| URL: | samradapps.com |
| Full analysis: | https://app.any.run/tasks/6bbaeeae-6f53-4bc0-ac4e-25bac82bb243 |
| Verdict: | Malicious activity |
| Analysis date: | December 18, 2023, 11:40:03 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 28356F5BFD80DA44F7E1676A68BFD566 |
| SHA1: | 7AE0B94170AE2DE0F3BFA86910AC7870854DBBC7 |
| SHA256: | A0EABD422A0192862D6D12D4485B81CBB635C6F77E35DC06B6EA644A0781CEAC |
| SSDEEP: | 3:OECWZI:JZI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "samradapps.com" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 668 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1148 --field-trial-handle=1180,i,14642096497007851246,2301061880021918935,131072 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 680 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --disable-quic --mojo-platform-channel-handle=1408 --field-trial-handle=1180,i,14642096497007851246,2301061880021918935,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 712 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2020 --field-trial-handle=1180,i,14642096497007851246,2301061880021918935,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 784 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1264 --field-trial-handle=1180,i,14642096497007851246,2301061880021918935,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 840 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=4284 --field-trial-handle=1180,i,14642096497007851246,2301061880021918935,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 880 | "C:\Users\admin\AppData\Local\Temp\nsk88E3.tmp\SWUpdaterSetup.exe" /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1&experiments=v161Xw51btB%3don%7cFri%2c%201%20Mar%202024%2000%3a00%3a00%20%2b0300" | C:\Users\admin\AppData\Local\Temp\nsk88E3.tmp\SWUpdaterSetup.exe | — | Wave Browser.exe | |||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Setup Exit code: 2147747849 Version: 1.3.133.0 Modules
| |||||||||||||||
| 920 | "C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /handoff "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1&experiments=v161Xw51btB%3don%7cFri%2c%201%20Mar%202024%2000%3a00%3a00%20%2b0300" /installsource otherinstallcmd /sessionid "{7F7E4879-F1AC-4227-8915-2456665053BF}" | C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe | — | SWUpdater.exe | |||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Exit code: 2147747849 Version: 1.3.133.0 Modules
| |||||||||||||||
| 996 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=1404 --field-trial-handle=1180,i,14642096497007851246,2301061880021918935,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1192 | "C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJTV1VwZGF0ZXIiIHVwZGF0ZXJ2ZXJzaW9uPSIxLjMuMTMzLjAiIHNoZWxsX3ZlcnNpb249IjEuMy4xMzMuMCIgaXNtYWNoaW5lPSIwIiBzZXNzaW9uaWQ9Ins3RjdFNDg3OS1GMUFDLTQyMjctODkxNS0yNDU2NjY1MDUzQkZ9IiB1c2VyaWQ9Ins2MmU3OWUwNS1lOTEyLTQ4MTEtYmU4NC1iZWYwM2NkNDFhNTN9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHJlcXVlc3RpZD0iezU2NkY4NkI3LTFFRkMtNDAxMC05ODAwLUZEOUQ1OEU1RkEwOH0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgcGh5c21lbW9yeT0iMyIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iNi4xLjc2MDEuMjQ1NDYiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0ie0Y2RjYwQUNFLTcxQUQtNDYxMC04MEQ0LTkyNTM3MjlGQjRCN30iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xMzMuMCIgbGFuZz0iZW4iIGJyYW5kPSIiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjM2MiIvPjwvYXBwPjwvcmVxdWVzdD4 | C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe | SWUpdater.exe | ||||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Exit code: 0 Version: 1.3.133.0 Modules
| |||||||||||||||
| (PID) Process: | (116) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (116) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (116) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (116) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (116) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (116) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 1 | |||
| (PID) Process: | (116) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (116) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (116) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_installdate |
Value: 0 | |||
| (PID) Process: | (116) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_enableddate |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 116 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RFe125b.TMP | — | |
MD5:— | SHA256:— | |||
| 116 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 116 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:9F941EA08DBDCA2EB3CFA1DBBBA6F5DC | SHA256:127F71DF0D2AD895D4F293E62284D85971AE047CA15F90B87BF6335898B0B655 | |||
| 116 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:358570F689377CE6838812643E03734B | SHA256:5B41FCC2E1A843AEAB9437B06E27B798870FF10D86A51B163BF48862BCD32590 | |||
| 116 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Variations | binary | |
MD5:961E3604F228B0D10541EBF921500C86 | SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED | |||
| 116 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RFe1420.TMP | text | |
MD5:C383FD120B14BB0E98E99C1BCC9B43F6 | SHA256:56A3A5EACBD28BEE1CF8C1D0052321A5C27EE858BEF7B2FA1DE20806A0823CC1 | |||
| 116 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RFe16df.TMP | — | |
MD5:— | SHA256:— | |||
| 116 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 116 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:9C016064A1F864C8140915D77CF3389A | SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787 | |||
| 116 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RFe150a.TMP | text | |
MD5:8593E82FF8753DC10267243C51E8A91B | SHA256:FE9EE2D77D9EB5CBA707EDBCB7F1ABAA83418CDB66D66835B4B9A1B6CC5CC34F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
784 | chrome.exe | GET | 200 | 198.185.159.145:80 | http://samradapps.com/ | unknown | html | 27.4 Kb | unknown |
784 | chrome.exe | GET | 200 | 151.101.0.237:80 | http://assets.squarespace.com/universal/styles-compressed/slide-normalize-f3e05d707a08546a77c65-min.en-US.css | unknown | text | 908 b | unknown |
784 | chrome.exe | GET | 200 | 151.101.0.237:80 | http://assets.squarespace.com/universal/styles-compressed/slides-7fd4392cd1d89561c45b-min.en-US.css | unknown | text | 5.50 Kb | unknown |
784 | chrome.exe | GET | 200 | 184.24.77.156:80 | http://use.typekit.net/ik/fq0x9qGrL5bJMg8Cwn3-p8WJCasi-gbBK5aqNX98jQqfe0q2f4e6pUJ6wRMU5QwXFmvuweI35QIkFe9XjRMtwAZcZcja5esRjRq-Rbw7OcBRiA8XpWFR-emqiAUTdcS0jhNlOfG0jAFu-WsoShFGZAsude80Zko0ZWbCHKoySkolZP37O1FydWm8dfukjAsy-hNh-WsEO1FUiABkZWF3jAF8OcFzdP37O1FUiABkZWF3jAF8ShFGZAsude80ZkoRdhXCjAFu-WsoShFGZAsude80ZkoRdhXCjAFu-WsoShFGZAsude80Zko0ZWbCjWw0dA9CdeNRjAUGdaFXOYFydW4yZeB3SYw0jhNlOYFydWm8dfukjAsy-hNh-WsEO1FUiABkZWF3jAF8OcFzdPUDSWmyScmDSeBRZWFR-emqiAUTdcS0jhNlOYiaikoyjamTiY8Djhy8ZYmC-Ao1OcFzdPUaiaS0jAFu-WsoShFGZAsude80Zko0ZWbCiaiaOcBDOcu8OYiaikoDjAukjAsySYgDOcFzdPUaiaS0ShBliAmCOW4yZeBndaZTiYG0SaBujW48Sagyjh90jhNlOYiaikoDSWmyScmDSeBRZWFR-emqiAUTdcS0jhNlJ68ciWsuScIlSYb7fbKImsMMeMb6MKG4fVN9IMMjgPMfH6qJym9bMg65JMHbMZ210T9e.js | unknown | text | 6.55 Kb | unknown |
784 | chrome.exe | GET | — | 151.101.0.237:80 | http://assets.squarespace.com/@sqs/polyfiller/1.6/modern.js | unknown | — | — | unknown |
784 | chrome.exe | GET | — | 151.101.0.237:80 | http://assets.squarespace.com/universal/scripts-compressed/extract-css-runtime-52718e7f4fcc1d610f17-min.en-US.js | unknown | — | — | unknown |
784 | chrome.exe | GET | — | 151.101.0.237:80 | http://assets.squarespace.com/universal/scripts-compressed/extract-css-moment-js-vendor-f36b6dc9867ad0b8d0a8-min.en-US.js | unknown | — | — | unknown |
784 | chrome.exe | GET | 200 | 151.101.0.237:80 | http://assets.squarespace.com/universal/scripts-compressed/slides-cb8a4a13a25c821cebf0-min.en-US.js | unknown | compressed | 41.4 Kb | unknown |
784 | chrome.exe | GET | — | 151.101.0.237:80 | http://assets.squarespace.com/universal/scripts-compressed/performance-b37c73015d73b8ed459e-min.en-US.js | unknown | — | — | unknown |
784 | chrome.exe | GET | 200 | 151.101.0.237:80 | http://assets.squarespace.com/universal/scripts-compressed/cldr-resource-pack-a682f7ad337741eb05d6-min.en-US.js | unknown | compressed | 24.3 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
116 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
784 | chrome.exe | 173.194.76.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
784 | chrome.exe | 198.185.159.145:80 | samradapps.com | SQUARESPACE | US | unknown |
784 | chrome.exe | 151.101.0.237:80 | assets.squarespace.com | FASTLY | US | unknown |
784 | chrome.exe | 184.24.77.156:80 | use.typekit.net | Akamai International B.V. | DE | unknown |
784 | chrome.exe | 151.101.0.238:443 | images.squarespace-cdn.com | FASTLY | US | unknown |
784 | chrome.exe | 142.250.186.34:443 | pagead2.googlesyndication.com | GOOGLE | US | unknown |
784 | chrome.exe | 184.24.77.156:443 | use.typekit.net | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
accounts.google.com |
| shared |
samradapps.com |
| unknown |
assets.squarespace.com |
| whitelisted |
use.typekit.net |
| whitelisted |
images.squarespace-cdn.com |
| whitelisted |
pagead2.googlesyndication.com |
| whitelisted |
www.youtube.com |
| whitelisted |
googleads.g.doubleclick.net |
| whitelisted |
static1.squarespace.com |
| whitelisted |
p.typekit.net |
| shared |