| URL: | https://textup.fr/542667c7 |
| Full analysis: | https://app.any.run/tasks/d5faa8b9-36b5-4cc8-bbc0-b588149bc8af |
| Verdict: | Malicious activity |
| Analysis date: | May 11, 2021, 22:13:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 23F2827FB1CED841858F73D19CE73434 |
| SHA1: | EC3CED88BD1F42821A4F4DCDDF86922335E1B516 |
| SHA256: | DE66D95965C302F79DF1C3F4537DB40FB088C04F2C45845AC0B7C420EAE5AE62 |
| SSDEEP: | 3:N8IcV3bxTs:2IcV3dTs |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1520 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "https://textup.fr/542667c7" | C:\Program Files\Google\Chrome\Application\chrome.exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2116 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6bbba9d0,0x6bbba9e0,0x6bbba9ec | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 | |||||||||||||||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 301 | 104.21.20.7:80 | http://ghostbin.co/ | US | html | 194 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 142.250.184.227:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
— | — | 142.250.186.141:443 | accounts.google.com | Google Inc. | US | whitelisted |
— | — | 172.217.168.10:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
— | — | 193.31.15.1:443 | fbin.pw | — | — | suspicious |
— | — | 172.217.168.35:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
— | — | 162.159.135.233:443 | cdn.discordapp.com | Cloudflare Inc | — | shared |
— | — | 216.58.212.174:443 | clients1.google.com | Google Inc. | US | whitelisted |
— | — | 104.21.60.53:443 | anonfiles.com | Cloudflare Inc | US | suspicious |
— | — | 199.16.128.45:443 | textup.fr | PlanetHoster | CA | unknown |
— | — | 172.67.196.152:443 | freychang.fun | — | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
textup.fr |
| whitelisted |
accounts.google.com |
| shared |
www.google-analytics.com |
| whitelisted |
clients1.google.com |
| whitelisted |
ssl.gstatic.com |
| whitelisted |
fbin.pw |
| suspicious |
fonts.googleapis.com |
| whitelisted |
v2.bytefend.com |
| suspicious |
fonts.gstatic.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET DNS Query to a *.pw domain - Likely Hostile |
— | — | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |