| URL: | https://www.youtube.com/redirect?event=comments&redir_token=QUFFLUhqblJuSWRjWUFXYTBzTVVLOVFDajlLZTMxOU10d3xBQ3Jtc0tuOUQ3eU04OEZvdy1PenZFQVdmUldxYU1DanQ3cEVDZzhBZkJuR203Q1c4UEFPZVVoMjZGM0s3dGhTRklScXB6ekgzdmZZeklZT1VtSTkzU0tEazZTSzRxMndSSi1ENWtBc3pNd3c3Y3pwWU1hRGpSOA&q=http%3A%2F%2Fnutakugoldhack.xyz%2F&stzid=Ugx8Gry-AoI30FpCb-94AaABAg.9NKz3Vk4gkq9NMsx2YchJJ |
| Full analysis: | https://app.any.run/tasks/50ba9eb6-51bb-40a1-a76c-850727d81dc6 |
| Verdict: | Malicious activity |
| Analysis date: | May 20, 2021, 20:55:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | AC56DA33D25EB2389390C8941A0FA6E5 |
| SHA1: | DF96F2BC2811809FB5DBA87D1CA5860C7D632CBA |
| SHA256: | B8E93EC6A292C1A61AB8AF90DEF49BE913407AC121EC049DCECD3B8FB6823053 |
| SSDEEP: | 6:2OLUxGKmquxZm2Gjcf1JxALgARqwPGQ86iMD9lMUukGYBBljkTszkiOzn919p:2jGRPPmNjMJOxuQuMD9lMWR4TsQxBp |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 184 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,8678841632162380497,17366829444150174423,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=10813605574985205248 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2176 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 548 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,8678841632162380497,17366829444150174423,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=275016352320600337 --renderer-client-id=19 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4272 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 556 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,8678841632162380497,17366829444150174423,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=18265277807925506947 --renderer-client-id=18 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1996 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 904 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,8678841632162380497,17366829444150174423,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14954583740339781751 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2348 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 916 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,8678841632162380497,17366829444150174423,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=3743327471880245855 --mojo-platform-channel-handle=4108 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1232 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,8678841632162380497,17366829444150174423,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14574787751462861653 --renderer-client-id=34 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5316 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1456 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,8678841632162380497,17366829444150174423,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12428509181923205506 --renderer-client-id=30 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4772 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1460 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,8678841632162380497,17366829444150174423,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4063297845947514424 --renderer-client-id=26 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4884 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1472 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "https://www.youtube.com/redirect?event=comments&redir_token=QUFFLUhqblJuSWRjWUFXYTBzTVVLOVFDajlLZTMxOU10d3xBQ3Jtc0tuOUQ3eU04OEZvdy1PenZFQVdmUldxYU1DanQ3cEVDZzhBZkJuR203Q1c4UEFPZVVoMjZGM0s3dGhTRklScXB6ekgzdmZZeklZT1VtSTkzU0tEazZTSzRxMndSSi1ENWtBc3pNd3c3Y3pwWU1hRGpSOA&q=http%3A%2F%2Fnutakugoldhack.xyz%2F&stzid=Ugx8Gry-AoI30FpCb-94AaABAg.9NKz3Vk4gkq9NMsx2YchJJ" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1492 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,8678841632162380497,17366829444150174423,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=9936905503554411230 --renderer-client-id=21 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1860 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (1472) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (1472) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (1472) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (1472) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (1472) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1472) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (1472) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (1472) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3252-13245750958665039 |
Value: 0 | |||
| (PID) Process: | (1472) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (1472) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 1472-13266017771178625 |
Value: 259 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1472 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-60A6CCEB-5C0.pma | — | |
MD5:— | SHA256:— | |||
| 1472 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\1b0161aa-497d-4818-b1e3-1bde7b505820.tmp | — | |
MD5:— | SHA256:— | |||
| 1472 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp | — | |
MD5:— | SHA256:— | |||
| 1472 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF13954e.TMP | text | |
MD5:C2DDBA63E4A2BD2E39A8B6C2C6384AAE | SHA256:6D5C1C78341C6F84911055D970ADDB0EC3499F8BF7FADE062122A22209CE67D9 | |||
| 1472 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:C2DDBA63E4A2BD2E39A8B6C2C6384AAE | SHA256:6D5C1C78341C6F84911055D970ADDB0EC3499F8BF7FADE062122A22209CE67D9 | |||
| 1472 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:D4322EEBAC92D1B8F7A6F5E39F6264B7 | SHA256:A3EEDF21B850DCC7CE5AE04395ECDD2D29DA4EA549C8A185DD9E8B552A87B8C2 | |||
| 1472 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF13953e.TMP | text | |
MD5:D4322EEBAC92D1B8F7A6F5E39F6264B7 | SHA256:A3EEDF21B850DCC7CE5AE04395ECDD2D29DA4EA549C8A185DD9E8B552A87B8C2 | |||
| 1472 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | text | |
MD5:67F45CAA18C889645F50CD6216C81E65 | SHA256:33ED82CDDDFFD55A5059C147C6CD20F66C6712314F890A39576D3C10914D0029 | |||
| 1472 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1472 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF139732.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1944 | chrome.exe | GET | 301 | 142.250.185.78:80 | http://google.com/ | US | html | 219 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1944 | chrome.exe | 216.58.207.238:443 | www.youtube.com | Google Inc. | US | whitelisted |
1944 | chrome.exe | 142.250.186.173:443 | accounts.google.com | Google Inc. | US | suspicious |
1944 | chrome.exe | 142.250.184.227:443 | www.gstatic.com | Google Inc. | US | whitelisted |
1944 | chrome.exe | 142.250.185.110:443 | clients1.google.com | Google Inc. | US | whitelisted |
1944 | chrome.exe | 104.21.75.5:80 | nutakugoldhack.xyz | Cloudflare Inc | US | suspicious |
1944 | chrome.exe | 142.250.185.163:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
1944 | chrome.exe | 104.21.75.5:443 | nutakugoldhack.xyz | Cloudflare Inc | US | suspicious |
1944 | chrome.exe | 142.250.186.174:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
1944 | chrome.exe | 142.250.184.234:443 | ajax.googleapis.com | Google Inc. | US | whitelisted |
1944 | chrome.exe | 104.21.47.153:443 | hackersgroup.net | Cloudflare Inc | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.youtube.com |
| whitelisted |
accounts.google.com |
| shared |
www.gstatic.com |
| whitelisted |
clients1.google.com |
| whitelisted |
nutakugoldhack.xyz |
| suspicious |
ssl.gstatic.com |
| whitelisted |
s.w.org |
| whitelisted |
tugenerator.club |
| malicious |
hackersgroup.net |
| suspicious |
d1sf3a4rercrry.cloudfront.net |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1944 | chrome.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |