Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4

Overview

General Information

Sample URL:https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4
Analysis ID:1556058

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected landing page (webpage, office document or email)
HTML page contains suspicious javascript code
HTML body contains low number of good links
HTML body contains password input but no form action
HTML title does not match URL
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 532 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6828 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1888,i,1732873202329785937,16230637607138776747,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2908 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6256 --field-trial-handle=1888,i,1732873202329785937,16230637607138776747,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6028 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=6220 --field-trial-handle=1888,i,1732873202329785937,16230637607138776747,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6352 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://www.amazon.com/dp/B0CV6TDDLX?tag=drawnacom-20&linkCode=osi&th=1&psc=1&dn_platform=websiteJoe Sandbox AI: Page contains button: 'Continue shopping' Source: '3.6.pages.csv'
Source: https://d1nruqhae353qc.cloudfront.net/primesignup/widget.jsHTTP Parser: window.location.href = atob(
Source: https://www.drawnames.com/account/sign-inHTTP Parser: Number of links: 0
Source: https://www.drawnames.com/account/sign-inHTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://accounts.google.com/v3/signin/identifier?opparams=%253Fgis_params%253DChlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tEhlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tGAcqFm1ZVnRndGd6UTU3NHQ1aVFjaEVjc3cySDU0NTQ1MjQ0ODUyMi1tMHYxcmhocm5iZjVsNXU5cGt1NXA3ZmpxMWZqNmJjMC5hcHBzLmdvb2dsZXVzZXJjb250ZW50LmNvbTgBQkA2ZTdlYjVlMmQ1YjBiNzhlNGQ0MjhhMjU2MDhlZmE4Yzk4YmVkMTAxM2Q5MGY5YTc4ZDA1YTgyZjMwZjU1ZTJh%2526origin%253Dhttps%25253A%25252F%25252Fwww.drawnames.com%2526response_mode%253Dform_post&dsh=S-1792440859%3A1731614868801787&client_id=545452448522-m0v1rhhrnbf5l5u9pku5p7fjq1fj6bc0.apps.googleusercontent.com&ddm=1&display=popup&gsiwebsdk=gis_attributes&o2v=1&prompt=select_account&redirect_uri=https%3A%2F%2Fwww.drawnames.com&response_type=id_token&scope=openid+email+profile&service=lso&flowName=GeneralOAuthFlow&continue=https%3A%2F%2Faccounts.google.com%2Fsignin%2Foauth%2Fconsent%3Fauthuser%3Dunknown%26part%3DAJi8hAOU3pZ4keoWL4a2Ovsuq-zuUfgKYSFWJJav42hVY9ecK6zKGygkaNtBWhxyoESLe_S1LIvEFlj_GxzEoip4lNupMITAoxWhd8Is-ORcRgp6PjdxSVQafpnmmCv8BNJxt...HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://www.drawnames.com/account/sign-inHTTP Parser: Title: Sign in does not match URL
Source: https://www.drawnames.com/account/sign-inHTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-TD6QJL2
Source: https://www.drawnames.com/account/sign-inHTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-TD6QJL2
Source: https://www.drawnames.com/account/sign-inHTTP Parser: Iframe src: https://accounts.google.com/gsi/button?type=icon&width=100&client_id=545452448522-m0v1rhhrnbf5l5u9pku5p7fjq1fj6bc0.apps.googleusercontent.com&iframe_id=gsi_855822_27907&as=mYVtgtgzQ574t5iQchEcsw
Source: https://www.drawnames.com/account/sign-inHTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-TD6QJL2
Source: https://www.drawnames.com/account/sign-inHTTP Parser: Iframe src: https://accounts.google.com/gsi/button?type=icon&width=100&client_id=545452448522-m0v1rhhrnbf5l5u9pku5p7fjq1fj6bc0.apps.googleusercontent.com&iframe_id=gsi_855822_27907&as=mYVtgtgzQ574t5iQchEcsw
Source: https://www.drawnames.com/account/sign-inHTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-TD6QJL2
Source: https://www.drawnames.com/account/sign-inHTTP Parser: Iframe src: https://accounts.google.com/gsi/button?type=icon&width=100&client_id=545452448522-m0v1rhhrnbf5l5u9pku5p7fjq1fj6bc0.apps.googleusercontent.com&iframe_id=gsi_855822_27907&as=mYVtgtgzQ574t5iQchEcsw
Source: https://www.drawnames.com/account/sign-inHTTP Parser: <input type="password" .../> found
Source: https://accounts.google.com/v3/signin/identifier?opparams=%253Fgis_params%253DChlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tEhlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tGAcqFm1ZVnRndGd6UTU3NHQ1aVFjaEVjc3cySDU0NTQ1MjQ0ODUyMi1tMHYxcmhocm5iZjVsNXU5cGt1NXA3ZmpxMWZqNmJjMC5hcHBzLmdvb2dsZXVzZXJjb250ZW50LmNvbTgBQkA2ZTdlYjVlMmQ1YjBiNzhlNGQ0MjhhMjU2MDhlZmE4Yzk4YmVkMTAxM2Q5MGY5YTc4ZDA1YTgyZjMwZjU1ZTJh%2526origin%253Dhttps%25253A%25252F%25252Fwww.drawnames.com%2526response_mode%253Dform_post&dsh=S-1792440859%3A1731614868801787&client_id=545452448522-m0v1rhhrnbf5l5u9pku5p7fjq1fj6bc0.apps.googleusercontent.com&ddm=1&display=popup&gsiwebsdk=gis_attributes&o2v=1&prompt=select_account&redirect_uri=https%3A%2F%2Fwww.drawnames.com&response_type=id_token&scope=openid+email+profile&service=lso&flowName=GeneralOAuthFlow&continue=https%3A%2F%2Faccounts.google.com%2Fsignin%2Foauth%2Fconsent%3Fauthuser%3Dunknown%26part%3DAJi8hAOU3pZ4keoWL4a2Ovsuq-zuUfgKYSFWJJav42hVY9ecK6zKGygkaNtBWhxyoESLe_S1LIvEFlj_GxzEoip4lNupMITAoxWhd8Is-ORcRgp6PjdxSVQafpnmmCv8BNJxt...HTTP Parser: <input type="password" .../> found
Source: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4HTTP Parser: No favicon
Source: https://static-cdn.drawnames.com/Content/Assets/icon-account-inactive.svg?nc=201911111111HTTP Parser: No favicon
Source: https://www.amazon.com/dp/B0CV6TDDLX?tag=drawnacom-20&linkCode=osi&th=1&psc=1&dn_platform=websiteHTTP Parser: No favicon
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?opparams=%253Fgis_params%253DChlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tEhlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tGAcqFm1ZVnRndGd6UTU3NHQ1aVFjaEVjc3cySDU0NTQ1MjQ0ODUyMi1tMHYxcmhocm5iZjVsNXU5cGt1NXA3ZmpxMWZqNmJjMC5hcHBzLmdvb2dsZXVzZXJjb250ZW50LmNvbTgBQkA2ZTdlYjVlMmQ1YjBiNzhlNGQ0MjhhMjU2MDhlZmE4Yzk4YmVkMTAxM2Q5MGY5YTc4ZDA1YTgyZjMwZjU1ZTJh%2526origin%253Dhttps%25253A%25252F%25252Fwww.drawnames.com%2526response_mode%253Dform_post&dsh=S-1792440859%3A1731614868801787&client_id=545452448522-m0v1rhhrnbf5l5u9pku5p7fjq1fj6bc0.apps.googleusercontent.com&ddm=1&display=popup&gsiwebsdk=gis_attributes&o2v=1&prompt=select_account&redirect_uri=https%3A%2F%2Fwww.drawnames.com&response_type=id_token&scope=openid+email+profile&service=lso&flowName=GeneralOAuthFlow&continue=https%3A%2F%2Faccounts.google.com%2Fsignin%2Foauth%2Fconsent%3Fauthuser%3Dunknown%26part%3DAJi8hAOU3pZ4keoWL4a2Ovsuq-zuUfgKYSFWJJav42hVY9ecK6zKGygkaNtBWhxyoESLe_S1LIvEFlj_GxzEoip4lNupMITAoxWhd8Is-ORcRgp6PjdxSVQafpnmmCv8BNJxt...HTTP Parser: No favicon
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No <meta name="author".. found
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No <meta name="author".. found
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No <meta name="author".. found
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No <meta name="author".. found
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?opparams=%253Fgis_params%253DChlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tEhlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tGAcqFm1ZVnRndGd6UTU3NHQ1aVFjaEVjc3cySDU0NTQ1MjQ0ODUyMi1tMHYxcmhocm5iZjVsNXU5cGt1NXA3ZmpxMWZqNmJjMC5hcHBzLmdvb2dsZXVzZXJjb250ZW50LmNvbTgBQkA2ZTdlYjVlMmQ1YjBiNzhlNGQ0MjhhMjU2MDhlZmE4Yzk4YmVkMTAxM2Q5MGY5YTc4ZDA1YTgyZjMwZjU1ZTJh%2526origin%253Dhttps%25253A%25252F%25252Fwww.drawnames.com%2526response_mode%253Dform_post&dsh=S-1792440859%3A1731614868801787&client_id=545452448522-m0v1rhhrnbf5l5u9pku5p7fjq1fj6bc0.apps.googleusercontent.com&ddm=1&display=popup&gsiwebsdk=gis_attributes&o2v=1&prompt=select_account&redirect_uri=https%3A%2F%2Fwww.drawnames.com&response_type=id_token&scope=openid+email+profile&service=lso&flowName=GeneralOAuthFlow&continue=https%3A%2F%2Faccounts.google.com%2Fsignin%2Foauth%2Fconsent%3Fauthuser%3Dunknown%26part%3DAJi8hAOU3pZ4keoWL4a2Ovsuq-zuUfgKYSFWJJav42hVY9ecK6zKGygkaNtBWhxyoESLe_S1LIvEFlj_GxzEoip4lNupMITAoxWhd8Is-ORcRgp6PjdxSVQafpnmmCv8BNJxtHTTP Parser: No <meta name="author".. found
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No <meta name="copyright".. found
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No <meta name="copyright".. found
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No <meta name="copyright".. found
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No <meta name="copyright".. found
Source: https://www.drawnames.com/account/sign-inHTTP Parser: No <meta name="copyright".. found
Source: https://accounts.google.com/v3/signin/identifier?opparams=%253Fgis_params%253DChlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tEhlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tGAcqFm1ZVnRndGd6UTU3NHQ1aVFjaEVjc3cySDU0NTQ1MjQ0ODUyMi1tMHYxcmhocm5iZjVsNXU5cGt1NXA3ZmpxMWZqNmJjMC5hcHBzLmdvb2dsZXVzZXJjb250ZW50LmNvbTgBQkA2ZTdlYjVlMmQ1YjBiNzhlNGQ0MjhhMjU2MDhlZmE4Yzk4YmVkMTAxM2Q5MGY5YTc4ZDA1YTgyZjMwZjU1ZTJh%2526origin%253Dhttps%25253A%25252F%25252Fwww.drawnames.com%2526response_mode%253Dform_post&dsh=S-1792440859%3A1731614868801787&client_id=545452448522-m0v1rhhrnbf5l5u9pku5p7fjq1fj6bc0.apps.googleusercontent.com&ddm=1&display=popup&gsiwebsdk=gis_attributes&o2v=1&prompt=select_account&redirect_uri=https%3A%2F%2Fwww.drawnames.com&response_type=id_token&scope=openid+email+profile&service=lso&flowName=GeneralOAuthFlow&continue=https%3A%2F%2Faccounts.google.com%2Fsignin%2Foauth%2Fconsent%3Fauthuser%3Dunknown%26part%3DAJi8hAOU3pZ4keoWL4a2Ovsuq-zuUfgKYSFWJJav42hVY9ecK6zKGygkaNtBWhxyoESLe_S1LIvEFlj_GxzEoip4lNupMITAoxWhd8Is-ORcRgp6PjdxSVQafpnmmCv8BNJxt...HTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49828 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49843 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49844 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49884 version: TLS 1.2
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: global trafficDNS traffic detected: DNS query: www.drawnames.com
Source: global trafficDNS traffic detected: DNS query: static-cdn.drawnames.com
Source: global trafficDNS traffic detected: DNS query: gf-details.drawnames.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: gf-wishgiftdetails.drawnames.com
Source: global trafficDNS traffic detected: DNS query: gf-categories.drawnames.com
Source: global trafficDNS traffic detected: DNS query: gf-merchants.drawnames.com
Source: global trafficDNS traffic detected: DNS query: gf-search.drawnames.com
Source: global trafficDNS traffic detected: DNS query: cachena-cdn.drawnames.com
Source: global trafficDNS traffic detected: DNS query: www.facebook.com
Source: global trafficDNS traffic detected: DNS query: www.amazon.com
Source: global trafficDNS traffic detected: DNS query: images-na.ssl-images-amazon.com
Source: global trafficDNS traffic detected: DNS query: fls-na.amazon.com
Source: global trafficDNS traffic detected: DNS query: connect.facebook.net
Source: global trafficDNS traffic detected: DNS query: csp.withgoogle.com
Source: global trafficDNS traffic detected: DNS query: play.google.com
Source: global trafficDNS traffic detected: DNS query: lh3.googleusercontent.com
Source: global trafficDNS traffic detected: DNS query: accounts.youtube.com
Source: global trafficDNS traffic detected: DNS query: m.media-amazon.com
Source: global trafficDNS traffic detected: DNS query: completion.amazon.com
Source: global trafficDNS traffic detected: DNS query: d1cgrmilfgg1y.cloudfront.net
Source: global trafficDNS traffic detected: DNS query: d1nruqhae353qc.cloudfront.net
Source: global trafficDNS traffic detected: DNS query: d2h8zr0m6mus4x.cloudfront.net
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49983
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49980
Source: unknownNetwork traffic detected: HTTP traffic on port 49932 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50131 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49979
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49978
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49976
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49975
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49974
Source: unknownNetwork traffic detected: HTTP traffic on port 50085 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49971
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49909 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49969
Source: unknownNetwork traffic detected: HTTP traffic on port 49978 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49967
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49965
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49964
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49962
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49961
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49960
Source: unknownNetwork traffic detected: HTTP traffic on port 50108 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50073 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50028 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49959
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49958
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49957
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49954
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49953
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49952
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49951
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49950
Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50051 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50153 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49949
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49948
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49947
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49946
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49945
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 50061 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 50026 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 50095 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50155 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 50038 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50143 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 50083 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 50121 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 50016 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49934 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 50036 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50151 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50116 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50071 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50106
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50105
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50108
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50107
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50109
Source: unknownNetwork traffic detected: HTTP traffic on port 49929 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50100
Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50102
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50101
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50104
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50103
Source: unknownNetwork traffic detected: HTTP traffic on port 49964 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50128 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50117
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50116
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50119
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50118
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50111
Source: unknownNetwork traffic detected: HTTP traffic on port 49930 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50110
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50113
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50112
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50115
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50114
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50128
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50127
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50129
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 49952 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50120
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 50093 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50122
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50121
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50124
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50123
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50126
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50125
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50048 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49907 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50106 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50081 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49919 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49954 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50014 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50046 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50141 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49976 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50118 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50024 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50163 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50058 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49920 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49926 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50054
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50053
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50056
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50055
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50058
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50057
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50059
Source: unknownNetwork traffic detected: HTTP traffic on port 49961 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50061
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50060
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50063
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50062
Source: unknownNetwork traffic detected: HTTP traffic on port 50102 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50045 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50148 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50065
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50064
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50067
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50066
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50069
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50068
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50070
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50072
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50071
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50074
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50073
Source: unknownNetwork traffic detected: HTTP traffic on port 50080 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50076
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50075
Source: unknownNetwork traffic detected: HTTP traffic on port 50057 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50078
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50077
Source: unknownNetwork traffic detected: HTTP traffic on port 50114 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50079
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50081
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50080
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50083
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50082
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50085
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50084
Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50087
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50086
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50089
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50088
Source: unknownNetwork traffic detected: HTTP traffic on port 50079 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50090
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50092
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50091
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50094
Source: unknownNetwork traffic detected: HTTP traffic on port 50136 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49983 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50093
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50096
Source: unknownNetwork traffic detected: HTTP traffic on port 49938 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50023 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50095
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50018
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50017
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50019
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49951 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50010
Source: unknownNetwork traffic detected: HTTP traffic on port 49916 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50055 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50090 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50014
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50013
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50016
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50015
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50029
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50028
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50021
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50020
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50023
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50022
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50025
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50024
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50027
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50026
Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50021 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50030
Source: unknownNetwork traffic detected: HTTP traffic on port 50138 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50067 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50039
Source: unknownNetwork traffic detected: HTTP traffic on port 49928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50032
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50031
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50034
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50033
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50036
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50035
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50038
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50037
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50041
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50040
Source: unknownNetwork traffic detected: HTTP traffic on port 50104 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50089 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50033 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50043
Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50042
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50045
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50044
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50047
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50046
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50049
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50048
Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50050
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50052
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50051
Source: unknownNetwork traffic detected: HTTP traffic on port 50126 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50122 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49958 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49946 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50018 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50077 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50134 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50053 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49924 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50099 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50031 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50156 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50043 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50100 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50065 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49942
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49941
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50098
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50097
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50099
Source: unknownNetwork traffic detected: HTTP traffic on port 50112 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50075 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50158 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49938
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49937
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49936
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49935
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49934
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49933
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49932
Source: unknownNetwork traffic detected: HTTP traffic on port 50087 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49931
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49930
Source: unknownNetwork traffic detected: HTTP traffic on port 49971 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49936 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49929
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49928
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49927
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49926
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49925
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49924
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49923
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49922
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49921
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49920
Source: unknownNetwork traffic detected: HTTP traffic on port 50063 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50124 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49877 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49914 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49919
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49918
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49917
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49916
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49915
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49914
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49913
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49911
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49910
Source: unknownNetwork traffic detected: HTTP traffic on port 49948 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50041 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50146 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49899 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50097 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49909
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49907
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49906
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49905
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49904
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49903
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49901
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49900
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50154 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 50039 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 49967 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50074 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50107 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 50120 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49828 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49843 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49844 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49884 version: TLS 1.2
Source: classification engineClassification label: mal48.phis.win@26/6@94/413
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1888,i,1732873202329785937,16230637607138776747,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1888,i,1732873202329785937,16230637607138776747,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6256 --field-trial-handle=1888,i,1732873202329785937,16230637607138776747,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=6220 --field-trial-handle=1888,i,1732873202329785937,16230637607138776747,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6256 --field-trial-handle=1888,i,1732873202329785937,16230637607138776747,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=6220 --field-trial-handle=1888,i,1732873202329785937,16230637607138776747,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Drive-by Compromise
Windows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/40%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
star-mini.c10r.facebook.com
157.240.0.35
truefalse
    high
    p-defr00.kxcdn.com
    185.172.148.128
    truefalse
      high
      csp.withgoogle.com
      172.217.18.17
      truefalse
        high
        hosts.dnusgetwishgiftdetailsfa.azurewebsites.net
        20.49.104.35
        truefalse
          unknown
          hosts.dnusgetdetailsfa.azurewebsites.net
          20.49.104.35
          truefalse
            unknown
            hosts.dnusgetmerchantsfa.azurewebsites.net
            20.49.104.35
            truefalse
              unknown
              hosts.dnussearchfa.azurewebsites.net
              20.49.104.35
              truefalse
                unknown
                ax-0001.ax-msedge.net
                150.171.28.10
                truefalse
                  high
                  media.amazon.map.fastly.net
                  151.101.65.16
                  truefalse
                    unknown
                    d2h8zr0m6mus4x.cloudfront.net
                    13.32.118.212
                    truefalse
                      unknown
                      completion.amazon.com
                      44.215.116.37
                      truefalse
                        unknown
                        scontent.xx.fbcdn.net
                        157.240.251.9
                        truefalse
                          high
                          play.google.com
                          216.58.206.78
                          truefalse
                            high
                            www3.l.google.com
                            142.250.185.174
                            truefalse
                              high
                              hosts.dnusgetcategoriesfa.azurewebsites.net
                              20.49.104.35
                              truefalse
                                unknown
                                d1cgrmilfgg1y.cloudfront.net
                                3.160.156.217
                                truefalse
                                  unknown
                                  d1nruqhae353qc.cloudfront.net
                                  13.225.84.24
                                  truefalse
                                    unknown
                                    www.drawnames.com
                                    85.10.142.19
                                    truefalse
                                      high
                                      www.google.com
                                      172.217.16.196
                                      truefalse
                                        high
                                        c.media-amazon.com
                                        108.138.1.27
                                        truefalse
                                          unknown
                                          d3ag4hukkh62yn.cloudfront.net
                                          99.86.8.42
                                          truefalse
                                            unknown
                                            googlehosted.l.googleusercontent.com
                                            216.58.212.129
                                            truefalse
                                              high
                                              endpoint.prod.us-east-1.forester.a2z.com
                                              174.129.222.11
                                              truefalse
                                                unknown
                                                www.facebook.com
                                                unknown
                                                unknownfalse
                                                  high
                                                  m.media-amazon.com
                                                  unknown
                                                  unknownfalse
                                                    high
                                                    gf-merchants.drawnames.com
                                                    unknown
                                                    unknownfalse
                                                      high
                                                      gf-search.drawnames.com
                                                      unknown
                                                      unknownfalse
                                                        high
                                                        gf-details.drawnames.com
                                                        unknown
                                                        unknownfalse
                                                          unknown
                                                          gf-categories.drawnames.com
                                                          unknown
                                                          unknownfalse
                                                            high
                                                            images-na.ssl-images-amazon.com
                                                            unknown
                                                            unknownfalse
                                                              high
                                                              connect.facebook.net
                                                              unknown
                                                              unknownfalse
                                                                high
                                                                lh3.googleusercontent.com
                                                                unknown
                                                                unknownfalse
                                                                  high
                                                                  static-cdn.drawnames.com
                                                                  unknown
                                                                  unknownfalse
                                                                    high
                                                                    www.amazon.com
                                                                    unknown
                                                                    unknownfalse
                                                                      high
                                                                      gf-wishgiftdetails.drawnames.com
                                                                      unknown
                                                                      unknownfalse
                                                                        unknown
                                                                        accounts.youtube.com
                                                                        unknown
                                                                        unknownfalse
                                                                          high
                                                                          cachena-cdn.drawnames.com
                                                                          unknown
                                                                          unknownfalse
                                                                            high
                                                                            fls-na.amazon.com
                                                                            unknown
                                                                            unknownfalse
                                                                              high
                                                                              NameMaliciousAntivirus DetectionReputation
                                                                              https://www.amazon.com/dp/B0CV6TDDLX?tag=drawnacom-20&linkCode=osi&th=1&psc=1&dn_platform=websitetrue
                                                                                unknown
                                                                                https://static-cdn.drawnames.com/Content/Assets/icon-account-inactive.svg?nc=201911111111false
                                                                                  unknown
                                                                                  https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4false
                                                                                    unknown
                                                                                    https://www.drawnames.com/account/sign-infalse
                                                                                      unknown
                                                                                      • No. of IPs < 25%
                                                                                      • 25% < No. of IPs < 50%
                                                                                      • 50% < No. of IPs < 75%
                                                                                      • 75% < No. of IPs
                                                                                      IPDomainCountryFlagASNASN NameMalicious
                                                                                      142.250.185.99
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      18.239.70.223
                                                                                      unknownUnited States
                                                                                      16509AMAZON-02USfalse
                                                                                      172.217.16.138
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      108.138.16.195
                                                                                      unknownUnited States
                                                                                      16509AMAZON-02USfalse
                                                                                      151.101.1.16
                                                                                      unknownUnited States
                                                                                      54113FASTLYUSfalse
                                                                                      3.215.167.18
                                                                                      unknownUnited States
                                                                                      14618AMAZON-AESUSfalse
                                                                                      142.250.185.227
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      142.250.185.106
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      142.250.184.225
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      142.250.186.110
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      13.225.84.24
                                                                                      d1nruqhae353qc.cloudfront.netUnited States
                                                                                      16509AMAZON-02USfalse
                                                                                      142.250.184.195
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      142.250.185.68
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      1.1.1.1
                                                                                      unknownAustralia
                                                                                      13335CLOUDFLARENETUSfalse
                                                                                      99.86.8.42
                                                                                      d3ag4hukkh62yn.cloudfront.netUnited States
                                                                                      16509AMAZON-02USfalse
                                                                                      216.58.206.40
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      157.240.0.35
                                                                                      star-mini.c10r.facebook.comUnited States
                                                                                      32934FACEBOOKUSfalse
                                                                                      172.217.18.3
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      85.10.142.19
                                                                                      www.drawnames.comFrance
                                                                                      21283A1SI-ASA1SlovenijaSIfalse
                                                                                      239.255.255.250
                                                                                      unknownReserved
                                                                                      unknownunknownfalse
                                                                                      23.215.17.144
                                                                                      unknownUnited States
                                                                                      20940AKAMAI-ASN1EUfalse
                                                                                      142.250.185.194
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      142.250.186.40
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      142.250.184.238
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      172.217.16.196
                                                                                      www.google.comUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      142.250.186.46
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      172.217.18.17
                                                                                      csp.withgoogle.comUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      142.250.185.78
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      216.58.206.74
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      216.58.206.78
                                                                                      play.google.comUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      18.245.200.135
                                                                                      unknownUnited States
                                                                                      16509AMAZON-02USfalse
                                                                                      216.58.212.129
                                                                                      googlehosted.l.googleusercontent.comUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      80.69.88.77
                                                                                      unknownNetherlands
                                                                                      20857TRANSIP-ASAmsterdamtheNetherlandsNLfalse
                                                                                      151.101.65.16
