| URL: | https://www.myehtrip.net |
| Full analysis: | https://app.any.run/tasks/6ef59e81-eded-47f4-ba92-70302c0d6b01 |
| Verdict: | Malicious activity |
| Analysis date: | November 20, 2020, 20:44:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 282ECCA1BD34EDA0D94A949B8473D4C7 |
| SHA1: | 8BB6631458EEAF7B3C1355F6A4502E61A8C57A5A |
| SHA256: | D7E27B0750229FEF713E0D0F9CDF23CB0D545110EFE046CEFD83BA52E6C51893 |
| SSDEEP: | 3:N8DSLKk/AR:2OLKIAR |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 1596 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "https://www.myehtrip.net" | C:\Program Files\Google\Chrome\Application\chrome.exe | — | explorer.exe |
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 | ||||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 304 | 13.107.4.50:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.5 Kb | whitelisted |
— | — | GET | 200 | 13.107.4.50:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.5 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 172.217.21.227:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
— | — | 52.210.128.165:443 | match.adsrvr.org | Amazon.com, Inc. | IE | unknown |
— | — | 104.24.111.71:443 | www.myehtrip.net | Cloudflare Inc | US | unknown |
— | — | 216.58.212.173:443 | accounts.google.com | Google Inc. | US | whitelisted |
— | — | 104.108.144.214:443 | ads.pubmatic.com | TOT Public Company Limited | US | unknown |
— | — | 172.217.16.130:443 | adservice.google.com | Google Inc. | US | whitelisted |
— | — | 99.86.2.41:443 | nitrocdn.com | AT&T Services, Inc. | US | malicious |
— | — | 216.58.207.34:443 | pagead2.googlesyndication.com | Google Inc. | US | whitelisted |
— | — | 142.250.74.200:443 | ssl.google-analytics.com | Google Inc. | US | suspicious |
— | — | 216.58.206.2:443 | securepubads.g.doubleclick.net | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.myehtrip.net |
| malicious |
accounts.google.com |
| shared |
ads.pubmatic.com |
| whitelisted |
adservice.google.com |
| whitelisted |
nitrocdn.com |
| malicious |
ad.doubleclick.net |
| whitelisted |
googleads.g.doubleclick.net |
| whitelisted |
gum.criteo.com |
| whitelisted |
ontetag-sys.com |
| malicious |
pagead2.googlesyndication.com |
| whitelisted |