Windows Analysis Report http://bit.ly/sex4ass

Overview

General Information

Sample URL: http://bit.ly/sex4ass
Analysis ID: 652

Most interesting Screenshot:

Detection

Porn Scam
Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected Porn Scam
Queries disk information (often used to detect virtual machines)
HTML body contains low number of good links
Tries to load missing DLLs
No HTML title found

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious

Phishing:

barindex
HTML body contains low number of good links
Source: https://tours.hushlove.com/902/?t=34460&aid=115443&sid=59435_1303537&xk=b04120f2a34cd5731806c91c826f1d69&bn=38&gu=http%3A%2F%2Fgo.moartraffic.com%2Fgo.php%3Ft%3D34460%26aid%3D115443%26sid%3D59435_1303537%26clickid%3Dlhtad6168d92e0004be23%26hts_id%3D4d75f029-c0c9-42ec-a8e5-269e774b290d&clickid=lhtad6168d92e0004be23&i18n_country=CH&hts_id=4d75f029-c0c9-42ec-a8e5-269e774b290d HTTP Parser: Number of links: 0
Source: https://tours.hushlove.com/902/?t=34460&aid=115443&sid=59435_1303537&xk=b04120f2a34cd5731806c91c826f1d69&bn=38&gu=http%3A%2F%2Fgo.moartraffic.com%2Fgo.php%3Ft%3D34460%26aid%3D115443%26sid%3D59435_1303537%26clickid%3Dlhtad6168d92e0004be23%26hts_id%3D4d75f029-c0c9-42ec-a8e5-269e774b290d&clickid=lhtad6168d92e0004be23&i18n_country=CH&hts_id=4d75f029-c0c9-42ec-a8e5-269e774b290d HTTP Parser: Number of links: 0
No HTML title found
Source: https://tours.hushlove.com/902/?t=34460&aid=115443&sid=59435_1303537&xk=b04120f2a34cd5731806c91c826f1d69&bn=38&gu=http%3A%2F%2Fgo.moartraffic.com%2Fgo.php%3Ft%3D34460%26aid%3D115443%26sid%3D59435_1303537%26clickid%3Dlhtad6168d92e0004be23%26hts_id%3D4d75f029-c0c9-42ec-a8e5-269e774b290d&clickid=lhtad6168d92e0004be23&i18n_country=CH&hts_id=4d75f029-c0c9-42ec-a8e5-269e774b290d HTTP Parser: HTML title missing
Source: https://tours.hushlove.com/902/?t=34460&aid=115443&sid=59435_1303537&xk=b04120f2a34cd5731806c91c826f1d69&bn=38&gu=http%3A%2F%2Fgo.moartraffic.com%2Fgo.php%3Ft%3D34460%26aid%3D115443%26sid%3D59435_1303537%26clickid%3Dlhtad6168d92e0004be23%26hts_id%3D4d75f029-c0c9-42ec-a8e5-269e774b290d&clickid=lhtad6168d92e0004be23&i18n_country=CH&hts_id=4d75f029-c0c9-42ec-a8e5-269e774b290d HTTP Parser: HTML title missing
Source: https://tours.hushlove.com/902/?t=34460&aid=115443&sid=59435_1303537&xk=b04120f2a34cd5731806c91c826f1d69&bn=38&gu=http%3A%2F%2Fgo.moartraffic.com%2Fgo.php%3Ft%3D34460%26aid%3D115443%26sid%3D59435_1303537%26clickid%3Dlhtad6168d92e0004be23%26hts_id%3D4d75f029-c0c9-42ec-a8e5-269e774b290d&clickid=lhtad6168d92e0004be23&i18n_country=CH&hts_id=4d75f029-c0c9-42ec-a8e5-269e774b290d HTTP Parser: No <meta name="author".. found
Source: https://tours.hushlove.com/902/?t=34460&aid=115443&sid=59435_1303537&xk=b04120f2a34cd5731806c91c826f1d69&bn=38&gu=http%3A%2F%2Fgo.moartraffic.com%2Fgo.php%3Ft%3D34460%26aid%3D115443%26sid%3D59435_1303537%26clickid%3Dlhtad6168d92e0004be23%26hts_id%3D4d75f029-c0c9-42ec-a8e5-269e774b290d&clickid=lhtad6168d92e0004be23&i18n_country=CH&hts_id=4d75f029-c0c9-42ec-a8e5-269e774b290d HTTP Parser: No <meta name="author".. found
Source: https://tours.hushlove.com/902/?t=34460&aid=115443&sid=59435_1303537&xk=b04120f2a34cd5731806c91c826f1d69&bn=38&gu=http%3A%2F%2Fgo.moartraffic.com%2Fgo.php%3Ft%3D34460%26aid%3D115443%26sid%3D59435_1303537%26clickid%3Dlhtad6168d92e0004be23%26hts_id%3D4d75f029-c0c9-42ec-a8e5-269e774b290d&clickid=lhtad6168d92e0004be23&i18n_country=CH&hts_id=4d75f029-c0c9-42ec-a8e5-269e774b290d HTTP Parser: No <meta name="copyright".. found
Source: https://tours.hushlove.com/902/?t=34460&aid=115443&sid=59435_1303537&xk=b04120f2a34cd5731806c91c826f1d69&bn=38&gu=http%3A%2F%2Fgo.moartraffic.com%2Fgo.php%3Ft%3D34460%26aid%3D115443%26sid%3D59435_1303537%26clickid%3Dlhtad6168d92e0004be23%26hts_id%3D4d75f029-c0c9-42ec-a8e5-269e774b290d&clickid=lhtad6168d92e0004be23&i18n_country=CH&hts_id=4d75f029-c0c9-42ec-a8e5-269e774b290d HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 143.204.98.12:443 -> 192.168.2.3:49547 version: TLS 1.2
Source: unknown HTTPS traffic detected: 143.204.98.12:443 -> 192.168.2.3:49546 version: TLS 1.2
Source: chrome.exe Memory has grown: Private usage: 1MB later: 24MB
Source: unknown DNS traffic detected: queries for: accounts.google.com
Source: unknown Network traffic detected: HTTP traffic on port 54150 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56954
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63929
Source: unknown Network traffic detected: HTTP traffic on port 63793 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63929 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49686 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61227
Source: unknown Network traffic detected: HTTP traffic on port 60328 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61946 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50641 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58022 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54309
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 51462 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49837 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49545 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65343 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64052 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50189
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54150
Source: unknown Network traffic detected: HTTP traffic on port 55927 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64506
Source: unknown Network traffic detected: HTTP traffic on port 60587 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49548 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 59010 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56148 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61871
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64467
Source: unknown Network traffic detected: HTTP traffic on port 54309 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49686
Source: unknown Network traffic detected: HTTP traffic on port 56230 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55927
Source: unknown Network traffic detected: HTTP traffic on port 53163 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55202 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50189 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63900 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52414
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53073
Source: unknown Network traffic detected: HTTP traffic on port 49793 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56585
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49837
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63941
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64506 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49793
Source: unknown Network traffic detected: HTTP traffic on port 57436 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49547 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 60091 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61026 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61227 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51055
Source: unknown Network traffic detected: HTTP traffic on port 59724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50641
Source: unknown Network traffic detected: HTTP traffic on port 58815 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59734
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57436
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63954
Source: unknown Network traffic detected: HTTP traffic on port 65112 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65485 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56513 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56230
Source: unknown Network traffic detected: HTTP traffic on port 64248 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63793
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64122
Source: unknown Network traffic detected: HTTP traffic on port 61530 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60328
Source: unknown Network traffic detected: HTTP traffic on port 50795 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61530
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64248
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49549
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49548
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49547
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49546
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49545
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65078
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 63075 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65472
Source: unknown Network traffic detected: HTTP traffic on port 56954 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51462
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58815
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59624
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56513
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51195
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61946
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58383
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63609
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58022
Source: unknown Network traffic detected: HTTP traffic on port 52073 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64122 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65343
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63960
Source: unknown Network traffic detected: HTTP traffic on port 49252 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49627 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61026
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65485
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49252
Source: unknown Network traffic detected: HTTP traffic on port 51195 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63960 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57214
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53776
Source: unknown Network traffic detected: HTTP traffic on port 56585 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60587
Source: unknown Network traffic detected: HTTP traffic on port 65078 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60582
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64026
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65112
Source: unknown Network traffic detected: HTTP traffic on port 63954 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59624 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52414 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49546 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53073 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65252
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63075
Source: unknown Network traffic detected: HTTP traffic on port 58383 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65472 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50795
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55202
Source: unknown Network traffic detected: HTTP traffic on port 64467 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63900
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60631
Source: unknown Network traffic detected: HTTP traffic on port 57214 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63609 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59010
Source: unknown Network traffic detected: HTTP traffic on port 60582 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49549 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61681
Source: unknown Network traffic detected: HTTP traffic on port 54640 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61871 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51055 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64052
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54640
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60091
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56148
Source: unknown Network traffic detected: HTTP traffic on port 63941 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 60631 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53163
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52073
Source: unknown Network traffic detected: HTTP traffic on port 64026 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49627
Source: unknown Network traffic detected: HTTP traffic on port 61681 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65252 -> 443
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: unknown TCP traffic detected without corresponding DNS query: 2.21.142.245
Source: global traffic HTTP traffic detected: GET /sex4ass HTTP/1.1Host: bit.lyConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /sex4ass HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: en-US,en;q=0.5Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.18363Accept-Encoding: gzip, deflateHost: bit.lyConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /sex4ass HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: en-US,en;q=0.5Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.18363Accept-Encoding: gzip, deflateHost: bit.lyConnection: Keep-AliveCookie: _bit=l9f1ro-b21edf69b1af5009c0-00A
Source: unknown HTTPS traffic detected: 143.204.98.12:443 -> 192.168.2.3:49547 version: TLS 1.2
Source: unknown HTTPS traffic detected: 143.204.98.12:443 -> 192.168.2.3:49546 version: TLS 1.2

Spam, unwanted Advertisements and Ransom Demands:

barindex
Yara detected Porn Scam
Source: Yara match File source: 85279.3.pages.csv, type: HTML

System Summary:

barindex
Tries to load missing DLLs
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Section loaded: icuuc.dll
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Section loaded: icuin.dll
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Section loaded: icuuc.dll
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Section loaded: icuin.dll
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Section loaded: icuuc.dll
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Section loaded: icuin.dll
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Section loaded: icuuc.dll
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Section loaded: icuin.dll
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\alfredo\AppData\Local\Temp\fb1b5425-b6ab-408f-b05c-8f33d065e767.tmp
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: classification engine Classification label: mal48.phis.win@56/153@42/237
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation --single-argument http://bit.ly/sex4ass
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1696,3818573255597981772,7157584305214687754,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 /prefetch:8
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe 'C:\Windows\System32\MicrosoftEdgeCP.exe' -ServerName:Windows.Internal.WebRuntime.ContentProcessServer
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe 'C:\Windows\System32\MicrosoftEdgeCP.exe' -ServerName:Windows.Internal.WebRuntime.ContentProcessServer
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1696,3818573255597981772,7157584305214687754,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe 'C:\Windows\System32\MicrosoftEdgeCP.exe' -ServerName:Windows.Internal.WebRuntime.ContentProcessServer
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe 'C:\Windows\System32\MicrosoftEdgeCP.exe' -ServerName:Windows.Internal.WebRuntime.ContentProcessServer
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe 'C:\Windows\System32\MicrosoftEdgeCP.exe' -ServerName:Windows.Internal.WebRuntime.ContentProcessServer
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe 'C:\Windows\System32\MicrosoftEdgeCP.exe' -ServerName:Windows.Internal.WebRuntime.ContentProcessServer
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe 'C:\Windows\System32\MicrosoftEdgeCP.exe' -ServerName:Windows.Internal.WebRuntime.ContentProcessServer
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe 'C:\Windows\System32\MicrosoftEdgeCP.exe' -ServerName:Windows.Internal.WebRuntime.ContentProcessServer
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe 'C:\Windows\System32\MicrosoftEdgeCP.exe' -ServerName:Windows.Internal.WebRuntime.ContentProcessServer
Source: unknown Process created: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe 'C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe' -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1632,15554398161899842066,18166183983483826829,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1992 /prefetch:8
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeSH.exe C:\Windows\system32\MicrosoftEdgeSH.exe SCODEF:2044 CREDAT:9730 APH:1000000000000003 JITHOST /prefetch:2
Source: unknown Process created: C:\Windows\System32\MicrosoftEdgeCP.exe 'C:\Windows\System32\MicrosoftEdgeCP.exe' -ServerName:Windows.Internal.WebRuntime.ContentProcessServer
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1632,15554398161899842066,18166183983483826829,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1992 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InProcServer32
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-61695757-1290.pma
Source: Window Recorder Window detected: More than 3 window changes detected

Malware Analysis System Evasion:

barindex
Queries disk information (often used to detect virtual machines)
Source: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe File opened: PhysicalDrive22
Source: C:\Windows\System32\MicrosoftEdgeCP.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs