Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.deutschepost-gefolgt.com/

Overview

General Information

Sample URL:https://www.deutschepost-gefolgt.com/
Analysis ID:1405718
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 4192 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5856 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2208,i,9327621530216998631,12272357097468982883,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6512 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.deutschepost-gefolgt.com/ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://www.deutschepost-gefolgt.com/Avira URL Cloud: detection malicious, Label: phishing
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.deutschepost-gefolgt.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.deutschepost-gefolgt.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.deutschepost-gefolgt.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: www.deutschepost-gefolgt.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: mal48.win@19/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2208,i,9327621530216998631,12272357097468982883,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.deutschepost-gefolgt.com/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2208,i,9327621530216998631,12272357097468982883,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.deutschepost-gefolgt.com/1%VirustotalBrowse
https://www.deutschepost-gefolgt.com/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.251.2.147
truefalse
    high
    www.deutschepost-gefolgt.com
    193.143.1.54
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalseunknown
      NameMaliciousAntivirus DetectionReputation
      https://www.deutschepost-gefolgt.com/true
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        193.143.1.54
        www.deutschepost-gefolgt.comunknown
        57271BITWEB-ASRUfalse
        142.251.2.147
        www.google.comUnited States
        15169GOOGLEUSfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        IP
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1405718
        Start date and time:2024-03-09 02:00:28 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 4s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://www.deutschepost-gefolgt.com/
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:5
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal48.win@19/0@4/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 74.125.137.94, 142.251.2.138, 142.251.2.102, 142.251.2.100, 142.251.2.139, 142.251.2.101, 142.251.2.113, 142.251.2.84, 34.104.35.123, 23.66.177.182, 40.68.123.157, 23.206.229.80, 23.206.229.76, 20.242.39.171, 192.229.211.108
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Mar 9, 2024 02:01:14.633742094 CET49675443192.168.2.4173.222.162.32
        Mar 9, 2024 02:01:24.241897106 CET49675443192.168.2.4173.222.162.32
        Mar 9, 2024 02:01:25.348391056 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:25.348443031 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:25.348504066 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:25.348957062 CET49735443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:25.348997116 CET44349735193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:25.349046946 CET49735443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:25.349318027 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:25.349339962 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:25.349565029 CET49735443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:25.349575996 CET44349735193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.133462906 CET44349735193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.133996010 CET49735443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.134026051 CET44349735193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.134135962 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.134310007 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.134336948 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.135065079 CET44349735193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.135126114 CET49735443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.135824919 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.135895967 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.136540890 CET49735443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.136626005 CET44349735193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.137630939 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.137742996 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.137748957 CET49735443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.137763977 CET44349735193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.181751013 CET49735443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.181762934 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.181813002 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.227979898 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.877947092 CET44349735193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.878062963 CET44349735193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.878129005 CET49735443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.879021883 CET49735443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:26.879050016 CET44349735193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:26.923783064 CET49738443192.168.2.4142.251.2.147
        Mar 9, 2024 02:01:26.923858881 CET44349738142.251.2.147192.168.2.4
        Mar 9, 2024 02:01:26.923938036 CET49738443192.168.2.4142.251.2.147
        Mar 9, 2024 02:01:26.948970079 CET49738443192.168.2.4142.251.2.147
        Mar 9, 2024 02:01:26.949007988 CET44349738142.251.2.147192.168.2.4
        Mar 9, 2024 02:01:27.314286947 CET44349738142.251.2.147192.168.2.4
        Mar 9, 2024 02:01:27.314997911 CET49738443192.168.2.4142.251.2.147
        Mar 9, 2024 02:01:27.315025091 CET44349738142.251.2.147192.168.2.4
        Mar 9, 2024 02:01:27.316095114 CET44349738142.251.2.147192.168.2.4
        Mar 9, 2024 02:01:27.316163063 CET49738443192.168.2.4142.251.2.147
        Mar 9, 2024 02:01:27.318932056 CET49738443192.168.2.4142.251.2.147
        Mar 9, 2024 02:01:27.319035053 CET44349738142.251.2.147192.168.2.4
        Mar 9, 2024 02:01:27.361123085 CET49738443192.168.2.4142.251.2.147
        Mar 9, 2024 02:01:27.361143112 CET44349738142.251.2.147192.168.2.4
        Mar 9, 2024 02:01:27.413316011 CET49738443192.168.2.4142.251.2.147
        Mar 9, 2024 02:01:28.021410942 CET49739443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:28.021464109 CET44349739193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:28.021524906 CET49739443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:28.022171021 CET49739443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:28.022190094 CET44349739193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:28.064848900 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:28.112248898 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:28.488122940 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:28.488373995 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:28.488440990 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:28.488934040 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:28.488959074 CET44349734193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:28.488970995 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:28.488998890 CET49734443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:28.782656908 CET44349739193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:28.783096075 CET49739443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:28.783123016 CET44349739193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:28.783620119 CET44349739193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:28.784847975 CET49739443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:28.785017014 CET44349739193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:28.836289883 CET49739443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:33.574960947 CET49742443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:33.575018883 CET44349742193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:33.575103998 CET49742443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:33.575644970 CET49742443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:33.575661898 CET44349742193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:33.588952065 CET49739443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:33.636236906 CET44349739193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:34.026073933 CET44349739193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:34.026176929 CET44349739193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:34.027720928 CET49739443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:34.027755022 CET44349739193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:34.027790070 CET49739443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:34.028127909 CET49739443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:34.336083889 CET44349742193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:34.337068081 CET49742443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:34.337145090 CET44349742193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:34.337682009 CET44349742193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:34.357109070 CET49742443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:34.357321024 CET44349742193.143.1.54192.168.2.4
        Mar 9, 2024 02:01:34.403556108 CET49742443192.168.2.4193.143.1.54
        Mar 9, 2024 02:01:37.301229000 CET49672443192.168.2.4173.222.162.32
        Mar 9, 2024 02:01:37.301271915 CET44349672173.222.162.32192.168.2.4
        Mar 9, 2024 02:01:37.315798998 CET44349738142.251.2.147192.168.2.4
        Mar 9, 2024 02:01:37.315875053 CET44349738142.251.2.147192.168.2.4
        Mar 9, 2024 02:01:37.315932989 CET49738443192.168.2.4142.251.2.147
        Mar 9, 2024 02:01:37.956309080 CET49738443192.168.2.4142.251.2.147
        Mar 9, 2024 02:01:37.956346989 CET44349738142.251.2.147192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Mar 9, 2024 02:01:23.801142931 CET53557501.1.1.1192.168.2.4
        Mar 9, 2024 02:01:23.918015003 CET53606871.1.1.1192.168.2.4
        Mar 9, 2024 02:01:24.733277082 CET4957653192.168.2.41.1.1.1
        Mar 9, 2024 02:01:24.733428955 CET5881753192.168.2.41.1.1.1
        Mar 9, 2024 02:01:25.219281912 CET53579371.1.1.1192.168.2.4
        Mar 9, 2024 02:01:25.347260952 CET53495761.1.1.1192.168.2.4
        Mar 9, 2024 02:01:25.347548008 CET53588171.1.1.1192.168.2.4
        Mar 9, 2024 02:01:26.747359037 CET5298653192.168.2.41.1.1.1
        Mar 9, 2024 02:01:26.747824907 CET5995353192.168.2.41.1.1.1
        Mar 9, 2024 02:01:26.902381897 CET53529861.1.1.1192.168.2.4
        Mar 9, 2024 02:01:26.902657986 CET53599531.1.1.1192.168.2.4
        Mar 9, 2024 02:01:41.115577936 CET138138192.168.2.4192.168.2.255
        Mar 9, 2024 02:01:42.836899042 CET53546521.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Mar 9, 2024 02:01:24.733277082 CET192.168.2.41.1.1.10xf221Standard query (0)www.deutschepost-gefolgt.comA (IP address)IN (0x0001)false
        Mar 9, 2024 02:01:24.733428955 CET192.168.2.41.1.1.10x32a3Standard query (0)www.deutschepost-gefolgt.com65IN (0x0001)false
        Mar 9, 2024 02:01:26.747359037 CET192.168.2.41.1.1.10x5f0cStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Mar 9, 2024 02:01:26.747824907 CET192.168.2.41.1.1.10x713dStandard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Mar 9, 2024 02:01:25.347260952 CET1.1.1.1192.168.2.40xf221No error (0)www.deutschepost-gefolgt.com193.143.1.54A (IP address)IN (0x0001)false
        Mar 9, 2024 02:01:26.902381897 CET1.1.1.1192.168.2.40x5f0cNo error (0)www.google.com142.251.2.147A (IP address)IN (0x0001)false
        Mar 9, 2024 02:01:26.902381897 CET1.1.1.1192.168.2.40x5f0cNo error (0)www.google.com142.251.2.99A (IP address)IN (0x0001)false
        Mar 9, 2024 02:01:26.902381897 CET1.1.1.1192.168.2.40x5f0cNo error (0)www.google.com142.251.2.105A (IP address)IN (0x0001)false
        Mar 9, 2024 02:01:26.902381897 CET1.1.1.1192.168.2.40x5f0cNo error (0)www.google.com142.251.2.104A (IP address)IN (0x0001)false
        Mar 9, 2024 02:01:26.902381897 CET1.1.1.1192.168.2.40x5f0cNo error (0)www.google.com142.251.2.106A (IP address)IN (0x0001)false
        Mar 9, 2024 02:01:26.902381897 CET1.1.1.1192.168.2.40x5f0cNo error (0)www.google.com142.251.2.103A (IP address)IN (0x0001)false
        Mar 9, 2024 02:01:26.902657986 CET1.1.1.1192.168.2.40x713dNo error (0)www.google.com65IN (0x0001)false
        Mar 9, 2024 02:01:40.229985952 CET1.1.1.1192.168.2.40x5467No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Mar 9, 2024 02:01:40.229985952 CET1.1.1.1192.168.2.40x5467No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        • www.deutschepost-gefolgt.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449735193.143.1.544435856C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-03-09 01:01:26 UTC671OUTGET / HTTP/1.1
        Host: www.deutschepost-gefolgt.com
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2024-03-09 01:01:26 UTC167INHTTP/1.1 500 Internal Server Error
        Server: nginx
        Date: Sat, 09 Mar 2024 01:01:26 GMT
        Content-Type: application/x-httpd-php
        Content-Length: 0
        Connection: close


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449734193.143.1.544435856C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-03-09 01:01:28 UTC697OUTGET / HTTP/1.1
        Host: www.deutschepost-gefolgt.com
        Connection: keep-alive
        Cache-Control: max-age=0
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2024-03-09 01:01:28 UTC167INHTTP/1.1 500 Internal Server Error
        Server: nginx
        Date: Sat, 09 Mar 2024 01:01:28 GMT
        Content-Type: application/x-httpd-php
        Content-Length: 0
        Connection: close


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.449739193.143.1.544435856C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-03-09 01:01:33 UTC697OUTGET / HTTP/1.1
        Host: www.deutschepost-gefolgt.com
        Connection: keep-alive
        Cache-Control: max-age=0
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2024-03-09 01:01:34 UTC167INHTTP/1.1 500 Internal Server Error
        Server: nginx
        Date: Sat, 09 Mar 2024 01:01:33 GMT
        Content-Type: application/x-httpd-php
        Content-Length: 0
        Connection: close


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:02:01:20
        Start date:09/03/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:02:01:22
        Start date:09/03/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2208,i,9327621530216998631,12272357097468982883,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:02:01:24
        Start date:09/03/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.deutschepost-gefolgt.com/
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly