| URL: | http://www.wenxuecity.com |
| Full analysis: | https://app.any.run/tasks/d8915789-6a0e-4d13-9f4b-6262303cb0e9 |
| Verdict: | No threats detected |
| Analysis date: | May 15, 2019, 16:39:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 7972F5E9C27406604F9198EAEFCD00C0 |
| SHA1: | 9E64BC0E6F8DD603EB53A3637CF986B84F30898B |
| SHA256: | F7EA4FE5CF922FA9C0780E583B0F804367DBD9A504D7829B1A1D2B1FAF99C97A |
| SSDEEP: | 3:N1KJS4dQAWLKn:Cc4zWLK |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 680 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,8812356221339311642,6170884054344634227,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=130751071645564151 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=130751071645564151 --renderer-client-id=21 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6980 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 828 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,8812356221339311642,6170884054344634227,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=7783853927450580920 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7783853927450580920 --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4104 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 832 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=940,8812356221339311642,6170884054344634227,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=7604040425794670807 --mojo-platform-channel-handle=2972 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 856 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,8812356221339311642,6170884054344634227,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=11148695291559986012 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11148695291559986012 --renderer-client-id=13 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3052 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 864 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,8812356221339311642,6170884054344634227,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=5016461981781001173 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5016461981781001173 --renderer-client-id=25 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7708 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 912 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,8812356221339311642,6170884054344634227,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=4589344466752116750 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4589344466752116750 --renderer-client-id=42 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7944 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 928 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,8812356221339311642,6170884054344634227,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=3246133728837160008 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=3246133728837160008 --renderer-client-id=40 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7924 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 948 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=940,8812356221339311642,6170884054344634227,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=16260494575351186920 --mojo-platform-channel-handle=7000 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1040 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,8812356221339311642,6170884054344634227,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=4624799335256428889 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4624799335256428889 --renderer-client-id=24 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5920 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| 1208 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=940,8812356221339311642,6170884054344634227,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=10860270188697476794 --mojo-platform-channel-handle=7532 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 73.0.3683.75 Modules
| |||||||||||||||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1464) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 3660-13202411981855000 |
Value: 259 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3488-13197474229333984 |
Value: 0 | |||
| (PID) Process: | (3660) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3660-13202411981855000 |
Value: 259 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0 | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_2 | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_3 | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\1bba2123-b1e0-4520-8131-20b1416f3fd5.tmp | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000018.dbtmp | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\index | — | |
MD5:— | SHA256:— | |||
| 3660 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_0 | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3660 | chrome.exe | GET | 200 | 35.190.55.229:80 | http://www.wenxuecity.com/css/pmc.css?ver2018101017 | US | text | 1.68 Kb | unknown |
3660 | chrome.exe | GET | 200 | 35.190.55.229:80 | http://www.wenxuecity.com/css/project.css | US | text | 2.08 Kb | unknown |
3660 | chrome.exe | GET | 200 | 35.190.55.229:80 | http://www.wenxuecity.com/pages/js/haiwai_homepage.js? | US | html | 1.30 Kb | unknown |
3660 | chrome.exe | GET | 200 | 35.190.55.229:80 | http://www.wenxuecity.com/ | US | html | 27.1 Kb | unknown |
3660 | chrome.exe | GET | 200 | 35.190.55.229:80 | http://www.wenxuecity.com/css/common.css?ver=20190201 | US | text | 2.35 Kb | unknown |
3660 | chrome.exe | GET | 200 | 35.190.31.60:80 | http://passport.wenxuecity.com/members/js/md5.js?tmp=4 | US | text | 3.03 Kb | whitelisted |
3660 | chrome.exe | GET | 200 | 35.190.55.229:80 | http://www.wenxuecity.com/images/simplified.gif | US | image | 1.26 Kb | unknown |
3660 | chrome.exe | GET | 200 | 35.190.55.229:80 | http://www.wenxuecity.com/css/index1.css?ver20190307 | US | text | 3.19 Kb | unknown |
3660 | chrome.exe | GET | 200 | 173.241.240.220:80 | http://pubgalaxy-d.openx.net/w/1.0/arj?ju=http%3A%2F%2Fwww.wenxuecity.com%2F&jr=&ch=UTF-8&res=1280x720x24&ifr=false&tz=-60&tws=1280x572&be=1&bc=hb_pb_2.1.6&dddid=d85bd890-64cf-4ab0-81cd-df6f3dd74936%2Cde4e056c-5667-4490-80ab-f67eaa180344%2Ced1c49c7-147f-416e-875a-a2a5efbf9ae3%2C6d699e3c-986f-49e9-9b24-f3dbade8d18e%2Cdd154bd4-8944-4b05-9021-57e238d07958%2C502f2875-6be6-4a3e-94bd-18966340a3ab%2C8f4650b8-c2a2-4176-a616-44bd83bbf41e%2C752777cd-c4f6-498a-9702-f1089d5b4cf8%2C8bfe47e3-f256-4aa0-bf1d-5837d46585be%2Ca3715012-8370-498a-8cb7-b91f345b0ba7%2C95f16870-4098-406c-be4a-404256b92a2f&nocache=1557938386633&aus=160x600%7C160x600%7C728x90%7C300x600%7C728x90%7C160x600%7C728x90%7C300x250%7C160x600%7C300x250%7C300x600&divIds=div-gpt-ad-1535449483619-0%2Cdiv-gpt-ad-1536310089101-4%2Cdiv-gpt-ad-1543413129742-1%2Cdiv-gpt-ad-wenxuecitycom34945%2Cdiv-gpt-ad-1536310089101-0%2Cdiv-gpt-ad-wenxuecitycom35078%2Cdiv-gpt-ad-1535449508562-0%2Cdiv-gpt-ad-1539687949704-1%2Cdiv-gpt-ad-1543413129742-0%2Cdiv-gpt-ad-1536310089101-5%2Cdiv-gpt-ad-wenxuecitycom35217&auid=540307646%2C540305020%2C540490252%2C540451735%2C540301382%2C540457547%2C540307647%2C540394736%2C540490253%2C540307471%2C540674486&aumfs=10%2C10%2C10%2C10%2C10%2C10%2C10%2C10%2C10%2C10%2C10& | US | text | 164 b | whitelisted |
3660 | chrome.exe | GET | 200 | 213.19.162.51:80 | http://fastlane.rubiconproject.com/a/api/fastlane.json?account_id=18630&site_id=212196&zone_id=1131382&size_id=2&p_pos=unknown&rf=http%3A%2F%2Fwww.wenxuecity.com%2F&tk_flint=pbjs_lite_v2.8.0&x_source.tid=ed1c49c7-147f-416e-875a-a2a5efbf9ae3&p_screen_res=1280x720&rp_floor=0.01&rp_secure=0&slots=1&rand=0.629613073168688 | GB | text | 240 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3660 | chrome.exe | 178.250.2.152:80 | bidder.criteo.com | Criteo SA | FR | unknown |
3660 | chrome.exe | 173.241.240.220:80 | pubgalaxy-d.openx.net | OPENX TECHNOLOGIES, INC. | US | unknown |
3660 | chrome.exe | 35.190.55.229:80 | www.wenxuecity.com | Google Inc. | US | unknown |
3660 | chrome.exe | 216.58.207.67:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 216.58.205.226:443 | www.googletagservices.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 216.58.207.77:443 | accounts.google.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 172.217.22.40:443 | www.googletagmanager.com | Google Inc. | US | whitelisted |
3660 | chrome.exe | 13.32.222.6:80 | dsh7ky7308k4b.cloudfront.net | Amazon.com, Inc. | US | whitelisted |
3660 | chrome.exe | 13.32.222.6:443 | dsh7ky7308k4b.cloudfront.net | Amazon.com, Inc. | US | whitelisted |
3660 | chrome.exe | 213.19.162.51:80 | fastlane.rubiconproject.com | The Rubicon Project, Inc. | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
www.wenxuecity.com |
| unknown |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
dsh7ky7308k4b.cloudfront.net |
| whitelisted |
www.googletagservices.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
passport.wenxuecity.com |
| unknown |
pagead2.googlesyndication.com |
| whitelisted |
ib.adnxs.com |
| whitelisted |
pubgalaxy-d.openx.net |
| whitelisted |