URL: | crowdstrike.woccpa.com |
Full analysis: | https://app.any.run/tasks/79eceae3-d818-4de0-9517-0a4dddf095c4 |
Verdict: | Malicious activity |
Analysis date: | July 24, 2024, 10:42:20 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Indicators: | |
MD5: | 62747547EC1312954AC8BD276A125CF2 |
SHA1: | A0C16EDADF5C0350BDB73622678F9D6130D1EB64 |
SHA256: | C1EAB88C83E15BC2EC007B52B8AA889B8B8D5499576EE51E18329869C0D066D2 |
SSDEEP: | 3:Kyu58I:K3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
208 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "crowdstrike.woccpa.com" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 122.0.6261.70 Modules
| |||||||||||||||
364 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
712 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4016 --field-trial-handle=1856,i,592881194742633555,16099687631014197570,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 122.0.6261.70 Modules
| |||||||||||||||
1028 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2128 --field-trial-handle=1856,i,592881194742633555,16099687631014197570,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:3 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 122.0.6261.70 | |||||||||||||||
3908 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4664 --field-trial-handle=1856,i,592881194742633555,16099687631014197570,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
4252 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=2940 --field-trial-handle=1856,i,592881194742633555,16099687631014197570,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 122.0.6261.70 Modules
| |||||||||||||||
4880 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x220,0x224,0x228,0x1fc,0x22c,0x7fff02a5dc40,0x7fff02a5dc4c,0x7fff02a5dc58 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 122.0.6261.70 | |||||||||||||||
5532 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2988 --field-trial-handle=1856,i,592881194742633555,16099687631014197570,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 | |||||||||||||||
6048 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2908 --field-trial-handle=1856,i,592881194742633555,16099687631014197570,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
6512 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2236 --field-trial-handle=1856,i,592881194742633555,16099687631014197570,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 122.0.6261.70 |
PID | Process | Filename | Type | |
---|---|---|---|---|
208 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
208 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
208 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
208 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RFe1c3e.TMP | — | |
MD5:— | SHA256:— | |||
208 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RFe1c4e.TMP | — | |
MD5:— | SHA256:— | |||
208 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
208 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old | — | |
MD5:— | SHA256:— | |||
208 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
208 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:FC81892AC822DCBB09441D3B58B47125 | SHA256:FB077C966296D02D50CCBF7F761D2A3311A206A784A7496F331C2B0D6AD205C8 | |||
208 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\091f9607-f453-4abc-a72b-3c50fe7be325.tmp | binary | |
MD5:5058F1AF8388633F609CADB75A75DC9D | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1028 | chrome.exe | GET | 200 | 208.91.197.24:80 | http://crowdstrike.woccpa.com/px.js?ch=1 | unknown | — | — | malicious |
— | — | GET | 200 | 64.190.63.136:80 | http://sedoparking.com/frmpark/crowdstrike.woccpa.com/Skenzor7/park.js?reg_logo=netsol-logo.png®_href_text=This+Page+Is+Under+Construction+-+Coming+Soon%21®_href_url=®_href_text_2=Why+am+I+seeing+this+%27Under+Construction%27+page%3F®_href_url_2=http%3A%2F%2Fcrowdstrike.woccpa.com%2F__media__%2Fdesign%2Funderconstructionnotice.php%3Fd%3Dwoccpa.com | unknown | — | — | whitelisted |
1028 | chrome.exe | GET | 404 | 208.91.197.24:80 | http://crowdstrike.woccpa.com/favicon.ico | unknown | — | — | malicious |
5028 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
— | — | GET | 432 | 64.190.63.136:80 | http://sedoparking.com/search/registrar.php?domain=crowdstrike.woccpa.com&rpv=2®istrar=Skenzor7&gst=ChMI54Cu_b6_hwMVSdoCBx20xQHPEmoBlLqpjw2kSb6k_AQP_jE6L_Z02njIwdIh7HHqmCuwtIaB5EVXy_inV2mxPgTlB5008wihTzUwRl-g8XBLKa9IGSatx1UCs2AjabUd0z0IJoaonifTUawRLMMau3FJC9dK_6-_ZX2JYD2u&ref=®_logo=netsol-logo.png®_href_text=This%20Page%20Is%20Under%20Construction%20-%20Coming%20Soon%21®_href_text_2=Why%20am%20I%20seeing%20this%20%27Under%20Construction%27%20page%3F®_href_url_2=http%3A%2F%2Fcrowdstrike.woccpa.com%2F__media__%2Fdesign%2Funderconstructionnotice.php%3Fd%3Dwoccpa.com | unknown | — | — | whitelisted |
916 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
1028 | chrome.exe | GET | 200 | 208.91.197.24:80 | http://crowdstrike.woccpa.com/ | unknown | — | — | malicious |
1028 | chrome.exe | GET | 200 | 208.91.197.24:80 | http://crowdstrike.woccpa.com/px.js?ch=2 | unknown | — | — | malicious |
1028 | chrome.exe | GET | — | 208.91.197.24:80 | http://crowdstrike.woccpa.com/ | unknown | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
6012 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6384 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4548 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 2.23.209.174:443 | — | Akamai International B.V. | GB | unknown |
4204 | svchost.exe | 4.209.32.198:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3952 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
208 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1028 | chrome.exe | 74.125.128.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
1028 | chrome.exe | 208.91.197.24:443 | crowdstrike.woccpa.com | CONFLUENCE-NETWORK-INC | VG | unknown |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crowdstrike.woccpa.com |
| malicious |
accounts.google.com |
| whitelisted |
www.google.com |
| whitelisted |
sedoparking.com |
| whitelisted |
pagead2.googlesyndication.com |
| whitelisted |
syndicatedsearch.goog |
| unknown |
js-agent.newrelic.com |
| whitelisted |
bam.nr-data.net |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] An application monitoring request to newrelic .com |