| URL: | http://m1.nsimg.net |
| Full analysis: | https://app.any.run/tasks/3d35fbb6-391a-475f-8d4f-db5e1ba7c31c |
| Verdict: | Malicious activity |
| Analysis date: | May 15, 2019, 13:05:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | B928623BF3536F133422CD57D03EE7C6 |
| SHA1: | 03420BC789506D5C9145C22FAF98D88F1B1ECB92 |
| SHA256: | B2A7D3A2681898668691399B6EDDA799B5E7506C7D47265AD5A649EE69BE00B1 |
| SSDEEP: | 3:N1KT4L//ARn:Cs/IR |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 636 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=960,879739905061943554,18376928256344750665,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=13447318998880241700 --mojo-platform-channel-handle=3908 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1096 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=960,879739905061943554,18376928256344750665,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=3382997987073479603 --mojo-platform-channel-handle=3868 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1160 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=960,879739905061943554,18376928256344750665,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=7820624178678114426 --mojo-platform-channel-handle=3880 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1252 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=960,879739905061943554,18376928256344750665,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=10236934788391745923 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=10236934788391745923 --renderer-client-id=23 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5272 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1412 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=960,879739905061943554,18376928256344750665,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=4127943379339358697 --mojo-platform-channel-handle=3692 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1512 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=960,879739905061943554,18376928256344750665,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=5284465911828584605 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5284465911828584605 --renderer-client-id=21 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4724 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1680 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=960,879739905061943554,18376928256344750665,131072 --enable-features=PasswordImport --service-pipe-token=7240104288866590894 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7240104288866590894 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2016 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1900 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=960,879739905061943554,18376928256344750665,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=10883491838056767483 --mojo-platform-channel-handle=3828 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 2124 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=960,879739905061943554,18376928256344750665,131072 --enable-features=PasswordImport --service-pipe-token=13326005839914048453 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=13326005839914048453 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2040 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 2312 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=960,879739905061943554,18376928256344750665,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=6283486832073692789 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6283486832073692789 --renderer-client-id=16 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2732 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (3160) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 3660-13202399156298750 |
Value: 259 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3488-13197474229333984 |
Value: 0 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3660-13202399156298750 |
Value: 259 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0 | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_2 | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_3 | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\c1a2eefa-3fde-41cf-b3d9-571036810192.tmp | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\index | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_0 | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000018.dbtmp | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3660 | chrome.exe | GET | 200 | 173.194.183.103:80 | http://r2---sn-aigl6nek.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvMjJlQUFXRC12Ny1ldUFnMXF3SDlXZDlFZw/7319.128.0.1_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&mip=194.187.251.125&mm=28&mn=sn-aigl6nek&ms=nvh&mt=1557925472&mv=m&pl=24&shardbypass=yes | US | crx | 842 Kb | whitelisted |
3660 | chrome.exe | GET | 200 | 205.185.216.42:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 56.1 Kb | whitelisted |
3660 | chrome.exe | GET | 200 | 23.58.216.132:80 | http://contextual.media.net/checksync.php?&gdpr=1&cs=2&cv=31&cid=8CU2LC283 | US | html | 4.06 Kb | shared |
3660 | chrome.exe | GET | 200 | 23.58.216.132:80 | http://contextual.media.net/fcmdynet.js?&gdpr=1&cid=8CU2LC283&cpcd=DEXGNnw-39VSRms_RmjU9Q%3D%3D&crid=736350025&size=728x90&cc=BE&vif=1&requrl=http%3A%2F%2Fcutestat.com%2F&kwrf=https%3A%2F%2Fwww.google.be&nse=3&vi=1557925598438703084&lw=1&ugd=4&re=1&nb=1 | US | text | 13.2 Kb | shared |
3660 | chrome.exe | GET | 200 | 23.58.216.132:80 | http://contextual.media.net/dmedianet.js?cid=8CU2LC283 | US | text | 44.9 Kb | shared |
3660 | chrome.exe | GET | 200 | 23.58.216.132:80 | http://contextual.media.net/fcmdynet.js?&gdpr=1&cid=8CU2LC283&cpcd=DEXGNnw-39VSRms_RmjU9Q%3D%3D&crid=871402158&size=300x250&cc=BE&vif=1&requrl=http%3A%2F%2Fcutestat.com%2F&kwrf=https%3A%2F%2Fwww.google.be&nse=3&vi=1557925598710958628&lw=1&ugd=4&re=1&nb=1 | US | text | 13.5 Kb | shared |
3660 | chrome.exe | GET | 200 | 23.58.216.132:80 | http://contextual.media.net/checksync.php?&gdpr=1&cs=2&cv=31&cid=8CU2LC283 | US | html | 4.06 Kb | shared |
3660 | chrome.exe | GET | 200 | 23.58.216.132:80 | http://contextual.media.net/mediamain.html?&cid=8CU2LC283&cpcd=DEXGNnw-39VSRms_RmjU9Q%3D%3D&crid=736350025&pid=8POW877NW&size=728x90&cpnet=yVb1sHm-0KIh29BOFTjjrHnN8rgyVUaE8Omhsozexxw%3D&cme=1r-Di2oBLyioMXz_K7SC2thGKWSC6haC1q8q_tBx2m3oNuDdYKl2-mwZ1UGnRz0zIbvRX1xckPWewtvIg2ZmtvDYgi25L5V2IxMezQuMrOeJtTI-WLGD2trsrWORj5Zu-xtlPvr7rs6zffS5CrH7sw%3D%3D%7C%7CNDHRnZ9Gz3KXlI-i9OnZqQ%3D%3D%7C5gDUJdTGiJzedmq9hanWYg%3D%3D%7CN7fu2vKt8_s%3D%7CFcl4VLL-IaKpIb_Tsg8j0y_c6t1-6gqM8h7KBbUigkAaJ4D3ty-fSPvjwacOROWByE6PX24FSqk%3D%7Cy2SqoJcE0s9nfXn920_qJQW8Zw-v5JrgE_3GhPHd4Bs%3D%7C&cc=BE&bf=0&staticIframe=1&vif=1&nse=3&bid=243695&vi=1557925598438703084&lw=1&ugd=4&ib=0&nb=1 | US | html | 14.3 Kb | shared |
3660 | chrome.exe | GET | 200 | 23.58.216.132:80 | http://contextual.media.net/fcmdynet.js?&gdpr=1&cid=8CU2LC283&cpcd=DEXGNnw-39VSRms_RmjU9Q%3D%3D&crid=362344516&size=580x250&cc=BE&vif=1&requrl=http%3A%2F%2Fcutestat.com%2F&kwrf=https%3A%2F%2Fwww.google.be&nse=3&vi=1557925598816477117&lw=1&ugd=4&re=1&nb=1 | US | text | 13.5 Kb | shared |
3660 | chrome.exe | GET | 200 | 23.58.216.132:80 | http://contextual.media.net/mediamain.html?&cid=8CU2LC283&cpcd=DEXGNnw-39VSRms_RmjU9Q%3D%3D&crid=362344516&pid=8POG42IZ1&size=580x250&cpnet=yVb1sHm-0KIh29BOFTjjrOxh5BkNZP9JPhl2hMRNmms%3D&cme=xWTjNfdnaEBxho1k2q8rp4PeFnFKMrL5p_UF0N12hSKWJIUj74XHGeWV2R1pgic0MhQRJpIzV1PwGO6ZdnXgDpuG6s1BH6siwFY9SV-4UUuglD3Y-K3U4LRcgB9NiuU6lp6gZOGFzGq_xeoX9tXLxw%3D%3D%7C%7CNDHRnZ9Gz3KXlI-i9OnZqQ%3D%3D%7C5gDUJdTGiJzedmq9hanWYg%3D%3D%7CN7fu2vKt8_s%3D%7CFcl4VLL-IaKpIb_Tsg8j0y_c6t1-6gqM8h7KBbUigkAaJ4D3ty-fSANejkjOXHKDGQU8NKhnt6o%3D%7Cy2SqoJcE0s9nfXn920_qJQW8Zw-v5JrgE_3GhPHd4Bs%3D%7C&cc=BE&bf=0&staticIframe=1&vif=1&nse=3&bid=243664&vi=1557925598816477117&lw=1&ugd=4&ib=0&nb=1 | US | html | 18.1 Kb | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3660 | chrome.exe | 216.58.210.14:443 | ogs.google.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 216.58.208.35:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 207.178.0.79:80 | m1.nsimg.net | Accretive Networks | US | unknown |
— | — | 172.217.22.36:443 | www.google.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 216.58.206.14:443 | clients2.google.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 172.217.22.14:80 | redirector.gvt1.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 172.217.16.129:443 | clients2.googleusercontent.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 172.217.16.131:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 216.58.207.67:443 | www.google.be | Google Inc. | US | whitelisted |
3660 | chrome.exe | 172.217.22.34:443 | adservice.google.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
m1.nsimg.net |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| malicious |
clients2.google.com |
| whitelisted |
clients2.googleusercontent.com |
| whitelisted |
redirector.gvt1.com |
| whitelisted |
r2---sn-aigl6nek.gvt1.com |
| whitelisted |
ssl.gstatic.com |
| whitelisted |
www.google.be |
| whitelisted |