Edit tour

Windows Analysis Report
http://cdn.taboola-display.com

Overview

General Information

Sample URL:http://cdn.taboola-display.com
Analysis ID:1579911
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1832 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1312 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2000,i,4898467449033585590,11003152932544282617,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6528 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cdn.taboola-display.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.114.18
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.114.18
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.168.117
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.168.117
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: cdn.taboola-display.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: cdn.taboola-display.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://cdn.taboola-display.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: cdn.taboola-display.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenConnection: keep-alivex-amz-bucket-region: us-east-1x-amz-request-id: 79NHFV9JZ2E8R3A2x-amz-id-2: jffQyoUx5bLyHl+xcUaRIiENmz/6AxsTAgdPZZ6W9M4ZX6wTqKm6EynI2uLgwEBLgaTDgz8lbCU=Content-Type: application/xmlServer: AmazonS3Accept-Ranges: bytesDate: Mon, 23 Dec 2024 14:14:25 GMTVia: 1.1 varnishX-Served-By: cache-ewr-kewr1740069-EWRX-Cache: MISSX-Cache-Hits: 0X-Timer: S1734963265.382125,VS0,VE9Cache-Control: private,max-age=14400abp: 89Access-Control-Allow-Origin: *transfer-encoding: chunkedData Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 37 39 4e 48 46 56 39 4a 5a 32 45 38 52 33 41 32 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 6a 66 66 51 79 6f 55 78 35 62 4c 79 48 6c 2b 78 63 55 61 52 49 69 45 4e 6d 7a 2f 36 41 78 73 54 41 67 64 50 5a 5a 36 57 39 4d 34 5a 58 36 77 54 71 4b 6d 36 45 79 6e 49 32 75 4c 67 77 45 42 4c 67 61 54 44 67 7a 38 6c 62 43 55 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a 30 0d 0a 0d 0a Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>79NHFV9JZ2E8R3A2</RequestId><HostId>jffQyoUx5bLyHl+xcUaRIiENmz/6AxsTAgdPZZ6W9M4ZX6wTqKm6EynI2uLgwEBLgaTDgz8lbCU=</HostId></Error>0
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: classification engineClassification label: clean0.win@16/2@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2000,i,4898467449033585590,11003152932544282617,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cdn.taboola-display.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2000,i,4898467449033585590,11003152932544282617,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1579911 URL: http://cdn.taboola-display.com Startdate: 23/12/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49561 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 172.217.21.36, 443, 49737, 49772 GOOGLEUS United States 10->17 19 tls13.taboola.map.fastly.net 151.101.1.44, 49739, 49740, 49741 FASTLYUS United States 10->19 21 cdn.taboola-display.com 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
tls13.taboola.map.fastly.net
151.101.1.44
truefalse
    high
    www.google.com
    172.217.21.36
    truefalse
      high
      cdn.taboola-display.com
      unknown
      unknownfalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://cdn.taboola-display.com/false
          unknown
          http://cdn.taboola-display.com/favicon.icofalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            172.217.21.36
            www.google.comUnited States
            15169GOOGLEUSfalse
            151.101.1.44
            tls13.taboola.map.fastly.netUnited States
            54113FASTLYUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1579911
            Start date and time:2024-12-23 15:13:21 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 59s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://cdn.taboola-display.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/2@4/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.21.35, 173.194.220.84, 172.217.19.238, 172.217.17.46, 142.250.181.142, 199.232.210.172, 192.229.221.95, 172.217.17.35, 23.218.208.109, 4.175.87.197, 13.107.246.63
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
            • Not all processes where analyzed, report is missing behavior information
            • VT rate limit hit for: http://cdn.taboola-display.com
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:XML 1.0 document, ASCII text
            Category:downloaded
            Size (bytes):243
            Entropy (8bit):5.592066534814641
            Encrypted:false
            SSDEEP:6:TMVBd/ZbZjZvKtWRVzjBjugUE00J7aeFZdWiYbZ3PFan:TMHd9BZKtWRGgC0JWeTUiYbZfFa
            MD5:CC9BC4E382E239B273805816EF9DAD68
            SHA1:249D99FE4F3E94E0F02D582A44ED2B80A13DEF64
            SHA-256:B088A010E98808B28ED02B38F2CFF3A54114E2D88A4CFC4BED374EFFD98D2E00
            SHA-512:9DDE349BB2543BC4DC4B10FBEE7ED1822955338CB8D04D219CCD5311EA7209A54B17813F1D53629CEC21C823318429B546EB7BD7C7B41FDC60D55D310E71BF82
            Malicious:false
            Reputation:low
            URL:http://cdn.taboola-display.com/
            Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>79NHFV9JZ2E8R3A2</RequestId><HostId>jffQyoUx5bLyHl+xcUaRIiENmz/6AxsTAgdPZZ6W9M4ZX6wTqKm6EynI2uLgwEBLgaTDgz8lbCU=</HostId></Error>
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 44
            • 443 (HTTPS)
            • 80 (HTTP)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Dec 23, 2024 15:14:16.772530079 CET49675443192.168.2.4173.222.162.32
            Dec 23, 2024 15:14:22.444952965 CET49737443192.168.2.4172.217.21.36
            Dec 23, 2024 15:14:22.445003033 CET44349737172.217.21.36192.168.2.4
            Dec 23, 2024 15:14:22.445161104 CET49737443192.168.2.4172.217.21.36
            Dec 23, 2024 15:14:22.445517063 CET49737443192.168.2.4172.217.21.36
            Dec 23, 2024 15:14:22.445554018 CET44349737172.217.21.36192.168.2.4
            Dec 23, 2024 15:14:24.155397892 CET44349737172.217.21.36192.168.2.4
            Dec 23, 2024 15:14:24.155709982 CET49737443192.168.2.4172.217.21.36
            Dec 23, 2024 15:14:24.155766010 CET44349737172.217.21.36192.168.2.4
            Dec 23, 2024 15:14:24.157526016 CET44349737172.217.21.36192.168.2.4
            Dec 23, 2024 15:14:24.157599926 CET49737443192.168.2.4172.217.21.36
            Dec 23, 2024 15:14:24.158647060 CET49737443192.168.2.4172.217.21.36
            Dec 23, 2024 15:14:24.158746958 CET44349737172.217.21.36192.168.2.4
            Dec 23, 2024 15:14:24.203540087 CET49737443192.168.2.4172.217.21.36
            Dec 23, 2024 15:14:24.203564882 CET44349737172.217.21.36192.168.2.4
            Dec 23, 2024 15:14:24.256752968 CET49737443192.168.2.4172.217.21.36
            Dec 23, 2024 15:14:24.329971075 CET4973980192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:24.330919981 CET4974080192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:24.383244991 CET4974180192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:24.449583054 CET8049739151.101.1.44192.168.2.4
            Dec 23, 2024 15:14:24.449667931 CET4973980192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:24.450058937 CET4973980192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:24.450378895 CET8049740151.101.1.44192.168.2.4
            Dec 23, 2024 15:14:24.450452089 CET4974080192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:24.502784967 CET8049741151.101.1.44192.168.2.4
            Dec 23, 2024 15:14:24.502849102 CET4974180192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:24.569559097 CET8049739151.101.1.44192.168.2.4
            Dec 23, 2024 15:14:25.543510914 CET8049739151.101.1.44192.168.2.4
            Dec 23, 2024 15:14:25.588975906 CET4973980192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:25.618549109 CET4973980192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:25.738121986 CET8049739151.101.1.44192.168.2.4
            Dec 23, 2024 15:14:25.932220936 CET8049739151.101.1.44192.168.2.4
            Dec 23, 2024 15:14:25.932406902 CET8049739151.101.1.44192.168.2.4
            Dec 23, 2024 15:14:25.932990074 CET4973980192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:25.932990074 CET4973980192.168.2.4151.101.1.44
            Dec 23, 2024 15:14:26.052607059 CET8049739151.101.1.44192.168.2.4
            Dec 23, 2024 15:14:33.833901882 CET44349737172.217.21.36192.168.2.4
            Dec 23, 2024 15:14:33.834078074 CET44349737172.217.21.36192.168.2.4
            Dec 23, 2024 15:14:33.834157944 CET49737443192.168.2.4172.217.21.36
            Dec 23, 2024 15:14:34.663669109 CET49737443192.168.2.4172.217.21.36
            Dec 23, 2024 15:14:34.663743973 CET44349737172.217.21.36192.168.2.4
            Dec 23, 2024 15:14:36.982673883 CET4972380192.168.2.423.193.114.18
            Dec 23, 2024 15:14:37.102570057 CET804972323.193.114.18192.168.2.4
            Dec 23, 2024 15:14:37.102633953 CET4972380192.168.2.423.193.114.18
            Dec 23, 2024 15:15:09.459256887 CET4974080192.168.2.4151.101.1.44
            Dec 23, 2024 15:15:09.506201982 CET4974180192.168.2.4151.101.1.44
            Dec 23, 2024 15:15:09.578851938 CET8049740151.101.1.44192.168.2.4
            Dec 23, 2024 15:15:09.625778913 CET8049741151.101.1.44192.168.2.4
            Dec 23, 2024 15:15:22.366326094 CET49772443192.168.2.4172.217.21.36
            Dec 23, 2024 15:15:22.366430044 CET44349772172.217.21.36192.168.2.4
            Dec 23, 2024 15:15:22.366523027 CET49772443192.168.2.4172.217.21.36
            Dec 23, 2024 15:15:22.366905928 CET49772443192.168.2.4172.217.21.36
            Dec 23, 2024 15:15:22.366942883 CET44349772172.217.21.36192.168.2.4
            Dec 23, 2024 15:15:22.724586964 CET4972480192.168.2.42.16.168.117
            Dec 23, 2024 15:15:22.844831944 CET80497242.16.168.117192.168.2.4
            Dec 23, 2024 15:15:22.845244884 CET4972480192.168.2.42.16.168.117
            Dec 23, 2024 15:15:24.066601038 CET44349772172.217.21.36192.168.2.4
            Dec 23, 2024 15:15:24.067125082 CET49772443192.168.2.4172.217.21.36
            Dec 23, 2024 15:15:24.067164898 CET44349772172.217.21.36192.168.2.4
            Dec 23, 2024 15:15:24.068314075 CET44349772172.217.21.36192.168.2.4
            Dec 23, 2024 15:15:24.068636894 CET49772443192.168.2.4172.217.21.36
            Dec 23, 2024 15:15:24.068824053 CET44349772172.217.21.36192.168.2.4
            Dec 23, 2024 15:15:24.115081072 CET49772443192.168.2.4172.217.21.36
            Dec 23, 2024 15:15:24.663652897 CET4974080192.168.2.4151.101.1.44
            Dec 23, 2024 15:15:24.663718939 CET4974180192.168.2.4151.101.1.44
            Dec 23, 2024 15:15:24.783982992 CET8049740151.101.1.44192.168.2.4
            Dec 23, 2024 15:15:24.784163952 CET4974080192.168.2.4151.101.1.44
            Dec 23, 2024 15:15:24.784478903 CET8049741151.101.1.44192.168.2.4
            Dec 23, 2024 15:15:24.784535885 CET4974180192.168.2.4151.101.1.44
            Dec 23, 2024 15:15:33.755876064 CET44349772172.217.21.36192.168.2.4
            Dec 23, 2024 15:15:33.755956888 CET44349772172.217.21.36192.168.2.4
            Dec 23, 2024 15:15:33.756057978 CET49772443192.168.2.4172.217.21.36
            Dec 23, 2024 15:15:34.664482117 CET49772443192.168.2.4172.217.21.36
            Dec 23, 2024 15:15:34.664535999 CET44349772172.217.21.36192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Dec 23, 2024 15:14:18.554903030 CET53539621.1.1.1192.168.2.4
            Dec 23, 2024 15:14:18.602675915 CET53622921.1.1.1192.168.2.4
            Dec 23, 2024 15:14:21.284276009 CET53503351.1.1.1192.168.2.4
            Dec 23, 2024 15:14:22.303591967 CET5011553192.168.2.41.1.1.1
            Dec 23, 2024 15:14:22.303736925 CET5221253192.168.2.41.1.1.1
            Dec 23, 2024 15:14:22.441818953 CET53501151.1.1.1192.168.2.4
            Dec 23, 2024 15:14:22.443835974 CET53522121.1.1.1192.168.2.4
            Dec 23, 2024 15:14:24.109045982 CET6433053192.168.2.41.1.1.1
            Dec 23, 2024 15:14:24.109636068 CET5399453192.168.2.41.1.1.1
            Dec 23, 2024 15:14:24.319210052 CET53539941.1.1.1192.168.2.4
            Dec 23, 2024 15:14:24.325931072 CET53643301.1.1.1192.168.2.4
            Dec 23, 2024 15:14:34.296926975 CET138138192.168.2.4192.168.2.255
            Dec 23, 2024 15:14:38.238581896 CET53552321.1.1.1192.168.2.4
            Dec 23, 2024 15:14:57.208064079 CET53632051.1.1.1192.168.2.4
            Dec 23, 2024 15:15:18.094789982 CET53495611.1.1.1192.168.2.4
            Dec 23, 2024 15:15:20.260684967 CET53624891.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Dec 23, 2024 15:14:22.303591967 CET192.168.2.41.1.1.10x1b28Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Dec 23, 2024 15:14:22.303736925 CET192.168.2.41.1.1.10x3d40Standard query (0)www.google.com65IN (0x0001)false
            Dec 23, 2024 15:14:24.109045982 CET192.168.2.41.1.1.10x391fStandard query (0)cdn.taboola-display.comA (IP address)IN (0x0001)false
            Dec 23, 2024 15:14:24.109636068 CET192.168.2.41.1.1.10x31c8Standard query (0)cdn.taboola-display.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Dec 23, 2024 15:14:22.441818953 CET1.1.1.1192.168.2.40x1b28No error (0)www.google.com172.217.21.36A (IP address)IN (0x0001)false
            Dec 23, 2024 15:14:22.443835974 CET1.1.1.1192.168.2.40x3d40No error (0)www.google.com65IN (0x0001)false
            Dec 23, 2024 15:14:24.319210052 CET1.1.1.1192.168.2.40x31c8No error (0)cdn.taboola-display.comtls13.taboola.map.fastly.netCNAME (Canonical name)IN (0x0001)false
            Dec 23, 2024 15:14:24.325931072 CET1.1.1.1192.168.2.40x391fNo error (0)cdn.taboola-display.comtls13.taboola.map.fastly.netCNAME (Canonical name)IN (0x0001)false
            Dec 23, 2024 15:14:24.325931072 CET1.1.1.1192.168.2.40x391fNo error (0)tls13.taboola.map.fastly.net151.101.1.44A (IP address)IN (0x0001)false
            Dec 23, 2024 15:14:24.325931072 CET1.1.1.1192.168.2.40x391fNo error (0)tls13.taboola.map.fastly.net151.101.65.44A (IP address)IN (0x0001)false
            Dec 23, 2024 15:14:24.325931072 CET1.1.1.1192.168.2.40x391fNo error (0)tls13.taboola.map.fastly.net151.101.129.44A (IP address)IN (0x0001)false
            Dec 23, 2024 15:14:24.325931072 CET1.1.1.1192.168.2.40x391fNo error (0)tls13.taboola.map.fastly.net151.101.193.44A (IP address)IN (0x0001)false
            • cdn.taboola-display.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449739151.101.1.44801312C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Dec 23, 2024 15:14:24.450058937 CET438OUTGET / HTTP/1.1
            Host: cdn.taboola-display.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Dec 23, 2024 15:14:25.543510914 CET804INHTTP/1.1 403 Forbidden
            Connection: keep-alive
            x-amz-bucket-region: us-east-1
            x-amz-request-id: 79NHFV9JZ2E8R3A2
            x-amz-id-2: jffQyoUx5bLyHl+xcUaRIiENmz/6AxsTAgdPZZ6W9M4ZX6wTqKm6EynI2uLgwEBLgaTDgz8lbCU=
            Content-Type: application/xml
            Server: AmazonS3
            Accept-Ranges: bytes
            Date: Mon, 23 Dec 2024 14:14:25 GMT
            Via: 1.1 varnish
            X-Served-By: cache-ewr-kewr1740069-EWR
            X-Cache: MISS
            X-Cache-Hits: 0
            X-Timer: S1734963265.382125,VS0,VE9
            Cache-Control: private,max-age=14400
            abp: 89
            Access-Control-Allow-Origin: *
            transfer-encoding: chunked
            Data Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 37 39 4e 48 46 56 39 4a 5a 32 45 38 52 33 41 32 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 6a 66 66 51 79 6f 55 78 35 62 4c 79 48 6c 2b 78 63 55 61 52 49 69 45 4e 6d 7a 2f 36 41 78 73 54 41 67 64 50 5a 5a 36 57 39 4d 34 5a 58 36 77 54 71 4b 6d 36 45 79 6e 49 32 75 4c 67 77 45 42 4c 67 61 54 44 67 7a 38 6c 62 43 55 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a 30 0d 0a 0d 0a
            Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>79NHFV9JZ2E8R3A2</RequestId><HostId>jffQyoUx5bLyHl+xcUaRIiENmz/6AxsTAgdPZZ6W9M4ZX6wTqKm6EynI2uLgwEBLgaTDgz8lbCU=</HostId></Error>0
            Dec 23, 2024 15:14:25.618549109 CET390OUTGET /favicon.ico HTTP/1.1
            Host: cdn.taboola-display.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Referer: http://cdn.taboola-display.com/
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Dec 23, 2024 15:14:25.932220936 CET353INHTTP/1.1 204 No Content
            Connection: close
            Server: Varnish
            Retry-After: 0
            Content-Type:
            Accept-Ranges: bytes
            Date: Mon, 23 Dec 2024 14:14:25 GMT
            Via: 1.1 varnish
            X-Served-By: cache-ewr-kewr1740069-EWR
            X-Cache: HIT
            X-Cache-Hits: 0
            X-Timer: S1734963266.779400,VS0,VE0
            Cache-Control: private, max-age=2592000
            Access-Control-Allow-Origin: *


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449740151.101.1.44801312C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Dec 23, 2024 15:15:09.459256887 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449741151.101.1.44801312C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Dec 23, 2024 15:15:09.506201982 CET6OUTData Raw: 00
            Data Ascii:


            020406080s020406080100

            Click to jump to process

            020406080s0.0020406080100MB

            Click to jump to process

            Target ID:0
            Start time:09:14:12
            Start date:23/12/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:09:14:16
            Start date:23/12/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2000,i,4898467449033585590,11003152932544282617,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:09:14:22
            Start date:23/12/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cdn.taboola-display.com"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly