| URL: | www.intercambiosvirtuales.org | 
| Full analysis: | https://app.any.run/tasks/a8ca0505-34f8-4f81-84ef-a7270b0f42a8 | 
| Verdict: | Malicious activity | 
| Analysis date: | November 16, 2023, 23:39:29 | 
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) | 
| Indicators: | |
| MD5: | 73739E98208F1E72069952FD757750E1 | 
| SHA1: | 7AD7F68EE32BC576A19FBAD029EBFDE7BEAD8807 | 
| SHA256: | ABF8946D5C3425D197CC58F5F1AEB025F2F8CFAF8D57630604948CB087B19CAE | 
| SSDEEP: | 3:EGRAWEICCROWLD:TRADNC7f | 
PID  | CMD  | Path  | Indicators  | Parent process  | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2888 --field-trial-handle=1136,i,1708784135954535347,6810440975275620385,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 536 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=34 --mojo-platform-channel-handle=3040 --field-trial-handle=1136,i,1708784135954535347,6810440975275620385,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 556 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=3780 --field-trial-handle=1136,i,1708784135954535347,6810440975275620385,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 564 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=42 --mojo-platform-channel-handle=4516 --field-trial-handle=1136,i,1708784135954535347,6810440975275620385,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 644 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=60 --mojo-platform-channel-handle=856 --field-trial-handle=1136,i,1708784135954535347,6810440975275620385,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 756 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=2152 --field-trial-handle=1136,i,1708784135954535347,6810440975275620385,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 788 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3676 --field-trial-handle=1136,i,1708784135954535347,6810440975275620385,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 844 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=66 --mojo-platform-channel-handle=5580 --field-trial-handle=1136,i,1708784135954535347,6810440975275620385,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 1088 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3944 --field-trial-handle=1136,i,1708784135954535347,6810440975275620385,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| 1228 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=57 --mojo-platform-channel-handle=5280 --field-trial-handle=1136,i,1708784135954535347,6810440975275620385,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
  | |||||||||||||||
| (PID) Process: | (3484) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon | 
| Operation: | write | Name: | failed_count | 
Value: 0  | |||
| (PID) Process: | (3484) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon | 
| Operation: | write | Name: | state | 
Value: 1  | |||
| (PID) Process: | (3484) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty | 
| Operation: | write | Name: | StatusCodes | 
Value: 01000000  | |||
| (PID) Process: | (3484) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon | 
| Operation: | write | Name: | state | 
Value: 2  | |||
| (PID) Process: | (3484) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} | 
| Operation: | write | Name: | dr | 
Value: 1  | |||
| (PID) Process: | (3484) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics | 
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly | 
Value: 1  | |||
| (PID) Process: | (3484) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome | 
| Operation: | write | Name: | UsageStatsInSample | 
Value: 0  | |||
| (PID) Process: | (3484) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} | 
| Operation: | write | Name: | usagestats | 
Value: 0  | |||
| (PID) Process: | (3484) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} | 
| Operation: | write | Name: | metricsid_installdate | 
Value: 0  | |||
| (PID) Process: | (3484) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} | 
| Operation: | write | Name: | metricsid_enableddate | 
Value: 0  | |||
PID  | Process  | Filename  | Type  | |
|---|---|---|---|---|
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF169782.TMP | — | |
MD5:—  | SHA256:—  | |||
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:—  | SHA256:—  | |||
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:9C016064A1F864C8140915D77CF3389A  | SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787  | |||
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:9F941EA08DBDCA2EB3CFA1DBBBA6F5DC  | SHA256:127F71DF0D2AD895D4F293E62284D85971AE047CA15F90B87BF6335898B0B655  | |||
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF1697c0.TMP | text | |
MD5:CDCC923CEC2CD9228330551E6946A9C2  | SHA256:592F4750166BE662AA88728F9969537163FEC5C3E95E81537C8C6917F8D0929E  | |||
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old | text | |
MD5:B806171F9E7C87423595645872D869B0  | SHA256:851A8D533BEBF6A69C5518375396E97463302C1E2031D04F8EB5851C5C82CEB9  | |||
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF169d3e.TMP | — | |
MD5:—  | SHA256:—  | |||
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:—  | SHA256:—  | |||
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF169956.TMP | text | |
MD5:561161B0FF5BCA89BF47F8AC972A7499  | SHA256:ECCA5CCFA0BEED7581B39FCE03D0FD3B694DF0F92BFFF780F702118AD51FC17D  | |||
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF1699d3.TMP | text | |
MD5:99EC94B2503FAD33EDAF99779EBA5BC8  | SHA256:DC554AB7EDCAD375F39ED106CA1EF9A89FB8D9063A4D08F377F2C80D66799D7E  | |||
PID  | Process  | Method  | HTTP Code  | IP  | URL  | CN  | Type  | Size  | Reputation  | 
|---|---|---|---|---|---|---|---|---|---|
868  | svchost.exe  | HEAD  | 200  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3  | unknown  |  —   | —  | unknown  | 
868  | svchost.exe  | GET  | 200  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/AJqZYiqGvCtix64S2N84g-M_2020.11.2.164946/EWvH2e-LS80S29cxzuTfRA  | unknown  | binary  | 111 Kb  | unknown  | 
868  | svchost.exe  | HEAD  | 200  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/AJqZYiqGvCtix64S2N84g-M_2020.11.2.164946/EWvH2e-LS80S29cxzuTfRA  | unknown  | binary  | 178 Kb  | unknown  | 
868  | svchost.exe  | GET  | 206  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3  | unknown  | binary  | 45.6 Kb  | unknown  | 
868  | svchost.exe  | HEAD  | 200  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adtp63xadzqu6yysjolme33hjxoq_20220505/dhlpobdgcjafebgbbhjdnapejmpkgiie_20220505_all_adfdqqtvlhuhhtrt6irlkpynghca.crx3  | unknown  | binary  | 111 Kb  | unknown  | 
3516  | chrome.exe  | GET  | 301  | 188.114.97.3:80  | http://www.intercambiosvirtuales.org/  | unknown  | html  | 185 b  | unknown  | 
868  | svchost.exe  | GET  | 200  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad7a7t3vkmd2z6rufl24oh5levra_120.0.6046.0/jamhcnnkihinmdlkakkaopbjbbcngflc_120.0.6046.0_all_iyckh6iuywf7jqrenech6qrzkm.crx3  | unknown  | binary  | 1.06 Mb  | unknown  | 
868  | svchost.exe  | HEAD  | 200  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adjf6wcl4cbrlb2cluyt7lfamsaa_2023.10.13.1141/ggkkehgbnfjpeggfpleeakpidbkibbmn_2023.10.13.1141_all_b2zmlptxrzxlqwbi22z542vqne.crx3  | unknown  | binary  | 1.06 Mb  | unknown  | 
868  | svchost.exe  | HEAD  | 200  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad7a7t3vkmd2z6rufl24oh5levra_120.0.6046.0/jamhcnnkihinmdlkakkaopbjbbcngflc_120.0.6046.0_all_iyckh6iuywf7jqrenech6qrzkm.crx3  | unknown  | binary  | 136 Kb  | unknown  | 
868  | svchost.exe  | HEAD  | 200  | 34.104.35.123:80  | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3  | unknown  | binary  | 429 b  | unknown  | 
PID  | Process  | IP  | Domain  | ASN  | CN  | Reputation  | 
|---|---|---|---|---|---|---|
3516  | chrome.exe  | 188.114.96.3:443  | www.intercambiosvirtuales.org  | —  | —  | unknown  | 
3516  | chrome.exe  | 142.250.185.109:443  | accounts.google.com  | GOOGLE  | US  | unknown  | 
3484  | chrome.exe  | 239.255.255.250:1900  | —  | —  | —  | whitelisted  | 
3516  | chrome.exe  | 188.114.97.3:80  | www.intercambiosvirtuales.org  | CLOUDFLARENET  | NL  | unknown  | 
3516  | chrome.exe  | 151.101.130.137:443  | code.jquery.com  | FASTLY  | US  | unknown  | 
3516  | chrome.exe  | 35.190.80.1:443  | a.nel.cloudflare.com  | —  | —  | unknown  | 
3516  | chrome.exe  | 172.217.16.193:443  | blogger.googleusercontent.com  | GOOGLE  | US  | whitelisted  | 
3516  | chrome.exe  | 208.93.230.26:443  | st.chatango.com  | CHATANGO  | US  | unknown  | 
3516  | chrome.exe  | 146.75.116.193:443  | i.imgur.com  | FASTLY  | US  | unknown  | 
3516  | chrome.exe  | 104.26.3.189:443  | s.reembed.com  | CLOUDFLARENET  | US  | unknown  | 
Domain  | IP  | Reputation  | 
|---|---|---|
www.intercambiosvirtuales.org  | 
  | unknown  | 
accounts.google.com  | 
  | shared  | 
code.jquery.com  | 
  | whitelisted  | 
a.nel.cloudflare.com  | 
  | whitelisted  | 
blogger.googleusercontent.com  | 
  | whitelisted  | 
i.imgur.com  | 
  | shared  | 
st.chatango.com  | 
  | whitelisted  | 
s.reembed.com  | 
  | unknown  | 
connect.facebook.net  | 
  | whitelisted  | 
content-autofill.googleapis.com  | 
  | whitelisted  | 
PID  | Process  | Class  | Message  | 
|---|---|---|---|
3516  | chrome.exe  | Not Suspicious Traffic  | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)  |