Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://bayarquickw.online/Alliance.html

Overview

General Information

Sample URL:https://bayarquickw.online/Alliance.html
Analysis ID:1541809
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 6112 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4944 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2024,i,16910092057696208239,6038050795464392340,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6388 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bayarquickw.online/Alliance.html" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: bayarquickw.online
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@20/0@21/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2024,i,16910092057696208239,6038050795464392340,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bayarquickw.online/Alliance.html"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2024,i,16910092057696208239,6038050795464392340,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    google.com
    142.250.184.238
    truefalse
      unknown
      www.google.com
      142.250.185.132
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          bayarquickw.online
          unknown
          unknownfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.185.132
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1541809
            Start date and time:2024-10-25 07:10:36 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 10s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://bayarquickw.online/Alliance.html
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@20/0@21/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 64.233.166.84, 142.250.185.142, 142.250.184.195, 34.104.35.123, 4.245.163.56, 199.232.210.172, 192.229.221.95, 20.3.187.198
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 25, 2024 07:11:40.418440104 CEST49737443192.168.2.4142.250.185.132
            Oct 25, 2024 07:11:40.418490887 CEST44349737142.250.185.132192.168.2.4
            Oct 25, 2024 07:11:40.418576002 CEST49737443192.168.2.4142.250.185.132
            Oct 25, 2024 07:11:40.418847084 CEST49737443192.168.2.4142.250.185.132
            Oct 25, 2024 07:11:40.418859005 CEST44349737142.250.185.132192.168.2.4
            Oct 25, 2024 07:11:41.292593002 CEST44349737142.250.185.132192.168.2.4
            Oct 25, 2024 07:11:41.293217897 CEST49737443192.168.2.4142.250.185.132
            Oct 25, 2024 07:11:41.293247938 CEST44349737142.250.185.132192.168.2.4
            Oct 25, 2024 07:11:41.294887066 CEST44349737142.250.185.132192.168.2.4
            Oct 25, 2024 07:11:41.294965982 CEST49737443192.168.2.4142.250.185.132
            Oct 25, 2024 07:11:41.296093941 CEST49737443192.168.2.4142.250.185.132
            Oct 25, 2024 07:11:41.296355009 CEST44349737142.250.185.132192.168.2.4
            Oct 25, 2024 07:11:41.339061022 CEST49737443192.168.2.4142.250.185.132
            Oct 25, 2024 07:11:41.339073896 CEST44349737142.250.185.132192.168.2.4
            Oct 25, 2024 07:11:41.385930061 CEST49737443192.168.2.4142.250.185.132
            Oct 25, 2024 07:11:41.541929007 CEST49738443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:41.542020082 CEST44349738184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:41.542567015 CEST49738443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:41.544434071 CEST49738443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:41.544481039 CEST44349738184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:42.403165102 CEST44349738184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:42.403345108 CEST49738443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:42.407749891 CEST49738443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:42.407808065 CEST44349738184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:42.408191919 CEST44349738184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:42.456228971 CEST49738443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:42.499376059 CEST44349738184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:42.701108932 CEST44349738184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:42.701178074 CEST44349738184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:42.701296091 CEST49738443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:42.701296091 CEST49738443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:42.701376915 CEST49738443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:42.701420069 CEST44349738184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:42.735651970 CEST49739443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:42.735744953 CEST44349739184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:42.735996008 CEST49739443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:42.736339092 CEST49739443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:42.736388922 CEST44349739184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:43.591773033 CEST44349739184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:43.591869116 CEST49739443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:43.593065977 CEST49739443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:43.593094110 CEST44349739184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:43.593502998 CEST44349739184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:43.594548941 CEST49739443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:43.639324903 CEST44349739184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:43.842104912 CEST44349739184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:43.842190027 CEST44349739184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:43.842257977 CEST49739443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:43.846272945 CEST49739443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:43.846273899 CEST49739443192.168.2.4184.28.90.27
            Oct 25, 2024 07:11:43.846343040 CEST44349739184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:43.846379042 CEST44349739184.28.90.27192.168.2.4
            Oct 25, 2024 07:11:47.789604902 CEST49672443192.168.2.4173.222.162.32
            Oct 25, 2024 07:11:47.789653063 CEST44349672173.222.162.32192.168.2.4
            Oct 25, 2024 07:11:51.113104105 CEST4972380192.168.2.4199.232.214.172
            Oct 25, 2024 07:11:51.118841887 CEST8049723199.232.214.172192.168.2.4
            Oct 25, 2024 07:11:51.118995905 CEST4972380192.168.2.4199.232.214.172
            Oct 25, 2024 07:11:51.292114019 CEST44349737142.250.185.132192.168.2.4
            Oct 25, 2024 07:11:51.292253017 CEST44349737142.250.185.132192.168.2.4
            Oct 25, 2024 07:11:51.292325020 CEST49737443192.168.2.4142.250.185.132
            Oct 25, 2024 07:11:51.293595076 CEST49737443192.168.2.4142.250.185.132
            Oct 25, 2024 07:11:51.293637991 CEST44349737142.250.185.132192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Oct 25, 2024 07:11:36.725852966 CEST53629881.1.1.1192.168.2.4
            Oct 25, 2024 07:11:36.726561069 CEST53591341.1.1.1192.168.2.4
            Oct 25, 2024 07:11:37.972333908 CEST53610711.1.1.1192.168.2.4
            Oct 25, 2024 07:11:38.246246099 CEST5444853192.168.2.41.1.1.1
            Oct 25, 2024 07:11:38.246247053 CEST5902953192.168.2.41.1.1.1
            Oct 25, 2024 07:11:38.255670071 CEST53544481.1.1.1192.168.2.4
            Oct 25, 2024 07:11:38.256342888 CEST53590291.1.1.1192.168.2.4
            Oct 25, 2024 07:11:38.257133961 CEST5074853192.168.2.41.1.1.1
            Oct 25, 2024 07:11:38.266602039 CEST53507481.1.1.1192.168.2.4
            Oct 25, 2024 07:11:38.331901073 CEST5638753192.168.2.48.8.8.8
            Oct 25, 2024 07:11:38.332443953 CEST5282753192.168.2.41.1.1.1
            Oct 25, 2024 07:11:38.338892937 CEST53563878.8.8.8192.168.2.4
            Oct 25, 2024 07:11:38.339703083 CEST53528271.1.1.1192.168.2.4
            Oct 25, 2024 07:11:39.361259937 CEST6184953192.168.2.41.1.1.1
            Oct 25, 2024 07:11:39.361360073 CEST6196553192.168.2.41.1.1.1
            Oct 25, 2024 07:11:39.371069908 CEST53618491.1.1.1192.168.2.4
            Oct 25, 2024 07:11:39.374558926 CEST53619651.1.1.1192.168.2.4
            Oct 25, 2024 07:11:39.401010036 CEST6001753192.168.2.41.1.1.1
            Oct 25, 2024 07:11:39.401114941 CEST5045453192.168.2.41.1.1.1
            Oct 25, 2024 07:11:39.410244942 CEST53504541.1.1.1192.168.2.4
            Oct 25, 2024 07:11:39.410758972 CEST53600171.1.1.1192.168.2.4
            Oct 25, 2024 07:11:40.409157038 CEST6255353192.168.2.41.1.1.1
            Oct 25, 2024 07:11:40.409260988 CEST5084753192.168.2.41.1.1.1
            Oct 25, 2024 07:11:40.417481899 CEST53625531.1.1.1192.168.2.4
            Oct 25, 2024 07:11:40.417670965 CEST53508471.1.1.1192.168.2.4
            Oct 25, 2024 07:11:43.318268061 CEST5407353192.168.2.41.1.1.1
            Oct 25, 2024 07:11:43.318370104 CEST5964153192.168.2.41.1.1.1
            Oct 25, 2024 07:11:43.327151060 CEST53540731.1.1.1192.168.2.4
            Oct 25, 2024 07:11:43.327179909 CEST53596411.1.1.1192.168.2.4
            Oct 25, 2024 07:11:43.328057051 CEST5542553192.168.2.41.1.1.1
            Oct 25, 2024 07:11:43.337472916 CEST53554251.1.1.1192.168.2.4
            Oct 25, 2024 07:11:43.348906040 CEST5775453192.168.2.41.1.1.1
            Oct 25, 2024 07:11:43.349131107 CEST5375353192.168.2.48.8.8.8
            Oct 25, 2024 07:11:43.356950045 CEST53577541.1.1.1192.168.2.4
            Oct 25, 2024 07:11:43.357525110 CEST53537538.8.8.8192.168.2.4
            Oct 25, 2024 07:11:48.399725914 CEST6236253192.168.2.41.1.1.1
            Oct 25, 2024 07:11:48.400408983 CEST5178253192.168.2.41.1.1.1
            Oct 25, 2024 07:11:48.409190893 CEST53623621.1.1.1192.168.2.4
            Oct 25, 2024 07:11:48.410396099 CEST53517821.1.1.1192.168.2.4
            Oct 25, 2024 07:11:48.422446966 CEST5322053192.168.2.41.1.1.1
            Oct 25, 2024 07:11:48.431655884 CEST53532201.1.1.1192.168.2.4
            Oct 25, 2024 07:11:48.464472055 CEST5058853192.168.2.41.1.1.1
            Oct 25, 2024 07:11:48.464798927 CEST6488553192.168.2.41.1.1.1
            Oct 25, 2024 07:11:48.472193003 CEST53505881.1.1.1192.168.2.4
            Oct 25, 2024 07:11:48.474302053 CEST53648851.1.1.1192.168.2.4
            Oct 25, 2024 07:11:50.345434904 CEST138138192.168.2.4192.168.2.255
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 25, 2024 07:11:38.246246099 CEST192.168.2.41.1.1.10x9aa7Standard query (0)bayarquickw.onlineA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:38.246247053 CEST192.168.2.41.1.1.10xa9efStandard query (0)bayarquickw.online65IN (0x0001)false
            Oct 25, 2024 07:11:38.257133961 CEST192.168.2.41.1.1.10x70b9Standard query (0)bayarquickw.onlineA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:38.331901073 CEST192.168.2.48.8.8.80x5d24Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:38.332443953 CEST192.168.2.41.1.1.10xbf91Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:39.361259937 CEST192.168.2.41.1.1.10x78c6Standard query (0)bayarquickw.onlineA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:39.361360073 CEST192.168.2.41.1.1.10xb530Standard query (0)bayarquickw.online65IN (0x0001)false
            Oct 25, 2024 07:11:39.401010036 CEST192.168.2.41.1.1.10xe459Standard query (0)bayarquickw.onlineA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:39.401114941 CEST192.168.2.41.1.1.10x918dStandard query (0)bayarquickw.online65IN (0x0001)false
            Oct 25, 2024 07:11:40.409157038 CEST192.168.2.41.1.1.10xcb90Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:40.409260988 CEST192.168.2.41.1.1.10x4bc1Standard query (0)www.google.com65IN (0x0001)false
            Oct 25, 2024 07:11:43.318268061 CEST192.168.2.41.1.1.10xe809Standard query (0)bayarquickw.onlineA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:43.318370104 CEST192.168.2.41.1.1.10x7520Standard query (0)bayarquickw.online65IN (0x0001)false
            Oct 25, 2024 07:11:43.328057051 CEST192.168.2.41.1.1.10x3df7Standard query (0)bayarquickw.onlineA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:43.348906040 CEST192.168.2.41.1.1.10x5944Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:43.349131107 CEST192.168.2.48.8.8.80x440eStandard query (0)google.comA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:48.399725914 CEST192.168.2.41.1.1.10xc454Standard query (0)bayarquickw.onlineA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:48.400408983 CEST192.168.2.41.1.1.10xa74aStandard query (0)bayarquickw.online65IN (0x0001)false
            Oct 25, 2024 07:11:48.422446966 CEST192.168.2.41.1.1.10x8d1dStandard query (0)bayarquickw.onlineA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:48.464472055 CEST192.168.2.41.1.1.10xa6f8Standard query (0)bayarquickw.onlineA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:48.464798927 CEST192.168.2.41.1.1.10xd2b2Standard query (0)bayarquickw.online65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 25, 2024 07:11:38.255670071 CEST1.1.1.1192.168.2.40x9aa7Name error (3)bayarquickw.onlinenonenoneA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:38.256342888 CEST1.1.1.1192.168.2.40xa9efName error (3)bayarquickw.onlinenonenone65IN (0x0001)false
            Oct 25, 2024 07:11:38.266602039 CEST1.1.1.1192.168.2.40x70b9Name error (3)bayarquickw.onlinenonenoneA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:38.338892937 CEST8.8.8.8192.168.2.40x5d24No error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:38.339703083 CEST1.1.1.1192.168.2.40xbf91No error (0)google.com142.250.185.174A (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:39.371069908 CEST1.1.1.1192.168.2.40x78c6Name error (3)bayarquickw.onlinenonenoneA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:39.374558926 CEST1.1.1.1192.168.2.40xb530Name error (3)bayarquickw.onlinenonenone65IN (0x0001)false
            Oct 25, 2024 07:11:39.410244942 CEST1.1.1.1192.168.2.40x918dName error (3)bayarquickw.onlinenonenone65IN (0x0001)false
            Oct 25, 2024 07:11:39.410758972 CEST1.1.1.1192.168.2.40xe459Name error (3)bayarquickw.onlinenonenoneA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:40.417481899 CEST1.1.1.1192.168.2.40xcb90No error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:40.417670965 CEST1.1.1.1192.168.2.40x4bc1No error (0)www.google.com65IN (0x0001)false
            Oct 25, 2024 07:11:43.327151060 CEST1.1.1.1192.168.2.40xe809Name error (3)bayarquickw.onlinenonenoneA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:43.327179909 CEST1.1.1.1192.168.2.40x7520Name error (3)bayarquickw.onlinenonenone65IN (0x0001)false
            Oct 25, 2024 07:11:43.337472916 CEST1.1.1.1192.168.2.40x3df7Name error (3)bayarquickw.onlinenonenoneA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:43.356950045 CEST1.1.1.1192.168.2.40x5944No error (0)google.com142.250.185.78A (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:43.357525110 CEST8.8.8.8192.168.2.40x440eNo error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:48.409190893 CEST1.1.1.1192.168.2.40xc454Name error (3)bayarquickw.onlinenonenoneA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:48.410396099 CEST1.1.1.1192.168.2.40xa74aName error (3)bayarquickw.onlinenonenone65IN (0x0001)false
            Oct 25, 2024 07:11:48.431655884 CEST1.1.1.1192.168.2.40x8d1dName error (3)bayarquickw.onlinenonenoneA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:48.472193003 CEST1.1.1.1192.168.2.40xa6f8Name error (3)bayarquickw.onlinenonenoneA (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:48.474302053 CEST1.1.1.1192.168.2.40xd2b2Name error (3)bayarquickw.onlinenonenone65IN (0x0001)false
            Oct 25, 2024 07:11:50.491899014 CEST1.1.1.1192.168.2.40x2be6No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:50.491899014 CEST1.1.1.1192.168.2.40x2be6No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Oct 25, 2024 07:11:53.041677952 CEST1.1.1.1192.168.2.40x222dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 25, 2024 07:11:53.041677952 CEST1.1.1.1192.168.2.40x222dNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449738184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-25 05:11:42 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-25 05:11:42 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF70)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=214400
            Date: Fri, 25 Oct 2024 05:11:42 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449739184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-25 05:11:43 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-25 05:11:43 UTC515INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=214399
            Date: Fri, 25 Oct 2024 05:11:43 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-10-25 05:11:43 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:01:11:31
            Start date:25/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:01:11:34
            Start date:25/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2024,i,16910092057696208239,6038050795464392340,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:01:11:37
            Start date:25/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bayarquickw.online/Alliance.html"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly