URL:

https://cheater.fun/hacks_roblox/

Full analysis: https://app.any.run/tasks/6dfc768a-3afd-4c40-9458-0b279717a599
Verdict: Malicious activity
Analysis date: April 03, 2025, 11:17:06
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
obfuscated-js
github
Indicators:
MD5:

34044B856D2C7FD8EA039DE12AC8F338

SHA1:

0ACFE5FF81B65DF44E4CD2F55838C2668C30D438

SHA256:

A05268767782B6A2211D37E35592ADE39B743BE7989B4124EE7B82F9FC8A8977

SSDEEP:

3:N8QgQyWW63dK:2QgQX3dK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes powershell execution policy (RemoteSigned)

      • ConvertMate.exe (PID: 4728)
    • Changes the autorun value in the registry

      • Mod Menu.exe (PID: 920)
  • SUSPICIOUS

    • Searches for installed software

      • ConvertMate.exe (PID: 4728)
    • Creates a software uninstall entry

      • ConvertMate.exe (PID: 4728)
    • Reads the date of Windows installation

      • ConvertMate.exe (PID: 4728)
    • SQL CE related mutex has been found

      • ConvertMate.exe (PID: 4728)
    • The process executes Powershell scripts

      • ConvertMate.exe (PID: 4728)
    • Reads security settings of Internet Explorer

      • ConvertMate.exe (PID: 4728)
      • Convert Mate.exe (PID: 8916)
      • ShellExperienceHost.exe (PID: 4220)
      • Mod Menu.exe (PID: 920)
    • Process drops legitimate windows executable

      • ConvertMate.exe (PID: 4728)
      • Mod Menu.exe (PID: 920)
    • Executable content was dropped or overwritten

      • ConvertMate.exe (PID: 4728)
      • Mod Menu.exe (PID: 920)
    • Gets path to any of the special folders (POWERSHELL)

      • powershell.exe (PID: 4464)
    • Starts POWERSHELL.EXE for commands execution

      • ConvertMate.exe (PID: 4728)
    • Application launched itself

      • XModz Mod Menu.exe (PID: 9080)
  • INFO

    • Creates files or folders in the user directory

      • ConvertMate.exe (PID: 4728)
      • Mod Menu.exe (PID: 920)
      • XModz Mod Menu.exe (PID: 9080)
      • XModz Mod Menu.exe (PID: 4452)
    • Autorun file from Downloads

      • chrome.exe (PID: 5936)
      • chrome.exe (PID: 5868)
      • chrome.exe (PID: 8928)
      • chrome.exe (PID: 8856)
    • Reads the computer name

      • ConvertMate.exe (PID: 4728)
      • Convert Mate.exe (PID: 8916)
      • Mod Menu.exe (PID: 920)
      • ShellExperienceHost.exe (PID: 4220)
      • XModz Mod Menu.exe (PID: 9080)
      • XModz Mod Menu.exe (PID: 2780)
      • XModz Mod Menu.exe (PID: 4452)
      • Noxic.exe (PID: 4324)
    • Reads the machine GUID from the registry

      • ConvertMate.exe (PID: 4728)
      • Convert Mate.exe (PID: 8916)
      • XModz Mod Menu.exe (PID: 9080)
    • Disables trace logs

      • ConvertMate.exe (PID: 4728)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 5936)
      • chrome.exe (PID: 8920)
    • Checks supported languages

      • ConvertMate.exe (PID: 4728)
      • ShellExperienceHost.exe (PID: 4220)
      • Mod Menu.exe (PID: 920)
      • Convert Mate.exe (PID: 8916)
      • XModz Mod Menu.exe (PID: 9080)
      • XModz Mod Menu.exe (PID: 2780)
      • XModz Mod Menu.exe (PID: 4452)
      • XModz Mod Menu.exe (PID: 5756)
      • XModz Mod Menu.exe (PID: 8872)
      • Noxic.exe (PID: 4324)
    • Manual execution by a user

      • ConvertMate.exe (PID: 4728)
      • WinRAR.exe (PID: 7972)
      • Mod Menu.exe (PID: 920)
      • WinRAR.exe (PID: 9052)
      • Noxic.exe (PID: 4324)
    • Checks proxy server information

      • ConvertMate.exe (PID: 4728)
      • slui.exe (PID: 7144)
      • XModz Mod Menu.exe (PID: 9080)
    • Reads Environment values

      • ConvertMate.exe (PID: 4728)
      • XModz Mod Menu.exe (PID: 9080)
      • XModz Mod Menu.exe (PID: 5756)
    • Reads the software policy settings

      • ConvertMate.exe (PID: 4728)
      • slui.exe (PID: 7144)
      • XModz Mod Menu.exe (PID: 9080)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 4464)
    • Create files in a temporary directory

      • ConvertMate.exe (PID: 4728)
      • Mod Menu.exe (PID: 920)
      • XModz Mod Menu.exe (PID: 9080)
      • Noxic.exe (PID: 4324)
    • Creates files in the program directory

      • ConvertMate.exe (PID: 4728)
    • Process checks computer location settings

      • ConvertMate.exe (PID: 4728)
      • Mod Menu.exe (PID: 920)
      • XModz Mod Menu.exe (PID: 9080)
      • XModz Mod Menu.exe (PID: 5756)
      • XModz Mod Menu.exe (PID: 8872)
    • The sample compiled with english language support

      • chrome.exe (PID: 8920)
      • Mod Menu.exe (PID: 920)
    • Application launched itself

      • chrome.exe (PID: 8336)
      • chrome.exe (PID: 5936)
    • Reads product name

      • XModz Mod Menu.exe (PID: 9080)
      • XModz Mod Menu.exe (PID: 5756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
518
Monitored processes
375
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
132"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=8820 --field-trial-handle=1924,i,13908320013041301812,17036960602718486746,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
232"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=13356 --field-trial-handle=1924,i,13908320013041301812,17036960602718486746,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
236"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=8500 --field-trial-handle=1924,i,13908320013041301812,17036960602718486746,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
444"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=9060 --field-trial-handle=1924,i,13908320013041301812,17036960602718486746,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
496"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=9120 --field-trial-handle=1924,i,13908320013041301812,17036960602718486746,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
496"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=12340 --field-trial-handle=1924,i,13908320013041301812,17036960602718486746,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
540"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=8824 --field-trial-handle=1924,i,13908320013041301812,17036960602718486746,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
540"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=8476 --field-trial-handle=1924,i,13908320013041301812,17036960602718486746,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
540"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=8340 --field-trial-handle=1924,i,13908320013041301812,17036960602718486746,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
720"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=9632 --field-trial-handle=1924,i,13908320013041301812,17036960602718486746,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
48 833
Read events
48 552
Write events
211
Delete events
70

Modification events

(PID) Process:(5936) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(5936) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(5936) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(5936) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(5936) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(5868) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
0100000000000000663D08138AA4DB01
(PID) Process:(4728) ConvertMate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConvertMate_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4728) ConvertMate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConvertMate_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4728) ConvertMate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConvertMate_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(4728) ConvertMate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConvertMate_RASAPI32
Operation:writeName:FileTracingMask
Value:
Executable files
43
Suspicious files
990
Text files
354
Unknown types
2

Dropped files

PID
Process
Filename
Type
5936chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF10ce7d.TMP
MD5:
SHA256:
5936chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
5936chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF10ce8d.TMP
MD5:
SHA256:
5936chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
5936chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF10ce8d.TMP
MD5:
SHA256:
5936chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
5936chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF10ce9c.TMP
MD5:
SHA256:
5936chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
5936chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF10ce9c.TMP
MD5:
SHA256:
5936chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
501
DNS requests
650
Threats
17

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5868
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
5868
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
7344
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/V3P1l2hLvLw_7/7_all_sslErrorAssistant.crx3
US
binary
1.09 Kb
whitelisted
7344
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/V3P1l2hLvLw_7/7_all_sslErrorAssistant.crx3
US
binary
2.13 Kb
whitelisted
7344
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/V3P1l2hLvLw_7/7_all_sslErrorAssistant.crx3
US
compressed
2.06 Kb
whitelisted
7344
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac6mhlwypzipnufijdvfyhdgvt4q_67/khaoiebndkojlmppeemjhbpbandiljpe_67_win_kfegpqlp6gezs4ree2ol2br2ym.crx3
US
compressed
2.06 Kb
whitelisted
7344
svchost.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac6mhlwypzipnufijdvfyhdgvt4q_67/khaoiebndkojlmppeemjhbpbandiljpe_67_win_kfegpqlp6gezs4ree2ol2br2ym.crx3
US
binary
5.88 Kb
whitelisted
7344
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad7b4ekpxt66p7qmikviomfbfmjq_1273/efniojlnjndmcbiieegkicadnoecjjef_1273_all_drbdpovkqgwwclsjgubiyepbja.crx3
US
17.7 Kb
whitelisted
7344
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad7b4ekpxt66p7qmikviomfbfmjq_1273/efniojlnjndmcbiieegkicadnoecjjef_1273_all_drbdpovkqgwwclsjgubiyepbja.crx3
US
binary
42.6 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.51:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
3216
svchost.exe
20.10.31.115:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7208
chrome.exe
104.26.15.166:443
cheater.fun
CLOUDFLARENET
US
suspicious
239.255.255.250:1900
whitelisted
7208
chrome.exe
64.233.166.84:443
accounts.google.com
GOOGLE
US
whitelisted
7208
chrome.exe
142.250.186.98:443
securepubads.g.doubleclick.net
GOOGLE
US
whitelisted
7208
chrome.exe
65.109.72.77:443
ads.digitalcaramel.com
Hetzner Online GmbH
FI
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
  • 142.250.184.206
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.164.51
  • 2.16.164.106
  • 2.16.164.49
  • 2.16.164.120
  • 2.16.164.18
  • 2.16.164.114
whitelisted
client.wns.windows.com
  • 20.10.31.115
whitelisted
cheater.fun
  • 104.26.15.166
  • 104.26.14.166
  • 172.67.72.33
unknown
accounts.google.com
  • 64.233.166.84
whitelisted
securepubads.g.doubleclick.net
  • 142.250.186.98
whitelisted
ads.digitalcaramel.com
  • 65.109.72.77
unknown
pagead2.googlesyndication.com
  • 142.250.186.98
  • 216.58.206.34
whitelisted
fonts.googleapis.com
  • 142.250.185.106
  • 142.250.181.234
whitelisted

Threats

PID
Process
Class
Message
7208
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
7208
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
7208
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
7208
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
7208
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7208
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7208
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7208
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
7208
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
7208
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
No debug info