URL: | https://www.myehtrip.net |
Full analysis: | https://app.any.run/tasks/6ef59e81-eded-47f4-ba92-70302c0d6b01 |
Verdict: | Malicious activity |
Analysis date: | November 20, 2020, 20:44:27 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | 282ECCA1BD34EDA0D94A949B8473D4C7 |
SHA1: | 8BB6631458EEAF7B3C1355F6A4502E61A8C57A5A |
SHA256: | D7E27B0750229FEF713E0D0F9CDF23CB0D545110EFE046CEFD83BA52E6C51893 |
SSDEEP: | 3:N8DSLKk/AR:2OLKIAR |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1596 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "https://www.myehtrip.net" | C:\Program Files\Google\Chrome\Application\chrome.exe | — | explorer.exe |
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 75.0.3770.100 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 13.107.4.50:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.5 Kb | whitelisted |
— | — | GET | 304 | 13.107.4.50:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.5 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 172.217.16.130:443 | adservice.google.com | Google Inc. | US | whitelisted |
— | — | 216.58.212.173:443 | accounts.google.com | Google Inc. | US | whitelisted |
— | — | 104.108.144.214:443 | ads.pubmatic.com | TOT Public Company Limited | US | unknown |
— | — | 104.24.111.71:443 | www.myehtrip.net | Cloudflare Inc | US | unknown |
— | — | 99.86.2.41:443 | nitrocdn.com | AT&T Services, Inc. | US | malicious |
— | — | 216.58.207.34:443 | pagead2.googlesyndication.com | Google Inc. | US | whitelisted |
— | — | 216.58.206.2:443 | securepubads.g.doubleclick.net | Google Inc. | US | whitelisted |
— | — | 142.250.74.200:443 | ssl.google-analytics.com | Google Inc. | US | suspicious |
— | — | 185.33.220.145:443 | ib.adnxs.com | AppNexus, Inc | — | unknown |
— | — | 178.250.2.131:443 | bidder.criteo.com | Criteo SA | FR | unknown |
Domain | IP | Reputation |
---|---|---|
www.myehtrip.net |
| malicious |
accounts.google.com |
| shared |
ads.pubmatic.com |
| whitelisted |
adservice.google.com |
| whitelisted |
nitrocdn.com |
| malicious |
ad.doubleclick.net |
| whitelisted |
googleads.g.doubleclick.net |
| whitelisted |
gum.criteo.com |
| whitelisted |
ontetag-sys.com |
| malicious |
pagead2.googlesyndication.com |
| whitelisted |