| URL: | https://fidelityy.com |
| Full analysis: | https://app.any.run/tasks/157f1663-7889-4b75-a573-c660a2eda1a1 |
| Verdict: | Malicious activity |
| Analysis date: | April 26, 2023, 22:05:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 260FB7B62981650FC443DF36CB6FE32A |
| SHA1: | 99BD883215FB6611D61373FA7C2FCD36CA6811EF |
| SHA256: | C6FB1F867CAE5B69194385156EA8854FFBBB2EE0FA76F65D946BFA0B6FA1BB33 |
| SSDEEP: | 3:N86t2:26I |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1836396307557264623,592681983027791922,131072 --enable-features=PasswordImport --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1852 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 672 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1836396307557264623,592681983027791922,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1948 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 768 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1836396307557264623,592681983027791922,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=22 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3592 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1172 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1836396307557264623,592681983027791922,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1780 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1300 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=1036,1836396307557264623,592681983027791922,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1964 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1348 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1836396307557264623,592681983027791922,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1904 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1368 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=1036,1836396307557264623,592681983027791922,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2660 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1840 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1836396307557264623,592681983027791922,131072 --enable-features=PasswordImport --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1844 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 2272 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1036,1836396307557264623,592681983027791922,131072 --enable-features=PasswordImport --gpu-preferences=MAAAAAAAAADgACAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=1124 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 2344 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1036,1836396307557264623,592681983027791922,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=24 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3576 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| (PID) Process: | (3296) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3296) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3296) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3296) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3296) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3296) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3296) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3296) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_installdate |
Value: 0 | |||
| (PID) Process: | (3296) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_enableddate |
Value: 0 | |||
| (PID) Process: | (3296) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3296 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-6449A024-CE0.pma | — | |
MD5:— | SHA256:— | |||
| 3484 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma | binary | |
MD5:03C4F648043A88675A920425D824E1B3 | SHA256:F91DBB7C64B4582F529C968C480D2DCE1C8727390482F31E4355A27BB3D9B450 | |||
| 3296 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:00046F773EFDD3C8F8F6D0F87A2B93DC | SHA256:593EDE11D17AF7F016828068BCA2E93CF240417563FB06DC8A579110AEF81731 | |||
| 3296 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:8FF312A95D60ED89857FEB720D80D4E1 | SHA256:946A57FAFDD28C3164D5AB8AB4971B21BD5EC5BFFF7554DBF832CB58CC37700B | |||
| 3296 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:9C016064A1F864C8140915D77CF3389A | SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787 | |||
| 3296 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old | text | |
MD5:7721CDA9F5B73CE8A135471EB53B4E0E | SHA256:DD730C576766A46FFC84E682123248ECE1FF1887EC0ACAB22A5CE93A450F4500 | |||
| 3296 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF1085eb.TMP | text | |
MD5:8304B8F42465198890090F52D3F80A4C | SHA256:80C32AC2585E7E81200104B1630F19560A156C4ABF51B5888B0FBF07323FAB34 | |||
| 3296 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF1084a3.TMP | text | |
MD5:81F483F77EE490F35306A4F94DB2286B | SHA256:82434CE3C9D13F509EBEEBE3A7A1A1DE9AB4557629D9FC855761E0CFA45E8BCE | |||
| 3296 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:5BD3C311F2136A7A88D3E197E55CF902 | SHA256:FA331915E1797E59979A3E4BCC2BD0D3DEAA039B94D4DB992BE251FD02A224B9 | |||
| 3296 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF108474.TMP | text | |
MD5:936EB7280DA791E6DD28EF3A9B46D39C | SHA256:CBAF2AFD831B32F6D1C12337EE5D2F090D6AE1F4DCB40B08BEF49BF52AD9721F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3856 | chrome.exe | GET | 204 | 142.250.186.35:80 | http://www.gstatic.com/generate_204 | US | — | — | whitelisted |
3856 | chrome.exe | GET | — | 103.224.182.206:80 | http://galotop1.com/favicon.ico | AU | — | — | suspicious |
3856 | chrome.exe | GET | 200 | 103.224.182.206:80 | http://galotop1.com/jscheck.php?enc=H9fKFfS8JNpqyK%2B0l2sSwn49fkxRNkg5RmZ1SWxEblcvcllhbCtpVzRJY2FYZ0s2UHc4T2FlbWl5QzNIS282czBYdTMwOFBQOGl5dmhFODhMUDZaN21ZSzhpTnBvTFhzM3lRdHFVVCs2SU11aERPTWR6c2ZSZG1RTHRpd1VtU0NzQ1hZdjRKVmVwZ3hjU2Q1cDBzM093UGZSUXQweng3MDZVZ1hJYXlMRUdYbXNkWUsyVWlZcHA4VHlnbnFSMlNKUzY3aHplTnhwUTJvWXVtaGh4VFJldmlTekh6RmwyclIrZ1UwTzFSbDRVN1BpbmF2TDRkNnh3dGx0ZnNsdWxIU0trRi9wa2U0T29GNGpOeTVibDI2NnlvMEJVSUo0UHdjNXQzdG1DNFN2MUdMeVltYkVPdCsrV0g4aUJuSjU0Q3V2dFdDdHJ5NFB3TXRtemY2N1dmVXVMa2VXanEwOTJmbWQwR01CR2h2R1NUeHovVFdRS2xYVlBnYXhsb29sZ3VSNE9VNk4rRS9CT2NnNFpST0dZTm1aUnQvTDlIcStFek4wTWJXWEJXd01GczdGRzdzdFJxbmVBdzJzU0xmMkF3c3Y4MUdvK2kwTEZWcUFGN09WOVp1TUlPcXk2R2hrTG9jYVZQK1lQQTQ3bkQzV2svbzZWam96N3QxQ2xQN2N6empsUkhiTzNvUmtqSUk1RWN1NXg5RG1uNHFocWRDNE80dm1nUWwrblRDQ0VJOGJkWW9QczhuM3F0VlJIVVdGZStCcE9ObDhscjBuOGVjUld0dkE4U2tUbm9ERlNRSFJDaEh5V0hiVVhIMFdaekp2bXZYT2FEcjhwektSWkNLU2d5eUMvTUprTTUzUVUzMXdjSnNvUytPb1hlQ0V1TkM2OEd0SDRjbjVOOWpUKzdJTnZESER3cnV1YlQ5NDFwNENoN2NOb1BMOTMzUWVjVWFOM1JTajlQNUJYeGI5MFFPa09sejUxWXhZeWlTVEdOWVZvL2piR0x3T0hFODAwVmxPL3lZb0U3UFB2WXJzby9HNzRWeHZYT1ZjdFFVZ1MxellJYnNUcm5qN0FxT1dwMk9TclJqZmM2aVFVYWJoNnh6YUYwam8rZnR4Qis1ajJGUGVwM2xYSTdwM2hwemVZbDRIMzMvVEZSdE9HMk1abGhJUHRxaUZkZmRhRmZ4L3hCcXRiQ1JiQkwvK0g3UkdPSUpSTU9LMStoYkZOcHBSdW5wTTFQRk13T1NDaCtNMW5vTFoySUlvOE94VHFWMm4wemtWbVRFQWVBZmdsRWw0aGFacFJjT1JvY1dJK0lVQmZwQVNqMVYzVnZYOCtQRm91R0lCakgwMUJTMjZRNlRNMmxkaTd5TXM5YkhyZUp4eUVjckZDanhUK2s%3D&rand=0.5404332799356553 | AU | — | — | suspicious |
3856 | chrome.exe | GET | 302 | 103.224.182.206:80 | http://galotop1.com/r.php?u=https%3A%2F%2Frdr.ecomtrck.com%2Fgo%2F117dce2f-fab6-4e8c-9425-46aee812f3c3%3Fcpv%3D0.005%26subid%3Dtr668614155%26kw%3D.lv.subp.nonadult%26sid%3D2023042708054962aea8229e94666b4b&s=j&enc=H9fKFfS8JNpqyK%2B0l2sSwn49fkxRNkg5RmZ1SWxEblcvcllhbCtpVzRJY2FYZ0s2UHc4T2FlbWl5QzNIS282czBYdTMwOFBQOGl5dmhFODhMUDZaN21ZSzhpTnBvTFhzM3lRdHFVVCs2SU11aERPTWR6c2ZSZG1RTHRpd1VtU0NzQ1hZdjRKVmVwZ3hjU2Q1cDBzM093UGZSUXQweng3MDZVZ1hJYXlMRUdYbXNkWUsyVWlZcHA4VHlnbnFSMlNKUzY3aHplTnhwUTJvWXVtaGh4VFJldmlTekh6RmwyclIrZ1UwTzFSbDRVN1BpbmF2TDRkNnh3dGx0ZnNsdWxIU0trRi9wa2U0T29GNGpOeTVibDI2NnlvMEJVSUo0UHdjNXQzdG1DNFN2MUdMeVltYkVPdCsrV0g4aUJuSjU0Q3V2dFdDdHJ5NFB3TXRtemY2N1dmVXVMa2VXanEwOTJmbWQwR01CR2h2R1NUeHovVFdRS2xYVlBnYXhsb29sZ3VSNE9VNk4rRS9CT2NnNFpST0dZTm1aUnQvTDlIcStFek4wTWJXWEJXd01GczdGRzdzdFJxbmVBdzJzU0xmMkF3c3Y4MUdvK2kwTEZWcUFGN09WOVp1TUlPcXk2R2hrTG9jYVZQK1lQQTQ3bkQzV2svbzZWam96N3QxQ2xQN2N6empsUkhiTzNvUmtqSUk1RWN1NXg5RG1uNHFocWRDNE80dm1nUWwrblRDQ0VJOGJkWW9QczhuM3F0VlJIVVdGZStCcE9ObDhscjBuOGVjUld0dkE4U2tUbm9ERlNRSFJDaEh5V0hiVVhIMFdaekp2bXZYT2FEcjhwektSWkNLU2d5eUMvTUprTTUzUVUzMXdjSnNvUytPb1hlQ0V1TkM2OEd0SDRjbjVOOWpUKzdJTnZESER3cnV1YlQ5NDFwNENoN2NOb1BMOTMzUWVjVWFOM1JTajlQNUJYeGI5MFFPa09sejUxWXhZeWlTVEdOWVZvL2piR0x3T0hFODAwVmxPL3lZb0U3UFB2WXJzby9HNzRWeHZYT1ZjdFFVZ1MxellJYnNUcm5qN0FxT1dwMk9TclJqZmM2aVFVYWJoNnh6YUYwam8rZnR4Qis1ajJGUGVwM2xYSTdwM2hwemVZbDRIMzMvVEZSdE9HMk1abGhJUHRxaUZkZmRhRmZ4L3hCcXRiQ1JiQkwvK0g3UkdPSUpSTU9LMStoYkZOcHBSdW5wTTFQRk13T1NDaCtNMW5vTFoySUlvOE94VHFWMm4wemtWbVRFQWVBZmdsRWw0aGFacFJjT1JvY1dJK0lVQmZwQVNqMVYzVnZYOCtQRm91R0lCakgwMUJTMjZRNlRNMmxkaTd5TXM5YkhyZUp4eUVjckZDanhUK2s%3D&vs=1280:572&ds=1280:720&sl=0:0&os=f&nos=f&swfV=0.0.0&if=f&sc=f&gpu=Google%20Inc.%20-%20Google%20SwiftShader | AU | — | — | suspicious |
3856 | chrome.exe | GET | 200 | 103.224.182.206:80 | http://galotop1.com/javascript/jscheck.js | AU | compressed | 405 b | suspicious |
3856 | chrome.exe | GET | 200 | 103.224.182.206:80 | http://galotop1.com/javascript/swfobject.js | AU | compressed | 3.86 Kb | suspicious |
3856 | chrome.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?36f2328b96e87ed9 | US | compressed | 62.3 Kb | whitelisted |
3856 | chrome.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d718b32e7cb3b991 | US | compressed | 62.3 Kb | whitelisted |
3856 | chrome.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?bf0a88eda13a49fe | US | compressed | 62.3 Kb | whitelisted |
3856 | chrome.exe | GET | 200 | 103.224.182.206:80 | http://galotop1.com/r2.php?e=XoiSftmz16FbQJBRIQhUiX49fmg0S2g4bDdjaWxaWGRYMDRhNXN6N1NwUmVsVitQWmNqNEQ3L1piWWltMThxMFZ3NTdoZlh5S3lYU3UyRTVnNk95UnlHbHlHYjIwdHEzYmovc3c0SFE0Q2RHREdaRXk5MXd6b1ptZG4raU9uM2t5SHc0VnlEdHBmTkh3Tm9HRU5KZVRoNjJkUjg5bktIU05lZUJ2b205a0hsczV3TWxkWTI3Wmp3ZG4xN2lwcmhxQ2lycTRRTFFRVHJnaE1BaE9TYjZuYTE3ck91aDVMV2VCbU9Gd3UrTERVSUJWaVc4cWlyUDg0c1lodEw2dk1xN1IwVHM0S3hXdVUvMzE0UWFPMjNKMHpEUGVZSjRKNkpCa0xMN1hlNXZmbElNV1F5R3lYT2FNTzM4T29Pd0FOQUxpdXBpS2pGR1I3WEczd3AyYlB2c0ppMm5la095aVJ0SW80UEVMQ3lhZG94ZjNYaVdMYkxQL3pGZEcwcGp3d0ZJeWFDTFNxOEMrWGVzRnRCNk15SENuUmgrbUM0d3B2dWk2UVhqeFhMM3BsOVJ4eUx2Um9ORzVGb2pSZFB0dWhJMEJKQlRFMkhVbzRjTUpUd0hWNndOWUczeFVMSk44L1BYZDl5SW9BWHBpUGo5NVVGOTNKbkgrbHBCenFtNi9naVI1b25wemhyNTBWc3luakdQcXRUeWJ1VzM4ckt2NTgvUVgxRDJTMVM0U3lQeExydGdhTktEV0hwU1ZqV3pCTXdvL2VRbXk5c21idmdhcC9JckVkRHVOZC83MG9iUzdxVWx6eXVpeXAySUVHZFBwQ1FmeVAzaUc5cHdLaDdwYmx4Q1AvOVpodVNjTjc0SFYybTBLSVhERFNtSU5PQkJkQ3kwaks0dkYrUHdjREw2Z3VPR29NZ3ArOEI0OStqSkduOHFleFVQdXgvbmpNY05Bb0xMd2EvcEFEKytod01RaFB1bUpVOXl1WUJHckY5SExiT1ROV2RsMnAxQTJENnUwRHdJbFJSVXhYeWk4amNLZm11N280dkp6YTNvN2x1cHBaSms5Zy9SS292L3N4UTZicW51K3FKNlVTcmhTd0VVaWVJMmlDNHhQSGZxeTl4M05Vb0JUb0V1ZmlrdnRhSzAxR2x2NzlGd0tRQjBkUWpOcXRBUllodktsZzlFbklyVUFKSjRKa2NTcUFDZzhWN25oWGVoNGdP | AU | compressed | 2.21 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 18.66.97.90:443 | www.zaful.com | — | US | unknown |
3856 | chrome.exe | 52.222.214.96:443 | eur.zaful.com | AMAZON-02 | US | suspicious |
3856 | chrome.exe | 108.138.7.77:443 | css.zafcdn.com | AMAZON-02 | US | unknown |
3856 | chrome.exe | 142.250.185.168:443 | ssl.google-analytics.com | GOOGLE | US | suspicious |
3856 | chrome.exe | 142.250.184.237:443 | accounts.google.com | GOOGLE | US | suspicious |
3856 | chrome.exe | 172.217.23.110:443 | clients2.google.com | GOOGLE | US | whitelisted |
3856 | chrome.exe | 103.224.182.241:443 | fidelityy.com | Trellian Pty. Limited | AU | malicious |
3856 | chrome.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | STACKPATH-CDN | US | whitelisted |
3856 | chrome.exe | 142.250.186.35:80 | www.gstatic.com | GOOGLE | US | whitelisted |
3856 | chrome.exe | 103.224.182.206:80 | galotop1.com | Trellian Pty. Limited | AU | suspicious |
Domain | IP | Reputation |
|---|---|---|
fidelityy.com |
| malicious |
clients2.google.com |
| whitelisted |
accounts.google.com |
| shared |
ctldl.windowsupdate.com |
| whitelisted |
ssl.gstatic.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
galotop1.com |
| suspicious |
rdr.ecomtrck.com |
| suspicious |
rdrd.ecomtrck.com |
| suspicious |
ecomuster.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
3856 | chrome.exe | Potential Corporate Privacy Violation | AV POLICY Observed TikTok Domain in TLS SNI (tiktok.com) |