| URL: | https://www.google.com/search?q=bandicam+crack+2020&oq=bandicam+&aqs=chrome.2.69i57j0i433j0l2j0i433j0l3.4020j0j7&sourceid=chrome&ie=UTF-8 |
| Full analysis: | https://app.any.run/tasks/45acd09a-fd41-4446-83f5-9ad5fcb1de9f |
| Verdict: | Malicious activity |
| Analysis date: | November 21, 2020, 19:20:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 7A0E0B86331E3B075F75DA5F19723F40 |
| SHA1: | 6EA1E769ABA039C9B13BCFE952429BB3D18B09C6 |
| SHA256: | C16EF9F3A2DCA1B6C465479B1F80CAB091CAC9432324124E0E4243B899FA996E |
| SSDEEP: | 3:N8DSLIwAEXGp/GTcjXVTqvTvEJAj4wO+wPLRtqDUX9GiVzjId:2OLIwBGwT2yTvEJAj4H+wVwDUTOd |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 2644 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "https://www.google.com/search?q=bandicam+crack+2020&oq=bandicam+&aqs=chrome.2.69i57j0i433j0l2j0i433j0l3.4020j0j7&sourceid=chrome&ie=UTF-8" | C:\Program Files\Google\Chrome\Application\chrome.exe | — | explorer.exe |
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 | ||||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 301 | 172.67.152.75:80 | http://hiltonmac.xyz/?s=21&q=Bandicam-Crack-4651757-With-Registration-Code-Latest&g=10c91ed56a369156dae106a9c7f9d5ab&mode=&dedica=10 | US | — | — | suspicious |
— | — | GET | — | 198.15.92.226:80 | http://www.paraindia.org/?big=bandicam-keygen-full-crack-download/ | US | — | — | malicious |
— | — | GET | 302 | 3.131.95.4:80 | http://ec2-3-131-95-4.us-east-2.compute.amazonaws.com/?t=21&q=Bandicam-Crack-4651757-With-Registration-Code-Latest&dedica=10 | US | html | 783 b | shared |
— | — | GET | 200 | 3.131.95.4:80 | http://ec2-3-131-95-4.us-east-2.compute.amazonaws.com/loading.gif | US | image | 17.8 Kb | shared |
— | — | GET | 200 | 3.131.95.4:80 | http://ec2-3-131-95-4.us-east-2.compute.amazonaws.com/?x_filehash=cloud-372862982a38a361c0a3bf783e769666&c2778ecc2fac3ab9a1d1f639f9f38c3f98dcdc05=4495875d35f3a890eb9fe82f07f4c76a88514a62 | US | compressed | 1.41 Mb | shared |
— | — | POST | 200 | 3.131.95.4:80 | http://ec2-3-131-95-4.us-east-2.compute.amazonaws.com/?go=fec4f1f981fd8f6&dedica=10 | US | html | 1.32 Kb | shared |
— | — | GET | 200 | 3.101.113.145:80 | http://3.101.113.145/mFZUjpoxfcQNdlGvCFEjpgqfC51LLi5LjKIGvpMiLloQGwf23DpT75zsIC3FyRbFL1gdf7ykCkyJRFm0P922awUR1lnbTKsAedIYeWa_VEXNcApLOeYWThFXeRtKBv22TkAzISA3YG3JMxXxfI8VvA/?is=2&hash=pxs_GPvmEbflyHkQxLBPUXZvk6Bs6p1L9JPrTpPvTSfiKEn87fZNbLUxLv7ixaYm_e9DWGNcF2yxHKtLLO0QbQ | US | html | 1.80 Kb | unknown |
— | — | GET | 404 | 3.131.95.4:80 | http://ec2-3-131-95-4.us-east-2.compute.amazonaws.com/favicon.ico | US | html | 292 b | shared |
— | — | GET | 200 | 3.101.113.145:80 | http://3.101.113.145/bootstrap-darkly.min.css | US | text | 24.3 Kb | unknown |
— | — | POST | 200 | 3.131.95.4:80 | http://ec2-3-131-95-4.us-east-2.compute.amazonaws.com/?cloudx=e0ad2decd0bcee57f5bc98b&dedica=10 | US | html | 1.19 Kb | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 172.217.18.100:443 | www.google.com | Google Inc. | US | whitelisted |
— | — | 172.217.18.109:443 | accounts.google.com | Google Inc. | US | suspicious |
— | — | 172.217.21.227:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
— | — | 216.58.210.14:443 | consent.google.com | Google Inc. | US | whitelisted |
— | — | 64.233.171.100:443 | play.google.com | Google Inc. | US | whitelisted |
— | — | 172.217.18.3:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
— | — | 172.217.195.156:443 | adservice.google.com | Google Inc. | US | unknown |
— | — | 172.217.22.110:443 | encrypted-vtbn3.gstatic.com | Google Inc. | US | whitelisted |
— | — | 172.217.18.106:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
— | — | 104.24.115.230:443 | up4pc.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
www.google.com |
| malicious |
accounts.google.com |
| shared |
fonts.gstatic.com |
| whitelisted |
consent.google.com |
| shared |
www.gstatic.com |
| whitelisted |
apis.google.com |
| whitelisted |
ogs.google.com |
| whitelisted |
encrypted-tbn0.gstatic.com |
| whitelisted |
play.google.com |
| whitelisted |
adservice.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |