Edit tour

Windows Analysis Report
http://contact@t.brevo.com

Overview

General Information

Sample URL:http://contact@t.brevo.com
Analysis ID:1387005
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

URL contains potential PII (phishing indication)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 4488 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4412 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2536 --field-trial-handle=2296,i,7383919434186168815,13523271778941481687,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6580 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://contact@t.brevo.com MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://contact@t.brevo.comSample URL: PII: contact@t.brevo.com
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: classification engineClassification label: unknown0.win@19/0@16/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2536 --field-trial-handle=2296,i,7383919434186168815,13523271778941481687,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://contact@t.brevo.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2536 --field-trial-handle=2296,i,7383919434186168815,13523271778941481687,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1387005 URL: http://contact@t.brevo.com Startdate: 05/02/2024 Architecture: WINDOWS Score: 0 14 t.brevo.com 2->14 16 fp2e7a.wpc.phicdn.net 2->16 18 fp2e7a.wpc.2be4.phicdn.net 2->18 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 20 192.168.2.4, 138, 443, 49292 unknown unknown 6->20 22 239.255.255.250 unknown Reserved 6->22 11 chrome.exe 6->11         started        process5 dnsIp6 24 clients.l.google.com 142.250.9.100, 443, 49730 GOOGLEUS United States 11->24 26 accounts.google.com 64.233.176.84, 443, 49731 GOOGLEUS United States 11->26 28 4 other IPs or domains 11->28

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://contact@t.brevo.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.253.126.101
truefalse
    high
    accounts.google.com
    64.233.176.84
    truefalse
      high
      www.google.com
      64.233.185.103
      truefalse
        high
        clients.l.google.com
        142.250.9.100
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            clients2.google.com
            unknown
            unknownfalse
              high
              t.brevo.com
              unknown
              unknownfalse
                unknown
                NameMaliciousAntivirus DetectionReputation
                https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                  high
                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    64.233.176.84
                    accounts.google.comUnited States
                    15169GOOGLEUSfalse
                    142.250.9.100
                    clients.l.google.comUnited States
                    15169GOOGLEUSfalse
                    64.233.185.103
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.4
                    Joe Sandbox version:39.0.0 Ruby
                    Analysis ID:1387005
                    Start date and time:2024-02-05 18:13:12 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 2m 1s
                    Hypervisor based Inspection enabled:false
                    Report type:light
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://contact@t.brevo.com
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:5
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:UNKNOWN
                    Classification:unknown0.win@19/0@16/5
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    Cookbook Comments:
                    • URL browsing timeout or error
                    • URL not reachable
                    • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 64.233.177.94, 34.104.35.123, 23.63.206.91, 20.12.23.50, 23.40.205.73, 23.40.205.43, 23.40.205.19, 23.40.205.40, 23.40.205.51, 23.40.205.67, 23.40.205.74, 23.40.205.59, 23.40.205.34, 20.242.39.171, 192.229.211.108
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtOpenFile calls found.
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: http://contact@t.brevo.com
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    No created / dropped files found
                    No static file info
                    • Total Packets: 49
                    • 443 (HTTPS)
                    • 53 (DNS)
                    TimestampSource PortDest PortSource IPDest IP
                    Feb 5, 2024 18:13:59.652002096 CET49675443192.168.2.4173.222.162.32
                    Feb 5, 2024 18:14:06.367054939 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.367091894 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:06.367149115 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.367728949 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.367737055 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:06.368647099 CET49731443192.168.2.464.233.176.84
                    Feb 5, 2024 18:14:06.368685007 CET4434973164.233.176.84192.168.2.4
                    Feb 5, 2024 18:14:06.368735075 CET49731443192.168.2.464.233.176.84
                    Feb 5, 2024 18:14:06.369450092 CET49731443192.168.2.464.233.176.84
                    Feb 5, 2024 18:14:06.369469881 CET4434973164.233.176.84192.168.2.4
                    Feb 5, 2024 18:14:06.592993975 CET4434973164.233.176.84192.168.2.4
                    Feb 5, 2024 18:14:06.593219995 CET49731443192.168.2.464.233.176.84
                    Feb 5, 2024 18:14:06.593244076 CET4434973164.233.176.84192.168.2.4
                    Feb 5, 2024 18:14:06.594760895 CET4434973164.233.176.84192.168.2.4
                    Feb 5, 2024 18:14:06.594821930 CET49731443192.168.2.464.233.176.84
                    Feb 5, 2024 18:14:06.596096039 CET49731443192.168.2.464.233.176.84
                    Feb 5, 2024 18:14:06.596170902 CET4434973164.233.176.84192.168.2.4
                    Feb 5, 2024 18:14:06.596297026 CET49731443192.168.2.464.233.176.84
                    Feb 5, 2024 18:14:06.596313000 CET4434973164.233.176.84192.168.2.4
                    Feb 5, 2024 18:14:06.611534119 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:06.611722946 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.611732006 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:06.612142086 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:06.612205982 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.612893105 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:06.612940073 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.614013910 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.614118099 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:06.614180088 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.614187956 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:06.746665955 CET49731443192.168.2.464.233.176.84
                    Feb 5, 2024 18:14:06.760031939 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.813713074 CET4434973164.233.176.84192.168.2.4
                    Feb 5, 2024 18:14:06.813849926 CET4434973164.233.176.84192.168.2.4
                    Feb 5, 2024 18:14:06.813894987 CET49731443192.168.2.464.233.176.84
                    Feb 5, 2024 18:14:06.815016031 CET49731443192.168.2.464.233.176.84
                    Feb 5, 2024 18:14:06.815032959 CET4434973164.233.176.84192.168.2.4
                    Feb 5, 2024 18:14:06.854789019 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:06.854927063 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:06.854979038 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.855463982 CET49730443192.168.2.4142.250.9.100
                    Feb 5, 2024 18:14:06.855479002 CET44349730142.250.9.100192.168.2.4
                    Feb 5, 2024 18:14:09.193783998 CET49736443192.168.2.464.233.185.103
                    Feb 5, 2024 18:14:09.193825960 CET4434973664.233.185.103192.168.2.4
                    Feb 5, 2024 18:14:09.193928957 CET49736443192.168.2.464.233.185.103
                    Feb 5, 2024 18:14:09.194314003 CET49736443192.168.2.464.233.185.103
                    Feb 5, 2024 18:14:09.194336891 CET4434973664.233.185.103192.168.2.4
                    Feb 5, 2024 18:14:09.264504910 CET49675443192.168.2.4173.222.162.32
                    Feb 5, 2024 18:14:09.408484936 CET4434973664.233.185.103192.168.2.4
                    Feb 5, 2024 18:14:09.408925056 CET49736443192.168.2.464.233.185.103
                    Feb 5, 2024 18:14:09.408952951 CET4434973664.233.185.103192.168.2.4
                    Feb 5, 2024 18:14:09.409827948 CET4434973664.233.185.103192.168.2.4
                    Feb 5, 2024 18:14:09.409910917 CET49736443192.168.2.464.233.185.103
                    Feb 5, 2024 18:14:09.411236048 CET49736443192.168.2.464.233.185.103
                    Feb 5, 2024 18:14:09.411295891 CET4434973664.233.185.103192.168.2.4
                    Feb 5, 2024 18:14:09.466998100 CET49736443192.168.2.464.233.185.103
                    Feb 5, 2024 18:14:09.467025042 CET4434973664.233.185.103192.168.2.4
                    Feb 5, 2024 18:14:09.511562109 CET49736443192.168.2.464.233.185.103
                    Feb 5, 2024 18:14:19.407655954 CET4434973664.233.185.103192.168.2.4
                    Feb 5, 2024 18:14:19.407720089 CET4434973664.233.185.103192.168.2.4
                    Feb 5, 2024 18:14:19.407805920 CET49736443192.168.2.464.233.185.103
                    Feb 5, 2024 18:14:20.489758968 CET49736443192.168.2.464.233.185.103
                    Feb 5, 2024 18:14:20.489777088 CET4434973664.233.185.103192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Feb 5, 2024 18:14:06.248397112 CET5141353192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:06.248764038 CET4929253192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:06.249408960 CET6031753192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:06.249655962 CET6283053192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:06.344888926 CET53579051.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:06.365953922 CET53514131.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:06.366242886 CET53492921.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:06.366653919 CET53603171.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:06.367414951 CET53628301.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:07.019124985 CET53542101.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:07.993098021 CET6393953192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:07.993350983 CET6072953192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:08.113436937 CET53639391.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:08.114017963 CET53607291.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:08.114736080 CET5310053192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:08.235604048 CET53531001.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:08.267858028 CET6009353192.168.2.48.8.8.8
                    Feb 5, 2024 18:14:08.268421888 CET6486053192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:08.371628046 CET53600938.8.8.8192.168.2.4
                    Feb 5, 2024 18:14:08.386138916 CET53648601.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:09.074373007 CET5313853192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:09.074579000 CET5927153192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:09.191896915 CET53592711.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:09.191945076 CET53531381.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:09.278770924 CET6404353192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:09.279258966 CET5638853192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:09.399205923 CET53563881.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:09.400125980 CET53640431.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:14.569617987 CET6532653192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:14.570055962 CET5779653192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:14.690080881 CET53653261.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:14.690412998 CET53577961.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:14.691133022 CET5674653192.168.2.41.1.1.1
                    Feb 5, 2024 18:14:14.813812971 CET53567461.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:24.099020004 CET53516641.1.1.1192.168.2.4
                    Feb 5, 2024 18:14:25.735162973 CET138138192.168.2.4192.168.2.255
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Feb 5, 2024 18:14:06.248397112 CET192.168.2.41.1.1.10x8f7dStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:06.248764038 CET192.168.2.41.1.1.10x50bbStandard query (0)clients2.google.com65IN (0x0001)false
                    Feb 5, 2024 18:14:06.249408960 CET192.168.2.41.1.1.10x82a1Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:06.249655962 CET192.168.2.41.1.1.10x26f9Standard query (0)accounts.google.com65IN (0x0001)false
                    Feb 5, 2024 18:14:07.993098021 CET192.168.2.41.1.1.10x899bStandard query (0)t.brevo.comA (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:07.993350983 CET192.168.2.41.1.1.10xa95bStandard query (0)t.brevo.com65IN (0x0001)false
                    Feb 5, 2024 18:14:08.114736080 CET192.168.2.41.1.1.10x62dStandard query (0)t.brevo.comA (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.267858028 CET192.168.2.48.8.8.80x13e7Standard query (0)google.comA (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.268421888 CET192.168.2.41.1.1.10x611fStandard query (0)google.comA (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:09.074373007 CET192.168.2.41.1.1.10x2152Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:09.074579000 CET192.168.2.41.1.1.10x2deeStandard query (0)www.google.com65IN (0x0001)false
                    Feb 5, 2024 18:14:09.278770924 CET192.168.2.41.1.1.10x5d72Standard query (0)t.brevo.comA (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:09.279258966 CET192.168.2.41.1.1.10xbf49Standard query (0)t.brevo.com65IN (0x0001)false
                    Feb 5, 2024 18:14:14.569617987 CET192.168.2.41.1.1.10xb1efStandard query (0)t.brevo.comA (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:14.570055962 CET192.168.2.41.1.1.10x7bb4Standard query (0)t.brevo.com65IN (0x0001)false
                    Feb 5, 2024 18:14:14.691133022 CET192.168.2.41.1.1.10xfe0aStandard query (0)t.brevo.comA (IP address)IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Feb 5, 2024 18:14:06.365953922 CET1.1.1.1192.168.2.40x8f7dNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Feb 5, 2024 18:14:06.365953922 CET1.1.1.1192.168.2.40x8f7dNo error (0)clients.l.google.com142.250.9.100A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:06.365953922 CET1.1.1.1192.168.2.40x8f7dNo error (0)clients.l.google.com142.250.9.139A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:06.365953922 CET1.1.1.1192.168.2.40x8f7dNo error (0)clients.l.google.com142.250.9.138A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:06.365953922 CET1.1.1.1192.168.2.40x8f7dNo error (0)clients.l.google.com142.250.9.102A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:06.365953922 CET1.1.1.1192.168.2.40x8f7dNo error (0)clients.l.google.com142.250.9.113A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:06.365953922 CET1.1.1.1192.168.2.40x8f7dNo error (0)clients.l.google.com142.250.9.101A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:06.366242886 CET1.1.1.1192.168.2.40x50bbNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Feb 5, 2024 18:14:06.366653919 CET1.1.1.1192.168.2.40x82a1No error (0)accounts.google.com64.233.176.84A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.371628046 CET8.8.8.8192.168.2.40x13e7No error (0)google.com172.253.126.101A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.371628046 CET8.8.8.8192.168.2.40x13e7No error (0)google.com172.253.126.100A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.371628046 CET8.8.8.8192.168.2.40x13e7No error (0)google.com172.253.126.113A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.371628046 CET8.8.8.8192.168.2.40x13e7No error (0)google.com172.253.126.102A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.371628046 CET8.8.8.8192.168.2.40x13e7No error (0)google.com172.253.126.139A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.371628046 CET8.8.8.8192.168.2.40x13e7No error (0)google.com172.253.126.138A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.386138916 CET1.1.1.1192.168.2.40x611fNo error (0)google.com142.250.9.100A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.386138916 CET1.1.1.1192.168.2.40x611fNo error (0)google.com142.250.9.138A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.386138916 CET1.1.1.1192.168.2.40x611fNo error (0)google.com142.250.9.139A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.386138916 CET1.1.1.1192.168.2.40x611fNo error (0)google.com142.250.9.101A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.386138916 CET1.1.1.1192.168.2.40x611fNo error (0)google.com142.250.9.113A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:08.386138916 CET1.1.1.1192.168.2.40x611fNo error (0)google.com142.250.9.102A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:09.191896915 CET1.1.1.1192.168.2.40x2deeNo error (0)www.google.com65IN (0x0001)false
                    Feb 5, 2024 18:14:09.191945076 CET1.1.1.1192.168.2.40x2152No error (0)www.google.com64.233.185.103A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:09.191945076 CET1.1.1.1192.168.2.40x2152No error (0)www.google.com64.233.185.99A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:09.191945076 CET1.1.1.1192.168.2.40x2152No error (0)www.google.com64.233.185.106A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:09.191945076 CET1.1.1.1192.168.2.40x2152No error (0)www.google.com64.233.185.104A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:09.191945076 CET1.1.1.1192.168.2.40x2152No error (0)www.google.com64.233.185.147A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:09.191945076 CET1.1.1.1192.168.2.40x2152No error (0)www.google.com64.233.185.105A (IP address)IN (0x0001)false
                    Feb 5, 2024 18:14:23.930926085 CET1.1.1.1192.168.2.40x3e91No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Feb 5, 2024 18:14:23.930926085 CET1.1.1.1192.168.2.40x3e91No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    • accounts.google.com
                    • clients2.google.com
                    All data are 0.

                    Target ID:0
                    Start time:18:14:01
                    Start date:05/02/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                    Target ID:2
                    Start time:18:14:03
                    Start date:05/02/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2536 --field-trial-handle=2296,i,7383919434186168815,13523271778941481687,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                    Target ID:3
                    Start time:18:14:07
                    Start date:05/02/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://contact@t.brevo.com
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly