Edit tour
Windows
Analysis Report
https://app.bitdam.com/api/v1.0/links/rewrite_click/?rewrite_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJyZXdyaXRlX2lkIjoiNjcyOGQ2YzliOTFmMDRhNDE1NjM3NTRhIiwidXJsIjoiIiwib3JnYW5pemF0aW9uX2lkIjo1ODQwfQ.Uhd2nS1gN1sUzvqpPDTmoAH1ZU9vF-hNz1sM06cv-iA&url=https%3A//www.google.it/url%3Fq%3Dhttps%3A//www.g
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Detected non-DNS traffic on DNS port
Sigma detected: Suspicious Office Token Search Via CLI
Stores files to the Windows start menu directory
Classification
- System is w10x64_ra
- chrome.exe (PID: 3896 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6748 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2088 --fi eld-trial- handle=197 2,i,136795 1796152063 5089,12012 0554909421 22961,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6356 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://app.b itdam.com/ api/v1.0/l inks/rewri te_click/? rewrite_to ken=eyJ0eX AiOiJKV1Qi LCJhbGciOi JIUzI1NiJ9 .eyJyZXdya XRlX2lkIjo iNjcyOGQ2Y zliOTFmMDR hNDE1NjM3N TRhIiwidXJ sIjoiIiwib 3JnYW5pemF 0aW9uX2lkI jo1ODQwfQ. Uhd2nS1gN1 sUzvqpPDTm oAH1ZU9vF- hNz1sM06cv -iA&url=ht tps%3A//ww w.google.i t/url%3Fq% 3Dhttps%3A //www.goog le.it/url% 3Fq%3Dhttp s%3A//www. google.it/ url%3Fq%3D https%3A// www.google .ro/url%3F q%3Dhttps% 3A//www.go ogle.nl/ur l%3Fq%3DZF CKQSES42J8 31UCOWMB4M EAK36T3IE7 YuQiApLjOD z3yh4nNeW8 uuQi&rct=X S%25RANDOM 4%25wDnNeW 8yycT&sa=t &esrc=nNeW 8F%25RANDO M3%25A0xys 8Em2FL&sou rce=&cd=tS 6T8%25RAND OM3%25Tiw9 XH&cad=XpP kDfJX%25RA NDOM4%25VS 0Y&ved=xjn ktlqryYWwZ IBRrgvK&ua ct=&url=am p%2F%6E%65 %77%68%6F% 6D%65%73%7 6%6E%2E%63 %6F%6D%2F% 63%67%69%2 F/3we/Y29s aW4uZ3Jhbn RAZmlyc3Rv bnRhcmlvLm NvbQ==" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No yara matches
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |