reduxmedia.com |
| malicious |
ads.stickyadstv.com |
| whitelisted |
cm.g.doubleclick.net |
| whitelisted |
image6.pubmatic.com |
| whitelisted |