| URL: | http://crackstreams.ga/mmastreams/watch-ufc-243-whittaker-vs-adesanya/ |
| Full analysis: | https://app.any.run/tasks/be5dc6f1-326d-4ec9-ab3b-6b0c0385ad8e |
| Verdict: | Malicious activity |
| Analysis date: | October 06, 2019, 02:34:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | EC234206FBAD11682952E5A159D5E571 |
| SHA1: | 99BB17AA2B02A25D816A1585D2737CC93FB8C634 |
| SHA256: | A30A6415BC5C0FACBD53603679FF471DC3B864694C168FBB4D01AD8705231301 |
| SSDEEP: | 3:N1KdXnFNWChyXwvNQivX2ozL:CThyAOivtP |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 956 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,3597726404359042726,2487024350613296123,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=3131563549312840957 --mojo-platform-channel-handle=4284 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2184 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,3597726404359042726,2487024350613296123,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=1554813782564561812 --mojo-platform-channel-handle=4828 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2300 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,3597726404359042726,2487024350613296123,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=1466896009191053137 --mojo-platform-channel-handle=1608 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2536 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1020,3597726404359042726,2487024350613296123,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=7995426584210802340 --mojo-platform-channel-handle=4512 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2552 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,3597726404359042726,2487024350613296123,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8328229411712245002 --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3284 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2560 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,3597726404359042726,2487024350613296123,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=3761476157339509578 --mojo-platform-channel-handle=4496 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2568 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,3597726404359042726,2487024350613296123,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17854399233170179605 --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3272 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2684 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,3597726404359042726,2487024350613296123,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4770727100898141567 --renderer-client-id=24 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5068 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2688 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,3597726404359042726,2487024350613296123,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=9336033945331255877 --mojo-platform-channel-handle=5272 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2764 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,3597726404359042726,2487024350613296123,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=14393417585473579143 --mojo-platform-channel-handle=4752 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (2952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 1512-13197841398593750 |
Value: 0 | |||
| (PID) Process: | (2952) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (2952) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 2952-13214802875067875 |
Value: 259 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\1281e1aa-4a96-4f0d-8abc-5d00d06936f7.tmp | — | |
MD5:— | SHA256:— | |||
| 2952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF114ec9.TMP | text | |
MD5:— | SHA256:— | |||
| 2952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF114ec9.TMP | text | |
MD5:— | SHA256:— | |||
| 2952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
| 2952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2952 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2300 | chrome.exe | GET | 204 | 35.190.64.167:80 | http://onclickmega.com/script/suurl.php?r=2524319&cbrandom=0.9140630841896649&cbiframe=0&cbWidth=1280&cbHeight=572&cbtitle=UFC%20243%20Live%20%7C%20MMA%20Streams%20%7C%20UFC%20streams%20%7C%20MMAStreams&cbref=&cbdescription=mmastreams%20reddit%20-%20Watch%20UFC%20243%3A%20Whittaker%20vs.%20Adesanya%20stream%20free%20HD.%20Come%20and%20watch%20free%20mma%20streams%20ppv.&cbkeywords=live%20MMA%20streams%2C%20covington%20vs%20lawler%2C%20covington%2C%20lawler%2C%20ufc%20fight%20night%20sacramento%2C%20watch%20covington%20vs%20lawler%20live%2C%20MMA%20stream%2C%20watch%20andrade%20vs%20zhang%20HD%2C%20watch%20andrade%20vs%20zhang%2C%20live%20free%2C%20covington%20vs%20lawler%2C%20ufc%20240%2C%20MMA%20video%2C%20mmastreams%2C%20reddit%2C%20ufc%20243%20live&cbcdn=moneymakercdn.com | US | — | — | whitelisted |
2300 | chrome.exe | GET | 200 | 104.18.41.85:80 | http://w.24timezones.com/l.js | US | text | 7.49 Kb | suspicious |
2300 | chrome.exe | GET | 200 | 35.201.115.74:80 | http://moneymakercdn.com/script/compatibility.js | US | text | 11.7 Kb | suspicious |
2300 | chrome.exe | GET | 200 | 34.102.216.250:80 | http://dada.warriorz.xyz/hls/ufc.m3u8 | US | text | 1.54 Kb | suspicious |
2300 | chrome.exe | GET | 200 | 35.201.115.74:80 | http://moneymakercdn.com/script/chrome.js | US | text | 18.5 Kb | suspicious |
2300 | chrome.exe | GET | 200 | 208.93.230.28:80 | http://st.chatango.com/js/gz/emb.js | US | text | 24.0 Kb | whitelisted |
2300 | chrome.exe | GET | 200 | 34.102.216.250:80 | http://dada.warriorz.xyz/hls/ufc-100.ts | US | ts | 1.05 Mb | suspicious |
2300 | chrome.exe | GET | 200 | 208.93.230.28:80 | http://st.chatango.com/js/gz/r0915191710/CollapsedViewModule.js | US | text | 3.42 Kb | whitelisted |
2300 | chrome.exe | GET | 200 | 208.93.230.28:80 | http://st.chatango.com/cfg/nc/r.json?9508110020000231280663907 | US | text | 20 b | whitelisted |
2300 | chrome.exe | GET | 304 | 34.102.216.250:80 | http://dada.warriorz.xyz/hls/ufc.m3u8 | US | text | 1.54 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2300 | chrome.exe | 35.201.115.74:80 | moneymakercdn.com | Google Inc. | US | whitelisted |
2300 | chrome.exe | 172.217.18.163:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
2300 | chrome.exe | 104.27.132.2:80 | crackstreams.ga | Cloudflare Inc | US | unknown |
2300 | chrome.exe | 172.64.196.26:80 | crackstreams.com | Cloudflare Inc | US | unknown |
2300 | chrome.exe | 35.190.42.176:80 | uptimecdn.com | Google Inc. | US | whitelisted |
2300 | chrome.exe | 23.210.248.44:443 | s7.addthis.com | Akamai International B.V. | NL | whitelisted |
2300 | chrome.exe | 35.190.8.27:80 | onclicksuper.com | Google Inc. | US | whitelisted |
2300 | chrome.exe | 104.18.54.71:80 | ufpcdn.com | Cloudflare Inc | US | shared |
2300 | chrome.exe | 35.190.64.167:80 | onclickmega.com | Google Inc. | US | whitelisted |
2300 | chrome.exe | 172.217.16.206:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
crackstreams.ga |
| suspicious |
accounts.google.com |
| shared |
www.googletagmanager.com |
| whitelisted |
pagead2.googlesyndication.com |
| whitelisted |
s7.addthis.com |
| whitelisted |
moneymakercdn.com |
| suspicious |
uptimecdn.com |
| whitelisted |
st.chatango.com |
| whitelisted |
w.24timezones.com |
| suspicious |
PID | Process | Class | Message |
|---|---|---|---|
1060 | svchost.exe | Potentially Bad Traffic | ET INFO DNS Query for Suspicious .ga Domain |
2300 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2300 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2300 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2300 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2300 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2300 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2300 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2300 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2300 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |