URL: | https://pixel.sitescout.com/iap/18afd268d0a70733 |
Full analysis: | https://app.any.run/tasks/833e85f9-1428-474e-a7e7-68815f7b44cc |
Verdict: | Malicious activity |
Analysis date: | March 25, 2024, 04:02:12 |
OS: | Ubuntu 22.04.2 |
MD5: | FB6C43F17760BC605F5183ED36C771CB |
SHA1: | 8C87B3C4CF74447DF537E47D9FBE8F6D8A4644FC |
SHA256: | D99024732B5FAAB44B043621A8CF9C991E192C555FF558A8F700C7F42AACE14B |
SSDEEP: | 3:N8IEzGl2MeERn:2I4Gl2Meen |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
9291 | /bin/sh -c "DISPLAY=:0 sudo -iu user google-chrome \"https://pixel\.sitescout\.com/iap/18afd268d0a70733\" " | /bin/sh | — | any-guest-agent |
User: user Integrity Level: UNKNOWN | ||||
9292 | sudo -iu user google-chrome https://pixel.sitescout.com/iap/18afd268d0a70733 | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN | ||||
9293 | /usr/bin/google-chrome https://pixel.sitescout.com/iap/18afd268d0a70733 | /opt/google/chrome/chrome | — | sudo |
User: user Integrity Level: UNKNOWN | ||||
9294 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
9295 | readlink -f /usr/bin/google-chrome | /usr/bin/readlink | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
9296 | dirname /opt/google/chrome/google-chrome | /usr/bin/dirname | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
9297 | mkdir -p /home/user/.local/share/applications | /usr/bin/mkdir | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
9298 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN | ||||
9299 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN | ||||
9300 | /opt/google/chrome/chrome | — | chrome | |
User: user Integrity Level: UNKNOWN Exit code: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
9293 | chrome | /9293/fd/63 | — | |
MD5:— | SHA256:— | |||
9293 | chrome | /home/user/.config/google-chrome/BrowserMetrics/BrowserMetrics-6600F74A-244D.pma | — | |
MD5:— | SHA256:— | |||
9293 | chrome | /.com.google.Chrome.lxgNw1 | — | |
MD5:— | SHA256:— | |||
9293 | chrome | /.com.google.Chrome.7lnl9n | — | |
MD5:— | SHA256:— | |||
9293 | chrome | /home/user/.config/google-chrome/Default/Session Storage/LOG | — | |
MD5:— | SHA256:— | |||
9293 | chrome | /home/user/.config/google-chrome/Default/shared_proto_db/metadata/LOG | — | |
MD5:— | SHA256:— | |||
9293 | chrome | /home/user/.config/google-chrome/Default/shared_proto_db/LOG | — | |
MD5:— | SHA256:— | |||
9293 | chrome | /home/user/.config/google-chrome/WidevineCdm/.com.google.Chrome.WoEn3d | — | |
MD5:— | SHA256:— | |||
9293 | chrome | /.com.google.Chrome.cTfeNc | — | |
MD5:— | SHA256:— | |||
9293 | chrome | /.com.google.Chrome.1f54Q7 | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jx7rkbwas3jtmlgf6ivmagwisi_2024.3.22.0/niikhdgajlphfehepabhhblakbdgeefj_2024.03.22.00_all_pplglefstwrw27olw4xpo7hgs4.crx3 | unknown | binary | 5.92 Kb | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYTBmQUFZUHRkSkgtb01uSGNvRHZ2Tm5HQQ/1.0.0.15_llkgjffcdpffmhiakmfcdcblohccpfmo.crx | unknown | binary | 3.07 Kb | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/a35mboten4bcfb5vyedocgsscu_8621/hfnkpimlhhgieaddgfemjhofmfblmnib_8621_all_hyo5lvnfb2cearzvzynnrdl45y.crx3 | unknown | binary | 26.1 Kb | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adenfnd66guzd4vn7ffvjgkyl7wq_439/lmelglejhemejginpboagddgdfbepgmp_439_all_ZZ_adbbwdbp45y3tcec5bde2wha5nnq.crx3 | unknown | binary | 46.8 Kb | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/efniojlnjndmcbiieegkicadnoecjjef/1.81edfe5c9bcd5c93a7431df1cf92255bb705c56adeb8c1167fc2571494b02794/1.6fcc02a365d39485c49c9da8679a9fd979832315b2d47ff7f0ab395b10e303bd/e9b2d40c051400dde730a4513c31c6d190deb9bbab06617af1a35a2f80e79aa3.puff | unknown | binary | 22.2 Kb | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/jflookgnkcckhobaglndicnbbgbonegd/1.c7f445d90541e46806f932c860cf78e900b7949c56ccb45c53681b7dfc9270a7/1.ab8da5b849ba36382f26992fe1b52d72aa457549f31246a0c386d6880fca8afc/30b8ef13d7a852a769e41fddfbce995cfbf508643a3b68249eaf8cda4232245b.puff | unknown | binary | 51.9 Kb | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acfoa3x64p3467wwho3hx34n7spa_2024.3.23.1/jflhchccmppkfebkiaminageehmchikm_2024.03.23.01_all_fytxkahks4fazxdm4bsyu2ll3y.crx3 | unknown | binary | 9.18 Kb | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jtw2yebqy6ogv6wzfigbjphimy_2024.3.20.0/gonpemdgkjcecdgbnaabipppbmgfggbe_2024.03.20.00_all_acyqzrhkvpmzwu7jrinfxlenms5a.crx3 | unknown | binary | 6.47 Kb | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 239.255.255.250:1900 | — | — | — | unknown |
— | — | 216.58.206.67:443 | clientservices.googleapis.com | GOOGLE | US | unknown |
— | — | 108.177.96.84:443 | accounts.google.com | GOOGLE | US | unknown |
— | — | 98.98.134.243:443 | pixel.sitescout.com | ZEN-ECN | US | unknown |
— | — | 142.250.185.67:443 | update.googleapis.com | GOOGLE | US | unknown |
— | — | 216.58.206.36:443 | www.google.com | — | — | unknown |
— | — | 142.250.184.202:443 | optimizationguide-pa.googleapis.com | GOOGLE | US | unknown |
— | — | 34.104.35.123:80 | edgedl.me.gvt1.com | GOOGLE | US | unknown |
— | — | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
Domain | IP | Reputation |
---|---|---|
clientservices.googleapis.com |
| unknown |
accounts.google.com |
| unknown |
pixel.sitescout.com |
| unknown |
update.googleapis.com |
| unknown |
134.100.168.192.in-addr.arpa |
| unknown |
www.google.com |
| unknown |
optimizationguide-pa.googleapis.com |
| unknown |
connectivity-check.ubuntu.com |
| unknown |
edgedl.me.gvt1.com |
| unknown |
api.snapcraft.io |
| unknown |