Windows
Analysis Report
https://www.googleadservices.com/pagead/aclk?sa=L&ai=C0Usyv4rrZanTKoT848AP4aexoAmK5sTbdcXSndz2EaGcpYbiPxABIIaPgAJgyY6Ii7yksBmgAee3oJUDyAEGqQJPxyfSzVmyPqgDAaoE7gFP0LCb_VWhsSTPWZHRzLK1IalD51QUW6ZDxdlkv6WY3uiX6bRQiRUM6sqklTwYDBKIH0zxsdBnP7iDASkP2mPkqEpZOSVo0ODJFtQfeBCCL-yKseO0WrN1zOiCQ3262DGQtf1poiiV-R
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Found iframes
Program does not show much activity (idle)
Classification
- System is w10x64
chrome.exe (PID: 5856 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 2492 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2108 --fi eld-trial- handle=205 6,i,278414 6977150846 062,120298 7470834397 4160,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 7132 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= audio.mojo m.AudioSer vice --lan g=en-US -- service-sa ndbox-type =audio --m ojo-platfo rm-channel -handle=57 04 --field -trial-han dle=2056,i ,278414697 7150846062 ,120298747 0834397416 0,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion /pref etch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 6428 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http s://www.go ogleadserv ices.com/p agead/aclk ?sa=L&ai=C 0Usyv4rrZa nTKoT848AP 4aexoAmK5s TbdcXSndz2 EaGcpYbiPx ABIIaPgAJg yY6Ii7yksB mgAee3oJUD yAEGqQJPxy fSzVmyPqgD AaoE7gFP0L Cb_VWhsSTP WZHRzLK1Ia lD51QUW6ZD xdlkv6WY3u iX6bRQiRUM 6sqklTwYDB KIH0zxsdBn P7iDASkP2m PkqEpZOSVo 0ODJFtQfeB CCL-yKseO0 WrN1zOiCQ3 262DGQtf1p oiiV-RkLxr zDxum6Jd3v gW632y71PW 5smoqMqg22 Eaxgf6zM5s -rFhpjs4Pw aNWFD_KyxJ dFQCQfbr70 oQ_Mq_Nnm7 Owqxoylg20 PZQrs9axHX j1bbFuRpXw s_5Gos26vM Yhkmfyd35U hZOrulAJHb p4DBukhf_F BHZkOv_EmT GMgPNNbzEk wJumwATn3s imxgSIBaHq w8RMkAYBoA Y3gAeByN9q iAcBkAcCqA fZtrECqAez mLECqAevvr ECqAfVyRuo B6a-G6gHjs 4bqAeT2Buo B-DgG6gH7p axAqgH_p6x AqgHnbmxAq gHmgaoB_PR G6gHltgbqA eqm7ECqAeD rbECqAfgvb ECqAf_nrEC qAffn7ECqA e2rbECqAfK qbECqAemv7 ECqAehqrEC qAfqsbECqA eZtbECqAe- t7ECqAekr7 EC2AcAqAgB 0ggmCAAQAh hCMgEAOg2_ 8YCAgIAEgM CAgIAgSLfm vyFYhoWOr9 XlhAOxCUG8 XunTVEqBgA oTmAsByAsF 0AstgAwB2g wVCgsQ4P7K 9ePfy7ijAR IBBTIDCgEy 6AwJmg0BLa oNAlVTyA0B 2BMOiBQCqB UB0BUB2BUB -BYBgBcBsh gJEgKwUxg3 IgEB&ae=1& ase=3&gcli d=CjwKCAiA i6uvBhADEi wAWiyRduXP R2h9H4QS0Q ZheFBxVZ-B e_3d_YQw-t CPD08aq_H9 hSHTOjIxOB oC29gQAvD_ BwE&cit=Ck UKCQiAi6uv BhCcARI0AF MmYGGS2VX8 PeG7Lks_jc zRTcJM6wna noKKAFjWvW AEfvMugVQB G2iTIbd5qj 2f6uJyYhoC Ixnw_wcB&n um=1&cid=C AQSIgB7FLt q0ZfCL1XpN 6HJFExsPRJ 9A_39i59YB FmuuDIuiJM YAQ&sig=AO D64_0_CAOG n8uiEslKGx 1biFfmzAuw ag&client= ca-gmail&l abel=gmail _message_a d_external _click&adu rl=https%3 A%2F%2Ftot albattle.c om%2Flp%2F city9alike 2_webgl_da rk_po_2%2F 3%3Fowr%3D IL%26frt%3 DDisplay%2 6crt%3Dcit y9alike%26 typ%3DNU%2 6cnt%3DUK% 26int%3Dst rategy%26a dgp%3Dads% 26prtr%3DG oogle%26cq _src%3Dgoo gle_ads%26 cq_cmp%3D2 0544812321 %26cq_term %3D%26cq_p lac%3Dmail .google.co m%26cq_net %3Dd%26cq_ plt%3Dgp%2 6ad_id%3D6 7371542344 6%26gclid% 3DCjwKCAiA i6uvBhADEi wAWiyRduXP R2h9H4QS0Q ZheFBxVZ-B e_3d_YQw-t CPD08aq_H9 hSHTOjIxOB oC29gQAvD_ BwE MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
- • Phishing
- • Networking
- • System Summary
- • Malware Analysis System Evasion
- • Anti Debugging
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | String found in binary or memory: |