Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://cdn.statisticline.com

Overview

General Information

Sample URL:http://cdn.statisticline.com
Analysis ID:1585923
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 2136 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6100 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2268,i,10869499711930421036,3467080765669512565,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6548 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cdn.statisticline.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://cdn.statisticline.comAvira URL Cloud: detection malicious, Label: malware
Source: http://cdn.statisticline.com/favicon.icoAvira URL Cloud: Label: malware
Source: global trafficTCP traffic: 192.168.2.4:51792 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: cdn.statisticline.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: cdn.statisticline.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://cdn.statisticline.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: cdn.statisticline.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0 (Ubuntu)Date: Wed, 08 Jan 2025 13:13:35 GMTContent-Length: 0Connection: keep-aliveX-Powered-By: ExpressAccess-Control-Allow-Origin: *
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51847
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: classification engineClassification label: mal56.win@16/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2268,i,10869499711930421036,3467080765669512565,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cdn.statisticline.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2268,i,10869499711930421036,3467080765669512565,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://cdn.statisticline.com100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://cdn.statisticline.com/favicon.ico100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.186.132
truefalse
    high
    cdn.statisticline.com
    165.22.209.237
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://cdn.statisticline.com/favicon.icotrue
      • Avira URL Cloud: malware
      unknown
      http://cdn.statisticline.com/true
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        165.22.209.237
        cdn.statisticline.comUnited States
        14061DIGITALOCEAN-ASNUSfalse
        142.250.186.132
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1585923
        Start date and time:2025-01-08 14:12:35 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 45s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://cdn.statisticline.com
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:7
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal56.win@16/0@4/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.186.35, 142.250.185.238, 74.125.71.84, 216.58.206.78, 142.250.186.174, 172.217.16.206, 88.221.110.91, 192.229.221.95, 142.250.74.206, 142.250.184.206, 142.250.184.238, 142.250.80.110, 74.125.0.74, 142.250.185.78, 142.250.186.67, 23.56.254.164, 172.202.163.200, 13.107.246.45
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, r5.sn-t0aedn7e.gvt1.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, r5---sn-t0aedn7e.gvt1.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: http://cdn.statisticline.com
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Jan 8, 2025 14:13:29.188771009 CET49675443192.168.2.4173.222.162.32
        Jan 8, 2025 14:13:32.323431969 CET49738443192.168.2.4142.250.186.132
        Jan 8, 2025 14:13:32.323479891 CET44349738142.250.186.132192.168.2.4
        Jan 8, 2025 14:13:32.323554039 CET49738443192.168.2.4142.250.186.132
        Jan 8, 2025 14:13:32.323779106 CET49738443192.168.2.4142.250.186.132
        Jan 8, 2025 14:13:32.323791027 CET44349738142.250.186.132192.168.2.4
        Jan 8, 2025 14:13:32.959863901 CET44349738142.250.186.132192.168.2.4
        Jan 8, 2025 14:13:32.960366964 CET49738443192.168.2.4142.250.186.132
        Jan 8, 2025 14:13:32.960398912 CET44349738142.250.186.132192.168.2.4
        Jan 8, 2025 14:13:32.961293936 CET44349738142.250.186.132192.168.2.4
        Jan 8, 2025 14:13:32.961371899 CET49738443192.168.2.4142.250.186.132
        Jan 8, 2025 14:13:32.962730885 CET49738443192.168.2.4142.250.186.132
        Jan 8, 2025 14:13:32.962785959 CET44349738142.250.186.132192.168.2.4
        Jan 8, 2025 14:13:33.016761065 CET49738443192.168.2.4142.250.186.132
        Jan 8, 2025 14:13:33.016772985 CET44349738142.250.186.132192.168.2.4
        Jan 8, 2025 14:13:33.063621998 CET49738443192.168.2.4142.250.186.132
        Jan 8, 2025 14:13:34.098866940 CET4974080192.168.2.4165.22.209.237
        Jan 8, 2025 14:13:34.099368095 CET4974180192.168.2.4165.22.209.237
        Jan 8, 2025 14:13:34.103661060 CET8049740165.22.209.237192.168.2.4
        Jan 8, 2025 14:13:34.103714943 CET4974080192.168.2.4165.22.209.237
        Jan 8, 2025 14:13:34.103884935 CET4974080192.168.2.4165.22.209.237
        Jan 8, 2025 14:13:34.104137897 CET8049741165.22.209.237192.168.2.4
        Jan 8, 2025 14:13:34.104190111 CET4974180192.168.2.4165.22.209.237
        Jan 8, 2025 14:13:34.108673096 CET8049740165.22.209.237192.168.2.4
        Jan 8, 2025 14:13:35.099981070 CET8049740165.22.209.237192.168.2.4
        Jan 8, 2025 14:13:35.132704020 CET4974080192.168.2.4165.22.209.237
        Jan 8, 2025 14:13:35.137705088 CET8049740165.22.209.237192.168.2.4
        Jan 8, 2025 14:13:35.500056028 CET8049740165.22.209.237192.168.2.4
        Jan 8, 2025 14:13:35.549755096 CET4974080192.168.2.4165.22.209.237
        Jan 8, 2025 14:13:42.874859095 CET44349738142.250.186.132192.168.2.4
        Jan 8, 2025 14:13:42.874924898 CET44349738142.250.186.132192.168.2.4
        Jan 8, 2025 14:13:42.875094891 CET49738443192.168.2.4142.250.186.132
        Jan 8, 2025 14:13:44.852478027 CET49738443192.168.2.4142.250.186.132
        Jan 8, 2025 14:13:44.852505922 CET44349738142.250.186.132192.168.2.4
        Jan 8, 2025 14:13:50.789123058 CET5179253192.168.2.41.1.1.1
        Jan 8, 2025 14:13:50.793956041 CET53517921.1.1.1192.168.2.4
        Jan 8, 2025 14:13:50.794047117 CET5179253192.168.2.41.1.1.1
        Jan 8, 2025 14:13:50.794071913 CET5179253192.168.2.41.1.1.1
        Jan 8, 2025 14:13:50.798913956 CET53517921.1.1.1192.168.2.4
        Jan 8, 2025 14:13:51.253125906 CET53517921.1.1.1192.168.2.4
        Jan 8, 2025 14:13:51.253978968 CET5179253192.168.2.41.1.1.1
        Jan 8, 2025 14:13:51.259088993 CET53517921.1.1.1192.168.2.4
        Jan 8, 2025 14:13:51.259159088 CET5179253192.168.2.41.1.1.1
        Jan 8, 2025 14:13:55.503547907 CET8049740165.22.209.237192.168.2.4
        Jan 8, 2025 14:13:55.503640890 CET4974080192.168.2.4165.22.209.237
        Jan 8, 2025 14:13:56.847124100 CET4974080192.168.2.4165.22.209.237
        Jan 8, 2025 14:13:56.851922035 CET8049740165.22.209.237192.168.2.4
        Jan 8, 2025 14:14:19.111350060 CET4974180192.168.2.4165.22.209.237
        Jan 8, 2025 14:14:19.116202116 CET8049741165.22.209.237192.168.2.4
        Jan 8, 2025 14:14:32.380707026 CET51847443192.168.2.4142.250.186.132
        Jan 8, 2025 14:14:32.380734921 CET44351847142.250.186.132192.168.2.4
        Jan 8, 2025 14:14:32.380808115 CET51847443192.168.2.4142.250.186.132
        Jan 8, 2025 14:14:32.381086111 CET51847443192.168.2.4142.250.186.132
        Jan 8, 2025 14:14:32.381099939 CET44351847142.250.186.132192.168.2.4
        Jan 8, 2025 14:14:33.036726952 CET44351847142.250.186.132192.168.2.4
        Jan 8, 2025 14:14:33.037056923 CET51847443192.168.2.4142.250.186.132
        Jan 8, 2025 14:14:33.037066936 CET44351847142.250.186.132192.168.2.4
        Jan 8, 2025 14:14:33.037357092 CET44351847142.250.186.132192.168.2.4
        Jan 8, 2025 14:14:33.037659883 CET51847443192.168.2.4142.250.186.132
        Jan 8, 2025 14:14:33.037714958 CET44351847142.250.186.132192.168.2.4
        Jan 8, 2025 14:14:33.082506895 CET51847443192.168.2.4142.250.186.132
        Jan 8, 2025 14:14:34.849848986 CET4974180192.168.2.4165.22.209.237
        Jan 8, 2025 14:14:34.854990005 CET8049741165.22.209.237192.168.2.4
        Jan 8, 2025 14:14:34.855061054 CET4974180192.168.2.4165.22.209.237
        Jan 8, 2025 14:14:36.860589027 CET4972380192.168.2.4199.232.214.172
        Jan 8, 2025 14:14:36.860815048 CET4972480192.168.2.4199.232.214.172
        Jan 8, 2025 14:14:36.865609884 CET8049723199.232.214.172192.168.2.4
        Jan 8, 2025 14:14:36.865675926 CET4972380192.168.2.4199.232.214.172
        Jan 8, 2025 14:14:36.866045952 CET8049724199.232.214.172192.168.2.4
        Jan 8, 2025 14:14:36.866101027 CET4972480192.168.2.4199.232.214.172
        Jan 8, 2025 14:14:42.964463949 CET44351847142.250.186.132192.168.2.4
        Jan 8, 2025 14:14:42.964524984 CET44351847142.250.186.132192.168.2.4
        Jan 8, 2025 14:14:42.964572906 CET51847443192.168.2.4142.250.186.132
        Jan 8, 2025 14:14:44.846750975 CET51847443192.168.2.4142.250.186.132
        Jan 8, 2025 14:14:44.846788883 CET44351847142.250.186.132192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Jan 8, 2025 14:13:28.538058996 CET53608721.1.1.1192.168.2.4
        Jan 8, 2025 14:13:28.550353050 CET53651521.1.1.1192.168.2.4
        Jan 8, 2025 14:13:29.765429020 CET53636341.1.1.1192.168.2.4
        Jan 8, 2025 14:13:32.315450907 CET6236553192.168.2.41.1.1.1
        Jan 8, 2025 14:13:32.315512896 CET6501753192.168.2.41.1.1.1
        Jan 8, 2025 14:13:32.322258949 CET53650171.1.1.1192.168.2.4
        Jan 8, 2025 14:13:32.322537899 CET53623651.1.1.1192.168.2.4
        Jan 8, 2025 14:13:34.041637897 CET5644853192.168.2.41.1.1.1
        Jan 8, 2025 14:13:34.041930914 CET5241753192.168.2.41.1.1.1
        Jan 8, 2025 14:13:34.069289923 CET53524171.1.1.1192.168.2.4
        Jan 8, 2025 14:13:34.094825029 CET53564481.1.1.1192.168.2.4
        Jan 8, 2025 14:13:46.742930889 CET53519011.1.1.1192.168.2.4
        Jan 8, 2025 14:13:48.460000992 CET138138192.168.2.4192.168.2.255
        Jan 8, 2025 14:13:50.788697004 CET53515011.1.1.1192.168.2.4
        Jan 8, 2025 14:14:28.073625088 CET53599831.1.1.1192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Jan 8, 2025 14:13:32.315450907 CET192.168.2.41.1.1.10x8083Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Jan 8, 2025 14:13:32.315512896 CET192.168.2.41.1.1.10x451Standard query (0)www.google.com65IN (0x0001)false
        Jan 8, 2025 14:13:34.041637897 CET192.168.2.41.1.1.10xb03dStandard query (0)cdn.statisticline.comA (IP address)IN (0x0001)false
        Jan 8, 2025 14:13:34.041930914 CET192.168.2.41.1.1.10x3ebcStandard query (0)cdn.statisticline.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Jan 8, 2025 14:13:32.322258949 CET1.1.1.1192.168.2.40x451No error (0)www.google.com65IN (0x0001)false
        Jan 8, 2025 14:13:32.322537899 CET1.1.1.1192.168.2.40x8083No error (0)www.google.com142.250.186.132A (IP address)IN (0x0001)false
        Jan 8, 2025 14:13:34.094825029 CET1.1.1.1192.168.2.40xb03dNo error (0)cdn.statisticline.com165.22.209.237A (IP address)IN (0x0001)false
        Jan 8, 2025 14:13:34.094825029 CET1.1.1.1192.168.2.40xb03dNo error (0)cdn.statisticline.com134.122.109.150A (IP address)IN (0x0001)false
        Jan 8, 2025 14:13:34.094825029 CET1.1.1.1192.168.2.40xb03dNo error (0)cdn.statisticline.com165.232.114.226A (IP address)IN (0x0001)false
        • cdn.statisticline.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.449740165.22.209.237806100C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Jan 8, 2025 14:13:34.103884935 CET436OUTGET / HTTP/1.1
        Host: cdn.statisticline.com
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Jan 8, 2025 14:13:35.099981070 CET287INHTTP/1.1 200 OK
        Server: nginx/1.18.0 (Ubuntu)
        Date: Wed, 08 Jan 2025 13:13:34 GMT
        Content-Type: application/javascript
        Transfer-Encoding: chunked
        Connection: keep-alive
        X-Powered-By: Express
        Access-Control-Allow-Origin: *
        Cache-Control: no-store
        Cache-Control: no-cache
        Data Raw: 30 0d 0a 0d 0a
        Data Ascii: 0
        Jan 8, 2025 14:13:35.132704020 CET386OUTGET /favicon.ico HTTP/1.1
        Host: cdn.statisticline.com
        Connection: keep-alive
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Referer: http://cdn.statisticline.com/
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Jan 8, 2025 14:13:35.500056028 CET192INHTTP/1.1 404 Not Found
        Server: nginx/1.18.0 (Ubuntu)
        Date: Wed, 08 Jan 2025 13:13:35 GMT
        Content-Length: 0
        Connection: keep-alive
        X-Powered-By: Express
        Access-Control-Allow-Origin: *


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.449741165.22.209.237806100C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Jan 8, 2025 14:14:19.111350060 CET6OUTData Raw: 00
        Data Ascii:


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:08:13:24
        Start date:08/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:08:13:26
        Start date:08/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2268,i,10869499711930421036,3467080765669512565,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:08:13:33
        Start date:08/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cdn.statisticline.com"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly