Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf

Overview

General Information

Sample URL:http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btX
Analysis ID:1583000
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 2720 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1748 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2284,i,10806530655782899240,14554039934141943059,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6600 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf5ZYWuxV_Ytx1pTi2iUY6P97JH0U81" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf5ZYWuxV_Ytx1pTi2iUY6P97JH0U81Avira URL Cloud: detection malicious, Label: malware
Source: https://track.b2bmktvault.com/index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0feAvira URL Cloud: Label: malware
Source: https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~HTTP Parser: No favicon
Source: global trafficTCP traffic: 192.168.2.4:57467 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fe HTTP/1.1Host: track.b2bmktvault.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~ HTTP/1.1Host: click.procore.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: click.procore.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf5ZYWuxV_Ytx1pTi2iUY6P97JH0U81 HTTP/1.1Host: tracking.b2bmktvault.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: tracking.b2bmktvault.com
Source: global trafficDNS traffic detected: DNS query: track.b2bmktvault.com
Source: global trafficDNS traffic detected: DNS query: click.procore.com
Source: global trafficDNS traffic detected: DNS query: 171.39.242.20.in-addr.arpa
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/jsonContent-Length: 68Connection: closeDate: Wed, 01 Jan 2025 11:23:28 GMTServer: msys-httpVary: AcceptX-Cache: Error from cloudfrontVia: 1.1 67697a0060e2336f6ffa8579d528820e.cloudfront.net (CloudFront)X-Amz-Cf-Pop: FRA60-P8X-Amz-Cf-Id: IvjzcMYh5bwkKH4sZnIEGh5Yh7CPs4u2z1Frq_ojjqfKI4FmOzVjcg==
Source: global trafficHTTP traffic detected: HTTP/1.1 404 NOT FOUNDContent-Type: text/plainContent-Length: 0Connection: closeDate: Wed, 01 Jan 2025 11:23:29 GMTServer: msys-httpX-Cache: Error from cloudfrontVia: 1.1 5f5fdd347d6ea8b242af79ee38a02fae.cloudfront.net (CloudFront)X-Amz-Cf-Pop: FRA60-P8X-Amz-Cf-Id: 7cbZhUOxR2ERINJ5Ko6mEeI9PWyBGvEfovpAJ7Gm4M8vmmC45Vgp_A==
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 57524 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57524
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engineClassification label: mal56.win@17/2@10/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2284,i,10806530655782899240,14554039934141943059,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf5ZYWuxV_Ytx1pTi2iUY6P97JH0U81"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2284,i,10806530655782899240,14554039934141943059,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf5ZYWuxV_Ytx1pTi2iUY6P97JH0U81100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://track.b2bmktvault.com/index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fe100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
api.elasticemail.com
188.165.1.80
truefalse
    high
    d7o1arlc177s.cloudfront.net
    18.172.112.78
    truefalse
      unknown
      www.google.com
      142.250.185.196
      truefalse
        high
        track.b2bmktvault.com
        188.114.97.3
        truefalse
          unknown
          click.procore.com
          unknown
          unknownfalse
            high
            tracking.b2bmktvault.com
            unknown
            unknownfalse
              unknown
              171.39.242.20.in-addr.arpa
              unknown
              unknownfalse
                high
                NameMaliciousAntivirus DetectionReputation
                https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~false
                  high
                  https://click.procore.com/favicon.icofalse
                    high
                    http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf5ZYWuxV_Ytx1pTi2iUY6P97JH0U81true
                      unknown
                      https://track.b2bmktvault.com/index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fefalse
                      • Avira URL Cloud: malware
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      239.255.255.250
                      unknownReserved
                      unknownunknownfalse
                      142.250.185.196
                      www.google.comUnited States
                      15169GOOGLEUSfalse
                      188.114.97.3
                      track.b2bmktvault.comEuropean Union
                      13335CLOUDFLARENETUSfalse
                      142.250.186.164
                      unknownUnited States
                      15169GOOGLEUSfalse
                      18.172.112.78
                      d7o1arlc177s.cloudfront.netUnited States
                      3MIT-GATEWAYSUSfalse
                      188.165.1.80
                      api.elasticemail.comFrance
                      16276OVHFRfalse
                      IP
                      192.168.2.4
                      Joe Sandbox version:41.0.0 Charoite
                      Analysis ID:1583000
                      Start date and time:2025-01-01 12:22:25 +01:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 2m 51s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:browseurl.jbs
                      Sample URL:http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf5ZYWuxV_Ytx1pTi2iUY6P97JH0U81
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:8
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:MAL
                      Classification:mal56.win@17/2@10/7
                      EGA Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                      • Excluded IPs from analysis (whitelisted): 216.58.206.67, 142.250.185.206, 74.125.71.84, 216.58.212.174, 172.217.16.206, 216.58.206.78, 199.232.210.172, 192.229.221.95, 172.217.18.110, 142.250.181.238, 142.250.185.238, 216.58.206.35, 142.250.186.174, 184.28.90.27, 172.202.163.200, 20.242.39.171, 4.245.163.56, 13.107.246.45
                      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
                      • Not all processes where analyzed, report is missing behavior information
                      • VT rate limit hit for: http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf5ZYWuxV_Ytx1pTi2iUY6P97JH0U81
                      No simulations
                      No context
                      No context
                      No context
                      No context
                      No context
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:JSON data
                      Category:downloaded
                      Size (bytes):68
                      Entropy (8bit):4.005790728141841
                      Encrypted:false
                      SSDEEP:3:agX//FHIz3bMRN2L3pFjmfY:aSXq7bMCpFjmw
                      MD5:84610D693E2466CD35FE4BF3DC597714
                      SHA1:9B317B90EC8550C3327D60C6EE0E78E27E02A982
                      SHA-256:11050D453D49174A45528911B43F0C7DB85721FBF4CCDAF8FA27CA4A2E1DBB60
                      SHA-512:0F68022B364838C80DFC1A08FD80C6DAB41D8EE3D8E92B4E7DFBA868FE57020957432F446F32093FC3610193C9CE28ABFD911E600F5E37416AC74F204FAB9D12
                      Malicious:false
                      Reputation:low
                      URL:https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~
                      Preview:{ "errors": [ { "message": "permission denied", "code": "1100" } ] }
                      No static file info
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 1, 2025 12:23:19.338391066 CET49675443192.168.2.4173.222.162.32
                      Jan 1, 2025 12:23:22.674782038 CET49737443192.168.2.4142.250.185.196
                      Jan 1, 2025 12:23:22.674819946 CET44349737142.250.185.196192.168.2.4
                      Jan 1, 2025 12:23:22.674894094 CET49737443192.168.2.4142.250.185.196
                      Jan 1, 2025 12:23:22.675113916 CET49737443192.168.2.4142.250.185.196
                      Jan 1, 2025 12:23:22.675127983 CET44349737142.250.185.196192.168.2.4
                      Jan 1, 2025 12:23:23.311048985 CET44349737142.250.185.196192.168.2.4
                      Jan 1, 2025 12:23:23.311342955 CET49737443192.168.2.4142.250.185.196
                      Jan 1, 2025 12:23:23.311362028 CET44349737142.250.185.196192.168.2.4
                      Jan 1, 2025 12:23:23.312236071 CET44349737142.250.185.196192.168.2.4
                      Jan 1, 2025 12:23:23.312302113 CET49737443192.168.2.4142.250.185.196
                      Jan 1, 2025 12:23:23.313442945 CET49737443192.168.2.4142.250.185.196
                      Jan 1, 2025 12:23:23.313503027 CET44349737142.250.185.196192.168.2.4
                      Jan 1, 2025 12:23:23.354464054 CET49737443192.168.2.4142.250.185.196
                      Jan 1, 2025 12:23:23.354470968 CET44349737142.250.185.196192.168.2.4
                      Jan 1, 2025 12:23:23.400978088 CET49737443192.168.2.4142.250.185.196
                      Jan 1, 2025 12:23:24.532352924 CET4974080192.168.2.4188.165.1.80
                      Jan 1, 2025 12:23:24.532636881 CET4974180192.168.2.4188.165.1.80
                      Jan 1, 2025 12:23:24.537262917 CET8049740188.165.1.80192.168.2.4
                      Jan 1, 2025 12:23:24.537322998 CET4974080192.168.2.4188.165.1.80
                      Jan 1, 2025 12:23:24.537476063 CET4974080192.168.2.4188.165.1.80
                      Jan 1, 2025 12:23:24.537491083 CET8049741188.165.1.80192.168.2.4
                      Jan 1, 2025 12:23:24.537556887 CET4974180192.168.2.4188.165.1.80
                      Jan 1, 2025 12:23:24.542248011 CET8049740188.165.1.80192.168.2.4
                      Jan 1, 2025 12:23:25.173418999 CET8049740188.165.1.80192.168.2.4
                      Jan 1, 2025 12:23:25.186820030 CET49742443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.186847925 CET44349742188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:25.187004089 CET49742443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.187279940 CET49742443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.187292099 CET44349742188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:25.214896917 CET4974080192.168.2.4188.165.1.80
                      Jan 1, 2025 12:23:25.665740013 CET44349742188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:25.666029930 CET49742443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.666057110 CET44349742188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:25.667476892 CET44349742188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:25.667691946 CET49742443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.672342062 CET49742443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.672342062 CET49742443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.672445059 CET49742443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.672601938 CET44349742188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:25.672739029 CET49742443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.673099995 CET49743443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.673135042 CET44349743188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:25.673394918 CET49743443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.673394918 CET49743443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:25.673424006 CET44349743188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:26.149267912 CET44349743188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:26.149687052 CET49743443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:26.149712086 CET44349743188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:26.151356936 CET44349743188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:26.151428938 CET49743443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:26.152815104 CET49743443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:26.152904987 CET44349743188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:26.153264046 CET49743443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:26.153270960 CET44349743188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:26.199191093 CET49743443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:26.425545931 CET44349743188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:26.425925970 CET44349743188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:26.426023960 CET49743443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:26.658056021 CET49743443192.168.2.4188.114.97.3
                      Jan 1, 2025 12:23:26.658087015 CET44349743188.114.97.3192.168.2.4
                      Jan 1, 2025 12:23:26.688045979 CET49744443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:26.688075066 CET4434974418.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:26.688137054 CET49744443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:26.688380003 CET49744443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:26.688391924 CET4434974418.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:27.401638031 CET4434974418.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:27.401981115 CET49744443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:27.401998997 CET4434974418.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:27.402864933 CET4434974418.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:27.402924061 CET49744443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:27.403971910 CET49744443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:27.404023886 CET4434974418.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:27.404234886 CET49744443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:27.404246092 CET4434974418.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:27.448112965 CET49744443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:28.231132030 CET4434974418.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:28.231568098 CET4434974418.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:28.231632948 CET49744443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:28.232350111 CET49744443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:28.232362986 CET4434974418.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:28.308798075 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:28.308912992 CET4434974518.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:28.309006929 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:28.311363935 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:28.311403990 CET4434974518.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:29.070319891 CET4434974518.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:29.114954948 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:29.196327925 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:29.196357012 CET4434974518.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:29.196706057 CET4434974518.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:29.197559118 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:29.197628975 CET4434974518.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:29.197921991 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:29.239353895 CET4434974518.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:29.810244083 CET4434974518.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:29.810496092 CET4434974518.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:29.810554981 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:29.810913086 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:29.810972929 CET4434974518.172.112.78192.168.2.4
                      Jan 1, 2025 12:23:29.811006069 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:29.811027050 CET49745443192.168.2.418.172.112.78
                      Jan 1, 2025 12:23:33.247467995 CET44349737142.250.185.196192.168.2.4
                      Jan 1, 2025 12:23:33.247519016 CET44349737142.250.185.196192.168.2.4
                      Jan 1, 2025 12:23:33.247574091 CET49737443192.168.2.4142.250.185.196
                      Jan 1, 2025 12:23:35.043481112 CET49737443192.168.2.4142.250.185.196
                      Jan 1, 2025 12:23:35.043500900 CET44349737142.250.185.196192.168.2.4
                      Jan 1, 2025 12:23:37.816303015 CET8049723217.20.57.34192.168.2.4
                      Jan 1, 2025 12:23:37.816505909 CET4972380192.168.2.4217.20.57.34
                      Jan 1, 2025 12:23:37.816572905 CET4972380192.168.2.4217.20.57.34
                      Jan 1, 2025 12:23:37.821296930 CET8049723217.20.57.34192.168.2.4
                      Jan 1, 2025 12:23:47.485045910 CET5746753192.168.2.4162.159.36.2
                      Jan 1, 2025 12:23:47.489931107 CET5357467162.159.36.2192.168.2.4
                      Jan 1, 2025 12:23:47.494514942 CET5746753192.168.2.4162.159.36.2
                      Jan 1, 2025 12:23:47.499378920 CET5357467162.159.36.2192.168.2.4
                      Jan 1, 2025 12:23:47.944308043 CET5746753192.168.2.4162.159.36.2
                      Jan 1, 2025 12:23:47.949450970 CET5357467162.159.36.2192.168.2.4
                      Jan 1, 2025 12:23:47.949523926 CET5746753192.168.2.4162.159.36.2
                      Jan 1, 2025 12:23:52.639584064 CET8049724217.20.57.34192.168.2.4
                      Jan 1, 2025 12:23:52.639667034 CET4972480192.168.2.4217.20.57.34
                      Jan 1, 2025 12:23:52.639759064 CET4972480192.168.2.4217.20.57.34
                      Jan 1, 2025 12:23:52.644547939 CET8049724217.20.57.34192.168.2.4
                      Jan 1, 2025 12:24:09.541599989 CET4974180192.168.2.4188.165.1.80
                      Jan 1, 2025 12:24:09.546572924 CET8049741188.165.1.80192.168.2.4