                                                                                      media.amazon.map.fastly.netUnited States
                                                                                      54113FASTLYUSfalse
                                                                                      74.125.206.84
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      150.171.28.10
                                                                                      ax-0001.ax-msedge.netUnited States
                                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                      142.250.184.206
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      3.160.156.217
                                                                                      d1cgrmilfgg1y.cloudfront.netUnited States
                                                                                      16509AMAZON-02USfalse
                                                                                      20.49.104.35
                                                                                      hosts.dnusgetwishgiftdetailsfa.azurewebsites.netUnited States
                                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                      185.172.148.132
                                                                                      unknownGermany
                                                                                      44239PROINITYPROINITYDEfalse
                                                                                      142.250.186.99
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      66.102.1.84
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      142.250.110.84
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      108.138.1.27
                                                                                      c.media-amazon.comUnited States
                                                                                      16509AMAZON-02USfalse
                                                                                      142.250.185.138
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      174.129.222.11
                                                                                      endpoint.prod.us-east-1.forester.a2z.comUnited States
                                                                                      14618AMAZON-AESUSfalse
                                                                                      3.160.156.24
                                                                                      unknownUnited States
                                                                                      16509AMAZON-02USfalse
                                                                                      3.214.44.145
                                                                                      unknownUnited States
                                                                                      14618AMAZON-AESUSfalse
                                                                                      150.171.27.10
                                                                                      unknownUnited States
                                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                      157.240.251.9
                                                                                      scontent.xx.fbcdn.netUnited States
                                                                                      32934FACEBOOKUSfalse
                                                                                      185.172.148.128
                                                                                      p-defr00.kxcdn.comGermany
                                                                                      44239PROINITYPROINITYDEfalse
                                                                                      142.250.185.174
                                                                                      www3.l.google.comUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      157.240.253.1
                                                                                      unknownUnited States
                                                                                      32934FACEBOOKUSfalse
                                                                                      54.145.222.9
                                                                                      unknownUnited States
                                                                                      14618AMAZON-AESUSfalse
                                                                                      64.233.184.84
                                                                                      unknownUnited States
                                                                                      15169GOOGLEUSfalse
                                                                                      IP
                                                                                      192.168.2.16
                                                                                      Joe Sandbox version:41.0.0 Charoite
                                                                                      Analysis ID:1556058
                                                                                      Start date and time:2024-11-14 21:05:56 +01:00
                                                                                      Joe Sandbox product:CloudBasic
                                                                                      Overall analysis duration:
                                                                                      Hypervisor based Inspection enabled:false
                                                                                      Report type:full
                                                                                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                      Sample URL:https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4
                                                                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                      Number of analysed new started processes analysed:15
                                                                                      Number of new started drivers analysed:0
                                                                                      Number of existing processes analysed:0
                                                                                      Number of existing drivers analysed:0
                                                                                      Number of injected processes analysed:0
                                                                                      Technologies:
                                                                                      • EGA enabled
                                                                                      Analysis Mode:stream
                                                                                      Analysis stop reason:Timeout
                                                                                      Detection:MAL
                                                                                      Classification:mal48.phis.win@26/6@94/413
                                                                                      • Exclude process from analysis (whitelisted): svchost.exe
                                                                                      • Excluded IPs from analysis (whitelisted): 142.250.184.195, 142.250.184.206, 74.125.206.84, 34.104.35.123, 216.58.206.40
                                                                                      • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, www.googletagmanager.com, clientservices.googleapis.com, clients.l.google.com
                                                                                      • Not all processes where analyzed, report is missing behavior information
                                                                                      • VT rate limit hit for: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4
                                                                                      InputOutput
                                                                                      URL: https://www.drawnames.com Model: Joe Sandbox AI
                                                                                      {
                                                                                          "typosquatting": false,
                                                                                          "unusual_query_string": false,
                                                                                          "suspicious_tld": false,
                                                                                          "ip_in_url": false,
                                                                                          "long_subdomain": false,
                                                                                          "malicious_keywords": false,
                                                                                          "encoded_characters": false,
                                                                                          "redirection": false,
                                                                                          "contains_email_address": false,
                                                                                          "known_domain": true,
                                                                                          "brand_spoofing_attempt": false,
                                                                                          "third_party_hosting": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": true,
                                                                                        "trigger_text": "We use cookies for marketing purposes.",
                                                                                        "prominent_button_name": "I agree",
                                                                                        "text_input_field_labels": "unknown",
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": false,
                                                                                        "trigger_text": "unknown",
                                                                                        "prominent_button_name": "Search in Gift Finder",
                                                                                        "text_input_field_labels": "unknown",
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": false,
                                                                                        "trigger_text": "unknown",
                                                                                        "prominent_button_name": "Search in Gift Finder",
                                                                                        "text_input_field_labels": "unknown",
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "drawnnames"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": false,
                                                                                        "trigger_text": "unknown",
                                                                                        "prominent_button_name": "Search in Gift Finder",
                                                                                        "text_input_field_labels": "unknown",
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "drawnnames"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "Drawnames"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "URBAN COLLECTION",
                                                                                          "Pure Daily Care"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://static-cdn.drawnames.com Model: Joe Sandbox AI
                                                                                      {
                                                                                          "typosquatting": false,
                                                                                          "unusual_query_string": false,
                                                                                          "suspicious_tld": false,
                                                                                          "ip_in_url": false,
                                                                                          "long_subdomain": false,
                                                                                          "malicious_keywords": false,
                                                                                          "encoded_characters": false,
                                                                                          "redirection": false,
                                                                                          "contains_email_address": false,
                                                                                          "known_domain": false,
                                                                                          "brand_spoofing_attempt": false,
                                                                                          "third_party_hosting": true
                                                                                      }
                                                                                      URL: https://static-cdn.drawnames.com
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": false,
                                                                                        "trigger_text": "unknown",
                                                                                        "prominent_button_name": "View details",
                                                                                        "text_input_field_labels": "unknown",
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "MOKPR"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": false,
                                                                                        "trigger_text": "unknown",
                                                                                        "prominent_button_name": "Search in Gift Finder",
                                                                                        "text_input_field_labels": "unknown",
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.amazon.com/dp/B0CV6TDDLX?tag=drawnacom-20&linkCode=osi&th=1&psc=1&dn_platform=website Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": false,
                                                                                        "trigger_text": "unknown",
                                                                                        "prominent_button_name": "Continue shopping",
                                                                                        "text_input_field_labels": [
                                                                                          "Type characters"
                                                                                        ],
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": true,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.amazon.com/dp/B0CV6TDDLX?tag=drawnacom-20&linkCode=osi&th=1&psc=1&dn_platform=website Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "Amazon"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.amazon.com Model: Joe Sandbox AI
                                                                                      {
                                                                                          "typosquatting": false,
                                                                                          "unusual_query_string": false,
                                                                                          "suspicious_tld": false,
                                                                                          "ip_in_url": false,
                                                                                          "long_subdomain": false,
                                                                                          "malicious_keywords": false,
                                                                                          "encoded_characters": false,
                                                                                          "redirection": false,
                                                                                          "contains_email_address": false,
                                                                                          "known_domain": true,
                                                                                          "brand_spoofing_attempt": false,
                                                                                          "third_party_hosting": false
                                                                                      }
                                                                                      URL: https://www.amazon.com
                                                                                      URL: https://www.drawnames.com/wishlist/draw/GeoZyywvK48h1oNNizPuIQ-/W47fz4Y7Ik4eooK-94HN8w-/4 Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "URBAN COLLECTION",
                                                                                          "Pure Daily Care",
                                                                                          "MOKPR"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.amazon.com/dp/B0CV6TDDLX?tag=drawnacom-20&linkCode=osi&th=1&psc=1&dn_platform=website Model: Joe Sandbox AI
                                                                                      ```json{  "legit_domain": "amazon.com",  "classification": "wellknown",  "reasons": [    "The URL 'www.amazon.com' matches the legitimate domain name for the brand 'Amazon'.",    "Amazon is a well-known global e-commerce brand.",    "There are no suspicious elements in the URL such as misspellings, extra characters, or unusual domain extensions.",    "The domain is fully matching with the brand name, indicating a legitimate webpage."  ],  "riskscore": 1}
                                                                                      URL: www.amazon.com
                                                                                                  Brands: Amazon
                                                                                                  Input Fields: Type characters
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": false,
                                                                                        "trigger_text": "unknown",
                                                                                        "prominent_button_name": "unknown",
                                                                                        "text_input_field_labels": "unknown",
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": true,
                                                                                        "trigger_text": "Sign in",
                                                                                        "prominent_button_name": "Sign in",
                                                                                        "text_input_field_labels": [
                                                                                          "Email address",
                                                                                          "Password"
                                                                                        ],
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": true,
                                                                                        "trigger_text": "Sign in",
                                                                                        "prominent_button_name": "Sign in",
                                                                                        "text_input_field_labels": [
                                                                                          "Email address",
                                                                                          "Password"
                                                                                        ],
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "drawnnames"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": true,
                                                                                        "trigger_text": "Sign in",
                                                                                        "prominent_button_name": "Sign in",
                                                                                        "text_input_field_labels": [
                                                                                          "Email address",
                                                                                          "Password"
                                                                                        ],
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "drawnnames"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "drawnnames"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "drawnnames"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json{  "legit_domain": "drawnames.com",  "classification": "unknown",  "reasons": [    "The brand 'drawnnames' is not widely recognized, making it difficult to classify as 'known' or 'wellknown'.",    "The URL 'www.drawnames.com' closely matches the brand name 'drawnnames', but there is a slight discrepancy in spelling.",    "The domain 'drawnames.com' appears legitimate and does not contain suspicious elements such as misspellings or unusual domain extensions.",    "The presence of input fields for 'Email address' and 'Password' is common for legitimate sites but can also be used in phishing attempts."  ],  "riskscore": 4}
                                                                                      URL: www.drawnames.com
                                                                                                  Brands: drawnnames
                                                                                                  Input Fields: Email address, Password
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json{  "legit_domain": "drawnames.com",  "classification": "unknown",  "reasons": [    "The brand name 'drawnnames' does not match the URL 'drawnames.com'.",    "The URL 'www.drawnames.com' appears to be a legitimate domain for a service related to drawing names, but the brand 'drawnnames' is not recognized as a well-known or known brand.",    "The URL does not contain suspicious elements such as misspellings or unusual domain extensions.",    "The presence of input fields for email address and password is common for legitimate services but can also be used in phishing sites."  ],  "riskscore": 5}
                                                                                      URL: www.drawnames.com
                                                                                                  Brands: drawnnames
                                                                                                  Input Fields: Email address, Password
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json{  "legit_domain": "drawnames.com",  "classification": "unknown",  "reasons": [    "The brand name 'drawnnames' is not a well-known or widely recognized brand.",    "The URL 'www.drawnames.com' closely matches the brand name 'drawnnames', but there is a slight discrepancy in spelling.",    "The domain 'drawnames.com' appears to be a legitimate domain, but the brand name provided does not exactly match the URL.",    "The presence of input fields for 'Email address' and 'Password' is common for login pages, but without further context, it is not possible to determine legitimacy solely based on these fields."  ],  "riskscore": 5}
                                                                                      URL: www.drawnames.com
                                                                                                  Brands: drawnnames
                                                                                                  Input Fields: Email address, Password
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": true,
                                                                                        "trigger_text": "Your account gives you easy access to your wish list, drawn name and group page.",
                                                                                        "prominent_button_name": "Sign in",
                                                                                        "text_input_field_labels": [
                                                                                          "Email address",
                                                                                          "Password"
                                                                                        ],
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "drawnnames"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://www.drawnames.com/account/sign-in Model: Joe Sandbox AI
                                                                                      ```json{  "legit_domain": "drawnames.com",  "classification": "unknown",  "reasons": [    "The brand 'drawnnames' is not widely recognized, making it difficult to classify as 'known' or 'wellknown'.",    "The URL 'www.drawnames.com' closely matches the brand name 'drawnnames', but there is a slight discrepancy in spelling.",    "The domain 'drawnames.com' appears legitimate and does not contain suspicious elements such as misspellings or unusual characters.",    "The presence of input fields for 'Email address' and 'Password' is common for legitimate sites but can also be used in phishing attempts."  ],  "riskscore": 3}
                                                                                      URL: www.drawnames.com
                                                                                                  Brands: drawnnames
                                                                                                  Input Fields: Email address, Password
                                                                                      URL: https://accounts.google.com/v3/signin/identifier?opparams=%253Fgis_params%253DChlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tEhlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tGAcqFm1ZVnRndGd6UTU3NHQ1aVFjaEVjc3cySDU0NTQ1MjQ0ODUyMi1tMHYxcmhocm5iZjVsNXU5cGt1NXA3ZmpxMWZqNmJjMC5hcHBzL Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": true,
                                                                                        "trigger_text": "Sign in to continue to drawnnames.com",
                                                                                        "prominent_button_name": "Next",
                                                                                        "text_input_field_labels": [
                                                                                          "Email or phone"
                                                                                        ],
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://accounts.google.com/v3/signin/identifier?opparams=%253Fgis_params%253DChlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tEhlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tGAcqFm1ZVnRndGd6UTU3NHQ1aVFjaEVjc3cySDU0NTQ1MjQ0ODUyMi1tMHYxcmhocm5iZjVsNXU5cGt1NXA3ZmpxMWZqNmJjMC5hcHBzL Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "contains_trigger_text": true,
                                                                                        "trigger_text": "Sign in to continue to drawnnames.com",
                                                                                        "prominent_button_name": "Next",
                                                                                        "text_input_field_labels": [
                                                                                          "Email or phone"
                                                                                        ],
                                                                                        "pdf_icon_visible": false,
                                                                                        "has_visible_captcha": false,
                                                                                        "has_urgent_text": false,
                                                                                        "has_visible_qrcode": false
                                                                                      }
                                                                                      URL: https://accounts.google.com Model: Joe Sandbox AI
                                                                                      {
                                                                                          "typosquatting": false,
                                                                                          "unusual_query_string": false,
                                                                                          "suspicious_tld": false,
                                                                                          "ip_in_url": false,
                                                                                          "long_subdomain": false,
                                                                                          "malicious_keywords": false,
                                                                                          "encoded_characters": false,
                                                                                          "redirection": false,
                                                                                          "contains_email_address": false,
                                                                                          "known_domain": true,
                                                                                          "brand_spoofing_attempt": false,
                                                                                          "third_party_hosting": false
                                                                                      }
                                                                                      URL: https://accounts.google.com
                                                                                      URL: https://accounts.google.com/v3/signin/identifier?opparams=%253Fgis_params%253DChlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tEhlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tGAcqFm1ZVnRndGd6UTU3NHQ1aVFjaEVjc3cySDU0NTQ1MjQ0ODUyMi1tMHYxcmhocm5iZjVsNXU5cGt1NXA3ZmpxMWZqNmJjMC5hcHBzL Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "Google"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://accounts.google.com/v3/signin/identifier?opparams=%253Fgis_params%253DChlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tEhlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tGAcqFm1ZVnRndGd6UTU3NHQ1aVFjaEVjc3cySDU0NTQ1MjQ0ODUyMi1tMHYxcmhocm5iZjVsNXU5cGt1NXA3ZmpxMWZqNmJjMC5hcHBzL Model: Joe Sandbox AI
                                                                                      ```json
                                                                                      {
                                                                                        "brands": [
                                                                                          "Google"
                                                                                        ]
                                                                                      }
                                                                                      URL: https://accounts.google.com/v3/signin/identifier?opparams=%253Fgis_params%253DChlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tEhlodHRwczovL3d3dy5kcmF3bmFtZXMuY29tGAcqFm1ZVnRndGd6UTU3NHQ1aVFjaEVjc3cySDU0NTQ1MjQ0ODUyMi1tMHYxcmhocm5iZjVsNXU5cGt1NXA3ZmpxMWZqNmJjMC5hcHBzL Model: Joe Sandbox AI
                                                                                      ```json{  "legit_domain": "google.com",  "classification": "wellknown",  "reasons": [    "The URL 'accounts.google.com' is a subdomain of 'google.com', which is the legitimate domain for Google.",    "Google is a well-known brand with a strong online presence.",    "The URL does not contain any suspicious elements such as misspellings, extra characters, or unusual domain extensions.",    "The input fields 'Email or phone' are consistent with Google's account login pages."  ],  "riskscore": 1}
                                                                                      URL: accounts.google.com
                                                                                                  Brands: Google
                                                                                                  Input Fields: Email or phone
                                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Nov 14 19:06:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                      Category:dropped
                                                                                      Size (bytes):2673
                                                                                      Entropy (8bit):3.9836884897755427
                                                                                      Encrypted:false
                                                                                      SSDEEP:
                                                                                      MD5:8CD6E3034877916609C8D1A3B61303B3
                                                                                      SHA1:5A895F75B4E005815F096C84A793A8CB142E04D2
                                                                                      SHA-256:C558B7F40592DBE8299CBE0DD0681459C1FD89E5971C5DCC9287983773E901BB
                                                                                      SHA-512:ECB909CC35DF7B3AB61CFDF2E8DECE3EA0BE396BBE205358AB9726B078713683C4B775BCA0A820B34FAE1BD0CD3BBF17549B199BC0A4CAF8C7F7F9B8A44A3523
                                                                                      Malicious:false
                                                                                      Reputation:unknown
                                                                                      Preview:L..................F.@.. ...$+.,....$...6..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.InY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VnY.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VnY.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VnY............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VnY............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........1..Y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Nov 14 19:06:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                      Category:dropped
                                                                                      Size (bytes):2675
                                                                                      Entropy (8bit):3.999324836256093
                                                                                      Encrypted:false
                                                                                      SSDEEP:
                                                                                      MD5:582030C51D328E2EEC9DB0C91687C86D
                                                                                      SHA1:F24E118A171AA37DD6C5F6257990377C032FEA54
                                                                                      SHA-256:68B49B8939B9470FBD0B3CAC679C1C1EC3F762CC9A5FE8FCFEDA946B67141A01
                                                                                      SHA-512:DD7C0D92EB033EEDAC6357953B064B07501AE4341DF6E4CB83825FAE678F4C44C35D35C70B5AF9878ED76C3986ECFACC98FB93E4D4CB57428AC6350EC31D6DE0
                                                                                      Malicious:false
                                                                                      Reputation:unknown
                                                                                      Preview:L..................F.@.. ...$+.,....YD..6..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.InY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VnY.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VnY.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VnY............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VnY............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........1..Y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                      Category:dropped
                                                                                      Size (bytes):2689
                                                                                      Entropy (8bit):4.008813981958212
                                                                                      Encrypted:false
                                                                                      SSDEEP:
                                                                                      MD5:777B62FA9F0B5285F4F35FAAB1F5B186
                                                                                      SHA1:C4CF8D53C34997A1FD7C019113789912A852B705
                                                                                      SHA-256:909B529C9086E63CA072744152656EF37A285736EF117E2E6FFAFEB05C215AA9
                                                                                      SHA-512:DCAF830675C955A32FD935939FE31182962B181BD51E9F548531B8630F182F7C10A86750709D262F3886D977F9FD6D0A019807200759349365E6619F696C62B8
                                                                                      Malicious:false
                                                                                      Reputation:unknown
                                                                                      Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.InY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VnY.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VnY.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VnY............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........1..Y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Nov 14 19:06:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                      Category:dropped
                                                                                      Size (bytes):2677
                                                                                      Entropy (8bit):4.001134877345583
                                                                                      Encrypted:false
                                                                                      SSDEEP:
                                                                                      MD5:D06E132E584BD1BAD06944E7EF61DCDE
                                                                                      SHA1:1E9E7DDC82911543138494DD1456635F7243A55D
                                                                                      SHA-256:CA8D5E7FCB44092941F6C3502997E4E22F3EE9829CD1E0A42545928357B3B5B8
                                                                                      SHA-512:AA6C3BA9A05EEE5C5C7414AAEE5E971A566A77A85DE792771A3C3AD4ADA5B826A4BBB2ACD7E29C4C12246B3315DE1C5C27AE89E292E58E9859CCF80606A26427
                                                                                      Malicious:false
                                                                                      Reputation:unknown
                                                                                      Preview:L..................F.@.. ...$+.,........6..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.InY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VnY.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VnY.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VnY............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VnY............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........1..Y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Nov 14 19:06:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                      Category:dropped
                                                                                      Size (bytes):2677
                                                                                      Entropy (8bit):3.9882844185864994
                                                                                      Encrypted:false
                                                                                      SSDEEP:
                                                                                      MD5:9E05787F12655D0CDE860974C2CBF012
                                                                                      SHA1:E186B66B767DC492FC029A9FB19B6B96F007E440
                                                                                      SHA-256:A379617FC974138BFA197B360034A4888C6B63517234C04FF6596C9F37A12FB9
                                                                                      SHA-512:B34DB3A296022D5EE0D077F157E82479D4DB129A689E15CB03E4291FD74FFB15C8C6C89D8B02A3052BB731F9135943BCE2598D1671E9A1247946C163D86667B9
                                                                                      Malicious:false
                                                                                      Reputation:unknown
                                                                                      Preview:L..................F.@.. ...$+.,.....^..6..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.InY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VnY.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VnY.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VnY............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VnY............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........1..Y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Nov 14 19:06:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                      Category:dropped
                                                                                      Size (bytes):2679
                                                                                      Entropy (8bit):3.9943453044827653
                                                                                      Encrypted:false
                                                                                      SSDEEP:
                                                                                      MD5:7D72FA1F273E9D3083E2F55E150E153A
                                                                                      SHA1:9BABCCA95681633F1E8B1F44F0095B3FD96E9BE2
                                                                                      SHA-256:22A138DAB5E6AB6994A423135443C74C4286D1A4E5E6DF2A327104B03915AC34
                                                                                      SHA-512:A2DA38460195886FB9B36CAFBCDF323AE56B32FC064D98FAF005645AFEBBC47B0067EC37FE7BA4AEF0B2199E76F04C48C14F6AC73F5FE9E5527623D59AAAB580
                                                                                      Malicious:false
                                                                                      Reputation:unknown
                                                                                      Preview:L..................F.@.. ...$+.,....E...6..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.InY.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VnY.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VnY.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VnY............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VnY............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........1..Y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                      No static file info