Edit tour
Windows
Analysis Report
https://links.us1.defend.egress.com/Warning?crId=6719c1fe0a0594bd0e3efe86&Domain=lcatterton.com&Lang=en&Base64Url=eNolVefOpEgMfKLdjwxz0ulEzjnz5wQMDDDkDE9_zZ7UQh2q3MYuu6t1HZe_fn62uaUgmPrd1mXRDvn3dz50P-3yk7d1_v1nG_u_NwiCfyPuGvfyi9VXtqJoY9Z-IQL5DkazSK1JwuSwCshfCDMQqlPoOda5xUgz5HYXPtkiSC4R725tRJe4PxKAfe
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Detected non-DNS traffic on DNS port
Very long command line found
Classification
- System is w10x64
- chrome.exe (PID: 6556 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - chrome.exe (PID: 7120 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2256 --fi eld-trial- handle=219 6,i,172274 3004664671 2005,24208 0144414037 5319,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- chrome.exe (PID: 6932 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://links .us1.defen d.egress.c om/Warning ?crId=6719 c1fe0a0594 bd0e3efe86 &Domain=lc atterton.c om&Lang=en &Base64Url =eNolVefOp EgMfKLdjwx z0ulEzjnz5 wQMDDDkDE9 _zZ7UQh2q3 MYuu6t1HZe _fn62uaUgm Prd1mXRDvn 3dz50P-3yk 7d1_v1nG_u _NwiCfyPuG vfyi9VXtqJ oY9Z-IQL5D kazSK1JwuS wCshfCDMQq lPoOda5xUg z5HYXPtkiS C4R725tRJe 4PxKAfeu7q 4qF3mdBGd9 BZsjU9Bjcx Zveonl0nDY cKqZKZZcpI pTTkIVMsXh 43ZjUwXBrj bIC8FWt4ce tDqzi1_SVA p-YncEhbXB 7P5x4KWpvQ eETeeJR0t7 UmcQJlAGg- DRaTwUGqEQ 5Vz1GNaodv KzSEanmVp5 COJSTXB77E Fo1zuYCf2S UO-pyJwAHN pnlYIZScvT XAiVMYmquM XtnMYj2ohj Ddpqh7w4u9 UV8cFeZ1xe IIE9OPhcDu mzxVEHHrlZ HvGDJuWgRn 3eIhO2HytM EEF4zzYTYs uCFfZ6Rael pzniA2LkZ- A6ivEcyH6h Oh7JwCPD1F YvTa50vL6p sKSsHJUTSI _HaqPWsLje DDiX13Knqy 0WRijx7qaW ueOfQOrSrP dtCHhhZs6a xrZt87uEvn H37cTi7K1J jvgOOW3O5C J3c3MLv36b CFPsUjTLkB gMgXG1LT58 axUuSSqLsc puEnT6Kprz Oq2bDz_EL5 cAgPD79t7h WmIgldT5bD EWS0xRfEXZ 5nEa86aF8H 8zrnNy6fuK casIWG8myM XGghZz2aQx ogadU0r4qR ghWFbaviZC yr7TIMWW6k LiZwFXejm8 WxMObUQkMx xhVu9ChElh kVcir7mv2Y PJ17Km9Riw 5SM0qt7EKQ ZPwFvC9VmF O26x17yAta u79kIVAK2y QSSGeoGYeE BhMmW8UvK6 obJxZaEPCy LHzFHLvuD8 jW-RUZlqmD nxxITNZ0E6 A4yDZcAN6f Ij3BdkHfM7 nln6BjdOiZ ABN4O1R72o 9PLvDFHUgG F4Xcq5UsXR kO4GpjVuL4 2O3Jz-pKL9 VranwdYeQ5 rgnP7ienRS MRZjiidKOb VbcyPQ6H5K CcdJq-BxXG FZWUvsoJKX 5CIo2Z8NAc x5B1_LAwif 1lWs3i9AH9 kopwjbCp6D GspBSxwy86 guR8jAXZ2W k1TAAn5Ozt NpCofxxfZS IJCZbK_CWT oRqpvibrMf y3ZE0__XUg JCplxf4tsZ nquCca55Da uOxVKTEmiO 4QPmCZ_aVh JcLrlmi4kg Fxy0fYBacP N5CUNnRFEF CZd3k10zs1 ru7CvuzhDf -RdytcxM4J 5TLApRT1pk jBROwEEb6B rO5XcLQ9JQ saV0IqTTzv to37VyOnbc ulrKv1CJUW Wp81ACcgmw U_t5hM69S6 gQbGjlT10S Sse33claFi YvzAnpqJkR D9hiydOxY2 rHmbV-l6Z- ikBBwazAY8 EVpWydekK3 If_6GKbHLj cjNPDcOB8u 7fFNqIytXZ qjYhIYZzq5 vaZmJ62lR_ VntoGLh4kz oHaCJfI0R4 BHTbLujm1M jXph8ePJnu hAyKfu07mo FaaK2FhzRQ nPKgTS6rmC BCiTc4k_VU XGMKS_rxHZ ukcRZzGQaf exVV7QbWyH aGSh5AR3Uf B8gXMAYeEm 6IncwIQKwL NAEIyPNjQJ FygCioFLxW 6mnOjtxftA RNbudbNy__ SpIH1gbvFc qZfHromJkY 9BhKoKewT0 SCS_GviJRn Rm2jNLZ3SM SebLFjZUQi T03rpEqhFf 0ST5DBxraw kILtzw66_L nCWl8BfdN- pEGd0qO9E1 y__IJ9Ulfs kklLIkKLUD q81JJi-YqY m8Yw3JAbJU KfMpM4cMti C9jIjhZchs z9ajn5ubk4 LAExwmil_5 CwIH7WXIiZ YIafo3FtF0 x0uSFUiBQa s_HorQ0rnU 6WrJlRa" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |