Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://racrodisaver.co.in/

Overview

General Information

Sample URL:http://racrodisaver.co.in/
Analysis ID:1523777
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 3584 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2344 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1992,i,10190382223755918344,14878623388697037759,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6288 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://racrodisaver.co.in/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: racrodisaver.co.inVirustotal: Detection: 13%Perma Link
Source: http://racrodisaver.co.in/Virustotal: Detection: 13%Perma Link
Source: unknownHTTPS traffic detected: 23.53.114.19:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.53.114.19:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:49634 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.4:57195 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.4:59753 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 23.53.114.19
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: racrodisaver.co.inConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: racrodisaver.co.inConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://racrodisaver.co.in/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: racrodisaver.co.in
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.24.0Date: Wed, 02 Oct 2024 00:11:50 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: keep-aliveContent-Encoding: gzipData Raw: 62 30 0d 0a 1f 8b 08 00 00 00 00 00 04 03 ed 90 c1 0a c2 30 10 44 ef 82 ff b0 7e 40 9a 56 7a 5c 72 11 05 0f 7a f1 0b 52 77 6d 02 69 22 31 82 fd 7b 13 6d 41 3c 7b f4 b8 b3 6f 86 61 d0 a4 c1 a9 e5 02 0d 6b 52 98 6c 72 ac da ba 85 63 48 b0 0b 77 4f 28 df 22 ca 17 92 d1 2e d0 58 2c 67 f6 89 a3 42 d3 7c 3b b2 82 72 7a 97 ec 0c 4d 97 ef ad 7f c8 a6 5a b7 55 fd 89 c8 39 54 ce 85 56 42 80 86 ab 26 b2 be 87 14 80 ec 4d 77 8e e1 70 da 6f 41 7b 82 8d 89 61 60 b8 44 cb 9e dc 08 1c 63 88 d9 d1 33 08 51 0a fe 23 7e b9 c5 13 7b 1b 44 21 2b 02 00 00 0d 0a 30 0d 0a 0d 0a Data Ascii: b00D~@Vz\rzRwmi"1{mA<{oakRlrcHwO(".X,gB|;rzMZU9TVB&MwpoA{a`Dc3Q#~{D!+0
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49638 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49638
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.53.114.19:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.53.114.19:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: mal56.win@21/4@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1992,i,10190382223755918344,14878623388697037759,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://racrodisaver.co.in/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1992,i,10190382223755918344,14878623388697037759,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://racrodisaver.co.in/14%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
www.google.com0%VirustotalBrowse
racrodisaver.co.in14%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
216.58.206.68
truefalseunknown
racrodisaver.co.in
3.130.72.53
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
NameMaliciousAntivirus DetectionReputation
http://racrodisaver.co.in/true
    unknown
    http://racrodisaver.co.in/favicon.icotrue
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      3.130.72.53
      racrodisaver.co.inUnited States
      16509AMAZON-02USfalse
      216.58.206.68
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      192.168.2.5
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1523777
      Start date and time:2024-10-02 02:10:55 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 1s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:http://racrodisaver.co.in/
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:9
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal56.win@21/4@4/5
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 142.250.184.227, 66.102.1.84, 142.250.185.78, 34.104.35.123, 20.12.23.50, 93.184.221.240, 192.229.221.95, 52.165.164.15, 13.85.23.206, 20.3.187.198, 142.250.186.35, 131.107.255.255
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 555
      Category:downloaded
      Size (bytes):176
      Entropy (8bit):6.738206067673969
      Encrypted:false
      SSDEEP:3:FttIVhlb5XDu3SnodW47noYrBks1gD2SnPyptdCQ6jlrugx82sO1cMcg23ll:XtIXodWMXVA2S8CNxruLE1cMRk/
      MD5:7EF182B31A0C40B31FE7F37CC04E1319
      SHA1:223172DFC3094B518D4088E4B822340CB713C895
      SHA-256:159A25C1BFC7DD370445CCE2C68F09AA1E30407F38D84282BD07C3B64E5E32F0
      SHA-512:6C1D5F136BA602534785A6FB5D9D18A481807292D649AB750577C33BB1C62C64496CE8363593DB8985E124344E586C017A1A7F3A9F6ACB60AA78707CEACFFABF
      Malicious:false
      Reputation:low
      URL:http://racrodisaver.co.in/favicon.ico
      Preview:..............0.D...~@.Vz\r...z..Rwm.i"1..{.mA<{...o.a......kR.lr...cH..wO(."......X,g...B.|;..rz...M....Z.U...9T.VB...&......Mw..p.oA{...a`.D....c...3.Q..#~...{.D!+...
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:gzip compressed data, max speed, from Unix, truncated
      Category:downloaded
      Size (bytes):20
      Entropy (8bit):1.5567796494470394
      Encrypted:false
      SSDEEP:3:FttTll:XtTll
      MD5:A4745ABC5E7FDB89CC6DF3069F3C6E69
      SHA1:74789F7DDBEBD5B7323F6F8174005B4BF8C1F1ED
      SHA-256:D1111B245F685176180E6F1631E6DC49BADF6672368E9CE260C71355165EFFDF
      SHA-512:849461CB54ECDE577246AAD993D1ECABB879913E353AE322561C7C57605F571E23210FE12BDCEF49FAA99B5B003611976FF64348F620968271E38BBA1C7D7F62
      Malicious:false
      Reputation:low
      URL:http://racrodisaver.co.in/
      Preview:....................
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Oct 2, 2024 02:11:49.111314058 CEST49675443192.168.2.4173.222.162.32
      Oct 2, 2024 02:11:50.205209017 CEST4973580192.168.2.43.130.72.53
      Oct 2, 2024 02:11:50.205564976 CEST4973680192.168.2.43.130.72.53
      Oct 2, 2024 02:11:50.210118055 CEST80497353.130.72.53192.168.2.4
      Oct 2, 2024 02:11:50.210325956 CEST80497363.130.72.53192.168.2.4
      Oct 2, 2024 02:11:50.210422993 CEST4973580192.168.2.43.130.72.53
      Oct 2, 2024 02:11:50.210580111 CEST4973680192.168.2.43.130.72.53
      Oct 2, 2024 02:11:50.210580111 CEST4973680192.168.2.43.130.72.53
      Oct 2, 2024 02:11:50.215349913 CEST80497363.130.72.53192.168.2.4
      Oct 2, 2024 02:11:50.718750954 CEST80497363.130.72.53192.168.2.4
      Oct 2, 2024 02:11:50.751099110 CEST4973680192.168.2.43.130.72.53
      Oct 2, 2024 02:11:50.755891085 CEST80497363.130.72.53192.168.2.4
      Oct 2, 2024 02:11:50.870639086 CEST80497363.130.72.53192.168.2.4
      Oct 2, 2024 02:11:50.922704935 CEST4973680192.168.2.43.130.72.53
      Oct 2, 2024 02:11:52.953048944 CEST49739443192.168.2.4216.58.206.68
      Oct 2, 2024 02:11:52.953109980 CEST44349739216.58.206.68192.168.2.4
      Oct 2, 2024 02:11:52.953521967 CEST49739443192.168.2.4216.58.206.68
      Oct 2, 2024 02:11:52.955068111 CEST49739443192.168.2.4216.58.206.68
      Oct 2, 2024 02:11:52.955082893 CEST44349739216.58.206.68192.168.2.4
      Oct 2, 2024 02:11:53.135768890 CEST49740443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:53.135842085 CEST4434974023.53.114.19192.168.2.4
      Oct 2, 2024 02:11:53.136173010 CEST49740443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:53.139059067 CEST49740443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:53.139095068 CEST4434974023.53.114.19192.168.2.4
      Oct 2, 2024 02:11:53.596609116 CEST44349739216.58.206.68192.168.2.4
      Oct 2, 2024 02:11:53.598202944 CEST49739443192.168.2.4216.58.206.68
      Oct 2, 2024 02:11:53.598226070 CEST44349739216.58.206.68192.168.2.4
      Oct 2, 2024 02:11:53.599265099 CEST44349739216.58.206.68192.168.2.4
      Oct 2, 2024 02:11:53.599318981 CEST49739443192.168.2.4216.58.206.68
      Oct 2, 2024 02:11:53.629126072 CEST49739443192.168.2.4216.58.206.68
      Oct 2, 2024 02:11:53.629276991 CEST44349739216.58.206.68192.168.2.4
      Oct 2, 2024 02:11:53.683844090 CEST49739443192.168.2.4216.58.206.68
      Oct 2, 2024 02:11:53.683865070 CEST44349739216.58.206.68192.168.2.4
      Oct 2, 2024 02:11:53.730716944 CEST49739443192.168.2.4216.58.206.68
      Oct 2, 2024 02:11:53.767374039 CEST4434974023.53.114.19192.168.2.4
      Oct 2, 2024 02:11:53.767440081 CEST49740443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:53.771090984 CEST49740443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:53.771112919 CEST4434974023.53.114.19192.168.2.4
      Oct 2, 2024 02:11:53.771379948 CEST4434974023.53.114.19192.168.2.4
      Oct 2, 2024 02:11:53.819487095 CEST49740443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:53.867413998 CEST4434974023.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.020653963 CEST4434974023.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.020740032 CEST4434974023.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.020793915 CEST49740443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.020869970 CEST49740443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.020915985 CEST4434974023.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.065011978 CEST49741443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.065107107 CEST4434974123.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.065172911 CEST49741443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.065555096 CEST49741443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.065596104 CEST4434974123.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.691683054 CEST4434974123.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.691874981 CEST49741443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.695503950 CEST49741443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.695533037 CEST4434974123.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.695805073 CEST4434974123.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.698513985 CEST49741443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.739442110 CEST4434974123.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.954610109 CEST4434974123.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.954668045 CEST4434974123.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.954770088 CEST49741443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.958237886 CEST49741443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.958237886 CEST49741443192.168.2.423.53.114.19
      Oct 2, 2024 02:11:54.958283901 CEST4434974123.53.114.19192.168.2.4
      Oct 2, 2024 02:11:54.958309889 CEST4434974123.53.114.19192.168.2.4
      Oct 2, 2024 02:12:03.503122091 CEST44349739216.58.206.68192.168.2.4
      Oct 2, 2024 02:12:03.503180981 CEST44349739216.58.206.68192.168.2.4
      Oct 2, 2024 02:12:03.503335953 CEST49739443192.168.2.4216.58.206.68
      Oct 2, 2024 02:12:04.833362103 CEST49739443192.168.2.4216.58.206.68
      Oct 2, 2024 02:12:04.833369970 CEST44349739216.58.206.68192.168.2.4
      Oct 2, 2024 02:12:05.946856976 CEST5975353192.168.2.41.1.1.1
      Oct 2, 2024 02:12:05.951845884 CEST53597531.1.1.1192.168.2.4
      Oct 2, 2024 02:12:05.951946020 CEST5975353192.168.2.41.1.1.1
      Oct 2, 2024 02:12:05.951946020 CEST5975353192.168.2.41.1.1.1
      Oct 2, 2024 02:12:05.956727982 CEST53597531.1.1.1192.168.2.4
      Oct 2, 2024 02:12:06.415937901 CEST53597531.1.1.1192.168.2.4
      Oct 2, 2024 02:12:06.416636944 CEST5975353192.168.2.41.1.1.1
      Oct 2, 2024 02:12:06.421683073 CEST53597531.1.1.1192.168.2.4
      Oct 2, 2024 02:12:06.421977997 CEST5975353192.168.2.41.1.1.1
      Oct 2, 2024 02:12:07.415661097 CEST5719553192.168.2.41.1.1.1
      Oct 2, 2024 02:12:07.420537949 CEST53571951.1.1.1192.168.2.4
      Oct 2, 2024 02:12:07.420650959 CEST5719553192.168.2.41.1.1.1
      Oct 2, 2024 02:12:07.420650959 CEST5719553192.168.2.41.1.1.1
      Oct 2, 2024 02:12:07.425570011 CEST53571951.1.1.1192.168.2.4
      Oct 2, 2024 02:12:07.876534939 CEST53571951.1.1.1192.168.2.4
      Oct 2, 2024 02:12:07.880213976 CEST5719553192.168.2.41.1.1.1
      Oct 2, 2024 02:12:07.885473013 CEST53571951.1.1.1192.168.2.4
      Oct 2, 2024 02:12:07.885598898 CEST5719553192.168.2.41.1.1.1
      Oct 2, 2024 02:12:11.884670973 CEST4963453192.168.2.41.1.1.1
      Oct 2, 2024 02:12:11.889576912 CEST53496341.1.1.1192.168.2.4
      Oct 2, 2024 02:12:11.889956951 CEST4963453192.168.2.41.1.1.1
      Oct 2, 2024 02:12:11.890028954 CEST4963453192.168.2.41.1.1.1
      Oct 2, 2024 02:12:11.894789934 CEST53496341.1.1.1192.168.2.4
      Oct 2, 2024 02:12:12.362806082 CEST53496341.1.1.1192.168.2.4
      Oct 2, 2024 02:12:12.408530951 CEST4963453192.168.2.41.1.1.1
      Oct 2, 2024 02:12:12.456140041 CEST4963453192.168.2.41.1.1.1
      Oct 2, 2024 02:12:12.461422920 CEST53496341.1.1.1192.168.2.4
      Oct 2, 2024 02:12:12.461555958 CEST4963453192.168.2.41.1.1.1
      Oct 2, 2024 02:12:35.220088959 CEST4973580192.168.2.43.130.72.53
      Oct 2, 2024 02:12:35.225032091 CEST80497353.130.72.53192.168.2.4
      Oct 2, 2024 02:12:35.876358032 CEST4973680192.168.2.43.130.72.53
      Oct 2, 2024 02:12:35.881251097 CEST80497363.130.72.53192.168.2.4
      Oct 2, 2024 02:12:50.614594936 CEST80497353.130.72.53192.168.2.4
      Oct 2, 2024 02:12:50.614682913 CEST4973580192.168.2.43.130.72.53
      Oct 2, 2024 02:12:50.837393045 CEST4973580192.168.2.43.130.72.53
      Oct 2, 2024 02:12:50.842232943 CEST80497353.130.72.53192.168.2.4
      Oct 2, 2024 02:12:52.971915960 CEST49638443192.168.2.4216.58.206.68
      Oct 2, 2024 02:12:52.972033024 CEST44349638216.58.206.68192.168.2.4
      Oct 2, 2024 02:12:52.972099066 CEST49638443192.168.2.4216.58.206.68
      Oct 2, 2024 02:12:52.972538948 CEST49638443192.168.2.4216.58.206.68
      Oct 2, 2024 02:12:52.972585917 CEST44349638216.58.206.68192.168.2.4
      Oct 2, 2024 02:12:53.635349035 CEST44349638216.58.206.68192.168.2.4
      Oct 2, 2024 02:12:53.635704041 CEST49638443192.168.2.4216.58.206.68
      Oct 2, 2024 02:12:53.635752916 CEST44349638216.58.206.68192.168.2.4
      Oct 2, 2024 02:12:53.636236906 CEST44349638216.58.206.68192.168.2.4
      Oct 2, 2024 02:12:53.636754036 CEST49638443192.168.2.4216.58.206.68
      Oct 2, 2024 02:12:53.636843920 CEST44349638216.58.206.68192.168.2.4
      Oct 2, 2024 02:12:53.678407907 CEST49638443192.168.2.4216.58.206.68
      Oct 2, 2024 02:12:55.871361017 CEST80497363.130.72.53192.168.2.4
      Oct 2, 2024 02:12:55.871500969 CEST4973680192.168.2.43.130.72.53
      Oct 2, 2024 02:12:56.502963066 CEST4972380192.168.2.4199.232.214.172
      Oct 2, 2024 02:12:56.503211021 CEST4972480192.168.2.4199.232.214.172
      Oct 2, 2024 02:12:56.508826017 CEST8049723199.232.214.172192.168.2.4
      Oct 2, 2024 02:12:56.508945942 CEST8049724199.232.214.172192.168.2.4
      Oct 2, 2024 02:12:56.508971930 CEST4972380192.168.2.4199.232.214.172
      Oct 2, 2024 02:12:56.513123035 CEST4972480192.168.2.4199.232.214.172
      Oct 2, 2024 02:12:56.833206892 CEST4973680192.168.2.43.130.72.53
      Oct 2, 2024 02:12:56.838098049 CEST80497363.130.72.53192.168.2.4
      Oct 2, 2024 02:13:03.540482998 CEST44349638216.58.206.68192.168.2.4
      Oct 2, 2024 02:13:03.540549040 CEST44349638216.58.206.68192.168.2.4
      Oct 2, 2024 02:13:03.540613890 CEST49638443192.168.2.4216.58.206.68
      Oct 2, 2024 02:13:04.833494902 CEST49638443192.168.2.4216.58.206.68
      Oct 2, 2024 02:13:04.833575964 CEST44349638216.58.206.68192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Oct 2, 2024 02:11:48.620219946 CEST53629811.1.1.1192.168.2.4
      Oct 2, 2024 02:11:48.620235920 CEST53547031.1.1.1192.168.2.4
      Oct 2, 2024 02:11:49.828699112 CEST53555041.1.1.1192.168.2.4
      Oct 2, 2024 02:11:50.189671040 CEST5930353192.168.2.41.1.1.1
      Oct 2, 2024 02:11:50.189824104 CEST5177553192.168.2.41.1.1.1
      Oct 2, 2024 02:11:50.200573921 CEST53593031.1.1.1192.168.2.4
      Oct 2, 2024 02:11:50.200589895 CEST53517751.1.1.1192.168.2.4
      Oct 2, 2024 02:11:52.917435884 CEST5237653192.168.2.41.1.1.1
      Oct 2, 2024 02:11:52.918514013 CEST5329153192.168.2.41.1.1.1
      Oct 2, 2024 02:11:52.925256968 CEST53523761.1.1.1192.168.2.4
      Oct 2, 2024 02:11:52.925270081 CEST53532911.1.1.1192.168.2.4
      Oct 2, 2024 02:12:05.946520090 CEST53562761.1.1.1192.168.2.4
      Oct 2, 2024 02:12:06.823232889 CEST53532071.1.1.1192.168.2.4
      Oct 2, 2024 02:12:07.415296078 CEST53499951.1.1.1192.168.2.4
      Oct 2, 2024 02:12:08.106636047 CEST138138192.168.2.4192.168.2.255
      Oct 2, 2024 02:12:11.884188890 CEST53523451.1.1.1192.168.2.4
      Oct 2, 2024 02:12:48.136696100 CEST53629531.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Oct 2, 2024 02:11:50.189671040 CEST192.168.2.41.1.1.10xa884Standard query (0)racrodisaver.co.inA (IP address)IN (0x0001)false
      Oct 2, 2024 02:11:50.189824104 CEST192.168.2.41.1.1.10x8270Standard query (0)racrodisaver.co.in65IN (0x0001)false
      Oct 2, 2024 02:11:52.917435884 CEST192.168.2.41.1.1.10x7878Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Oct 2, 2024 02:11:52.918514013 CEST192.168.2.41.1.1.10x716cStandard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Oct 2, 2024 02:11:50.200573921 CEST1.1.1.1192.168.2.40xa884No error (0)racrodisaver.co.in3.130.72.53A (IP address)IN (0x0001)false
      Oct 2, 2024 02:11:52.925256968 CEST1.1.1.1192.168.2.40x7878No error (0)www.google.com216.58.206.68A (IP address)IN (0x0001)false
      Oct 2, 2024 02:11:52.925270081 CEST1.1.1.1192.168.2.40x716cNo error (0)www.google.com65IN (0x0001)false
      Oct 2, 2024 02:12:03.793464899 CEST1.1.1.1192.168.2.40xb364No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Oct 2, 2024 02:12:03.793464899 CEST1.1.1.1192.168.2.40xb364No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      • fs.microsoft.com
      • racrodisaver.co.in
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.4497363.130.72.53802344C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      Oct 2, 2024 02:11:50.210580111 CEST433OUTGET / HTTP/1.1
      Host: racrodisaver.co.in
      Connection: keep-alive
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9
      Oct 2, 2024 02:11:50.718750954 CEST225INHTTP/1.1 200 OK
      Server: nginx/1.24.0
      Date: Wed, 02 Oct 2024 00:11:50 GMT
      Content-Type: text/html; charset=UTF-8
      Transfer-Encoding: chunked
      Connection: keep-alive
      Content-Encoding: gzip
      Data Raw: 31 34 0d 0a 1f 8b 08 00 00 00 00 00 04 03 03 00 00 00 00 00 00 00 00 00 0d 0a 30 0d 0a 0d 0a
      Data Ascii: 140
      Oct 2, 2024 02:11:50.751099110 CEST380OUTGET /favicon.ico HTTP/1.1
      Host: racrodisaver.co.in
      Connection: keep-alive
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
      Referer: http://racrodisaver.co.in/
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9
      Oct 2, 2024 02:11:50.870639086 CEST373INHTTP/1.1 404 Not Found
      Server: nginx/1.24.0
      Date: Wed, 02 Oct 2024 00:11:50 GMT
      Content-Type: text/html
      Transfer-Encoding: chunked
      Connection: keep-alive
      Content-Encoding: gzip
      Data Raw: 62 30 0d 0a 1f 8b 08 00 00 00 00 00 04 03 ed 90 c1 0a c2 30 10 44 ef 82 ff b0 7e 40 9a 56 7a 5c 72 11 05 0f 7a f1 0b 52 77 6d 02 69 22 31 82 fd 7b 13 6d 41 3c 7b f4 b8 b3 6f 86 61 d0 a4 c1 a9 e5 02 0d 6b 52 98 6c 72 ac da ba 85 63 48 b0 0b 77 4f 28 df 22 ca 17 92 d1 2e d0 58 2c 67 f6 89 a3 42 d3 7c 3b b2 82 72 7a 97 ec 0c 4d 97 ef ad 7f c8 a6 5a b7 55 fd 89 c8 39 54 ce 85 56 42 80 86 ab 26 b2 be 87 14 80 ec 4d 77 8e e1 70 da 6f 41 7b 82 8d 89 61 60 b8 44 cb 9e dc 08 1c 63 88 d9 d1 33 08 51 0a fe 23 7e b9 c5 13 7b 1b 44 21 2b 02 00 00 0d 0a 30 0d 0a 0d 0a
      Data Ascii: b00D~@Vz\rzRwmi"1{mA<{oakRlrcHwO(".X,gB|;rzMZU9TVB&MwpoA{a`Dc3Q#~{D!+0
      Oct 2, 2024 02:12:35.876358032 CEST6OUTData Raw: 00
      Data Ascii:


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.4497353.130.72.53802344C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      Oct 2, 2024 02:12:35.220088959 CEST6OUTData Raw: 00
      Data Ascii:


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.44974023.53.114.19443
      TimestampBytes transferredDirectionData
      2024-10-02 00:11:53 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-10-02 00:11:54 UTC467INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF06)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-neu-z1
      Cache-Control: public, max-age=146051
      Date: Wed, 02 Oct 2024 00:11:53 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.44974123.53.114.19443
      TimestampBytes transferredDirectionData
      2024-10-02 00:11:54 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-10-02 00:11:54 UTC515INHTTP/1.1 200 OK
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF06)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-weu-z1
      Cache-Control: public, max-age=145998
      Date: Wed, 02 Oct 2024 00:11:54 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-10-02 00:11:54 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:20:11:43
      Start date:01/10/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:20:11:47
      Start date:01/10/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1992,i,10190382223755918344,14878623388697037759,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:20:11:49
      Start date:01/10/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://racrodisaver.co.in/"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly