| URL: | https://t.yesware.com/tt/0918991552324202c150158080524829c9678952/a09774190501485476243c809c242024/9854762f35e6789edb5004aa91899155/mud.montebravocontabilidade.com/edgar.gutierrez@bussie.com.co |
| Full analysis: | https://app.any.run/tasks/198776a0-4218-4610-9cdf-4cdb2e9c1c1c |
| Verdict: | Malicious activity |
| Analysis date: | August 11, 2023, 14:20:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | CA54CC153C252B7B1A1F6B4FB024AE81 |
| SHA1: | 78F01A86E35F5593F4C8F761293AEE13C30F9189 |
| SHA256: | ACF7341241430FFE7CC6ADBF3589052974091ACB0CCD9031B9A6A30E96BB06B4 |
| SSDEEP: | 3:N8DeAyKhROc1qhVulCRKyVeFVSSTX1tscS0bL2Tkt1Em9SIpRdlDHGA0+2EhXAVT:2qATq2CV8a2ts83ttFfjX0pDNLd |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 948 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1136 --field-trial-handle=1100,i,14015607460840265836,2044124432328569903,131072 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1424 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1668 --field-trial-handle=1156,i,4072809598112730257,18208604070746370244,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1468 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1452 --field-trial-handle=1100,i,14015607460840265836,2044124432328569903,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1796 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1416 --field-trial-handle=1100,i,14015607460840265836,2044124432328569903,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1804 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=1724 --field-trial-handle=1100,i,14015607460840265836,2044124432328569903,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1848 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4504 --field-trial-handle=1156,i,4072809598112730257,18208604070746370244,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2008 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3812 --field-trial-handle=1100,i,14015607460840265836,2044124432328569903,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2028 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=4048 --field-trial-handle=1156,i,4072809598112730257,18208604070746370244,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2040 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --profile-directory=Default | C:\Program Files\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2340 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1620 --field-trial-handle=1156,i,4072809598112730257,18208604070746370244,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3488) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3488) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3488) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3488) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3488) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3488) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 1 | |||
| (PID) Process: | (3488) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3488) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3488) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_installdate |
Value: 0 | |||
| (PID) Process: | (3488) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_enableddate |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3488 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RFfa9d3.TMP | — | |
MD5:— | SHA256:— | |||
| 3488 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3488 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RFfa9e3.TMP | text | |
MD5:CDCC923CEC2CD9228330551E6946A9C2 | SHA256:592F4750166BE662AA88728F9969537163FEC5C3E95E81537C8C6917F8D0929E | |||
| 3488 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old~RFfaca2.TMP | text | |
MD5:BB9548F35E841C9C11626E490F597944 | SHA256:0BAF506A4A0BB37DC50395F36A451B3EF3F6D883615B864A7B50F8D064AAD12D | |||
| 3488 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:9C016064A1F864C8140915D77CF3389A | SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787 | |||
| 3488 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:513218482935B0D388C0A990D868387A | SHA256:8E39CBAAF4AACC3A01AFA74EA8C30FB24FE69A22B8B30728AFB1614FD68809D9 | |||
| 3488 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RFfb0f7.TMP | — | |
MD5:— | SHA256:— | |||
| 3488 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3488 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\793fb895-60b9-436e-834d-e2a564cf872d.tmp | binary | |
MD5:5058F1AF8388633F609CADB75A75DC9D | SHA256:— | |||
| 3488 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:E91E138A25FD7E5BCA5E60111F39C91A | SHA256:B1F7E3537A31A4B847F862858E5D2581993CC9372F19ABF19EA2A9185FE42A4F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
868 | svchost.exe | HEAD | 200 | 152.199.19.161:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/f6826c01-0b71-45e6-a088-0fd0448b9004?P1=1692268145&P2=404&P3=2&P4=C9BcOEuvA76M1Jfd5BXqZrnrKqel3odHAam5dPwldwuSoeBSHqOM7BpeOFrIv6Nd7lap8rvqV9w6r0axTOu73Q%3d%3d | US | — | — | whitelisted |
2968 | msedge.exe | GET | 204 | 13.107.6.158:80 | http://edge-http.microsoft.com/captiveportal/generate_204 | US | — | — | whitelisted |
2364 | chrome.exe | GET | 204 | 216.58.206.35:80 | http://www.gstatic.com/generate_204 | US | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3284 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3488 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2364 | chrome.exe | 216.58.212.173:443 | accounts.google.com | GOOGLE | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2364 | chrome.exe | 151.101.2.137:443 | js-agent.newrelic.com | FASTLY | US | suspicious |
2364 | chrome.exe | 34.235.64.58:443 | t.yesware.com | AMAZON-AES | US | unknown |
2364 | chrome.exe | 162.247.243.29:443 | bam.nr-data.net | CLOUDFLARENET | US | suspicious |
2364 | chrome.exe | 103.153.183.192:443 | mud.montebravocontabilidade.com | SnTHostings | US | unknown |
2040 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
accounts.google.com |
| shared |
t.yesware.com |
| whitelisted |
js-agent.newrelic.com |
| whitelisted |
mud.montebravocontabilidade.com |
| unknown |
bam.nr-data.net |
| whitelisted |
www.google.com |
| malicious |
www.googleapis.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
ntp.msn.com |
| whitelisted |
config.edge.skype.com |
| malicious |
Process | Message |
|---|---|
chrome.exe | [0811/152205.872:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\f1d80553-1675-4a2d-ac88-404221ed5813: The system cannot find the file specified. (0x2)
|
chrome.exe | [0811/152205.873:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\f1d80553-1675-4a2d-ac88-404221ed5813: The system cannot find the file specified. (0x2)
|
chrome.exe | [0811/152205.873:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\f1d80553-1675-4a2d-ac88-404221ed5813: The system cannot find the file specified. (0x2)
|
chrome.exe | [0811/152237.272:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\f1d80553-1675-4a2d-ac88-404221ed5813: The system cannot find the file specified. (0x2)
|
chrome.exe | [0811/152237.290:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\f1d80553-1675-4a2d-ac88-404221ed5813: The system cannot find the file specified. (0x2)
|
chrome.exe | [0811/152237.290:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\83e115b3-f1ab-4357-9433-45f6e64d3992: The system cannot find the file specified. (0x2)
|
chrome.exe | [0811/152237.291:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\f1d80553-1675-4a2d-ac88-404221ed5813: The system cannot find the file specified. (0x2)
|
chrome.exe | [0811/152237.291:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\83e115b3-f1ab-4357-9433-45f6e64d3992: The system cannot find the file specified. (0x2)
|
chrome.exe | [0811/152237.292:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\f1d80553-1675-4a2d-ac88-404221ed5813: The system cannot find the file specified. (0x2)
|
chrome.exe | [0811/152237.292:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\83e115b3-f1ab-4357-9433-45f6e64d3992: The system cannot find the file specified. (0x2)
|