Click to jump to signature section
Source: http://kxyaiaqyijjz.com | Avira URL Cloud: detection malicious, Label: malware |
Source: http://kxyaiaqyijjz.com/favicon.ico | Avira URL Cloud: Label: malware |
Source: http://kxyaiaqyijjz.com/ | Avira URL Cloud: Label: malware |
Source: unknown | HTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49706 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:49707 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49708 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:49709 version: TLS 1.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.218.208.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1Host: kxyaiaqyijjz.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: kxyaiaqyijjz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://kxyaiaqyijjz.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9 |
Source: global traffic | DNS traffic detected: DNS query: kxyaiaqyijjz.com |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: global traffic | HTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/xmlTransfer-Encoding: chunkedConnection: keep-alivex-amz-bucket-region: us-east-1Server: AmazonS3Date: Thu, 26 Dec 2024 23:15:43 GMTX-Cache: Error from cloudfrontVia: 1.1 b5386ac724a3fa652b68ff3cd51ba8b6.cloudfront.net (CloudFront)X-Amz-Cf-Pop: BAH53-C1X-Amz-Cf-Id: MLX698mamPzxYfjgGcwa8V8h8w-5-ieK3IQL_tcXebr1m6HPvNG6vA==Data Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 4d 41 5a 4d 54 41 34 39 50 51 46 43 35 48 36 48 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 30 63 56 6d 63 57 69 69 35 44 2f 66 43 64 47 4c 68 69 2f 4c 52 6f 70 79 67 70 50 72 50 67 37 6b 48 4f 6b 44 55 64 4c 42 64 48 36 53 65 6b 4a 2b 33 64 6a 75 45 37 68 66 75 6e 38 51 79 6b 34 76 50 30 38 39 69 53 2b 63 6c 61 67 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a 30 0d 0a 0d 0a Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>MAZMTA49PQFC5H6H</RequestId><HostId>0cVmcWii5D/fCdGLhi/LRopygpPrPg7kHOkDUdLBdH6SekJ+3djuE7hfun8Qyk4vP089iS+clag=</HostId></Error>0 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/xmlTransfer-Encoding: chunkedConnection: keep-aliveServer: AmazonS3Date: Thu, 26 Dec 2024 23:15:44 GMTX-Cache: Error from cloudfrontVia: 1.1 b5386ac724a3fa652b68ff3cd51ba8b6.cloudfront.net (CloudFront)X-Amz-Cf-Pop: BAH53-C1X-Amz-Cf-Id: 6uuO_hXpHWEUWBH7OUuPAh7gXKKji1gpM0_0gu0rprzgnJYmzoGgSA==Data Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 32 44 45 57 51 5a 4e 45 58 46 4d 54 57 31 39 52 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 30 50 34 5a 65 65 51 63 5a 6d 71 4a 68 61 64 49 75 79 6a 35 6a 55 7a 34 53 4b 55 49 74 64 56 5a 62 6a 4e 39 64 6f 79 7a 37 62 58 74 49 62 2b 58 4e 5a 4a 32 59 54 4e 6d 74 4b 47 37 42 51 6c 64 34 42 39 4d 74 70 69 46 33 2b 6f 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>2DEWQZNEXFMTW19R</RequestId><HostId>0P4ZeeQcZmqJhadIuyj5jUz4SKUItdVZbjN9doyz7bXtIb+XNZJ2YTNmtKG7BQld4B9MtpiF3+o=</HostId></Error> |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49700 |
Source: unknown | Network traffic detected: HTTP traffic on port 49708 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49711 |
Source: unknown | Network traffic detected: HTTP traffic on port 49709 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49673 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49706 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49707 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49711 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49678 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49700 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49709 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49708 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49707 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49706 |
Source: unknown | HTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49706 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:49707 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49708 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:49709 version: TLS 1.2 |
Source: classification engine | Classification label: mal56.win@17/6@4/92 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1832,i,1552152032289816611,2616894040863888203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://kxyaiaqyijjz.com" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1832,i,1552152032289816611,2616894040863888203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk |