Analysis Report https://lb.artipbox.net/adServer/Service.svc/sync?uuids=UVJacWtMV1hpL0tnM0FDS2tjN2xTbnhqZEo1YWkzZDRvRjZ5YnJCZzFZbkp3NDRlU3Jhc3JZbTRxWGN5TXVNcyxRUlpxa0xXWGkvS2czQUNLa2M3bFNueGpkSjVhaTNkNG9GNnlickJnMVluSnc0NGVTcmFzclltNHFYY3lNdU1z&t=1606644641953

Overview

General Information

Sample URL: https://lb.artipbox.net/adServer/Service.svc/sync?uuids=UVJacWtMV1hpL0tnM0FDS2tjN2xTbnhqZEo1YWkzZDRvRjZ5YnJCZzFZbkp3NDRlU3Jhc3JZbTRxWGN5TXVNcyxRUlpxa0xXWGkvS2czQUNLa2M3bFNueGpkSjVhaTNkNG9GNnlickJnMVluSnc0NGVTcmFzclltNHFYY3lNdU1z&t=1606644641953
Analysis ID: 324347

Most interesting Screenshot:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: unknown DNS traffic detected: queries for: lb.artipbox.net
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr, manifest.json0.0.dr String found in binary or memory: https://accounts.google.com
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr, manifest.json0.0.dr String found in binary or memory: https://apis.google.com
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: manifest.json0.0.dr String found in binary or memory: https://content.googleapis.com
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr, a6676356-829e-47a6-abfd-985f31e20c33.tmp.1.dr, 7633e7e8-f178-4d87-b79a-6500afed1d72.tmp.1.dr String found in binary or memory: https://dns.google
Source: manifest.json0.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: manifest.json0.0.dr String found in binary or memory: https://hangouts.google.com/
Source: History.0.dr String found in binary or memory: https://lb.artipbox.net/adServer/Service.svc/sync?uuids=UVJacWtMV1hpL0tnM0FDS2tjN2xTbnhqZEo1YWkzZDRv
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr String found in binary or memory: https://play.google.com
Source: manifest.json.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr String found in binary or memory: https://ssl.gstatic.com
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr, manifest.json0.0.dr String found in binary or memory: https://www.google.com
Source: manifest.json.0.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.google.com;
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 78534e51-9ab1-4a08-8e2e-e3d7ddbf0fa0.tmp.1.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://www.gstatic.com;
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: classification engine Classification label: clean0.win@27/159@2/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5FC3FA7F-12B8.pma Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\a882b7e5-502f-4c3d-991b-a32966285613.tmp Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized 'https://lb.artipbox.net/adServer/Service.svc/sync?uuids=UVJacWtMV1hpL0tnM0FDS2tjN2xTbnhqZEo1YWkzZDRvRjZ5YnJCZzFZbkp3NDRlU3Jhc3JZbTRxWGN5TXVNcyxRUlpxa0xXWGkvS2czQUNLa2M3bFNueGpkSjVhaTNkNG9GNnlickJnMVluSnc0NGVTcmFzclltNHFYY3lNdU1z&t=1606644641953'
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1540,5898755889624346109,3772175596100600458,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1708 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1540,5898755889624346109,3772175596100600458,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1708 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 324347 URL: https://lb.artipbox.net/adS... Startdate: 29/11/2020 Architecture: WINDOWS Score: 0 5 chrome.exe 15 381 2->5         started        dnsIp3 11 192.168.2.1 unknown unknown 5->11 13 239.255.255.250 unknown Reserved 5->13 8 chrome.exe 15 5->8         started        process4 dnsIp5 15 googlehosted.l.googleusercontent.com 216.58.215.225, 443, 49733 GOOGLEUS United States 8->15 17 uk-lb-ad-01-1088271668.eu-west-1.elb.amazonaws.com 34.240.67.55, 443, 49714, 49716 AMAZON-02US United States 8->17 19 3 other IPs or domains 8->19
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
34.240.67.55
unknown United States
16509 AMAZON-02US false
216.58.215.225
unknown United States
15169 GOOGLEUS false
239.255.255.250
unknown Reserved
unknown unknown false

Private

IP
192.168.2.1
127.0.0.1

Contacted Domains

Name IP Active
uk-lb-ad-01-1088271668.eu-west-1.elb.amazonaws.com 34.240.67.55 true
googlehosted.l.googleusercontent.com 216.58.215.225 true
clients2.googleusercontent.com unknown unknown
lb.artipbox.net unknown unknown