| URL: | https://onelink.shein.com/1/3i8c10u65a4u |
| Full analysis: | https://app.any.run/tasks/42bb80bb-5d5f-4ed0-972f-5dab52bd2796 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2024, 12:23:43 |
| OS: | Ubuntu 22.04.2 |
| MD5: | 3A0E325EDA170F54C9A08F126B0878DD |
| SHA1: | 0A4DADD34A83FE7D78C34D52CD7A7DCC2B4F970A |
| SHA256: | FDB581129AA886231B29C82C32FA2440F85B963923029C1FA8CB7151509FDA49 |
| SSDEEP: | 3:N8CsA/LLKyWc9n:2CsAD2Yn |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 9298 | /bin/sh -c "DISPLAY=:0 sudo -iu user google-chrome \"https://onelink\.shein\.com/1/3i8c10u65a4u\" " | /bin/sh | — | any-guest-agent |
User: root Integrity Level: UNKNOWN | ||||
| 9299 | sudo -iu user google-chrome https://onelink.shein.com/1/3i8c10u65a4u | /usr/bin/sudo | — | sh |
User: root Integrity Level: UNKNOWN | ||||
| 9300 | /usr/bin/google-chrome https://onelink.shein.com/1/3i8c10u65a4u | /opt/google/chrome/chrome | — | sudo |
User: user Integrity Level: UNKNOWN | ||||
| 9301 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9302 | readlink -f /usr/bin/google-chrome | /usr/bin/readlink | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9303 | dirname /opt/google/chrome/google-chrome | /usr/bin/dirname | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9304 | mkdir -p /home/user/.local/share/applications | /usr/bin/mkdir | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9305 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN | ||||
| 9306 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN | ||||
| 9307 | /opt/google/chrome/chrome | — | chrome | |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 9300 | chrome | /9300/fd/63 | — | |
MD5:— | SHA256:— | |||
| 9300 | chrome | /home/user/.config/google-chrome/BrowserMetrics/BrowserMetrics-66001B55-2454.pma | — | |
MD5:— | SHA256:— | |||
| 9300 | chrome | /.com.google.Chrome.nY8GBG | — | |
MD5:— | SHA256:— | |||
| 9300 | chrome | /home/user/.config/google-chrome/Default/Sync Data/LevelDB/LOG | — | |
MD5:— | SHA256:— | |||
| 9300 | chrome | /.com.google.Chrome.N38JLf | — | |
MD5:— | SHA256:— | |||
| 9300 | chrome | /.com.google.Chrome.oR1stv | — | |
MD5:— | SHA256:— | |||
| 9300 | chrome | /.com.google.Chrome.KAZh9O | — | |
MD5:— | SHA256:— | |||
| 9300 | chrome | /home/user/.config/google-chrome/Default/Site Characteristics Database/LOG | — | |
MD5:— | SHA256:— | |||
| 9300 | chrome | /home/user/.config/google-chrome/Default/Local Storage/leveldb/LOG | — | |
MD5:— | SHA256:— | |||
| 9300 | chrome | /home/user/.config/google-chrome/Default/commerce_subscription_db/LOG | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 91.189.91.48:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | unknown |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adenfnd66guzd4vn7ffvjgkyl7wq_439/lmelglejhemejginpboagddgdfbepgmp_439_all_ZZ_adbbwdbp45y3tcec5bde2wha5nnq.crx3 | unknown | binary | 46.8 Kb | unknown |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jx7rkbwas3jtmlgf6ivmagwisi_2024.3.22.0/niikhdgajlphfehepabhhblakbdgeefj_2024.03.22.00_all_pplglefstwrw27olw4xpo7hgs4.crx3 | unknown | binary | 5.92 Kb | unknown |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acwgkdznoxamsx5mwpmya3o5zxwa_8619/hfnkpimlhhgieaddgfemjhofmfblmnib_8619_all_lejbgwpinvdzsfulvsthnrzf2u.crx3 | unknown | binary | 26.0 Kb | unknown |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acfoa3x64p3467wwho3hx34n7spa_2024.3.23.1/jflhchccmppkfebkiaminageehmchikm_2024.03.23.01_all_fytxkahks4fazxdm4bsyu2ll3y.crx3 | unknown | binary | 9.18 Kb | unknown |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYTBmQUFZUHRkSkgtb01uSGNvRHZ2Tm5HQQ/1.0.0.15_llkgjffcdpffmhiakmfcdcblohccpfmo.crx | unknown | binary | 3.07 Kb | unknown |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/jflookgnkcckhobaglndicnbbgbonegd/1.c7f445d90541e46806f932c860cf78e900b7949c56ccb45c53681b7dfc9270a7/1.ab8da5b849ba36382f26992fe1b52d72aa457549f31246a0c386d6880fca8afc/30b8ef13d7a852a769e41fddfbce995cfbf508643a3b68249eaf8cda4232245b.puff | unknown | binary | 51.9 Kb | unknown |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/efniojlnjndmcbiieegkicadnoecjjef/1.81edfe5c9bcd5c93a7431df1cf92255bb705c56adeb8c1167fc2571494b02794/1.6fcc02a365d39485c49c9da8679a9fd979832315b2d47ff7f0ab395b10e303bd/e9b2d40c051400dde730a4513c31c6d190deb9bbab06617af1a35a2f80e79aa3.puff | unknown | binary | 22.2 Kb | unknown |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jtw2yebqy6ogv6wzfigbjphimy_2024.3.20.0/gonpemdgkjcecdgbnaabipppbmgfggbe_2024.03.20.00_all_acyqzrhkvpmzwu7jrinfxlenms5a.crx3 | unknown | binary | 6.47 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 91.189.91.48:80 | — | Canonical Group Limited | US | unknown |
— | — | 185.125.190.49:80 | — | Canonical Group Limited | GB | unknown |
— | — | 108.177.96.84:443 | accounts.google.com | GOOGLE | US | unknown |
— | — | 239.255.255.250:1900 | — | — | — | unknown |
— | — | 142.250.184.227:443 | clientservices.googleapis.com | GOOGLE | US | unknown |
— | — | 172.64.151.183:443 | onelink.shein.com | CLOUDFLARENET | US | unknown |
— | — | 142.250.186.170:443 | safebrowsing.googleapis.com | GOOGLE | US | unknown |
— | — | 104.17.3.184:443 | challenges.cloudflare.com | — | — | unknown |
— | — | 142.250.186.131:443 | update.googleapis.com | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
onelink.shein.com |
| unknown |
onelink.shein.com.cdn.cloudflare.net |
| unknown |
safebrowsing.googleapis.com |
| whitelisted |
challenges.cloudflare.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
content-autofill.googleapis.com |
| whitelisted |
www.shein.com |
| whitelisted |
e29831.b.akamaiedge.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Misc activity | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |