Windows Analysis Report http://kiwifarms.net

Overview

General Information

Sample URL: http://kiwifarms.net
Analysis ID: 152
Infos:

Most interesting Screenshot:

Detection

Score: 20
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Found Tor onion address

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Source: unknown HTTPS traffic detected: 104.22.8.83:443 -> 192.168.2.3:50353 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.22.8.83:443 -> 192.168.2.3:50352 version: TLS 1.2
Source: unknown HTTPS traffic detected: 151.101.1.229:443 -> 192.168.2.3:63491 version: TLS 1.2
Source: unknown HTTPS traffic detected: 151.101.1.229:443 -> 192.168.2.3:63490 version: TLS 1.2

Networking:

barindex
Found Tor onion address
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: onion-location:http://uquusqsaaad66cvub4473csdu4uu7ahxou3zqc35fpw5d4ificedzyqd.onion/service_worker.js
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: HTTP/1.1 200date:Tue, 20 Jul 2021 14:31:12 GMTcontent-type:application/javascriptcf-bgj:minifycf-polished:origSize=6028etag:W/"609261f0-178c"last-modified:Wed, 05 May 2021 09:14:24 GMTlink:<https://kiwifarms.net/service_worker.js>; rel="canonical"onion-location:http://uquusqsaaad66cvub4473csdu4uu7ahxou3zqc35fpw5d4ificedzyqd.onion/service_worker.jsvary:Accept-Encodingcache-control:max-age=86400cf-cache-status:HITage:5141expect-ct:max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"server:cloudflarecf-ray:671ce44df9114e7a-FRAcontent-encoding:gzipalt-svc:h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
Source: 63b9a976ffc843f0_0.0.dr String found in binary or memory: Zhttp://uquusqsaaad66cvub4473csdu4uu7ahxou3zqc35fpw5d4ificedzyqd.onion/index.php?sw/offline"
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: kiwifarms.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknown DNS traffic detected: queries for: clients2.google.com
Source: angular.js.0.dr String found in binary or memory: http://angularjs.org
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: http://cacerts.digicert.com/CloudflareIncECCCA-3.crt0
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: http://crl3.digicert.com/CloudflareIncECCCA-3.crl07
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: http://crl3.digicert.com/Omniroot2025.crl0m
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: http://crl4.digicert.com/CloudflareIncECCCA-3.crl0
Source: angular.js.0.dr String found in binary or memory: http://errors.angularjs.org/1.6.4-local
Source: Favicons.0.dr, Session_13271297468083334.0.dr String found in binary or memory: http://kiwifarms.net/
Source: History Provider Cache.0.dr String found in binary or memory: http://kiwifarms.net/2
Source: History.0.dr String found in binary or memory: http://kiwifarms.net/Kiwi
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: http://ocsp.digicert.com0
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: http://ocsp.digicert.com0:
Source: mirroring_hangouts.js.0.dr String found in binary or memory: http://tools.ietf.org/html/rfc1950
Source: 63b9a976ffc843f0_0.0.dr String found in binary or memory: http://uquusqsaaad66cvub4473csdu4uu7ahxou3zqc35fpw5d4ificedzyqd.onion/index.php?sw/offline
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: http://uquusqsaaad66cvub4473csdu4uu7ahxou3zqc35fpw5d4ificedzyqd.onion/service_worker.js
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: http://uquusqsaaad66cvub4473csdu4uu7ahxou3zqc35fpw5d4ificedzyqd.onion/service_worker.jsvary:Accept-E
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: http://www.digicert.com/CPS0v
Source: mirroring_hangouts.js.0.dr String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions
Source: mirroring_hangouts.js.0.dr String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01
Source: mirroring_hangouts.js.0.dr String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-time
Source: mirroring_hangouts.js.0.dr String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/generic-frame-descriptor-00
Source: mirroring_hangouts.js.0.dr String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-layers-allocation00
Source: Reporting and NEL.1.dr String found in binary or memory: https://a.nel.cloudflare.com/report/v3?s=tUqha%2BursXcgwQaC0iliPMFm%2FBqaZE93tAVsQNsvcehoGdPlauhQaCu
Source: manifest.json0.0.dr, manifest.json2.0.dr, 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, 0d0336d5-832e-40b1-ba5a-c5d89ad51715.tmp.1.dr String found in binary or memory: https://accounts.google.com
Source: craw_window.js.0.dr String found in binary or memory: https://accounts.google.com/MergeSession
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://aomediacodec.github.io/av1-rtp-spec/#dependency-descriptor-rtp-header-extension
Source: manifest.json0.0.dr, manifest.json2.0.dr, 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, 0d0336d5-832e-40b1-ba5a-c5d89ad51715.tmp.1.dr String found in binary or memory: https://apis.google.com
Source: mirroring_common.js.0.dr String found in binary or memory: https://apis.google.com/js/client.js
Source: 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr String found in binary or memory: https://cdn.jsdelivr.net
Source: 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, 0d0336d5-832e-40b1-ba5a-c5d89ad51715.tmp.1.dr String found in binary or memory: https://clients2.google.com
Source: mirroring_hangouts.js.0.dr, mirroring_cast_streaming.js.0.dr String found in binary or memory: https://clients2.google.com/cr/report
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, 0d0336d5-832e-40b1-ba5a-c5d89ad51715.tmp.1.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://clients6.google.com
Source: 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr String found in binary or memory: https://content-autofill.googleapis.com
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://content.googleapis.com
Source: mirroring_cast_streaming.js.0.dr, common.js.0.dr String found in binary or memory: https://crash.corp.google.com/samples?reportid=&q=
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://creativecommons.org/publicdomain/zero/1.0/.
Source: Reporting and NEL.1.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external
Source: Reporting and NEL.1.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/OneGoogleWidgetUi/external
Source: mirroring_common.js.0.dr String found in binary or memory: https://docs.google.com
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: angular.js.0.dr String found in binary or memory: https://github.com/angular/material
Source: craw_background.js.0.dr, craw_window.js.0.dr String found in binary or memory: https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://github.com/madler/zlib/blob/master/zlib.h
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://hangouts.clients6.google.com
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://hangouts.google.com/
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://hangouts.google.com/_/logpref
Source: 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr String found in binary or memory: https://kiwifar.ms
Source: 000003.log4.0.dr, 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, Session_13271297468083334.0.dr String found in binary or memory: https://kiwifarms.net
Source: 000003.log2.0.dr String found in binary or memory: https://kiwifarms.net/
Source: 000003.log2.0.dr String found in binary or memory: https://kiwifarms.net/0
Source: History Provider Cache.0.dr String found in binary or memory: https://kiwifarms.net/2
Source: History.0.dr String found in binary or memory: https://kiwifarms.net/Kiwi
Source: Session_13271297468083334.0.dr String found in binary or memory: https://kiwifarms.net/chat/autism-thunderdome.5/
Source: Favicons.0.dr String found in binary or memory: https://kiwifarms.net/chat/autism-thunderdome.5//
Source: History.0.dr String found in binary or memory: https://kiwifarms.net/chat/autism-thunderdome.5/Autism
Source: Session_13271297468083334.0.dr String found in binary or memory: https://kiwifarms.net/chat/beauty-parlor.4/
Source: History.0.dr String found in binary or memory: https://kiwifarms.net/chat/beauty-parlor.4/Beauty
Source: Favicons.0.dr String found in binary or memory: https://kiwifarms.net/favicon.ico
Source: Session_13271297468083334.0.dr String found in binary or memory: https://kiwifarms.net/g4
Source: 63b9a976ffc843f0_0.0.dr String found in binary or memory: https://kiwifarms.net/index.php?sw/offline
Source: 63b9a976ffc843f0_0.0.dr String found in binary or memory: https://kiwifarms.net/index.php?sw/offlineP&Z
Source: Session_13271297468083334.0.dr String found in binary or memory: https://kiwifarms.net/search/search
Source: 000003.log2.0.dr String found in binary or memory: https://kiwifarms.net/service_worker.js
Source: 2cc80dabc69f58b6_1.0.dr String found in binary or memory: https://kiwifarms.net/service_worker.jsaD
Source: c4bd86b1-ed97-4ad9-bcf4-1d044cb9c122.tmp.0.dr, b1e6ba37-661b-495d-9e8f-f556929c3623.tmp.0.dr, f7bbe1a7-0c79-4939-9f08-c1e18153024f.tmp.0.dr, aaff355a-4820-4fe5-87cf-4412d6e26986.tmp.0.dr, fb498487-b000-4948-a50f-70e46170b497.tmp.0.dr String found in binary or memory: https://kiwifarms.net:443
Source: mirroring_common.js.0.dr String found in binary or memory: https://meet.google.com
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://meetings.clients6.google.com
Source: 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr String found in binary or memory: https://no-cookie.kiwifarms.net
Source: Network Action Predictor.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/
Source: 2606a6cb8d138dee_0.0.dr, 2606a6cb8d138dee_00.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/happyboard/chat/chat.js?5.12&_v=9cfbfdea
Source: 2606a6cb8d138dee_00.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/happyboard/chat/chat.js?5.12&_v=9cfbfdeaaD
Source: 83a3b6225b24e84d_00.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/vendor/jquery/jquery-3.5.1.min.js?_v=9cfbfdea
Source: 0e303d78ba4de217_0.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/vendor/jquery/jquery-3.5.1.min.js?_v=9cfbfdeaa
Source: 0e303d78ba4de217_0.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/vendor/jquery/jquery-3.5.1.min.js?_v=9cfbfdeaaD
Source: 7e6ab2a08da28049_0.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/vendor/vendor-compiled.js?_v=9cfbfdea
Source: 7e6ab2a08da28049_00.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/vendor/vendor-compiled.js?_v=9cfbfdeaa
Source: 7e6ab2a08da28049_00.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/vendor/vendor-compiled.js?_v=9cfbfdeaaD
Source: 04e491f77e80eab0_0.0.dr, 91587cab20671160_0.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/xf/core-compiled.js?_v=9cfbfdea
Source: 91587cab20671160_0.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/xf/core-compiled.js?_v=9cfbfdeaaD
Source: 55ead6e2e0d0d983_0.0.dr, 55ead6e2e0d0d983_00.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/xf/notice.min.js?_v=9cfbfdea
Source: 55ead6e2e0d0d983_00.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/xf/notice.min.js?_v=9cfbfdeaaD
Source: 169e14a6382d1f7d_0.0.dr, 169e14a6382d1f7d_00.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/xf/preamble.min.js?_v=9cfbfdea
Source: 169e14a6382d1f7d_00.0.dr String found in binary or memory: https://no-cookie.kiwifarms.net/js/xf/preamble.min.js?_v=9cfbfdeaaD
Source: 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, 0d0336d5-832e-40b1-ba5a-c5d89ad51715.tmp.1.dr String found in binary or memory: https://ogs.google.com
Source: craw_window.js.0.dr, manifest.json1.0.dr, manifest.json.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://play.google.com/log?format=json&hasfast=true
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://preprod-hangouts-googleapis.sandbox.google.com
Source: 151727db-f9eb-433b-9867-25f37b75d632.tmp.1.dr String found in binary or memory: https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct
Source: craw_window.js.0.dr, manifest.json1.0.dr, manifest.json.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, 0d0336d5-832e-40b1-ba5a-c5d89ad51715.tmp.1.dr String found in binary or memory: https://ssl.gstatic.com
Source: messages.json102.0.dr, feedback.html.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json102.0.dr, feedback.html.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, 0d0336d5-832e-40b1-ba5a-c5d89ad51715.tmp.1.dr String found in binary or memory: https://update.googleapis.com
Source: craw_background.js.0.dr, craw_window.js.0.dr String found in binary or memory: https://www-googleapis-staging.sandbox.google.com
Source: 2cc80dabc69f58b6_0.0.dr String found in binary or memory: https://www.digicert.com/CPS0
Source: manifest.json0.0.dr, manifest.json2.0.dr, 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, 0d0336d5-832e-40b1-ba5a-c5d89ad51715.tmp.1.dr String found in binary or memory: https://www.google.com
Source: manifest.json1.0.dr, manifest.json.0.dr String found in binary or memory: https://www.google.com/
Source: craw_window.js.0.dr String found in binary or memory: https://www.google.com/accounts/OAuthLogin?issueuberauth=1
Source: craw_window.js.0.dr String found in binary or memory: https://www.google.com/images/cleardot.gif
Source: craw_window.js.0.dr String found in binary or memory: https://www.google.com/images/dot2.gif
Source: craw_window.js.0.dr String found in binary or memory: https://www.google.com/images/x2.gif
Source: craw_background.js.0.dr String found in binary or memory: https://www.google.com/intl/en-US/chrome/blank.html
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://www.google.com/log?format=json&hasfast=true
Source: feedback_script.js.0.dr String found in binary or memory: https://www.google.com/tools/feedback
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://www.google.com;
Source: craw_background.js.0.dr, craw_window.js.0.dr, 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, 0d0336d5-832e-40b1-ba5a-c5d89ad51715.tmp.1.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json1.0.dr, manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json1.0.dr, manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json1.0.dr, manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json1.0.dr, manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json1.0.dr, manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: mirroring_common.js.0.dr String found in binary or memory: https://www.googleapis.com/calendar/v3
Source: mirroring_common.js.0.dr String found in binary or memory: https://www.googleapis.com/hangouts/v1
Source: 30713012-428d-42f8-bca7-979c3fe8fbe1.tmp.1.dr, 0d0336d5-832e-40b1-ba5a-c5d89ad51715.tmp.1.dr String found in binary or memory: https://www.gstatic.com
Source: common.js.0.dr String found in binary or memory: https://www.gstatic.com/hangouts_echo_detector/release/%
Source: manifest.json0.0.dr, manifest.json2.0.dr String found in binary or memory: https://www.gstatic.com;
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63490
Source: unknown Network traffic detected: HTTP traffic on port 58381 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62785 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63491
Source: unknown Network traffic detected: HTTP traffic on port 62779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62791 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56302 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51583 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58609 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57966 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65381 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63489
Source: unknown Network traffic detected: HTTP traffic on port 49199 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63488
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64214
Source: unknown Network traffic detected: HTTP traffic on port 50194 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55211 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63498 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56307 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58386 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49194 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50195
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50194
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63496
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63495
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63498
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63497
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63499
Source: unknown Network traffic detected: HTTP traffic on port 65088 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50195 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58608 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63497 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50197
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50196
Source: unknown Network traffic detected: HTTP traffic on port 51582 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56301 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62792 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58387 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49193 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58481
Source: unknown Network traffic detected: HTTP traffic on port 62786 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62784 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52455 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58379
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58378
Source: unknown Network traffic detected: HTTP traffic on port 51588 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56312 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62781 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56306 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51584
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51585
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51582
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51583
Source: unknown Network traffic detected: HTTP traffic on port 63499 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51588
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51589
Source: unknown Network traffic detected: HTTP traffic on port 50353 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51586
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51587
Source: unknown Network traffic detected: HTTP traffic on port 60588 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55207 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65088
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55958
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55959
Source: unknown Network traffic detected: HTTP traffic on port 58382 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62790 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49198 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63488 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49217 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 55212 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58383 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51589 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52455
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49197 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62796 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56311 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49218 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58607 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49199
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49198
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49197
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49196
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49195
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49194
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49193
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49192
Source: unknown Network traffic detected: HTTP traffic on port 51412 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56305 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51584 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49192 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52909
Source: unknown Network traffic detected: HTTP traffic on port 65382 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55208 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52514
Source: unknown Network traffic detected: HTTP traffic on port 55959 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58606 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49220
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56312
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52513
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56313
Source: unknown Network traffic detected: HTTP traffic on port 62794 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63489 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62788 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62791
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62792
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62793
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62794
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62795
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62796
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49219
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49218
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49217
Source: unknown Network traffic detected: HTTP traffic on port 62782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58481 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50352 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51586 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64509
Source: unknown Network traffic detected: HTTP traffic on port 63495 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50197 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56310 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63656
Source: unknown Network traffic detected: HTTP traffic on port 64509 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49219 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50353
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50352
Source: unknown Network traffic detected: HTTP traffic on port 59372 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56304 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51585 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65383 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58378 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58384 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49196 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62795 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51581
Source: unknown Network traffic detected: HTTP traffic on port 62789 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63656 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55210 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58379 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57966
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58387
Source: unknown Network traffic detected: HTTP traffic on port 49195 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58384
Source: unknown Network traffic detected: HTTP traffic on port 51587 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58383
Source: unknown Network traffic detected: HTTP traffic on port 58385 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58386
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58385
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58380
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58382
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58381
Source: unknown Network traffic detected: HTTP traffic on port 64214 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49220 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55958 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52514 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56303 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62793 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63491 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62787 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60588
Source: unknown Network traffic detected: HTTP traffic on port 62783 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55209
Source: unknown Network traffic detected: HTTP traffic on port 52513 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55207
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55208
Source: unknown Network traffic detected: HTTP traffic on port 56308 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62778
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55210
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62779
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55211
Source: unknown Network traffic detected: HTTP traffic on port 63490 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52909 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59372
Source: unknown Network traffic detected: HTTP traffic on port 56313 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65381
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65382
Source: unknown Network traffic detected: HTTP traffic on port 55209 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50196 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58609
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58608
Source: unknown Network traffic detected: HTTP traffic on port 58380 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65383
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62790
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56305
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56306
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58607
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56307
Source: unknown Network traffic detected: HTTP traffic on port 63496 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58606
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56308
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51412
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56301
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55212
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56302
Source: unknown Network traffic detected: HTTP traffic on port 51581 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56303
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56304
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62788
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62789
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56310
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56311
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62780
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62781
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62782
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62783
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62784
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62785
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62786
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62787
Source: unknown HTTPS traffic detected: 104.22.8.83:443 -> 192.168.2.3:50353 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.22.8.83:443 -> 192.168.2.3:50352 version: TLS 1.2
Source: unknown HTTPS traffic detected: 151.101.1.229:443 -> 192.168.2.3:63491 version: TLS 1.2
Source: unknown HTTPS traffic detected: 151.101.1.229:443 -> 192.168.2.3:63490 version: TLS 1.2
Source: classification engine Classification label: sus20.evad.win@34/238@16/9
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-60F75CB8-19CC.pma Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\27cb1a6e-8310-4266-9d33-6e0186e8b1a5.tmp Jump to behavior
Source: QuotaManager.0.dr Binary or memory string: CREATE TABLE HostQuotaTable(host TEXT NOT NULL, type INTEGER NOT NULL, quota INTEGER DEFAULT 0, UNIQUE(host, type));
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation --single-argument http://kiwifarms.net/
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1684,17103584337081238265,1050167775438477851,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1684,17103584337081238265,1050167775438477851,131072 --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4548 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1684,17103584337081238265,1050167775438477851,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1684,17103584337081238265,1050167775438477851,131072 --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4548 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs