URL:

http://scanner.openportstats.com

Full analysis: https://app.any.run/tasks/949407e3-7fde-47de-ad5d-b3ccc2f372c9
Verdict: Malicious activity
Analysis date: November 23, 2020, 02:48:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

FE392605AB3D54C3398077BDA21CADF3

SHA1:

19DC37353A95D734796D7CAFB59F4ECB3185D6D7

SHA256:

AC1CF25953EF6246B41102F96AFDB351CAB582F750E8E14A35A6F8C4EAFA3BCE

SSDEEP:

3:N1KNGiLAX+vKLGT:CUi0qKLGT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1168"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "http://scanner.openportstats.com"C:\Program Files\Google\Chrome\Application\chrome.exeexplorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
77
TCP/UDP connections
41
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
51.159.21.96:80
http://scanner.openportstats.com/
GB
html
3.59 Kb
malicious
GET
200
51.159.21.96:80
http://scanner.openportstats.com/css/extras.css
GB
text
5.20 Kb
malicious
GET
200
51.159.21.96:80
http://scanner.openportstats.com/js/jquery-min.js
GB
text
82.3 Kb
malicious
GET
200
51.159.21.96:80
http://scanner.openportstats.com/js/bootstrap.min.js
GB
text
47.8 Kb
malicious
GET
200
51.159.21.96:80
http://scanner.openportstats.com/js/popper.min.js
GB
text
18.5 Kb
malicious
GET
200
51.159.21.96:80
http://scanner.openportstats.com/js/owl.carousel.min.js
GB
text
14.5 Kb
malicious
GET
200
51.159.21.96:80
http://scanner.openportstats.com/js/jquery.countTo.js
GB
text
3.67 Kb
malicious
GET
200
51.159.21.96:80
http://scanner.openportstats.com/js/jquery.nav.js
GB
text
5.02 Kb
malicious
GET
200
51.159.21.96:80
http://scanner.openportstats.com/img/slider/bg-1.jpg
GB
image
303 Kb
malicious
GET
200
51.159.21.96:80
http://scanner.openportstats.com/img/logo.png
GB
image
6.96 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
216.58.212.173:443
accounts.google.com
Google Inc.
US
whitelisted
51.159.21.96:80
scanner.openportstats.com
GB
unknown
216.58.206.10:443
fonts.googleapis.com
Google Inc.
US
whitelisted
216.58.207.46:443
clients1.google.com
Google Inc.
US
whitelisted
172.217.23.131:443
ssl.gstatic.com
Google Inc.
US
whitelisted
216.58.212.131:443
fonts.gstatic.com
Google Inc.
US
whitelisted
172.217.18.3:443
www.google.com.ua
Google Inc.
US
whitelisted
172.217.22.3:443
www.gstatic.com
Google Inc.
US
whitelisted
64.233.180.138:443
apis.google.com
Google Inc.
US
unknown
216.58.207.78:443
ogs.google.com.ua
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
scanner.openportstats.com
  • 51.159.21.96
unknown
accounts.google.com
  • 216.58.212.173
shared
fonts.googleapis.com
  • 216.58.206.10
whitelisted
fonts.gstatic.com
  • 216.58.212.131
whitelisted
clients1.google.com
  • 216.58.207.46
  • 172.217.195.100
  • 172.217.195.102
  • 172.217.195.139
  • 172.217.195.113
  • 172.217.195.101
  • 172.217.195.138
whitelisted
ssl.gstatic.com
  • 172.217.23.131
whitelisted
www.google.com.ua
  • 172.217.18.3
whitelisted
www.gstatic.com
  • 172.217.22.3
whitelisted
apis.google.com
  • 64.233.180.138
  • 64.233.180.139
  • 64.233.180.102
  • 64.233.180.101
  • 64.233.180.100
  • 64.233.180.113
whitelisted
ogs.google.com.ua
  • 216.58.207.78
whitelisted

Threats

No threats detected
No debug info