Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUP

Overview

General Information

Sample URL:http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btX
Analysis ID:1582992
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain

Classification

  • System is w10x64
  • chrome.exe (PID: 5416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1352 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 --field-trial-handle=1896,i,1228148158081184919,11434548779742626300,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6564 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUPy3J_TvPM8sfKRevcMTcDv6eAynng1" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUPy3J_TvPM8sfKRevcMTcDv6eAynng1Avira URL Cloud: detection malicious, Label: malware
Source: https://track.b2bmktvault.com/index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0feAvira URL Cloud: Label: malware
Source: https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~HTTP Parser: No favicon
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fe HTTP/1.1Host: track.b2bmktvault.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~ HTTP/1.1Host: click.procore.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: click.procore.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUPy3J_TvPM8sfKRevcMTcDv6eAynng1 HTTP/1.1Host: tracking.b2bmktvault.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: tracking.b2bmktvault.com
Source: global trafficDNS traffic detected: DNS query: track.b2bmktvault.com
Source: global trafficDNS traffic detected: DNS query: click.procore.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/jsonContent-Length: 68Connection: closeDate: Wed, 01 Jan 2025 10:10:31 GMTServer: msys-httpVary: AcceptX-Cache: Error from cloudfrontVia: 1.1 24c73aa8cdc4e254694e2ac7073f8aea.cloudfront.net (CloudFront)X-Amz-Cf-Pop: FRA60-P8X-Amz-Cf-Id: pRTO20VQzwXJn9wrne_uhr0ICe2U6h2ksxpr_C9Eemo_R1m5e3GgEw==
Source: global trafficHTTP traffic detected: HTTP/1.1 404 NOT FOUNDContent-Type: text/plainContent-Length: 0Connection: closeDate: Wed, 01 Jan 2025 10:10:32 GMTServer: msys-httpX-Cache: Error from cloudfrontVia: 1.1 0e49b385c2bbe9db0820bc1551bde98a.cloudfront.net (CloudFront)X-Amz-Cf-Pop: FRA60-P8X-Amz-Cf-Id: Ew0VPS4SfcxSicsGjtBAPgKHxFN1kK2gkkDxduRFoQVYwgobZ5gT0g==
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engineClassification label: mal56.win@17/2@10/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 --field-trial-handle=1896,i,1228148158081184919,11434548779742626300,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUPy3J_TvPM8sfKRevcMTcDv6eAynng1"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 --field-trial-handle=1896,i,1228148158081184919,11434548779742626300,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUPy3J_TvPM8sfKRevcMTcDv6eAynng1100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://track.b2bmktvault.com/index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fe100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
api.elasticemail.com
46.105.88.234
truefalse
    high
    d7o1arlc177s.cloudfront.net
    18.172.112.65
    truefalse
      unknown
      www.google.com
      142.250.185.228
      truefalse
        high
        track.b2bmktvault.com
        188.114.97.3
        truefalse
          unknown
          click.procore.com
          unknown
          unknownfalse
            high
            tracking.b2bmktvault.com
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~false
                high
                https://click.procore.com/favicon.icofalse
                  high
                  http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUPy3J_TvPM8sfKRevcMTcDv6eAynng1true
                    unknown
                    https://track.b2bmktvault.com/index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fefalse
                    • Avira URL Cloud: malware
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    46.105.88.234
                    api.elasticemail.comFrance
                    16276OVHFRfalse
                    142.250.185.228
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    188.114.97.3
                    track.b2bmktvault.comEuropean Union
                    13335CLOUDFLARENETUSfalse
                    142.250.186.164
                    unknownUnited States
                    15169GOOGLEUSfalse
                    18.172.112.65
                    d7o1arlc177s.cloudfront.netUnited States
                    3MIT-GATEWAYSUSfalse
                    IP
                    192.168.2.4
                    Joe Sandbox version:41.0.0 Charoite
                    Analysis ID:1582992
                    Start date and time:2025-01-01 11:09:28 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 2m 48s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUPy3J_TvPM8sfKRevcMTcDv6eAynng1
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:7
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:MAL
                    Classification:mal56.win@17/2@10/7
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 142.250.186.131, 216.58.212.142, 74.125.71.84, 216.58.206.78, 142.250.181.238, 142.250.185.78, 199.232.214.172, 192.229.221.95, 142.250.184.238, 142.250.186.78, 142.250.185.238, 142.250.185.174, 216.58.206.35, 172.217.18.14, 184.28.90.27, 52.149.20.212, 13.107.246.45
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
                    • Not all processes where analyzed, report is missing behavior information
                    • VT rate limit hit for: http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUPy3J_TvPM8sfKRevcMTcDv6eAynng1
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:JSON data
                    Category:downloaded
                    Size (bytes):68
                    Entropy (8bit):4.005790728141841
                    Encrypted:false
                    SSDEEP:3:agX//FHIz3bMRN2L3pFjmfY:aSXq7bMCpFjmw
                    MD5:84610D693E2466CD35FE4BF3DC597714
                    SHA1:9B317B90EC8550C3327D60C6EE0E78E27E02A982
                    SHA-256:11050D453D49174A45528911B43F0C7DB85721FBF4CCDAF8FA27CA4A2E1DBB60
                    SHA-512:0F68022B364838C80DFC1A08FD80C6DAB41D8EE3D8E92B4E7DFBA868FE57020957432F446F32093FC3610193C9CE28ABFD911E600F5E37416AC74F204FAB9D12
                    Malicious:false
                    Reputation:low
                    URL:https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~
                    Preview:{ "errors": [ { "message": "permission denied", "code": "1100" } ] }
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Jan 1, 2025 11:10:12.877278090 CET49675443192.168.2.4173.222.162.32
                    Jan 1, 2025 11:10:22.492007017 CET49675443192.168.2.4173.222.162.32
                    Jan 1, 2025 11:10:26.494292974 CET49738443192.168.2.4142.250.185.228
                    Jan 1, 2025 11:10:26.494334936 CET44349738142.250.185.228192.168.2.4
                    Jan 1, 2025 11:10:26.494383097 CET49738443192.168.2.4142.250.185.228
                    Jan 1, 2025 11:10:26.494635105 CET49738443192.168.2.4142.250.185.228
                    Jan 1, 2025 11:10:26.494649887 CET44349738142.250.185.228192.168.2.4
                    Jan 1, 2025 11:10:27.126739979 CET44349738142.250.185.228192.168.2.4
                    Jan 1, 2025 11:10:27.127151966 CET49738443192.168.2.4142.250.185.228
                    Jan 1, 2025 11:10:27.127166033 CET44349738142.250.185.228192.168.2.4
                    Jan 1, 2025 11:10:27.128022909 CET44349738142.250.185.228192.168.2.4
                    Jan 1, 2025 11:10:27.128086090 CET49738443192.168.2.4142.250.185.228
                    Jan 1, 2025 11:10:27.129218102 CET49738443192.168.2.4142.250.185.228
                    Jan 1, 2025 11:10:27.129280090 CET44349738142.250.185.228192.168.2.4
                    Jan 1, 2025 11:10:27.173401117 CET49738443192.168.2.4142.250.185.228
                    Jan 1, 2025 11:10:27.173419952 CET44349738142.250.185.228192.168.2.4
                    Jan 1, 2025 11:10:27.220149040 CET49738443192.168.2.4142.250.185.228
                    Jan 1, 2025 11:10:28.398123026 CET4974080192.168.2.446.105.88.234
                    Jan 1, 2025 11:10:28.398895979 CET4974180192.168.2.446.105.88.234
                    Jan 1, 2025 11:10:28.402930975 CET804974046.105.88.234192.168.2.4
                    Jan 1, 2025 11:10:28.403142929 CET4974080192.168.2.446.105.88.234
                    Jan 1, 2025 11:10:28.403142929 CET4974080192.168.2.446.105.88.234
                    Jan 1, 2025 11:10:28.403662920 CET804974146.105.88.234192.168.2.4
                    Jan 1, 2025 11:10:28.403728008 CET4974180192.168.2.446.105.88.234
                    Jan 1, 2025 11:10:28.407903910 CET804974046.105.88.234192.168.2.4
                    Jan 1, 2025 11:10:29.001838923 CET804974046.105.88.234192.168.2.4
                    Jan 1, 2025 11:10:29.016786098 CET49743443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.016814947 CET44349743188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:29.016952038 CET49743443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.017251015 CET49743443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.017263889 CET44349743188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:29.050658941 CET4974080192.168.2.446.105.88.234
                    Jan 1, 2025 11:10:29.517031908 CET44349743188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:29.517412901 CET49743443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.517431021 CET44349743188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:29.518302917 CET44349743188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:29.518359900 CET49743443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.522483110 CET49743443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.522516966 CET49743443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.522542000 CET44349743188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:29.522670031 CET49743443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.522670031 CET49743443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.522681952 CET44349743188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:29.522794962 CET49743443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.523057938 CET49744443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.523143053 CET44349744188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:29.523231983 CET49744443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.523425102 CET49744443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:29.523466110 CET44349744188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:30.027903080 CET44349744188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:30.028155088 CET49744443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:30.028186083 CET44349744188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:30.029052973 CET44349744188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:30.029115915 CET49744443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:30.030239105 CET49744443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:30.030293941 CET44349744188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:30.030533075 CET49744443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:30.030539989 CET44349744188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:30.081717014 CET49744443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:30.330369949 CET44349744188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:30.330472946 CET44349744188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:30.330545902 CET49744443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:30.332047939 CET49744443192.168.2.4188.114.97.3
                    Jan 1, 2025 11:10:30.332088947 CET44349744188.114.97.3192.168.2.4
                    Jan 1, 2025 11:10:30.346806049 CET49745443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:30.346841097 CET4434974518.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:30.346904039 CET49745443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:30.347136021 CET49745443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:30.347150087 CET4434974518.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:31.084503889 CET4434974518.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:31.084786892 CET49745443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:31.084800959 CET4434974518.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:31.085680008 CET4434974518.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:31.085752010 CET49745443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:31.086762905 CET49745443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:31.086816072 CET4434974518.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:31.087011099 CET49745443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:31.087018013 CET4434974518.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:31.131330013 CET49745443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:31.508426905 CET4434974518.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:31.508482933 CET4434974518.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:31.508563995 CET49745443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:31.509798050 CET49745443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:31.509809017 CET4434974518.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:31.567351103 CET49746443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:31.567409992 CET4434974618.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:31.567490101 CET49746443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:31.567706108 CET49746443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:31.567723036 CET4434974618.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:32.291203976 CET4434974618.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:32.345390081 CET49746443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:32.349370956 CET49746443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:32.349383116 CET4434974618.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:32.349771023 CET4434974618.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:32.359802008 CET49746443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:32.359862089 CET4434974618.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:32.366219044 CET49746443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:32.411326885 CET4434974618.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:32.982320070 CET4434974618.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:32.982763052 CET4434974618.172.112.65192.168.2.4
                    Jan 1, 2025 11:10:32.982917070 CET49746443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:32.982917070 CET49746443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:32.982917070 CET49746443192.168.2.418.172.112.65
                    Jan 1, 2025 11:10:37.031737089 CET44349738142.250.185.228192.168.2.4
                    Jan 1, 2025 11:10:37.031794071 CET44349738142.250.185.228192.168.2.4
                    Jan 1, 2025 11:10:37.031912088 CET49738443192.168.2.4142.250.185.228
                    Jan 1, 2025 11:10:37.268481016 CET49738443192.168.2.4142.250.185.228
                    Jan 1, 2025 11:10:37.268501043 CET44349738142.250.185.228192.168.2.4
                    Jan 1, 2025 11:11:13.407332897 CET4974180192.168.2.446.105.88.234
                    Jan 1, 2025 11:11:13.412172079 CET804974146.105.88.234192.168.2.4
                    Jan 1, 2025 11:11:14.016628981 CET4974080192.168.2.446.105.88.234
                    Jan 1, 2025 11:11:14.021671057 CET804974046.105.88.234192.168.2.4
                    Jan 1, 2025 11:11:26.556555986 CET49801443192.168.2.4142.250.186.164
                    Jan 1, 2025 11:11:26.556581020 CET44349801142.250.186.164192.168.2.4
                    Jan 1, 2025 11:11:26.556639910 CET49801443192.168.2.4142.250.186.164
                    Jan 1, 2025 11:11:26.556880951 CET49801443192.168.2.4142.250.186.164
                    Jan 1, 2025 11:11:26.556895018 CET44349801142.250.186.164192.168.2.4
                    Jan 1, 2025 11:11:27.212470055 CET44349801142.250.186.164192.168.2.4
                    Jan 1, 2025 11:11:27.212748051 CET49801443192.168.2.4142.250.186.164
                    Jan 1, 2025 11:11:27.212768078 CET44349801142.250.186.164192.168.2.4
                    Jan 1, 2025 11:11:27.213085890 CET44349801142.250.186.164192.168.2.4
                    Jan 1, 2025 11:11:27.213404894 CET49801443192.168.2.4142.250.186.164
                    Jan 1, 2025 11:11:27.213465929 CET44349801142.250.186.164192.168.2.4
                    Jan 1, 2025 11:11:27.266726017 CET49801443192.168.2.4142.250.186.164
                    Jan 1, 2025 11:11:29.268471003 CET4974180192.168.2.446.105.88.234
                    Jan 1, 2025 11:11:29.273430109 CET804974146.105.88.234192.168.2.4
                    Jan 1, 2025 11:11:29.273499966 CET4974180192.168.2.446.105.88.234
                    Jan 1, 2025 11:11:37.124253035 CET44349801142.250.186.164192.168.2.4
                    Jan 1, 2025 11:11:37.124315023 CET44349801142.250.186.164192.168.2.4
                    Jan 1, 2025 11:11:37.124495029 CET49801443192.168.2.4142.250.186.164
                    Jan 1, 2025 11:11:37.269217968 CET49801443192.168.2.4142.250.186.164
                    Jan 1, 2025 11:11:37.269233942 CET44349801142.250.186.164192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Jan 1, 2025 11:10:22.511029005 CET53643151.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:22.512373924 CET53492791.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:23.509903908 CET53565421.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:26.486287117 CET5260153192.168.2.41.1.1.1
                    Jan 1, 2025 11:10:26.486459970 CET5300053192.168.2.41.1.1.1
                    Jan 1, 2025 11:10:26.492995977 CET53530001.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:26.493455887 CET53526011.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:28.356945992 CET6011853192.168.2.41.1.1.1
                    Jan 1, 2025 11:10:28.371726036 CET53601181.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:28.385088921 CET5302753192.168.2.41.1.1.1
                    Jan 1, 2025 11:10:28.402277946 CET53530271.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:29.005678892 CET6405753192.168.2.41.1.1.1
                    Jan 1, 2025 11:10:29.006011009 CET5578053192.168.2.41.1.1.1
                    Jan 1, 2025 11:10:29.013947010 CET53640571.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:29.016031981 CET53557801.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:30.333039045 CET6457153192.168.2.41.1.1.1
                    Jan 1, 2025 11:10:30.333185911 CET5714953192.168.2.41.1.1.1
                    Jan 1, 2025 11:10:30.343580008 CET53645711.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:30.346343994 CET53571491.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:40.493407011 CET53513631.1.1.1192.168.2.4
                    Jan 1, 2025 11:10:42.258127928 CET138138192.168.2.4192.168.2.255
                    Jan 1, 2025 11:10:59.509355068 CET53620121.1.1.1192.168.2.4
                    Jan 1, 2025 11:11:21.999799013 CET53564181.1.1.1192.168.2.4
                    Jan 1, 2025 11:11:22.510534048 CET53513141.1.1.1192.168.2.4
                    Jan 1, 2025 11:11:26.548988104 CET6067553192.168.2.41.1.1.1
                    Jan 1, 2025 11:11:26.549114943 CET5645653192.168.2.41.1.1.1
                    Jan 1, 2025 11:11:26.555788994 CET53564561.1.1.1192.168.2.4
                    Jan 1, 2025 11:11:26.555802107 CET53606751.1.1.1192.168.2.4
                    TimestampSource IPDest IPChecksumCodeType
                    Jan 1, 2025 11:10:28.402339935 CET192.168.2.41.1.1.1c25b(Port unreachable)Destination Unreachable
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Jan 1, 2025 11:10:26.486287117 CET192.168.2.41.1.1.10xbdf8Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:26.486459970 CET192.168.2.41.1.1.10x20fdStandard query (0)www.google.com65IN (0x0001)false
                    Jan 1, 2025 11:10:28.356945992 CET192.168.2.41.1.1.10x62bcStandard query (0)tracking.b2bmktvault.comA (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:28.385088921 CET192.168.2.41.1.1.10x9d9dStandard query (0)tracking.b2bmktvault.com65IN (0x0001)false
                    Jan 1, 2025 11:10:29.005678892 CET192.168.2.41.1.1.10xf204Standard query (0)track.b2bmktvault.comA (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:29.006011009 CET192.168.2.41.1.1.10x7738Standard query (0)track.b2bmktvault.com65IN (0x0001)false
                    Jan 1, 2025 11:10:30.333039045 CET192.168.2.41.1.1.10xd766Standard query (0)click.procore.comA (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:30.333185911 CET192.168.2.41.1.1.10x5781Standard query (0)click.procore.com65IN (0x0001)false
                    Jan 1, 2025 11:11:26.548988104 CET192.168.2.41.1.1.10x9766Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Jan 1, 2025 11:11:26.549114943 CET192.168.2.41.1.1.10xf00dStandard query (0)www.google.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Jan 1, 2025 11:10:26.492995977 CET1.1.1.1192.168.2.40x20fdNo error (0)www.google.com65IN (0x0001)false
                    Jan 1, 2025 11:10:26.493455887 CET1.1.1.1192.168.2.40xbdf8No error (0)www.google.com142.250.185.228A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:28.371726036 CET1.1.1.1192.168.2.40x62bcNo error (0)tracking.b2bmktvault.comapi.elasticemail.comCNAME (Canonical name)IN (0x0001)false
                    Jan 1, 2025 11:10:28.371726036 CET1.1.1.1192.168.2.40x62bcNo error (0)api.elasticemail.com46.105.88.234A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:28.371726036 CET1.1.1.1192.168.2.40x62bcNo error (0)api.elasticemail.com54.38.226.140A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:28.371726036 CET1.1.1.1192.168.2.40x62bcNo error (0)api.elasticemail.com164.132.95.123A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:28.371726036 CET1.1.1.1192.168.2.40x62bcNo error (0)api.elasticemail.com94.23.161.19A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:28.371726036 CET1.1.1.1192.168.2.40x62bcNo error (0)api.elasticemail.com188.165.1.80A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:28.402277946 CET1.1.1.1192.168.2.40x9d9dNo error (0)tracking.b2bmktvault.comapi.elasticemail.comCNAME (Canonical name)IN (0x0001)false
                    Jan 1, 2025 11:10:29.013947010 CET1.1.1.1192.168.2.40xf204No error (0)track.b2bmktvault.com188.114.97.3A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:29.013947010 CET1.1.1.1192.168.2.40xf204No error (0)track.b2bmktvault.com188.114.96.3A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:29.016031981 CET1.1.1.1192.168.2.40x7738No error (0)track.b2bmktvault.com65IN (0x0001)false
                    Jan 1, 2025 11:10:30.343580008 CET1.1.1.1192.168.2.40xd766No error (0)click.procore.comd7o1arlc177s.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                    Jan 1, 2025 11:10:30.343580008 CET1.1.1.1192.168.2.40xd766No error (0)d7o1arlc177s.cloudfront.net18.172.112.65A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:30.343580008 CET1.1.1.1192.168.2.40xd766No error (0)d7o1arlc177s.cloudfront.net18.172.112.37A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:30.343580008 CET1.1.1.1192.168.2.40xd766No error (0)d7o1arlc177s.cloudfront.net18.172.112.61A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:30.343580008 CET1.1.1.1192.168.2.40xd766No error (0)d7o1arlc177s.cloudfront.net18.172.112.78A (IP address)IN (0x0001)false
                    Jan 1, 2025 11:10:30.346343994 CET1.1.1.1192.168.2.40x5781No error (0)click.procore.comd7o1arlc177s.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                    Jan 1, 2025 11:11:26.555788994 CET1.1.1.1192.168.2.40xf00dNo error (0)www.google.com65IN (0x0001)false
                    Jan 1, 2025 11:11:26.555802107 CET1.1.1.1192.168.2.40x9766No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                    • track.b2bmktvault.com
                    • click.procore.com
                    • https:
                    • tracking.b2bmktvault.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.44974046.105.88.234801352C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Jan 1, 2025 11:10:28.403142929 CET736OUTGET /tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUPy3J_TvPM8sfKRevcMTcDv6eAynng1 HTTP/1.1
                    Host: tracking.b2bmktvault.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Jan 1, 2025 11:10:29.001838923 CET586INHTTP/1.1 302 Found
                    Cache-Control: private
                    Transfer-Encoding: chunked
                    Content-Type: text/html
                    Location: https://track.b2bmktvault.com/index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fe
                    Server: Microsoft-IIS/10.0
                    X-Powered-By: ASP.NET
                    Date: Wed, 01 Jan 2025 10:10:27 GMT
                    Data Raw: 66 38 0d 0a ef bb bf 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 32 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 20 74 6f 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 74 72 61 63 6b 2e 62 32 62 6d 6b 74 76 61 75 6c 74 2e 63 6f 6d 2f 69 6e 64 65 78 2e 70 68 70 2f 63 61 6d 70 61 69 67 6e 73 2f 76 72 32 37 34 39 71 67 65 31 61 37 62 2f 74 72 61 63 6b 2d 75 72 6c 2f 6c 6b 39 36 31 76 66 70 35 6a 62 30 30 2f 30 37 32 33 34 33 31 33 32 63 32 30 31 64 30 37 62 66 66 37 30 37 31 35 63 30 34 64 64 31 30 65 63 32 63 30 65 30 66 65 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 68 32 3e 0d 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a 0d 0a 30 0d 0a 0d 0a
                    Data Ascii: f8<html><head><title>Object moved</title></head><body><h2>Object moved to <a href="https://track.b2bmktvault.com/index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fe">here</a>.</h2></body></html>0
                    Jan 1, 2025 11:11:14.016628981 CET6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44974146.105.88.234801352C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Jan 1, 2025 11:11:13.407332897 CET6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.449744188.114.97.34431352C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-01-01 10:10:30 UTC762OUTGET /index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fe HTTP/1.1
                    Host: track.b2bmktvault.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2025-01-01 10:10:30 UTC1159INHTTP/1.1 301 Moved Permanently
                    Date: Wed, 01 Jan 2025 10:10:30 GMT
                    Content-Type: text/html; charset=UTF-8
                    Transfer-Encoding: chunked
                    Connection: close
                    X-XSS-Protection: 1; mode=block
                    Expires: Mon, 26 Jul 1997 05:00:00 GMT
                    Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                    Pragma: no-cache
                    cf-cache-status: DYNAMIC
                    Last-Modified: Wed, 01 Jan 2025 10:10:30 GMT
                    Location: https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~
                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=CMUZtLXC6ONLL14dSUnFrL%2B3hoNnoFOt2qaWV%2BDofjLzlZDKhTn5JxWukcMIiD0PyP%2BBN2UOKSjs92zU%2B4gH7DML4W5lTCv%2Bc0h0bUFZHWPCLDmItBUSc%2FmnzEYBYsPKDzqvRgs31%2FM%3D"}],"group":"cf-nel","max_age":604800}
                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                    Server: cloudflare
                    CF-RAY: 8fb1b84a3af1c407-EWR
                    alt-svc: h3=":443"; ma=86400
                    2025-01-01 10:10:30 UTC215INData Raw: 73 65 72 76 65 72 2d 74 69 6d 69 6e 67 3a 20 63 66 4c 34 3b 64 65 73 63 3d 22 3f 70 72 6f 74 6f 3d 54 43 50 26 72 74 74 3d 31 35 38 38 26 6d 69 6e 5f 72 74 74 3d 31 35 38 38 26 72 74 74 5f 76 61 72 3d 37 39 34 26 73 65 6e 74 3d 36 26 72 65 63 76 3d 36 26 6c 6f 73 74 3d 30 26 72 65 74 72 61 6e 73 3d 31 26 73 65 6e 74 5f 62 79 74 65 73 3d 34 32 31 36 26 72 65 63 76 5f 62 79 74 65 73 3d 31 33 34 30 26 64 65 6c 69 76 65 72 79 5f 72 61 74 65 3d 32 36 30 33 34 32 26 63 77 6e 64 3d 31 39 38 26 75 6e 73 65 6e 74 5f 62 79 74 65 73 3d 30 26 63 69 64 3d 34 30 33 36 64 39 34 38 38 38 36 31 39 30 35 37 26 74 73 3d 33 32 37 26 78 3d 30 22 0d 0a 0d 0a
                    Data Ascii: server-timing: cfL4;desc="?proto=TCP&rtt=1588&min_rtt=1588&rtt_var=794&sent=6&recv=6&lost=0&retrans=1&sent_bytes=4216&recv_bytes=1340&delivery_rate=260342&cwnd=198&unsent_bytes=0&cid=4036d94888619057&ts=327&x=0"
                    2025-01-01 10:10:30 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44974518.172.112.654431352C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-01-01 10:10:31 UTC962OUTGET /f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~ HTTP/1.1
                    Host: click.procore.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2025-01-01 10:10:31 UTC365INHTTP/1.1 403 Forbidden
                    Content-Type: application/json
                    Content-Length: 68
                    Connection: close
                    Date: Wed, 01 Jan 2025 10:10:31 GMT
                    Server: msys-http
                    Vary: Accept
                    X-Cache: Error from cloudfront
                    Via: 1.1 24c73aa8cdc4e254694e2ac7073f8aea.cloudfront.net (CloudFront)
                    X-Amz-Cf-Pop: FRA60-P8
                    X-Amz-Cf-Id: pRTO20VQzwXJn9wrne_uhr0ICe2U6h2ksxpr_C9Eemo_R1m5e3GgEw==
                    2025-01-01 10:10:31 UTC68INData Raw: 7b 20 22 65 72 72 6f 72 73 22 3a 20 5b 20 7b 20 22 6d 65 73 73 61 67 65 22 3a 20 22 70 65 72 6d 69 73 73 69 6f 6e 20 64 65 6e 69 65 64 22 2c 20 22 63 6f 64 65 22 3a 20 22 31 31 30 30 22 20 7d 20 5d 20 7d
                    Data Ascii: { "errors": [ { "message": "permission denied", "code": "1100" } ] }


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.44974618.172.112.654431352C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-01-01 10:10:32 UTC892OUTGET /favicon.ico HTTP/1.1
                    Host: click.procore.com
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2025-01-01 10:10:32 UTC344INHTTP/1.1 404 NOT FOUND
                    Content-Type: text/plain
                    Content-Length: 0
                    Connection: close
                    Date: Wed, 01 Jan 2025 10:10:32 GMT
                    Server: msys-http
                    X-Cache: Error from cloudfront
                    Via: 1.1 0e49b385c2bbe9db0820bc1551bde98a.cloudfront.net (CloudFront)
                    X-Amz-Cf-Pop: FRA60-P8
                    X-Amz-Cf-Id: Ew0VPS4SfcxSicsGjtBAPgKHxFN1kK2gkkDxduRFoQVYwgobZ5gT0g==


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:05:10:16
                    Start date:01/01/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:05:10:20
                    Start date:01/01/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 --field-trial-handle=1896,i,1228148158081184919,11434548779742626300,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:05:10:27
                    Start date:01/01/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGu732v1MZ_EelGtWldAkkdtYGfnD-GIQEN8fgQfvllyKpzr3-J0fwpuBZsUPy3J_TvPM8sfKRevcMTcDv6eAynng1"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly