Analysis Report https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINAL

Overview

General Information

Sample URL: https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINAL
Analysis ID: 339318

Most interesting Screenshot:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Source: unknown HTTPS traffic detected: 52.217.0.180:443 -> 192.168.2.5:49731 version: TLS 1.2
Source: unknown DNS traffic detected: queries for: survey.alchemer.com
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr, manifest.json0.0.dr String found in binary or memory: https://accounts.google.com
Source: 433ff0fc5a6cc6f8_0.0.dr String found in binary or memory: https://alchemer.com/
Source: 433ff0fc5a6cc6f8_0.0.dr String found in binary or memory: https://alchemer.com/P
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr, manifest.json0.0.dr String found in binary or memory: https://apis.google.com
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr String found in binary or memory: https://content-autofill.googleapis.com
Source: manifest.json0.0.dr String found in binary or memory: https://content.googleapis.com
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr, bdad2fd6-408b-4556-8bae-461793d5ebe2.tmp.2.dr, 982f410b-f4e1-4dd5-a547-84de14331441.tmp.2.dr String found in binary or memory: https://dns.google
Source: manifest.json0.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr String found in binary or memory: https://fonts.googleapis.com
Source: Network Action Predictor.0.dr String found in binary or memory: https://fonts.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: manifest.json0.0.dr String found in binary or memory: https://hangouts.google.com/
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr String found in binary or memory: https://r1---sn-4g5ednle.gvt1.com
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr String found in binary or memory: https://redirector.gvt1.com
Source: manifest.json.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr String found in binary or memory: https://ssl.gstatic.com
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr String found in binary or memory: https://survey.alchemer.com
Source: 000003.log0.0.dr String found in binary or memory: https://survey.alchemer.com/
Source: Current Session.0.dr, History.0.dr String found in binary or memory: https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINAL
Source: Current Session.0.dr String found in binary or memory: https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINAL#sg-skipnav-target
Source: History-journal.0.dr String found in binary or memory: https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINAL#sg-skipnav-targetCOVID
Source: Current Session.0.dr String found in binary or memory: https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINAL#sg-skipnav-target_
Source: History Provider Cache.0.dr String found in binary or memory: https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINAL2
Source: History-journal.0.dr String found in binary or memory: https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINALCOVID
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr String found in binary or memory: https://www.alchemer.com
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr, manifest.json0.0.dr String found in binary or memory: https://www.google.com
Source: manifest.json.0.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.google.com;
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: d452acba-5d11-483f-8d58-b71a6434702e.tmp.2.dr, 11f12588-057a-4850-b68d-fdb446f94a80.tmp.2.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://www.gstatic.com;
Source: Network Action Predictor.0.dr String found in binary or memory: https://www.surveygizmo.com/
Source: 433ff0fc5a6cc6f8_0.0.dr String found in binary or memory: https://www.surveygizmo.com/2021.01.12.01/runtimejs/dist/survey/js/survey.js
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49777 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown HTTPS traffic detected: 52.217.0.180:443 -> 192.168.2.5:49731 version: TLS 1.2
Source: classification engine Classification label: clean0.win@31/171@5/9
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5FFFCED9-CC8.pma Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\240e5f93-2001-466c-99ae-667c915ed273.tmp Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized 'https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINAL'
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1556,5521841523715785419,345617750357767133,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1692 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1556,5521841523715785419,345617750357767133,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1692 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 339318 URL: https://survey.alchemer.com... Startdate: 13/01/2021 Architecture: WINDOWS Score: 0 5 chrome.exe 14 398 2->5         started        dnsIp3 11 192.168.2.1 unknown unknown 5->11 13 239.255.255.250 unknown Reserved 5->13 8 chrome.exe 20 5->8         started        process4 dnsIp5 15 googlehosted.l.googleusercontent.com 108.177.126.132, 443, 49743 GOOGLEUS United States 8->15 17 survey.alchemer.com 13.224.94.105, 443, 49716, 49749 AMAZON-02US United States 8->17 19 11 other IPs or domains 8->19
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
18.221.77.186
unknown United States
16509 AMAZON-02US false
52.217.0.180
unknown United States
16509 AMAZON-02US false
13.224.94.105
unknown United States
16509 AMAZON-02US false
239.255.255.250
unknown Reserved
unknown unknown false
13.224.94.66
unknown United States
16509 AMAZON-02US false
108.177.126.132
unknown United States
15169 GOOGLEUS false

Private

IP
192.168.2.1
192.168.2.255
127.0.0.1

Contacted Domains

Name IP Active
s3-1-w.amazonaws.com 52.217.0.180 true
d3gvv5iecquak.cloudfront.net 13.224.94.66 true
survey.alchemer.com 13.224.94.105 true
cluster96-elbwpeel-u8fat1y76lys-241867217.us-east-2.elb.amazonaws.com 18.221.77.186 true
googlehosted.l.googleusercontent.com 108.177.126.132 true
clients2.googleusercontent.com unknown unknown
www.surveygizmo.com unknown unknown
surveygizmolibrary.s3.amazonaws.com unknown unknown
www.alchemer.com unknown unknown

Contacted URLs

Name Malicious Antivirus Detection Reputation
https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINAL false
    unknown
    https://survey.alchemer.com/s3/6136192/COVID-Impact-Survey-FINAL#sg-skipnav-target false
      unknown