                      Jan 1, 2025 12:24:10.182172060 CET4974080192.168.2.4188.165.1.80
                      Jan 1, 2025 12:24:10.187103033 CET8049740188.165.1.80192.168.2.4
                      Jan 1, 2025 12:24:22.738261938 CET57524443192.168.2.4142.250.186.164
                      Jan 1, 2025 12:24:22.738291979 CET44357524142.250.186.164192.168.2.4
                      Jan 1, 2025 12:24:22.738353968 CET57524443192.168.2.4142.250.186.164
                      Jan 1, 2025 12:24:22.738641977 CET57524443192.168.2.4142.250.186.164
                      Jan 1, 2025 12:24:22.738651991 CET44357524142.250.186.164192.168.2.4
                      Jan 1, 2025 12:24:23.361648083 CET44357524142.250.186.164192.168.2.4
                      Jan 1, 2025 12:24:23.361975908 CET57524443192.168.2.4142.250.186.164
                      Jan 1, 2025 12:24:23.361989975 CET44357524142.250.186.164192.168.2.4
                      Jan 1, 2025 12:24:23.362270117 CET44357524142.250.186.164192.168.2.4
                      Jan 1, 2025 12:24:23.362605095 CET57524443192.168.2.4142.250.186.164
                      Jan 1, 2025 12:24:23.362653971 CET44357524142.250.186.164192.168.2.4
                      Jan 1, 2025 12:24:23.416321993 CET57524443192.168.2.4142.250.186.164
                      Jan 1, 2025 12:24:25.043132067 CET4974180192.168.2.4188.165.1.80
                      Jan 1, 2025 12:24:25.048274994 CET8049741188.165.1.80192.168.2.4
                      Jan 1, 2025 12:24:25.048341990 CET4974180192.168.2.4188.165.1.80
                      Jan 1, 2025 12:24:33.294583082 CET44357524142.250.186.164192.168.2.4
                      Jan 1, 2025 12:24:33.294675112 CET44357524142.250.186.164192.168.2.4
                      Jan 1, 2025 12:24:33.294730902 CET57524443192.168.2.4142.250.186.164
                      Jan 1, 2025 12:24:35.043656111 CET57524443192.168.2.4142.250.186.164
                      Jan 1, 2025 12:24:35.043667078 CET44357524142.250.186.164192.168.2.4
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 1, 2025 12:23:18.827833891 CET53626121.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:18.828361034 CET53608081.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:19.900773048 CET53591061.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:22.667068005 CET4967353192.168.2.41.1.1.1
                      Jan 1, 2025 12:23:22.667208910 CET5801153192.168.2.41.1.1.1
                      Jan 1, 2025 12:23:22.673814058 CET53580111.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:22.673866987 CET53496731.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:24.503499031 CET6018453192.168.2.41.1.1.1
                      Jan 1, 2025 12:23:24.503822088 CET5012953192.168.2.41.1.1.1
                      Jan 1, 2025 12:23:24.510854006 CET53601841.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:24.531677961 CET53501291.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:25.176052094 CET5672153192.168.2.41.1.1.1
                      Jan 1, 2025 12:23:25.176052094 CET5611953192.168.2.41.1.1.1
                      Jan 1, 2025 12:23:25.185192108 CET53567211.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:25.186327934 CET53561191.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:26.673741102 CET5730753192.168.2.41.1.1.1
                      Jan 1, 2025 12:23:26.673893929 CET5888953192.168.2.41.1.1.1
                      Jan 1, 2025 12:23:26.684941053 CET53573071.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:26.685518026 CET53588891.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:36.908705950 CET53503581.1.1.1192.168.2.4
                      Jan 1, 2025 12:23:38.579061985 CET138138192.168.2.4192.168.2.255
                      Jan 1, 2025 12:23:47.482587099 CET5353425162.159.36.2192.168.2.4
                      Jan 1, 2025 12:23:47.960434914 CET5225753192.168.2.41.1.1.1
                      Jan 1, 2025 12:23:47.967549086 CET53522571.1.1.1192.168.2.4
                      Jan 1, 2025 12:24:22.730312109 CET5806653192.168.2.41.1.1.1
                      Jan 1, 2025 12:24:22.737238884 CET53580661.1.1.1192.168.2.4
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Jan 1, 2025 12:23:22.667068005 CET192.168.2.41.1.1.10xd820Standard query (0)www.google.comA (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:22.667208910 CET192.168.2.41.1.1.10x39f1Standard query (0)www.google.com65IN (0x0001)false
                      Jan 1, 2025 12:23:24.503499031 CET192.168.2.41.1.1.10x3789Standard query (0)tracking.b2bmktvault.comA (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:24.503822088 CET192.168.2.41.1.1.10xddfbStandard query (0)tracking.b2bmktvault.com65IN (0x0001)false
                      Jan 1, 2025 12:23:25.176052094 CET192.168.2.41.1.1.10x3384Standard query (0)track.b2bmktvault.comA (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:25.176052094 CET192.168.2.41.1.1.10x5434Standard query (0)track.b2bmktvault.com65IN (0x0001)false
                      Jan 1, 2025 12:23:26.673741102 CET192.168.2.41.1.1.10x13b4Standard query (0)click.procore.comA (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:26.673893929 CET192.168.2.41.1.1.10x155eStandard query (0)click.procore.com65IN (0x0001)false
                      Jan 1, 2025 12:23:47.960434914 CET192.168.2.41.1.1.10xb035Standard query (0)171.39.242.20.in-addr.arpaPTR (Pointer record)IN (0x0001)false
                      Jan 1, 2025 12:24:22.730312109 CET192.168.2.41.1.1.10x7bddStandard query (0)www.google.comA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Jan 1, 2025 12:23:22.673814058 CET1.1.1.1192.168.2.40x39f1No error (0)www.google.com65IN (0x0001)false
                      Jan 1, 2025 12:23:22.673866987 CET1.1.1.1192.168.2.40xd820No error (0)www.google.com142.250.185.196A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:24.510854006 CET1.1.1.1192.168.2.40x3789No error (0)tracking.b2bmktvault.comapi.elasticemail.comCNAME (Canonical name)IN (0x0001)false
                      Jan 1, 2025 12:23:24.510854006 CET1.1.1.1192.168.2.40x3789No error (0)api.elasticemail.com188.165.1.80A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:24.510854006 CET1.1.1.1192.168.2.40x3789No error (0)api.elasticemail.com46.105.88.234A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:24.510854006 CET1.1.1.1192.168.2.40x3789No error (0)api.elasticemail.com54.38.226.140A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:24.510854006 CET1.1.1.1192.168.2.40x3789No error (0)api.elasticemail.com94.23.161.19A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:24.510854006 CET1.1.1.1192.168.2.40x3789No error (0)api.elasticemail.com164.132.95.123A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:24.531677961 CET1.1.1.1192.168.2.40xddfbNo error (0)tracking.b2bmktvault.comapi.elasticemail.comCNAME (Canonical name)IN (0x0001)false
                      Jan 1, 2025 12:23:25.185192108 CET1.1.1.1192.168.2.40x3384No error (0)track.b2bmktvault.com188.114.97.3A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:25.185192108 CET1.1.1.1192.168.2.40x3384No error (0)track.b2bmktvault.com188.114.96.3A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:25.186327934 CET1.1.1.1192.168.2.40x5434No error (0)track.b2bmktvault.com65IN (0x0001)false
                      Jan 1, 2025 12:23:26.684941053 CET1.1.1.1192.168.2.40x13b4No error (0)click.procore.comd7o1arlc177s.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                      Jan 1, 2025 12:23:26.684941053 CET1.1.1.1192.168.2.40x13b4No error (0)d7o1arlc177s.cloudfront.net18.172.112.78A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:26.684941053 CET1.1.1.1192.168.2.40x13b4No error (0)d7o1arlc177s.cloudfront.net18.172.112.37A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:26.684941053 CET1.1.1.1192.168.2.40x13b4No error (0)d7o1arlc177s.cloudfront.net18.172.112.61A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:26.684941053 CET1.1.1.1192.168.2.40x13b4No error (0)d7o1arlc177s.cloudfront.net18.172.112.65A (IP address)IN (0x0001)false
                      Jan 1, 2025 12:23:26.685518026 CET1.1.1.1192.168.2.40x155eNo error (0)click.procore.comd7o1arlc177s.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                      Jan 1, 2025 12:23:47.967549086 CET1.1.1.1192.168.2.40xb035Name error (3)171.39.242.20.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
                      Jan 1, 2025 12:24:22.737238884 CET1.1.1.1192.168.2.40x7bddNo error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                      • track.b2bmktvault.com
                      • click.procore.com
                      • https:
                      • tracking.b2bmktvault.com
                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.449740188.165.1.80801748C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      Jan 1, 2025 12:23:24.537476063 CET736OUTGET /tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf5ZYWuxV_Ytx1pTi2iUY6P97JH0U81 HTTP/1.1
                      Host: tracking.b2bmktvault.com
                      Connection: keep-alive
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                      Accept-Encoding: gzip, deflate
                      Accept-Language: en-US,en;q=0.9
                      Jan 1, 2025 12:23:25.173418999 CET586INHTTP/1.1 302 Found
                      Cache-Control: private
                      Transfer-Encoding: chunked
                      Content-Type: text/html
                      Location: https://track.b2bmktvault.com/index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fe
                      Server: Microsoft-IIS/10.0
                      X-Powered-By: ASP.NET
                      Date: Wed, 01 Jan 2025 11:23:24 GMT
                      Data Raw: 66 38 0d 0a ef bb bf 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 32 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 20 74 6f 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 74 72 61 63 6b 2e 62 32 62 6d 6b 74 76 61 75 6c 74 2e 63 6f 6d 2f 69 6e 64 65 78 2e 70 68 70 2f 63 61 6d 70 61 69 67 6e 73 2f 76 72 32 37 34 39 71 67 65 31 61 37 62 2f 74 72 61 63 6b 2d 75 72 6c 2f 6c 6b 39 36 31 76 66 70 35 6a 62 30 30 2f 30 37 32 33 34 33 31 33 32 63 32 30 31 64 30 37 62 66 66 37 30 37 31 35 63 30 34 64 64 31 30 65 63 32 63 30 65 30 66 65 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 68 32 3e 0d 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a 0d 0a 30 0d 0a 0d 0a
                      Data Ascii: f8<html><head><title>Object moved</title></head><body><h2>Object moved to <a href="https://track.b2bmktvault.com/index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fe">here</a>.</h2></body></html>0
                      Jan 1, 2025 12:24:10.182172060 CET6OUTData Raw: 00
                      Data Ascii:


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.449741188.165.1.80801748C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      Jan 1, 2025 12:24:09.541599989 CET6OUTData Raw: 00
                      Data Ascii:


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.449743188.114.97.34431748C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2025-01-01 11:23:26 UTC762OUTGET /index.php/campaigns/vr2749qge1a7b/track-url/lk961vfp5jb00/072343132c201d07bff70715c04dd10ec2c0e0fe HTTP/1.1
                      Host: track.b2bmktvault.com
                      Connection: keep-alive
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: navigate
                      Sec-Fetch-User: ?1
                      Sec-Fetch-Dest: document
                      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                      sec-ch-ua-mobile: ?0
                      sec-ch-ua-platform: "Windows"
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2025-01-01 11:23:26 UTC1157INHTTP/1.1 301 Moved Permanently
                      Date: Wed, 01 Jan 2025 11:23:26 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      X-XSS-Protection: 1; mode=block
                      Expires: Mon, 26 Jul 1997 05:00:00 GMT
                      Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                      Pragma: no-cache
                      cf-cache-status: DYNAMIC
                      Last-Modified: Wed, 01 Jan 2025 11:23:26 GMT
                      Location: https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=xSjRvAjRTwg%2BeW%2FzYmAQhJ1BB4A60fkKTY0HsvYH1ryE4W8Cf3%2BZlbVesU%2FwTSPchiE0FfsDVQhbJQjosuwF0OXk%2FoyOFvmMWSHlF5q8eD%2BoizV4gm483Dy24mCwdr44J29ZxqpUjxw%3D"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8fb22320ef5c8c60-EWR
                      alt-svc: h3=":443"; ma=86400
                      2025-01-01 11:23:26 UTC215INData Raw: 73 65 72 76 65 72 2d 74 69 6d 69 6e 67 3a 20 63 66 4c 34 3b 64 65 73 63 3d 22 3f 70 72 6f 74 6f 3d 54 43 50 26 72 74 74 3d 31 37 36 36 26 6d 69 6e 5f 72 74 74 3d 31 37 36 31 26 72 74 74 5f 76 61 72 3d 36 37 31 26 73 65 6e 74 3d 34 26 72 65 63 76 3d 36 26 6c 6f 73 74 3d 30 26 72 65 74 72 61 6e 73 3d 30 26 73 65 6e 74 5f 62 79 74 65 73 3d 32 38 33 37 26 72 65 63 76 5f 62 79 74 65 73 3d 31 33 34 30 26 64 65 6c 69 76 65 72 79 5f 72 61 74 65 3d 31 36 31 38 36 32 35 26 63 77 6e 64 3d 36 37 26 75 6e 73 65 6e 74 5f 62 79 74 65 73 3d 30 26 63 69 64 3d 32 36 30 64 37 62 65 31 33 66 63 66 39 34 65 30 26 74 73 3d 32 39 34 26 78 3d 30 22 0d 0a 0d 0a
                      Data Ascii: server-timing: cfL4;desc="?proto=TCP&rtt=1766&min_rtt=1761&rtt_var=671&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2837&recv_bytes=1340&delivery_rate=1618625&cwnd=67&unsent_bytes=0&cid=260d7be13fcf94e0&ts=294&x=0"
                      2025-01-01 11:23:26 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.44974418.172.112.784431748C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2025-01-01 11:23:27 UTC962OUTGET /f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~ HTTP/1.1
                      Host: click.procore.com
                      Connection: keep-alive
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: navigate
                      Sec-Fetch-User: ?1
                      Sec-Fetch-Dest: document
                      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                      sec-ch-ua-mobile: ?0
                      sec-ch-ua-platform: "Windows"
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2025-01-01 11:23:28 UTC365INHTTP/1.1 403 Forbidden
                      Content-Type: application/json
                      Content-Length: 68
                      Connection: close
                      Date: Wed, 01 Jan 2025 11:23:28 GMT
                      Server: msys-http
                      Vary: Accept
                      X-Cache: Error from cloudfront
                      Via: 1.1 67697a0060e2336f6ffa8579d528820e.cloudfront.net (CloudFront)
                      X-Amz-Cf-Pop: FRA60-P8
                      X-Amz-Cf-Id: IvjzcMYh5bwkKH4sZnIEGh5Yh7CPs4u2z1Frq_ojjqfKI4FmOzVjcg==
                      2025-01-01 11:23:28 UTC68INData Raw: 7b 20 22 65 72 72 6f 72 73 22 3a 20 5b 20 7b 20 22 6d 65 73 73 61 67 65 22 3a 20 22 70 65 72 6d 69 73 73 69 6f 6e 20 64 65 6e 69 65 64 22 2c 20 22 63 6f 64 65 22 3a 20 22 31 31 30 30 22 20 7d 20 5d 20 7d
                      Data Ascii: { "errors": [ { "message": "permission denied", "code": "1100" } ] }


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      2192.168.2.44974518.172.112.784431748C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2025-01-01 11:23:29 UTC892OUTGET /favicon.ico HTTP/1.1
                      Host: click.procore.com
                      Connection: keep-alive
                      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                      sec-ch-ua-mobile: ?0
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      sec-ch-ua-platform: "Windows"
                      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                      Sec-Fetch-Site: same-origin
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: image
                      Referer: https://click.procore.com/f/a/rDGa2Qc3t8SRYvK3QfYfyA~~/AAQRxQA~/RgRpRqbaP0SHaHR0cHM6Ly9saW5rLnNic3Rjay5jb20vcmVkaXJlY3QvY2M3YzViMzUtMDQyMS00MzFhLWFkYTAtZmY0ZjFjNTE3ZDZkP2o9ZXlKMUlqb2lORzluYTJab0luMC5HZmNKWXJRM2JuYWxfWDctd3ptZ0FiazhaN3htQnNJY0psY1ZvVndVbnRjVwNzcGNCCmdV2iFkZ3GlYOVSG2NyZWF0aXYuZXRyYXZvbHRhQGdtYWlsLmNvbVgEAAADcA~~
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2025-01-01 11:23:29 UTC344INHTTP/1.1 404 NOT FOUND
                      Content-Type: text/plain
                      Content-Length: 0
                      Connection: close
                      Date: Wed, 01 Jan 2025 11:23:29 GMT
                      Server: msys-http
                      X-Cache: Error from cloudfront
                      Via: 1.1 5f5fdd347d6ea8b242af79ee38a02fae.cloudfront.net (CloudFront)
                      X-Amz-Cf-Pop: FRA60-P8
                      X-Amz-Cf-Id: 7cbZhUOxR2ERINJ5Ko6mEeI9PWyBGvEfovpAJ7Gm4M8vmmC45Vgp_A==


                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:06:23:14
                      Start date:01/01/2025
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:2
                      Start time:06:23:16
                      Start date:01/01/2025
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2284,i,10806530655782899240,14554039934141943059,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:3
                      Start time:06:23:23
                      Start date:01/01/2025
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://tracking.b2bmktvault.com/tracking/click?d=qPk_c18mu4tAnpVkjkvM74XnWEgCEJFMr0kmnRaZVETZIbfUm-V7axMnjqAoCLnqzaVyNRK36FUkPva8vnzGVvH9cqu1JpLb-vxN3FkjjYhK51_3JrkS14Hcuqb1FOJE1bnSPADYUAMl8knPwYz7btXcOUX9DY4_AjytTbLRGEQ0R8vUhh6vaa-KBtd0YdWGVJFQli_mKczqrYpzYk33dCMwBXQR8R8u2JajJsC51OFcIlRSs_l3i1d9MQf5ZYWuxV_Ytx1pTi2iUY6P97JH0U81"
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:true

                      No disassembly